Enterprise AI · Zimbabwe

The governance and architecture desk for enterprise AI in Zimbabwe.

For the CIO, CTO, COO and risk officer who has to sign off. What the Cyber and Data Protection Act and the Reserve Bank actually require, section by section; which architectures survive Zimbabwe's bandwidth, power and forex realities; and a scored checklist to test your own organisation before an auditor does.

What this desk covers

Six references, one job: de-risk the decision

  1. 01

    Governance

    An eight-domain framework mapped to the Cyber and Data Protection Act, SI 155 of 2024 and RBZ prudential standards, with an accountability model and a visible FAQ.

  2. 02

    Architecture

    Three reference architectures drawn for Zimbabwe: a private AI gateway, retrieval over internal data with access control enforced at retrieval, and an agent platform with approval gates in front of core banking, ERP and SCADA.

  3. 03

    Security

    A threat model for LLM systems: trust boundaries, prompt injection, data residency, access control and vendor risk, aligned to the RBZ Cybersecurity and Resilience Guideline (August 2025).

  4. 04

    Model strategy

    Open versus hosted models, on-premises versus regional cloud, and the AI Deployment Options Matrix for Zimbabwe: residency, forex exposure, power, latency, skills, GPU access and regulator posture.

  5. 05

    Industries

    Banking, mining, telecoms, insurance and the public sector: sourced sector figures and three concrete use cases each, with the risk notes a risk committee will ask for.

  6. 06

    Briefings

    Long-form, dated and sourced: what has to be true before a bank runs an LLM, from cameras to decisions on a mine, vendor due diligence, data residency, and the National AI Strategy.

Regulatory reference

The obligations most AI projects discover late

Six that recur in every review we run. The full table, with section-level notes, is on the governance page.

Selected AI-relevant obligations for Zimbabwean enterprises. Sources linked on the governance page.
ObligationInstrumentReference
No decision based solely on automated processing with legal or similarly significant effects, unless the data subject consents or a law provides for itCyber and Data Protection Act [Chapter 12:07]s.25(1)–(2); SI 155 of 2024 s.10(3)
Personal data may not be transferred to a foreign country unless an adequate level of protection is ensured there; adequacy assessed on the nature of the data, purpose, duration, recipient country's law and security measuresCyber and Data Protection Acts.28(1)–(2); derogations s.29
Notify the Data Protection Authority of any intention to transfer or share data subjects' information outside Zimbabwe, and of any processing involving biometric or genetic dataSI 155 of 2024s.10(2)(c)–(d)
Report personal data breaches to the Authority within 24 hours (Form DP3); inform affected data subjects within 72 hours where the risk is highCyber and Data Protection Act; SI 155 of 2024s.19; SI 155 s.17(1)–(3)
Prior written approval from the Reserve Bank before implementing new technology platforms, launching digital financial services or making significant changes to ICT infrastructure; inform the Reserve Bank early about outsourcing critical functions to cloud providersRBZ Cybersecurity and Resilience Guideline (August 2025)para 6.4 "Regulatory Compliance Requirements"; para 5.12
Maintain a model register, validate models independently before production use, and give the board sight of validation results for material modelsRBZ Prudential Standard No. 02-2023/BSD Model Risk ManagementDefinitions; paras 2.1.3–2.1.5, 2.4.5, 2.4.17

Deployment reality

Three numbers that shape every architecture decision here

545,123 Mbps
Used incoming international internet bandwidth, Zimbabwe, Q3 2025 (equipped capacity 1,456,270 Mbps). Every hosted-model call leaves the country over this link.
POTRAZ Q3 2025 abridged report via Techzim, 19 Dec 2025
138 days
Consecutive days without load shedding reported by ZESA's group CEO in May 2026, with a stated target of ending load shedding by December 2026. Design for the outage anyway.
New Zimbabwe via allAfrica, 11 May 2026
3 hours
Window in which a regulated institution must report a cyber incident to the Reserve Bank. An AI system that leaks data is a cyber incident.
RBZ Cybersecurity and Resilience Guideline, Aug 2025, para 4.30

See the deployment options matrix →

Briefings

Latest briefings

  • Vendor due diligence for AI in regulated Zimbabwean sectors

    The Reserve Bank's August 2025 guideline reads as if it were written for AI vendors. This briefing turns its third-party section, the Act's processor rules and SI 155's written-contract requirement into a twelve-criterion scoring table, a list of contract clauses, and the questions that end most vendor conversations early.

    Evert Vorster · 14 September 2026
  • Data residency: where can a Zimbabwean enterprise legally run AI?

    Section 28 of the Act, the Reserve Bank's cloud paragraphs and the size of the international link all point the same way. This briefing sets out the law, the facilities that exist, a decision path drawn as a diagram, and a worked classification of a bank's data classes into hosting patterns.

    Evert Vorster · 14 September 2026
  • What Zimbabwe's National AI Strategy 2026–2030 changes for a CIO

    The strategy was approved by Cabinet in October 2025 and launched by the President in March 2026. It creates direction, bodies and a sandbox, and no legal obligations. This briefing reads it for an enterprise: what to expect, what still binds you, and five things to do now.

    Evert Vorster · 14 September 2026
  • AI in mine operations: from cameras to decisions

    A mine's model produces a physical action. This briefing draws the sensor-to-decision pipeline, states what must run at the edge given Zimbabwe's grid and links, and separates event detection (low exposure) from identification (biometric data, written consent, notification).

    Evert Vorster · 14 September 2026

All briefings →

Executive briefing

Ninety minutes with your executive or board risk committee

We walk the committee through the eight governance domains, the regulatory reference table for your sector, the deployment options that are realistic for your organisation, and the ten controls that usually fail first. You leave with a scored checklist and a one-page position on what to approve, defer and decline.