advertisement
Fortinet Brings The AI Cyber Threat Home At SmartGov Summit
Africa’s public sector innovators gathered in Nairobi on 23 July 2026 for the Smart Government Summit at the Iconic Hotel, an event that has become one of the continent’s key forums for exploring how digital technology is reshaping the way governments operate. As internet access and mobile connectivity continue to expand across the region, the summit’s organisers used this year’s gathering to push a theme that is quickly becoming unavoidable for public institutions: how to secure digital government services in an age when the attackers, not just the defenders, are armed with artificial intelligence.
Fortinet sponsored this year’s summit, and the company used its platform to deliver one of the event’s more sobering sessions. Imran Chaudhrey, Fortinet’s Country Manager for East Africa, took the stage with a presentation titled “When The Machines Attack: AI & The Collapse Of Old Cyber Defence”. A talk that set out to explain why security models built for a human-paced adversary are struggling to keep up now that attackers can operate at machine speed.
The session opened with a statistic that grounded the conversation firmly in Kenya’s own digital reality. The Communications Authority of Kenya recorded 4.56 billion cyber threat events in a single quarter, a 441 per cent surge that the regulator has partly attributed to attackers weaponising artificial intelligence. For a country whose government services, financial systems and everyday commerce increasingly run on the same digital networks now under sustained attack, the figure was less an abstract industry statistic than a live warning.
advertisement
Chaudhrey framed this as the backdrop for everything that followed: with phishing, reconnaissance and deception campaigns now running at machine pace, the question is no longer just how to defend, but how to defend fast enough.
A recurring thread through Chaudhrey’s presentation was how quickly organisations have embraced AI without fully reckoning with the risks that come with it. He noted that businesses, including governments, have brought AI into their workplaces at speed, often without pausing to weigh the consequences of doing so.
To illustrate the point, he referenced a widely discussed incident involving OpenAI, in which a highly capable chatbot under test reportedly escaped its testing environment and accessed the AI platform Hugging Face. For Chaudhrey, the anecdote wasn’t really about that single event, it was a way of showing the audience how unpredictable AI systems can be, and how much risk organisations absorb when they adopt powerful new tools faster than they can govern them.
advertisement
The same appetite for speed and automation that has made AI attractive to legitimate businesses, he explained, has been picked up just as eagerly by cybercriminals. Attackers are using AI tools to scale their operations, automate reconnaissance, and exploit vulnerabilities long before human defenders can respond.
Cybercrime Has Become an Industry
Chaudhrey was direct in describing what this shift means in practice: cybercrime has effectively become industrialised. What used to be episodic, opportunistic attacks has evolved into a continuous, automated pipeline of exploitation, reconnaissance and identity theft, all running with minimal human involvement on the attacker’s side. The tools that have made legitimate businesses more efficient have simply been repurposed by criminal groups to weaponise their operations and exploit weaknesses at a scale and speed that traditional defences were never designed to match.
According to Chaudhrey, the question that matters most today isn’t how many security tools an organisation owns, but how quickly it can detect, contain and shut down a threat. He introduced “velocity” as the term now defining the state of the industry – not just the velocity at which attackers are improving, but the velocity with which defenders must respond in kind.
advertisement
This, he argued, is why automation has become non-negotiable rather than optional. Detection and containment systems need to operate at a pace that matches the machine-speed threats now targeting networks, because human-paced response processes simply cannot keep up.
Zero Trust as a Starting Point, Not an Afterthought
Chaudhrey also made the case for rethinking access control from the ground up. Rather than treating trust as a default and restricting it only when problems arise, he urged organisations to adopt a Zero Trust posture from day one, assuming no user or device should be inherently trusted, and enforcing the principle of least-privilege access as a baseline rather than a retrofit. For government institutions handling citizen data and critical services, he suggested, this shift in mindset is becoming as important as any specific technology investment.
For a summit built around accelerating Africa’s digital government transformation, the session was a fitting reminder that the same technologies powering that transformation are also being turned against it, and that the defenders who move fastest will be the ones who keep pace.