Back to Blog
Kenya Opens AI Policy Consultation: A 7-Day Window for Founders to Shape AI Governance
AI

Kenya Opens AI Policy Consultation: A 7-Day Window for Founders to Shape AI Governance

July 28, 2026GashoTech Team

Kenya Opens AI Policy Consultation: A 7-Day Window for Founders to Shape AI Governance



On 27 July 2026, Kenya’s Ministry of Information, Communications and the Digital Economy opened a public consultation on its Draft Artificial Intelligence and Other Emerging Technologies Policy. Comments are accepted until 4 August 2026.

That seven-day window is not a routine bureaucratic exercise. It is the first structured opportunity for founders, deployers, investors, and foreign technology providers to influence the register, grading criteria, and enforcement architecture that will govern AI systems in Kenya for the next decade.

If your company builds, deploys, funds, or supplies AI systems used in Kenya — especially in finance, health, education, or public services — the policy draft is already relevant to you. The question is whether you will engage before the rules harden.

The governance gap this is meant to fill



Kenya has been one of Africa’s most aggressive adopters of digital infrastructure. M-Pesa rewired payments. The National AI Strategy 2025–2030 allocated KES 152 billion over five years to accelerate AI adoption across agriculture, health, finance, and government. The Data Protection Act 2019 already imposes constraints on personal data processing.

What was missing was a dedicated AI statute with enforceable obligations, an oversight institution, and a mechanism for grading AI systems by risk. That gap is what the draft policy, and the parallel Artificial Intelligence Bill, 2026, are designed to close.

The draft policy is deliberately broad: it covers AI, blockchain, IoT, robotics, and other emerging technologies. Its core mechanism is a risk-based classification system that will assign different compliance burdens depending on how much a system affects health, safety, fundamental rights, the environment, or livelihoods.

What the draft says about high-risk AI



Under the draft, an AI system would be classified as high-risk if it is deployed in critical sectors — finance, healthcare, education, public administration, employment, or security — or if it makes decisions with legal or similarly significant effects on individuals.

For those systems, the draft proposes:

  • Pre-deployment risk assessments and human-rights impact assessments before the system goes live.

  • Mandatory human oversight — automation cannot fully replace human decision-making in high-stakes contexts.

  • Five-year record-keeping — deployers must retain documentation on training data, inputs, outputs, and performance metrics.

  • Annual compliance reporting to the AI Commissioner, with renewal triggered by material changes to the system.

  • Cybersecurity and robustness standards that align with the Computer Misuse and Cybercrimes Act and the Data Protection Act.


For AI systems that generate images, voice, or synthetic likenesses, the draft introduces explicit labelling and consent requirements — particularly where there is risk of harm, misinformation, or infringement of rights. That provision directly targets deepfake technology and AI-generated political content.

A new workplace obligation



One of the less discussed but equally consequential provisions is the workforce impact assessment. Where AI deployment is likely to affect employment, deployers must analyse the impact on staff and implement mitigation measures — including reskilling or redeployment programmes — in collaboration with government agencies.

For Kenyan employers already navigating a competitive tech labour market, this adds a new compliance layer on top of existing employment law. It also signals that the policy treats AI as a labour-market intervention, not just a technology procurement decision.

Foreign providers face local registration



The draft makes no exception for offshore AI providers. Foreign companies whose systems are used in high-risk Kenyan contexts — Open AI, Google, Meta, and others — would be required to register with the AI Commissioner, provide technical documentation, and submit to conformity assessments for their Kenya-facing deployments.

The practical effect is that Kenyan deployers of foreign AI models will carry compliance exposure, and foreign providers will need local legal and technical representation. That is a meaningful compliance cost, and it aligns Kenya with the risk-based logic of the EU AI Act.

What the AI Commissioner will actually do



The draft proposes establishing an Office of the Artificial Intelligence Commissioner as an independent State Office. The Commissioner’s functions would include:

  • Conducting risk assessments, conformity audits, and post-market surveillance.

  • Developing guidelines, standards, and codes of practice on AI governance, ethics, and safety.

  • Promoting AI literacy and public awareness.

  • Advising the Cabinet Secretary on regulations covering classification criteria, assessment methodologies, and enforcement mechanisms.


The Commissioner would also chair an Advisory Committee on Artificial Intelligence, with representation from government, the Office of the Data Protection Commissioner, scientific bodies, the private sector, and civil society. That committee would advise on emerging risks, ethical considerations, and workforce transitions.

Why this consultation matters now



Kenya is not the first African country to draft AI governance rules. Nigeria’s Digital Economy and E-Governance Bill, South Africa’s POPIA-based framework, and Rwanda’s AI policy have all moved in similar directions. What makes Kenya’s draft distinct is its timing relative to the National AI Strategy and the emerging constitutional requirement for public participation.

The four-week consultation — closing 4 August 2026 — is the moment when the grading criteria, enforcement priorities, and compliance burdens are still malleable. Once the policy is gazetted and the AI Bill advances through Parliament, the window for influencing the structure of the rules narrows sharply.

For founders, the most strategically valuable engagement points are:

  • The register of high-risk systems — shaping which use cases are captured, and which are exempted.

  • The proportionality of record-keeping and reporting burdens — ensuring compliance costs are commensurate with actual risk.

  • The definition of workplace impact — influencing how and when reskilling obligations apply.

  • The labelling and consent thresholds for AI-generated content — particularly for media, marketing, and political applications.

  • The registration and conformity-assessment process for foreign providers — ensuring it does not become a non-tariff barrier to innovation.


How to participate



The Ministry of Information, Communications and the Digital Economy is accepting submissions through:

  • An online consultation portal at ict.go.ke.

  • Email submissions to the Committee on Artificial Intelligence and Other Emerging Technologies.

  • Written submissions addressed to the Committee.


The consultation is open to government institutions, private sector organisations, academia, civil society, professional bodies, innovators, development partners, and members of the public.

Conclusion



Kenya’s draft AI policy is a pivot moment. The country has already committed the money and the political will to become an AI leader. Now it is writing the rules that will determine whether that ambition produces trusted innovation or regulatory friction.

Founders who engage before 4 August will help shape those rules. Founders who wait will inherit them — and may find that the register, the grading criteria, and the enforcement priorities were written without their input.

The question is not whether Kenya needs AI governance. It is whether the governance will be shaped by the ecosystem it governs, or designed around it.

The consultation closes 4 August 2026. Submit your feedback through the Ministry of ICT portal.

Want to learn more?

Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.

Get in Touch