WSIS Forum 2026
Rapport généré par l'IA

Operationalizing Digital Sovereignty: The African Blueprint

6 intervenants
Résumé

Résumé

Cette discussion, animée par Maryna Veuthey, a réuni des intervenants de RealTyme, de l'Organisation arabe des TIC (AICTO), de Smart Africa et de Talisman Cybersecurity afin d'explorer la souveraineté numérique, la gouvernance des données et les défis émergents de la cryptographie post-quantique . François Rodriguez a ouvert les débats en distinguant le sentiment d'être souverain sur le plan numérique de la réalité de cette souveraineté, en mettant en lumière trois dimensions clés : vérifier où les données sont stockées, comprendre la juridiction des fournisseurs de services cloud et garantir la conformité réglementaire . Il a averti que les gouvernements risquent de perdre leur indépendance opérationnelle s'ils s'appuient sur des fournisseurs pouvant retirer leurs services unilatéralement , et a souligné l'urgence de la transition vers le chiffrement post-quantique, notant que l'informatique quantique capable de briser la cryptographie actuelle pourrait être disponible dès 2030-2031 . S.E. Mohamed Benamor de l'AICTO a soutenu que la souveraineté numérique n'est pas un choix binaire entre contrôle national et coopération régionale, mais plutôt un équilibre entre les deux . Il a décrit que le rôle de l'AICTO est de faciliter le consensus et de permettre aux États membres de collaborer sur la cybersécurité, la recherche en IA et les normes communes, tout en préservant la prise de décision nationale . Gallo Fall a ajouté que de nombreux pays du Sud global ont déjà perdu le contrôle de leur infrastructure numérique sans s'en rendre compte, et que sa plateforme a été conçue pour cartographier la posture de souveraineté et fournir des recommandations concrètes . Thelma Efua Quaye a souligné que posséder une infrastructure est insuffisant sans investissement, compréhension et stimulation du marché, s'appuyant sur son expérience d'un réseau dorsal national fonctionnant à moins de 10 % de sa capacité . Elle et les autres intervenants ont convenu qu'aucune offre d'infrastructure gratuite ne devrait être acceptée sans examen approfondi, car les données, la souveraineté ou l'influence stratégique en constituent invariablement le coût caché . La session s'est conclue par un exercice participatif avec le public, révélant des lacunes importantes dans la connaissance des gouvernements en matière de lois sur la gouvernance des données, de clauses contractuelles des fournisseurs, de contrôle des clés de chiffrement et de préparation au post-quantique , soulignant ainsi le rôle crucial des programmes de renforcement des capacités proposés par des plateformes telles que la Smart Africa Digital Academy et l'Académie de l'UIT .

Points clés

Objectif général

La discussion visait à sensibiliser les gouvernements - en particulier ceux du Sud global et des régions arabes - à la souveraineté numérique, à la gouvernance des données, à la cryptographie post-quantique et au renforcement des capacités. La session a cherché à aider les décideurs politiques à comprendre l'écart entre le fait de se sentir souverain et celui de l'être réellement, et à promouvoir des cadres pratiques, des programmes de formation et une coopération régionale pour combler cet écart. ---

Principaux points de discussion

- Définir et mesurer la souveraineté numérique : François Rodriguez a précisé que la véritable souveraineté numérique requiert trois niveaux vérifiables : savoir où les données résident physiquement, comprendre la juridiction du fournisseur cloud ou de services, et s'assurer que les données ne transitent pas par des systèmes tiers non contrôlés. Il a insisté sur la distinction essentielle entre le sentiment de souveraineté et sa réalité. S.E. Ing. Mohamed Benamor a renforcé ce point en définissant simplement la souveraineté comme « la capacité d'un pays à exercer un contrôle total sur ses données ». - La dépendance aux fournisseurs et les risques des offres d'infrastructure « gratuites » : Les intervenants ont mis en garde avec force contre l'enfermement propriétaire et les dangers d'accepter des infrastructures construites et gérées par des entités étrangères sans coût apparent. Thelma Efua Quaye a cité un exemple concret au Ghana, où une subvention du gouvernement américain pour des données de santé a été annulée parce que les données des citoyens en constituaient une condition cachée. François Rodriguez a ajouté qu'au-delà des données, la propriété intellectuelle et les données d'entraînement des modèles d'IA peuvent être extraites silencieusement, permettant à des acteurs étrangers de construire des simulations stratégiques de la population d'un pays. Gallo Fall a qualifié cela de « colonisation des données », exhortant les nations - en particulier en Afrique - à classer et protéger leurs données stratégiques essentielles telles que les systèmes d'identité nationale, les données biométriques et les listes électorales. - L'écart entre posséder et exploiter une infrastructure numérique : Thelma Efua Quaye s'est appuyée sur son expérience de directrice technique pour illustrer qu'un pays peut posséder une infrastructure sans pour autant l'utiliser ou la maintenir efficacement, souvent parce que les gouvernements n'en comprennent pas l'importance stratégique et n'y investissent donc pas. Elle a identifié trois étapes pour passer de la propriété au contrôle opérationnel : comprendre l'importance de l'infrastructure, investir dans le renforcement des capacités et stimuler la demande du marché pour en assurer l'utilisation. - La cryptographie post-quantique : une menace urgente et sous-budgétisée : François Rodriguez a souligné que l'informatique quantique - dont on estimait auparavant qu'elle menacerait le chiffrement existant d'ici 2040 - est désormais anticipée dès 2031, faisant de l'anticipation de la migration vers la cryptographie post-quantique une priorité immédiate. L'exercice participatif en fin de session a révélé que pratiquement aucune main ne s'est levée lorsqu'on a demandé si la migration post-quantique était déjà budgétisée, soulignant l'écart entre la prise de conscience et le passage à l'action. - La coopération régionale et le renforcement des capacités comme leviers de souveraineté : S.E. Ing. Mohamed Benamor a expliqué que le rôle de l'AICTO n'est pas de plaider pour la centralisation, mais de faciliter le consensus, en aidant les États membres à collaborer sur la cybersécurité, la recherche en IA, l'interopérabilité et les normes communes, tout en préservant l'autorité décisionnelle nationale. La session a également annoncé un nouveau mémorandum d'accord entre RealTYme et l'AICTO, venant compléter les partenariats existants avec Smart Africa, afin d'étendre les programmes de renforcement des capacités dans la région arabe et en Afrique. ---

Ton général

Les intervenants ont été informatifs et collaboratifs. Ils ont également fait quelques mises en garde. La modératrice, Maryna Veuthey, a maintenu un registre dynamique et engageant, utilisant l'humour et des exercices interactifs pour maintenir l'implication du public. Les intervenants ont été mesurés et constructifs plutôt qu'alarmistes, bien que des moments qu'un sentiment d'urgence se soit fait sentir, notamment lors des discussions sur la colonisation des données , les risques des infrastructures « gratuites » et l'imminence des menaces quantiques . Vers la fin de la discussion, les intervenants se sont montrés motivés et orientés vers l'action, la session se concluant par des appels à rejoindre des plateformes de formation et des webinaires à venir. Dans l'ensemble, la discussion a équilibré le réalisme quant aux vulnérabilités actuelles avec l'optimisme concernant les outils, les cadres et les partenariats disponibles pour y remédier.

Intervenants

- Maryna Veuthey - Modératrice de la session ; associée à RealTime (partenaire de renforcement des capacités de l'UIT) - François Rodriguez - Présentateur et intervenant ; associé à RealTime, partenaire de renforcement des capacités de l'UIT ; couvre des sujets incluant les cadres de souveraineté numérique, la cryptographie post-quantique et les communications gouvernementales sécurisées - Thelma Efua Quaye - Intervenante ; responsable du renforcement des compétences en infrastructure numérique à Smart Africa ; expertise en infrastructure numérique, renforcement des capacités et politique pour les gouvernements africains - S.E. Ing. Mohamed Benamor - Intervenant (en ligne) ; Secrétaire général de l'Organisation arabe des TIC (AICTO) ; expertise en politique régionale des TIC, souveraineté numérique, stratégie de cybersécurité et gouvernance de l'IA dans la région arabe - Gallo Fall - Intervenant ; fondateur et directeur technique de Talisman Cybersecurity ; expertise en cybersécurité, plateformes de renseignement sur la souveraineté numérique et infrastructure numérique pour les gouvernements et les institutions critiques, en particulier dans le Sud global Intervenants supplémentaires : - Public - Un membre non identifié du public ayant fait une brève intervention lors de la partie exercice interactif de la session ; aucun rôle ni affiliation identifiés

Intervenants
FR
François Rodriguez
135 wpm · 12 min
HE
H.E. Eng. Mohamed Benamor
96 wpm · 4 min
GF
Gallo Fall
138 wpm · 4 min
TE
Thelma Efua Quaye
138 wpm · 6 min
MV
Maryna Veuthey
123 wpm · 19 min
A
Audience
902 wpm · 1 s

Résumé élargi : Souveraineté numérique, gouvernance des données et cryptographie post-quantique

#

Présentation de la session et introductions

La séance, modérée par Maryna Veuthey, a réuni quatre intervenants pour explorer les thèmes interconnectés de la souveraineté numérique, de la gouvernance des données, de la cybersécurité et de la cryptographie post-quantique . Le panel comprenait François Rodriguez de RealTyme, S.E. Ing. Mohamed Benamor, Secrétaire général de l'Organisation arabe des TIC (AICTO), participant à distance ; Thelma Efua Quaye, responsable du renforcement des compétences en infrastructure numérique de Smart Africa ; et Gallo Fall, fondateur et directeur technique de Talisman Cybersecurity . Maryna Veuthey a précisé qu'il s'agissait d'une séance interactive, promettant la participation du public et un exercice pratique en complément des discussions du panel . Un développement institutionnel majeur a été annoncé au cours de la session : RealTyme a signé un nouveau Mémorandum d'entente (MOU) avec l'AICTO, venant compléter ses partenariats existants - dont une collaboration antérieure avec le GFC et son partenariat actuel avec Smart Africa - afin d'étendre les programmes de renforcement des capacités à la région arabe .

#

Mise en contexte : du sentiment de souveraineté à la souveraineté réelle

François Rodriguez a ouvert la discussion de fond en s'appuyant sur l'expérience de RealTyme en tant que partenaire de renforcement des capacités de l'UIT, ayant formé plus de 50 pays sur les thèmes de la souveraineté numérique, de la cryptographie post-quantique et des communications gouvernementales sécurisées . Il a apporté le thème central de la discussion : la distinction entre la volonté de se sentir souverain et la réalité d'être effectivement souverain . Ce cadrage a donné le ton à l'ensemble de la discussion, remettant en question l'idée que la signature d'accords ou la possession d'infrastructures confère automatiquement une souveraineté véritable.

François Rodriguez a défini trois dimensions vérifiables de la souveraineté numérique. La première est l'auditabilité - la capacité d'un gouvernement à vérifier réellement qu'il est souverain . La deuxième concerne la localisation des données et la juridiction applicable : où les données résident physiquement ? Se trouvent-elles à l'intérieur des frontières du pays ? Quelle juridiction régit le fournisseur de services cloud ? La troisième dimension porte sur les routes par lesquelles les données transitent, notamment si les fournisseurs de logiciels tiers relèvent de la même juridiction que le gouvernement, et si les écarts entre ces juridictions créent des vulnérabilités . Il a cité un exemple récent dans lequel des gouvernements ont vu leur accès à certains outils d'IA coupé par des fournisseurs, avertissant que si un prestataire cesse de fournir des services ou des mises à jour, les opérations d'un pays peuvent s'arrêter entièrement, affectant directement les citoyens .

#

La gouvernance des données comme fondement de la souveraineté

François Rodriguez a avancé que la gouvernance des données représente la couche fondatrice sur laquelle reposent toutes les autres mesures de souveraineté . Il a exposé un cadre de cycle de vie des données couvrant quatre étapes : comprendre quelles données sont collectées et intégrées dans les environnements numériques ; déterminer comment elles sont stockées et protégées en fonction de leur sensibilité ; gérer la façon dont elles sont utilisées dans les flux de travail quotidiens ; et décider quelles données doivent être supprimées . Il a souligné que la minimisation des données, c'est-à-dire réduire le volume de données stockées, limite directement l'exposition en cas de violation . Un chiffrement approprié doit ensuite être appliqué aux données nécessitant une protection, ce qui est directement lié à l'urgence de la transition vers la cryptographie post-quantique .

François Rodriguez a également soulevé la question de la gouvernance des données liées à l'IA, notant que plus de 50 % des requêtes adressées à l'IA sont suffisamment simples pour être traitées sur l'appareil lui-même, par le biais de la synthèse, de la traduction et de l'intégration dans les flux de travail, sans que les données soient acheminées vers des systèmes d'IA en cloud . Il a soutenu que l'envoi inutile de données vers l'IA en cloud reproduit les risques de souveraineté déjà identifiés : une fois que les données entrent dans le cloud, le contrôle sur celles-ci est effectivement abandonné . Ce point a renforcé l'argument central de la session selon lequel la souveraineté n'est pas seulement une question réglementaire ou contractuelle, mais une série de choix opérationnels quotidiens.

#

Harmonisation réglementaire et limites des cadres importés

François Rodriguez a également abordé le défi de l'harmonisation réglementaire, notant que les pays africains ont de plus en plus cherché à mettre en œuvre des réglementations calquées sur les cadres de l'UE . Tout en reconnaissant le leadership de l'UE en matière de réglementation numérique stricte, il a mis en garde contre la nécessité de prendre en compte l'adéquation architecturale et contextuelle, car des réglementations conçues pour une destination peuvent ne pas répondre aux besoins d'une autre . Il a utilisé l'exemple des corridors commerciaux de l'UE, initialement conçus pour les matières premières, qui ne ressemblent guère aux routes de l'économie numérique actuelle dans les secteurs de l'agriculture, de la santé et de la finance . Il a noté que le dialogue en cours sur l'IA à Genève tente d'harmoniser les réglementations mondiales, mais a mis en doute la capacité d'une telle harmonisation à contraindre réellement les hyperscalers fournissant des services dans de multiples juridictions .

#

La perspective de l'AICTO : la souveraineté par la solidarité régionale

S.E. Ing. Mohamed Benamor a offert une perspective de gouvernance régionale, soutenant que la souveraineté numérique ne devrait pas être présentée comme un choix binaire entre un contrôle national total et des capacités régionales partagées . Il a décrit le rôle de l'AICTO non pas comme la promotion de la centralisation, mais comme la facilitation du consensus entre les États membres , leur permettant de collaborer volontairement dans des domaines où l'action régionale crée davantage de valeur, notamment la cybersécurité, la recherche en IA, l'infrastructure numérique publique, l'interopérabilité, le renforcement des capacités et les normes techniques communes, tout en conservant le contrôle sur les infrastructures critiques et les politiques nationales . Il a précisé que l'AICTO offre une plateforme multipartite pour l'élaboration conjointe de cadres de gouvernance et de mécanismes de coopération de confiance qui respectent les priorités nationales tout en faisant progresser des valeurs régionales communes , avec pour objectif ultime de renforcer la souveraineté numérique nationale par la solidarité régionale .

S.E. Ing. Mohamed Benamor a été invité à donner une définition de la souveraineté en une phrase et il a simplement déclaré qu'il s'agit de « la capacité d'un pays à avoir le plein contrôle de ses données » . Cette définition maximaliste a été complétée par d'autres panélistes qui ont proposé des perspectives plus nuancées sur le plan opérationnel, donnant lieu à l'un des échanges qui ont précisé la définition de la souveraineté numérique.

#

La réalité technique : de nombreux pays ont déjà perdu le contrôle

Gallo Fall a introduit une distinction conceptuelle précise entre cybersécurité et souveraineté numérique. Il a décrit la cybersécurité comme une discipline essentiellement technique axée sur la protection des systèmes contre les accès non autorisés, les perturbations ou la destruction, tandis que la souveraineté numérique est un concept stratégique plus large : un système peut être parfaitement sécurisé et pourtant ne pas être sous le contrôle du pays . Cette distinction est cruciale car elle empêche les gouvernements de confondre les mesures de sécurité technique avec une véritable autonomie stratégique.

Gallo Fall a expliqué que sa plateforme de renseignement sur la souveraineté numérique chez Talisman Cybersecurity a été construite par conviction personnelle, après avoir été témoin de cyberattaques généralisées dans les pays du Sud en tant que natif du Sénégal . La plateforme fonctionne comme un écosystème de renseignement unifié et continu, spécialement conçu pour les ministères gouvernementaux, les institutions d'infrastructure critique et d'autres entités qui refusent de céder le contrôle stratégique de leurs données, de leurs infrastructures et de leurs capacités en matière d'IA . Elle cartographie les cadres de cybersécurité par rapport aux piliers de la souveraineté et fournit des KPI, des rapports et des recommandations pour aider les gouvernements à comprendre leur situation actuelle . Son constat central était sans appel : de nombreux pays du Sud ont déjà perdu le contrôle de leurs données et de leur infrastructure numérique sans s'en rendre compte, parce qu'ils ignorent leur posture en matière de souveraineté numérique . Cette observation a directement renforcé la distinction établie précédemment par François Rodriguez entre se sentir souverain et l'être réellement, et a conduit Maryna Veuthey à identifier l'ignorance - et non la malveillance ou une défaillance technique - comme la principale cause de la perte de souveraineté .

Gallo Fall a également établi une distinction explicite entre les cadres de conformité et l'évaluation véritable de la souveraineté, soutenant que la conformité donne aux gouvernements « une liste de contrôle qui ne fait que vous délivrer un certificat de certification » mais ne leur dit pas ce qui se passe réellement en temps réel . Sa plateforme, en revanche, est conçue pour fournir une conscience situationnelle afin que les gouvernements sachent par où commencer pour combler leurs lacunes .

#

De la possession à l'exploitation : l'impératif du renforcement des capacités

Thelma Efua Quaye a abordé la question de la souveraineté sous l'angle de l'utilisation des infrastructures et du renforcement des capacités, en s'appuyant sur son expérience d'ancienne directrice technique ayant géré une infrastructure reliant des zones critiques . Elle a raconté que l'utilisation de l'infrastructure était inférieure à 10 %, et que la maintenance et les services étaient médiocres, parce que le gouvernement ne comprenait pas l'importance stratégique de cet actif et n'y investissait donc pas . Cette expérience a servi d'illustration concrète du fossé entre la possession d'une infrastructure et la capacité à l'exploiter efficacement.

Thelma Efua Quaye a identifié trois étapes nécessaires pour passer de la propriété au contrôle opérationnel . La première est la compréhension : les gouvernements doivent saisir pourquoi l'investissement dans l'infrastructure numérique est important avant de s'y engager financièrement, et c'est précisément là que les programmes de renforcement des capacités jouent leur rôle . La deuxième est l'investissement lui-même, qui découle de la compréhension . La troisième consiste à stimuler la demande du marché pour s'assurer que l'infrastructure, une fois construite, est effectivement utilisée . Elle a noté que plusieurs pays avaient investi dans des centres de données souverains motivés par le sentiment de souveraineté plutôt que par un besoin réel du marché, ce qui avait entraîné une faible utilisation - un écho direct de la distinction entre sentiment et réalité établie plus tôt dans la session . Elle a suggéré que les gouvernements peuvent stimuler la demande par des mécanismes tels que les startups et les usines d'IA .

Thelma Efua Quaye a également offert une perspective sur la souveraineté qui proposait un standard plus opérationnellement atteignable, en particulier pour les pays en développement. Elle a soutenu que l'isolement total n'est pas réaliste dans le monde d'aujourd'hui, et que la souveraineté pour un gouvernement devrait signifier la transparence et la capacité de savoir à quoi servent ses données, avec le pouvoir de dire oui ou non .

#

Les dangers des offres d'infrastructure « gratuites »

Les intervenants ont ensuite discuter de l'option pour les gouvernements d'accepter des offres d'infrastructure numérique gratuite de la part de fournisseurs ou de gouvernements étrangers. Maryna Veuthey a posé un scénario hypothétique dans lequel un pays ou un fournisseur proposait de construire et de gérer l'intégralité d'une infrastructure nationale de A à Z sans frais, invitant les intervenants à réfléchir aux implications avant d'accepter .

Thelma Efua Quaye a répondu avec une une certaine franchise et a affirmé qu'il n'existe rien de gratuit. Elle a utilisé l'expression imagée suivante : « si vous n'êtes pas celui qui mange, vous êtes probablement celui qui est mangé » . Elle a donné un exemple concret pour illustrer son propos, : le service de santé du Ghana et le gouvernement américain avaient trouvé un accord, prétendument gratuit. Cependant, l'une des conditions cachée semblait être l'accès aux donnéesd des citoyens. Le gouvernement a donc refusé et annulé l'accord . Elle a exhorté les gouvernements à examiner attentivement les petits caractères de toute offre de ce type, en se demandant ce qui est donné en échange - que ce soit des données, la souveraineté ou la liberté - même lorsqu'aucune somme d'argent ne change de mains .

François Rodriguez a acquiescé mais a apporté une profondeur analytique supplémentaire, distinguant plusieurs types de modèles économiques cachés : les structures freemium où les coûts apparaissent une fois qu'un seuil d'utilisation est atteint ; les périodes gratuites limitées dans le temps après lesquelles les paiements commencent ; et l'extraction secrète de données et de propriété intellectuelle qui se produit en coulisses sans que le gouvernement en soit conscient . Il a introduit le concept de jumeau numérique, avertissant que si les données de santé d'un pays étaient absorbées dans un modèle d'IA étranger, il deviendrait possible de simuler l'impact stratégique d'une infection ou d'une autre menace sur la population de ce pays, ce aui deviendrait ainsi un problème de sécurité nationale .

Gallo Fall a qualifié cette dynamique de « colonisation des données », soutenant que des pays et des entreprises puissants construisent délibérément des modèles d'IA à partir de données africaines pour servir leurs propres intérêts stratégiques . Il a spécifiquement averti que des adversaires utilisent ces données pour manipuler des élections, et a exhorté les nations africaines à classer rigoureusement leurs données et à identifier les ensembles de données stratégiques, notamment les systèmes d'identité nationale, les données biométriques et les listes électorales, qui ne doivent jamais quitter le pays . S.E. Ing. Mohamed Benamor a invoqué le Cheval de Troie comme analogie historique, notant qu'un cadeau gratuit mérite toujours un examen attentif des motivations du donateur , et a mentionné les réponses politiques régionales concrètes de l'AICTO, notamment la Stratégie arabe de cybersécurité de 2023 et le Pacte arabe d'éthique de l'IA, comme mécanismes permettant de traduire le dialogue en action .

#

Dépendance aux fournisseurs et contrôle des marchés publics

François Rodriguez a abordé la question de la manière dont les gouvernements peuvent parvenir à une véritable indépendance numérique au-delà du simple changement de fournisseur . Il a défini trois filtres à travers lesquels les gouvernements doivent évaluer leur souveraineté : premièrement, vérifier où se trouvent les données, si elle sont sur site, sur un cloud ou dans une configuration hybride ; deuxièmement, appliquer la réglementation spécifique à la juridiction appropriée au secteur concerné, qu'il s'agisse du gouvernement, de la finance, de la santé ou de l'énergie ; et troisièmement, garantir l'indépendance opérationnelle, c'est-à-dire la capacité de continuer à mener des opérations si un fournisseur retire son soutien, met fin à un contrat ou décide de ne plus fournir de services . Il a souligné que lors des marchés publics, les gouvernements doivent vérifier qu'ils contrôlent leurs clés de chiffrement, leurs données et leur destin opérationnel .

Maryna Veuthey a par la suite organisé un exercice interactif avec le publi. Cet exercice a confirmé les lacunes identifiées par François Rodriguez. Elle a demandé aux participants s'ils savaient quelle loi régissait leurs données gouvernementales les plus critiques, s'ils pouvaient résilier un contrat avec un fournisseur de services cloud ou de logiciels dans un délai de 30 jours, s'ils savaient qui contrôlait leurs clés de chiffrement, et si leur gouvernement disposait d'une politique concernant l'utilisation par le personnel d'outils d'IA publics avec des données sensibles . Le faible nombre de mains levées à ces questions a démontré que même des décideurs avertis participant à une session sur la souveraineté numérique manquaient d'une connaissance élémentaire de leurs droits contractuels et de leurs contrôles techniques. Un membre du public a affiné le propos en notant que la question cruciale lors de la résiliation d'un contrat n'est pas seulement de savoir si la sortie est possible, mais ce qu'il advient des données et quelles en sont les implications juridiques .

#

Cryptographie post-quantique : une menace urgente et sous-budgétisée

François Rodriguez a identifié la cryptographie post-quantique comme l'une des menaces les plus urgentes et les plus sous-estimées auxquelles sont confrontés les gouvernements . Il a noté que l'informatique quantique, dont on attendait auparavant qu'elle menace la cryptographie existante dans environ dix ans, est désormais projetée pour arriver entre 2030 et 2040, avec 2031 cité comme un marqueur à court terme, ce qui signifie qu'elle est déjà « à notre porte » . Il a décrit comme une actualité récente de juin l'adoption du Quantum Act, représentant un investissement nouveau et significatif pour accélérer le développement de l'informatique quantique, ce qui a encore comprimé ce calendrier . L'implication est que les données actuellement chiffrées par des méthodes conventionnelles pourraient être déchiffrées par des ordinateurs quantiques dans quelques années, exposant les données gouvernementales sensibles à des acteurs étrangers .

L'urgence de cette menace a été clairement confirmée par l'exercice final avec le public, au cours duquel Maryna Veuthey a demandé aux participants de lever la main si la migration post-quantique était déjà budgétisée plutôt que simplement discutée . L'absence de mains levées a illustré un fossé quasi universel entre la prise de conscience et la préparation financière, même parmi les participants à une session dédiée à la souveraineté numérique . Maryna Veuthey a noté que si l'IA est devenue un sujet familier, l'informatique post-quantique représente un défi supplémentaire et moins bien compris que les gouvernements doivent commencer à aborder .

#

Exercice avec le public et réflexions finales

La séance s'est conclue par un exercice interactif en cinq questions conçu pour révéler les lacunes pratiques dans la conscience des gouvernements en matière de souveraineté . Maryna Veuthey introduit l'exercice en demandant qui avait consulté son téléphone au cours des dix dernières minutes, pour illustrer que les êtres humains sont dépendants de quelque chose, encadrant ainsi le contexte plus large de la dépendance numérique . L'exercice a ensuite abordé des questions sur la loi de gouvernance des données, les droits de résiliation de contrat, le contrôle des clés de chiffrement, les politiques d'utilisation de l'IA et la budgétisation post-quantique . Les résultats ont confirmé l'argument central de la session : que le principal obstacle à la souveraineté numérique n'est pas l'absence de solutions techniques ou de cadres réglementaires, mais un manque fondamental de conscience de la situation actuelle des gouvernements .

Maryna Veuthey a expliqué comment interpréter les résultats des activités qu'elle a organisé : ceux qui pouvaient répondre affirmativement à quatre ou cinq questions étaient largement en contrôle ; deux ou trois indiquaient des progrès partiels ; et zéro ou un indiquait des lacunes importantes à combler . Elle a souligné que l'objectif de l'exercice n'était pas de juger mais de motiver, et a invité les participants à s'engager dans le prochain webinaire et cours sur les cadres de souveraineté numérique développés en partenariat avec Smart Africa et l'AICTO .

Thelma Efua Quaye a conclu en encourageant tous les participants à scanner le code QR et à rejoindre la plateforme de la Smart Africa Digital Academy (SADA), notant que les cours sont conçus et élaborés spécifiquement pour les décideurs politiques à travers l'Afrique, et que les conversations tenues au cours de la session soulignent l'importance de renforcer les capacités des décideurs à faire les bons choix .

#

Évaluation globale

La session a produit un fort degré d'alignement entre les quatre panélistes sur les thèmes centraux : la souveraineté doit être vérifiable plutôt que supposée ; il n'existe pas d'offre d'infrastructure numérique gratuite ; le renforcement des capacités est un prérequis fondamental pour passer de la possession à l'exploitation des infrastructures ; certaines catégories de données ne doivent jamais quitter les frontières d'un pays ; et la dépendance aux fournisseurs constitue une menace fondamentale pour l'indépendance nationale . Un domaine notable de convergence était la vision selon laquelle la souveraineté ne doit pas nécessairement signifier un contrôle national absolu, mais plutôt la transparence, le consentement éclairé et une coopération régionale sélective . Le résultat institutionnel le plus significatif de la session a été l'annonce du Mémorandum d'entente entre RealTyme et AICTO, étendant le partenariat de renforcement des capacités qui existe déjà avec Smart Africa à la région arabe, et signalant un engagement multilatéral croissant à traduire les principes de souveraineté numérique en formations pratiques et en cadres politiques .

Maryna Veuthey
And just before we start, it will be an interactive session. And at the end, we're going to also have amazing panelists, some tricky questions. So be ready. And then we're going to also have a little activity with you guys, with the audience. And I hope that you can also hear me well. For everyone who is joining online, thank you so much for being here. So I will be your moderator today. My name is Marina, with Y. Quite exotic, but here we go. So today we will be talking about architecture, digital autonomy. And actually, we will be tackling some also tricky topics that no one is out, I think. And it would be around... What is that? What is that? So we'll actually tackle it today. So let me also present our amazing panelists today. So Mr. Francois Rodriguez, which is in the middle. Hi. Also, we have His Excellency Mohammed Ben Amour, who is joining us online. Hello. Can you hear us?
H.E. Eng. Mohamed Benamor
Yes, I'm hearing you very well. Thank you.
Maryna Veuthey
Perfect. Thank you so much for joining. We also have Ms. Thelma, the Digital Infrastructure Skills Empowerment Officer of Smart Africa. It's been a pleasure to see you here today. And Mr. Gawafal, founder and CTO of Talisman Cybersecurity. Thank you so much for being with us today. So I cannot just pass the mic. We all have mics here. But I will pass the word to my colleague, Francois, who will do in a quick. interest of today thank you the four is yours mike is yours françois
François Rodriguez
thank you so thank you marina for this introduction so let's uh spice up a little bit the topic with some context and then the idea is to have some questions to the panelists so the journey started as one of the capacity building partner of itu so we are real time and we've been training more than 50 different countries on capacity it builds you know the topic of today which is uh you know what digital digital sovereignty really means uh the transition into the post -quantum arena as well as you know implementing secure communications in the government space so this is how the journey started and the idea is to give you some snippet of what we deliver in these uh trainings to set up the the context so the the first one is really prominence and digital sovereignty frameworks, how basically you implement those and the reality on the field happens. So there's two notions between the willingness of feeling sovereign and the reality of really being sovereign in the field. So very quickly, not theoretical, but the first dimension is really the verification of it. So can you really audit that you are really sovereign? This is the first thing. It all started with the framework with the jurisdiction where you use your data sitting. Is it in country? And the third layer is the regulation out of it. So implementing the regulation in the country to make sure that you prevent this data leakage and the jurisdiction basically So I think that's the first And then the of the data traveling outside the perimeter of your country. So it all started with, you know, this spread of clouds. So people think that, you know, cloud data is sitting out there, but in fact cloud is somewhere else's service, right? So your data is somewhere, not in the cloud. So where those servers are sitting are basically the first question to ask. The second is the jurisdiction of the service provider of that cloud infrastructure. And third, basically where the data is transiting through. Are you using, you know, third -party software? If yes, those providers are sitting in the same jurisdiction of you or not, and this is the gap of the two that you need to pay attention to. So some traps have been happening in the news recently. Recently, some government have turned off, you know, the access to certain, you know, AI Table 5. This has really happened recently, but this is also... are you in control of your independence so are you autonomous so if your provider is switching off if your provider is not providing updates are you able to continuously run your operations because if operation stops your country stops to work and your citizens are not happy so the independence is really at stake in that point so harmonizing as well especially when we talk about implementation of the regulations so we've seen for instance in Africa implementation of certain regulations mimicking or trying to identify the similarities between EU EU has been really at the front of implementing very strict regulations. So I think we need to find also a balance out of fit because the architecture might not fit with certain destinations. So a quick example here of a comment, but the EU proposed corridors at the time were basically minerals and materials, raw materials were important and not the same routes of today, right, with the digital economy, the agriculture, the healthcare, the financial sector are basically using different routes. So you need to as well pay attention of the implementation of those regulations that are really fitting the purpose of the destiny that applies to it. the harmonization is also something that is up in the air at the moment so you've got this ai dialogue happening right now in geneva so the idea is to harmonize those global regulations but can you really control those hyperscalers that are providing the services this is the other question so when you do the procurement we've been hearing in different sessions you need to pay attention to certain you are really in control of the keys you are control of your data you are in control of your destiny this is what we are promoting here um so it all starts with data governance because without data this ai world and digital world doesn't really work and one of the framework because the idea is to show you some blueprints this is the topic of the session okay one of the interesting blueprints to start with is basically what is the data that you are collecting ingesting in your environments and digital economy then more important, okay, because and how do you store? Because you need to protect certain sensitive data. Certain data is public, so therefore you give access. Some data is just for internal use only. And then how you use it, how you propel this data into your day -to -day workflows operations. And more importantly, because at RealTime we are very sensitive to data minimization, is what data do you delete? Because the less data you are storing in case of breaches. So therefore you need to classify that data accordingly and make sure that you apply the right encryption level into the data that needs to be protected out of it. And this is one of the key points of transitioning now into post -quantum cryptography, which is resistant to quantum computing, right? Otherwise it's you have this potential of, you know, foreign advisors getting access to that data that is not encrypted and therefore accessible area. The data that is also these days put into the AI framework is also one of the topics that we are putting in motion in this capacity building trainings, is that not every data needs to be nurturing the cloud AI. So there is a lot of AI and some stats are reflecting that more than 50 % of AI queries are just simple queries that you can run on AGI, meaning on the device that are summarizing, translating workflows integration into the workspace that can be run. mobile phone where dumping all the the data in the cloud ai basically you lose control of what you put in the cloud the same as you know the sovereign aspect that we just touched on so that's um some of the important dimension that we are putting together and another news that came you know in june as well recently is the quantum act basically a lot of investment have been put now in quantum computing to accelerate the development of this technology that will to break the existing cryptography um so the third and last topic that we've been training the different countries on is the migration in post quantum encryption for the same reason that we've just been explaining so quantum was expected to be implemented 10 years from now we're talking now of 2030 2040 2031 the latest so he's knocking the door already and we've been putting all this capacity building through different platforms as we explained we started with propelling the GFC more recently we signed an agreement with smart Africa and we're gonna announce as well the basically signature of today with the Arab ICT organization that's the announcement of today so thank you for welcoming us in that journey and that's the reason that we've got mr. Ben Amour with us.
Maryna Veuthey
Super efficient 12 minutes puff so so which is very nice so we're gonna have more time for the questions and also to questions to your intervenants and panelists and then more time for the exercise and your questions as well. So thank you so much, Francois. So what I see from actually in a quick overview, right, that you gave the context is that we have also four intervenants today. We also have four particular angles, if we can say, the original policies and regulations. We also have a capacity building as well as cybersecurity, right? So that then leads to the questions there, right? Some of them were shared in the previous before the session. Some of them not. So let's get started then. So Francois, quick question to you. You were not expecting this, right? You were talking for. Twelve minutes and then you thought that I'm going to move to someone else. But no. So during this session and also the sessions that we attended. as well topics about the sovereignty also the dependency but i just have any quick question to you how does a government sell a real digital independence apart from just signing with a different vendor so can you just spend a little bit more on that?
François Rodriguez
Yeah thank you marina for the question so um the uh it goes through the filters that we've just been through right so do you really have um the control where the data is uh sitting in in basically in a cloud is it sitting on premises is an hybrid setup so that's the first measure so you need to have control of those implementations the second is you can you really apply the jurisdiction, the regulation that is applicable for that specific environment? Is it government? Is it financial sector? Is it healthcare? Is it energy? So you need to as well apply the regulation that is specific to those verticals. And the third is the independency that we just mentioned before. Can you really operate? Basically, that vendor is not supporting you anymore or you're out of contract or out of support. Or, as we've seen, this vendor is deciding not to provide service to you
Maryna Veuthey
So thank you so much. So actually, it's how to avoid a vendor lock -in, right? So what questions we need to ask ourselves. So the next question will be for as we move, right, through your actually layer. I will address definitely to His Excellency Mohammed Ben Amour. You're here with us today. Thank you so much. The Secretary General of AICTO. Because, first of all, I was talking also about one of the layers, which is regulations. And normally, we say that regulations is the base, right? So let's then challenge it with you. Are you ready? So I hope so. So some member states want to kind of have a shared one, right? Due to maybe some territories issues or even budgeting stuff. So others want to have a full national control. How actually does AICTO get them to agree?
H.E. Eng. Mohamed Benamor
Thank you, Marina, for this good question. Happy to join you. Thank you real time for this MOU that we signed remotely. And as an answer, I will say that as a regional organization, Arab ICT organization addresses ICT challenge through regional convergence folks. For this question, I think that this is an issue of balance rather than choosing between two opposing countries prioritize full national control over their digital infrastructure. While others recognize the benefits of shared regional capabilities, we consider both perspectives as legitimate. The role of ICT is not to advocate for centralization. But we trust and facilitate consensus. We believe that digital sovereignty and regional cooperation can reinforce one another. Countries should receive and control over their critical infrastructure, data, and national policies while voluntarily collaborating on areas where regional action creates greater value, such as cybersecurity, AI research, digital public infrastructure, interoperability, capacity building, and shared technical standards. Arab ICT organization provides a nurtured multi -stakeholder platform where member states can jointly develop governance frameworks, common standards, and trusted cooperation mechanisms that respect national priorities while advancing common values. ultimately our objective is simple to strengthen national digital sovereignty through regional solidarity ensuring that every country benefits from collective expertise while maintaining its sovereignty decision making
Maryna Veuthey
thank you thank you so much for this full answer but i have one more question to you so yeah i know that i'm asking too many questions but this is kind of my goal for today and my job so if we talk about also the sovereignty it's one sentence what does it mean for you actually and also for your organization
H.E. Eng. Mohamed Benamor
thank you yes sovereignty means that this is the capability of one country have the full control of their data
Maryna Veuthey
Thank you so much so we we will be then switching to um topics about and around the control that right because that's something that i hear pretty often when we talk about sovereignty and um also through the capacity building exercises that we are doing and the trainings that we are delivering normally uh what we hear sovereignty is control right but um totally agree with that by the way but i think that nowadays it's really hard to balance this control and have a full control right so uh let's maybe then switch to uh some technical questions and we have an expert for that here today with us who's gonna help us also understand what are the limits of the control right from the technical perspective so today we have Gala Fall, founder and CTO of TALIS. Before I ask a question, actually we have a very nice story together, a better together story. So how we actually met, it was through the training and also the course via the ITU Academy. And that's also a good, I think, example of how capacity building activities and sharing knowledge, connecting people, right? We are not lucky. I don't know if I can say it. Sorry for that. Also connecting people, right? So quick question to you then. Actually, you've built a platform that are addressing the sovereignty question, right? And the question of control. Yeah. and my question would be platform right so government don't lose their control of their data right so this is the main goal of your platform what does a government typically not realize it's already lost control of?
Gallo Fall
lost control of it so tricky question yes it is a tricky question hello yes so thank you for the privilege of your time and I built like the digital sovereignty intelligence platform which is like a continuous unified continuous intelligence ecosystem purpose built for government ministries critical infrastructure institution that refuse to see their strategy control of their data infrastructure and AI features so this comes like out of conviction because myself like I'm a native of Senegal and I you know witness like a lot of cyber attack happening like in the global south so I build like the tool so that you know like by background in cyber security and cyber security focuses on protecting like system from unauthorized access disruption or destruction so which is largely a technical discipline then digital sovereignty is broadly strategic concept is perfectly secure do you control it and I noticed that like a lot of countries in the south they already lost control of their data and digital infrastructure because they don't know actually where they stand up they don't know their digital sovereignty posture And with this tool, I built it by mapping all the cybersecurity framework and the different sovereignty pillars. And I developed digital tools that provide KPI and report and recommendations to help these
Maryna Veuthey
governments that already lost pretty much digital sovereignty. So you scare people, right? So you're kind of like, whoa, you already lost it. So, well, the reality, right, is that digital sovereignty is actually a huge topic and super, super complex, right? But what I'm hearing is that actually the main problem comes from not knowing. Right. And I think that's. that's the main cause right we don't know where we are what do we then when we don't know where we are we don't know where we're going to do or where we're going to go what's what's going to happen next
Gallo Fall
yes you know like the frameworks tells you like what to do so your compliance is a checklist that just give you a certification certificate but what this platform does it tells you like what's happening currently okay so that you can really use it in order to mitigate like your gaps in terms of digital sovereignty and have like exactly so from where to start i think that's the main
Maryna Veuthey
The main point so where we are right now so um and what i hear from it is that not knowing where we are causes the main the main issue and for that i think that we can address um um also one question to miss tama right as the person who is actually yeah sure so to know better of where we are at right we need to have in a bit and also have this awareness right and then that's where this capacity building comes in so um i would ask you in a quick question a country can own the infrastructure right as francois explained right as galo also explained we can have the frameworks right um but a country can have the infrastructure but still not be able to run it right so we are coming from we don't know where we are okay we know where we are so how we persist further so the question would be um what does it actually take to close this gap to know how we can run it and how we can move forward
Thelma Efua Quaye
So your question is taking me back to, I don't know, maybe 10 years ago when I was running a network. I was a CTO, and the country owned an infrastructure, which can be comparable to what we are talking about now. But now, first of all, utilization was below 10%. Utilization was below 10%. For the 10% of traffic that they have, the maintenance and the service was terrible. Like you would call and you would not get anyone. So I'm just reflecting on it and reflecting on your question. And thinking what went wrong. so what I think happened was there was no investment from the government because it was not a priority and it was not a priority because the government did not understand why okay if private sector is running a backbone why should I invest in investment for instance so there was no investment but also there was no understanding of the impact of this because this was a backbone that was connecting very critical areas right again allow me to use this because I think it's very contextual to you know what we are we are saying even in the AI infrastructure that we are talking about and so how a country would move from just you said owning to running yes would be the first is you know to understand it so that you can invest understand the importance of it why do we need to invest in investment why do we need to invest in cloud as a country or serving cloud why do we need to invest in the country. And that is where, you know, our capacity building comes in, where we build their capacity for them to understand. And I do appreciate, you know, the four angles that you take them through. We are getting quite a lot of good feedback and looking forward to the next webinar later this month, right? Yeah. So it's important that they understand because a lot of them at this moment, when you talk about sovereign, for them it's just me, which has been described as completely disagreed because I don't think in this world we can be totally isolated. For me, control for a government would be transparency or sovereignty for a government should be transparency and ability to know where their data, or what their data is being used for. and having the ability to say no or yes. That should be the sovereignty. So back to how they go to run in its capacity building, for sure, investment, but also making sure that the demand exists. Four years ago, we did a tour for data centers. How can we bring about or facilitate regional data centers? And for all the countries that we went to, they had invested in what they call sovereign data centers, but utilization was low because they first went by the investment or the need to be sovereign, which goes to your point of feeling versus being. It was more a feeling to invest in the infrastructure. They invested in it, but there was no market. right so the third point would be the need to ensure the market and there's there are so many ways governments can stimulate markets right and through startups by often at we are doing now with what we call the AI factories there are so many ways to stimulate So these are the three things I think a government should do. Investment, capacity building, stimulating the market. That would take them from just owning to running the infrastructure.
Maryna Veuthey
Thank you so much, Thelma. That was really nice and very wise, by the way. That's why I really love to have women on the panel. So because advertisements are too straightforward, women get this carried approach, right? So not kind of unaware and only after care. It's more about the care. So thank you so much, Thelma, for that. And so as we are running close to small activity, right, I have one final question for you. So give me a moment, please. So. Let's imagine that a country or a vendor or any kind of out -of -the -country service or provider or whatever offered to build and run from A to Z an infrastructure or a country for free. And think through before accepting it. So Thelma please.
Thelma Efua Quaye
I can think. So, first of all, I don't believe there's anything free. That was a catch, right? There's nothing free because if you are not the one eating, you are probably being eaten. So, what the government should look through, and I like... I'd like to give an example of... something recently that happened in Ghana between Ghana, the health service and the US government where the US but the catch, so grant is free right? but the catch there was citizen data and the government said no and they cancelled it so these are the fine prints that governments need to look at first of all you need to understand there's nothing free and then you should understand that there's nothing free, what am I giving? Is it my data? Is it my sovereignty? Is it my freedom? Even if you are not giving money so it's important that governments understand what is being given and it comes back again to capacity building, they need to understand that really there's nothing right? They need to understand that data is a super mind and so if somebody comes to you to say I'll build for free sovereign data center for free ask them what is the data they are taking yes, nothing is for free at this work, right and scratch my back, I'll scratch yours and all this
Maryna Veuthey
nothing is for free at this work, right and scratch my back, I'll scratch yours and all this business stuff, whatever right, so thank you so much Telna, Francois
François Rodriguez
the floor is yours tell me though I wanted to add to what Telna just was saying, so nothing is for free for sure, but there is a business model, right, so the business model needs to be understood if it's, you know, free what I'm giving in a premium model where basically I start free, but if I basically reach a certain threshold I start in paying or is it, you know, free for a certain period and then, you know after three years or five years I start paying, so you need to understand as well what is at stake, so that's the first point The second thing is auditability. So can I audit what I'm giving? Because sometimes people are thinking it's free, but in fact everything has been pumped behind the scenes. It can be data, but it can be also IP. And these days in the AI world, we're talking about digital twin. I don't know if people are at certain points who have been given so much data that AI models can really run the same basically data sets of the whole country. Imagine that the whole healthcare data had been sucked into the AI model from ABC country, let's say Switzerland. You can replicate basically a simulation of what an infection can affect or could affect Switzerland based on the data of the citizens. So we are basically now moving into leveraging data for strategic posture, can be for benefits. but can be also for threats.
Maryna Veuthey
Exactly. So, Tata is a new oil and it has AI for good. Everything should be for good in the ideal world. But we are living in a wild world. So, thank you so much, Francois. By the way, I need to say that normally when Francois is replying to my questions, he scares me a lot. But that's not today. I kind of get used to it. It should be fine. So, Mr. Gallo, tell me, what do you think about it?
Gallo Fall
Yes, we have my… Like something especially in the global south, they have to be careful with the relationship with like the big hyperscaler or any companies that is willing to use those. You know, like if a country is telling you that I'm going to build a sovereign data center, but you need to ask like a lot of questions. What does it entail? I think that's the thing. and who controls it, who owns the data because right now there is a thirst of getting especially African data, what I call data colonization and we have to be very careful about what we hand to these powerful countries because they are actually building models pretty much to manipulate the data to their own advantage so that's why we just don't want to be subject but we have to be very realistic and make that we hand, you have to really think through it and also make sure that African nations they should start classifying their data there are certain data that you should never let leave your country things like your national ID system, your biometrics data your election rolls and you have to be very realistic about what you are saying and you have to be very realistic about what you are saying and you have to be very realistic about what I mean, all these right now, like you have like adversaries, like manipulating election to really put them in the crown jewel, leave the country.
Maryna Veuthey
Thank you so much for that. So, actually, yeah, stop being just a consumer, be a regulator, right? So, a big screen somewhere. So, thank you so much for that. And just the same question would be for His Excellency Mohammed Ben Amour.
H.E. Eng. Mohamed Benamor
Thank you. The same question, yes. Let me make the first one. It's about the question that you asked to tell me about the free gift. And this has made me thinking about the Trojan. This is... mythic history of Greek and when you get a free gift you need to think twice about why this free gift. The second one is about our program in the region. So in the Arab ICT organization we always focus on translating regional dialogue into concrete actions and we this sense we are making a lot of capacity building programs. We and our members also through technical assistance and also through helping them in regional policy development. We made a lot of initiatives like the Arab cyber security and the strategy that was made in 2023 we made the Arab AI ethics pact which was made one year these are the main actions that are made by Arab organization through this activity for their members.
Maryna Veuthey
thank you so much thank you so much for that so I I can see clearly now it's it's a song by the way but I will not say it today so capacity building regulations technology so that was actually the red line of this just got five minutes left and we're gonna do in a small exercise if you were okay with that first of all can you please move to the next slide please yes so what are we going to do I have five questions to you guys Just five, not like our panelists got the tricky questions. Just five, pretty simple. And just before we start, zero question, ground question would be, who actually checked his phone in the last ten minutes? You can raise your hand. There is no judgment. There is no judgment, right? Both, even two, bingo, right? So there is no judgment, but we see that we are all actually as human beings, we are dependent of something, right? And this is a good, I think, example of the dependency that actually we have, right? Addicts, right? Well, phonetics cannot have the same consequences if you are having, like, out of the community. You have to have control of your sovereignty. But, yeah, we can say, right? So the next exercise will be super, super simple. Thank you so much for that Five questions We will raise our hands We can raise our hands like this Any way you like it Hands up If you know which country Laws Governs Your most critical government Data We have government representative here Do you know which law Actually in your country Governs the data Yes Or okay Any data One two three That's fine So raise your hand Or you can keep your hand But I will not force you to keep your hand all the time So if you could switch A cloud Or software providers With info today Can you right now switch Your software Provider or a cloud provider, any kind of contract, can you terminate in 30 days? Do you know it? Yes, you can. You can. You Switch. I'm sorry. Switch. That's a good point. I'm sorry. I'm just getting a little bit nervous when it comes to the questions. Switch. If you can terminate the contract, what do you get the data? What's the legal implication? That's what I'm asking.
Audience
If you can terminate the contract, what do you get the data? What's the legal implication? That's what I'm asking.
Maryna Veuthey
Yeah, you're right. So, and a quick question. Do you know if actually your country controls the encryption case or if it is a vendor who is? I've got a good question. I've got a good question. Yeah, so we are not freezing our hands. So, and the last one, no, not the last one. If your government has a policy on staff using public AI tools with sensitive data, do you know if it exists? Yeah. It exists. Yes. Yes, you can raise your hand or the finger in the air. The last one. So, that's also, as a tricky question, so a tricky situation, but we can count, right? And the last one. Also, we didn't touch upon it because it's a kind of, we talked about it. Last one. Hands up if post -quantum migration is already budgeted and not just discussed. I think we wouldn't want to have any hands there, right? Because actually AI right now, we are talking about AI a lot, and it's kind of everywhere, and we are getting used to it. But then there is one more animal to trade, right, is the post -quantum. So no hands. So there is no judgment, as I said. Can we move to the next slide, please? Awesome. Thank you. So for those, right, who got like four to five points, you are largely in control, right? So you are knowing what's going on, right, to the point of Gallo, who was saying, like, from where it should start, right? Two, three, you are partially there. So you are moving. That's all right. That's cool. And, well, if there is no or one, that would be real gaps to close. But that's all right. Right? So we are happy. like sovereignty, AI, post -quantum, whatever. But it's complicated, but there is no way to go. So that's why we would love to invite you as well to follow the first webinar and then also the course about sovereignty and actually how to move from the frameworks and how to start doing things, right? And with our partners, SADA, Smart Africa team, we are preparing this amazing webinar and the course. So feel free to subscribe. And I think that there will be also more with our new partners right now, AICTO. Thank you so much. In case you have any questions, we are, guys, 35. 46, I'm sorry, one minute late. And if you have any questions, feel free. We are here to answer it. Thank you. Thank you for joining the session, by the way. Thank you. Thank you all. Thank you so much for joining, for everyone who has joined online. Yeah, just
Thelma Efua Quaye
Beyond this, there are so many other courses available for policymakers across Africa, which is made for you, curated for you. You heard most of the conversations we had, you know, went back to building the capacity of policymakers so you can make the right choices. So please take the time to scan the QR code and join the SADA platform. Thank you. SADA, Smart Africa Digital Academy. Thank you.
Maryna Veuthey
Thank you so much, Thelma. And so see you there. In case you have any questions, we will be. here. Thank you so much for joining. Cheers. Thank you.

Avertissement : Il ne s'agit pas d'un compte rendu officiel de la session. DiploAI génère ces ressources à partir d'enregistrements audiovisuels ; elles sont présentées telles quelles, y compris d'éventuelles erreurs. En raison de contraintes logistiques (audio/vidéo ou transcriptions), les noms peuvent être mal orthographiés. Nous nous efforçons d'être aussi précis que possible.