A Deep-Dive Legal and Policy Analysis
1. Executive Summary
Senator Karen Nyamu introduced the Artificial Intelligence Bill, 2026, which was gazetted on 19 February 2026. It’s Kenya’s first real attempt at a dedicated, comprehensive law for regulating AI. Structurally, it leans heavily on the EU AI Act’s risk-tiered model, but grafts on distinctly Kenyan features: a State Office, a Public Service Commission-run appointment process, an Advisory Committee, and obligations that reach down to county governments.
At its core, the Bill does three things. First, it creates a new regulator — the Office of the Artificial Intelligence Commissioner — with power to investigate, enforce, set standards, and advise. Second, it sets up a four-tier risk classification system (unacceptable, high, limited, minimal) that determines how much compliance burden falls on the people building or deploying AI systems. Third, it lays out a fairly detailed offences and penalties regime, running from administrative fines up to criminal liability of five million shillings and/or two years in prison, with directors potentially exposed personally.
Bottom line
This is an ambitious, EU-inspired regulatory transplant, not a light-touch amendment to existing law. Whether it works will come down to the subsidiary regulations (which don’t exist yet), how much capacity the new Office actually has, and how the classification and enforcement provisions get operationalised once the ink is dry.
2. Legislative Context and Rationale
The Bill’s own Memorandum of Objects and Reasons frames it as closing a gap left by existing law — mainly the Science, Technology and Innovation Act and the Data Protection Act (Cap. 411C), neither of which was written with AI-specific risks in mind. Two influences stand out. The first is the EU AI Act, visible in the near-identical four-tier risk classification and in many of the high-risk obligations around risk assessments, human oversight, transparency, and record-keeping. The second is Kenya’s own National Artificial Intelligence Strategy 2025–2030, with the new Office positioned as the body that actually implements it.
Constitutionally, this is a Senate Bill because it “concerns county governments” under Article 110(1)(a) — the Fourth Schedule functions of counties (healthcare, agriculture, education, and so on) are directly touched by the Bill’s high-risk sector list and its provisions on devolved AI use. The Bill states it is not a money Bill under Article 114, and that it doesn’t limit any fundamental rights or freedoms. That second claim is worth scrutinising given how much the Bill touches data, profiling, and content generation (see Section 11).
3. Part I — Preliminary: Definitions and Scope
Part I (clauses 1–3) lays the interpretive groundwork. The definitions are deliberately broad and technology-neutral, following the EU’s approach of regulating by function and risk rather than naming specific technologies.
Key definitions
“Artificial intelligence” is defined as a machine-based system that uses machine learning, data processing, or algorithmic methods, operates with varying degrees of autonomy, and infers outputs — predictions, content, recommendations, or decisions — from inputs, including systems doing tasks that would normally require human intelligence.
“Generative AI” means an AI system capable of producing text, images, audio, video, or other content by drawing on learned patterns in data.
A “high-risk AI system” is one that poses significant risk to health, safety, fundamental rights, or societal welfare, with the detail to be filled in by regulations.
A “provider” is a natural or legal person who develops an AI system (or has one developed) and puts it on the market or into service under their own name or trademark. A “deployer” is whoever puts an AI system into service or uses it under their own authority — this excludes ordinary personal, non-professional end-users.
“Synthetic media” covers content generated or manipulated with generative AI that depicts events, speech, or appearances that never actually happened. A “regulatory sandbox” is a controlled environment for testing AI systems under regulatory oversight.
Observations
- The AI definition is intentionally wide — broad enough to capture everything from a basic recommendation engine to a large generative model. That means the law’s real bite depends almost entirely on the risk classification regulations promised under clause 25, which simply don’t exist yet in the Bill itself.
- The provider/deployer split mirrors EU AI Act terminology closely. That will make life easier for multinational vendors who’ve already built EU-compliant products, but it may fit awkwardly with Kenya’s actual AI market, which is dominated by people deploying foreign-built models rather than domestic developers.
- Object (g) — aligning “with international standards on artificial intelligence” — is written in as a formal object of the Act. That gives courts and the Commissioner an interpretive hook to pull in EU or international jurisprudence even where the Kenyan text itself is silent.
4. Part II — The Office of the Artificial Intelligence Commissioner
4.1 Establishment and status (clause 4)
The Bill sets up the Office as a State Office under Article 260(q) of the Constitution — the same constitutional category as the Auditor-General or the Controller of Budget. It’s a body corporate with perpetual succession, able to sue, contract, and hold property, and it’s described as “independent in the performance of its functions.”
4.2 Appointment process (clauses 5–7)
The appointment pathway is multi-stage and mirrors how other constitutional and statutory offices get filled. The Public Service Commission has 7 days from a vacancy to start recruitment, then a further 21 days to advertise, shortlist, and interview candidates. The PSC nominates three qualified candidates in order of merit to the President, who then nominates one for parliamentary approval. Before taking up duties, the Commissioner swears an oath set out in the Schedule.
4.3 Qualifications (clause 6)
A Commissioner needs a master’s degree in AI, computer science, IT, engineering, data science, law, ethics, or a related field; at least 10 years’ experience in a relevant governance, technology, or ethics field; at least 10 years managing public or private institutions; and they must meet the Chapter Six integrity requirements of the Constitution. The term runs five years and is renewable once.
4.4 Removal (clauses 8–9)
Removal grounds are the standard ones used for other independent office holders — serious constitutional or legal violation, gross misconduct, incapacity, incompetence, or bankruptcy. The process runs through a complaint to the PSC, an investigation, a report to the Cabinet Secretary, and the Commissioner gets the right to know the reasons and mount a defence, in line with Article 47’s fair administrative action requirements. The President makes the final call, on the Cabinet Secretary’s recommendation.
4.5 Functions (clause 10)
The Office’s functions span enforcement, standard-setting, and softer promotional roles. On the regulatory side, it oversees and enforces the Act, carries out risk assessments, conducts conformity audits and post-market surveillance, and handles complaints. On standard-setting, it develops codes of practice, ethical guidelines, and risk classification criteria. It also has a promotional mandate — fostering responsible AI development, running sandboxes, promoting AI literacy, and building capacity at national and county level — plus an advisory role toward national and county governments and international bodies. It’s expected to monitor AI trends, including environmental impact and job displacement, and to keep a public register of high-risk AI systems, including those used by county governments.
4.6 Powers (clause 11)
The Office’s powers are coercive and investigatory: entering and inspecting premises, systems, and records on reasonable notice; compelling production of documents; issuing enforcement notices and directives; imposing administrative fines (with the actual amounts left to regulations); summoning witnesses; and delegating powers to “authorized officers.” These have to be exercised consistent with Article 47, but there’s no separate appeals tribunal — the Bill just requires the Office to “establish an appeals mechanism for decisions made by the Office” (clause 11(1)(g)). That raises an obvious question about whether an internal appeal against the same body’s own decisions is really good enough (more on this in Section 11).
4.7 Staffing, remuneration, liability, confidentiality (clauses 12–16)
Staff — deputy and assistant commissioners and others — are appointed by the Commissioner in consultation with the Salaries and Remuneration Commission and the PSC, and the SRC sets pay for the Commissioner and staff. Clause 14 lets the Commissioner delegate statutory powers to sector regulators set up under other Acts of Parliament, which matters in practice: it’s the mechanism that would let the Central Bank, the Data Protection Commissioner, or the Communications Authority exercise AI-related powers within their own sectors. The Commissioner and staff get good-faith protection from personal liability (clause 15), and there’s a statutory confidentiality obligation over information obtained under the Act (clause 16).
5. Part III — The Advisory Committee on Artificial Intelligence
Clauses 17–20 set up a multi-stakeholder Advisory Committee, chaired by the Commissioner, with fairly broad-based representation: one representative each from the ICT Cabinet Secretary, the Office of the Data Protection Commissioner, and the National Commission for Science, Technology and Innovation; two AI ethics or human rights experts nominated by professional bodies; two Council of Governors nominees (one man, one woman) giving counties a voice; and one private-sector technology representative and one civil-society representative, both nominated through consultative processes.
Members other than the ex officio ones serve three-year terms, renewable once, and the Cabinet Secretary and Commissioner are required to ensure gender balance, regional representation, and disability inclusion in appointments. The Committee’s role is purely advisory — it weighs in on trends and risks, reviews and recommends on proposed regulations and guidelines, facilitates stakeholder engagement, and advises on workforce transition strategies. It must meet at least four times a year, with quorum set at half its members, but it has no independent decision-making or enforcement power. Final authority sits with the Commissioner and the Cabinet Secretary.
6. Part IV — Financial Provisions
Clauses 21–24 cover fairly conventional public-finance ground: funding comes from parliamentary appropriations, grants, gifts, donations, and other accruals; annual estimates have to be prepared at least three months before each financial year; audits follow Articles 226 and 229 of the Constitution along with the Public Finance Management Act and the Public Audit Act; and an annual report goes to the Cabinet Secretary within three months of the financial year-end, which must then be tabled in Parliament within 14 days of receipt. One detail worth flagging: clause 22(2)(f) allows the Office to build reserve funds for “future or contingent liabilities,” which could be useful for funding enforcement litigation or sandbox programmes without having to wait on annual appropriations.
7. Part V — Governance of Artificial Intelligence (the Risk Framework)
This is the substantive heart of the Bill, and it closely — though not identically — replicates the EU AI Act’s four-tier risk pyramid.
7.1 Risk classification (clause 25)
At the top, “unacceptable risk” systems are those posing “severe threats,” and they’re prohibited outright, subject to exceptions still to be prescribed by regulation. “High risk” covers systems used in critical sectors — healthcare, education, agriculture, finance, security, employment, or public administration — and these carry the full compliance regime under clause 26. “Limited risk” systems carry “moderate” risk and face lighter, largely transparency-based obligations under clause 28. “Minimal risk” systems, with “negligible” risk, are effectively unregulated beyond baseline transparency norms.
Crucially, the detailed classification criteria are left to regulations made by the Cabinet Secretary on the Commissioner’s recommendation (clause 25(2)) — the Bill itself only names the high-risk sectors, not the specific criteria that would trigger classification within them. The Commissioner can periodically update the classification criteria “having regard to international standards.”
7.2 Obligations for high-risk systems (clause 26)
Before deployment and on an ongoing basis, providers or deployers of high-risk AI systems have to conduct a risk assessment and put mitigation measures in place, including human oversight; carry out a human rights impact assessment; ensure transparency, traceability, and explainability of decision-making; keep records of data inputs, training datasets, outputs, and performance metrics for at least five years; comply with the Data Protection Act, including data protection impact assessments where required; build in robustness, accuracy, and cybersecurity measures; and where a system generates or manipulates a person’s image, voice, or likeness, obtain explicit consent and clearly label the AI-generated output.
Providers of high-risk systems also have to submit annual compliance reports to the Office, with the non-confidential parts made public, and the Office itself reviews assessments for public-sector high-risk systems.
7.3 Register and transparency (clauses 27–28)
The Office keeps a public register of high-risk AI systems, including those used by counties. Separately, all providers and deployers — not just the high-risk ones — have to tell users what the system is for, what its limitations are, how much of the process is automated versus human-driven, and what bias mitigation or fairness measures are in place. Where automated decisions produce “significant legal or similar effects,” the Data Protection Act’s safeguards kick in, including the right to human intervention, to express a view, and to contest the decision. This cross-references and reinforces the existing profiling protections under Cap. 411C rather than creating a wholly new right.
7.4 Regulatory sandboxes (clause 29)
The Office has to set up sandboxes for controlled testing, with participation conditions around ethics, data protection, and risk monitoring set by the Commissioner. Priority for sandbox admission goes to innovations addressing “national priorities” and to those encouraging county-government collaboration — potentially a useful on-ramp for local AI startups that can’t otherwise absorb the full cost of high-risk compliance before they’ve even launched.
7.5 Ethical guidelines (clause 30)
The Commissioner has to publish ethical guidelines covering bias and discrimination (with particular regard to vulnerable groups), privacy and dignity, human oversight and redress for harms, environmental sustainability — including energy and carbon footprint assessments, a notably forward-looking addition — equitable access to AI’s benefits, and a prohibition on non-consensual use of personal likenesses in AI-generated content.
7.6 AI literacy (clause 31)
The Office has to run AI literacy programmes at both national and county level, working with educational institutions and ICT hubs — this is what actually operationalises Object 3(f) of the Act.
7.7 Human-centric AI (clause 32)
Designers and deployers have to make sure AI “enhances rather than replaces” human capability, build in features that keep humans in the loop, and provide human oversight for critical decisions — including a right for a “qualified person” to intervene in or override outputs that affect human rights, safety, or societal well-being. It’s the Cabinet Secretary who gets to prescribe, by regulation, what actually counts as a “critical decision” requiring this oversight, so again the real detail is pushed down to subsidiary legislation.
7.8 Workforce impact (clause 33)
Providers and deployers of AI systems “likely to impact employment” must carry out workforce impact assessments — including potential job displacement — and put mitigation measures in place, such as reskilling programmes, working with national and county agencies. The Commissioner is also required to develop guidelines on vocational training partnerships and incentives for job-creating AI adoption.
7.9 Public sector use (clause 34)
Public entities, including county governments, that use AI systems have to comply with the Act — which extends the compliance regime to government use of AI, for example in social protection targeting, security and surveillance, or public service delivery. Worth noting: this clause is numbered 34 in the Bill’s body text but cross-referenced inconsistently elsewhere as 33 or 34 — see Section 11.3.
8. Part VI — Offences, Penalties, and Regulations
8.1 Offences (clause 35)
The Bill creates nine categories of offence: deploying an unacceptable-risk system; deploying a high-risk system without the required risk assessment or mitigation; failing transparency and disclosure obligations; breaching sandbox conditions; failing to conduct workforce impact assessments; contravening ethical guidelines in a way that causes bias, discrimination, or harm; unlawful public-sector AI use that causes prejudice; obstructing the Office, including by providing false information; and generating or distributing non-consensual synthetic media that causes harm, misinformation, defamation, or a privacy breach.
8.2 Penalties (clause 35(2)–(3))
The most serious offences — unacceptable-risk deployment, unmitigated high-risk deployment, sandbox breaches, failure to do a workforce assessment, unlawful public-sector use, and non-consensual harmful synthetic media — carry a fine of up to KES 5,000,000, or imprisonment of up to two years, or both. Transparency and disclosure failures, contravening ethical guidelines, and obstructing the Office carry a lighter fine of up to KES 1,000,000, or up to six months in prison, or both. On the corporate side, any director or officer who knew about an offence and failed to exercise due diligence is personally guilty of that offence.
There’s a real drafting problem here worth flagging: clause 35(1) and (2) refer to “section 34” for the offences, but the offences are actually listed in clause 35 itself, and the workforce provision is clause 33, not 32. This looks like a drafting or renumbering error that will probably get fixed before enactment, but as gazetted, it creates genuine uncertainty about which conduct is actually being criminalised (see Section 11.3).
8.3 Regulations and review (clauses 36–37)
The Cabinet Secretary, in consultation with the Commissioner, can make regulations on a long list of matters — classification criteria, assessment procedures, sandbox conditions, the content of ethical guidelines, data governance standards, enforcement and appeal procedures, fees, consent and labelling procedures for synthetic media, and exceptions for legitimate image manipulation. That confirms what the rest of the Bill already suggests: as gazetted, this is a skeletal framework. Nearly every operative threshold — what counts as high-risk, what fines apply to what conduct, how sandboxes actually work — is left to regulations that haven’t been written yet. The Act itself has to be reviewed every three years, with a report to Parliament on effectiveness, emerging risks, and recommended amendments.
9. Comparative Analysis: Kenya’s Bill vs. the EU AI Act
On risk tiers, the structure is nearly identical — unacceptable, high, limited, minimal — a direct conceptual import from the EU model. Where the two diverge more is in the regulator model: the EU relies on national competent authorities plus an EU AI Office, while Kenya centralises almost everything in a single new national Commissioner, a much more concentrated model, similar in spirit to how the Data Protection Commissioner is set up.
The high-risk sector lists are broadly similar — health, education, employment, critical infrastructure and finance, law enforcement and security — but the Kenyan text defines them at a much higher level of generality, with the real detail deferred to regulations that don’t exist yet. Enforcement is where the gap is starkest: the EU AI Act uses turnover-based fines, up to 7% of global turnover for the worst breaches, while Kenya’s Bill uses a flat fine capped at KES 5 million, roughly USD 30,000–40,000. That’s arguably too low to deter a large multinational AI provider, though it could be reasonably proportionate for Kenya’s domestic SME and startup market.
Both regimes include regulatory sandboxes, though Kenya’s explicitly prioritises “national priorities” and county collaboration, reflecting local development goals. The devolution dimension is unique to Kenya — the Bill has to navigate the Fourth Schedule division of functions between national and county government, something the EU Act simply has no equivalent for. And on workforce and environmental provisions, Kenya’s Bill actually goes further than the original EU AI Act text, making workforce impact assessments and carbon-footprint and energy-consumption guidelines core statutory obligations rather than voluntary codes.
10. Strengths of the Bill
- Comprehensive institutional design: rather than a bare principles-based statute, it builds a full regulator with appointment safeguards, funding, staffing, and reporting lines — giving it more institutional durability than a set of guidelines would have.
- Explicit devolution integration: county representation on the Advisory Committee and mandatory advisory functions for devolved sectors is a thoughtful response to Kenya’s constitutional structure, something many purely national digital-policy instruments simply ignore.
- Synthetic media and consent provisions: clause 26(1)(g), clause 30(2)(f), and the clause 35(1)(i) offence together form a fairly coherent chain — consent, labelling, and criminal liability — around deepfakes and non-consensual AI-generated likenesses, an area many peer jurisdictions still leave to general defamation or privacy law.
- Human-centric AI and workforce provisions: mandatory workforce-impact assessments and reskilling obligations under clause 33 are more concrete than the EU AI Act’s original text, and speak directly to job-displacement anxieties.
- Sandbox-plus-literacy combination: pairing sandboxes with mandatory AI literacy programmes suggests real intent to grow domestic capacity, not just police it.
11. Gaps, Ambiguities, and Risks
11.1 Heavy reliance on unwritten subsidiary regulations
The single biggest structural weakness is that almost every operative threshold — what counts as “high-risk” within a listed sector, the actual fine amounts for administrative penalties, sandbox eligibility, and what “critical decisions” require human oversight — is pushed down to regulations under clause 36 that don’t exist yet. That means the Bill, on its own, is largely a framework of intentions. Its real-world impact can’t really be assessed until the regulations are published, and Parliament is effectively delegating a lot of law-making power to the executive — a point the Bill’s own Memorandum acknowledges under “delegation of legislative powers.”
11.2 Internal appeals mechanism
Clause 11(1)(g) requires the Office itself to “establish an appeals mechanism for decisions made by the Office.” Having the same body that issues enforcement notices and fines also design — and presumably staff — the body that hears appeals against those decisions raises an obvious natural-justice concern, absent stronger safeguards like an independent tribunal or a clear route to the High Court. The Bill doesn’t clarify whether recourse to the ordinary courts stays available in parallel, though that would typically be preserved under Article 47 and the Fair Administrative Action Act regardless.
11.3 Drafting and cross-referencing errors
The Table of Contents lists clause 34 as “Offences and Penalties” and clause 33 as “Use of artificial intelligence in the public sector,” yet the actual clause numbering in the body text places “Use of AI in the public sector” at clause 34 and “Offences and Penalties” at clause 35 — with clause 35 itself then internally citing “section 34” for the offence list. Whether this is a gazetting or OCR artefact or a genuine drafting error, it creates real ambiguity about which clause numbers actually govern criminal liability, and it would need fixing via amendment before the Bill could be safely enacted or reliably cited in litigation.
11.4 Penalty proportionality and deterrence
A maximum fine of KES 5 million isn’t likely to meaningfully deter large, well-capitalised AI providers — often multinational tech companies — from cutting corners on high-risk compliance, especially set against the EU’s turnover-based penalty model. At the same time, that same flat fine could be disproportionately harsh for a small Kenyan AI startup, since there’s no explicit provision for scaling the penalty by company size or revenue.
11.5 Undefined “unacceptable risk” exceptions
Clause 35(1)(a) criminalises deploying an unacceptable-risk system “except in circumstances prescribed by regulations,” but clause 25(3) states flatly that such systems “are prohibited,” with no exceptions of its own in the text. The interplay between an apparently absolute statutory prohibition and a regulation-created exception to criminal liability for the same conduct is legally awkward and should be cleaned up.
11.6 Scope and overlap with the Data Protection Act
Several obligations — data protection impact assessments, rights around automated decision-making — simply cross-reference the existing Data Protection Act rather than creating new causes of action. That avoids duplication, but it also means AI-specific redress for a data subject may still run through the Office of the Data Protection Commissioner, raising a coordination question between two independent offices that the Bill doesn’t really address beyond a shared Advisory Committee seat.
11.7 Definition breadth
The AI definition in clause 2 is broad enough to capture ordinary rule-based automation and basic algorithmic systems, not just modern machine-learning models. Without the classification regulations in place, businesses may struggle to know in advance whether a given tool — a spreadsheet macro-based decision tool, say, or a simple rules engine — actually counts as “AI” for the purposes of the Act.
12. Implementation Considerations
- Sequencing risk: because compliance obligations for high-risk systems, sandbox rules, and fine schedules are all regulation-dependent, businesses and county governments have no real way to prepare for compliance until the Cabinet Secretary publishes the clause 36 regulations — creating a potential compliance cliff-edge at commencement.
- Institutional capacity: the Office has an extremely wide functional mandate — enforcement, standard-setting, literacy programmes, sandbox management, research, county advisory work — for a brand-new institution with a five-year Commissioner term. Whether it can actually deliver will depend on adequate initial funding under Part IV and fast, competent staffing under clause 12.
- County engagement: the Bill puts real obligations on county governments — compliance duties under clause 34, register entries for county-used high-risk systems — but county AI capacity varies widely across Kenya’s 47 counties. The mandated literacy and capacity-building programmes under clause 31 will need genuine investment to avoid a two-tier system between well-resourced and under-resourced counties.
- Sandbox-to-market pathway: clause 29 doesn’t specify what legal status a product tested in a sandbox has once it graduates — whether that’s a presumption of compliance or a fresh conformity assessment. This gap should be clarified in regulations if the sandbox is going to be genuinely useful for startups.
- Interaction with sectoral regulators: clause 14’s delegation power to “a regulator established through an Act of Parliament” is a sensible mechanism for embedding AI oversight into, say, the Central Bank of Kenya for AI in lending and credit scoring, or the Insurance Regulatory Authority. But the Bill offers no criteria for when delegation should actually happen, which risks inconsistent treatment across sectors.



