Every time a new technology or innovation arrives, the reflex in African policy circles is, “how can the government regulate this?” Then comes “which foreign framework should we model?” With data protection, it was the European Union’s GDPR. Now, with artificial intelligence, the considerations are the European Union’s AI Act, the executive orders coming from Washington, and a growing list of national strategies modelled on both.
The African Union’s AI Strategy, to its credit, has resisted the urge. Adopted in 2024, the strategy takes a development-first approach by prioritising how countries can harness AI benefits. It is crucial this focus extends to legislation and prevents “responsible AI” language from pushing member states toward overly restrictive regulations.
Consider what the EU’s AI Act actually costs the businesses subject to it. Independent analyses of the AI Act’s high-risk obligations compiled by the Cloud Security Alliance (CSA) put initial compliance for a mid-size firm between $2 million and $5 million, with large enterprises facing $8 million to $15 million. Even ongoing annual costs can run into millions more. Other studies indicate that even a small startup deploying a single high-risk system can expect to spend €50,000 to €150,000 to conform with the Act. A macroeconomic study from the Centre for Data Innovation (CDI) shows that a total compliance framework, encompassing the quality management system (QMS), technical documentation, and external conformity assessments, can run past €400,000 for an SME. The Centre for European Policy Studies’ (CEPS) official regulatory impact assessments confirm this overhead cost, putting the AI Act’s cumulative administrative burden at roughly 17 percent on top of whatever a company was already spending to build the AI.
African leaders should recognise that adopting foreign legislation with high costs can stifle local startups and risk missed opportunities for economic development. This warning is not based on hypothetical worry about some future AI legislation in Africa. It is already shaping some national regulations, even well-intentioned ones. For instance, Nigeria’s National AI Strategy, released by the Ministry of Communications, Innovation and Digital Economy in August 2024, is in most respects a sensible document built around infrastructure and responsible AI governance, and it explicitly aims to position Nigeria as a continental leader in AI adoption. But the effect of strategies like this depend on what their implementing regulations eventually say.
The first major statutory attempt to introduce explicit AI compliance rules was the National Digital Economy and E-Governance Bill. In its early draft, this bill established a risk-based classification system modeled after international frameworks like the European Union’s AI Act. The tiered framework focused its regulatory mechanisms on high-risk AI systems deployed in sectors capable of directly affecting a citizen’s access to essential services. Under this classification, the most critical parts of the growing tech ecosystem were swept in, including financial services and fintech credit scoring, employment and human resources hiring tools, healthcare and medical diagnostics, public administration, and surveillance and biometrics software. Any AI system falling into these designated high-risk sectors faced massive pre-deployment compliance, including compulsory annual algorithmic audits, mandatory registration with the National Information Technology Development Agency (NITDA), extensive technical logging, and a requirement to maintain human-in-the-loop oversight to ensure automated decisions could always be challenged by a person.
However, before the Bill passed third reading and advanced to presidential assent, the lawmakers already removed the AI-specific regulatory provisions from the text to allow the Act focused strictly on digital infrastructure, e-governance frameworks, and general digital economy operations. While those strict provisions on AI compliance were excised from the final e-governance law, they left behind a clear footprint of the federal government’s regulatory intentions and a clear blueprint of the direction the country’s AI legislation is going.
Now, the core of Nigeria’s AI regulatory ambitions has been explicitly rechanneled into a dedicated, standalone legislation titled the National Artificial Intelligence Commission (Establishment) Bill which already passed first reading before the Senate.
Lessons from the Past
Another African country has already run the experiment of emerging technology regulation once—and better—and it is worth remembering how it turned out. When Safaricom launched M-Pesa in Kenya in 2007, the Central Bank of Kenya (CBK) resisted heavy pressure from commercial banks to shut it down. Instead of forcing the pilot project to meet rigid capital and licensing standards written for commercial banks, the CBK issued a “Letter of No Objection”, classifying it as a retail payment service and not a bank. For four years, the regulator observed how Kenyans actually used the platform, using this observation period to conduct risk audits. Only in 2011, after the system had matured to over 14 million users, did the CBK formally codify its oversight through the National Payment System Act. This regulatory patience is a large part of why East Africa became the epicentre of mobile money.
Meanwhile, AI is a more complex, and in some respects riskier, technology than mobile money, and nobody seriously argues that fraud, deepfake abuse, or algorithmic discrimination should go unaddressed. But the lesson from Kenyan mobile money was not “regulate less”. It was “regulate what you have evidence of harm from.”
Nigeria does not need a hypothetical case to see where this leads, because it has already run the pilot in two sectors. The Nigeria Data Protection Act of 2023 requires any data controller or processor of “major importance” to appoint a data protection officer and file annual compliance audits which cost between ₦1 million and ₦1.5 million. That audit cannot even be self-filed. The Act requires any organisation of major importance to route its annual Compliance Audit Return through a Data Protection Compliance Organisation (DPCO) licensed by the Commission. DPCO licensing alone runs to roughly ₦3 million, and a business engaging one for its own audit should budget between ₦500,000 and ₦4 million a year depending on size, on top of the salary of the dedicated data protection officer the law separately requires all major-importance controllers and processors to retain. The burden is the mandatory, expensive market for compliance professionals that the legislation itself created, and that every regulated business must pay into every year, whether or not it has ever mishandled any data.
On virtual assets, the SEC’s licensing regime under the Investments and Securities Act (ISA) 2025 established heavy entry bars for capital market participation. Following the SEC’s revised capital directives, Digital Asset Intermediaries (DAIs) and Digital Asset Platform Operators (DAPOs) are required to hold a minimum paid-up capital of ₦500 million. For larger structural entities, such as Real-World Asset Tokenisation Platforms (RATOP) and full-scale exchanges, thresholds have soared to ₦1 billion and ₦2 billion respectively. Industry analysts warned that regional peers were pulling ahead in crypto and digital-asset innovation due to significantly lower cost barriers to market entry.
South Africa’s Financial Sector Conduct Authority (FSCA), by contrast, imposes no fixed minimum share capital threshold for Crypto Asset Service Providers (CASPs); instead, it evaluates an applicant’s financial integrity and operational resources relative to the actual scale and risk profile of its operations. This South African risk-proportionate strategy enabled it to process over 530 applications and issue more than 300 licenses, while Nigeria’s Securities and Exchange Commission has only admitted or provisionally approved 10 entities under its Accelerated Regulatory Incubation Programme (ARIP) and digital asset framework.
Nigeria built the toughest entry price in Africa and is now watching founders and capital go elsewhere. That looks like the trajectory AI governance is on if regulators reach for the same playbook, where capital requirements and audit regimes designed for a fully capitalised European market are bolted onto companies still raising their first seed funding.
Africa’s AI Legislations
As of last year, 13 African countries had adopted or drafted AI strategies of their own. Multiply a compliance bill across that many jurisdictions, each with its own registration regime and its own definition of “high-risk”, and you have not built continent-wide AI governance, but 55 reasons never to launch a product on the continent.
This is not an argument against governance as such. It is an argument for governance that is sequenced correctly and reasonably.
Look across the globe, and the danger of getting this sequence wrong becomes obvious. In the United States, the absence of a unified federal statute on privacy has spawned a chaotic patchwork of fifty distinct state-level regulatory regimes. That legal fragmentation is projected to drain over $1 trillion from the U.S. economy over a decade, with young startups bearing the brunt of multi-jurisdictional compliance.
Meanwhile, the European Union’s AI Act showcases the immense power of a harmonised framework. After enacting a single binding regulation for all 27 member states, Brussels created a seamless digital single market of roughly 450 million consumers. An AI startup in Tallinn or Lisbon can design a tool once, pass a single set of standardised criteria, and immediately scale across the entire bloc without re-architecting its software or renegotiating entry in 27 different countries.
Asia offers another practical precedent. The Association of Southeast Asian Nations (ASEAN) eschewed rigid top-down mandates in favor of a joint Guide on AI Governance and Ethics. A common definition, common risk baselines, and cross-border interoperability goals across its ten member states, allowed economies like Singapore, Indonesia, and Vietnam to domesticate rules on their own timetables.
That is the exact model AI governance in Africa should borrow. A continental AI framework, anchored to the AfCFTA Digital Trade Protocol, agreed once at the AU level and then domesticated by each member state, would give founders one set of definitions to build for all 55 nations. It ensures that a healthcare tool built in Nairobi or a fintech model trained in Lagos meets equivalent safety floors in Accra or Kigali, allowing African innovation to scale easily across borders.
Every AU member state currently drafting an AI bill should be asked if they want compliance easy and cost-effective for their founders and if they want their founders to build for one nation or the 55 AU member states. That question, asked frankly, could dictate whether regulations will make or mar the emergence and progress of AI technology in the continent.