TRENDING

A New Policy Brief Says West Africa’s AI Future Hinges on Fixing Fragmented Data Governance

By: indexprima

September 9, 2026

Image Source:

Share

West Africa’s ability to actually benefit from artificial intelligence isn’t being held back by a shortage of data, according to a new policy brief from Solomon Kershima Yateghtegh, founder of Benue-based SKYHub Nigeria. The real constraint, the brief argues, is the region’s inability to move data securely and responsibly across institutions and borders while still protecting privacy, accountability, and national control over it. Titled “Beyond Fragmented Data,” the brief makes the case that West Africa needs to move away from fragmented, parallel data governance efforts and toward what it calls interoperable data sovereignty, a model built to enable responsible regional data flows without African institutions losing meaningful authority over how their most important data gets used.

The Nigerian Example That Makes the Problem Concrete

Nigeria’s own Digital Public Infrastructure rollout illustrates exactly what the brief is describing. The National Information Technology Development Agency is building a Nigerian Data Exchange meant to unify identity, payment, and service-delivery data currently scattered across separate government agencies, with implementation beginning in early 2026. The everyday version of this problem is one most Nigerians have lived through directly: having to resubmit the same biometric and personal data across NIN registration, BVN, SIM registration, and passport applications, simply because those systems were never built to talk to each other. There’s an ironic wrinkle worth noting too. NGDX, one of Nigeria’s flagship attempts at digital sovereignty, is actually financed under the European Union’s Global Gateway initiative, with Finland, Estonia, Germany, and France directly participating in its design workshops. External partnership can genuinely speed up delivery, but without deliberate investment in local technical capacity alongside it, a sovereignty project risks leaving African institutions dependent on the very foreign infrastructure it was meant to reduce reliance on.

Why Moving Data Across Borders Is Legally Messy

Beyond the technical fragmentation, the brief points to a real legal headache facing any business or researcher operating across multiple West African countries. Nigeria’s Data Protection Act of 2023 only permits cross-border data transfers where the receiving country or organisation can demonstrate an adequate level of protection, or where a specific statutory exception applies. A company working across Nigeria, Ghana, Senegal, and Côte d’Ivoire has to satisfy a broadly similar but not identical version of that same test in each country separately, with no mutual recognition between them. That’s not a minor compliance inconvenience, it’s a structural drag on exactly the kind of regional data pooling that AI systems need to work well for African users in the first place.

The Warning From West Africa’s Own Recent History

The brief’s most pointed argument draws on a cautionary continental precedent rather than a hypothetical risk. The African Union’s Malabo Convention on cybersecurity and data protection was adopted back in 2014, but it didn’t actually enter into force until 2023, nine years later, once the fifteenth country finally ratified it. Even after that, only around 16 of the AU’s 55 member states had ratified the convention as of 2025. The lesson isn’t that regional legal frameworks are pointless, it’s that a signed agreement without funded institutions, staffed data protection authorities, and sustained political follow-through can sit essentially dormant for a decade. ECOWAS’s own Regional Open Data Legal Framework, still under member-state review as of March 2026, faces exactly that same risk unless implementation capacity gets built alongside the legal text rather than negotiated afterward as an afterthought.

What Interoperable Data Sovereignty Actually Means

The brief is careful to reject a false choice between fully open data flows and strict data localisation. Excessive localisation, it argues, would simply raise infrastructure costs and choke off the regional digital integration West Africa actually needs. Real sovereignty, in this framing, isn’t about where a server physically sits, it’s about whether African institutions genuinely control what data gets collected, who can access it, under what conditions it moves, how it gets processed, who profits from it, and what accountability applies when something goes wrong.

The Concrete Recommendations

Rather than stopping at diagnosis, the brief lays out specific policy moves: extending ECOWAS’s open data framework beyond public-sector data to cover civil registration, tax, and health data specifically, with an implementation budget attached at the moment of adoption rather than negotiated later; building a single regional adequacy or certification mechanism, modelled on Nigeria’s own cross-border test, so one certification satisfies every member state instead of each country separately; identifying a specific shortlist of public-interest, AI-relevant datasets in agriculture, health, and financial inclusion for structured regional access; requiring externally financed infrastructure projects like NGDX to come paired with binding local-capacity commitments, including technology transfer and local technical leadership; and funding and staffing data protection authorities before new agreements get signed, not after, precisely the sequencing failure that left the Malabo Convention dormant for so long.

Why This Framing Matters

The brief’s closing argument is worth sitting with regardless of how the specific policy recommendations land: the future of African AI may end up depending less on who builds the most powerful models and more on who actually has the institutional capacity to govern the data those models are trained and run on. For a region racing to digitise public services and build homegrown AI capability at the same time, that’s a genuinely useful reframe, treating data governance not as a compliance afterthought sitting beside AI policy, but as the foundation any serious AI strategy has to be built on top of.

Read policy brief.