CSA Warns Businesses On Safe AI Adoption

Tag: General news

Published On: August 25, 2026

Ghana’s Cyber Security Authority is urging businesses to weigh data-security risks as AI adoption accelerates, warning that consumer AI tools can expose company information without users realizing it.

Stephen Cudjoe-Seshie, the CSA’s Deputy Director-General, said Ghana’s AI adoption is set to accelerate sharply over the next decade and businesses need to separate using AI from using it safely. “You can use AI to improve your business,” he said, but stressed that companies must understand the safeguards attached to whatever tool their staff are using. He pointed to a common risk: an employee running internal company documents through a personal AI account, which can unintentionally push intellectual property or confidential information outside the organization’s control. The exposure is greatest at small and medium enterprises, he said, where AI tools often get adopted informally without any policy governing what employees can feed into them. His advice was direct: businesses relying on AI regularly should move to corporate accounts that come with stronger safeguards, and should read the terms and conditions of whatever tool they choose.

The warning lands as Ghana treats AI less as an emerging technology and more as national policy. President John Dramani Mahama launched the country’s National AI Strategy on April 24 at Labadi Beach Hotel, an 84-page, decade-long blueprint covering 2025 to 2035 that positions AI as a productivity tool across agriculture, healthcare, education, finance and public services. The strategy proposes a National AI Fund starting at GH¢5 billion through 2030 and scaling to GH¢15 billion by 2035, alongside a target of attracting GH¢200 billion in foreign and local private investment, and recommends establishing an independent Responsible AI Authority within its first year to coordinate implementation. Ghana currently ranks 72nd globally and sixth in Africa on the 2025 Global AI Index, behind Egypt, Mauritius, South Africa and Tunisia.

Cudjoe-Seshie flagged a structural gap behind that ambition: Ghana remains mostly a consumer of AI systems built elsewhere rather than a developer of its own. “Right now, we are mostly using other people’s models, which has its dangers,” he said, noting that systems trained largely on data from other jurisdictions may not always perform reliably for Ghanaian businesses, consumers and institutions. He argued this strengthens the case for local universities and technical institutions to build models better suited to the country’s own environment, a priority the national strategy already identifies.

Ghana’s legal framework has not fully caught up. The Data Protection Commission still operates under the Data Protection Act of 2012, though Cudjoe-Seshie said proposed reforms now under discussion are expected to account for AI. The CSA itself is preparing separately for AI-enabled threats, including cyberattacks that use the technology to speed up or sharpen their execution.

The result, he suggested, is a two-track transition: one push toward AI-driven productivity gains, and a parallel need for the security awareness, corporate policies and skills to make those gains safe.