Back to Blog
Kenya Hosts Six African Regulators to Rewrite the Rules for AI, Cybersecurity and Data
Cybersecurity

Kenya Hosts Six African Regulators to Rewrite the Rules for AI, Cybersecurity and Data

October 9, 2026GashoTech Team
While most of Nairobi's tech conversations this week are about funding rounds and product launches, a quieter meeting is underway that will shape the rules behind all of them. From October 5 to 9, Kenya's Communications Authority is hosting regulators from six African countries in Nairobi under the ICT Policy and Regulation Institutional Strengthening Programme, better known as iPRIS. The participants come from Sierra Leone, Mauritius, Namibia, Zimbabwe, Tanzania and Liberia, joined by regional bodies including CRASA, EACO and WATRA, and by experts from Sweden, Luxembourg and Portugal.

On the surface, it is a capacity-building workshop. In practice, it is a working session on the hardest regulatory problem of the decade: how to govern a digital economy that no longer respects the boundaries between telecoms, finance, data protection and consumer rights.

The Problem: One Digital System, Five Regulatory Mandates



The traditional telecom regulator licensed networks and managed spectrum. That job description is obsolete. Today, a single digital service can touch communications infrastructure, financial services, personal data, competition policy and consumer safety at the same time.

Consider what Kenyans already live with. An AI system that helps decide whether you get a loan sits at the intersection of financial regulation, data protection and emerging AI governance rules. A payment app runs on telecom infrastructure, processes financial data and competes with banks. A cloud provider hosting government systems raises questions of cybersecurity, resilience and sovereignty all at once.

David Mugonyi, Director General of the Communications Authority of Kenya, framed the challenge at the opening session: rapid development in AI, digital platforms and next-generation networks is creating real economic opportunity while presenting increasingly complex regulatory challenges. His prescription: regulators must remain agile, evidence-driven and collaborative.

That last word matters most. No single regulator, and no single country, can solve this alone.

Why the Stakes Are This High



The economics explain the urgency. According to GSMA figures cited at the forum, mobile technologies and services contributed about 240 billion US dollars to Africa's economy in 2025, equivalent to 7.8 percent of the continent's GDP, and support around 13 million jobs. The projection for 2030 is roughly 290 billion dollars.

But the same expansion creates risks that sector-by-sector rulebooks struggle to contain. Cybersecurity offers the clearest Kenyan example. The National KE-CIRT/CC detected more than 3.36 billion cyber threat events between January and March 2026 and issued 20.6 million advisories in that period alone. A detected threat event is not a confirmed breach, but the volume shows the scale of hostile activity moving across the region's infrastructure every day. The threat is also evolving: security agencies report increasing use of AI and automation by malicious actors to improve phishing, reconnaissance and social engineering.

This is a defensive problem for everyone who uses digital services. It means the institutions that watch over your network, your bank and your data need to share intelligence faster than the threats move. That is precisely what the Nairobi forum is designed to build.

The Inclusion Problem Nobody Can Regulate Away



There is a second, quieter crisis running alongside the security one. GSMA estimates that nearly one billion Africans, about 63 percent of the population, were not using mobile internet in 2025 despite living within mobile broadband coverage. The barriers are affordability, digital skills and access to suitable devices.

This matters for governance because coverage is not adoption, and adoption is not meaningful use. A country can celebrate network rollout statistics while its citizens still cannot access the services being digitised. Professor Caroline Wamala Larsson, Director of SPIDER, made this point in Nairobi: Africa's digital transformation should be judged by who can access new technologies, who can use them meaningfully, who benefits and who remains excluded.

For Kenya specifically, the ITU reports that only 18 percent of African countries have reached its most advanced stage of ICT regulatory development, against a global average of 38 percent. The gap is not ambition. It is institutional capacity, and that is exactly what iPRIS exists to close.

From Workshop to Enforceable Change: The May 2027 Test



The most important thing about this forum is not what is discussed this week. It is what each participant takes home.

iPRIS works through "Change Initiatives": institution-specific reform projects that each participating regulator developed after the cohort's first gathering in Sweden in May 2026. These projects cover spectrum management, connectivity, cybersecurity, consumer protection and digital inclusion. This week's Nairobi session is the halfway review. Final reports are due in May 2027.

That timeline gives the region something rare in tech governance: a measurable test. In May 2027, anyone will be able to ask whether the regulators who sat in Nairobi actually changed their policies, procedures and institutional capabilities, or simply attended another workshop.

What Kenya Gets Out of Hosting



Kenya is not a bystander here. Hosting the forum puts the country's own regulatory experiments under friendly peer review, from the emergency-alert systems the Communications Authority has been hardening, to the AI-in-lending rules now requiring transparency, bias checks and human oversight from credit providers, to the data protection regime that had received over 7,000 complaints by March 2025.

There is also an economic argument. UNESCO estimates AI could add up to 1.2 trillion dollars to Africa's economy by 2030, but warns that many large language models remain poorly adapted to African languages. The countries that build credible, coherent regulatory institutions will be the ones that attract the investment, infrastructure and local AI development needed to capture that value. Regulation, done well, is not a brake on the digital economy. It is part of the infrastructure.

The Takeaway



The story to watch this week is not a keynote. It is whether six regulatory institutions left Nairobi with sharper plans for governing AI, cybersecurity and data as one connected system, and whether those plans survive contact with their home bureaucracies. The deadline is May 2027. The rules that will govern how your mobile money, your lender and your personal data behave are being written in rooms like this one. It is worth knowing what comes out of them.

Follow GashoTech as we track the outcomes that matter for Kenya's digital economy.

Want to learn more?

Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.

Get in Touch