By Nafiul Ahmad Rafi, Director of Policy Research · Published by the Atlas Institute for Global AI Governance
Atlas Global South AI Policy Framework
A Development-First Reference Architecture for Digital Sovereignty and Technological Self-Determination.
Over 80% of the world's population resides in the Global South, yet the architecture, infrastructure, and standards of AI are monopolized by a handful of high-income corporate ecosystems. The AG-SAIPF is an actionable, legally precise model framework designed for low- and middle-income nations to reject passive technology dependency and assert data sovereignty.
What it is: AG-SAIPF is a model AI governance framework built specifically for low- and middle-income countries in the Global South, not a copy of EU/US regulation.
Author: Nafiul Ahmad Rafi, Director of Policy Research, Atlas Institute for Global AI Governance.
Published: Version 1.0, June 2026, under a Creative Commons Attribution 4.0 International License.
Core idea: Treats AI governance as an instrument of economic development and digital sovereignty, not just risk mitigation.
Structure: 14 sections plus appendices — institutional architecture, risk classification, data sovereignty, economic transformation, public sector AI, safety, monitoring, and a readiness-gated implementation roadmap.
The emergence of artificial intelligence as a defining technological, geopolitical, and macroeconomic force of the twenty-first century presents an unprecedented structural choice for the Global South. Nations across Africa, the Asia-Pacific, Latin America and the Caribbean, and the Middle East and North Africa collectively encompass over 80% of the global population. Yet the architectural design, market capitalization, and governance standards of AI remain concentrated within a minimal cluster of high-income jurisdictions and hyper-scale corporate actors.
The Atlas Global South AI Policy Framework (AG-SAIPF) addresses this structural asymmetry. It rejects the uncritical adoption of high-income, high-infrastructure regulatory frameworks that criminalize local innovation through excessive compliance costs. Instead, this framework establishes a Development-First Paradigm, wherein technological self-determination, digital sovereignty, and human development are unified into a single operational roadmap.
Purpose, Scope & Jurisdictional Adaptability
The AG-SAIPF is engineered as an adaptable reference architecture for deployment by national governments, regional economic communities (RECs), and multilateral development banks. It provides legally precise, modular policy provisions designed to be converted directly into national statutes, decrees, or regional treaties.
Recognizing the highly disparate digital maturity across low- and middle-income countries (LMICs), this framework does not mandate uniform compliance. Rather, it establishes progressive implementation thresholds calibrated directly to a nation's foundational digital public infrastructure (DPI) and available fiscal space.
Acknowledgements
This framework updates and synthesizes global instruments to align with the socioeconomic realities of developing economies, specifically incorporating standards from:
The UNESCO Recommendation on the Ethics of Artificial Intelligence (2021)
The UN Global Digital Compact (2024)
The African Union Digital Transformation Strategy (2020–2030)
The ASEAN Guide on AI Governance and Ethics (2024)
The operational insights of the World Bank's GovTech Global Partnership and the United Nations Development Programme (UNDP) digital registry frameworks
Comprehensive Glossary of Statutory Terms
Artificial Intelligence System (AI System)
A machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
Asymmetric Value Capture
The structural economic dynamic wherein raw data is extracted from local populations by external entities without equitable compensation, processed into proprietary models abroad, and sold back to the originating market at premium pricing.
Compute Sovereignty
The independent national or regional capacity to access, possess, and manage the physical hardware, processing units (GPUs/TPUs), and energy resources required to execute advanced algorithmic workloads without unilateral foreign interruption.
Data Extractivism
The non-reciprocal harvesting of sovereign national data assets, linguistic corpora, and cultural registries by external actors to train commercial algorithmic models without explicit state or community authorization.
Digital Public Infrastructure (DPI)
The open, secure, and interoperable digital platforms — specifically encompassing digital identity verification, unified retail payment systems, and secure data exchange layers — that serve as the foundational architecture for a digital economy.
Local Language AI Ecosystem
The technical infrastructure, including curated tokens, clean multilingual parallel corpora, and specialized base models, required to ensure that algorithmic systems perform with equal accuracy, safety, and contextual nuance in non-dominant, indigenous, and national languages.
Sovereign Data Commons
A legally protected, state-facilitated repository of non-personal, anonymized public sector, agricultural, health, and environmental data secured for domestic research, public utility application, and local enterprise development.
I.
Section I
Executive Summary
1.1 Strategic Vision
The Atlas Global South AI Policy Framework (AG-SAIPF) establishes an actionable blueprint for low- and middle-income countries to assert regulatory authority, secure digital sovereignty, and drive structural economic transformation through the deployment of artificial intelligence. Moving beyond purely restrictive risk-mitigation models, the AG-SAIPF treats AI governance as an active instrument of industrial development.
1.2 The Tripartite Core Problem Statement
The global AI landscape of 2026 is defined by three systemic crises that uniquely threaten the development trajectories of the Global South:
Crisis 1 — The Governance Asymmetry. Prevalent international regulatory models (e.g., the EU AI Act) assume highly advanced state machinery and formal, formalistic market structures. When duplicated in resource-constrained environments, they suffocate local tech ecosystems while failing to address immediate, localized risks like automated credit exclusion or widespread misinformation.
Crisis 2 — The Infrastructure and Compute Deficit. Advanced AI development relies heavily on hyper-scale cloud infrastructure. The concentrated ownership of this hardware exposes the Global South to infrastructural lock-in and systemic vulnerability to unilateral service termination.
Crisis 3 — The Data Extraction Paradigm. The Global South is increasingly treated as a source of low-cost data labeling labor and raw training data, while remaining excluded from the high-value layers of the international AI value chain.
Global AI Value Chain Asymmetry (2026)
Jurisdiction
Core Ownership & Control
Inputs, Labor & Dependencies
High-Income Economies
Owns 90%+ frontier models & compute infrastructure; controls global standards & commercial IP
Extracts value via asymmetric data and labor flows
Global South Jurisdictions
Dependent on foreign infrastructure importation
Provides raw consumer, health & environmental data; hosts low-cost human-in-the-loop labeling labor
1.3 Consolidated Pillars of the Reference Architecture
I
Enabling Governance
Focus: Institutional consolidation
Mechanisms: Singular National AI Commission; tiered risk architecture
II
Sovereign Assets
Focus: Asset protection & preservation
Mechanisms: Data sovereignty; Sovereign Data Commons; local language corpus preservation
III
Industrial Growth
Focus: Ecosystem expansion
Mechanisms: Public sector modernization; local compute funding; mandatory technology transfers
1.4 Immediate Action Directives for Executive Leadership
To implement this framework within a 24-month horizon, governments must execute the following structural steps:
Enact the Consolidated AI Governance and Data Sovereignty Act to establish a single regulatory authority with independent financial backing.
Implement the Digital Services and Sovereign Data Levy (DSSDL) to insulate national AI development from volatile donor-funding cycles.
Mandate the inclusion of the Sovereignty and Tech-Transfer Addendum in all public sector technology procurements exceeding 0.1% of national GDP.
Deploy the national AI Risk Classification and Readiness Assessment Tool to establish operational baselines across line ministries.
II.
Section II
Global Context & Problem Statement
2.1 The Political Economy of Geopolitical AI Concentration
The year 2026 marks an unprecedented concentration of technological power. Market capitalizations of private digital platforms driving frontier model research surpass the individual gross domestic products of multiple regional blocks in the Global South. This structural dynamic creates an asymmetric ecosystem where the digital trajectories of developing nations are determined by external corporate boards and foreign export-control policies.
The primary risk to the Global South is not a hypothetical existential threat, but a concrete economic one: the systemic loss of technological self-determination. When critical sectors like agricultural optimization, healthcare triage, and macroeconomic planning rely entirely on proprietary, closed-source models hosted in external jurisdictions, the sovereign state's capacity to govern its own economy is deeply compromised.
2.2 Deep Dive into Sectoral Deployment Realities
AI adoption in emerging markets is moving faster than domestic regulatory tracking. This rapid integration highlights both high-value opportunities and immediate vulnerabilities:
Sectoral Deployment Realities
Sector
High-Value Opportunity
Systemic Governance Risk
Agriculture
LLM-driven pest diagnostic tools; hyper-local micro-climate mapping for smallholder farmers
Total reliance on foreign soil and yield data model profiling; exploitative land financialization
Healthcare
Automated triage in rural clinics; computer-aided tuberculosis and malaria screening platforms
Diagnostic bias against local phenotypic and genomic profiles; cross-border data exfiltration
Financial Services
Alternative credit scoring data for unbanked populations
Predatory mobile lending models; black-box algorithmic redlining of marginalized communities
Algorithmic systemic bias in targeted social safety-net allocations
2.3 Deconstruction of Structural Governance Failures
The Fallacy of Direct Western Regulatory Transposition
Regulatory mechanisms like the European Union's comprehensive risk-auditing models rely on an extensive ecosystem of certified third-party legal and technical auditors. In most LMICs, this expert pool is non-existent or concentrated heavily in the private sector. Directly copying these compliance steps creates a severe regulatory bottleneck, criminalizes local open-source developers, and rewards wealthy multinational firms that can easily absorb compliance costs.
The Digital Public Infrastructure (DPI) Disconnect
AI systems do not operate in a vacuum; they require clean, real-time structured data streams. Where foundational DPI — such as unified registries, digitized land titles, and centralized health records — is fractured, AI deployment becomes highly fragile. Governance frameworks must explicitly connect AI deployment permissions to the parallel maturation of safe, open data-exchange infrastructures.
Institutional Brain Drain and Capacity Deficits
State regulatory bodies across the Global South face a continuous loss of technical talent to international markets. Frameworks that require complex case-by-case technical audits by state bureaucrats will inevitably stall out. Regulatory frameworks must favor structural, ex-ante automated guardrails over slow, human-in-the-loop bureaucratic checks.
The Extraction Matrix of Modern Data Colonialism
The continuous extraction of local data assets represents a major structural wealth transfer. Sovereign citizens generate high-value behavioral, environmental, and linguistic information daily. When external platforms capture this data without local tax liabilities, localization mandates, or domestic infrastructure investments, it entrenches an exploitative economic pattern: the systematic extraction of raw digital materials paired with the forced importation of expensive finished technological products.
III.
Section III
The Paradigm of Development-First Principles
3.1 Structural Taxonomy of Principles
The AG-SAIPF discards generic ethical platitudes in favor of actionable, enforceable principles organized into three functional tiers. Every principle must be directly tied to a specific institutional enforcement mechanism.
Priority Tiers of Development-First Principles
Priority Tier
Core Principles
Enforcement Mechanism
Tier I — Foundational Rights
Human dignity; non-discrimination; rule of law
Strict judicial review & statutory damages
Tier II — Operational Governance
Proportional transparency; safe lifecycle; sovereign privacy
Automated NAIC API compliance audits
Tier III — Developmental Mandates
Tech self-determination; local language parity; eco-balance
Procurement sourcing & compute subsidies
3.2 Tier I: Foundational Rights-Based Principles
3.2.1 Non-Negotiable Human Dignity and Sovereign Jurisdiction
The deployment of any AI system must operate under the absolute primacy of local constitutional rights and international human rights law. No operational directive, corporate terms-of-service, or foreign regulatory designation can override the legal jurisdiction of the domestic state to protect its citizens from automated degradation, physical harm, or systematic civil rights violations.
3.2.2 Algorithmic Equity and Contextualized Non-Discrimination
AI systems must be audited against local demographic, socio-economic, and cultural baselines. The simple absence of explicit bias within a model's Western-centric training dataset does not constitute compliance. Systems deployed in consequential domains must actively demonstrate that their error rates do not disproportionately impact historically marginalized communities, low-income groups, or specific linguistic demographics within the importing country.
3.2.3 Enforceable Liability Chains and Rule of Law
The shield of "proprietary complexity" is legally invalid. Every deployment of an AI system must map to a clearly designated local legal entity. In cases of systemic algorithmic failure, predatory pricing, or discriminatory exclusion, the liability chain must extend clearly from the domestic deployer through the distribution channel to the primary model developer, ensuring accessible legal recourse for affected citizens.
3.3 Tier II: Operational Governance Principles
3.3.1 Risk-Proportional Transparency and Explainability
The demand for explainability must be directly proportional to the system's potential for harm. Entertainment or low-risk retail applications require minimal, automated disclosures. Conversely, automated systems making decisions about public freedom, healthcare access, employment opportunities, or financial credit must provide clear, localized, non-technical explanations detailing the data inputs, algorithmic weightings, and specific logic driving the output.
3.3.2 Ex-Ante Technical Safety and Infrastructural Resilience
AI systems running critical national functions must exhibit structural resilience against adversarial attacks, data corruption, and connection dropouts. In areas with inconsistent connectivity, systems must feature functional, low-compute offline modes, ensuring that a disruption in external cloud access does not paralyze localized public services.
3.3.3 Sovereign Privacy and Localized Data Governance
Personal data collection by algorithmic systems must adhere strictly to minimization principles. De-identification and anonymization must happen directly at the local edge collection point. Strategic national data assets — such as genetic profiles, geological surveys, and localized agricultural maps — cannot be transferred out of country without explicit written authorization from the consolidated regulatory authority.
3.3.4 Multi-Stakeholder Inclusive Participation
The creation of AI technical standards must not be monopolized by metropolitan elite centers or tech industry trade groups. Regulatory advisory panels must maintain a mandatory minimum 40% composition representing regional universities, rural cooperatives, civil society actors, and local software engineering bodies.
When an AI application demonstrates a clear, verifiable contribution to national development objectives (such as reducing maternal mortality or optimizing water distribution during droughts), the regulatory authority is empowered to grant conditional operational waivers on standard compliance overhead. This ensures that administrative procedures never block high-impact, life-saving local innovations.
3.4.2 Technological Self-Determination and Compute Autonomy
Nations possess the inherent right to build independent technological capacity. The state must actively pursue diversified technology-sourcing strategies, support open-source architectures, and construct sovereign compute infrastructure to resist external technological monopolies or geopolitical blackmail.
3.4.3 Ecological Balance and Sustainable AI Industrialization
AI infrastructure planning must align with long-term climate adaptation strategies. The authorization of high-compute data centers is contingent on the integration of sustainable cooling architectures, localized renewable energy micro-grids, and concrete commitments to zero-waste electronics recycling. This prevents the Global South from becoming an energy-drained hosting ground for external processing demands.
4.1 The National AI and Data Sovereignty Commission (NAIC)
Rather than fragmenting scarce oversight resources across separate councils and regulatory units, states must establish a single National AI and Data Sovereignty Commission (NAIC). This commission operates as a politically independent, structurally unified statutory body under executive branch oversight, with long-term financial backing secured by the Digital Services and Sovereign Data Levy.
NAIC Structural Composition
Central Authority
Specialized Sector Desks
Embedding & Alignment
NAIC Central Directorate: strategy coordination; enforcement & audits; international treaties; registry management
Health Desk — embedded inside the Ministry of Health (MoH); Agricultural Desk — embedded inside the Ministry of Agriculture (MoA); Financial Desk — embedded inside the Ministry of Finance (MoF)
Embedded regulatory oversight with unified enforcement standards
Operational Sectoral Desks
The NAIC does not attempt to centrally manage every specialized industry. Instead, it embeds dedicated technical units directly into existing regulators and line ministries:
The Health AI Desk (embedded within the Ministry of Health) oversees diagnostic safety, medical data anonymization, and clinical validation.
The Agricultural AI Desk (embedded within the Ministry of Agriculture) manages environmental registries, drone deployment codes, and smallholder data co-ops.
The Financial AI Desk (embedded within the Central Bank) regulates credit scoring, algorithmic micro-lending consumer protections, and automated fraud-detection transparency.
Parliamentary and Judicial Accountability Infrastructure
The NAIC must submit a comprehensive, multi-indexed operational report to the national parliament every twelve months. Concurrently, governments must establish a specialized Judicial Tech Taskforce providing structured, ongoing training to magistrates, judges, and public defenders regarding algorithmic forensics, bias identification, and data privacy case law.
4.2 Public Procurement and Organizational Mandates
Procurement as an Industrial Policy Tool
Public sector tech spending is often the largest single driver of digital economies in LMICs. The NAIC mandates that all state technology tenders exceeding a specified budgetary threshold integrate the following explicit legal requirements:
Sovereign Edge Deployment: The vendor must ensure the system can run locally or within designated regional cloud nodes, completely insulated from external jurisdictional kill-switches.
Algorithmic Co-Ownership: Foreign developers must provide complete API transparency and grant state developers the right to create local fine-tuning layers, which remain sovereign intellectual property.
Compulsory Knowledge Sharing: Tenders must include a mandatory line item dedicating at least 15% of the total contract value to funding research fellowships at domestic public universities.
Full-time resident Data Sovereignty Officer; mandatory local language accessibility validation
Domestic Micro & SME Startups
Annual self-directed compliance check-ins; access to zero-cost regulatory sandboxes
Automated online compliance registration; exemption from complex third-party legal audits
4.3 Complete AI System Lifecycle Management
AI System Lifecycle Phases
Phase
Core Objective
Compliance & Safety Protocols
1. Design
System architecture
Bias assessment; corpus checks
2. Validation
Pre-deployment testing
Sandboxed adversarial testing (red-teaming)
3. Operation
Live production monitoring
Automated incident telemetry reporting
4. Decommission
System end-of-life
Secure data purging; safe asset migration
4.4 Regional and International Tier: Pooled Sovereign Capacity
Regional AI Regulatory Clearinghouses
Member states can pool tech resources to form unified regional clearinghouses. Instead of duplicate national testing centers, a single, highly sophisticated regional center can handle deep technical model evaluations and algorithmic forensics for all participating states.
Cross-Border Sovereign Data Trusts
To counter foreign model monopolies, regional nations can link their specialized public sectors into secure Cross-Border Data Trusts. By combining anonymized regional health, weather, agricultural, and linguistic records, Global South blocks can build massive, culturally representative datasets for co-developing highly accurate regional foundational models.
Immediate operational protection against critical extra-jurisdictional system failures
Empowers the NAIC to instantly freeze remote algorithmic operations violating national laws
VIII.
Section VIII
Public Sector AI Transformation & Procurement
8.1 GovTech and AI in Public Administration
AI deployment within public administration must be governed by strict accountability protocols. While automation can optimize resource distribution and streamline public services, it must not be used to insulate administrative actions from constitutional review or eliminate direct human accountability.
Mandatory GovTech Redress Pipeline
Execution Stage
Input/Trigger Metric
System Processing Layer
Mandatory Downstream Redress Action
Stage 1 — Ingestion
Benefit application submission
Automated Eligibility Assessment Engine
Deep evaluation of citizen data arrays against entitlement baseline rules
Stage 2A — Approval
System assessment positive
Direct Benefit Disbursement Layer
Immediate token transaction routing to designated citizen accounts
Stage 2B — Denial
System assessment negative
Immutable Log Generation & Native Notice
Production of cryptographic reasoning trace; automated local language notice delivery
Stage 3 — Escalation
Triggered by Stage 2B denial
Mandatory Human Intercept Protocol
Legally binding human evaluation and final resolution within a strict 48-hour window
8.2 Priority Public Sector AI Applications
Priority Public Sector AI Applications & Guardrails
Application Domain
High-Value Development Objective
Primary Systemic Risk
Mandatory Operational Guardrail
Social Protection & Welfare
Automated eligibility evaluation; predictive fraud detection; optimization of direct benefit transfers
Strict Liability: non-waivable financial and statutory accountability metrics
Statutory administrative fines scaling up to 6% of global annual turnover
Configuration Shifts / Operational Error
Deploying Organization / Public Agency
Operational Liability: implementation failures due to human oversight omission
Mandatory deployment suspension; direct restitution processing via public funds
10.3 Adaptive Governance for Emerging High-Cap Risks
The NAIC will establish a permanent Emerging Risk Working Group to manage advanced AI developments, including large language model behavioral alignment, automated agent networks, and biosecurity risks. This unit is legally authorized to issue temporary, 90-day moratoriums on novel AI features that have not undergone comprehensive technical safety testing.
Active headcount at the NAIC; completed legal actions; resolved technical appeals
Quarterly reporting cycle
Complete resolution of administrative appeals within a 60-day window
Risk Pipeline Compliance
Total volume of logged systems; authorized vs. denied applications; active system audits
Bi-annual performance check
Zero active public-sector deployments operating outside the official registry
Systemic Inclusion Parity
ΔEO scores across regional systems; voice interaction accuracy metrics
Annual performance audit
Achievement of ΔEO <= 0.05 across all active public welfare engines
Economic Development
Share of local GDP driven by tech; number of funded startups; value of software exports
Annual economic survey
Minimum annual ecosystem expansion rate of 15% across domestic tech hubs
Data Sovereignty Status
Volume of local computing infrastructure; logged DEL entries; active DPA investigations
Bi-annual infrastructure check
Minimum 75% local computing data residency for all public utility paths
11.2 Annual Transparency Reports and Independent Auditing
The NAIC will compile and present an Annual AI Governance Review directly to parliament, published openly in machine-readable formats and including all KPI metrics, system registries, and incident histories.
Every five years, the framework will undergo a comprehensive Independent Evaluation conducted by an external panel of technical experts, human rights organizations, and community representatives. The panel's findings will be used to update and adjust the national AI strategy.
XII.
Section XII
Phased Implementation Roadmap
12.1 The Gated Capability-Based Milestone Protocol
Gated Capability-Based Milestone Protocol
Progression Tier
Baseline Activation Threshold
Transition Gateway Target
Authorized Regulatory Scope
Phase I — Foundations
Baseline entry status (ARI < 40)
Cumulative score exceeds ARI 40
Development of foundational legal acts, baseline registry setup, and primary agency formation
Phase II — Capacity Building
Moderate status (40 ≤ ARI ≤ 70)
Cumulative score exceeds ARI 70
Full operational rollout of the AIA procurement protocol, SDC platform launch, and initial sector pilots
Phase III — Advanced Consolidation
Advanced status (ARI > 70)
Global Integration Gate (ARI > 85)
Enforcement of Tier V prohibitions, construction of domestic computing nodes, and regional integration
12.2 Comprehensive Phased Delivery Blueprint
Comprehensive Phased Delivery Blueprint
Operational Phase
ARI Activation Gate
Core Deliverable Focus
Mandatory Statutory Milestone
Phase I — Foundations
ARI < 40
Institutional design; creation of data protection rules; baseline registry setup
Enactment of the Foundational AI Governance Act; activation of the primary NAIC registry portal
Phase II — Capacity Building
40 ≤ ARI ≤ 70
Roll-out of the AIA protocol; launch of the SDC; setup of ethics review panels
Full deployment of the WADR procurement protocol for all major public infrastructure tenders
Phase III — Advanced Consolidation
ARI > 70
Activation of Tier V bans; funding for domestic computing hubs; regional data pooling
Direct funding for at least 50 native AI enterprises; launch of the automated incident registry
Phase IV — Sovereign Innovation
ARI > 85
Exporting native software solutions; independent 5-year reviews; international norm alignment
Achieving an adult digital literacy rate of 60%; full regional compute mesh integration
Template bilateral treaties and shared cross-border regulatory framework agreements
Appendix G — Global Alignment Reference Table
Global Alignment Reference Table
AG-SAIPF Principle / Provision
UNESCO Recommendation Alignment
OECD Principles Alignment
Human dignity and rights primacy
Value 1: Human rights and human dignity
Principle 1.1: Inclusive growth
Equity and non-discrimination
Value 4: Diversity and inclusiveness
Principle 1.1: Human-centred values
Transparency and explainability
Value 6: Transparency and explainability
Principle 1.3: Transparency and explainability
AI safety and robustness
Value 7: Safety and security
Principle 1.4: Robustness, security and safety
Accountability
Value 8: Responsibility and accountability
Principle 1.5: Accountability
Data sovereignty
Value 9: Data protection and privacy
Principle 2.2: National policy frameworks
Development-first regulation
Value 3: Fairness and non-discrimination (extension)
Principle 2.1: Investment in AI R&D
Digital sovereignty
Value 11: Multi-stakeholder and adaptive governance
Principle 2.4: International cooperation
Publication Metadata
Principal Author: Nafiul Ahmad Rafi, Director of Policy Research · Publishing Organization: The Atlas Institute for Global AI Governance · Document Version / Date: AG-SAIPF Version 1.0 | June 2026 · Legal Licensing: Published under the Creative Commons Attribution 4.0 International License.
Director of Policy Research at the Atlas Institute for Global AI Governance. Leads the development of the Atlas Global South AI Policy Framework and related national AI governance, data sovereignty, and digital public infrastructure research for Bangladesh and the broader Global South.
?
Frequently Asked Questions
AG-SAIPF at a Glance
What is the Atlas Global South AI Policy Framework (AG-SAIPF)?
AG-SAIPF is a development-first, modular AI governance framework built for low- and middle-income countries. It gives national governments, regional economic communities, and development banks legally precise, ready-to-adapt provisions covering institutional design, AI risk classification, data sovereignty, and a phased implementation roadmap, rather than asking them to copy high-income regulatory models built for very different economies.
Who authored the AG-SAIPF, and who published it?
AG-SAIPF v1.0 was authored by Nafiul Ahmad Rafi, Director of Policy Research, and published in June 2026 by the Atlas Institute for Global AI Governance (Atlas AI Institute), an independent, non-partisan research organization focused on AI governance and South-South capacity building.
Why can't the Global South just adopt the EU AI Act or similar frameworks?
Frameworks like the EU AI Act assume a deep pool of certified auditors, mature state machinery, and formal market structures that most low- and middle-income countries do not yet have. Transplanting them directly creates compliance bottlenecks that suffocate local innovation while still failing to address the region's most pressing risks, such as automated credit exclusion or misinformation.
What is compute sovereignty and data sovereignty in AI policy?
Compute sovereignty is a country's or region's independent capacity to access and control the hardware, processing units, and energy needed to run AI workloads without depending on a single foreign provider. Data sovereignty means a nation's data, including strategic public-sector, health, and agricultural datasets, stays under domestic legal control and cannot be extracted or moved offshore without explicit authorization.
What institution does AG-SAIPF recommend for AI governance?
AG-SAIPF recommends a single National AI and Data Sovereignty Commission (NAIC) rather than fragmenting oversight across multiple bodies. The NAIC is a politically independent statutory authority with its own long-term funding, supported by specialized desks embedded inside existing ministries such as Health, Agriculture, and Finance.
How is the AG-SAIPF funded without relying on foreign donors?
AG-SAIPF proposes a Digital Services and Sovereign Data Levy (DSSDL), a fixed 1.0% fiscal levy on gross domestic revenues of non-resident digital platforms and hyperscale operators. Revenue is split between sovereign compute infrastructure and human capital funding, removing dependency on volatile international donor cycles.
How does AG-SAIPF classify AI risk?
The AI Risk Classification (AIRC) pipeline sorts systems into five tiers, from Tier V (unacceptable risk, prohibited outright) down to Tier I (minimal risk, self-certified). Classification also uses a Contextual Risk Multiplier that raises a system's risk score in regions with low digital literacy, weak infrastructure, or limited legal recourse.