Much of how cybersecurity is implemented and regulated today is now shaped by new developments in artificial intelligence (AI). International standards and donor benchmarks demand AI-related risk management requirements from developing states, prompting them to adjust procurement, auditing and data-governance policies as part of their funding criteria. For many developing and underdeveloped states however, the adoption of AI-enabled security practices is not necessarily a sovereign policy choice made on equal footing. Rather, it is a process shaped by long-standing dependency on foreign infrastructure, knowledge and expertise. Drawing on dependency theory, Foucauldian governmentality, and decolonial and postdevelopment critique, this paper examines AI and cybersecurity governance in Ghana and Trinidad & Tobago. Employing qualitative data analysis from these case states (2020–2023), it demonstrates how donor-driven digital development initiatives that are designed to aid their preparedness efforts, alongside vendor-managed services, formalise national strategies around emerging technologies while deepening infrastructural and epistemic asymmetries. The paper argues therefore, that responsible AI governance in such states must move beyond standard ethics checklists to embrace epistemic plurality and regional solidarities to ensure that sovereignty is realised in practice rather than simply on paper, or through discursive rhetorics.
Jasper Uyi Egbobamwonyi-Bedaux (Wed,) studied this question.