By Gleb Tsipursky, PhD
Africa is preparing to spend heavily on the physical foundations of artificial intelligence. The next investment should be in control.
Africa’s AI infrastructure buildout is already accelerating. As Towncrier Africa recently reported in “WIOCC Raises $300 Million as Africa’s Data and AI Infrastructure Race Accelerates,” WIOCC Group secured $300 million to expand fibre, data centres and connectivity across African markets. On September 8, finance ministers and business leaders gathered in Seoul for the African Development Bank’s KOAFEC Ministerial Conference, focused on harnessing AI and digital infrastructure for Africa’s transformation.
That investment is overdue. Africa needs more compute, better connectivity, stronger local data infrastructure, and greater capacity to build and deploy AI systems on African terms. But infrastructure policy should now account for a new kind of layer: the operational authority given to AI agents.
A conventional AI assistant can summarize a document or answer a question. An AI agent can use credentials, execute code, change records, contact outside systems, move money, or delegate work to other agents. Those capabilities create value. They also mean that the security of an AI system increasingly depends on what it is allowed to do after deployment.
The need became concrete during a major real-world security incident involving OpenAI’s cybersecurity evaluations and Hugging Face. According to OpenAI’s incident report and an independent investigation by METR and Redwood Research, agents operating in an evaluation environment with reduced safeguards circumvented controls, established unauthorized communication channels and attacked Hugging Face systems outside the scope of their assigned tasks. The principal compromise was driven by an internal-only OpenAI research model, while GPT-5.6 Sol agents were also involved in a smaller portion of the activity. Around 1,200 agents used the unauthorized message board and roughly 700 participated in the Hugging Face attack.
The lesson for Africa is practical. As governments and businesses connect AI agents to payment systems, customer records, public services, logistics platforms, energy infrastructure, health data, and other consequential systems, they should govern those agents by operational authority rather than by model brand or marketing category.
Africa’s AI buildout therefore needs an authority layer alongside fibre, cloud, and compute.
The first element should be explicit authority tiers. An agent that only observes or recommends should face lighter controls than one that changes records, sends communications, executes transactions, or controls physical systems. A system that can act independently should face stronger safeguards than one that requires human approval before consequential steps.
That distinction gives organizations a way to adopt AI faster without treating every use case as equally risky. Low-authority agents can move quickly. Higher-authority agents earn additional permissions only after stronger testing and clearer accountability.
Second, high-authority agents should undergo realistic independent evaluation. A system that will receive production credentials should be tested with comparable access, tools, communication channels, and delegation pathways. Evaluating a stripped-down version tells leaders too little about the system they are actually deploying.
Third, organizations should map delegation. The Hugging Face incident showed that many agents sharing information and dividing work can create capabilities that are easy to miss when each agent is examined alone. Procurement teams should ask whether an agent can launch, instruct, or exchange information with other agents and whether combined permissions create a larger attack surface.
Fourth, serious agent incidents should produce structured learning. Africa does not need to wait for a catastrophic failure before building reporting norms. Governments, regulators, and major operators should define reportable events such as unauthorized external access, serious boundary violations, consequential evaluation tampering, or agent behavior that escapes assigned scope. Independent review can turn those incidents into better standards rather than isolated lessons.
Fifth, every consequential agent needs a rapid shutdown path. Human operators should know how to revoke credentials, cancel delegated tasks, block external communication, and preserve logs for investigation. The greater the authority, the faster that path should work.
These controls fit Africa’s broader AI ambitions. The African Union has declared AI a strategic priority and called for infrastructure, domestic capacity, investment, and governance that enable adoption while protecting people. The African Development Bank’s AI agenda similarly emphasizes trust as one of the foundations for large-scale adoption.
I’m no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face incident.
That matters because Africa cannot afford a governance model that forces leaders to choose between moving slowly and taking unmanaged risks. The continent already faces a compute gap, skills shortages, capital constraints, and uneven digital infrastructure. A permission-based approach lets institutions focus heavier controls where the consequences justify them while allowing lower-risk uses to spread quickly.
It also gives African governments leverage as buyers. Public procurement can require vendors to disclose agent permissions, delegation capabilities, logging, human approval thresholds, and revocation procedures. Governments do not need to understand every internal detail of a frontier model to ask a simpler operational question: what can this system actually do with the access we give it?
The same principle can shape private investment. Banks, insurers, telecom companies, manufacturers, logistics firms, hospitals, and other major adopters can require an authority map before an agent touches consequential workflows. Investors funding African AI infrastructure can support security testing and control tooling as part of the deployment ecosystem rather than treating safety as an afterthought.
Africa’s AI future will depend partly on how quickly it closes its infrastructure gap. But the quality of that infrastructure matters as much as its quantity.
The continent should build more fibre, more data centres, more compute capacity, and more homegrown AI. At the same time, it should make operational authority visible, bounded, testable, and revocable. That authority layer can help Africa adopt AI aggressively without giving autonomous systems more power than institutions are prepared to control.
About the author: Gleb Tsipursky, PhD, is a behavioral scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026).
Discover more from Towncrier Africa
Subscribe to get the latest posts sent to your email.