The problem

Telecom subscriber data - call detail records, real-time location data, and billing records - constitutes a surveillance-grade data layer that maps the behaviour, movements, and financial identity of billions of subscribers. AI systems across the Global South are now processing this data for churn prediction, fraud detection, dynamic pricing, network optimisation, and credit scoring.

In the majority of these deployments, the AI models are owned by third-party vendors. The operators deploying them cannot audit the model architecture, cannot trace what data was used in training, and cannot explain the basis of any individual decision to a subscriber or a regulator.

In Europe, this would constitute a serious compliance failure. In the Global South, it represents something more concerning: an unpriced risk that no operator is currently measuring.

The nature of the data

Telecom data falls into three categories, each with distinct governance implications:

  • Call Detail Records (CDRs) - map the social graph of every subscriber. Intelligence agencies have long recognised that communications metadata can be more revealing than content.
  • Location data - tracks subscriber movement through cell tower connections with forensic accuracy, revealing home address, workplace, travel patterns, places of worship, and medical facility visits.
  • Billing and financial records - tie identity to economic behaviour. In markets with mobile money services, this extends to a near-complete picture of a subscriber's economic life.

Combined, these constitute surveillance-grade data: a composite that maps social relationships, physical movements, and financial behaviour simultaneously.

What AI is doing with this data today

The deployments are operationally embedded and consequential. AI-driven fraud flags can disconnect subscribers from banking and government services. Credit scores built from call patterns and recharge behaviour determine access to microloans and insurance - with no visibility into how scores are generated. Dynamic pricing may effectively charge different prices based on inferred economic status. Network optimisation decisions determine which areas receive capacity investment and which subscribers experience throttling.

The regulatory gap

The EU AI Act classifies telecommunications as critical infrastructure, mandating conformity assessments for high-risk AI systems. The GDPR provides subscribers with rights to meaningful information about automated decision-making.

The Global South does not yet have equivalent frameworks. India's DPDP Act does not include AI-specific provisions. ASEAN's framework remains voluntary. Sub-Saharan Africa presents the widest gap - in markets where mobile networks are the primary infrastructure for financial inclusion, healthcare, and government services.

The critical observation: these frameworks are arriving. The question is whether operators will have built governance before it is required - or face the cost of retrofitting it after the fact.

The rip-and-replace precedent

The 5G security experience offers a direct precedent. When European governments required removal of certain 5G vendors, the cost was measured in billions. Operators who had diversified early faced a manageable transition. Those who had not faced a crisis. The parallel to AI governance is direct - operators building on models they cannot audit are constructing the same vulnerability.

The Three Sovereignty Questions

This paper proposes that meaningful AI governance in telecommunications can be assessed against three diagnostic questions. An operator that cannot answer all three does not have operational sovereignty over its AI systems.

  1. What data built this model? - A question of provenance. What data categories were used in training? Was subscriber data included? What consent basis applies?
  2. Where is inference running? - A question of jurisdiction. On infrastructure within the operator's national jurisdiction? On a hyperscaler's cloud in a different country?
  3. What did the model do in the last sixty seconds? - A question of observability. Can the operator produce a verifiable record of what the model did, to whom, on what basis?

An operator that cannot answer all three has a subscription to a capability, not sovereignty over it.

What early movers signal

Deutsche Telekom, Singtel, and SK Telecom have made strategic investments in sovereign AI infrastructure - not because a regulator forced them, but because they recognise governance is becoming a differentiator. The question for operators in the Global South is whether they will act on the same signal, or wait for regulation to force a more expensive transition.

Download full paper Discuss this research

Citation: Institute for Technology Stewardship (2026). The Unpriced Risk: Telecom AI Governance and the Data Sovereignty Gap in the Global South. Issues Paper No. 1, July 2026.
© 2026 Institute for Technology Stewardship. Licensed for non-commercial distribution with attribution.