WSIS Forum 2026
AI-generated report

Operationalizing Digital Sovereignty: The African Blueprint

6 speakers
Summary

This discussion brought together panellists from RealTyme, the Arab ICT Organization (AICTO), Smart Africa, and Talisman Cybersecurity to explore digital sovereignty, data governance, and the emerging challenges of post-quantum cryptography .

François Rodriguez (RealTyme) opened by distinguishing between the feeling of being digitally sovereign and the reality of achieving it, highlighting three key dimensions: verifying where data is stored, understanding the jurisdiction of cloud service providers, and ensuring regulatory compliance . He warned that governments risk losing operational independence if they rely on vendors who can withdraw services unilaterally , and stressed the urgency of transitioning to post-quantum encryption, noting that quantum computing capable of breaking current cryptography may arrive as early as 2030-2031 .

H.E. Mohamed Benamor of AICTO argued that digital sovereignty is not a binary choice between national control and regional cooperation, but rather a balance between the two . He described AICTO's role as facilitating consensus and enabling member states to collaborate on cybersecurity, AI research, and shared standards while preserving national decision-making . Gallo Fall added that many countries in the Global South have already lost control of their digital infrastructure without realising it, and that his platform was built to map sovereignty posture and provide actionable recommendations .

Thelma Efua Quaye emphasised that owning infrastructure is insufficient without investment, understanding, and market stimulation, drawing on her experience of a national backbone operating at below 10% utilisation (less than one-tenth of the network's total data-carrying capacity is actually being used) . She and other panellists agreed that no offer of free infrastructure should be accepted without scrutiny, as data, sovereignty, or strategic leverage are invariably the cost .

The session concluded with an audience exercise revealing significant gaps in governments' awareness of data governance laws, vendor contract terms, encryption key control, and post-quantum readiness , underscoring the critical role of capacity building programmes offered through platforms such as Smart Africa Digital Academy and ITU Academy .

Keypoints
  • Overall Purpose

  • The discussion aims to raise awareness of digital sovereignty, data governance, post-quantum cryptography, and capacity-building among governments - particularly in the Global South and Arab regions. The session seeks to help policymakers understand the gap between 'feeling' sovereign and 'being' sovereign, and to promote practical frameworks, training programmes, and regional cooperation to close that gap.
  • --
  • Major Discussion Points

  • Defining and measuring digital sovereignty: François Rodriguez outlined that true digital sovereignty requires three verifiable layers - knowing where data physically resides, understanding the jurisdiction of the cloud or service provider, and ensuring data does not transit through uncontrolled third-party systems. He emphasised the critical distinction between the 'feeling' of sovereignty and its reality. H.E. Mohamed Benamor reinforced this by defining sovereignty simply as "the capability of one country to have full control of its data." - Vendor dependency and the risks of 'free' infrastructure offers: Panellists warned strongly against vendor lock-in and the dangers of accepting infrastructure built and run by foreign entities at no apparent cost. François Rodriguez added that, beyond data, intellectual property, and AI model training data can be silently extracted, enabling foreign actors to build strategic simulations of a country's population. Gallo Fall spoke of data colonisation, urging nations to classify and protect crown-jewel data such as national ID systems, biometrics, and election rolls. - The gap between owning and running digital infrastructure: Thelma Efua Quaye drew on her experience as a CTO to illustrate that a country can own infrastructure yet fail to utilise or maintain it effectively, often because governments do not understand its strategic importance and therefore do not invest in it. She identified three steps to move from ownership to operational control: understanding the importance of the infrastructure, investing in capacity building, and stimulating market demand to ensure utilisation. - Post-quantum cryptography as an urgent, underbudgeted threat: François Rodriguez highlighted that quantum computing - previously expected to threaten existing encryption by 2040 - is now anticipated as early as 2031, making the migration to post-quantum cryptography an immediate priority. The audience exercise at the end of the session revealed that virtually no hands were raised when asked whether post-quantum migration was already budgeted, underscoring the gap between awareness and action. - Regional cooperation and capacity building as enablers of sovereignty: H.E. Mohamed Benamor explained that AICTO's role is not to advocate for centralisation but to facilitate consensus, helping member states collaborate on cybersecurity, AI research, interoperability, and shared standards while preserving national decision-making authority. The session also announced a new MOU between RealTime and AICTO, complementing existing partnerships with Smart Africa, to expand capacity building programmes across the Arab region and Africa.
  • --
  • Overall Tone

  • The tone throughout the discussion is informative, collaborative, and gently cautionary. The moderator, Maryna Veuthey, maintains an upbeat and engaging register, using humour and interactive exercises to keep the audience involved. The panellists are measured and constructive rather than alarmist, though moments of urgency emerge - particularly when discussing data colonisation , the risks of "free" infrastructure , and the imminence of quantum threats . The tone shifts slightly towards the end, becoming more motivational and action-oriented as the session closes with calls to join training platforms and upcoming webinars. Overall, the discussion balances realism about current vulnerabilities with optimism about the tools, frameworks, and partnerships available to address them.
Speakers Overview
FR
François Rodriguez
135 wpm · 12 min
HE
H.E. Eng. Mohamed Benamor
96 wpm · 4 min
GF
Gallo Fall
138 wpm · 4 min
TE
Thelma Efua Quaye
138 wpm · 6 min
MV
Maryna Veuthey
123 wpm · 19 min
A
Audience
902 wpm · 1 s

Expanded Summary: Digital Sovereignty, Data Governance, and Post-Quantum Cryptography

#

Session Overview and Introductions

The session, moderated by Maryna Veuthey, brought together four panellists to explore the interconnected themes of digital sovereignty, data governance, cybersecurity, and post-quantum cryptography . The panel comprised François Rodriguez of RealTime, H.E. Eng. Mohamed Benamor, Secretary General of the Arab ICT Organisation (AICTO), joining remotely ; Thelma Efua Quaye, Digital Infrastructure Skills Empowerment Officer of Smart Africa ; and Gallo Fall, founder and CTO of Talisman Cybersecurity . Veuthey framed the session as interactive, promising audience participation and a practical exercise alongside the panel discussion . A significant institutional development was announced during the session: RealTime signed a new Memorandum of Understanding (MOU) with AICTO, complementing its existing partnerships - including a prior collaboration with the GFC and its current partnership with Smart Africa - to extend capacity building programmes across the Arab region .

#

Setting the Context: From Feeling Sovereign to Being Sovereign

François Rodriguez opened the substantive discussion by drawing on RealTime's experience as a capacity building partner of the ITU, having trained more than 50 different countries on digital sovereignty, post-quantum cryptography, and secure government communications . He immediately established the session's central intellectual tension: the distinction between the willingness to feel sovereign and the reality of actually being sovereign in the field . This framing set the tone for the entire discussion, challenging the assumption that signing agreements or owning infrastructure automatically confers genuine sovereignty.

Rodriguez outlined three verifiable dimensions of digital sovereignty. The first is auditability - whether a government can genuinely verify that it is sovereign . The second concerns data location and jurisdiction: where data physically resides, whether it sits within the country's borders, and what jurisdiction governs the cloud service provider . The third dimension addresses the routes through which data transits, including whether third-party software providers operate under the same jurisdiction as the government, and whether gaps between these jurisdictions create vulnerabilities . He cited a recent, unspecified instance in which governments had access to certain AI tools switched off by providers, warning that if a vendor stops providing services or updates, a country's operations can halt entirely, directly affecting citizens .

#

Data Governance as the Foundation of Sovereignty

Rodriguez presented data governance as the foundational layer upon which all other sovereignty measures depend . He outlined a data lifecycle framework covering four stages: understanding what data is collected and ingested into digital environments; determining how it is stored and protected according to sensitivity; managing how it is used in day-to-day workflows; and, critically, deciding what data should be deleted . He emphasised that data minimisation - reducing the volume of data stored - directly limits exposure in the event of a breach . Appropriate encryption must then be applied to data requiring protection, which connects directly to the urgency of transitioning to post-quantum cryptography .

Rodriguez also raised the question of AI data governance, noting that more than 50% of AI queries are sufficiently simple to be processed on-device - through summarisation, translation, and workflow integration - without routing data to cloud AI systems . He argued that unnecessarily sending data to cloud AI mirrors the broader sovereignty risks already identified: once data enters the cloud, control over it is effectively surrendered . This point reinforced the session's broader argument that sovereignty is not merely a regulatory or contractual matter but a series of daily operational choices.

#

Regulatory Harmonisation and the Limits of Borrowed Frameworks

Rodriguez also addressed the challenge of regulatory harmonisation, noting that African countries have increasingly sought to implement regulations modelled on EU frameworks . While acknowledging the EU's leadership in strict digital regulation, he cautioned that architectural and contextual fit must be considered, as regulations designed for one destination may not serve the needs of another . He used the example of EU trade corridors originally designed for raw materials, which bear little resemblance to today's digital economy routes in agriculture, healthcare, and finance . He noted that the ongoing AI dialogue in Geneva is attempting to harmonise global regulations, but questioned whether such harmonisation can realistically constrain hyperscalers providing services across multiple jurisdictions .

#

AICTO's Perspective: Sovereignty Through Regional Solidarity

H.E. Eng. Mohamed Benamor offered a regional governance perspective, arguing that digital sovereignty should not be framed as a binary choice between full national control and shared regional capabilities . He described AICTO's role not as advocating for centralisation but as facilitating consensus among member states , enabling them to collaborate voluntarily on areas where regional action creates greater value - including cybersecurity, AI research, digital public infrastructure, interoperability, capacity building, and shared technical standards - while retaining control over critical infrastructure and national policies . He described AICTO as providing a multi-stakeholder platform for jointly developing governance frameworks and trusted cooperation mechanisms that respect national priorities while advancing common regional values , with the ultimate objective of strengthening national digital sovereignty through regional solidarity .

When asked for a one-sentence definition of sovereignty, Benamor stated simply that it is "the capability of one country to have full control of their data" . This maximalist definition was later complemented by other panellists who offered more operationally nuanced perspectives, creating one of the session's more productive definitional exchanges.

#

The Technical Reality: Many Countries Have Already Lost Control

Gallo Fall introduced a sobering perspective, drawing a precise conceptual distinction between cybersecurity and digital sovereignty. He described cybersecurity as a largely technical discipline focused on protecting systems from unauthorised access, disruption, or destruction, whereas digital sovereignty is a broader strategic concept: a system can be perfectly secure and yet not be under the country's control . This distinction is critical because it prevents governments from conflating technical security measures with genuine strategic autonomy.

Fall explained that his digital sovereignty intelligence platform at Talisman Cybersecurity was built out of personal conviction, having witnessed widespread cyber attacks in the Global South as a native of Senegal . The platform functions as a continuous unified intelligence ecosystem, purpose-built for government ministries, critical infrastructure institutions, and others that refuse to cede strategic control of their data, infrastructure, and AI capabilities . It maps cybersecurity frameworks against sovereignty pillars and provides KPIs, reports, and recommendations to help governments understand where they currently stand . His central finding was stark: many countries in the Global South have already lost control of their data and digital infrastructure without realising it, because they do not know their digital sovereignty posture . This observation directly reinforced Rodriguez's earlier distinction between feeling and being sovereign, and prompted Veuthey to identify ignorance - not malice or technical failure - as the primary cause of sovereignty loss .

Fall also drew an explicit distinction between compliance frameworks and genuine sovereignty assessment, arguing that compliance gives governments "a checklist that just gives you a certification certificate" but does not tell them what is actually happening in real time . His platform, by contrast, is designed to provide situational awareness so that governments know where to start addressing their gaps .

#

From Owning to Running: The Capacity Building Imperative

Thelma Efua Quaye approached the question of sovereignty from the perspective of infrastructure utilisation and capacity building, drawing on her experience as a former CTO who managed a backbone infrastructure connecting critical areas . She recounted that utilisation of the infrastructure was below 10%, and that maintenance and service were poor, because the government did not understand the strategic importance of the asset and therefore did not invest in it . This experience served as a concrete illustration of the gap between owning infrastructure and being able to run it effectively.

Quaye identified three steps necessary to transition from ownership to operational control . The first is understanding: governments must comprehend why investment in digital infrastructure matters before they will commit resources to it, and this is precisely where capacity building programmes play their role . The second is investment itself, which follows from understanding . The third is stimulating market demand to ensure that infrastructure, once built, is actually utilised . She noted that several countries had invested in sovereign data centres driven by the feeling of sovereignty rather than actual market need, resulting in low utilisation - a direct echo of the feeling-versus-being distinction established earlier in the session . She suggested that governments can stimulate demand through mechanisms such as startups and AI factories, though the precise context of the latter was not fully elaborated in the transcript .

Quaye also offered a perspective on sovereignty that provided a more operationally achievable standard, particularly for developing nations. She argued that total isolation is not realistic in today's world, and that sovereignty for a government should mean transparency and the ability to know what their data is being used for, with the power to say yes or no . This framing - sovereignty as informed consent rather than absolute control - offered a practically meaningful standard for countries that cannot realistically build fully independent digital ecosystems.

#

The Dangers of "Free" Infrastructure Offers

The panel converged strongly on the question of whether governments should accept offers of free digital infrastructure from foreign vendors or governments. Veuthey posed a hypothetical scenario in which a country or vendor offered to build and run an entire national infrastructure from A to Z at no cost, inviting panellists to think through the implications before accepting .

Quaye responded with characteristic directness, stating that there is nothing free and that "if you are not the one eating, you are probably being eaten" . She grounded this principle in a concrete example, citing a situation involving Ghana's health service and the US government in which citizen data appeared to be the condition of what had been presented as a free grant; the government declined and cancelled the agreement . She urged governments to scrutinise the fine print of any such offer, asking what is being given in exchange - whether data, sovereignty, or freedom - even when no money changes hands .

Rodriguez agreed but added analytical depth, distinguishing between several types of business models: freemium structures where costs emerge once a usage threshold is reached; time-limited free periods after which payments begin; and covert extraction of data and intellectual property that occurs behind the scenes without the government's awareness . He introduced the concept of the digital twin, warning that if a country's healthcare data were absorbed into a foreign AI model, it would become possible to simulate the strategic impact of an infection or other threat on that country's population - moving data exploitation from a privacy concern into the realm of national security .

Gallo Fall framed this dynamic as "data colonisation," arguing that powerful countries and companies are deliberately building AI models from African data to serve their own strategic advantage . He specifically warned that adversaries are using such data to manipulate elections, and urged African nations to classify their data rigorously and identify crown jewel datasets - including national ID systems, biometric data, and electoral rolls - that must never leave the country . H.E. Benamor invoked the Trojan Horse as a historical analogy, noting that a free gift always warrants careful scrutiny of the giver's motives , and pointed to AICTO's concrete regional policy responses, including the Arab Cybersecurity Strategy of 2023 and the Arab AI Ethics Pact, as mechanisms for translating dialogue into action .

#

Vendor Lock-In and Procurement Control

Rodriguez addressed the question of how governments can achieve genuine digital independence beyond simply switching to a different vendor . He outlined three filters through which governments must assess their sovereignty: first, verifying where data sits - whether on-premises, in a cloud, or in a hybrid configuration ; second, applying the jurisdiction-specific regulation appropriate to the sector in question, whether government, financial, healthcare, or energy ; and third, ensuring operational independence - the ability to continue running operations if a vendor withdraws support, ends a contract, or decides not to provide services . He stressed that during procurement, governments must verify that they are in control of their encryption keys, their data, and their operational destiny .

Veuthey's interactive audience exercise later in the session provided empirical confirmation of the gaps Rodriguez had identified. She asked participants whether they knew which law governed their most critical government data, whether they could terminate a cloud or software provider contract within 30 days, whether they knew who controlled their encryption keys, and whether their government had a policy on staff using public AI tools with sensitive data . The limited number of raised hands across these questions demonstrated that even informed policymakers attending a digital sovereignty session lacked basic awareness of their contractual rights and technical controls. An audience member sharpened the point by noting that the critical issue upon contract termination is not merely whether exit is possible but what happens to the data and what the legal implications are .

#

Post-Quantum Cryptography: An Urgent and Underbudgeted Threat

Rodriguez identified post-quantum cryptography as one of the most urgent and underappreciated threats facing governments . He noted that quantum computing - previously expected to threaten existing cryptography approximately ten years hence - is now projected to arrive within a range of 2030 to 2040, with 2031 cited as a near-term marker, meaning it is already "knocking at the door" . He described as recent news from June the passage of the Quantum Act, representing significant new investment to accelerate quantum computing development, which has further compressed this timeline . The implication is that data currently encrypted using conventional methods could be decrypted by quantum computers within a few years, exposing sensitive government data to foreign actors .

The urgency of this threat was starkly confirmed by the closing audience exercise, in which Veuthey asked participants to raise their hands if post-quantum migration was already budgeted rather than merely discussed . The absence of raised hands illustrated a near-universal gap between awareness and financial preparedness, even among participants at a session dedicated to digital sovereignty . Veuthey noted that while AI has become a familiar topic, post-quantum computing represents a further and less well-understood challenge that governments must begin to address .

#

Audience Exercise and Closing Reflections

The session concluded with a five-question interactive exercise designed to reveal the practical gaps in governments' sovereignty awareness . Veuthey prefaced the exercise by asking who had checked their phone in the last ten minutes, to illustrate that as human beings people are dependent on something, framing the broader context of digital dependency . The exercise then moved through questions on data governance law, contract termination rights, encryption key control, AI use policies, and post-quantum budgeting . The results confirmed the session's central argument: that the primary obstacle to digital sovereignty is not the absence of technical solutions or regulatory frameworks but a fundamental lack of awareness of where governments currently stand .

Veuthey summarised the scoring framework: those who could answer four or five questions affirmatively were largely in control; two or three indicated partial progress; and zero or one indicated significant gaps to close . She emphasised that the purpose of the exercise was not to judge but to motivate, and invited participants to engage with the forthcoming webinar and course on digital sovereignty frameworks being developed in partnership with Smart Africa (SADA) and AICTO .

Thelma Efua Quaye closed by encouraging all participants to scan the QR code and join the Smart Africa Digital Academy (SADA) platform, noting that courses are made and curated specifically for policymakers across Africa, and that the conversations held during the session underscore the importance of building the capacity of decision-makers to make the right choices .

#

Overall Assessment

The session produced a strong degree of alignment across all four panellists on the core themes: sovereignty must be verifiable rather than assumed ; there is no such thing as a free digital infrastructure offer ; capacity building is a foundational prerequisite for moving from owning to running infrastructure ; certain categories of data must never leave a country's borders ; and vendor lock-in poses a fundamental threat to national independence . A notable area of convergence was the view that sovereignty need not mean absolute national control, but rather transparency, informed consent, and selective regional cooperation . The session's most significant institutional outcome was the announcement of the RealTime-AICTO MOU, extending the capacity building partnership that already exists with Smart Africa to the Arab region, and signalling a growing multilateral commitment to translating digital sovereignty principles into practical training and policy frameworks .

Maryna Veuthey
And just before we start, it will be an interactive session. And at the end, we're going to also have amazing panelists, some tricky questions. So be ready. And then we're going to also have a little activity with you guys, with the audience. And I hope that you can also hear me well. For everyone who is joining online, thank you so much for being here. So I will be your moderator today. My name is Marina, with Y. Quite exotic, but here we go. So today we will be talking about architecture, digital autonomy. And actually, we will be tackling some also tricky topics that no one is out, I think. And it would be around... What is that? What is that? So we'll actually tackle it today. So let me also present our amazing panelists today. So Mr. Francois Rodriguez, which is in the middle. Hi. Also, we have His Excellency Mohammed Ben Amour, who is joining us online. Hello. Can you hear us?
H.E. Eng. Mohamed Benamor
Yes, I'm hearing you very well. Thank you.
Maryna Veuthey
Perfect. Thank you so much for joining. We also have Ms. Thelma, the Digital Infrastructure Skills Empowerment Officer of Smart Africa. It's been a pleasure to see you here today. And Mr. Gawafal, founder and CTO of Talisman Cybersecurity. Thank you so much for being with us today. So I cannot just pass the mic. We all have mics here. But I will pass the word to my colleague, Francois, who will do in a quick. interest of today thank you the four is yours mike is yours françois
François Rodriguez
thank you so thank you marina for this introduction so let's uh spice up a little bit the topic with some context and then the idea is to have some questions to the panelists so the journey started as one of the capacity building partner of itu so we are real time and we've been training more than 50 different countries on capacity it builds you know the topic of today which is uh you know what digital digital sovereignty really means uh the transition into the post -quantum arena as well as you know implementing secure communications in the government space so this is how the journey started and the idea is to give you some snippet of what we deliver in these uh trainings to set up the the context so the the first one is really prominence and digital sovereignty frameworks, how basically you implement those and the reality on the field happens. So there's two notions between the willingness of feeling sovereign and the reality of really being sovereign in the field. So very quickly, not theoretical, but the first dimension is really the verification of it. So can you really audit that you are really sovereign? This is the first thing. It all started with the framework with the jurisdiction where you use your data sitting. Is it in country? And the third layer is the regulation out of it. So implementing the regulation in the country to make sure that you prevent this data leakage and the jurisdiction basically So I think that's the first And then the of the data traveling outside the perimeter of your country. So it all started with, you know, this spread of clouds. So people think that, you know, cloud data is sitting out there, but in fact cloud is somewhere else's service, right? So your data is somewhere, not in the cloud. So where those servers are sitting are basically the first question to ask. The second is the jurisdiction of the service provider of that cloud infrastructure. And third, basically where the data is transiting through. Are you using, you know, third -party software? If yes, those providers are sitting in the same jurisdiction of you or not, and this is the gap of the two that you need to pay attention to. So some traps have been happening in the news recently. Recently, some government have turned off, you know, the access to certain, you know, AI Table 5. This has really happened recently, but this is also... are you in control of your independence so are you autonomous so if your provider is switching off if your provider is not providing updates are you able to continuously run your operations because if operation stops your country stops to work and your citizens are not happy so the independence is really at stake in that point so harmonizing as well especially when we talk about implementation of the regulations so we've seen for instance in Africa implementation of certain regulations mimicking or trying to identify the similarities between EU EU has been really at the front of implementing very strict regulations. So I think we need to find also a balance out of fit because the architecture might not fit with certain destinations. So a quick example here of a comment, but the EU proposed corridors at the time were basically minerals and materials, raw materials were important and not the same routes of today, right, with the digital economy, the agriculture, the healthcare, the financial sector are basically using different routes. So you need to as well pay attention of the implementation of those regulations that are really fitting the purpose of the destiny that applies to it. the harmonization is also something that is up in the air at the moment so you've got this ai dialogue happening right now in geneva so the idea is to harmonize those global regulations but can you really control those hyperscalers that are providing the services this is the other question so when you do the procurement we've been hearing in different sessions you need to pay attention to certain you are really in control of the keys you are control of your data you are in control of your destiny this is what we are promoting here um so it all starts with data governance because without data this ai world and digital world doesn't really work and one of the framework because the idea is to show you some blueprints this is the topic of the session okay one of the interesting blueprints to start with is basically what is the data that you are collecting ingesting in your environments and digital economy then more important, okay, because and how do you store? Because you need to protect certain sensitive data. Certain data is public, so therefore you give access. Some data is just for internal use only. And then how you use it, how you propel this data into your day -to -day workflows operations. And more importantly, because at RealTime we are very sensitive to data minimization, is what data do you delete? Because the less data you are storing in case of breaches. So therefore you need to classify that data accordingly and make sure that you apply the right encryption level into the data that needs to be protected out of it. And this is one of the key points of transitioning now into post -quantum cryptography, which is resistant to quantum computing, right? Otherwise it's you have this potential of, you know, foreign advisors getting access to that data that is not encrypted and therefore accessible area. The data that is also these days put into the AI framework is also one of the topics that we are putting in motion in this capacity building trainings, is that not every data needs to be nurturing the cloud AI. So there is a lot of AI and some stats are reflecting that more than 50 % of AI queries are just simple queries that you can run on AGI, meaning on the device that are summarizing, translating workflows integration into the workspace that can be run. mobile phone where dumping all the the data in the cloud ai basically you lose control of what you put in the cloud the same as you know the sovereign aspect that we just touched on so that's um some of the important dimension that we are putting together and another news that came you know in june as well recently is the quantum act basically a lot of investment have been put now in quantum computing to accelerate the development of this technology that will to break the existing cryptography um so the third and last topic that we've been training the different countries on is the migration in post quantum encryption for the same reason that we've just been explaining so quantum was expected to be implemented 10 years from now we're talking now of 2030 2040 2031 the latest so he's knocking the door already and we've been putting all this capacity building through different platforms as we explained we started with propelling the GFC more recently we signed an agreement with smart Africa and we're gonna announce as well the basically signature of today with the Arab ICT organization that's the announcement of today so thank you for welcoming us in that journey and that's the reason that we've got mr. Ben Amour with us.
Maryna Veuthey
Super efficient 12 minutes puff so so which is very nice so we're gonna have more time for the questions and also to questions to your speakers and panelists and then more time for the exercise and your questions as well. So thank you so much, Francois. So what I see from actually in a quick overview, right, that you gave the context is that we have also four speakers today. We also have four particular angles, if we can say, the original policies and regulations. We also have a capacity building as well as cybersecurity, right? So that then leads to the questions there, right? Some of them were shared in the previous before the session. Some of them not. So let's get started then. So Francois, quick question to you. You were not expecting this, right? You were talking for. Twelve minutes and then you thought that I'm going to move to someone else. But no. So during this session and also the sessions that we attended. as well topics about the sovereignty also the dependency but i just have any quick question to you how does a government sell a real digital independence apart from just signing with a different vendor so can you just spend a little bit more on that?
François Rodriguez
Yeah thank you marina for the question so um the uh it goes through the filters that we've just been through right so do you really have um the control where the data is uh sitting in in basically in a cloud is it sitting on premises is an hybrid setup so that's the first measure so you need to have control of those implementations the second is you can you really apply the jurisdiction, the regulation that is applicable for that specific environment? Is it government? Is it financial sector? Is it healthcare? Is it energy? So you need to as well apply the regulation that is specific to those verticals. And the third is the independency that we just mentioned before. Can you really operate? Basically, that vendor is not supporting you anymore or you're out of contract or out of support. Or, as we've seen, this vendor is deciding not to provide service to you
Maryna Veuthey
So thank you so much. So actually, it's how to avoid a vendor lock -in, right? So what questions we need to ask ourselves. So the next question will be for as we move, right, through your actually layer. I will address definitely to His Excellency Mohammed Ben Amour. You're here with us today. Thank you so much. The Secretary General of AICTO. Because, first of all, I was talking also about one of the layers, which is regulations. And normally, we say that regulations is the base, right? So let's then challenge it with you. Are you ready? So I hope so. So some member states want to kind of have a shared one, right? Due to maybe some territories issues or even budgeting stuff. So others want to have a full national control. How actually does AICTO get them to agree?
H.E. Eng. Mohamed Benamor
Thank you, Marina, for this good question. Happy to join you. Thank you real time for this MOU that we signed remotely. And as an answer, I will say that as a regional organization, Arab ICT organization addresses ICT challenge through regional convergence folks. For this question, I think that this is an issue of balance rather than choosing between two opposing countries prioritize full national control over their digital infrastructure. While others recognize the benefits of shared regional capabilities, we consider both perspectives as legitimate. The role of ICT is not to advocate for centralization. But we trust and facilitate consensus. We believe that digital sovereignty and regional cooperation can reinforce one another. Countries should receive and control over their critical infrastructure, data, and national policies while voluntarily collaborating on areas where regional action creates greater value, such as cybersecurity, AI research, digital public infrastructure, interoperability, capacity building, and shared technical standards. Arab ICT organization provides a nurtured multi -stakeholder platform where member states can jointly develop governance frameworks, common standards, and trusted cooperation mechanisms that respect national priorities while advancing common values. ultimately our objective is simple to strengthen national digital sovereignty through regional solidarity ensuring that every country benefits from collective expertise while maintaining its sovereignty decision making
Maryna Veuthey
thank you thank you so much for this full answer but i have one more question to you so yeah i know that i'm asking too many questions but this is kind of my goal for today and my job so if we talk about also the sovereignty it's one sentence what does it mean for you actually and also for your organization
H.E. Eng. Mohamed Benamor
thank you yes sovereignty means that this is the capability of one country have the full control of their data
Maryna Veuthey
Thank you so much so we we will be then switching to um topics about and around the control that right because that's something that i hear pretty often when we talk about sovereignty and um also through the capacity building exercises that we are doing and the trainings that we are delivering normally uh what we hear sovereignty is control right but um totally agree with that by the way but i think that nowadays it's really hard to balance this control and have a full control right so uh let's maybe then switch to uh some technical questions and we have an expert for that here today with us who's gonna help us also understand what are the limits of the control right from the technical perspective so today we have Gala Fall, founder and CTO of TALIS. Before I ask a question, actually we have a very nice story together, a better together story. So how we actually met, it was through the training and also the course via the ITU Academy. And that's also a good, I think, example of how capacity building activities and sharing knowledge, connecting people, right? We are not lucky. I don't know if I can say it. Sorry for that. Also connecting people, right? So quick question to you then. Actually, you've built a platform that are addressing the sovereignty question, right? And the question of control. Yeah. and my question would be platform right so government don't lose their control of their data right so this is the main goal of your platform what does a government typically not realize it's already lost control of?
Gallo Fall
lost control of it so tricky question yes it is a tricky question hello yes so thank you for the privilege of your time and I built like the digital sovereignty intelligence platform which is like a continuous unified continuous intelligence ecosystem purpose built for government ministries critical infrastructure institution that refuse to see their strategy control of their data infrastructure and AI features so this comes like out of conviction because myself like I'm a native of Senegal and I you know witness like a lot of cyber attack happening like in the global south so I build like the tool so that you know like by background in cyber security and cyber security focuses on protecting like system from unauthorized access disruption or destruction so which is largely a technical discipline then digital sovereignty is broadly strategic concept is perfectly secure do you control it and I noticed that like a lot of countries in the south they already lost control of their data and digital infrastructure because they don't know actually where they stand up they don't know their digital sovereignty posture And with this tool, I built it by mapping all the cybersecurity framework and the different sovereignty pillars. And I developed digital tools that provide KPI and report and recommendations to help these
Maryna Veuthey
governments that already lost pretty much digital sovereignty. So you scare people, right? So you're kind of like, whoa, you already lost it. So, well, the reality, right, is that digital sovereignty is actually a huge topic and super, super complex, right? But what I'm hearing is that actually the main problem comes from not knowing. Right. And I think that's. that's the main cause right we don't know where we are what do we then when we don't know where we are we don't know where we're going to do or where we're going to go what's what's going to happen next
Gallo Fall
yes you know like the frameworks tells you like what to do so your compliance is a checklist that just give you a certification certificate but what this platform does it tells you like what's happening currently okay so that you can really use it in order to mitigate like your gaps in terms of digital sovereignty and have like exactly so from where to start i think that's the main
Maryna Veuthey
The main point so where we are right now so um and what i hear from it is that not knowing where we are causes the main the main issue and for that i think that we can address um um also one question to miss tama right as the person who is actually yeah sure so to know better of where we are at right we need to have in a bit and also have this awareness right and then that's where this capacity building comes in so um i would ask you in a quick question a country can own the infrastructure right as francois explained right as galo also explained we can have the frameworks right um but a country can have the infrastructure but still not be able to run it right so we are coming from we don't know where we are okay we know where we are so how we persist further so the question would be um what does it actually take to close this gap to know how we can run it and how we can move forward
Thelma Efua Quaye
So your question is taking me back to, I don't know, maybe 10 years ago when I was running a network. I was a CTO, and the country owned an infrastructure, which can be comparable to what we are talking about now. But now, first of all, utilization was below 10%. Utilization was below 10%. For the 10% of traffic that they have, the maintenance and the service was terrible. Like you would call and you would not get anyone. So I'm just reflecting on it and reflecting on your question. And thinking what went wrong. so what I think happened was there was no investment from the government because it was not a priority and it was not a priority because the government did not understand why okay if private sector is running a backbone why should I invest in investment for instance so there was no investment but also there was no understanding of the impact of this because this was a backbone that was connecting very critical areas right again allow me to use this because I think it's very contextual to you know what we are we are saying even in the AI infrastructure that we are talking about and so how a country would move from just you said owning to running yes would be the first is you know to understand it so that you can invest understand the importance of it why do we need to invest in investment why do we need to invest in cloud as a country or serving cloud why do we need to invest in the country. And that is where, you know, our capacity building comes in, where we build their capacity for them to understand. And I do appreciate, you know, the four angles that you take them through. We are getting quite a lot of good feedback and looking forward to the next webinar later this month, right? Yeah. So it's important that they understand because a lot of them at this moment, when you talk about sovereign, for them it's just me, which has been described as completely disagreed because I don't think in this world we can be totally isolated. For me, control for a government would be transparency or sovereignty for a government should be transparency and ability to know where their data, or what their data is being used for. and having the ability to say no or yes. That should be the sovereignty. So back to how they go to run in its capacity building, for sure, investment, but also making sure that the demand exists. Four years ago, we did a tour for data centers. How can we bring about or facilitate regional data centers? And for all the countries that we went to, they had invested in what they call sovereign data centers, but utilization was low because they first went by the investment or the need to be sovereign, which goes to your point of feeling versus being. It was more a feeling to invest in the infrastructure. They invested in it, but there was no market. right so the third point would be the need to ensure the market and there's there are so many ways governments can stimulate markets right and through startups by often at we are doing now with what we call the AI factories there are so many ways to stimulate So these are the three things I think a government should do. Investment, capacity building, stimulating the market. That would take them from just owning to running the infrastructure.
Maryna Veuthey
Thank you so much, Thelma. That was really nice and very wise, by the way. That's why I really love to have women on the panel. So because advertisements are too straightforward, women get this carried approach, right? So not kind of unaware and only after care. It's more about the care. So thank you so much, Thelma, for that. And so as we are running close to small activity, right, I have one final question for you. So give me a moment, please. So. Let's imagine that a country or a vendor or any kind of out -of -the -country service or provider or whatever offered to build and run from A to Z an infrastructure or a country for free. And think through before accepting it. So Thelma please.
Thelma Efua Quaye
I can think. So, first of all, I don't believe there's anything free. That was a catch, right? There's nothing free because if you are not the one eating, you are probably being eaten. So, what the government should look through, and I like... I'd like to give an example of... something recently that happened in Ghana between Ghana, the health service and the US government where the US but the catch, so grant is free right? but the catch there was citizen data and the government said no and they cancelled it so these are the fine prints that governments need to look at first of all you need to understand there's nothing free and then you should understand that there's nothing free, what am I giving? Is it my data? Is it my sovereignty? Is it my freedom? Even if you are not giving money so it's important that governments understand what is being given and it comes back again to capacity building, they need to understand that really there's nothing right? They need to understand that data is a super mind and so if somebody comes to you to say I'll build for free sovereign data center for free ask them what is the data they are taking yes, nothing is for free at this work, right and scratch my back, I'll scratch yours and all this
Maryna Veuthey
nothing is for free at this work, right and scratch my back, I'll scratch yours and all this business stuff, whatever right, so thank you so much Telna, Francois
François Rodriguez
the floor is yours tell me though I wanted to add to what Telna just was saying, so nothing is for free for sure, but there is a business model, right, so the business model needs to be understood if it's, you know, free what I'm giving in a premium model where basically I start free, but if I basically reach a certain threshold I start in paying or is it, you know, free for a certain period and then, you know after three years or five years I start paying, so you need to understand as well what is at stake, so that's the first point The second thing is auditability. So can I audit what I'm giving? Because sometimes people are thinking it's free, but in fact everything has been pumped behind the scenes. It can be data, but it can be also IP. And these days in the AI world, we're talking about digital twin. I don't know if people are at certain points who have been given so much data that AI models can really run the same basically data sets of the whole country. Imagine that the whole healthcare data had been sucked into the AI model from ABC country, let's say Switzerland. You can replicate basically a simulation of what an infection can affect or could affect Switzerland based on the data of the citizens. So we are basically now moving into leveraging data for strategic posture, can be for benefits. but can be also for threats.
Maryna Veuthey
Exactly. So, Tata is a new oil and it has AI for good. Everything should be for good in the ideal world. But we are living in a wild world. So, thank you so much, Francois. By the way, I need to say that normally when Francois is replying to my questions, he scares me a lot. But that's not today. I kind of get used to it. It should be fine. So, Mr. Gallo, tell me, what do you think about it?
Gallo Fall
Yes, we have my… Like something especially in the global south, they have to be careful with the relationship with like the big hyperscaler or any companies that is willing to use those. You know, like if a country is telling you that I'm going to build a sovereign data center, but you need to ask like a lot of questions. What does it entail? I think that's the thing. and who controls it, who owns the data because right now there is a thirst of getting especially African data, what I call data colonization and we have to be very careful about what we hand to these powerful countries because they are actually building models pretty much to manipulate the data to their own advantage so that's why we just don't want to be subject but we have to be very realistic and make that we hand, you have to really think through it and also make sure that African nations they should start classifying their data there are certain data that you should never let leave your country things like your national ID system, your biometrics data your election rolls and you have to be very realistic about what you are saying and you have to be very realistic about what you are saying and you have to be very realistic about what I mean, all these right now, like you have like adversaries, like manipulating election to really put them in the crown jewel, leave the country.
Maryna Veuthey
Thank you so much for that. So, actually, yeah, stop being just a consumer, be a regulator, right? So, a big screen somewhere. So, thank you so much for that. And just the same question would be for His Excellency Mohammed Ben Amour.
H.E. Eng. Mohamed Benamor
Thank you. The same question, yes. Let me make the first one. It's about the question that you asked to tell me about the free gift. And this has made me thinking about the Trojan. This is... mythic history of Greek and when you get a free gift you need to think twice about why this free gift. The second one is about our program in the region. So in the Arab ICT organization we always focus on translating regional dialogue into concrete actions and we this sense we are making a lot of capacity building programs. We and our members also through technical assistance and also through helping them in regional policy development. We made a lot of initiatives like the Arab cyber security and the strategy that was made in 2023 we made the Arab AI ethics pact which was made one year these are the main actions that are made by Arab organization through this activity for their members.
Maryna Veuthey
thank you so much thank you so much for that so I I can see clearly now it's it's a song by the way but I will not say it today so capacity building regulations technology so that was actually the red line of this just got five minutes left and we're gonna do in a small exercise if you were okay with that first of all can you please move to the next slide please yes so what are we going to do I have five questions to you guys Just five, not like our panelists got the tricky questions. Just five, pretty simple. And just before we start, zero question, ground question would be, who actually checked his phone in the last ten minutes? You can raise your hand. There is no judgment. There is no judgment, right? Both, even two, bingo, right? So there is no judgment, but we see that we are all actually as human beings, we are dependent of something, right? And this is a good, I think, example of the dependency that actually we have, right? Addicts, right? Well, phonetics cannot have the same consequences if you are having, like, out of the community. You have to have control of your sovereignty. But, yeah, we can say, right? So the next exercise will be super, super simple. Thank you so much for that Five questions We will raise our hands We can raise our hands like this Any way you like it Hands up If you know which country Laws Governs Your most critical government Data We have government representative here Do you know which law Actually in your country Governs the data Yes Or okay Any data One two three That's fine So raise your hand Or you can keep your hand But I will not force you to keep your hand all the time So if you could switch A cloud Or software providers With info today Can you right now switch Your software Provider or a cloud provider, any kind of contract, can you terminate in 30 days? Do you know it? Yes, you can. You can. You Switch. I'm sorry. Switch. That's a good point. I'm sorry. I'm just getting a little bit nervous when it comes to the questions. Switch. If you can terminate the contract, what do you get the data? What's the legal implication? That's what I'm asking.
Audience
If you can terminate the contract, what do you get the data? What's the legal implication? That's what I'm asking.
Maryna Veuthey
Yeah, you're right. So, and a quick question. Do you know if actually your country controls the encryption case or if it is a vendor who is? I've got a good question. I've got a good question. Yeah, so we are not freezing our hands. So, and the last one, no, not the last one. If your government has a policy on staff using public AI tools with sensitive data, do you know if it exists? Yeah. It exists. Yes. Yes, you can raise your hand or the finger in the air. The last one. So, that's also, as a tricky question, so a tricky situation, but we can count, right? And the last one. Also, we didn't touch upon it because it's a kind of, we talked about it. Last one. Hands up if post -quantum migration is already budgeted and not just discussed. I think we wouldn't want to have any hands there, right? Because actually AI right now, we are talking about AI a lot, and it's kind of everywhere, and we are getting used to it. But then there is one more animal to trade, right, is the post -quantum. So no hands. So there is no judgment, as I said. Can we move to the next slide, please? Awesome. Thank you. So for those, right, who got like four to five points, you are largely in control, right? So you are knowing what's going on, right, to the point of Gallo, who was saying, like, from where it should start, right? Two, three, you are partially there. So you are moving. That's all right. That's cool. And, well, if there is no or one, that would be real gaps to close. But that's all right. Right? So we are happy. like sovereignty, AI, post -quantum, whatever. But it's complicated, but there is no way to go. So that's why we would love to invite you as well to follow the first webinar and then also the course about sovereignty and actually how to move from the frameworks and how to start doing things, right? And with our partners, SADA, Smart Africa team, we are preparing this amazing webinar and the course. So feel free to subscribe. And I think that there will be also more with our new partners right now, AICTO. Thank you so much. In case you have any questions, we are, guys, 35. 46, I'm sorry, one minute late. And if you have any questions, feel free. We are here to answer it. Thank you. Thank you for joining the session, by the way. Thank you. Thank you all. Thank you so much for joining, for everyone who has joined online. Yeah, just
Thelma Efua Quaye
Beyond this, there are so many other courses available for policymakers across Africa, which is made for you, curated for you. You heard most of the conversations we had, you know, went back to building the capacity of policymakers so you can make the right choices. So please take the time to scan the QR code and join the SADA platform. Thank you. SADA, Smart Africa Digital Academy. Thank you.
Maryna Veuthey
Thank you so much, Thelma. And so see you there. In case you have any questions, we will be. here. Thank you so much for joining. Cheers. Thank you.

Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.