Executive Summary
Artificial intelligence is moving into state security faster than many governments are establishing control over the infrastructure that supports it. The AU has begun treating data control, source code access, computing capacity, and human oversight as peace and security issues, while Saudi Arabia and the United Arab Emirates are pursuing stronger national control through sovereign data infrastructure and large-scale technology partnerships. These approaches reflect different levels of financial and technical capacity, but they all confront the same dependence on foreign semiconductors, cloud providers, and advanced models. For states, the immediate challenge is sharper because continental institutions are preparing to use artificial intelligence in early warning and security analysis while much of the underlying computing capability remains externally supplied.
On 16 April 2026, the African Union (AU) Peace and Security Council (PSC) placed artificial intelligence (AI) directly within Africa’s peace and security agenda. Its ministerial meeting called for data localisation, technology transfer, source code disclosure, and stronger African control across the AI ecosystem, while proposing greater use of AI within the African Peace and Security Architecture (APSA) and the Continental Early Warning System (CEWS). The same communiqué called for meaningful human control over security applications and faster development of a Common African Position on AI covering peace, security, democracy and development. The combination shows that the continental debate is moving beyond general principles on responsible technology towards control over systems that could increasingly influence how African institutions identify and respond to security threats.
The proposed expansion of AI within CEWS demonstrates the practical sovereignty problem. AI could increase the speed at which large volumes of conflict data are analysed, support scenario modelling and identify patterns across displacement, political violence and information activity. Those capabilities become more sensitive when the underlying model, cloud infrastructure or data-processing environment is controlled by an external provider. African security institutions then need to know where their information is stored, who can access it, how the model produces its conclusions and whether the system can continue operating if a commercial relationship or foreign technology policy changes. Source-code access and human oversight therefore concern control over parts of the security decision chain, alongside wider questions of technological development.
Africa enters this transition with limited infrastructure as the continent accounts for less than one percent of global data-centre capacity and an even smaller share of advanced computing infrastructure used to develop frontier AI systems. Domestic research capacity, electricity reliability and specialist technical skills are also uneven across states. These constraints make external partnerships unavoidable for many governments seeking rapid access to AI. The AU Commission (AUC), for example, signed a memorandum with Google on 17 February covering AI, cloud infrastructure, training, research and African-language capability while presenting the partnership as supporting sovereign African capacity. The arrangement captures the immediate dilemma: foreign platforms can close capability gaps quickly, but governments need sufficient technical and contractual authority to prevent that dependence from becoming permanent.
The Middle East and North Africa provide a useful comparison because states with much larger financial resources are confronting the same problem from a stronger negotiating position. Saudi Arabia has built its approach around the Saudi Data and Artificial Intelligence Authority (SDAIA), domestic data jurisdiction, sovereign computing infrastructure and the state-backed AI company HUMAIN. Its strategy combines national capability with relationships across the United States and Chinese technology ecosystems, giving the government greater scope to diversify suppliers while advanced processors and other critical technologies remain produced externally. Saudi Arabia’s model therefore uses capital and domestic regulation to increase control over selected layers of the AI system without attempting to reproduce the entire global technology supply chain.
The United Arab Emirates (UAE) has pursued a more infrastructure-intensive model. State-linked technology company G42 has developed the Digital Embassies concept, which seeks to preserve government jurisdiction over data and digital systems even when infrastructure is hosted outside national territory. The UAE is also investing in large computing clusters and Arabic-language models, including the Falcon series. Access to the highest-end processors nevertheless remains affected by United States export controls, including approvals governing advanced chips supplied to G42. The UAE consequently demonstrates that substantial capital can buy computing capability and privileged supplier relationships while external governments can retain leverage over critical components.
Regional institutions are approaching these dependencies differently. The Gulf Cooperation Council (GCC) has developed guidance on AI ethics, public-sector use and policy coordination, while the Arab League Educational, Cultural and Scientific Organisation (ALECSO) has focused on privacy, technological sovereignty, cultural identity and Arabic-language representation. The AU has moved further into explicit peace and security governance through the PSC. This partly reflects different institutional needs. Gulf states with greater national capacity can develop large domestic systems independently, while many African states may gain more practical control through shared standards, pooled computing capacity and collective procurement.
That collective approach will require careful treatment of data sovereignty. The PSC has supported localisation of sensitive data, yet continental security systems such as CEWS depend on information moving across borders. Conflict patterns in the Sahel, Horn of Africa, and Great Lakes region rarely remain within a single jurisdiction, while cyber threats and coordinated information operations can operate across several states at once. Strict national localisation rules could therefore protect jurisdictional authority while limiting the data sharing required for regional security analysis. African institutions will need to separate information that requires national protection from datasets that can circulate through trusted continental mechanisms, subject to clear access and oversight rules.
Local capability also affects whether AI systems can be trusted for state use. Nigeria’s development of the open-source N-ATLaS model, which covers Yoruba, Hausa, Igbo, and Nigerian-accented English, illustrates why language capability has security relevance. Models developed primarily for dominant global languages can misread local political discourse, coded speech or regional terminology, reducing their value for early warning and information analysis. Similar investments in Arabic-language models by Saudi Arabia and the UAE show that language sovereignty is increasingly treated as part of technical capability, as governments require systems that can accurately interpret domestic information environments.
The security stakes increase further when AI enters cyber defence, intelligence analysis, and military decision support. Commercial cloud providers and civilian data centres are becoming increasingly important to defence applications, while advanced processors and software remain concentrated among a small number of international companies. Governments may therefore own surveillance platforms or military systems while relying on external firms for the computing infrastructure that processes the resulting information. The PSC’s emphasis on meaningful human control becomes particularly relevant in these environments because state institutions require the ability to challenge automated outputs and to retain clear responsibility for decisions that carry legal or coercive consequences.
The next phase is likely to shift from a continental strategy to procurement and technical standards, where the practical meaning of AI sovereignty will become clearer. As APSA, CEWS and national security institutions begin adopting more AI-enabled tools, African governments will need common requirements covering data jurisdiction, model auditing, human oversight, supplier substitution and access to underlying systems. Saudi Arabia and the UAE will continue demonstrating how capital and strategic relationships can strengthen bargaining power with technology providers, while most African states will depend more heavily on regional pooling and common standards. The central security question will therefore become whether African institutions can increase AI-enabled analytical capacity while retaining enough technical authority to govern the systems on which that capacity increasingly depends.