This discussion brought together panellists from RealTyme, the Arab ICT Organization (AICTO), Smart Africa, and Talisman Cybersecurity to explore digital sovereignty, data governance, and the emerging challenges of post-quantum cryptography .
François Rodriguez (RealTyme) opened by distinguishing between the feeling of being digitally sovereign and the reality of achieving it, highlighting three key dimensions: verifying where data is stored, understanding the jurisdiction of cloud service providers, and ensuring regulatory compliance . He warned that governments risk losing operational independence if they rely on vendors who can withdraw services unilaterally , and stressed the urgency of transitioning to post-quantum encryption, noting that quantum computing capable of breaking current cryptography may arrive as early as 2030-2031 .
H.E. Mohamed Benamor of AICTO argued that digital sovereignty is not a binary choice between national control and regional cooperation, but rather a balance between the two . He described AICTO's role as facilitating consensus and enabling member states to collaborate on cybersecurity, AI research, and shared standards while preserving national decision-making . Gallo Fall added that many countries in the Global South have already lost control of their digital infrastructure without realising it, and that his platform was built to map sovereignty posture and provide actionable recommendations .
Thelma Efua Quaye emphasised that owning infrastructure is insufficient without investment, understanding, and market stimulation, drawing on her experience of a national backbone operating at below 10% utilisation (less than one-tenth of the network's total data-carrying capacity is actually being used) . She and other panellists agreed that no offer of free infrastructure should be accepted without scrutiny, as data, sovereignty, or strategic leverage are invariably the cost .
The session concluded with an audience exercise revealing significant gaps in governments' awareness of data governance laws, vendor contract terms, encryption key control, and post-quantum readiness , underscoring the critical role of capacity building programmes offered through platforms such as Smart Africa Digital Academy and ITU Academy .
Overall Purpose
- The discussion aims to raise awareness of digital sovereignty, data governance, post-quantum cryptography, and capacity-building among governments - particularly in the Global South and Arab regions. The session seeks to help policymakers understand the gap between 'feeling' sovereign and 'being' sovereign, and to promote practical frameworks, training programmes, and regional cooperation to close that gap.
- --
Major Discussion Points
- Defining and measuring digital sovereignty: François Rodriguez outlined that true digital sovereignty requires three verifiable layers - knowing where data physically resides, understanding the jurisdiction of the cloud or service provider, and ensuring data does not transit through uncontrolled third-party systems. He emphasised the critical distinction between the 'feeling' of sovereignty and its reality. H.E. Mohamed Benamor reinforced this by defining sovereignty simply as "the capability of one country to have full control of its data." - Vendor dependency and the risks of 'free' infrastructure offers: Panellists warned strongly against vendor lock-in and the dangers of accepting infrastructure built and run by foreign entities at no apparent cost. François Rodriguez added that, beyond data, intellectual property, and AI model training data can be silently extracted, enabling foreign actors to build strategic simulations of a country's population. Gallo Fall spoke of data colonisation, urging nations to classify and protect crown-jewel data such as national ID systems, biometrics, and election rolls. - The gap between owning and running digital infrastructure: Thelma Efua Quaye drew on her experience as a CTO to illustrate that a country can own infrastructure yet fail to utilise or maintain it effectively, often because governments do not understand its strategic importance and therefore do not invest in it. She identified three steps to move from ownership to operational control: understanding the importance of the infrastructure, investing in capacity building, and stimulating market demand to ensure utilisation. - Post-quantum cryptography as an urgent, underbudgeted threat: François Rodriguez highlighted that quantum computing - previously expected to threaten existing encryption by 2040 - is now anticipated as early as 2031, making the migration to post-quantum cryptography an immediate priority. The audience exercise at the end of the session revealed that virtually no hands were raised when asked whether post-quantum migration was already budgeted, underscoring the gap between awareness and action. - Regional cooperation and capacity building as enablers of sovereignty: H.E. Mohamed Benamor explained that AICTO's role is not to advocate for centralisation but to facilitate consensus, helping member states collaborate on cybersecurity, AI research, interoperability, and shared standards while preserving national decision-making authority. The session also announced a new MOU between RealTime and AICTO, complementing existing partnerships with Smart Africa, to expand capacity building programmes across the Arab region and Africa.
- --
Overall Tone
- The tone throughout the discussion is informative, collaborative, and gently cautionary. The moderator, Maryna Veuthey, maintains an upbeat and engaging register, using humour and interactive exercises to keep the audience involved. The panellists are measured and constructive rather than alarmist, though moments of urgency emerge - particularly when discussing data colonisation , the risks of "free" infrastructure , and the imminence of quantum threats . The tone shifts slightly towards the end, becoming more motivational and action-oriented as the session closes with calls to join training platforms and upcoming webinars. Overall, the discussion balances realism about current vulnerabilities with optimism about the tools, frameworks, and partnerships available to address them.
Expanded Summary: Digital Sovereignty, Data Governance, and Post-Quantum Cryptography
#
Session Overview and Introductions
The session, moderated by Maryna Veuthey, brought together four panellists to explore the interconnected themes of digital sovereignty, data governance, cybersecurity, and post-quantum cryptography . The panel comprised François Rodriguez of RealTime, H.E. Eng. Mohamed Benamor, Secretary General of the Arab ICT Organisation (AICTO), joining remotely ; Thelma Efua Quaye, Digital Infrastructure Skills Empowerment Officer of Smart Africa ; and Gallo Fall, founder and CTO of Talisman Cybersecurity . Veuthey framed the session as interactive, promising audience participation and a practical exercise alongside the panel discussion . A significant institutional development was announced during the session: RealTime signed a new Memorandum of Understanding (MOU) with AICTO, complementing its existing partnerships - including a prior collaboration with the GFC and its current partnership with Smart Africa - to extend capacity building programmes across the Arab region .
#
Setting the Context: From Feeling Sovereign to Being Sovereign
François Rodriguez opened the substantive discussion by drawing on RealTime's experience as a capacity building partner of the ITU, having trained more than 50 different countries on digital sovereignty, post-quantum cryptography, and secure government communications . He immediately established the session's central intellectual tension: the distinction between the willingness to feel sovereign and the reality of actually being sovereign in the field . This framing set the tone for the entire discussion, challenging the assumption that signing agreements or owning infrastructure automatically confers genuine sovereignty.
Rodriguez outlined three verifiable dimensions of digital sovereignty. The first is auditability - whether a government can genuinely verify that it is sovereign . The second concerns data location and jurisdiction: where data physically resides, whether it sits within the country's borders, and what jurisdiction governs the cloud service provider . The third dimension addresses the routes through which data transits, including whether third-party software providers operate under the same jurisdiction as the government, and whether gaps between these jurisdictions create vulnerabilities . He cited a recent, unspecified instance in which governments had access to certain AI tools switched off by providers, warning that if a vendor stops providing services or updates, a country's operations can halt entirely, directly affecting citizens .
#
Data Governance as the Foundation of Sovereignty
Rodriguez presented data governance as the foundational layer upon which all other sovereignty measures depend . He outlined a data lifecycle framework covering four stages: understanding what data is collected and ingested into digital environments; determining how it is stored and protected according to sensitivity; managing how it is used in day-to-day workflows; and, critically, deciding what data should be deleted . He emphasised that data minimisation - reducing the volume of data stored - directly limits exposure in the event of a breach . Appropriate encryption must then be applied to data requiring protection, which connects directly to the urgency of transitioning to post-quantum cryptography .
Rodriguez also raised the question of AI data governance, noting that more than 50% of AI queries are sufficiently simple to be processed on-device - through summarisation, translation, and workflow integration - without routing data to cloud AI systems . He argued that unnecessarily sending data to cloud AI mirrors the broader sovereignty risks already identified: once data enters the cloud, control over it is effectively surrendered . This point reinforced the session's broader argument that sovereignty is not merely a regulatory or contractual matter but a series of daily operational choices.
#
Regulatory Harmonisation and the Limits of Borrowed Frameworks
Rodriguez also addressed the challenge of regulatory harmonisation, noting that African countries have increasingly sought to implement regulations modelled on EU frameworks . While acknowledging the EU's leadership in strict digital regulation, he cautioned that architectural and contextual fit must be considered, as regulations designed for one destination may not serve the needs of another . He used the example of EU trade corridors originally designed for raw materials, which bear little resemblance to today's digital economy routes in agriculture, healthcare, and finance . He noted that the ongoing AI dialogue in Geneva is attempting to harmonise global regulations, but questioned whether such harmonisation can realistically constrain hyperscalers providing services across multiple jurisdictions .
#
AICTO's Perspective: Sovereignty Through Regional Solidarity
H.E. Eng. Mohamed Benamor offered a regional governance perspective, arguing that digital sovereignty should not be framed as a binary choice between full national control and shared regional capabilities . He described AICTO's role not as advocating for centralisation but as facilitating consensus among member states , enabling them to collaborate voluntarily on areas where regional action creates greater value - including cybersecurity, AI research, digital public infrastructure, interoperability, capacity building, and shared technical standards - while retaining control over critical infrastructure and national policies . He described AICTO as providing a multi-stakeholder platform for jointly developing governance frameworks and trusted cooperation mechanisms that respect national priorities while advancing common regional values , with the ultimate objective of strengthening national digital sovereignty through regional solidarity .
When asked for a one-sentence definition of sovereignty, Benamor stated simply that it is "the capability of one country to have full control of their data" . This maximalist definition was later complemented by other panellists who offered more operationally nuanced perspectives, creating one of the session's more productive definitional exchanges.
#
The Technical Reality: Many Countries Have Already Lost Control
Gallo Fall introduced a sobering perspective, drawing a precise conceptual distinction between cybersecurity and digital sovereignty. He described cybersecurity as a largely technical discipline focused on protecting systems from unauthorised access, disruption, or destruction, whereas digital sovereignty is a broader strategic concept: a system can be perfectly secure and yet not be under the country's control . This distinction is critical because it prevents governments from conflating technical security measures with genuine strategic autonomy.
Fall explained that his digital sovereignty intelligence platform at Talisman Cybersecurity was built out of personal conviction, having witnessed widespread cyber attacks in the Global South as a native of Senegal . The platform functions as a continuous unified intelligence ecosystem, purpose-built for government ministries, critical infrastructure institutions, and others that refuse to cede strategic control of their data, infrastructure, and AI capabilities . It maps cybersecurity frameworks against sovereignty pillars and provides KPIs, reports, and recommendations to help governments understand where they currently stand . His central finding was stark: many countries in the Global South have already lost control of their data and digital infrastructure without realising it, because they do not know their digital sovereignty posture . This observation directly reinforced Rodriguez's earlier distinction between feeling and being sovereign, and prompted Veuthey to identify ignorance - not malice or technical failure - as the primary cause of sovereignty loss .
Fall also drew an explicit distinction between compliance frameworks and genuine sovereignty assessment, arguing that compliance gives governments "a checklist that just gives you a certification certificate" but does not tell them what is actually happening in real time . His platform, by contrast, is designed to provide situational awareness so that governments know where to start addressing their gaps .
#
From Owning to Running: The Capacity Building Imperative
Thelma Efua Quaye approached the question of sovereignty from the perspective of infrastructure utilisation and capacity building, drawing on her experience as a former CTO who managed a backbone infrastructure connecting critical areas . She recounted that utilisation of the infrastructure was below 10%, and that maintenance and service were poor, because the government did not understand the strategic importance of the asset and therefore did not invest in it . This experience served as a concrete illustration of the gap between owning infrastructure and being able to run it effectively.
Quaye identified three steps necessary to transition from ownership to operational control . The first is understanding: governments must comprehend why investment in digital infrastructure matters before they will commit resources to it, and this is precisely where capacity building programmes play their role . The second is investment itself, which follows from understanding . The third is stimulating market demand to ensure that infrastructure, once built, is actually utilised . She noted that several countries had invested in sovereign data centres driven by the feeling of sovereignty rather than actual market need, resulting in low utilisation - a direct echo of the feeling-versus-being distinction established earlier in the session . She suggested that governments can stimulate demand through mechanisms such as startups and AI factories, though the precise context of the latter was not fully elaborated in the transcript .
Quaye also offered a perspective on sovereignty that provided a more operationally achievable standard, particularly for developing nations. She argued that total isolation is not realistic in today's world, and that sovereignty for a government should mean transparency and the ability to know what their data is being used for, with the power to say yes or no . This framing - sovereignty as informed consent rather than absolute control - offered a practically meaningful standard for countries that cannot realistically build fully independent digital ecosystems.
#
The Dangers of "Free" Infrastructure Offers
The panel converged strongly on the question of whether governments should accept offers of free digital infrastructure from foreign vendors or governments. Veuthey posed a hypothetical scenario in which a country or vendor offered to build and run an entire national infrastructure from A to Z at no cost, inviting panellists to think through the implications before accepting .
Quaye responded with characteristic directness, stating that there is nothing free and that "if you are not the one eating, you are probably being eaten" . She grounded this principle in a concrete example, citing a situation involving Ghana's health service and the US government in which citizen data appeared to be the condition of what had been presented as a free grant; the government declined and cancelled the agreement . She urged governments to scrutinise the fine print of any such offer, asking what is being given in exchange - whether data, sovereignty, or freedom - even when no money changes hands .
Rodriguez agreed but added analytical depth, distinguishing between several types of business models: freemium structures where costs emerge once a usage threshold is reached; time-limited free periods after which payments begin; and covert extraction of data and intellectual property that occurs behind the scenes without the government's awareness . He introduced the concept of the digital twin, warning that if a country's healthcare data were absorbed into a foreign AI model, it would become possible to simulate the strategic impact of an infection or other threat on that country's population - moving data exploitation from a privacy concern into the realm of national security .
Gallo Fall framed this dynamic as "data colonisation," arguing that powerful countries and companies are deliberately building AI models from African data to serve their own strategic advantage . He specifically warned that adversaries are using such data to manipulate elections, and urged African nations to classify their data rigorously and identify crown jewel datasets - including national ID systems, biometric data, and electoral rolls - that must never leave the country . H.E. Benamor invoked the Trojan Horse as a historical analogy, noting that a free gift always warrants careful scrutiny of the giver's motives , and pointed to AICTO's concrete regional policy responses, including the Arab Cybersecurity Strategy of 2023 and the Arab AI Ethics Pact, as mechanisms for translating dialogue into action .
#
Vendor Lock-In and Procurement Control
Rodriguez addressed the question of how governments can achieve genuine digital independence beyond simply switching to a different vendor . He outlined three filters through which governments must assess their sovereignty: first, verifying where data sits - whether on-premises, in a cloud, or in a hybrid configuration ; second, applying the jurisdiction-specific regulation appropriate to the sector in question, whether government, financial, healthcare, or energy ; and third, ensuring operational independence - the ability to continue running operations if a vendor withdraws support, ends a contract, or decides not to provide services . He stressed that during procurement, governments must verify that they are in control of their encryption keys, their data, and their operational destiny .
Veuthey's interactive audience exercise later in the session provided empirical confirmation of the gaps Rodriguez had identified. She asked participants whether they knew which law governed their most critical government data, whether they could terminate a cloud or software provider contract within 30 days, whether they knew who controlled their encryption keys, and whether their government had a policy on staff using public AI tools with sensitive data . The limited number of raised hands across these questions demonstrated that even informed policymakers attending a digital sovereignty session lacked basic awareness of their contractual rights and technical controls. An audience member sharpened the point by noting that the critical issue upon contract termination is not merely whether exit is possible but what happens to the data and what the legal implications are .
#
Post-Quantum Cryptography: An Urgent and Underbudgeted Threat
Rodriguez identified post-quantum cryptography as one of the most urgent and underappreciated threats facing governments . He noted that quantum computing - previously expected to threaten existing cryptography approximately ten years hence - is now projected to arrive within a range of 2030 to 2040, with 2031 cited as a near-term marker, meaning it is already "knocking at the door" . He described as recent news from June the passage of the Quantum Act, representing significant new investment to accelerate quantum computing development, which has further compressed this timeline . The implication is that data currently encrypted using conventional methods could be decrypted by quantum computers within a few years, exposing sensitive government data to foreign actors .
The urgency of this threat was starkly confirmed by the closing audience exercise, in which Veuthey asked participants to raise their hands if post-quantum migration was already budgeted rather than merely discussed . The absence of raised hands illustrated a near-universal gap between awareness and financial preparedness, even among participants at a session dedicated to digital sovereignty . Veuthey noted that while AI has become a familiar topic, post-quantum computing represents a further and less well-understood challenge that governments must begin to address .
#
Audience Exercise and Closing Reflections
The session concluded with a five-question interactive exercise designed to reveal the practical gaps in governments' sovereignty awareness . Veuthey prefaced the exercise by asking who had checked their phone in the last ten minutes, to illustrate that as human beings people are dependent on something, framing the broader context of digital dependency . The exercise then moved through questions on data governance law, contract termination rights, encryption key control, AI use policies, and post-quantum budgeting . The results confirmed the session's central argument: that the primary obstacle to digital sovereignty is not the absence of technical solutions or regulatory frameworks but a fundamental lack of awareness of where governments currently stand .
Veuthey summarised the scoring framework: those who could answer four or five questions affirmatively were largely in control; two or three indicated partial progress; and zero or one indicated significant gaps to close . She emphasised that the purpose of the exercise was not to judge but to motivate, and invited participants to engage with the forthcoming webinar and course on digital sovereignty frameworks being developed in partnership with Smart Africa (SADA) and AICTO .
Thelma Efua Quaye closed by encouraging all participants to scan the QR code and join the Smart Africa Digital Academy (SADA) platform, noting that courses are made and curated specifically for policymakers across Africa, and that the conversations held during the session underscore the importance of building the capacity of decision-makers to make the right choices .
#
Overall Assessment
The session produced a strong degree of alignment across all four panellists on the core themes: sovereignty must be verifiable rather than assumed ; there is no such thing as a free digital infrastructure offer ; capacity building is a foundational prerequisite for moving from owning to running infrastructure ; certain categories of data must never leave a country's borders ; and vendor lock-in poses a fundamental threat to national independence . A notable area of convergence was the view that sovereignty need not mean absolute national control, but rather transparency, informed consent, and selective regional cooperation . The session's most significant institutional outcome was the announcement of the RealTime-AICTO MOU, extending the capacity building partnership that already exists with Smart Africa to the Arab region, and signalling a growing multilateral commitment to translating digital sovereignty principles into practical training and policy frameworks .
Sovereignty requires verifiable control over where data sits, the jurisdiction of service providers, and the routes data transits through - Data location and jurisdiction control
Arg. 1François Rodriguez argues that digital sovereignty begins with knowing where data is physically stored, which jurisdiction governs the service provider, and what third-party software is involved in data transit. These three layers form the foundation of any meaningful sovereignty framework. Without clarity on all three, a country cannot claim genuine control over its digital environment.
He explained that cloud data is not abstract but sits on physical servers somewhere, and the first question is where those servers are located . The second is the jurisdiction of the cloud service provider , and the third is whether data transits through third-party software providers operating under a different jurisdiction, which creates a sovereignty gap .
True sovereignty is not merely a feeling but must be measurable and auditable in practice - Feeling vs. being sovereign
Arg. 2François Rodriguez distinguishes between the subjective sense of being sovereign and the objective, verifiable reality of it. He argues that governments must be able to audit their sovereignty claims rather than simply assume them. This distinction is central to his framing of digital sovereignty as a practical, measurable condition.
He stated that there are two notions: the willingness of feeling sovereign and the reality of really being sovereign in the field . He emphasised that the first dimension of sovereignty is verification - whether a country can really audit that it is truly sovereign .
on: Digital sovereignty requires verifiable, measurable control rather than a mere feeling of being sovereign
on: Definition of digital sovereignty: full data control vs. transparency and informed consent
If a vendor stops providing services or updates, a country's operations can halt entirely, putting national independence at risk - Operational dependency risk
Arg. 3François Rodriguez warns that reliance on a single vendor creates a critical vulnerability: if that vendor withdraws services, stops providing updates, or is subject to geopolitical decisions, the country's entire digital operations may cease. This makes operational independence a core component of digital sovereignty. He frames this as a direct threat to citizens and national functioning.
He cited recent real-world examples of governments having access to certain AI tools switched off , and noted that if a provider stops supporting a country or decides not to provide services, operations stop and citizens are affected . He also referenced the broader question of whether a country is truly in control of its independence and autonomy .
on: Vendor lock-in and operational dependency on external providers represent a fundamental threat to national digital sovereignty
Governments must ask whether they truly control their encryption keys, their data, and their destiny when procuring cloud or digital services - Procurement control checklist
Arg. 4François Rodriguez argues that during procurement, governments must verify that they retain control over encryption keys, data, and operational continuity. He frames this as a checklist of sovereignty conditions that must be satisfied before entering into any digital service agreement. Failing to ask these questions during procurement leads to dependency and loss of sovereignty.
He stated that when doing procurement, governments need to pay attention to whether they are really in control of the keys, in control of their data, and in control of their destiny . He linked this directly to the broader data governance framework he was presenting .
on: Vendor lock-in and operational dependency on external providers represent a fundamental threat to national digital sovereignty
Regulations implemented in one region, such as the EU, may not fit the architecture or needs of other destinations, requiring context-appropriate harmonisation - Regulatory fit and harmonisation
Arg. 5François Rodriguez cautions against simply copying regulatory frameworks from one region and applying them to another without considering whether they are architecturally and contextually appropriate. He uses the EU as an example of a region with strong regulations that may not translate directly to other contexts. He calls for harmonisation that is fit for purpose in each destination.
He noted that Africa has seen implementation of regulations mimicking the EU, which has been at the forefront of strict regulation, but that a balance must be found because the architecture might not fit certain destinations . He used the example of EU-proposed trade corridors that were designed for raw materials but do not reflect today's digital economy routes in agriculture, healthcare, and finance .
on: National control vs. regional cooperation as the primary model for digital governance
Effective data governance requires understanding what data is collected, how it is stored, how it is used, and crucially, what data should be deleted to minimise breach exposure - Data lifecycle management
Arg. 6François Rodriguez presents a data lifecycle framework that covers collection, storage, use, and deletion as the four pillars of effective data governance. He emphasises that data minimisation — deleting data that is no longer needed — is particularly important because it reduces the attack surface in the event of a breach. He also stresses the need to classify data and apply appropriate encryption levels.
He outlined the framework as: understanding what data is collected and ingested, how it is stored with appropriate protection for sensitive data , how it is used in workflows , and what data should be deleted, noting that less stored data means less exposure in case of breaches . He also stressed the need to classify data and apply the right encryption level .
on: Data classification is critical, and certain categories of sensitive data must be protected with the highest levels of control
on: Whether compliance frameworks and certifications are sufficient to establish sovereignty posture
Not all AI queries require cloud processing; more than 50% of AI queries are simple enough to run on-device, meaning governments lose unnecessary control by sending data to cloud AI - On-device AI to reduce data exposure
Arg. 7François Rodriguez argues that governments and organisations are unnecessarily exposing data by routing simple AI queries through cloud-based AI systems when these could be handled on-device. He cites statistics suggesting that more than half of AI queries are simple enough to run locally. This unnecessary cloud dependency compounds sovereignty risks.
He stated that more than 50% of AI queries are simple queries that can be run on-device - such as summarising, translating, and workflow integration - and can be run on a mobile phone . He warned that by dumping all data into cloud AI, users lose control of what they put in the cloud, mirroring the sovereign risks already discussed .
Capacity building programmes delivered through ITU, Smart Africa, and AICTO are designed to help countries understand and implement digital sovereignty frameworks, post-quantum cryptography, and secure government communications - Multilateral capacity building partnerships
Arg. 8François Rodriguez describes a multilateral capacity building effort that has trained more than 50 countries on digital sovereignty, post-quantum cryptography, and secure government communications. He outlines the partnerships formed with ITU, Smart Africa, and the newly announced agreement with AICTO. These programmes aim to translate theoretical frameworks into practical implementation.
He explained that Real Time has been training more than 50 different countries on capacity building covering digital sovereignty, post-quantum transition, and secure government communications . He noted the partnership with Smart Africa and announced the signing of an agreement with the Arab ICT organisation at the session itself .
on: Capacity building is essential for governments to understand, invest in, and effectively operate digital infrastructure
Quantum computing is expected to break existing cryptography by as early as 2030–2031, making migration to post-quantum encryption an urgent priority rather than a distant concern - Quantum timeline urgency
Arg. 9François Rodriguez argues that the threat from quantum computing to existing cryptographic systems is no longer a distant theoretical concern but an imminent one, with timelines now pointing to 2030–2031. He frames this as a door that is already being knocked on, requiring urgent action. Failure to migrate to post-quantum encryption leaves sensitive government data vulnerable to future decryption.
He stated that quantum computing was previously expected to be implemented ten years from now, but the timeline has moved to 2030-2031 at the latest, meaning it is already knocking at the door . He also noted that without post-quantum encryption, foreign adversaries could gain access to unencrypted data .
The Quantum Act represents significant new investment to accelerate quantum computing development, further shortening the window for governments to migrate their cryptographic systems - Quantum Act investment acceleration
Arg. 10François Rodriguez highlights the Quantum Act as a policy and investment signal that quantum computing development is being actively accelerated, which in turn shortens the time governments have to migrate their cryptographic infrastructure. He presents this as a further reason for urgency in post-quantum migration planning. The Act represents a structural shift in the threat landscape.
He referenced the Quantum Act, noting that a lot of investment has been put into quantum computing to accelerate the development of this technology, which will be capable of breaking existing cryptography .
Free offers may involve business models such as freemium thresholds, time-limited free periods, or covert extraction of data and intellectual property that can be used to build strategic AI models of an entire country - business models and IP extraction
Arg. 11François Rodriguez warns that so-called free digital infrastructure offers often conceal business models that extract value in non-monetary ways, including data and intellectual property. He argues that auditability is essential to detect what is being extracted behind the scenes. He raises the alarming possibility that AI models could be built from a country's data to simulate strategic scenarios against that country.
He outlined several business model structures, including freemium models where costs kick in at certain thresholds, and time-limited free periods that eventually convert to paid arrangements . He also warned that data and IP can be extracted covertly, and gave the example of healthcare data being used to build an AI model that could simulate how an infection would affect a country's population, which could be used for strategic or threatening purposes .
on: There is no such thing as a free offer in the digital infrastructure space; costs always exist
Sovereignty means a country's full capability to control its own data - One-sentence definition
Arg. 1H.E. Eng. Mohamed Benamor offers a concise, one-sentence definition of digital sovereignty as the full capability of a country to control its own data. This definition centres sovereignty on data control as the primary measure. It aligns with the broader discussion's emphasis on data as the foundation of digital independence.
When asked for a one-sentence definition, he stated directly that sovereignty means the capability of one country to have full control of their data .
on: Digital sovereignty requires verifiable, measurable control rather than a mere feeling of being sovereign
on: Definition of digital sovereignty: full data control vs. transparency and informed consent
Digital sovereignty and regional cooperation are not mutually exclusive; countries can maintain control over critical infrastructure while voluntarily collaborating on cybersecurity, AI research, interoperability, and shared standards - Balance of national and regional interests
Arg. 2H.E. Eng. Mohamed Benamor argues that the perceived tension between national sovereignty and regional cooperation is a false dichotomy. Countries can retain full control over their critical infrastructure and national policies while choosing to collaborate regionally in areas where collective action adds value. He presents this as a balance rather than a binary choice.
He stated that this is an issue of balance rather than choosing between two opposing positions, and that both full national control and shared regional capabilities are legitimate perspectives . He listed areas where regional collaboration creates greater value, including cybersecurity, AI research, digital public infrastructure, interoperability, capacity building, and shared technical standards .
on: National control vs. regional cooperation as the primary model for digital governance
AICTO's role is to facilitate consensus and provide a multi-stakeholder platform for developing governance frameworks that respect national priorities while advancing common regional values - Regional facilitation role
Arg. 3H.E. Eng. Mohamed Benamor describes AICTO's function not as an advocate for centralisation but as a facilitator of consensus among member states with differing priorities. The organisation provides a platform where governance frameworks and common standards can be jointly developed. This approach is designed to respect national sovereignty while enabling regional solidarity.
He stated that the role of AICTO is not to advocate for centralisation but to facilitate consensus , and that the organisation provides a multi-stakeholder platform where member states can jointly develop governance frameworks, common standards, and trusted cooperation mechanisms that respect national priorities while advancing common values . He also noted that the objective is to strengthen national digital sovereignty through regional solidarity .
on: Capacity building is essential for governments to understand, invest in, and effectively operate digital infrastructure
A free gift should prompt the same caution as the Trojan Horse; regional organisations must translate dialogue into concrete actions such as the Arab Cybersecurity Strategy and the Arab AI Ethics Pact - Trojan Horse analogy and regional action
Arg. 4H.E. Eng. Mohamed Benamor uses the Trojan Horse analogy to caution governments against accepting free digital infrastructure offers without scrutinising the conditions. He then pivots to describe how AICTO translates regional dialogue into concrete policy actions. He presents specific initiatives as evidence of this approach in practice.
He invoked the mythic history of the Trojan Horse to illustrate that a free gift always warrants deeper scrutiny . He then described AICTO's concrete actions, including the Arab Cybersecurity Strategy developed in 2023 and the Arab AI Ethics Pact developed the following year, as examples of translating regional dialogue into action .
on: There is no such thing as a free offer in the digital infrastructure space; costs always exist
Many countries in the Global South have already lost control of their data and digital infrastructure without realising it - Unrecognised loss of control
Arg. 1Gallo Fall argues that a significant number of countries, particularly in the Global South, have already lost meaningful control over their data and digital infrastructure, but are unaware of this because they lack the tools to assess their own sovereignty posture. He distinguishes between cybersecurity as a technical discipline and digital sovereignty as a broader strategic concept. The absence of self-knowledge is itself the core problem.
He noted that cybersecurity focuses on protecting systems from unauthorised access, which is largely a technical discipline, whereas digital sovereignty is a broader strategic concept - a system can be perfectly secure and yet not be under the country's control . He stated that many countries in the Global South have already lost control of their data and digital infrastructure because they do not know where they stand or what their digital sovereignty posture is .
on: Digital sovereignty requires verifiable, measurable control rather than a mere feeling of being sovereign
The digital sovereignty intelligence platform was built to map cybersecurity frameworks against sovereignty pillars and provide governments with KPIs, reports, and recommendations so they know where they currently stand - Sovereignty posture assessment tool
Arg. 2Gallo Fall describes his digital sovereignty intelligence platform as a tool purpose-built for governments, ministries, and critical infrastructure institutions that want to regain strategic control. The platform maps cybersecurity frameworks against sovereignty pillars and generates KPIs, reports, and recommendations. Its primary value is giving governments a clear picture of where they currently stand so they can begin to close gaps.
He described the platform as a continuous unified intelligence ecosystem purpose-built for government ministries and critical infrastructure institutions that refuse to lose strategic control of their data, infrastructure, and AI features . He explained that he built it by mapping all cybersecurity frameworks and different sovereignty pillars, and developed digital tools that provide KPIs, reports, and recommendations to help governments that have already largely lost digital sovereignty .
on: Capacity building is essential for governments to understand, invest in, and effectively operate digital infrastructure
on: Whether compliance frameworks and certifications are sufficient to establish sovereignty posture
Certain categories of data – such as national ID systems, biometric data, and electoral rolls – must never leave a country's borders - Crown jewel data classification
Arg. 3Gallo Fall argues that not all data carries the same strategic risk, and that certain categories — which he calls crown jewels — must be treated as non-negotiable and kept within national borders at all times. He frames this as a matter of national security and democratic integrity. He warns that adversaries are actively targeting this data to manipulate elections and build strategic advantage.
He stated that African nations should start classifying their data and that certain data should never leave the country, specifically naming national ID systems, biometric data, and electoral rolls as examples . He warned that adversaries are currently manipulating elections using such data and that these crown jewels must not leave the country .
on: Data classification is critical, and certain categories of sensitive data must be protected with the highest levels of control
There is a growing thirst for African data, amounting to data colonisation, and adversaries are using such data to manipulate elections and build models that serve their own strategic advantage - Data colonisation risk
Arg. 4Gallo Fall introduces the concept of data colonisation to describe the systematic extraction of African data by powerful external actors for their own strategic benefit. He argues that this is not merely a commercial phenomenon but a geopolitical one, with adversaries using the data to manipulate elections and build AI models that serve their interests. He calls on African nations to be realistic and vigilant about what data they hand over.
He stated that there is a thirst for getting especially African data, which he calls data colonisation, and that powerful countries are building models to manipulate data to their own advantage . He warned that adversaries are manipulating elections using this data and that African nations must be very careful about what they hand to these powerful countries .
on: There is no such thing as a free offer in the digital infrastructure space; costs always exist
Sovereignty for a government should mean transparency and the ability to know what their data is being used for, with the power to say yes or no - Transparency as sovereignty
Arg. 1Thelma Efua Quaye reframes sovereignty not as total isolation or absolute control but as transparency and informed consent over data use. She argues that a government's sovereignty is meaningful when it knows what its data is being used for and retains the power to approve or refuse that use. This is a more pragmatic and achievable definition than full national control.
She stated that in today's world, total isolation is not realistic, and that for her, sovereignty for a government should be transparency and the ability to know where their data is and what it is being used for, with the ability to say no or yes .
on: Definition of digital sovereignty: full data control vs. transparency and informed consent
A country can own infrastructure but fail to run it effectively if there is no government investment, no understanding of its strategic importance, and no stimulated market demand - Owning vs. running infrastructure
Arg. 2Thelma Efua Quaye draws on her experience as a CTO to illustrate that ownership of infrastructure does not automatically translate into effective operation. She identifies three root causes of failure: lack of government investment, lack of understanding of the infrastructure's strategic importance, and absence of market demand. She uses a real-world example of a national backbone with below 10% utilisation to make the point concrete.
She recounted her experience running a network where the country owned the infrastructure but utilisation was below 10%, maintenance was poor, and no one responded to service calls . She attributed this to the government not investing because it did not understand why it should, particularly when the private sector was already running a backbone . She also noted that sovereign data centres built in several countries had low utilisation because the investment was driven by the feeling of sovereignty rather than actual market demand .
on: Digital sovereignty requires verifiable, measurable control rather than a mere feeling of being sovereign
The three steps to move from owning to running infrastructure are: understanding and investment, capacity building, and stimulating market demand - Three-step transition framework
Arg. 3Thelma Efua Quaye proposes a three-step framework for governments to transition from merely owning digital infrastructure to actively and effectively running it. The steps are: first, understanding the strategic importance of the infrastructure so that investment follows; second, building the capacity of people to operate it; and third, stimulating market demand to ensure the infrastructure is actually used. She presents these as sequential and interdependent.
She outlined the three steps explicitly: understanding the importance of the infrastructure so that investment is made , capacity building to enable operation , and stimulating market demand through mechanisms such as startups and AI factories . She summarised these as the three things a government should do to move from owning to running infrastructure .
on: Capacity building is essential for governments to understand, invest in, and effectively operate digital infrastructure
There is no such thing as a free offer; if a government is not paying with money, it is likely paying with data, sovereignty, or strategic freedom - Nothing is free
Arg. 4Thelma Efua Quaye argues that any offer of free digital infrastructure must be treated with deep scepticism because the cost is always present, even if not monetary. She frames this as a fundamental principle: if you are not the one eating, you are probably being eaten. Governments must identify what they are giving up in exchange for the apparent gift.
She stated plainly that she does not believe there is anything free, and that if you are not the one eating, you are probably being eaten . She then asked governments to consider what they are giving in exchange - whether it is data, sovereignty, or freedom - even if no money changes hands .
on: There is no such thing as a free offer in the digital infrastructure space; costs always exist
Governments must scrutinise the fine print of any free offer, as illustrated by Ghana's cancellation of a health data agreement with the US government when citizen data was identified as the cost - Fine print and citizen data
Arg. 5Thelma Efua Quaye uses a concrete recent example from Ghana to illustrate the importance of reading the fine print of any free digital offer. In this case, a grant from the US government to Ghana's health service appeared free but required citizen data as the cost, leading Ghana to cancel the agreement. She presents this as a model of the kind of scrutiny all governments should apply.
She described a recent situation in Ghana involving the health service and the US government, where a grant was offered for free but the catch was citizen data . The Ghanaian government identified this condition and cancelled the agreement . She used this as an example of the fine print that governments need to look at carefully .
Governments often do not know whether they can switch or terminate a cloud or software provider contract within 30 days, or what happens to their data if they do - Contractual awareness gap
Arg. 1Maryna Veuthey uses an interactive audience exercise to highlight a critical awareness gap: most governments and officials do not know the contractual terms governing their cloud or software provider relationships, including whether they can terminate within 30 days and what the legal implications for their data would be. This lack of awareness is itself a sovereignty risk. She frames it as a practical test of whether sovereignty is real or merely assumed.
During the audience exercise, she asked participants to raise their hands if they could switch or terminate a cloud or software provider contract within 30 days and know what happens to their data and the legal implications . The exercise was designed to reveal how few officials actually know the answer to this question, illustrating the contractual awareness gap in practice .
on: Vendor lock-in and operational dependency on external providers represent a fundamental threat to national digital sovereignty
Post-quantum migration is rarely budgeted by governments and remains at the discussion stage, representing a critical gap given the approaching timeline - Budgeting gap for post-quantum migration
Arg. 2Maryna Veuthey uses the audience exercise to reveal that post-quantum migration is not yet being budgeted by governments, despite the urgency of the timeline discussed earlier in the session. She contrasts the widespread discussion of AI with the relative neglect of post-quantum preparedness. She frames post-quantum as the next major challenge that governments are not yet taking seriously in financial planning terms.
During the exercise, she asked participants to raise their hands if post-quantum migration was already budgeted and not just discussed , and anticipated that there would be no hands raised . She noted that while AI is everywhere and people are getting used to it, post-quantum is another animal that has yet to be addressed in budgeting .
When terminating a contract with a cloud or software provider, the key question is not just whether you can terminate but what happens to the data and what the legal implications are - Data retrieval and legal implications upon contract termination
Arg. 1An audience member intervenes during the interactive exercise to clarify and sharpen the question being posed, pointing out that the critical issue is not merely whether a contract can be terminated but what legal rights a government retains over its data after termination. This contribution highlights that contractual awareness must extend beyond exit clauses to encompass data retrieval rights and legal consequences. It underscores the complexity of vendor relationships that governments often overlook.
During the audience exercise, a participant echoed and reinforced the moderator's question by restating it: if you can terminate the contract, what happens to the data and what are the legal implications .
on: Vendor lock-in and operational dependency on external providers represent a fundamental threat to national digital sovereignty
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
All panellists agreed that digital sovereignty is not a passive or assumed state but one that must be actively verified and measured. François Rodriguez explicitly distinguished between 'the willingness of feeling sovereign and the reality of really being sovereign in the field' , emphasising that the first dimension of sovereignty is verification - whether a country can audit that it is truly sovereign . Gallo Fall reinforced this by noting that many countries in the Global South have already lost control without realising it, because they do not know their digital sovereignty posture . Thelma Efua Quaye illustrated this with her experience of a country owning infrastructure with below 10% utilisation , and H.E. Eng. Mohamed Benamor defined sovereignty concisely as 'the capability of one country to have full control of their data' .
True sovereignty is not merely a feeling but must be measurable and auditable in practice - Feeling vs. being sovereign
Many countries in the Global South have already lost control of their data and digital infrastructure without realising it - Unrecognised loss of control
A country can own infrastructure but fail to run it effectively if there is no government investment, no understanding of its strategic importance, and no stimulated market demand - Owning vs. running infrastructure
Sovereignty means a country's full capability to control its own data - One-sentence definition
All four panellists converged strongly on the principle that no digital infrastructure offer is genuinely free. Thelma Efua Quaye stated plainly that 'if you are not the one eating, you are probably being eaten' , and used the concrete example of Ghana cancelling a health data agreement with the US government when citizen data was identified as the cost . François Rodriguez elaborated on the business model structures, including freemium thresholds and covert extraction of data and intellectual property , warning that healthcare data could be used to build AI models capable of simulating strategic threats against a country . Gallo Fall framed this as 'data colonisation', warning that powerful countries are building models to manipulate African data to their own advantage . H.E. Eng. Mohamed Benamor invoked the Trojan Horse analogy, stating that 'when you get a free gift you need to think twice about why this free gift' .
There is no such thing as a free offer; if a government is not paying with money, it is likely paying with data, sovereignty, or strategic freedom - Nothing is free
Free offers may involve business models such as freemium thresholds, time-limited free periods, or covert extraction of data and intellectual property that can be used to build strategic AI models of an entire country - business models and IP extraction
There is a growing thirst for African data, amounting to data colonisation, and adversaries are using such data to manipulate elections and build models that serve their own strategic advantage - Data colonisation risk
A free gift should prompt the same caution as the Trojan Horse; regional organisations must translate dialogue into concrete actions such as the Arab Cybersecurity Strategy and the Arab AI Ethics Pact - Trojan Horse analogy and regional action
All panellists agreed that capacity building is a foundational prerequisite for meaningful digital sovereignty. François Rodriguez described training more than 50 countries on digital sovereignty, post-quantum cryptography, and secure government communications through partnerships with ITU, Smart Africa, and the newly announced AICTO agreement . Thelma Efua Quaye outlined a three-step framework - understanding and investment, capacity building, and stimulating market demand - as the path from owning to running infrastructure , noting that sovereign data centres had low utilisation because investment was driven by the feeling of sovereignty rather than actual understanding . H.E. Eng. Mohamed Benamor described AICTO's role in making capacity building programmes and technical assistance available to member states . Gallo Fall's platform itself serves as a capacity-building tool, providing KPIs and recommendations to help governments understand where they stand .
Capacity building programmes delivered through ITU, Smart Africa, and AICTO are designed to help countries understand and implement digital sovereignty frameworks, post-quantum cryptography, and secure government communications - Multilateral capacity building partnerships
The three steps to move from owning to running infrastructure are: understanding and investment, capacity building, and stimulating market demand - Three-step transition framework
AICTO's role is to facilitate consensus and provide a multi-stakeholder platform for developing governance frameworks that respect national priorities while advancing common regional values - Regional facilitation role
The digital sovereignty intelligence platform was built to map cybersecurity frameworks against sovereignty pillars and provide governments with KPIs, reports, and recommendations so they know where they currently stand - Sovereignty posture assessment tool
Both François Rodriguez and Gallo Fall emphasised that not all data carries the same risk and that governments must classify data and apply appropriate protections. François Rodriguez outlined a data lifecycle framework covering collection, storage, use, and deletion, stressing that data minimisation reduces breach exposure and that the right encryption level must be applied to data that needs protection . Gallo Fall went further, identifying specific categories - national ID systems, biometric data, and electoral rolls - as 'crown jewels' that must never leave a country's borders , warning that adversaries are actively targeting this data to manipulate elections .
Effective data governance requires understanding what data is collected, how it is stored, how it is used, and crucially, what data should be deleted to minimise breach exposure - Data lifecycle management
Certain categories of data – such as national ID systems, biometric data, and electoral rolls – must never leave a country's borders - Crown jewel data classification
François Rodriguez, Maryna Veuthey, and an audience member all converged on the danger of vendor lock-in. François Rodriguez cited real-world examples of governments having access to AI tools switched off , and warned that if a provider stops supporting a country or decides not to provide services, operations stop and citizens are affected . He also stressed that during procurement, governments must verify they are in control of the keys, data, and destiny . Maryna Veuthey's interactive exercise revealed that most officials do not know whether they can terminate a cloud or software provider contract within 30 days and what happens to their data . An audience member sharpened this point by restating that the critical issue is what happens to the data and what the legal implications are upon termination .
If a vendor stops providing services or updates, a country's operations can halt entirely, putting national independence at risk - Operational dependency risk
Governments must ask whether they truly control their encryption keys, their data, and their destiny when procuring cloud or digital services - Procurement control checklist
Governments often do not know whether they can switch or terminate a cloud or software provider contract within 30 days, or what happens to their data if they do - Contractual awareness gap
When terminating a contract with a cloud or software provider, the key question is not just whether you can terminate but what happens to the data and what the legal implications are - Data retrieval and legal implications upon contract termination
Both H.E. Eng. Mohamed Benamor and Thelma Efua Quaye shared a pragmatic, non-absolutist view of digital sovereignty that rejects total isolation in favour of informed cooperation and transparency. H.E. Eng. Mohamed Benamor argued that digital sovereignty and regional cooperation can reinforce one another, with countries retaining control over critical infrastructure while voluntarily collaborating on cybersecurity, AI research, and shared standards . Thelma Efua Quaye similarly stated that total isolation is not realistic in today's world, and that sovereignty for a government should mean transparency and the ability to know what their data is being used for, with the power to say yes or no . Both speakers thus reframed sovereignty as a condition of informed consent and selective cooperation rather than absolute control. Both François Rodriguez and Gallo Fall emphasised that digital sovereignty is a technical and strategic condition that must be actively verified, and that many governments are unaware of how much control they have already lost. François Rodriguez stressed that sovereignty begins with knowing where data is physically stored, which jurisdiction governs the service provider, and what third-party software is involved , and that the first dimension of sovereignty is the ability to audit it . Gallo Fall reinforced this by distinguishing cybersecurity as a technical discipline from digital sovereignty as a broader strategic concept, noting that a system can be perfectly secure and yet not be under the country's control , and that many countries in the Global South do not know their digital sovereignty posture . Both François Rodriguez and Thelma Efua Quaye highlighted the gap between formal or structural adoption of digital frameworks and their effective, contextually appropriate implementation. François Rodriguez cautioned against simply copying EU regulatory frameworks and applying them to other contexts without considering architectural fit , using the example of EU trade corridors designed for raw materials that do not reflect today's digital economy routes . Thelma Efua Quaye illustrated the same gap from an infrastructure perspective, recounting how countries invested in sovereign data centres driven by the feeling of sovereignty rather than actual market demand, resulting in low utilisation . Both speakers thus converged on the idea that form without function — whether regulatory or infrastructural — does not constitute genuine sovereignty. François Rodriguez, Gallo Fall, and Thelma Efua Quaye all shared the view that the flow of data to external actors — whether through cloud AI, data colonisation, or conditions in free offers — represents a structural sovereignty risk that governments must actively resist. François Rodriguez warned that routing simple AI queries through cloud systems unnecessarily exposes data , and that cloud dependency mirrors the sovereign risks already discussed. Gallo Fall introduced the concept of data colonisation, arguing that powerful countries are building AI models from African data to serve their own strategic advantage . Thelma Efua Quaye grounded this in a concrete example, describing how Ghana cancelled a health data agreement when citizen data was identified as the cost of a free grant . All three thus converged on the need for governments to scrutinise and limit the outward flow of data.
It might have been expected that a session on digital sovereignty would produce strong advocacy for maximum national control and independence. Instead, a notable consensus emerged across speakers from different backgrounds - a regional policy organisation leader, a digital infrastructure skills officer, and a cybersecurity capacity building expert - that total sovereignty is neither achievable nor desirable. Thelma Efua Quaye explicitly stated that total isolation is not realistic and reframed sovereignty as transparency and the ability to say yes or no to data use . H.E. Eng. Mohamed Benamor argued that digital sovereignty and regional cooperation reinforce one another, and that both full national control and shared regional capabilities are legitimate perspectives . François Rodriguez cautioned against blindly mimicking EU regulations without considering contextual fit . This convergence on a nuanced, cooperative definition of sovereignty - rather than an absolutist one - was unexpected given the session's framing around independence and control.
While post-quantum cryptography was not the central focus of the session, there was a striking consensus between François Rodriguez and Maryna Veuthey - confirmed by the audience exercise - that this issue is both urgently important and almost entirely neglected in government budgeting. François Rodriguez stated that quantum computing was previously expected to be ten years away but is now projected for 2030-2031, meaning it is 'already knocking at the door' , and that the Quantum Act has accelerated investment in this technology . Maryna Veuthey's audience exercise revealed that no participants had post-quantum migration already budgeted rather than merely discussed . The unexpected element is that despite the urgency articulated by the technical expert, the audience exercise confirmed a near-universal gap in financial preparedness, suggesting that even informed policymakers attending a digital sovereignty session had not yet translated awareness into action.
Across the session, speakers from technical, policy, regional, and moderation perspectives all converged on the unexpected finding that the primary obstacle to digital sovereignty is not a lack of technical tools or regulatory frameworks but a fundamental lack of awareness. Gallo Fall noted that countries in the Global South have already lost control without realising it, because they do not know their digital sovereignty posture . Thelma Efua Quaye attributed infrastructure underperformance to governments not understanding why investment was needed . Maryna Veuthey's audience exercise demonstrated that even participants at a digital sovereignty session could not answer basic questions about their contractual rights or encryption key control . François Rodriguez framed this as the gap between feeling sovereign and being sovereign . The consensus that awareness - rather than resources or technology - is the binding constraint was unexpected and has significant implications for how capacity building programmes should be designed and prioritised.
The session produced a high degree of consensus across all four panellists and the moderator on the core themes of digital sovereignty. All speakers agreed that: (1) sovereignty must be verifiable and measurable rather than assumed; (2) there is no such thing as a free digital infrastructure offer, with costs always present in the form of data, intellectual property, or strategic leverage; (3) capacity building is a foundational prerequisite for governments to move from owning to running digital infrastructure; (4) data classification is essential, with certain categories of data - such as biometrics, national IDs, and electoral rolls - requiring the highest levels of protection; and (5) vendor lock-in and operational dependency on external providers represent a fundamental threat to national sovereignty. A notable area of unexpected consensus was the pragmatic redefinition of sovereignty away from absolute national control toward transparency, informed consent, and selective regional cooperation. The audience exercise further confirmed consensus on the gap between awareness and action, particularly regarding contractual rights and post-quantum migration budgeting .
H.E. Eng. Mohamed Benamor defined sovereignty as 'the capability of one country to have full control of their data' , implying a maximalist, absolute conception of control. Thelma Efua Quaye explicitly challenged this framing, stating that total isolation is not realistic in today's world and that sovereignty should instead mean 'transparency and ability to know where their data is, or what their data is being used for, and having the ability to say no or yes' . François Rodriguez offered a third angle, framing sovereignty as something that must be verifiable and auditable rather than merely felt , which sits between the other two positions - acknowledging that full control is the goal but that measurability is the operative test. These three framings reflect a genuine definitional disagreement about whether sovereignty is an absolute condition, a pragmatic transparency standard, or an auditable operational state.
Sovereignty means a country's full capability to control its own data - One-sentence definition
Sovereignty for a government should mean transparency and the ability to know what their data is being used for, with the power to say yes or no - Transparency as sovereignty
True sovereignty is not merely a feeling but must be measurable and auditable in practice - Feeling vs. being sovereign
H.E. Eng. Mohamed Benamor argued that digital sovereignty and regional cooperation are mutually reinforcing, and that countries should voluntarily collaborate on areas such as cybersecurity, AI research, and shared technical standards while retaining control over critical infrastructure . He presented AICTO's role as facilitating this consensus . François Rodriguez, by contrast, cautioned that regional regulatory harmonisation - particularly the tendency to mimic EU frameworks - may not fit the architectural and contextual realities of other destinations . He used the example of EU trade corridors designed for raw materials that do not reflect today's digital economy routes in agriculture, healthcare, and finance . While both speakers support some form of regional engagement, Rodriguez's emphasis on the risks of misapplied harmonisation implicitly questions the ease of the cooperative model Benamor advocates.
Digital sovereignty and regional cooperation are not mutually exclusive; countries can maintain control over critical infrastructure while voluntarily collaborating on cybersecurity, AI research, interoperability, and shared standards - Balance of national and regional interests
Regulations implemented in one region, such as the EU, may not fit the architecture or needs of other destinations, requiring context-appropriate harmonisation - Regulatory fit and harmonisation
Gallo Fall explicitly stated that compliance frameworks give governments 'a checklist that just gives you a certification certificate' but do not tell them what is actually happening currently . He argued that his platform goes beyond compliance to provide real-time situational awareness of sovereignty posture . François Rodriguez, while also emphasising practical data governance, framed his approach around implementing a data lifecycle framework - collection, storage, use, and deletion - as the operative blueprint . The disagreement is subtle but real: Fall sees existing compliance frameworks as fundamentally insufficient and potentially misleading, whereas Rodriguez treats data governance frameworks as the starting blueprint, implying they have more foundational value. Fall's position is more sceptical of the framework-as-solution approach that Rodriguez's presentation implicitly endorses.
The digital sovereignty intelligence platform was built to map cybersecurity frameworks against sovereignty pillars and provide governments with KPIs, reports, and recommendations so they know where they currently stand - Sovereignty posture assessment tool
Effective data governance requires understanding what data is collected, how it is stored, how it is used, and crucially, what data should be deleted to minimise breach exposure - Data lifecycle management
This disagreement was unexpected given that both speakers were participating in a collaborative session broadly aligned on the importance of digital sovereignty. H.E. Eng. Mohamed Benamor's one-sentence definition - 'the capability of one country to have full control of their data' - implies a maximalist conception that could be read as endorsing full national control. Thelma Efua Quaye directly challenged this direction, stating that 'a lot of them at this moment, when you talk about sovereign, for them it's just me' and that she 'completely disagreed because I don't think in this world we can be totally isolated' . She reframed sovereignty as transparency and the ability to say yes or no to data use . This was unexpected because Benamor had earlier argued that sovereignty and regional cooperation are not mutually exclusive , yet his definitional statement implied a more absolutist position that Quaye felt compelled to explicitly push back against. The disagreement surfaced a genuine tension between aspirational definitions and pragmatic operational realities.
This disagreement was unexpected because both speakers were presenting aligned positions on the importance of data governance and sovereignty frameworks. However, Gallo Fall made a pointed critique of compliance frameworks, stating that 'compliance is a checklist that just gives you a certification certificate' and that his platform instead tells governments 'what's happening currently' so they can mitigate gaps . This implicitly critiques the kind of framework-based approach that François Rodriguez had presented as a blueprint earlier in the session . Rodriguez's presentation treated data governance frameworks as foundational tools for sovereignty , whereas Fall's argument suggests that relying on such frameworks may give governments a false sense of security. The disagreement was not made explicit between the two speakers but emerges clearly from comparing their positions, making it an unexpected undercurrent in an otherwise harmonious discussion.
The discussion was characterised by a high degree of surface-level consensus on the importance of digital sovereignty, the risks of vendor lock-in, the dangers of free infrastructure offers, and the need for capacity building. However, meaningful disagreements emerged in three areas: (1) the definition of sovereignty itself, with Benamor favouring full data control , Quaye favouring transparency and informed consent , and Rodriguez emphasising auditability ; (2) the appropriate level of governance - national procurement controls versus regional policy frameworks - with Rodriguez focusing on technical and contractual mechanisms and Benamor on regional consensus-building ; and (3) the value of compliance frameworks, with Fall arguing they provide false assurance while Rodriguez treated them as useful blueprints . The interactive audience exercise conducted by Maryna Veuthey further revealed a practical disagreement between what governments believe they control and what they actually control, particularly regarding contract termination rights and post-quantum budgeting .
All four speakers agreed that free offers of digital infrastructure should be treated with deep scepticism and that costs are always present. Thelma Efua Quaye stated plainly that 'there is nothing free' and that 'if you are not the one eating, you are probably being eaten' , using Ghana's cancelled health data agreement with the US government as a concrete example . François Rodriguez agreed but added analytical depth, distinguishing between freemium business models, time-limited free periods, and covert extraction of data and intellectual property , and warning that AI models could be built from a country's data to simulate strategic scenarios against it . Gallo Fall framed this as 'data colonisation' and warned that adversaries are using African data to manipulate elections . H.E. Eng. Mohamed Benamor invoked the Trojan Horse analogy . However, the speakers differed in emphasis: Quaye focused on citizen data and informed consent , Rodriguez on IP and AI model extraction , Fall on geopolitical manipulation , and Benamor on the need for concrete regional policy responses . They agreed on the problem but offered different framings of its most dangerous dimension.
There is no such thing as a free offer; if a government is not paying with money, it is likely paying with data, sovereignty, or strategic freedom - Nothing is free Free offers may involve business models such as freemium thresholds, time-limited free periods, or covert extraction of data and intellectual property that can be used to build strategic AI models of an entire country - business models and IP extraction There is a growing thirst for African data, amounting to data colonisation, and adversaries are using such data to manipulate elections and build models that serve their own strategic advantage - Data colonisation risk A free gift should prompt the same caution as the Trojan Horse; regional organisations must translate dialogue into concrete actions such as the Arab Cybersecurity Strategy and the Arab AI Ethics Pact - Trojan Horse analogy and regional action
All three speakers agreed that the primary barrier to effective digital sovereignty is not the absence of infrastructure or frameworks but the absence of understanding and awareness. Gallo Fall argued that countries in the Global South have already lost control 'because they don't know actually where they stand' . Thelma Efua Quaye illustrated this with her experience of a national backbone running at below 10% utilisation because the government did not understand why it should invest , and noted that sovereign data centres were built based on 'the feeling of sovereignty' rather than actual market demand . François Rodriguez framed capacity building as the mechanism to close this gap, citing training delivered to more than 50 countries . However, they differed on the solution: Fall emphasised real-time posture assessment tools , Quaye proposed a three-step framework of understanding, investment, and market stimulation , and Rodriguez focused on multilateral training partnerships . They agreed on the diagnosis but offered different prescriptions.
A country can own infrastructure but fail to run it effectively if there is no government investment, no understanding of its strategic importance, and no stimulated market demand - Owning vs. running infrastructure Capacity building programmes delivered through ITU, Smart Africa, and AICTO are designed to help countries understand and implement digital sovereignty frameworks, post-quantum cryptography, and secure government communications - Multilateral capacity building partnerships Many countries in the Global South have already lost control of their data and digital infrastructure without realising it - Unrecognised loss of control
Both Rodriguez and Benamor agreed that governments must retain meaningful control over their digital environments and that institutional frameworks — whether procurement checklists or regional governance platforms — are the mechanism to achieve this. Rodriguez argued that during procurement, governments must verify control over encryption keys, data, and operational continuity , while Benamor described AICTO as providing a platform where member states can jointly develop governance frameworks and common standards that respect national priorities . Both agreed on the goal of preserving national control, but differed on the level at which this is best achieved: Rodriguez focused on the technical and contractual level of individual government procurement , while Benamor emphasised the regional governance level as the appropriate arena for building sovereignty . This reflects a tension between bottom-up technical sovereignty and top-down regional policy coordination.
Governments must ask whether they truly control their encryption keys, their data, and their destiny when procuring cloud or digital services - Procurement control checklist AICTO's role is to facilitate consensus and provide a multi-stakeholder platform for developing governance frameworks that respect national priorities while advancing common regional values - Regional facilitation role
- Digital sovereignty requires verifiable, auditable control over where data sits, the jurisdiction of service providers, and the routes through which data transits — it is not merely a feeling but must be measurable in practice.
- Sovereignty, in its simplest form, means a country's full capability to control its own data, with transparency about how that data is used and the power to say yes or no to its use.
- Many countries in the Global South have already lost control of their data and digital infrastructure without realising it, largely because they do not know their current digital sovereignty posture.
- Vendor lock-in poses a critical national risk: if a vendor stops providing services or updates, a country's operations can halt entirely, threatening national independence.
- Governments must scrutinise procurement contracts to confirm they control their encryption keys, their data, and their ability to exit contracts — many do not know whether they can switch providers within 30 days or what happens to their data if they do.
- Digital sovereignty and regional cooperation are not mutually exclusive; countries can maintain control over critical infrastructure while voluntarily collaborating on cybersecurity, AI research, interoperability, and shared standards.
- Regulations from one region, such as the EU, may not be architecturally or contextually appropriate for other destinations, requiring context-sensitive harmonisation rather than direct replication.
- Effective data governance requires managing the full data lifecycle — collection, storage, use, and deletion — and classifying data appropriately, with certain categories such as national ID systems, biometric data, and electoral rolls never permitted to leave a country's borders.
- More than 50% of AI queries are simple enough to run on-device, meaning governments unnecessarily surrender data control by routing queries to cloud AI systems.
- A country can own digital infrastructure but fail to run it effectively without government investment, strategic understanding, and stimulated market demand — the three steps to transition from owning to running are: understanding and investment, capacity building, and market stimulation.
- There is no such thing as a free offer of digital infrastructure; if a government is not paying with money, it is likely paying with data, sovereignty, or strategic freedom, as illustrated by Ghana's cancellation of a health data agreement when citizen data was identified as the cost.
- Free offers may conceal business models including freemium thresholds, time-limited free periods, or covert extraction of data and intellectual property that can be used to build strategic AI models of an entire country.
- There is a growing and deliberate thirst for African data, amounting to data colonisation, with adversaries using such data to manipulate elections and build models that serve their own strategic advantage.
- Quantum computing is expected to break existing cryptography by as early as 2030–2031, making migration to post-quantum encryption an urgent priority; the Quantum Act represents significant new investment accelerating this timeline.
- Post-quantum migration is rarely budgeted by governments and remains at the discussion stage, representing a critical and dangerous gap given the approaching timeline.
- Capacity building — delivered through partnerships with ITU, Smart Africa (SADA), and AICTO — is essential for helping countries understand and implement digital sovereignty frameworks, post-quantum cryptography, and secure government communications.
- A digital sovereignty intelligence platform that maps cybersecurity frameworks against sovereignty pillars and provides governments with KPIs, reports, and recommendations can help governments understand where they currently stand and where to begin closing gaps.
“There's two notions between the willingness of feeling sovereign and the reality of really being sovereign in the field.”
“If your provider is switching off, if your provider is not providing updates, are you able to continuously run your operations? Because if operation stops, your country stops to work and your citizens are not happy.”
“Cybersecurity focuses on protecting systems from unauthorised access, disruption or destruction — which is largely a technical discipline. Then digital sovereignty is a broadly strategic concept. A system can be perfectly secure — but do you control it?”
“A lot of countries in the south have already lost control of their data and digital infrastructure because they don't know actually where they stand — they don't know their digital sovereignty posture.”
“Sovereignty for a government should be transparency and the ability to know where their data is and what their data is being used for — and having the ability to say no or yes. That should be the sovereignty.”
“If you are not the one eating, you are probably being eaten. There is nothing free — and if it is free, what am I giving? Is it my data? Is it my sovereignty? Is it my freedom?”
“We are now moving into leveraging data for strategic posture — it can be for benefits, but it can also be for threats. Imagine that the whole healthcare data had been sucked into an AI model from another country. You can replicate a simulation of what an infection could affect that country based on the data of its citizens.”
“There is a thirst for getting especially African data — what I call data colonisation. We have to be very careful about what we hand to these powerful countries because they are actually building models pretty much to manipulate the data to their own advantage.”
“Digital sovereignty and regional cooperation can reinforce one another. Countries should retain control over their critical infrastructure, data, and national policies while voluntarily collaborating on areas where regional action creates greater value.”
“Quantum computing was expected to be implemented 10 years from now — we are now talking about 2030 to 2031. It is knocking at the door already.”
How can governments truly verify and audit their digital sovereignty rather than merely feeling sovereign?
François highlighted the gap between the willingness to feel sovereign and actually being sovereign in practice. This distinction is critical because governments may believe they are in control of their data and infrastructure without having the mechanisms to verify it, leaving them vulnerable to data leakage, foreign jurisdiction issues, and vendor dependency.
How can governments effectively control hyperscalers and large cloud service providers within their regulatory frameworks?
François raised this as an open question during the discussion on harmonising global AI and digital regulations. Given the immense power and reach of hyperscalers, it remains unclear how national or regional regulations can meaningfully constrain them, making this a pressing area for further policy research.
How should regional digital sovereignty frameworks be balanced against full national control, particularly for smaller or resource-constrained states?
Maryna posed this directly to H.E. Benamor, and while he provided a high-level answer about consensus-building, the practical mechanisms for achieving this balance remain underexplored. Further research is needed into governance models that allow shared regional capabilities without compromising national sovereignty.
What specific data categories should governments in the Global South prioritise for protection and never allow to leave their borders?
Gallo mentioned national ID systems, biometric data, and election rolls as crown jewels that should never leave a country, but a comprehensive, research-backed taxonomy of critical data categories for developing nations has not been established. This is an important area for further study to guide policy and data classification frameworks.
How can governments in the Global South identify and assess their current digital sovereignty posture when they are largely unaware of where they stand?
Gallo noted that many countries have already lost control of their data and digital infrastructure without realising it. Maryna echoed this by stating that not knowing where you are is the main cause of the problem. Further research into standardised assessment tools and methodologies for measuring digital sovereignty posture is needed.
What business models underpin 'free' infrastructure or service offers from foreign vendors, and how can governments identify costs such as data extraction or intellectual property transfer?
All panellists touched on the dangers of accepting free infrastructure offers, with examples including data colonisation and the Trojan Horse analogy. However, there is a need for further research into frameworks that help governments systematically identify and evaluate the true costs and risks embedded in such arrangements, including premium model traps, auditability gaps, and AI model training on national data.
How can governments stimulate domestic demand and market development to ensure that sovereign digital infrastructure, once built, is actually utilised?
Thelma highlighted that many countries have invested in sovereign data centres with very low utilisation rates because the market was not developed alongside the infrastructure. Further research into policy mechanisms, such as government procurement mandates, startup ecosystems, and AI factories, that can stimulate demand is essential to making sovereign infrastructure investments viable.
What is the current state of post-quantum cryptography migration planning and budgeting across governments, and what steps are needed to accelerate readiness before 2030–2031?
François noted that quantum computing capable of breaking existing cryptography is expected by 2030–2031, and the audience exercise revealed that no hands were raised when asked whether post-quantum migration was already budgeted. This represents a significant and urgent gap requiring further research into migration roadmaps, cost frameworks, and international cooperation mechanisms.
How can global AI and digital regulations be harmonised without imposing frameworks that are ill-suited to the specific economic, infrastructural, and developmental contexts of different regions?
François pointed out that regulations such as those from the EU may not be directly applicable to other regions, using the example of trade corridor mismatches. Further research is needed into how international regulatory harmonisation efforts, such as the AI dialogue in Geneva, can be made more inclusive and context-sensitive for regions like Africa and the Arab world.
How can governments develop and enforce policies governing staff use of public AI tools with sensitive data, and what compliance mechanisms are effective?
During the audience exercise, Maryna asked whether governments had policies on staff using public AI tools with sensitive data. The limited response suggested this is a widely neglected area. Further research into policy design, enforcement mechanisms, and awareness programmes for public sector AI use is needed.
How can the risk of 'data colonisation' through AI model training on African or Global South data be measured, regulated, and mitigated?
Gallo introduced the concept of data colonisation, warning that powerful nations and companies are harvesting data from the Global South to build AI models that serve their own strategic interests, including potential election manipulation. This is an emerging and underresearched area that requires both technical and geopolitical investigation.
What are the legal and contractual implications for governments when terminating cloud or software provider contracts, particularly regarding data retrieval and portability?
During the audience exercise, Maryna and an audience member raised the question of what happens to government data when a contract is terminated, including legal implications and data portability rights. This is a critical but often overlooked area of digital sovereignty that warrants further legal and policy research.
Who controls the encryption keys for government data stored with third-party providers, and how can governments reclaim or verify this control?
Maryna raised this during the audience exercise, and the limited response indicated that many governments do not know whether they or their vendors control their encryption keys. Further research into key management frameworks, contractual requirements, and technical standards for government data encryption is needed.
How can the concept of digital sovereignty be operationalised beyond a feeling of control into measurable, auditable, and enforceable standards?
Multiple speakers distinguished between feeling sovereign and being sovereign, and Gallo's platform attempts to address this through KPIs and reporting. However, there is no universally agreed set of measurable standards for digital sovereignty. Further research into internationally recognised metrics, audit frameworks, and certification mechanisms would be highly valuable.
