Intended audience: AU member state AI policy teams, pan-African technology companies, international development organizations working on African digital transformation, Smart Africa Digital Economy members, regional economic communities (EAC, ECOWAS, SADC, COMESA), and organizations aligning national AI strategies with continental frameworks.
Continental AI Strategy adopted. Phase 1 (2025-2026) governance structures active. The African Union adopted the Continental Artificial Intelligence Strategy in July 2024, endorsed by the Executive Council. Phase 1 (2025-2026) focuses on establishing governance structures, creating national AI strategies across member states, and mobilizing resources. The strategy aligns with the Malabo Convention on Cyber Security and Personal Data Protection and builds on the AU Agenda 2063. This is the governance framework that 55 member states reference when developing national AI policies.
1. AU AI Governance Landscape
The AU Continental AI Strategy sits above national AI policies adopted or in development across the continent, including those of Rwanda, Kenya, Nigeria, Ghana, and South Africa. It provides the governance template that member states adapt to their domestic contexts, creating a shared baseline for responsible AI deployment across the region.
The strategy was developed through multi-stakeholder consultation involving government ministries, private sector representatives, civil society, and international partners. It was adopted at the AU Executive Council meeting in Accra, Ghana in July 2024. It builds on several existing AU digital frameworks, including the AU Digital Transformation Strategy (2020-2030), the Malabo Convention on Cyber Security and Personal Data Protection, and Agenda 2063: The Africa We Want.
Phase 1 (2025-2026) is active now. The focus is on establishing continental and national governance structures, developing national AI strategies where none exist, building capacity, and mobilizing investment. Organizations deploying AI in AU member states should be prepared to demonstrate alignment with both the continental framework and any applicable national legislation.
2. Five Strategic Pillars
Pillar 1: Leveraging AI Benefits
Focused on deploying AI across priority sectors including agriculture, health, education, and infrastructure. Encourages member states to identify sector-specific use cases and create enabling environments for innovation. SWT3 relevance: AI-INF.1 (infrastructure attestation) and AI-PERF.1 (performance monitoring) provide evidence that deployed systems meet operational standards.
Pillar 2: Building Capacities
Addresses workforce development, research infrastructure, and centers of excellence. Calls for AI curricula, training programs, and knowledge-sharing networks across the continent. SWT3 relevance: AI-SKILL.1 (skill manifest attestation) and AI-GOV.5 (governance accountability) document organizational capacity and competence.
Pillar 3: Minimizing Risks
Covers ethical AI principles, safety frameworks, bias mitigation, and human rights protections. Aligns with the AU's broader commitment to inclusive development and the Malabo Convention's data protection provisions. SWT3 relevance: AI-RISK.1 (risk assessment), AI-FAIR.1 (fairness evaluation), and AI-SAFE.1 (safety attestation) create verifiable evidence of risk management.
Pillar 4: Boosting Investment
Targets resource mobilization from public budgets, development finance, and private investment. Calls for AI funds at national and continental levels. SWT3 relevance: AI-COST.1 (resource consumption witnessing) documents the cost and resource profile of AI deployments.
Pillar 5: Fostering Collaboration
Promotes cross-border data governance, multi-stakeholder coordination, and alignment with international frameworks. Emphasizes partnerships between regional economic communities and global organizations. SWT3 relevance: AI-CHAIN.1 (chain of custody), AI-TRUST.1 (inter-system trust), and AI-DEL.1 (delegation tracking) provide the technical substrate for cross-border governance.
3. Phase 1 Implementation Requirements
| Phase 1 Deliverable | Governance Objective | SWT3 Procedure |
|---|---|---|
| National AI strategy creation | Governance framework documentation | AI-GOV.1 |
| AI advisory board establishment | Governance accountability | AI-GOV.5 |
| Risk assessment frameworks | Risk register creation | AI-RISK.1 |
| Data governance alignment | Data provenance tracking | AI-DATA.1 / AI-DATA.2 |
| Center of excellence setup | Capability attestation | AI-SKILL.1 |
| Cross-border data governance | Chain of custody | AI-CHAIN.1 |
| Ethics review mechanisms | Fairness assessment | AI-FAIR.1 |
4. Obligation-to-Procedure Mapping
| AU Strategy Requirement | SWT3 Procedure | Evidence Produced |
|---|---|---|
| AI governance framework aligned with continental strategy | AI-GOV.1 | Governance policy witness anchor with continental reference |
| Governance accountability and advisory structures | AI-GOV.5 | Accountability chain anchor with role attestation |
| Risk assessment for AI deployments | AI-RISK.1 | Risk register witness with severity classification |
| Data provenance and quality assurance | AI-DATA.1 | Data lineage anchor with source attestation |
| Data protection (Malabo Convention alignment) | AI-DATA.2 | Data handling witness with consent and retention records |
| Fairness and inclusion in AI systems | AI-FAIR.1 | Fairness evaluation anchor with demographic analysis |
| Safety requirements for high-risk AI | AI-SAFE.1 | Safety attestation anchor with incident history |
| Cross-border data flows between member states | AI-CHAIN.1 | Chain of custody anchor with jurisdiction transitions |
| Inter-system verification across borders | AI-TRUST.1 | Trust credential exchange with mutual verification |
| Delegation of AI operations across organizations | AI-DEL.1 | Delegation tree anchor with authority chain |
| AI system performance monitoring | AI-PERF.1 | Performance baseline anchor with metric snapshots |
| Resource consumption transparency | AI-COST.1 | Resource consumption anchor with compute and cost data |
| Human oversight and review mechanisms | AI-HITL.1 | Human review anchor with reviewer binding |
| Model infrastructure attestation | AI-INF.1 | Infrastructure witness with deployment context |
5. SWT3 Procedure Cards
Governance Framework -- Continental Alignment
Witnesses the existence and structure of an AI governance framework. In the AU context, this procedure captures alignment between an organization's governance policies and the Continental AI Strategy's pillars and Phase 1 deliverables.
Factor A: Governance policy document hash. Factor B: Framework version and review date. Factor C: Continental strategy reference identifier.
Ask for evidence that the organization's AI governance framework references AU Continental Strategy Phase 1 deliverables. The witness anchor should include the governance document hash and the date of last alignment review.
Cross-Border Custody -- Multi-State Data Flows
Creates an immutable chain of custody when AI data or model artifacts move between AU member states. Each custody transition generates a witness anchor recording the source jurisdiction, destination jurisdiction, and the legal basis for the transfer.
Factor A: Source jurisdiction (ISO 3166-1). Factor B: Destination jurisdiction. Factor C: Transfer legal basis and data classification.
Verify that every cross-border data transfer has a corresponding AI-CHAIN.1 anchor with both source and destination ISO country codes. Confirm the legal basis aligns with the Malabo Convention and any bilateral data-sharing agreements.
Inter-System Trust -- Cross-Border Agent Verification
Enables mutual verification between AI systems operating in different AU member states. When systems exchange data or decisions, AI-TRUST.1 records the trust credential presented and the verification outcome, ensuring both parties can prove the interaction was authenticated.
Factor A: Local system identifier. Factor B: Remote system credential hash. Factor C: Verification outcome and trust level.
Request AI-TRUST.1 anchors for any cross-border AI integration. Confirm that trust credentials were exchanged before data was shared and that the remote system's identity was verified against a known registry.
Risk Assessment -- Continental Risk Framework
Witnesses the completion and findings of an AI risk assessment. Under the AU strategy, risk assessments should consider continental priorities including digital inclusion, linguistic diversity, and infrastructure constraints specific to the African context.
Factor A: Risk assessment methodology. Factor B: Risk severity classification. Factor C: Mitigation plan reference.
Confirm the risk assessment addresses AU-specific concerns such as infrastructure availability, multilingual populations, and potential exclusion of underserved communities. The anchor should reference the mitigation plan.
Data Governance -- Malabo Convention Alignment
Records data provenance, quality, and governance practices. For organizations operating under the Malabo Convention, this procedure captures evidence that data handling complies with the Convention's personal data protection requirements and any national implementing legislation.
Factor A: Data source and lineage hash. Factor B: Quality assessment outcome. Factor C: Malabo Convention compliance reference.
Verify that AI-DATA.1 anchors reference Malabo Convention compliance where the member state has ratified the Convention. For states that have not yet ratified, check for alignment with any national data protection law in force.
Fairness -- Inclusive AI Principles
Witnesses fairness evaluations for AI systems. The AU strategy emphasizes that AI must serve all populations equitably, with particular attention to gender equity, rural communities, linguistic minorities, and persons with disabilities.
Factor A: Evaluation methodology. Factor B: Demographic groups assessed. Factor C: Disparity metrics and findings.
Ask whether the fairness evaluation covers demographic categories relevant to the AU context, including gender, rural/urban, language groups, and disability status. The anchor should record which groups were assessed and the disparity findings.
6. Cross-Border Governance Patterns
The AU Continental AI Strategy's collaboration pillar requires governance mechanisms that work across sovereign borders. SWT3 provides several patterns for cross-border AI governance:
- AI-CHAIN.1 creates custody chains that track data and model artifacts as they cross member state borders. Each transition is a witness anchor with jurisdiction codes.
- AI-TRUST.1 enables mutual verification between AI systems in different member states. Before exchanging data or decisions, systems present and verify trust credentials.
- AI-DEL.1 tracks delegation of AI operations across organizational and national boundaries. When a Kenyan organization delegates processing to a South African partner, the delegation tree records the authority chain.
- Clearing levels control what evidence crosses borders. CL0 (Analytics) is suitable for shared governance dashboards. CL3 (Classified) restricts sensitive cross-border evidence to authorized parties only.
- Every witness anchor includes a jurisdiction field (ISO 3166-1), ensuring that the legal context of each attestation is permanently recorded.
Regional economic communities (EAC, ECOWAS, SADC, COMESA) can use these patterns to build shared governance infrastructure while respecting each member state's sovereignty over its own AI policies.
7. Quick Reference
| Assessor Question | SWT3 Procedure |
|---|---|
| Does the governance framework reference the AU Continental Strategy? | AI-GOV.1 |
| Is there an AI advisory board with documented accountability? | AI-GOV.5 |
| Has a risk assessment been completed for this AI system? | AI-RISK.1 |
| How is data provenance tracked for training data? | AI-DATA.1 |
| Does data handling comply with the Malabo Convention? | AI-DATA.2 |
| Has a fairness evaluation been performed? | AI-FAIR.1 |
| How are cross-border data transfers documented? | AI-CHAIN.1 |
| Can the system verify the identity of cross-border AI partners? | AI-TRUST.1 |
| Is delegation of AI operations tracked across organizations? | AI-DEL.1 |
| What is the resource consumption profile of the AI system? | AI-COST.1 |
8. Quick Start
Install the Python SDK and begin witnessing AI operations with AU jurisdiction context:
pip install swt3-ai
from swt3_ai import SWT3Witness
witness = SWT3Witness(
agent_id="au-health-ai-v2",
jurisdiction="AU",
purpose_class="healthcare_triage"
)
# Witness governance framework alignment
witness.witness(
procedure="AI-GOV.1",
factor_a="governance_policy_sha256:9f3c...",
factor_b="v2.1_reviewed_2026-06-15",
factor_c="au_continental_strategy_phase1"
)
# Witness cross-border data transfer
witness.witness(
procedure="AI-CHAIN.1",
factor_a="KE", # Source: Kenya
factor_b="ZA", # Destination: South Africa
factor_c="malabo_convention_art12"
)
witness.flush()
The TypeScript SDK follows the same pattern. See the SDK documentation for full API reference and adapter examples.
9. References
- AU Continental Artificial Intelligence Strategy (July 2024)
- Malabo Convention on Cyber Security and Personal Data Protection
- Smart Africa Alliance
- AU Agenda 2063: The Africa We Want
- Kenya AI Bill Crosswalk
- Nigeria AI Strategy Crosswalk
- Rwanda AI Policy Crosswalk
- SWT3 SDK Documentation -- 9 SDK packages, 266 procedures, 75 namespaces
- Create a free account to begin witnessing