← Insights

Governance and compliance

Governing AI use before the law arrives

8 August 2026 · 7 min read · 4 public sources

A person studying a chessboard opposite a robotic arm

Uganda’s national position on artificial intelligence is still being assembled. On 26 May 2026 the Ministry of ICT and National Guidance, with UNESCO, convened a validation workshop in Kampala for the country’s AI Readiness Assessment, produced using UNESCO’s Readiness Assessment Methodology and led nationally by Dr Joyce Nakatumba-Nabende of the Makerere University AI Lab. Among the areas it identified as needing attention were AI-specific regulation, digital infrastructure, AI literacy, and stronger data governance. Its recommendations feed the National AI and Emerging Technologies Strategy.

The existing regulator is already enforcing

On 18 July 2025 the Personal Data Protection Office decided Ssekamwa Frank & 3 others v Google LLC, complaint number 08/11/24/6683. It held that an entity established outside Uganda still qualifies as a data collector and controller where it collects personal data from Ugandan users and determines how that data is processed, ordering registration with the Office, provision of data protection officer contact details, and documentary evidence of the safeguards applied to cross-border transfers. The Office did not require approval for each individual transfer, but it did require a documented legal basis and safeguards available for inspection.

Read that alongside a typical AI deployment. A staff member pasting a customer list, a medical record, or an HR file into a hosted model is transferring personal data to a processor abroad. If the organisation cannot say which tool, which data, under what basis, and with what safeguards, the gap is in the record-keeping the regulator has already said it will inspect.

Shadow AI is a data-transfer problem, not a productivity one

  • Inventory the tools already in use before writing policy — including browser extensions, meeting transcribers, and AI features switched on inside software you already licence.
  • Classify what may never leave the organisation: personal data, credentials, client confidential material, unpublished financials.
  • Publish an approved list and, just as importantly, a rejected list with the reason, so the decision does not have to be relitigated privately.
  • Check vendor terms for whether inputs train the model, how long they are retained, and where processing occurs, and keep that assessment on file.
  • Give staff a sanctioned route that is genuinely easier than the unsanctioned one; policy alone does not compete with convenience.

Use the frameworks that already exist

There is no need to invent a governance model while the national strategy is drafted. ISO/IEC 42001, published in 2023, is the first management system standard for artificial intelligence, and covers risk assessment, impact assessment, lifecycle management, and oversight of third-party suppliers. NIST’s AI Risk Management Framework organises the same work into four functions — govern, map, measure, and manage — with governance running through the other three rather than sitting beside them. Both are voluntary, and both give an organisation a defensible answer to how a decision was made.

Keep a person accountable for the output

Where an AI system informs a decision that affects someone — a credit assessment, a shortlist, a claim — record who reviewed it, what they saw, and what they could override. That record is what turns an automated output into an accountable decision, and it is the same evidence a regulator, an auditor, or a customer will ask for.

Organisations that put this in place now are not slowing adoption down. They are making it possible to answer the questions that arrive with the strategy, rather than discovering during an inspection which tools the organisation was already using.

Sources and further reading

This article summarizes publicly available research. Source findings retain their original geographic and sector scope.

  1. [01]Government of Uganda and UNESCO validate Uganda’s AI Readiness ReportMinistry of ICT and National Guidance · 2026
  2. [02]Uganda: data protection regulator clarifies compliance requirements for offshore entitiesDLA Piper · 2025
  3. [03]Artificial Intelligence Risk Management Framework (AI RMF 1.0)National Institute of Standards and Technology · 2023
  4. [04]ISO/IEC 42001:2023 — AI management systemsISO · 2023

Put this thinking to work

Tell us about your estate and we’ll map what to build, secure, or fix first.

Keep reading

More insights