Ghana’s cyber security framework remains legally “impressive” but falls short on enforcement, institutional power and readiness for emerging threats such as artificial intelligence, according to cyber-security consultant Yaw Ansu Gyeabour.
In an interview with The High Street Journal, Gyeabour said the current Cybersecurity Act and its 2025 amendments “regulate the cyber security apparatus in Ghana”, but added, “as to whether that exists, and indeed there is an enforcement, that’s another issue.”
On AI regulation, Gyeabour warned that the law is “silent” on how to govern deepfakes, IP misuse, or data manipulation. “We must have a law that will seek to regulate the use of artificial intelligence technology in Ghana,” he said, warning it will influence elections, financial fraud and public trust.
He urged the Cyber Security Authority to be empowered to mandate posture, compel information-sharing, and co-develop standards with universities and technical institutions. “The Authority must partner other institutions of higher learning, towards that direction.”
On production of data for warrants and investigations, in his view, he noted, “in forensic, the mere data is not enough,” stressing that registries, logs, caches, and device memory are critical for post-incident analysis.
Beyond that technical concern, he highlighted structural gaps. These include,
• No legal mandate compelling institutions to adopt minimum cybersecurity posture, including financial institutions processing card data.
• No institutionalised framework for sharing attack intelligence.
• No national standards body prescribing best-practice baselines
On rising mobile money fraud, he said either systems have been compromised or insiders are leaking data, but the absence of enforceable standards is enabling complacency. “Some telecom companies are complacent because nobody is compelling them to do the right thing,” he said, calling for mandatory penetration testing and regulatory oversight.
Gyeabour noted that Ghana’s rapid digitalisation, card payments, cross-border usage, and online services, makes the country a more exposed target. “All eyes will also be on us,” he said. To keep pace, he argued, the Authority must be resourced not only to write laws but to enforce posture, set standards, and pre-empt AI-driven threats before they scale.
