Introduction on Fragmented AI Governance in Kenya
I approach the current Artificial Intelligence Bill in Kenya against the background that, until now, the country has not had a single, dedicated AI law in force. Instead, I see AI governance as having been fragmented across existing statutes such as:
- The Data Protection Act, 2019, which safeguards personal data and limits automated decision-making;
- The Computer Misuse and Cybercrimes Act, 2018, which secures digital infrastructure; and
- The Consumer Protection Act, 2012, which protects users of digital products.
These are complemented by soft-law instruments like the Kenya ICT Policy Guidelines 2020 and the National AI Strategy launched in March 2025, all of which collectively form a policy-driven, rather than statute-driven, framework for AI regulation in Kenya.
The AI Bill and it’s features
Turning to the Artificial Intelligence Bill, 2026, I see it as Kenya’s first serious attempt to consolidate this fragmented regime into a comprehensive legal framework.
- The Bill defines artificial intelligence broadly as technology that enables machines or systems to perform tasks that typically require human intelligence, such as learning, reasoning, decision-making, and pattern recognition.
- It then adopts a risk-based approach to its regulation, bringing into scope developers, deployers, and users of AI systems across sectors.
- It establishes the Office of the AI Commissioner as the central regulatory authority with powers to classify AI systems, approve their use, and maintain oversight through a public register, alongside an advisory committee to provide technical and policy guidance.
- It also provides for financial provisions to operationalize the regulatory framework.
- It sets out governance principles such as transparency, accountability, and human oversight, and introduces compliance obligations and penalties to enforce responsible AI use.
In my view, these features mirror Kenya’s ambition to transition from a policy-led approach to a binding regulatory system that reflects its status as a growing tech hub, often described as Africa’s “Silicon Savannah,” where AI is already embedded in sectors like agriculture, finance, and healthcare.
International influence
I also see the Bill as heavily influenced by international models, particularly the EU AI Act, with its emphasis on a risk-based classification of AI systems and strong requirements on transparency, data governance, and human oversight, as well as broader OECD principles on trustworthy AI. Ultimately, I interpret the Bill as Kenya positioning itself within global AI governance trends while tailoring regulation to its local innovation ecosystem, treating AI not just as a risk to be controlled, but as a strategic technological tool to drive economic growth and digital transformation.
Gaps and Risks
However, I find the Bill somewhat vague in clearly identifying and prohibiting high-risk or harmful AI practices. Unlike the EU AI Act, which expressly bans practices such as manipulative AI, exploitation of vulnerable groups, social scoring, and certain forms of biometric surveillance, the Kenyan Bill does not explicitly outline such prohibited uses. In my view, this lack of specificity may create regulatory gaps, particularly in addressing risks related to discrimination, privacy intrusion, and misuse of AI in sensitive contexts.
Recommendations
I recommend Kenya refine its AI Bill by balancing innovation with clear safeguards, drawing from the U.S.’s flexible, sector-based approach and the U.K.’s principles-based framework, while aligning with the OECD AI principles on transparency, accountability, and fairness. Such an approach could work effectively in real-life situations, for example, AI-powered mobile lending or credit scoring, where systems can expand financial inclusion while requiring oversight to prevent bias and protect consumers. A balanced framework like this would allow Kenya to harness AI as a practical, reliable tool while safeguarding rights and maintaining public trust.



