Back to Blog
Kenya’s Draft AI Policy 2026: What Businesses Need to Know
AI

Kenya’s Draft AI Policy 2026: What Businesses Need to Know

September 13, 2026GashoTech

Kenya’s Draft AI Policy 2026: What Businesses Need to Know



Introduction



Kenya’s Ministry of Information, Communications and the Digital Economy (MICDE) has published the Draft Artificial Intelligence and Other Emerging Technologies Policy, 2026 for public consultation. The policy is open for comments until August 4, 2026, and represents a significant step toward establishing a comprehensive AI governance framework in the country. This draft builds on Kenya’s existing AI Strategy (2025-2030), the Digital Master Plan (2022-2032), and the Data Protection Act (2019), while aiming to address coordination gaps identified in stakeholder consultations.

Policy Objectives and Scope



The draft policy aims to create a national framework that governs the development, deployment, and use of artificial intelligence and other emerging technologies across all sectors of the economy. It seeks to promote innovation while ensuring safety, security, inclusivity, and alignment with Kenya’s broader development goals, including the Bottom-Up Economic Transformation Agenda (BETA) and Vision 2030.

Institutional Framework: National AI and Other Emerging Technologies Council



At the heart of the policy is the proposed National AI and Other Emerging Technologies Council, which will serve as the central regulatory authority for AI in Kenya. The Council will be led by an AI and Other Emerging Technologies Director and supported by:

  • A Governing Board providing strategic oversight.

  • A Technical Advisory Forum offering expert guidance on emerging technologies.

  • Five specialized Directorates:

1. Policy & Standards: Developing AI policies, standards, and guidelines.
2. Compliance & Risk: Monitoring adherence to regulations and assessing risks.
3. Regulatory Sandbox: Managing controlled testing environments for innovative AI applications.
4. Advisory and Capacity Building: Providing technical assistance, training, and public awareness programs.
5. Safety and Security: Ensuring AI systems are resilient against threats and adhere to safety protocols.

Risk-Based Approach to AI Regulation



The policy introduces a risk-based classification system for AI applications, categorizing them into minimal, limited, high, and unacceptable risk levels. Key provisions include:

  • High-Risk AI Systems: Applications in critical sectors such as healthcare, transportation, energy, and public safety that require mandatory registration, impact assessments, and ongoing compliance monitoring.

  • Limited and Minimal Risk: Lower-risk applications subject to transparency obligations and voluntary standards.

  • Unacceptable Risk: AI systems deemed harmful to public safety, security, or fundamental rights are prohibited.


This approach allows regulators to focus resources on areas with the highest potential impact while minimizing burdens on low-risk innovators.

Regulatory Sandboxes: Balancing Innovation and Safety



To foster innovation without compromising safety, the policy establishes regulatory sandboxes where businesses and researchers can test emerging AI technologies under regulatory supervision. These sandboxes will:
  • Provide temporary relief from certain regulatory requirements during the testing phase.

  • Offer guidance on compliance requirements and risk mitigation.

  • Facilitate collaboration between innovators, regulators, and other stakeholders.

  • Generate data to inform future policy decisions and standards development.


Sectoral Applications and Local Content Promotion



The policy encourages the adoption of AI in priority sectors such as agriculture, healthcare, education, finance, and manufacturing. It includes provisions to:
  • Support local AI research and development through grants and partnerships.

  • Promote the use of locally developed AI solutions in public procurement.

  • Encourage capacity building and skill development in AI technologies for Kenyan workers.


Data Governance and Privacy



Recognizing the symbiotic relationship between AI and data, the policy emphasizes robust data governance practices. It builds on the Data Protection Act (2019) to ensure that AI systems handle personal data responsibly, with provisions for:
  • Data minimization and purpose limitation in AI training and deployment.

  • Consent mechanisms and data subject rights in AI-driven processing.

  • Security measures to protect data used by AI systems from breaches and misuse.

  • Cross-border data transfer rules aligned with international standards.


Ethics, Safety, Security, and Inclusion



The policy integrates ethical considerations throughout its framework, requiring AI systems to:
  • Adhere to principles of fairness, transparency, and accountability.

  • Implement bias detection and mitigation measures.

  • Ensure accessibility for persons with disabilities.

  • Protect against misuse for surveillance, discrimination, or harmful content generation.

  • Incorporate cybersecurity best practices to safeguard AI infrastructure.


Infrastructure and Digital Readiness



To support widespread AI adoption, the policy addresses infrastructure and readiness gaps, including:
  • Expanding broadband connectivity and computing capacity in underserved regions.

  • Promoting cloud and edge computing solutions for AI workloads.

  • Supporting the development of AI-ready data centers and digital infrastructure.

  • Encouraging public-private partnerships to accelerate infrastructure development.


Public Consultation Process



The public consultation period runs from the date of publication until August 4, 2026. Stakeholders are invited to submit written comments and memoranda via:
  • Email: aipolicy@moict.go.ke or legal@moict.go.ke

  • Physical delivery: Committee on AI and Other Emerging Technologies, Nairobi, 10th Floor, Telposta Towers

  • Online portal: Available on the MICDE website (https://ict.go.ke/call-public-partipation)


All submissions will be reviewed by the Ministry, and feedback will be considered in finalizing the policy before submission to Cabinet and Parliament.

Implications for Stakeholders



Businesses and Investors


  • Clarity on regulatory expectations reduces uncertainty for long-term planning.

  • Opportunities to engage in policy shaping and access regulatory sandboxes.

  • Need to assess compliance requirements early in the product development lifecycle.


Innovators and Startups


  • Access to testing environments for novel AI applications.

  • Guidance on navigating regulatory requirements while innovating.

  • Potential for collaboration with government agencies on pilot projects.


Civil Society and Academia


  • Opportunity to advocate for inclusive, ethical, and human-centered AI approaches.

  • Ability to contribute expertise on technical, social, and environmental impacts.

  • Platform to monitor policy implementation and hold authorities accountable.


Conclusion



Kenya’s Draft AI Policy 2026 marks a pivotal moment in the country’s journey toward becoming a regional AI hub. By establishing a clear, risk-based regulatory framework that promotes innovation while safeguarding public interests, the policy aims to create an environment where AI can thrive responsibly. The public consultation process offers a critical opportunity for stakeholders to shape the future of AI governance in Kenya. As the August 4 deadline approaches, businesses, innovators, and citizens are encouraged to review the draft, provide informed feedback, and participate in building a trusted AI ecosystem for Kenya’s digital transformation.

Word count: ~1050

Want to learn more?

Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.

Get in Touch