Data Sovereignty: Who Owns Africa's AI Future?
Every time a Kenyan farmer photographs a diseased crop, a Nigerian sends mobile money, or a South African clinic uploads an X-ray, data is created. The single most important question for the continent's AI future is deceptively simple: where does that data live, who profits from it, and who gets to say no? In 2026 the answer is still, overwhelmingly, "somewhere else, someone else, and nobody." That is data colonialism, and unwinding it is the defining sovereignty fight of the decade.
The one statistic that explains everything
Start with a single number. Africa is home to nearly 20% of humanity and holds roughly 1% of the world's data-centre capacity. Almost everything - the model training, the storage, the processing - happens on servers on other continents, in other jurisdictions, under other countries' laws.
The implications cascade. When African data is processed abroad, the economic value created from it - the models, the insights, the products - is captured abroad. The jobs are abroad. The taxes are abroad. And the legal control is abroad, which means an African government trying to protect its citizens' data is regulating something it cannot physically reach. This is what critics mean by data colonialism: raw material extracted from the continent, refined elsewhere, and sold back as a finished product.
Why this is not just a moral complaint
It would be easy to file data sovereignty under "activist grievance." That would be a mistake, because the costs are concrete and financial.
- Latency. When your data has to travel to Europe and back, African products are slower for African users. Local processing is faster, full stop.
- Cost. Cloud compute billed in dollars, in foreign data centres, is a permanent tax on every African AI company - one that scales with success.
- Value capture. If the data leaves, the AI economy built on it leaves too. Local data centres are how the value from African data stays in Africa.
- Control. Health and financial data governed by foreign law is data your own regulator cannot fully protect.
The build-out has started - with a catch
The most important sovereignty development of 2025 was money moving into local infrastructure. In October 2025, NVIDIA invested in Cassava Technologies as part of a partnership to build AI "factories" - GPU-powered data centres - across Africa, with deployments planned in South Africa, Egypt, Kenya, Morocco and Nigeria. The explicit pitch is sovereign compute: keep African data, and the value derived from it, inside the continent's borders.
This is real progress. It is also where honesty is required. Here is the catch that the press releases skate over: the chips are NVIDIA's, and much of the software layer above them still belongs to Google, Microsoft and Meta. A data centre on Kenyan soil running entirely on foreign silicon and foreign platforms is more sovereign than one in Virginia - but it is not fully sovereign.
Sovereignty is a stack, not a building. Owning the concrete and the fibre while renting the chips, the models and the platforms is a start - not a finish. The question is which layers Africa controls, not just where the racks sit.
The policy scaffolding is catching up
Hardware without rules is not sovereignty either. The legal layer has moved faster than most people realise.
- Kenya's Data Protection Act (2019) created the Office of the Data Protection Commissioner and restricts cross-border transfers unless adequate safeguards exist.
- Nigeria's Data Protection Act (2023) established the Nigeria Data Protection Commission, which issued its implementation directive in 2025 and has already investigated unlawful cross-border transfers.
- South Africa's POPIA gives the continent's most mature enterprise market a serious privacy regime.
- At the continental level, the African Union's 2024 Continental AI Strategy leans heavily on data protection and governance as the backbone of AI regulation, and Smart Africa is pushing for interoperable rules across borders.
The live tension is between data localisation - forcing data to stay in-country - and global cloud efficiency. Hard localisation can protect sovereignty and starve small startups of affordable infrastructure at the same time. Most African regulators have so far chosen scrutiny over strict localisation, which is probably the pragmatic call for now.
The trap to avoid
There is a version of "sovereignty" that is actually just a swap of landlords. A foreign hyperscaler builds a data centre in Lagos, calls it local, and captures the same value it always did - now with a sovereignty sticker on the door. Analysts have warned about exactly this "data-centre dilemma": physical presence without economic or technical control.
Genuine sovereignty has to reach further up the stack. It means African-owned infrastructure where possible, African-controlled data-governance rules, African-built models trained on African data, and African talent operating all of it. A rack in Nairobi owned and operated by foreigners, training foreign models on Kenyan data, is not sovereignty. It is colonialism with better ping times.
The cross-border question the continent has not answered
There is a deeper design choice hiding underneath the localisation debate, and it will shape the next decade. Fifty-five countries each writing their own incompatible data rules is a recipe for a fragmented, unwinnable market - a startup that has to re-paper its data agreements at every border will never reach the scale that makes African AI competitive. But a single continental free-flow of data, with no shared guardrails, hands the advantage straight back to whoever already has the biggest servers and the deepest pockets, which today means foreign hyperscalers.
The route out is coordination, not isolation. The same logic that produced the African Continental Free Trade Area for goods needs to be applied to data: common baseline protections, mutual recognition of each other's regimes, and the freedom to move information across borders once those protections are met. That is enormously hard political work, and it is moving slowly. But it is the only version of sovereignty that scales. A Kenyan startup that can serve Nigerian and South African users under interoperable rules is a continental company; one trapped behind 55 walls is a local curiosity.
Who should own Africa's AI future
My answer is deliberately unromantic. Total self-sufficiency is neither possible nor desirable in the near term - nobody is going to fabricate frontier chips in Kigali by 2028, and pretending otherwise wastes energy. The realistic goal is leverage: own enough of the critical layers that Africa negotiates as a participant, not a supplicant.
Concretely, that means insisting foreign investment comes with local ownership stakes, skills transfer and data-governance guarantees - not just imported racks. It means funding local model work like InkubaLM and Lesan so that the intelligence layer, not only the storage layer, has an African option. And it means regulators coordinating across borders so that 55 fragmented markets negotiate as one, which is the entire promise of the African Continental Free Trade Area applied to data.
Businesses have a role too, and it starts with clear-eyed decisions about their own data before they hand it to whoever offers the slickest demo - which is part of why it pays to understand the risk of buying AI before your business is ready. The data being generated across Africa right now is the raw material of the next economy. Whether Africans own the refinery, or just keep shipping the ore, is being decided in board rooms and parliaments this year. It is not too late to own it. But the clock is real.