arrow_back The AI Pravda
#98

Is Africa on the wrong side of AI cyber frontier?

The decisive instrument, the African exclusion, and the choices that remain

1. The instrument arrives, and the gate closes

In mid-September 2025 the AI company Anthropic caught a cyber-espionage operation that it later judged, with high confidence, to be the work of a Chinese state-sponsored group. The targets were ordinary: around thirty technology firms, banks, chemical makers, and government agencies, with a handful of confirmed break-ins. What made the case a turning point was who did the work.

The attackers tricked an agentic coding tool into believing it was running an authorized security test, and then let it run. The model carried out an estimated eighty to ninety percent of the tactical work itself. It found weaknesses, exploited them, moved sideways through the systems, raised its own access, and pulled out data, while the humans stepped in at only a few decision points. Anthropic stated the lesson plainly: a single actor with the right setup can now do the work of a whole team of skilled hackers. The United States House Committee on Homeland Security called the company's chief executive to testify.

Two months earlier, and far more quietly, a second event settled a different question. Anthropic handed its most advanced and still-unreleased model to a small group of large technology and security firms, because it judged the model could raise the odds of large AI-driven attacks and wanted its defensive value in trusted hands first. The early membership names the perimeter exactly: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, Microsoft, and Nvidia, later joined by NATO and the European Union's cybersecurity agency. No African government, operator, or university is on the list.

The first event shows what the instrument can do. The second shows who controls it. Read together, they answer the title's question before the argument has begun. What follows is how Africa got there, and what it can still do.

2. The model is now the attacker, not its assistant

For years the reassuring line was that AI helped hackers but could not replace them. That line is gone. The espionage case did not show a smarter assistant. It showed the assistant doing the job and the human watching.

The capability behind it is measurable, and the curve is steep. The United Kingdom's AI Security Institute reports that two years ago the best models could barely finish beginner cyber tasks. On expert challenges that no model could complete before April 2025, the new preview model now succeeds roughly seventy-three percent of the time. On the largest public benchmark of real-world vulnerability discovery, the same model scored above eighty percent against a prior best near twenty. A tool that finds and exploits real software flaws four times more often than before, inside a single release cycle, is the plain fact under the espionage report.

The same jump shows up outside security, which is why it is hard to dismiss as a fluke. At the 2025 world finals of the most demanding programming contest on earth, an OpenAI system solved every problem and a Google system solved most, under the clock applied to the human teams. The same general systems reached gold-medal standard in international mathematics and informatics that season. Cyber skill is one face of general reasoning, and general reasoning has stopped trailing the best humans.

3. Silicon Valley owns the locked frontier

A weapon this sharp would be less troubling for Africa if it came from many hands. It does not. The frontier that can run an espionage campaign on its own belongs to United States laboratories.

The point needs care, because the headline gap has narrowed. Chinese open-weight models now match Western quality on well-defined coding work, at far lower cost, and the broad middle of the market is genuinely competitive. The narrowing is real. It also misses the part that counts. On the four hardest reasoning benchmarks available, the leaders are all American labs, and the cyber-capable models behind the gated program are American and closed. The Chinese models that match Western quality share one trait that the gating cannot touch: they are open-weight, free to download and run by anyone, including any attacker. So the controllable part of the frontier is American and locked, and the uncontrollable part is open and already everywhere.

Money follows the same shape. In 2025 AI-related venture investment roughly doubled to about $259 billion, and three-quarters of it went to United States firms. American private investment in AI reached $285.9 billion that year, against China's $12.4 billion. The honest caveat is that the Chinese figure hides a state-led effort the private numbers never capture, so the true gap is smaller than twenty to one. The lead is a window, not a fixed state of the world. For as long as the window holds, the decisive instrument is built, owned, and rationed in one country.

4. Skilled people, power, and capital: all three are short

Suppose the gate opened tomorrow. We would see many challenges using those instruments, as running a frontier model takes three things the continent is short of: skilled people, compute and the power to feed it, and capital. Each gap is severe alone. Together they explain why the slower clock cannot be made to run faster by willpower.

Start with people, the most familiar shortage and still the worst. In the most recent country counts, the security body ISC2 put Nigeria near 8,400 cybersecurity professionals and South Africa near 57,000, against a United States workforce of about 483,000. Those figures are from 2023 and surely understate today, yet even a generous revision leaves the gap vast. Across the whole continent fewer than 300,000 professionals defend one of the world's fastest-growing digital economies, and only about eleven percent of tertiary graduates have had any formal digital training. A defensive AI tool does not run itself. It needs skilled hands to deploy, tune, and supervise it, and the instrument that lets one operator do the work of a team is most valuable exactly where teams are hardest to staff, and least reachable there for the very same reason.

Compute and power bind the next two. Africa holds under one percent of global data-center capacity while housing eighteen percent of the world's people, and the shortage of machines cannot be separated from the shortage of electricity, because the second decides the first. Almost 600 million Africans still live without power. The scale becomes concrete in one comparison: Ethiopia's entire national generation capacity is roughly 9,500 megawatts, while OpenAI's Stargate initiative alone is committed to 10,000 megawatts, more than Ethiopia's whole grid. Where capacity exists on paper it often fails in practice, and in Nigeria only a quarter of installed generation is actually available. The demand AI places on the grid is climbing fast, with global data-center power use set to double by 2030.

Capital is the sharpest gap, and the cruelest, because the same boom that builds the instrument drains the money Africa would need to answer it. United States AI firms raised about $159 billion in 2025, near four-fifths of global AI startup funding. In one quarter of that year, African AI startups raised about $14 million across five deals, roughly two-hundredths of one percent of the $47 billion invested worldwide in the same period. As global money pulls toward the United States, African founders have been pushed off international venture capital and onto domestic finance and debt. The gap on all three axes widens as the instrument that exploits it arrives.

5. The weapon is already turned on the continent

None of this is a forecast. The instrument is already turned on the continent, and it has aimed at the one part of the digital economy Africa leads the world in.

Africa's mobile-money system moves on the order of $1.4 trillion in transactions a year. It is now under direct pressure from AI-enabled fraud, with attackers using generated identities, forged documents, and synthetic biometric artifacts to defeat customer checks at scale. The numbers move one way. Deepfake-related incidents in South Africa rose more than 260 percent year on year, and in Kenya such attacks now make up nearly a tenth of all fraud attempts, even as fraud fell in the United States and Europe. The structural twist is that imported defensive tools, trained on other markets and other languages, fit local conditions poorly, so even bought capability underperforms on African ground. The weapon lands hardest on the market least equipped, so far, to answer it.

6. Shut out of the model, dependent on the vendor

Right now, Africa cannot build the instrument and must overcome many challenges to wield it. That leaves obtaining it from those who hold it, and two locks stand in the way. They are not the same kind of lock, and the difference decides what Africa can do.

The first lock is the gating of the frontier model. The controlled-access program hands the strongest cyber-relevant model only to vetted institutions drawn along a clear geopolitical line, and no African entity is inside. This is not an African failure to apply or negotiate. It is a sovereign decision by a private American company under American strategic conditions, and no policy adopted in Addis Ababa, Nairobi, or Pretoria can open it. Africa's position relative to this lock is simply to be outside it. The danger is in the timing: the gate holds only while the capability stays rare, and Anthropic itself forecasts that comparable models will spread within six to twelve months, some released with none of the safeguards that prevent misuse. The window in which the instrument is both decisive and controlled is the same window in which Africa is shut out of the controlled version while fully exposed to the loose one.

The second lock is different, and it lies with infrastructure choices. Chinese firms built much of the continent's connective tissue. Huawei alone built an estimated seventy percent of Africa's 4G networks and leads 5G across roughly thirty markets, with ZTE holding particular weight in Ethiopia and elsewhere. African states chose those vendors deliberately, and the choice was rational on the terms of the 2010s, when Chinese suppliers offered competitive equipment, faster build-out, and financing that Western rivals would not match. Nothing in that calculation was foolish. The single variable that now makes it costly, a gated frontier instrument that turns a supplier's national alignment into a defensive liability, did not exist when the contracts were signed. Unlike the first lock, this one was chosen, which means it can be revisited.

7. The only response that fits the window

The danger is immediate, not chronic, and that fact governs every honest answer. The builders forecast wide proliferation of new cyber threats within 6 to 12 months. The deficits in people, power, and capital are the work of years to close. Two clocks run at once on different scales, and Africa's exposure is the distance between them.

This is the sentence I am reluctant to write, because it indicts a great deal of well-meaning policy: a ten-year AI education plan, a sovereign-compute build-out, a homegrown frontier laboratory, each worth pursuing on its own merits, is an evasion when offered as the answer to this threat, because it answers a slower question than the one actually posed. The deserving counterargument is that without sovereign capacity Africa stays dependent forever, and that dependence is its own danger. That is true, and it is not a reason to lose the next year waiting for a capacity that cannot arrive in time. Both can hold.

The continent shall enter threat-intelligence sharing with bodies already operating at scale, an extension of the coordinated enforcement that has already dismantled thousands of fraud operations on timelines of months. It can adopt the safety and governance frameworks that European institutions, themselves inside the trusted perimeter, have already written, rather than spend years drafting its own. And it can open partnership talks with the laboratories and corporations that hold the frontier instrument, the hardest track, which the first two earn it the standing to attempt.

The argument has been hard and the conclusion is not soft. Africa cannot out-build the threat in the time it has, so it must use other's solutions for now, through partnerships within reach, and without the posture of a petitioner. Here is the part that the gate-keepers tend to miss: the fraud described in chapter five is not only Africa's wound, it is Africa's leverage. A continent of more than a billion people, on the front line of the attacks these systems enable and holding behavioral data no laboratory can gather from outside, sits on exactly what the defenders need to make their tools work on this ground. It comes to the table with something to sell, not a cup to fill. The window is narrow and it is closing, and what Africa makes of it will be decided by Africans, while there is still a table to join.

Mikael Alemu Gorsky

Mikael Alemu is an educator and researcher, and the author of two programs: Agentic Software Engineering, on building software with AI agents, and Building AI-Native Agentic Systems, on building software that thinks.

He teaches at the Holon Institute of Technology, near Tel Aviv, where Agentic Software Engineering runs as a credit-bearing course. He is an educator and researcher.

Nine published works, 76 citations. A 350-page textbook under contract with a major academic publisher.

Teaching and programs

Agentic Software Engineering — program, preprint and textbook

The discipline of structured, auditable human-agent workflows for building software. The human frames, specifies and judges. The agent executes. Nineteen modules in four parts, built on a running project called Tribunal, a web application in which agents argue opposing sides of a case and a judge agent decides. Taught for credit at the Holon Institute of Technology.

Agentic Software Engineering curriculum

Building AI-Native Agentic Systems — program, paper and book in writing

How to build systems that hold a language model as a working component, and treat that component as what it is: stochastic, slow and metered. Fourteen modules in four parts, about seventy hours. The running project is the Observatory, a news agency that watches sources, selects what matters and publishes on a cadence.

Research and analytics

Publications — journals and proceedings

Nine works, 76 citations. Research on artificial intelligence in education, with Ilya Levin and Alexei Semenov.

The AI Pravda — LinkedIn newsletter

Critical analysis of artificial intelligence and its effect on work and society. 5,500+ subscribers. The complete archive of 103 issues (2023–2026) is published in full at mgorsky.net/theaipravda.

Subscribe to The AI Pravda on LinkedIn

Pro bono

AI for seniors — free workshop

Helping older adults use everyday AI tools. Delivered to Russian-speaking communities in Israel.

For older adults, artificial intelligence is about preserving quality of life, maintaining autonomy, and sustaining the feeling of independence that defines dignified aging. For seniors who have emigrated, AI becomes a bridge: it can translate documents, explain official letters, help compose emails in the local language, and guide users through government websites. The workshop has been delivered to Russian-speaking communities in Israel, where participants — many of them in their 70s and 80s — discovered that AI could help them read Hebrew documents and communicate with Israeli institutions.

Startup competitions — unpaid time

Judging and mentoring early-stage ventures. Helping teams clarify their value proposition, assess technical feasibility, and prepare for the realities of scaling an AI product.

AC/VC LinkedIn group — community

A group for developers and students working with coding agents. The community shares practical insights, code examples, tool comparisons, and honest assessments of what works in production.

Join the AC/VC LinkedIn group

Recent

Important Links