A statute built for the wrong threat
Zambia's Aug. 13, 2026 general election was supposed to be a test of whether a young multiparty democracy could withstand the mechanics of social-media-era campaigning. Instead, MISA Regional's preliminary statement, published Aug. 17, 2026, concludes the country entered the vote with the wrong legal tools for the job: statutes broad enough to police what citizens said online, but not built to address how disinformation actually spread on the platform most Zambians used to follow the race (MISA Regional).
The legal architecture dates to April 2025, when President Hakainde Hichilema signed the Cyber Security Act, 2025 and the Cyber Crimes Act, 2025 (Act No. 4 of 2025) into law (National Assembly of Zambia). The Cyber Security Act created the Zambia Cyber Security Agency, housed a Central Monitoring and Coordination Centre capable of real-time communications interception, and required internet service providers to build in that interception capacity. The Cyber Crimes Act, meanwhile, criminalized the publication of "false information" likely to cause "public ridicule, contempt, hatred or embarrassment" under Section 22 — alongside a grab-bag of "obscene" and "lascivious" content offenses that give prosecutors wide interpretive latitude (CIPESA; Tech Policy Press).
Steelmanning the case for the law
Zambia's underlying problem is real. MISA's own statement notes that Facebook was the dominant information channel for the country's more than 4 million voting-age users during the campaign, and that platform served as a vector for attacks on female candidates — including fabricated claims about their marital status and, in some cases, witchcraft accusations — as well as false rumors about ballot delays and internet shutdowns that fact-checkers at iVerify had to actively debunk. A government confronting synthetic disinformation at that scale, with limited institutional capacity to counter it, has a legitimate interest in some baseline cybercrime and interception framework — the kind most G20 states already operate. Vague statutory drafting is a common growing pain in fast-moving digital-safety legislation, not proof of bad faith on its own.
Where the law crossed from safety to suppression
What converts a defensible instinct into a speech-suppression regime is design, not intent. MISA identifies the structural flaw plainly: the Zambia Cyber Security Agency is presidentially appointed, yet it "supported police investigations into critics of the very president who appointed them, as well as critics of the Electoral Commission of Zambia." An agency built to police the president's opponents cannot simultaneously be trusted to police disinformation neutrally — the two mandates are in direct tension, and the law resolves that tension in the executive's favor.
The clearest illustration is the case of ZNBC journalist McPherson Mukuka, detained for two weeks under the Cyber Crimes Act for allegedly recording a private conversation without consent. MISA calls the arrest "a warning to the entire journalistic sector" against straying from state-sanctioned narratives — and the chilling logic tracks. When a vague statute carries real jail time and a presidentially-controlled agency decides who gets investigated, the rational response for any journalist or ordinary Facebook user is to say less, not more, about the people in power. That is the opposite of what an election needs. Compounding the imprecision, Tech Policy Press notes the Act's emergency-interception provisions allow warrantless surveillance on a mere "imminent threat" finding, with only a 48-hour retrospective judicial check — a review window designed for after-the-fact rubber-stamping, not a meaningful check on abuse.
The disinformation problem the law never solved
Here is the deeper failure: none of this apparatus actually built platform-level defenses against the disinformation MISA documented. The gendered attacks on candidates, the false ballot-delay rumors, the fabricated shutdown claims — these spread through Facebook's ordinary distribution mechanics, not through acts a criminal statute against individual speakers can efficiently reach. Zambia's own civil society had to lean on a third-party fact-checking service, iVerify, to do the debunking the state apparatus was not built for. A law aimed at deterring individual posters did nothing to compel platform transparency, coordinated inauthentic-behavior takedowns, or ad-library disclosure — the actual levers that reduce election disinformation at scale, as seen in frameworks like the EU's Digital Services Act.
What proportionate reform looks like
Zambia does not need to choose between an open internet and election integrity — it needs a law that actually targets the second without gutting the first. The Law Association of Zambia's July 2025 High Court challenge to the Cyber Crimes Act is a first, appropriate check on Section 22's overbreadth (CIPESA, Tech Policy Press). Beyond litigation, three fixes would move Zambia toward genuine proportionality: narrow the "false information" offense to require proven intent and material electoral harm rather than subjective "embarrassment"; move interception authorization out of a presidentially-controlled agency and into an independent judicial body with real ex-ante review, not a 48-hour rubber stamp; and redirect enforcement energy toward platform-level transparency obligations rather than journalist prosecutions. None of that requires abandoning cybersecurity regulation — only building a version of it that survives being used against the people who wrote it.