
Artificial intelligence (AI) can strengthen cyber defence while also creating new dependencies on models, cloud services and external providers. This raises an ethical question that is often hidden by debates about access: is AI adoption fair when an institution receives advanced protective capability but lacks the power to test, challenge, interrupt or replace the system that protects it? This study compares the European Union and Mozambique through a structured analysis of 41 scientific, standards, legal, policy and operational sources published from 2021 to 2026. It develops the concept of assurance justice: institutions that bear AI-enabled cyber risk should also possess a fair share of the evidence, skills, authority and exit options needed to govern that risk. PROTEGE-IA is derived through explicit two-stage coding and cross-walked against the NIST AI RMF, ISO/IEC 42001, OECD AI Principles and responsible AI and ethics-assurance frameworks. The analysis shows that European institutions have deeper assurance capacity but still face external model dependence, while Mozambique has a strategic opportunity to embed assurance requirements as its cyber and AI governance structures mature. The article argues that responsible international cooperation should transfer not only technology, but also the capacity to verify, contest and replace it.