
AI
Kenya's Prembly Puts Identity Checks Inside Claude and ChatGPT - The Agentic AI Trust Race Is On
October 5, 2026GashoTech Team
The trust problem agentic AI created
The AI industry spent 2025 and much of 2026 teaching chatbots to talk. The next phase is harder: teaching AI agents to act, and proving, every single time, that the actions they take are legitimate.
That is a trust problem, and on 1 October 2026 a Kenya-founded company walked straight into the middle of it. Prembly, the identity verification and compliance infrastructure firm behind products used by banks, fintechs and platform businesses across Africa and beyond, launched its MCP Server - a connector that plugs its entire verification stack directly into AI assistants such as Claude and ChatGPT.
In plain terms: a compliance officer can now ask an AI assistant, in natural language, to verify an identity, screen a business against sanctions and PEP lists, or run a fraud intelligence check - and the assistant will actually do it, through Prembly's APIs.
What the MCP Server actually does
The Model Context Protocol (MCP) is the emerging open standard for connecting AI assistants to external tools and data sources. Prembly's server acts as a middleman: on one side it speaks MCP to an AI assistant, and on the other it makes standard REST API calls to Prembly's Core APIs, authenticated with the customer's own API key.
The capabilities exposed include identity verification, KYC and KYB (know your business), anti-money laundering checks, politically exposed person screening, fraud intelligence, and account management. Before this launch, using these tools required a developer to read API documentation, build a custom integration, and wire up workflows before anyone could run a check. Now the workflow starts with a sentence.
Two groups benefit immediately. Developers stop building and maintaining bespoke integrations for every AI platform that appears. Compliance and operations teams, who were never going to learn to code, get direct access to the checks that gate their daily work.
The security design is the story, not a footnote
The obvious question for any identity-data integration with a third-party AI model is: where does the data go? Prembly's answer is built into the product. Organisations can choose deployment options that align with their own security policies, including enterprise AI solutions with Zero Data Retention - meaning the AI provider processes but does not store the data - or locally hosted AI models, which keep sensitive identity data inside the organisation's own perimeter.
That choice matters more than it sounds. Identity verification data is among the most sensitive information any organisation handles: ID numbers, addresses, biometrics, financial records. Under Kenya's Data Protection Act, and equivalents in other markets, a business that pipes that data into an external AI service without a legal basis and contractual safeguards is creating liability, not efficiency. A trust product that ignores this would be a contradiction in terms. Prembly's design acknowledges that the buyer of trust infrastructure is, in part, buying data control.
Why the timing is not accidental
Prembly CEO Lanre Ogungbe framed the launch with a striking figure: nearly 90 per cent of organisations now use AI. The full quote is worth sitting with. As a technology-first company, he said, the priority is making trust more straightforward and accessible, because AI is moving into the workflows businesses already rely on.
The regulatory backdrop gives that framing teeth. Kenya's Central Bank published draft guidance on the use of AI in financial institutions that classifies only agentic AI - systems that take actions on their own - as high-risk, with the stricter governance and approval obligations that follow. Regulators elsewhere are converging on the same distinction: a chatbot that drafts text is one thing; an agent that can move money, open accounts, or onboard a customer is another.
That distinction creates a market. If agentic AI is to be allowed anywhere near onboarding, payments or lending, it needs provable guardrails: verified identities, auditable decisions, screening that runs before the agent acts rather than after. Prembly's MCP Server is, in effect, a pre-built guardrail kit for exactly that scenario. The launch reads less like a feature announcement and more like a bet on which layer of the AI economy becomes scarce first.
The Kenyan angle: moving up the stack
For years, the story of Kenyan tech has been consumer products: mobile money, lending apps, ride-hailing, betting platforms. The infrastructure layer - the identity, compliance and fraud tools those products sit on - was largely imported or built quietly in the background.
Prembly has been part of the change in that picture, and this launch sharpens it. The MCP Server is available worldwide, with the underlying API tools functioning globally. A compliance team in Lagos, Nairobi, London or Dubai can connect the same Kenyan-origin infrastructure to their AI stack on the same day.
That is what moving up the stack looks like: competing not on local market knowledge, but on the quality of plumbing that everyone else has to trust. It is the same position Stripe occupies in payments, or Twilio in communications - the unglamorous, deeply reliable layer that other products are built on.
What to watch
Three questions will decide whether this launch is a milestone or a footnote.
First, adoption. MCP is still a young standard, and enterprises move slowly. Watch whether Kenyan and African banks, saccos and fintechs move first, or whether the earliest adopters are Prembly's existing customers abroad.
Second, the regulator's response. CBK's draft AI guidance is out for industry input. If final rules require documented controls for agentic AI in financial services, products like this shift from nice-to-have to near-mandatory. If the rules soften, the urgency softens too.
Third, competition. Global KYC incumbents will not cede the agentic layer to a Nairobi-origin challenger. The trust-infrastructure race in AI is only starting, and the winner will be whoever compliance teams trust when the agent is moving faster than the human.
The bottom line
Agentic AI is only as deployable as the trust infrastructure around it. The industry's hardest problem right now is not making agents smarter; it is making their actions verifiable, auditable and safe. A Kenyan company just shipped a serious answer to that problem - and in doing so, signalled where the next decade of African tech value might actually sit: not in the apps, but in the rails underneath them.
If your organisation is experimenting with AI agents anywhere near customer onboarding, identity data or payments, this launch is your prompt to ask one question before anything else: what checks does my agent run before it acts, and where does the data it touches actually live?
Want to learn more?
Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.
Get in Touch