AI
Kenya's Artificial Intelligence Bill 2026: A Bold Legislative Step and the Questions It Must Answer
By Frederick Ofwono
The introduction of the Artificial Intelligence (AI) Bill 2026 into the Kenyan Senate on 13 February 2026 marks a significant moment in Africa’s technology governance story. Tabled by Senator Karen Nyamu, it is Kenya’s first dedicated statutory framework for AI regulation — placing Kenya among a small group of African countries that have moved from strategy documents to actual legislation. It is an ambitious and substantively serious effort.
The regional context matters. Within East Africa, Rwanda was first to act with a national AI policy in 2023. Ethiopia established the Ethiopian Artificial Intelligence Institute (EAII) as a permanent institutional hub backed by increased funding in 2025. Kenya’s National AI Strategy 2025–2030, launched by the Ministry of Information, Communications and the Digital Economy (MICT) in March 2025, provided the country’s first structured government vision. None of these instruments, however, is legislation. The AI Bill 2026 is Kenya’s attempt to give its AI governance ambitions the force of law — and in doing so, it breaks new ground in the East African Community (EAC) legislative space.
This article examines the Bill's contents in detail, considers the governance context in which it arrives, and addresses directly whether it is timely. The overall assessment is encouraging: the Bill gets the architecture right. The task now is to ensure the building matches the blueprint.
WHY LEGISLATION IS NEEDED
AI systems are already embedded in the services Kenyans use daily: mobile credit scoring algorithms determine loan eligibility for traders and farmers; agricultural insurance platforms use satellite imagery and machine learning to assess crop damage; healthcare facilities are piloting AI-assisted diagnostics; and public sector agencies are exploring AI for service delivery and revenue collection. The legal frameworks governing these deployments are fragmented and, in several respects, absent.
Data Protection Act (Cap 411C) governs what happens to personal data but does not govern what AI systems do with that data once processed, and it does not regulate AI systems that operate without personal data at all. Consider a facial recognition system that analyses crowd density using anonymised video feeds, identifying no individuals. No personal data is processed; the Data Protection Act is not triggered. The AI Bill addresses this directly, because its classification framework is based on what a system does and what harm it can cause — not on whether it handles personal data. The Computer Misuse and Cybercrimes Act 2018 targets malicious digital conduct but cannot reach AI systems that operate lawfully yet produce harmful outcomes — a hiring algorithm that systematically disadvantages women applicants commits no offence under that Act. The Central Bank of Kenya’s (CBK) Digital Credit Providers regulations set standards for mobile lenders but do not require algorithmic explainability, do not mandate human review of automated credit decisions, and do not reach sectors beyond finance. The Kenya Bureau of Standards (KEBS) published a draft Code of Practice for AI Applications in 2024, but this is not enforceable law. The AI Bill fills these gaps with a horizontal, cross-sectoral governance framework that no existing Kenyan instrument provides.
WHAT THE BILL DOES: A DETAILED READING
(a) The Office of the Artificial Intelligence Commissioner
The Bill’s centrepiece is the Office of the Artificial Intelligence Commissioner, established under Part II and designated a State Office under Article 260 of the Constitution of Kenya 2010 — the provision defining offices that carry constitutional status alongside the Judiciary, the Presidency, and the chapter fifteen commissions. This anchoring confers structural independence: the Office cannot be dissolved by ordinary executive action, and the Commissioner holds office on terms Parliament controls.
The Commissioner serves as Kenya’s principal AI regulatory authority: overseeing compliance by providers and deployers of AI systems, issuing binding ethical guidelines, establishing and supervising regulatory sandboxes for AI innovation, and publishing guidance on risk classification and workforce transition. The Office chairs the multi-stakeholder Advisory Committee and reports annually to Parliament through the Cabinet Secretary, ensuring democratic accountability in the governance of AI.
(b) The Advisory Committee on Artificial Intelligence
Part III establishes a multi-stakeholder Advisory Committee chaired by the Commissioner and including representatives from the Cabinet Secretary responsible for information and communications technology (ICT), the Office of the Data Protection Commissioner, the National Commission for Science, Technology and Innovation (NACOSTI), two AI ethics and human rights experts nominated by professional bodies, two nominees from the Council of Governors, one private sector representative, and one civil society representative. Gender balance, regional representation, and inclusion of persons with disabilities are legal obligations, not aspirational commitments. The Committee meets at least four times a year. Its functions include advising on emerging trends and risks, reviewing proposed regulations, facilitating stakeholder engagement, promoting multidisciplinary research, and advising on workforce re-skilling. This design builds legitimacy into the regulatory process from the outset.
(c) Risk Classification
Part V adopts a four-tier risk classification system that mirrors the European Union (EU) AI Act’s architecture: unacceptable risk (prohibited outright); high risk (heavily regulated); limited risk; and minimal risk. High-risk systems are those deployed in healthcare, education, agriculture, finance, security, employment, and public administration. Systems classified as unacceptable risk are prohibited under section 25(3). The substantive content of each tier — the precise criteria determining which system falls where — is delegated to Cabinet Secretary regulations. This is a legitimate approach to framework legislation, but it creates an important governance obligation: those regulations must be developed promptly, through full public consultation, and tabled before Parliament for scrutiny. The Senate committee stage should make these procedural requirements explicit in the Bill itself.
(d) Obligations for High-Risk Systems
Section 26 imposes demanding pre-deployment and ongoing obligations on providers and deployers of high-risk systems. Before deployment, a risk assessment and a human rights impact assessment (HRIA) are both required — the latter going beyond what many comparable frameworks demand, reflecting Kenya's constitutional commitment to rights-based governance. Once deployed, systems must ensure transparency, traceability, and explainability of decision-making; maintain records of data inputs, training datasets, outputs, and performance metrics for at least five years; comply with the Data Protection Act for personal data processing; and incorporate measures for robustness, accuracy, and cybersecurity. Operators must also obtain explicit consent and clearly label outputs as AI-generated where systems generate or manipulate images, voice, or likeness. Annual compliance reports are required, with non-confidential information made publicly available.
Section 26(1)(f)'s cybersecurity obligation — to 'incorporate measures for robustness, accuracy and cybersecurity' — is real but currently underdeveloped. The Bill specifies neither the applicable technical standards nor who certifies compliance. The Computer Misuse and Cybercrimes Act does not prescribe technical security standards for AI systems. The Data Protection Act requires 'appropriate technical and organisational measures' for data security, which overlaps with but is not identical to AI system cybersecurity. In practice, this obligation will only become enforceable once the Cabinet Secretary issues defining regulations. The Bill should create a statutory deadline for those regulations.
Section 28 extends transparency requirements to all AI systems. Providers and deployers must disclose the nature, purpose, and limitations of their systems; the degree of automated decision-making involved; and bias mitigation measures. Section 28(2) provides that where automated decisions produce 'significant legal or similar effects,' users have the right to human intervention, to express their views, and to contest the decision. Consider a loan application system using automated credit scoring without human oversight. If a trader's transactions change due to family illness—such as irregular deposits for medical costs—her score may drop, causing an automatic denial with no explanation or appeal. This leads to missed restocking, lost clients, and lower income. Section 28(2) introduces a legally enforceable right to human review, which current Kenyan law lacks; the Bill establishes this right.
(e) Sandboxes, Ethical Guidelines, and Workforce Protections
Section 29 authorises the Commissioner to establish regulatory sandboxes — controlled testing environments for AI systems operating under regulatory oversight. Priority must be given to innovations addressing national priorities, with collaboration encouraged across county governments. Section 30 requires the Commissioner to publish ethical guidelines covering bias prevention regarding vulnerable groups, privacy and human dignity, human oversight and accountability, environmental sustainability including energy consumption assessments, equitable access to AI benefits, and prohibition of non-consensual use of personal likenesses in AI-generated content.
Section 32 requires every designer and deployer to ensure AI systems enhance rather than replace human capabilities, and to provide for human oversight in critical decisions — including a qualified person's ability to intervene or override outputs affecting rights, safety, or societal well-being. Section 33 requires providers and deployers of employment-impacting systems to conduct workforce impact assessments before deployment and to implement reskilling programmes in collaboration with national and county agencies. The Commissioner must develop guidelines on workforce transition, including incentives for AI adoption that creates jobs. For a continent where AI-driven automation poses genuine risks to large segments of the workforce, this provision is not merely progressive — it is necessary.
(f) Offences and Penalties
Part VI creates a schedule of offences covering deployment of prohibited or unassessed high-risk systems, transparency failures, sandbox misconduct, workforce assessment failures, ethical guidelines contraventions causing bias or harm, public sector AI misuse, obstruction of the Commissioner, and non-consensual synthetic media distribution. The most serious offences attract fines of up to five million Kenyan shillings (KES) (approximately USD 38,000) or up to two years’ imprisonment. Corporate officer liability extends to directors and officers who had knowledge of an offence and failed to exercise due diligence — an important accountability mechanism. The penalty ceiling, however, is the Bill’s most significant structural weakness: USD 38,000 does not constitute a meaningful deterrent for global technology companies operating in Kenya. The EU AI Act imposes penalties of up to EUR 35 million or seven percent of global annual turnover for equivalent violations. The Senate committee stage is the appropriate moment to recalibrate.
THE POLICY QUESTION: WHAT EXISTS AND WHAT DOES NOT
A central contextual question is whether Kenya has an AI policy against which the Bill's choices can be measured. The honest answer, supported by the documentary record, is that Kenya has a strategy but not yet a policy — and the distinction is material.
Kenya’s National AI Strategy 2025–2030, launched by MICT in March 2025, sets out an ambitious government vision for ethical and inclusive AI adoption across priority sectors. It identifies strategic pillars covering infrastructure, data ecosystems, research and innovation, governance, talent, and ethics. It commits to alignment with the AU Continental AI Strategy and international frameworks including the EU AI Act. Crucially, however, the Strategy itself lists the development of a national AI policy as a future Phase 1 milestone — meaning the strategy acknowledges that the policy has not yet been produced. The White & Case global AI regulatory tracker, updated in 2025, confirmed that as of that date there are no specific laws or regulations in Kenya that directly regulate AI. A strategy sets ambitions. A policy makes the binding normative choices that translate those ambitions into regulatory decisions. Legislation then implements those choices. Kenya has moved quickly from strategy directly to legislation, compressing what is typically a longer sequencing.
The practical implication is that once the Commissioner is appointed, foundational regulatory choices — on risk classification criteria, cybersecurity standards, ethical guidelines, and sandbox conditions — will need to be made without a policy document to anchor them. The remedy is not to delay the Bill but to build a policy development obligation into it: a statutory requirement for the Cabinet Secretary to produce and gazette a national AI policy within a defined period after the Act comes into force, with the Commissioner's first substantive regulations required to be consistent with that policy.
HOW THE BILL FILLS THE GAPS IN KENYA'S LEGAL FRAMEWORK
The AI Bill's most important systemic contribution is a horizontal governance framework that applies across all sectors where only fragmented instruments currently exist. It fills three gaps of particular consequence for ordinary Kenyans.
First, it creates enforceable rights in automated decision-making that go beyond the Data Protection Act. That Act gives data subjects a right to object to automated processing, but practical enforcement has been limited, and the right is not prominently disclosed to consumers. Section 28(2) creates an explicit, enforceable right to human intervention in automated decisions with significant legal effects. Second, it reaches AI systems entirely outside the Data Protection Act’s scope — systems that do not process personal data, such as anonymised crowd analytics tools, property valuation algorithms, and supply chain optimisation systems, are currently ungoverned. The AI Bill governs them. Third, it creates workforce protections that no existing Kenyan law provides. The Employment Act 2007 and related instruments do not address pre-deployment AI impacts on employment. Section 33 does.
One area requires careful management: both the Office of the AI Commissioner and the Office of the Data Protection Commissioner will have jurisdiction over AI systems that process personal data. Both can investigate complaints about the same company in relation to the same system. The Bill contains no coordination mechanism between the two offices. This overlap should be addressed in committee — ideally by designating the Data Protection Commissioner as an ex-officio member of the Advisory Committee and requiring a formal coordination protocol within a specified period of the AI Commissioner's appointment.
IS THE BILL TIMELY?
The question of timing has a clear answer: yes. A Paradigm Initiative report presented at the ALP East Africa AI Forum in Kampala in November 2024 documented critical AI governance gaps across Kenya, Uganda, Tanzania, Rwanda, South Sudan, Mauritius, and Zambia, finding only Mauritius had sector-specific AI laws in force and calling for urgent legislative action. Kenya’s Bill is a direct response to exactly those documented gaps.
Regionally, Kenya’s legislative leadership signals to EAC partners that AI governance is a political priority, not merely a policy aspiration, and creates an opportunity for regional coordination and eventual harmonisation of AI governance standards. Internationally, the EU AI Act is already shaping compliance obligations for Kenyan companies operating in European markets. A domestic framework that is legible to foreign investors, development partners, and technology companies strengthens Kenya’s position in digital trade discussions and reduces the risk of having external governance standards imposed by default.
The Bill should proceed. The Senate committee stage is the moment to address the areas this article has identified: a statutory obligation to produce the national AI policy; a penalty regime calibrated to provide genuine deterrence; clarification of jurisdictional reach over foreign AI providers; and a coordination mechanism with the Data Protection Commissioner. These are targeted refinements to a creditable foundation. Kenya has produced a Bill that the region should watch carefully and that its own Parliament should pass — with the amendments it deserves.