Back to Blog
Kenya Draft AI Policy Consultation Closed 4 August — What Founders, Deployers, and Foreign Providers Need to Track
AI

Kenya Draft AI Policy Consultation Closed 4 August — What Founders, Deployers, and Foreign Providers Need to Track

August 10, 2026GashoTech

Kenya's Draft AI Policy Consultation Closed 4 August — Here Is What Founders, Deployers, and Foreign Providers Need to Track



On 27 July 2026, Kenya's Ministry of Information, Communications and the Digital Economy opened a seven-day public consultation on its Draft Artificial Intelligence and Other Emerging Technologies Policy. The window closed on 4 August. The document is now in the hands of the AI Commissioner's office, which will use the feedback to shape the statutory instruments that will govern how AI systems are built, deployed, and audited in Kenya for the next decade.

This is not a theoretical exercise. The draft introduces a risk-based classification system, mandatory pre-deployment assessments for high-risk AI, new workplace obligations for deployers, transparency duties for AI-generated content, and local registration requirements for foreign providers. If you build, deploy, fund, or procure AI systems in Kenya — or sell them into Kenya from abroad — these rules will affect you.

What the Draft Actually Proposes



Risk-Based Classification



The draft establishes a tiered classification system for AI systems. High-risk deployments — defined as those operating in finance, health, education, and public services — face the heaviest compliance load. The classification determines which obligations apply and how rigorous the oversight will be.

For high-risk systems, the draft mandates:

  • Pre-deployment risk assessments — systematic evaluation of what the AI can do, what it can fail at, and what harm it can cause

  • Human-rights impact assessments — explicit evaluation of whether the system's outputs could discriminate, surveil, or restrict rights

  • Five-year record-keeping — deployers must maintain logs of system decisions, inputs, and outputs for audit purposes


This is not a voluntary framework. The draft positions these as statutory requirements for systems classified as high-risk.

Workplace Impact Obligations



A new compliance layer sits on top of the risk classification. Deployers of AI systems in workplace contexts must demonstrate how the technology affects employment — and submit reskilling or mitigation plans. This is a direct response to the automation anxiety that the National AI Strategy 2025–2030 acknowledged but did not address operationally.

The implication: if you deploy AI that displaces, restructures, or augments roles, you need a documented plan for what happens to the people whose work changes. The draft does not specify what "adequate" reskilling looks like, but it signals that the AI Commissioner will define the standard through the consultation feedback.

Transparency and Content Duties



AI-generated images, voice, or likeness must carry labels. Where there is a risk of harm, misinformation, or rights infringement, consent flags are required. This directly affects content creators, media companies, and anyone using generative AI for public-facing outputs.

The draft is not trying to ban AI-generated content. It is trying to create a traceability layer — a way for regulators and the public to distinguish between human-created and AI-created outputs. For Kenyan content creators, this means labelling becomes a legal obligation, not a best practice.

Foreign Provider Registration



Non-Kenyan AI providers serving high-risk Kenyan deployers will need local registration and conformity assessments. This is the provision that will matter most to international companies. OpenAI, Google, Meta, and any other provider whose models are used in high-risk Kenyan contexts will need a registered entity in Kenya and a documented compliance process.

The draft does not require full data localisation. But it does require that foreign providers demonstrate conformity with Kenyan standards — which means the AI Commissioner will set the benchmarks that global models must meet to operate in the Kenyan market.

What This Means for the Ecosystem



For Founders and Investors



The consultation window has closed, but the policy is not final. The AI Commissioner will use the feedback to refine the classification criteria, the enforcement mechanisms, and the registration requirements before issuing statutory instruments. Founders who operate in AI — particularly in fintech, healthtech, edtech, and GovTech — should be tracking the Commissioner's next moves. The rules being written now will determine compliance costs, market access, and competitive positioning for years.

The KES 152 billion earmarked in the National AI Strategy 2025–2030 is the funding envelope. The draft policy is the governance framework. Together, they form the operating system for Kenya's AI economy.

For Deployers



If you deploy AI systems in Kenya — whether you built them or bought them — the risk classification will determine your compliance burden. The draft's focus on high-risk sectors (finance, health, education, public services) means that most enterprise AI deployments will fall under the heaviest oversight.

The workplace impact obligation is the most novel requirement. It creates an HR compliance layer that did not exist before. Deployers will need to document how AI affects roles, what reskilling they fund, and what mitigation they offer. This is not just a policy requirement — it is a signal that the government is watching the employment effects of AI adoption.

For Foreign Providers



The local registration requirement is the clearest market-access gate. If your model is used in high-risk Kenyan deployments, you need a registered entity and a conformity assessment. This is not unique — the EU AI Act has similar requirements — but it does mean that providers who have treated Kenya as an untaxed, unregulated market will need to establish a formal presence.

The conformity assessment is the critical detail. The AI Commissioner will define what conformity means — what benchmarks, what testing, what documentation. Until those standards are set, foreign providers face regulatory uncertainty.

The Bigger Picture



Kenya's draft AI policy is not happening in isolation. It sits alongside the Data Protection Act, the Artificial Intelligence Bill 2026, and the National AI Strategy 2025–2030. Together, these form a regulatory stack that is more comprehensive than most African markets and more specific than many global frameworks.

The consultation feedback will shape the statutory instruments — the detailed rules that turn the draft's principles into enforceable requirements. The AI Commissioner's office will publish the feedback summary and the revised draft in the coming weeks. That is the next decision point.

For now, the actionable step is simple: if you build, deploy, or sell AI systems in Kenya, start documenting your risk assessments, your workplace impact plans, and your compliance posture. The rules are being written. The question is whether you are shaping them or reacting to them.

Source Links



Want to learn more?

Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.

Get in Touch