Model strategy
Where the model runs decides most of the risk
Open-weight or hosted; a server room in Harare, a colocation cage, a South African cloud region or a global API. The choice is set less by model quality than by the Cyber and Data Protection Act, forex, the international link and the grid. This page lays the options side by side.
01 · The real question
Executives are usually offered a model choice ("which LLM is best?"). The decision that matters is the hosting pattern, because it fixes four things at once: whether personal data leaves Zimbabwe (s.28), whether the bill is in foreign currency, whether the system survives an international link or grid interruption, and whether the Reserve Bank must be informed or asked first. Model choice comes after, and can change yearly; hosting pattern is hard to reverse.
02 · AI Deployment Options Matrix for Zimbabwe
| Pattern | Residency (personal data) | Forex exposure | Power and link dependence | Latency to users | Skills needed | GPU access | Regulator posture (banks) | Best for |
|---|---|---|---|---|---|---|---|---|
| On-premises (own server room) | Stays in Zimbabwe; no s.28 transfer | Capital cost in USD once; running cost mostly local | Your generator and UPS; no international link needed for inference | Lowest; works during link outages | Highest: Linux, GPU, MLOps, security | Whatever you buy and can import; small to mid GPUs realistic | Inform RBZ of new platform (6.4); no cloud outsourcing notice | Personal and sensitive classes; branch and plant workloads; SCADA-adjacent |
| Zimbabwe colocation (e.g. TelOne Mazowe, Dandemutande facilities) | Stays in Zimbabwe | Colocation fees often USD-priced; hardware USD once | Facility generator and redundancy (Tier III design claimed by operators); still inside the national grid and link | Low; Harare and Bulawayo metro | High: same as on-prem minus facilities | As on-prem | Third-party outsourcing due diligence (5.3–5.7); RBZ informed if critical (5.12) | Institutions without a modern server room; shared platform for a group |
| Regional cloud (Cape Town: AWS af-south-1, Azure South Africa West; Johannesburg: Azure South Africa North, Google Cloud africa-south1) | Transfer to South Africa: s.28 adequacy assessment and SI 155 s.10(2)(c) notification required | Recurring USD or ZAR billing; hedge needed | Depends on international link (Zimbabwe used 545,123 Mbps incoming, Q3 2025); no local power dependence for the service | Moderate; regional round-trip | Medium: cloud, IAM, MLOps | Good; Johannesburg regions publicly list accelerator capacity | Cloud outsourcing of critical functions: inform RBZ early (5.12); jurisdictional risk and data-protection clauses (5.13) | Non-personal classes; burst; disaster recovery for in-country platform |
| Global cloud (EU, US regions) | Transfer; adequacy or s.29 basis and notification; sensitive data written consent (s.11–12) | Recurring USD | International link; longer path | Higher; intercontinental | Medium | Best availability of frontier accelerators | As regional plus stronger jurisdictional scrutiny | Research, non-personal workloads, model training on synthetic or public data |
| Hosted model APIs (frontier providers, wherever they run) | Transfer of every prompt; redact first; s.29 basis documented | Recurring USD per token; forex exposure scales with usage | International link for every call | Variable | Lowest to start; governance effort highest | Not your concern | Vendor due diligence, licensing and sanctions screening (6.4(b)); contract clauses (5.6) | Frontier quality on non-personal or redacted classes, behind your gateway with a budget |
Note for the CIOMost institutions end with two patterns, not one: an in-country platform (on-prem or colocation) for anything touching personal data and plant systems, and a hosted frontier model behind the gateway, redacted and budgeted, for the rest. The gateway architecture is what makes the pair governable.
03 · Open-weight versus hosted models
| Dimension | Open-weight (run yourself) | Hosted (API) |
|---|---|---|
| Data residency | Solved by location | Every prompt is a transfer; needs basis, redaction, notification |
| Quality ceiling | Strong for retrieval-grounded tasks, classification, extraction, summarisation; frontier reasoning lags | Highest on open-ended reasoning and long context |
| Cost shape | Fixed: hardware, power, people; marginal cost per query near zero | Variable: per token in USD; predictable only with budgets |
| Change control | You pin versions; PS 02-2023 validation is repeatable | Provider changes models; re-validation triggered by vendor, not you |
| Outage behaviour | Runs through link outages if in-country | Unavailable when the link or provider is |
| Vendor risk | Provenance of weights; support model | Full third-party regime (Guideline section 5); sanctions screening |
| Skills | MLOps and GPU operations in-house or via a local partner | Integration and governance skills |
04 · Cost model (illustrative)
An illustrative comparison, not a quote. Assume an institution with 400 knowledge workers each making 30 model calls a working day, averaging 2,000 input and 400 output tokens, 250 working days: about 3 million calls and roughly 7.2 billion tokens a year. Figures below are placeholders you replace with your own vendor quotes and hardware prices; the shape of the result is what matters.
| Line | In-country open-weight | Hosted API | Comment |
|---|---|---|---|
| Hardware (2 GPU servers, storage, network), once | H | 0 | USD capital, importable; depreciate over 3 years |
| Colocation or power and cooling, per year | C | 0 | Often USD-priced locally |
| People (2 FTE platform and MLOps), per year | P | P/2 | Hosted still needs governance and integration staff |
| Per-token fees, per year | 0 | T × 7.2bn | T = blended price per token from the quote; grows with usage and is fully forex-exposed |
| Compliance work (adequacy, notification, redaction) | low | high | s.28–29, SI 155 s.10(2)(c), RBZ 5.12–5.13 |
| Three-year total | H + 3(C + P) | 3(P/2 + T × 7.2bn) | Break-even token price T* = (H + 3C + 1.5P) ÷ 21.6bn |
The break-even line is the useful output: at the workload above, the in-country platform costs less whenever the blended hosted price exceeds T* per token. Put your own H, C and P in and the decision is a single comparison. Two Zimbabwean adjustments push the answer towards in-country: hosted fees are recurring foreign currency, which after the Reserve Bank's 2025 receipts of about US$16 billion is available on the willing-buyer willing-seller market but not free of friction, and hosted calls are unavailable during international-link incidents.
05 · A decision rule the board can apply
- 01
Classify the workload's data
Personal, sensitive (s.11), genetic/biometric/health (s.12), commercial-confidential, operational, public.
- 02
Personal or sensitive → in-country
On-prem or Zimbabwe colocation, open-weight models. Regional cloud only with a documented adequacy assessment and notification; global APIs only with redaction and a s.29 basis.
- 03
Operational and plant → in-country and local to the site
Edge inference where the link or grid can fail; see the mining page.
- 04
Everything else → best quality within a forex budget
Hosted frontier models behind the gateway, per-identity budgets, monthly reporting to the model risk pack.
- 05
Banks: sequence the regulator
Inform the Reserve Bank early on cloud outsourcing of critical functions (5.12); obtain prior written approval before implementing the platform (6.4); enter every model in the register (PS 02-2023).
Sources
- Data Protection Act, Act 5 of 2021 (Cyber and Data Protection Act [Chapter 12:07]) — s.11–12, s.28–29
- SI 155 of 2024 — s.10(2)(c)
- RBZ Cybersecurity and Resilience Guideline (August 2025) — paras 5.3–5.14, 6.4
- POTRAZ Q3 2025 abridged sector performance report via Techzim (19 December 2025) — international bandwidth 545,123 Mbps used incoming; 1,456,270 Mbps equipped
- The Zimbabwean (17 March 2026) — RBZ governor on ~US$16 billion foreign currency receipts in 2025 and the willing-buyer willing-seller market
- AWS — Africa (Cape Town) region, af-south-1; Google Cloud africa-south1 (Johannesburg); CIO — Azure South Africa North (Johannesburg) and West (Cape Town) regions
- Data Center Map — TelOne Mazowe Data Centre (Tier III design); DCD — Dandemutande plans US$15m data centre
- New Zimbabwe via allAfrica (11 May 2026) — ZESA on ending load shedding by December 2026