What does it actually mean to build digital systems that people can trust? With Digital Public Infrastructure (DPI)—the population-scale digital rails behind identity, health, and payments—becoming the backbone of modern states, how do we ensure these systems are inclusive before scaling to millions is a vital challenge.
At the East Africa Data Governance Conference in Nairobi, a panel convened by the Datasphere Initiative brought together voices from government, private sector, academia, development organizations, and civil society to address this undercurrent. . The answer to building that trust, increasingly, points to sandboxes.
The Datasphere Initiative defines a sandbox as: “a controlled learning environment designed for structured experimentation under defined governance frameworks, timeframes, and built-in safeguards to support iterative, multi-actor collaboration and evidence-based decision-making.” – Sandboxes for Digital Public Infrastructure, The Datasphere Initiative, 2026.
As framed in the Datasphere Initiative’s ‘Sandboxes for Digital Public Infrastructure Report, DPI is the digital essential services of modern societies, and trust is its most fragile layer. Sandboxes, the report argues, offer a way to stress-test that trust before it breaks at scale. What that looks like in practice, particularly across Africa, raises questions that are as much political as they are technical.
When artificial intelligence meets digital public infrastructure
The conversation around DPI has become impossible to separate from the conversation around artificial intelligence (AI). DPI systems – generate enormous amounts of structured, population-scale data as a byproduct of simply functioning. AI systems need exactly that kind of data to work. DIAL’s recently released ‘’The Convergence of AI and DPI: A Policymaker’s Guide to Aligning AI and DPI for Public Benefit’’ captures this convergence clearly: the same teams, the same agencies, the same infrastructure are now at the centre of both agendas, whether they are ready for it or not.
Put AI and DPI together, and the promise is real: more responsive public services, smarter resource allocation, and greater administrative efficiency. But so are the risks. Early AI deployments globally have shown how quickly algorithmic systems can reproduce bias, obscure decision-making, and leave people with no meaningful avenue for redress, especially when the speed of deployment outpaces scrutiny.
A timely framing of this duality is that as sovereignty agendas and the global AI race accelerate, the stakes are rising: what happens when DPI is powered by AI? Can DPI serve as a precedent or a guardrail for how AI gets governed?
This is where sandboxing becomes not just useful but necessary, primarily because governments need to be both cautious and strategic when integrating AI into DPI platforms, ensuring public services harness AI’s transformative power transparently and equitably. Rather than discovering failures at scale, after millions of people are already inside the system, sandboxes create a space to prototype AI-enabled DPI while embedding safeguards from the outset.
The lesson from early deployments is hard-won: retrofitting trust after harm has occurred is not a strategy, and accountability needs to be built in from day one.
The costs of opacity: Algorithmic risk in essential public services
Nowhere are the stakes more visible as relates to the real costs of AI-powered systems that operate without transparency or accountability, as in access to essential services.
One of our session’s discussants brought into sharp focus how Kenya’s Social Health Authority illustrates the tension. Changes in premium contribution models, reportedly informed by data-driven approaches, raised serious concerns about how individuals are categorized and whether those categorizations reflect their actual circumstances. For instance, when financial transaction data becomes a proxy for ability to pay, without adequate context, explanation, or oversight, people can quietly fall through the cracks of a system designed to catch them.
This persistent absence of transparency around how data is collected, shared, and used, or about how the system works and is interpreted, leaves no real basis for trust, or for challenge.
This is not an isolated case. Across the East Africa region, new systems of data-driven governance are being built while concerns around privacy, power, surveillance, and exclusion remain inadequately addressed. The risks are not abstract and show up in whether someone can access a doctor, receive a payment, or prove who they are. Data governance, in this light, is not simply a matter of compliance or technical standards.
It is about power, visibility, and fairness. Who decides what data matters? How is it interpreted? And who gets to question those decisions?
From technical pilots to political accountability: Building sandboxes for East Africa
As shown with the ‘Sandboxes for DPI Report,’ Africa does not yet have a DPI sandbox. That absence is itself revealing. Countries across the continent are actively investing in digital identity systems, payment platforms, and data exchange frameworks, and yet the spaces to critically test these systems before they reach scale remain limited. The result is a familiar and costly pattern: systems deployed first, governance challenges addressed reactively.
One of the most pointed questions to address, therefore, is not whether a DPI sandbox should exist, but what it would be designed to do and for whom. A sandbox genuinely grounded in public interest cannot be limited to testing technologies in isolation. It must also test governance processes. Who is involved in defining the risks? Who designs the value? What accountability mechanisms exist when things go wrong? And critically, are the benefits of experimentation flowing to the communities being tested on, or solely to the institutions running the experiment?
These are not comfortable questions. But they are the right ones and they need to be answered before the architecture is built, not after.
Sandboxes, at their best, offer a structured and time-bound environment to align innovation with accountability before harm occurs, ensuring that services are inclusive, interoperable, and secure from the ground up. Governments, developers, and other stakeholders can collaboratively explore innovations, stress-test regulatory frameworks, and surface societal impacts before full-scale deployment.
Testing before scaling is not just a technical practice, but it is also a governance philosophy. If DPI is to function as truly public infrastructure, it must be built on public interest values from the start. East Africa, sitting at the crossroads of rapid digital expansion and urgent accountability demands, may be exactly the right place to make that case.



