Skip to content

Main Insight

AI rules cannot reliably protect people when compliance cannot be checked. In a new CIGI policy brief co-authored by George Gor (TFS) and Kofi Yeboah (Mozilla), AI-enabled weapons in Africa serve as a case study of how procurement and regional verification can test supplier claims, reduce risks to civilians and military personnel and impose consequences

Buyer Beware: What AI-Enabled Weapons in Africa Reveal About Verification

August 10, 2026

This article draws four lessons from Toward Verifiable Controls on AI-Enabled Weapons in Africa, a CIGI policy brief co-authored by George Gor (The Future Society) and Kofi Yeboah (Mozilla).

An AI rule is difficult to enforce if no one can check whether it is being followed. Governments may adopt commitments and companies may publish safeguards, but those claims cannot support procurement, deployment, or accountability decisions unless independent assessors can test them.

George Gor and Kofi Yeboah’s CIGI policy brief applies this wider problem to AI-enabled and autonomous weapons in Africa. Purchasing states rely on suppliers’ claims about how systems identify targets, when they withhold force, and whether safeguards remain active. If those claims cannot be tested, system failures may harm civilians and military personnel, while states may be unable to investigate, hold suppliers accountable, or meet their own legal responsibilities. The brief argues that procurement can define enforceable conditions and regional verification capacity can test compliance, allowing African states to act without waiting for a global treaty.

The Assurance Gap for AI-Enabled Weapons Is Already Present

The assurance gap already affects systems entering African markets because buyers often cannot independently verify software-enabled functions that shape targeting or force. AI-enabled and autonomous weapons create related problems, although the terms are not interchangeable. AI can support targeting without autonomous engagement, while autonomous systems need not use AI. Existing transfer-control mechanisms do not require independent verification of these functions.

A 2025 study identified 167 UAV and UCAV systems with autonomous features acquired by the African Union and nineteen African countries between 2000 and 2024. Although not a definitive count of AI-enabled weapons, the figure shows that the assurance problem is no longer hypothetical.

Political Commitments Need Testable Conditions

African commitments on autonomous weapons must translate into requirements that suppliers can substantiate. In 2025, 49 African states supported the latest United Nations resolution on lethal autonomous weapons, while the African Union Peace and Security Council requested an African common position on AI and an African Charter on AI.

These commitments do not specify what suppliers must disclose, what evidence should support claims about targeting controls and safeguards, or when buyers should suspend a system. Without such conditions, political commitments do little to prevent deployment of systems with unproven safeguards or to preserve evidence when people are harmed. The brief proposes shared procurement requirements and regional verification capacity to close this gap.

Common Procurement Requirements Can Make Suppliers Accountable

African states can use procurement to protect people by requiring safeguards before transfer and preserving oversight after deployment. SIPRI identifies procurement as a means of implementing responsible military-AI commitments. Common conditions should require declarations of autonomous functions and targeting limits, access to testing evidence, and notice of incidents or material changes. Contracts should require verification at delivery and after updates, with suspension or termination when claims fail.

Common conditions coordinated through the African Union and regional economic communities would strengthen buyers’ leverage and spread assessment costs, especially when suppliers are scarce.

Verification Capacity Can Make Procurement Conditions Enforceable

Procurement conditions can protect people only if African institutions can verify compliance, investigate failures, and act when safeguards fail. Regional assessors could examine sensitive systems through controlled access, while protected incident reporting could reveal targeting errors, unauthorised uses, and ineffective safeguards.

The African Commission on Nuclear Energy offers a precedent for pooled verification.

These measures cannot prevent every misuse, but they can reduce the risk that people are harmed by systems whose safeguards remain untested, while helping authorities investigate harm, suspend deployment, and hold suppliers accountable when assurances fail. Although the brief focuses on military procurement, its wider lesson is that AI rules are difficult to enforce unless institutions can test the claims on which compliance depends and act on the results.

For more insights, research, and expert analysis, follow The Future Society on LinkedIn.

Team members

Related resources

What compute on European soil might buy Europe and what it depends on

What compute on European soil might buy Europe and what it depends on

Across Europe, there is growing appetite for locating large compute capacity at home. This post maps what the benefits' proponents claim such a buildout might bring and the key open questions these claims stand or fall on.

The Case for Cross-Border AI Incident Infrastructure

The Case for Cross-Border AI Incident Infrastructure

AI incidents are scaling fast, and coordinated global governance is lagging behind. This report proposes addressing this challenge through the development of internationally-distributed incident management infrastructure. Our recommendations aim to enable governments, multilateral bodies, and frontier AI companies to jointly detect, prepare for, and respond to AI incidents across jurisdictions.

Determining the State of the Art in General-Purpose AI Risk Management: From Code to Practice

Determining the State of the Art in General-Purpose AI Risk Management: From Code to Practice

The EU's AI Act and Code of Practice requires providers of the most advanced AI models to meet the ‘state of the art’ (SOTA) in safety and security. In a new policy memo, we argue that SOTA is best understood as a process-driven concept, advanced by the broader expert ecosystem.

EU AI Act meets AI Agents

EU AI Act meets AI Agents

Highlights from Tech Policy Press article “The EU AI Act is Not Ready for Agents,” examining how the EU AI Act applies to AI agents and governance challenges.

Future-Proofing EU AI Gigafactories: Four Design Imperatives

Future-Proofing EU AI Gigafactories: Four Design Imperatives

The EU's AI Gigafactory initiative is its largest planned compute investment to date. Our new memo identifies four imperatives that the initiative must address to deliver on Europe's frontier AI ambitions.

EU Frontier AI Sovereignty: Beware of Geeks Bearing Gifts

EU Frontier AI Sovereignty: Beware of Geeks Bearing Gifts

Our report “Beware of Geeks Bearing Gifts: Building True EU Frontier AI Sovereignty” is the first comprehensive framework mapping Europe’s frontier AI dependencies across the five pillars of sovereignty.