Cybersecurity

Dilemma 06 — Artificial Intelligence: Synthetic Content, Surveillance and Staff Safety

Synthetic audio and video now target named staff and organisations. The immediate risk is reputational and physical, not abstract.

By Mowlid Ali 23 Aug 2026 9 min Cybersecurity
Source

Originally reported by ACLED (Armed Conflict Location & Event Data Project). INGO ADVISORY analysis is attributable to our intelligence desk; the underlying reporting remains the property of the publisher.

Read the original publication View all 6 citations
Listen · 4 minReady to play · about 4 min

Synthetic audio and video now target named staff and organisations. The immediate risk is reputational and physical, not abstract. This is number 6 in our standing watch list of security dilemmas, and it is written for the people who have to make a decision this week rather than for the commentary market. Our assessment is set out below against the six questions we apply to every INGO Advisory analysis.

1. What happened

The current phase of this dilemma is driven by AI-enabled influence operations and surveillance. The record we hold, drawn from ACLED event data, UN OCHA and ReliefWeb reporting, and official statements from the authorities concerned, shows sustained activity across Continental rather than a single decisive event. We do not restate casualty figures we cannot corroborate; where the record is thin we say so.

2. What is changing

The trend, at moderate to high confidence, is that the drivers behind this dilemma are becoming structural rather than episodic. Two years ago an operations manager could treat it as a background condition. It now belongs in the country risk register with named owners, review dates and defined triggers.

3. Why it matters

  • Personnel: exposure shifts from frontline areas into routine movement, accommodation and airport transfers.
  • Access: programme delivery slows through permits, escorts and route closures rather than outright refusal.
  • Assets and supply chain: lead times lengthen, insurance terms tighten and single-source dependencies surface.
  • Reputation and compliance: payments, partners and escorts create scrutiny long after the incident closes.

4. Where the exposure sits

Exposure concentrates in Continental and across Continental. We name the corridor, the port and the district in client-specific assessments; generic references to "the region" hide the decision. Organisations with staff, partners or supply chains in these areas should assume the assessment applies to them directly.

5. What organisations should watch

  • Force posture changes: new deployments, withdrawals or a change in who holds a checkpoint.
  • Administrative signals: registration reviews, visa processing times, import clearance delays.
  • Market signals: fuel availability and price, currency movement, freight and insurance quotations.
  • Information environment: network restrictions, coordinated messaging campaigns naming organisations or staff.
  • Displacement: new arrivals in an area, or a route emptying, ahead of reported violence.

6. What organisations should do

  • Re-baseline the country risk assessment against this dilemma and record the date it was done.
  • Set movement rules to the threat level below, with the authorisation level written into policy.
  • Test the crisis plan against the most likely scenario here, using the roster that would actually take the call.
  • Confirm medical, communications and relocation arrangements before tempo builds, not during it.
  • Screen counterparties, escorts and landlords; in several of these theatres due diligence is the security control.

Threat level and operational meaning

We assess this dilemma at MODERATE on the United Kingdom five-tier scale. An attack is possible, but not likely. The rating is a decision trigger, not a description: it sets the authorisation level for movement, the reporting rhythm and the review frequency.

A rating that does not change what somebody does on Monday is commentary, not risk management.

Reporting basis

This analysis was written by Mowlid Ali for INGO Advisory. It draws on ACLED event data, UN OCHA and ReliefWeb humanitarian reporting, Insecurity Insight incident monitoring, official government and UN statements, and local media in Continental, triangulated against our own field engagement. The judgement is ours and is verified against multiple independent streams; the underlying reporting remains the property of the publishers named in the citations below.

Africa Risk Brief

Get the weekly Africa Risk Brief

Analysis like this — on cybersecurity and Africa's highest-risk operating environments — delivered every Monday. Free.

No spam. Unsubscribe anytime. We never share your email.