• Sat. Sep 19th, 2026

Weekend Read: When the Cloud Turns Against You

ByETimes

Sep 19, 2026 ,

Ghosts in the spreadsheet, rogue models, and the fight for data sovereignty in Africa’s AI age

By Tinotenda Bhunu and Jabulani Chibaya

HARARE – A SPREADSHEET does not look like a battlefield. It’s columns and formulas, budgets, maybe a company’s monthly expenses. It’s the kind of file people open without a second thought, because it’s so familiar it feels harmless.

So what happens when a spreadsheet turns into a command centre for espionage? What happens when an AI model, told to run a cybersecurity exercise, wanders out of its assigned environment and into real companies?

These aren’t hypotheticals anymore.

In September 2026, reports emerged that Google’s Gemini model had accessed three real companies during a cybersecurity evaluation run by Irregular in May. According to Google, the model reached systems it believed were part of its test environment. In one case it guessed credentials. In two others it found them in public repositories. It stopped once it realised these were real organisations.

Separately, Google’s Threat Intelligence Group and Mandiant documented GRIDTIDE, a backdoor tied to UNC2814, a China-linked espionage actor. The operation used Google Sheets APIs for command-and-control, blending its activity into a legitimate cloud service. Investigators identified 53 intrusions across 42 countries.

They look like stories from different worlds, one an experimental AI, the other a polished espionage campaign. They aren’t. Both show the same shift: the infrastructure of economic life is turning into the infrastructure of geopolitical power. And Africa has to decide whether it will simply consume that infrastructure or build the capacity to govern it, secure it and benefit from it.

When machines go rogue

What’s unsettling about the Gemini incident isn’t that an AI found vulnerabilities. Security professionals have been doing that for decades. It’s that machine agency is starting to close the gap between finding a weakness and acting on it.

A traditional attacker does reconnaissance, hunts for exposed credentials, tries to authenticate, tests access, decides what to do next. Every stage costs time, attention and human coordination. An autonomous agent can, in principle, do all of it at machine speed.

By most accounts the Gemini episode involved password guessing and credential discovery, not some dazzling technical breakthrough. That makes it more important, not less. Danger doesn’t always need a zero-day exploit. Sometimes it just needs an intelligent system that can search widely, connect the dots and keep testing. A weak password is weak whether a human or an AI finds it, and an exposed credential is exposed whether someone digs it out by hand or an agent turns it up in seconds.

This is where the economics of cyber risk shift. When the cost of attempting an intrusion falls, the number of attempts can rise. Defenders, meanwhile, still work within budgets, headcount and procedure. A security team might get thousands of alerts and work through them one at a time, while an automated attacker tests thousands of possibilities before the team finishes its first. The asymmetry is plain: the cost of attack scales easily, and the cost of defence stays tied to institutions.

Google’s note that the model stopped when it recognised the systems were real is somewhat reassuring about the safeguards. But it raises an uncomfortable question. What happens when a future system doesn’t recognise the boundary, misreads the instruction, or decides it has to keep going to finish its task?

“We hope the model behaves” can’t be the answer. AI systems connected to outside infrastructure need limits that are actually enforced: restricted permissions, isolated environments, constant monitoring, human escalation, and the ability to revoke access immediately. A model that can reason but can’t be reliably constrained isn’t just an impressive technology. It’s an unmanaged economic risk.

The spreadsheet that became a spy

GRIDTIDE teaches something different. The attacker didn’t have to build an obviously suspicious communication channel. The operation simply abused a legitimate cloud service.

Google and Mandiant reported that UNC2814 used a C-based backdoor that talked through Google Sheets APIs. Commands could be pulled from a spreadsheet cell, cell A1 among them, and the backdoor could alter the sheet’s contents to hide what it was doing. The campaign targeted telecommunications and government organisations in numerous countries.

The ingenuity wasn’t in inventing a new platform. It was in exploiting trust that already existed. Organisations expect Google services to talk to their systems. Cloud traffic is routine, and productivity tools are woven into daily work. A malicious instruction passing through a familiar API doesn’t look like the stereotypical attack. It’s the move from “living off the land” to living off the cloud: the attacker uses infrastructure already sitting in the victim’s own environment.

The implications are big. Traditional security imagines a perimeter, with the organisation inside, the attacker outside and a firewall in between. Cloud computing blurred that picture. APIs blurred it further. AI agents may blur it beyond recognition. The perimeter is no longer just the network edge. It’s the whole chain of identities, permissions, applications, APIs, data stores, software dependencies and automated decision-making systems.

A spreadsheet can be a command channel. A software repository can be a source of credentials. An AI model can become an operator nobody intended. The ordinary has become operational.

Africa’s digital transformation and the sovereignty question

The opportunities in Africa’s digital transformation are enormous. Mobile money has widened access to financial services. Digital platforms have cut transaction costs. Cloud computing gives businesses capabilities that once demanded heavy physical infrastructure. AI holds promise in agriculture, healthcare, logistics, education and public administration.

The African Union’s Digital Transformation Strategy for Africa 2020–2030 names digital infrastructure, skills, innovation, cybersecurity, digital identity and data protection as central to continental transformation. Its Data Policy Framework aims for harmonised governance, secure data flows and a trustworthy environment for an inclusive digital economy.

Under the optimism, though, sits a structural question: who controls the infrastructure Africa’s digital economy runs on?

A country can host a data centre and still depend on foreign companies for the cloud architecture, the software, the security tools, the AI models and the technical expertise running inside it. That isn’t automatically exploitation. Foreign technology and investment can expand productive capacity, lower costs and speed up development. But dependence becomes a vulnerability when strategic capabilities are concentrated somewhere else.

Think about what a telecom provider or a government institution holds: national identity numbers, financial records, location data, voter registration data, employment records and more. That’s not just administrative material. It maps economic relationships, social networks, patterns of movement, institutional weak spots and, potentially, political preferences. In the wrong hands it becomes intelligence. In an innovative economy’s hands it becomes productive capital. In the hands of an uncontrolled system it becomes systemic risk.

So data sovereignty can’t be boiled down to whether information is physically stored inside national borders. The deeper questions are these. Who can access it? Who controls the infrastructure? Who processes the information? Who captures the economic value? Who takes responsibility when systems fail? And can national institutions keep running if a foreign platform withdraws access or goes down? These are sovereignty questions because they’re about the ability to make decisions independently.

The future of capital is becoming digital

The next phase of global capitalism will be shaped by factories, minerals, financial markets and physical infrastructure, but also by who controls digital systems.

Capital has always followed productive opportunity. In the industrial age the advantage lay in machinery, energy and manufacturing capacity. In the financial age, information and communications became central to how capital was allocated. In the AI age, data, computing power, models and digital infrastructure increasingly decide who can produce, innovate and compete.

The chain is simple: data leads to intelligence, intelligence to productivity, productivity to investment, investment to capital formation. Whoever controls the infrastructure linking those stages can influence how economic value gets distributed.

That sets up a new kind of competition. Countries are racing for data centres, cloud investment, semiconductor supply chains, AI talent, digital payment systems and technical standards. Corporations are competing for data and computing capacity. Investors are looking at physical infrastructure and also at how resilient the digital systems behind it are.

Cybersecurity becomes part of the investment climate. An insecure financial institution faces operational losses, reputational damage and possibly higher funding costs. An insecure telecom network threatens business continuity. An insecure government database can erode public trust and impose costs on citizens and companies. A country that can’t protect its digital infrastructure may find the expected returns on digital investment shrinking.

That’s why cybersecurity should be treated as productive infrastructure, not an administrative expense. A secure system reduces uncertainty, and less uncertainty encourages adoption. Adoption creates markets, markets attract investment, and investment expands productive capacity. The economics of safety isn’t only about preventing damage. It’s about creating the conditions in which economic activity can go ahead with confidence.

Elections: the new contest over trust

The implications reach well beyond markets. Elections lean more and more on digital infrastructure. Voter registration databases, electoral management systems, political communication platforms, digital ad networks and public information channels are all potential targets.

The danger isn’t limited to flipping votes electronically. An attacker might disrupt registration, expose sensitive voter data, impersonate electoral officials, manipulate public information or simply erode confidence in the process. The goal may not be to decide who wins. It may be to convince citizens the system can’t be trusted.

That distinction matters. An election can be conducted lawfully and still be politically destabilised if large numbers of people believe its information systems were compromised. Future interference may involve less visible manipulation and more systematic attacks on confidence.

AI adds another layer. It can produce convincing false narratives, imitate voices, fabricate images and tailor messages at scale. Paired with stolen data, those tools could make political manipulation more targeted and harder to spot.

But the response has to protect democratic freedoms as well as systems. The answer can’t be unrestricted surveillance, or suppressing legitimate political speech in the name of fighting misinformation. It takes transparent electoral institutions, secure databases, independent oversight, media literacy, accountable platforms and credible ways to investigate digital interference.

The central asset here is trust. And trust, like capital, builds slowly and can vanish fast.

Cyberspace as the next geopolitical battleground

For most of modern history, geopolitical competition centred on territory, military strength, trade routes, energy and industrial capacity. Those still count. But cyberspace has opened another arena, one where states and non-state actors can exert influence without physically crossing a border.

A single cyber operation can hit a telecom network in one country, financial infrastructure in another and government systems in a third. The attacker may work through compromised infrastructure spread over several jurisdictions. Attribution is hard, retaliation is complicated, and the economic fallout can spill past the original target. All of that makes cyberspace attractive for espionage, strategic disruption and influence operations.

GRIDTIDE shows how legitimate cloud infrastructure can become part of a global espionage architecture. The Gemini incident shows how AI systems may bring new kinds of autonomous cyber risk. Together they suggest that future geopolitical competition will turn not only on who has the most advanced weapons but on who controls the digital systems economies run on.

For Africa, that’s both a vulnerability and an opportunity. The vulnerability is dependence on foreign technology stacks, thin domestic cyber capacity, and sensitive information concentrated in systems that may be hard to audit independently. The opportunity is to build capability before digital dependence becomes irreversible. African countries can work together on threat intelligence, incident response, digital identity standards, cybersecurity research and regional infrastructure. The African Union’s digital policy frameworks offer a base for that, including the aim of secure, interoperable systems that support continental integration and digital trade.

But cooperation takes more than declarations. It takes funding. It takes technical people. It takes institutions that can actually respond to incidents, universities that produce researchers and engineers, and businesses that can build locally relevant security solutions. And it takes governments willing to treat digital resilience as a national economic priority.

Zimbabwe: from digital adoption to digital resilience

Zimbabwe’s digital future won’t hinge only on how fast it adopts new technology. It’ll hinge on whether the country can secure the foundations that adoption sits on. There are real opportunities in fintech, digital public services, AI, data analytics and tech-enabled enterprise.

But digital transformation can reproduce existing institutional weaknesses if systems go in without proper governance. A slick application connected to a poorly secured database is still vulnerable. An AI system trained on unreliable information can automate bad decisions. A digital identity system without strong safeguards can concentrate risk. A cloud platform without proper access controls can give people a false sense of security.

The Cyber and Data Protection Act gives Zimbabwe a legal foundation for protecting personal information and regulating how data is processed. The challenge is making sure institutional capacity, technical implementation and accountability keep up with the pace of change. That means investing in computer incident response teams, local threat intelligence, cybersecurity education, public-private information sharing and resilient critical infrastructure. It also means building a culture where reporting a vulnerability is encouraged, not treated as an embarrassment to be buried.

A country can’t build digital trust by pretending breaches won’t happen. It builds trust by showing that when failures do happen, its institutions can detect them, respond openly and recover.

The economics of safety: seven priorities

Africa’s digital strategy should be guided by a handful of practical shifts.

First, from perimeter security to identity security. Assume systems will eventually face intrusion attempts, and protect access privileges, critical transactions and sensitive identities accordingly.

Second, from data localisation to real data sovereignty. Know not only where data is stored but who controls the infrastructure, who processes the information and who captures the value.

Third, from compliance to resilience. An organisation can pass an audit and still fail in an attack. Continuous testing, recovery planning and incident-response capability are essential.

Fourth, from imported intelligence to African threat telemetry. Local threats need local visibility. African institutions need stronger ways to collect and share intelligence on attacks hitting the continent.

Fifth, from AI enthusiasm to AI accountability. Every autonomous system connected to outside infrastructure should run with defined permissions, monitoring, audit trails, human escalation and a way to revoke access at once.

Sixth, from national silos to continental cooperation. Cyber threats cross borders, so the response has to as well.

Seventh, from technology consumption to technological production. Africa won’t get durable digital sovereignty just by becoming a bigger customer of foreign platforms. It has to develop its own software, security tools, research capacity, intellectual property and infrastructure.

Conclusion: sovereignty requires capability

The ghosts in the spreadsheet and the rogue models are warnings about one underlying change. The infrastructure of modern economic life is becoming intelligent, interconnected and hard to separate from the infrastructure of power.

The future of capital will be shaped by access to data, computing capacity, digital trust and secure technical systems. The future of elections will depend partly on whether citizens can trust the information and institutions through which democratic participation happens. The future of geopolitics will increasingly be a contest over networks, platforms, identities and infrastructure, and over the ability to disrupt or protect them.

Africa can’t afford to treat these as merely technical matters. They’re economic matters, institutional matters, sovereignty matters.

The goal isn’t technological isolation. Africa benefits from global connectivity, foreign investment and international cooperation. The goal is strategic interdependence: open enough to participate, secure enough to protect, sovereign enough to decide, productive enough to create, resilient enough to recover. Data sovereignty without productive capacity is incomplete sovereignty. Cybersecurity without economic resilience is incomplete security. And digital transformation without institutional capability is just digitised vulnerability.

The next geopolitical contest may not start with a missile crossing a border. It may start with a compromised identity, a manipulated database, a disabled payment system or an AI agent operating beyond its intended limits. The question is whether Africa will simply react, or invest now in the capabilities that let it shape its digital future.

Because in the AI age, countries that control their digital foundations will have more say over their economic destinies. Those that don’t may find sovereignty can be given away quietly, one API, one database and one neglected vulnerability at a time.

Jabulani Chibaya is an economic analyst and commentator. Tinotenda Bhunu is an economist by profession. LinkedIn: https://www.linkedin.com/in/tinotenda-bhunu-114645208?utm_source=share&utm_campaign=share_via&utm_content=profile&utm_medium=android_app


Discover more from Etimes

Subscribe to get the latest posts sent to your email.

0 0 votes
Article Rating

Leave a Reply

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Discover more from Etimes

Subscribe now to keep reading and get access to the full archive.

Continue reading

0
Would love your thoughts, please comment.x
()
x