
AI
CIPESA Urges Kenya to Fix Its Draft AI Policy — What Kenya's AI Governance Act Must Get Right
August 18, 2026GashoTech Team
What happened
In August 2026, the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) submitted a detailed set of recommendations to the Committee drafting Kenya's Artificial Intelligence and Other Emerging Technologies Policy, 2026. The submission lands at a critical moment: Kenya is moving from consultation to legislation. Public comments on the draft policy closed on 4 August 2026, and the Senate is separately working through the Artificial Intelligence Bill, 2026, which would create Kenya's first dedicated AI regulator with a four-tier risk classification system and criminal penalties.
CIPESA's message is balance. Kenya wants to become Africa's AI leader, and the draft policy reflects that ambition. But CIPESA argues that ambition must be matched with safeguards that protect people, not just attract investment. Without those safeguards, the network warns, Kenya risks building systems that are innovative but exclusive, unfair and harmful. This is not a fringe position. It reflects a wider regional push by civil society to ensure Africa's AI boom does not repeat the mistakes of the global social-media era, where growth outpaced accountability and ordinary users absorbed the harms.
Why this matters right now
The timing matters because the choices made in this policy will bind Kenya for a decade. The Artificial Intelligence and Other Emerging Technologies Policy, 2026 will shape how every bank, insurer, telco, employer and hospital in Kenya is allowed to build and use AI. It will also shape how ordinary Kenyans interact with automated systems — whether they know when they are talking to a machine, whether they can challenge a decision made about them, and whether they have recourse when a system gets it wrong.
CIPESA is one of the continent's most respected ICT policy networks, with years of work monitoring internet freedom and digital rights across East and Southern Africa. When it speaks, regulators and international partners listen. Its submission therefore carries weight beyond a single organisation's opinion.
The four core recommendations
1. Make human rights and gender impact assessments mandatory
CIPESA wants high-risk AI systems to undergo mandatory human rights and gender impact assessments before deployment. This is not a theoretical request. In Kenya, AI is already shaping credit decisions, insurance claims, customer service chatbots, job screening and clinical decision support. A rights-based approach that includes mandatory human rights impact assessments ensures potential harms are identified before systems are switched on, not after they cause damage.
The key word is mandatory. Voluntary assessments are easy to defer and easier to hide. Making them a legal gate before a high-risk system can operate shifts the burden onto builders rather than victims.
2. Strengthen the independence of oversight institutions
The submission calls for stronger independence and powers for Kenya's AI oversight bodies, including audit, enforcement and redress. A regulator that cannot audit systems, enforce decisions and provide redress is a regulator in name only. CIPESA argues oversight must have teeth to be trusted.
This matters because the draft policy proposes a National AI and Other Emerging Technologies Council led by a director, supported by a governing board, a technical advisory forum and five specialised directorates. The structure is ambitious. But structure alone is meaningless if the institutions lack the power and resources to act.
3. Protect workers across the AI value chain
From data annotators to content moderators, workers are the quiet backbone of the AI economy. CIPESA wants explicit protections for these workers, who are often the first to absorb the harms of poorly designed systems and the last to be compensated. This is a particularly timely call given the growth of AI-linked outsourcing work across the region, where low-paid workers label the training data that powers systems ultimately controlled by a few large firms.
4. Align with regional and international frameworks
CIPESA urges Kenya to align its policy with regional and international AI frameworks to avoid duplication and conflicting provisions. If Kenya's rules contradict the continent's emerging standards, businesses face confused compliance and citizens get weaker protection. Alignment also positions Kenya to shape those standards rather than react to them.
The environmental angle
The submission also pushes environmental accountability. AI systems are resource-intensive, consuming large amounts of energy and water for data-centre cooling while emitting carbon and generating electronic waste. CIPESA recommends independent third-party verification of environmental disclosures, published in the public registry.
This is a forward-looking point. Data centres and large language models have a real environmental footprint, and as Kenya positions itself as a regional AI hub, that footprint will grow. Requiring verified disclosure now prevents a costly and embarrassing reckoning later.
What this means for Kenyan businesses
For businesses, the message is clear: Kenya's AI rules are being built now, and the safeguards being debated will determine how expensive compliance is for years. A policy with mandatory impact assessments means banks, insurers, telcos and employers must build governance into their AI products from the start, not bolt it on later. Early adopters who treat governance as a feature rather than a cost will have a durable advantage.
The proposed fine structure is also relevant. The draft Artificial Intelligence Bill proposes fines of up to KES 5 million and prison terms of up to two years for creating or distributing harmful AI-generated content. Those are serious stakes, and any business building AI-facing products should be tracking the final policy closely.
What this means for Kenyan citizens
For citizens, the stakes are personal. AI systems are making decisions about credit, employment, healthcare and access to services. Whether those decisions are fair, transparent and reviewable depends almost entirely on what this policy — and the AI Governance Act that follows — says about oversight and accountability. The ability to know when you are interacting with AI, to contest an automated decision, and to seek redress is the difference between a tool that serves people and a structure that controls them.
The moment of decision
The question is no longer whether Kenya will regulate AI. The question is whether the final policy keeps the mandatory human rights impact assessments, or whether they are weakened before the Act is passed. CIPESA has made its case. Kenya's policymakers now have a choice: build an AI governance framework that protects people and earns regional trust, or build one that looks good on paper but leaves citizens exposed.
GashoTech will be watching which path Kenya chooses — and we will keep our readers informed as the policy moves from draft to law.
Want to learn more?
Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.
Get in Touch