Morocco’s strategic bet on artificial intelligence (AI) has entered a new phase with the unveiling of the "Morocco AI 2030" roadmap, which outlines significant economic and human objectives for the next four years. Among the key targets are the creation of 100 billion dirhams in added value, the generation of 50,000 job opportunities, and the training and certification of 200,000 skilled professionals. Achieving these ambitious goals, however, is intertwined with multiple challenges that extend beyond merely expanding the use of AI technologies. It also requires establishing the appropriate digital infrastructure, qualifying human resources, securing data and systems, and reducing technological dependencies.

In examining the gap between declared ambitions and the requirements for execution, "Assahifa" highlights the key features of this new roadmap and presents an analysis of Morocco’s readiness and potential challenges it may face by 2030. According to Hassan Kharrouj, a cybersecurity expert and visiting professor at Ibn Tofail University in Kenitra, the "Morocco AI 2030" plan reflects a significant transition from merely consuming digital solutions to attempting to build a national AI ecosystem. However, its success will be measured by the kingdom's ability to translate announced digital objectives into measurable and sustainable infrastructure, competencies, and projects.

Kharrouj noted that Morocco currently possesses a crucial initial foundation, which includes an expansion of fiber-optic networks, the development of data centers, and a pool of competent engineering and research talent, alongside upcoming sovereign cloud computing projects. Nevertheless, he cautioned that this foundation remains insufficient for building a competitive AI ecosystem on a large scale. He emphasized that AI requires more than just internet connectivity; it also necessitates high computing capacities, advanced processing technology, stable electrical power, secure data centers, national cloud platforms, and organized databases that comply with legal and technical standards.

Addressing the critical gaps in Morocco’s capabilities, Kharrouj, who also teaches digital marketing, underscored the necessity for a national computing capacity accessible to universities, private enterprises, and government agencies at reasonable costs. Additionally, he pointed out the need to improve the quality of public data, standardize it, and ensure its interoperability among institutions. Sustainable funding for research and development is also crucial, instead of relying solely on time-limited projects and programs.

Cybersecurity Risks Associated with AI Expansion

In tandem with infrastructure and computing capability requirements, Kharrouj warned that the increased use of AI would concurrently broaden the scope of cyber threats. He highlighted emerging risks such as the leakage of sensitive information through AI tools, model breaches, data poisoning, and manipulation of system outputs, as well as command injection attacks known as "Prompt Injection." Furthermore, these risks extend to identity theft and the production of highly convincing fake content using audio, video, and imagery, stressing that the threat does not solely originate from external attackers but can also arise from within organizations themselves.

Kharrouj illustrated this point by noting that an employee might upload administrative documents or personal data to a foreign platform without realizing that such information could leave the organization’s information system, a practice sometimes referred to as "Shadow AI." Regarding the national system's readiness to confront these threats, the expert affirmed that Morocco has made significant strides in cybersecurity, through the General Directorate for Information Systems Security, Law No. 05.20, and national frameworks for protecting information systems. However, he argued that the next phase necessitates a transition to AI-specific security measures, which include evaluating models before they are adopted, conducting continuous penetration testing, classifying applications based on their risk levels, monitoring the digital supply chain, and establishing specialized teams to respond to AI-related incidents.

Digital Sovereignty: Control without Isolation

When discussing the digital sovereignty challenge posed by the strategy, Kharrouj asserted that achieving this objective does not imply that Morocco must manufacture all components of AI independently or close its doors to international companies. Instead, it is about maintaining legal and technical control over sensitive data, where it is stored, how it is processed, and who has access to it. He believes that Morocco can achieve

As reported by assahifa.com.