Briefing · Public sector and cross-sector

What Zimbabwe's National AI Strategy 2026–2030 changes for a CIO

The strategy was approved by Cabinet in October 2025 and launched by the President in March 2026. It creates direction, bodies and a sandbox, and no legal obligations. This briefing reads it for an enterprise: what to expect, what still binds you, and five things to do now.

Cabinet approved Zimbabwe’s National Artificial Intelligence Strategy 2026–2030 in October 2025, and the President launched it at Parliament on 13 March 2026. It was developed by the Ministry of Information Communication Technology, Postal and Courier Services with UNESCO’s support, anchored on the country’s 2025 AI Readiness Assessment under UNESCO’s methodology, and consulted in Harare, Bulawayo and Masvingo during 2025. For a CIO the useful question is not whether it is ambitious but what, if anything, it changes on Monday morning.

What the strategy contains

Pillars: talent and capacity; infrastructure and computational sovereignty; sectoral adoption across a list of industries that includes agriculture, health, education, finance and public administration; research and innovation; international engagement; and governance and ethics, with Ubuntu named as the values framework.

Phases: Foundation Building (2025–2026), Scaling Core Applications (2027–2028), and Ecosystem Maturation and Leadership (2029–2030).

Bodies: a National AI Council and an AI Strategy Implementation Office to govern delivery, and a proposed National Digital Regulatory Committee. A regulated test-and-experiment environment (a sandbox) overseen by POTRAZ is described, in which innovators can trial AI in the market without the full weight of compliance at the outset.

What it does not contain

Legal force. A Cabinet-approved strategy sets policy direction; it does not create binding obligations, and no enabling legislation for the proposed bodies has been enacted. The African Law Matters analysis of July 2026 makes the point directly and argues for an AI Act within twelve to eighteen months, a statutory regulatory committee, and procedural rights around algorithmic decisions. It also notes that the strategy publishes no budget, implementation dashboard or public accountability mechanism.

That absence matters in both directions. Nothing in the strategy stops or requires anything an enterprise does today. Equally, an enterprise cannot point to the strategy as a compliance basis for anything.

What binds you today

The Cyber and Data Protection Act (Act 5 of 2021) and SI 155 of 2024. In particular: the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects (s.25); the transfer restriction (s.28–29); written consent for sensitive, genetic, biometric and health data (s.11–12); security measures and processor contracts (s.18); breach notification within 24 hours (s.19; SI 155 s.17); data controller licensing by tier and a certified DPO (SI 155 s.4–6, s.12–13); and notification of processing, transfers and biometric processing (SI 155 s.10(2)). For banking institutions, the Reserve Bank’s Risk Management and Model Risk standards and the August 2025 Cybersecurity and Resilience Guideline apply on top. The governance page lists them with sections.

The strategy’s own analysis is consistent with this: it operates within the existing legal framework rather than replacing it.

Reading the signals

Three signals are worth taking seriously even without a statute.

Computational sovereignty appears as a pillar. Read together with the Act’s s.28, it suggests that in-country hosting for personal and state data will be the expected posture, and that public-sector procurement will favour it. An enterprise that has already built an in-country platform will be aligned with policy rather than arguing against it.

A POTRAZ-overseen sandbox confirms that POTRAZ, already the Data Protection Authority and the telecoms regulator, is the centre of gravity for AI regulation. Material prepared for POTRAZ as Data Protection Authority (the register, the notifications, the breach runbook) will be the same material a sandbox or a future regulatory committee asks for.

Governance and ethics grounded in Ubuntu points to procedural expectations around transparency, explanation and contestability of decisions affecting people. Section 25 already gives that a legal edge; the strategy suggests it will widen.

Five actions before an AI Act

  1. Put the model register in place now, with materiality ratings and owners, whether or not you are a bank. It is the artefact every version of a future regime will ask for.
  2. Inventory decisions with legal or significant effects and document, for each, whether it is automated, the s.25 basis, and the human contest route.
  3. Complete the SI 155 administration: licence tier, DPO certification, processing notifications including AI systems, transfer notifications.
  4. Decide the hosting posture in writing, using the decision path, so that sovereignty expectations are met by design rather than retrofitted.
  5. Track the legislative pipeline (the AI Act the strategy implies, POTRAZ standards under s.18(6), any adequacy determinations) and assign the DPO to brief the risk committee when something is gazetted.

The network’s research publication, zimbabweai.co.zw, tracks the policy landscape and national adoption data; this desk covers what an enterprise must do about it. The public-sector page sets the strategy beside the Smart Zimbabwe 2030 Master Plan and the ZiG procurement rules.

Sources

  1. UNESCO (25 March 2026) — Zimbabwe launches National Artificial Intelligence Strategy — https://www.unesco.org/en/articles/zimbabwe-launches-national-artificial-intelligence-strategy
  2. TechAfrica News (16 October 2025) — Zimbabwe approves National AI Strategy for 2026–2030 — https://techafricanews.com/2025/10/16/zimbabwe-approves-national-artificial-intelligence-strategy-for-2026-2030/
  3. OECD.AI — Zimbabwe National Artificial Intelligence Strategy 2026–2030 — https://oecd.ai/en/dashboards/policy-initiatives/zimbabwe-national-artificial-intelligence-strategy-2026-2030
  4. Zimbabwe National Artificial Intelligence Strategy 2026–2030 (text via Veritas) — https://veritaszim.net/sites/veritas_d/files/Zimbabwe%20National%20Artificial%20Intelligence%20Strategy.pdf
  5. African Law Matters (27 July 2026) — Strategy Without Statute: Reading Zimbabwe's National AI Strategy — https://www.africanlawmatters.com/blog/strategy-without-statute-reading-zimbabwes-national-ai-strategy
  6. United Nations in Zimbabwe — Zimbabwe unveils 2026–2030 AI Strategy — https://zimbabwe.un.org/en/311859-zimbabwe-unveils-2026%E2%80%932030-ai-strategy-advance-inclusive-digital-transformation
  7. Data Protection Act, Act 5 of 2021 (Cyber and Data Protection Act [Chapter 12:07]) — https://t3n9sm.c2.acecdn.net/wp-content/uploads/2024/11/Data-Protection-Act-5-of-2021.pdf
  8. Statutory Instrument 155 of 2024 (POTRAZ) — https://www.potraz.gov.zw/wp-content/uploads/2025/02/sI-155-of-2024-Cyber-and-Data-Protection-Normal_240913_1250178.pdf