A summary of the Data Privacy and Governance Society of Kenya (DPGSK) webinar analysing the Artificial Intelligence Bill, 2026, featuring Quincy Tiano (Parliament; law and technology practitioner), Benji (technology representative, DPGSK; financial services privacy practitioner), and Josephine Kagoro (Research Associate, Centre for Intellectual Property and Information Technology Law – CIPIT, Strathmore University), moderated by Mutua.
Background
The Artificial Intelligence Bill, 2026 was introduced in the Senate on 19 February 2026. Its stated objects are to: establish a regulatory framework for AI in Kenya; ensure ethical, transparent, and accountable AI use; foster innovation; safeguard human rights, data protection, and public welfare; establish an Office of the AI Commissioner; promote AI literacy and advise county governments; and align with international AI standards. The Bill also proposes a multi-stakeholder Advisory Committee comprising representatives from the Office of the Data Protection Commissioner (ODPC), private sector, civil society, counties, and AI experts.
Where the Bill Falls Short of Kenya’s AI Strategy
Panellists repeatedly compared the Bill against Kenya’s existing AI Strategy and the in-progress AI and Emerging Technologies Policy and Data Governance Policy, arguing the Bill is narrower and more punitive than what those instruments envisioned:
- AI literacy: The Strategy envisioned curriculum reform from basic to tertiary education and skills-building as a development pathway. The Bill limits “AI literacy” to public education about AI’s benefits and risks — a much narrower scope, and one that (unlike the EU AI Act) does not impose a literacy obligation on AI providers/deployers regarding their own staff, including in public institutions.
- Enablement vs. punishment: The Strategy focused on enabling adoption — digital infrastructure, SME support, economic growth. The Bill is comparatively compliance- and penalty-focused, without matching investment in enabling provisions.
- Risk classification (Section 25): The Bill directs the AI Commissioner to classify systems as unacceptable, high, limited, or minimal risk, but leaves the actual definitions and criteria to future regulations — unlike the EU AI Act, which defines these categories in the primary legislation itself.
Provisions Panellists Considered Well-Designed
- Sections 31–35 (automated decision-making and explainability), grounded in Article 47 (fair administrative action) and Article 27 (equality) of the Constitution — seen as important given the growing use of AI in credit and loan decisions.
- Regulatory sandboxes (roughly Sections 36–41), modelled on the CMA’s sandbox framework operating since 2019, allowing controlled testing of AI innovations before public rollout.
- The multi-stakeholder Advisory Committee, bringing private sector, academia, and civil society into the consultative process.
- Alignment with the Data Protection Act, anchoring AI governance to an existing legal framework rather than creating an entirely free-standing regime.
- Risk-based classification as a concept, seen as a globally accepted regulatory model — though panellists cautioned its implementation will be difficult in practice.
The Office of the AI Commissioner: A Contested Proposal
Panellists raised significant concerns about creating an entirely new regulatory office:
- Jurisdictional overlap with the ODPC (which already oversees the data underpinning AI systems), the Communications Authority (regulates AI-generated content on digital platforms), and bodies like the National Commission for Science, Technology and Innovation (which promotes science and innovation policy).
- Resource competition: a new commission requires budget, staff, and infrastructure in an already fiscally constrained environment, competing with existing regulators for the same technical talent and funding.
- Standards fragmentation: risk of conflicting requirements between a new AI Commissioner’s standards and existing ODPC data processing guidance or Central Bank of Kenya (CBK) prudential guidelines.
- Suggested alternative: rather than a new commission, embed AI oversight functions within existing regulators — e.g., the ODPC for data-related oversight, CBK for financial-sector AI, the Kenya National Commission on Human Rights for bias/discrimination concerns — with increased budget allocations where needed, supported by formal inter-agency coordination mechanisms (e.g., MOUs, joint investigation protocols).
- A related concern raised: centralising control of an “algorithmic registry” in a single Commissioner’s office creates a risk of that office being able to unilaterally shut down AI systems or platforms.
Sector-Specific vs. Omnibus Regulation
A recurring theme was whether Kenya should have one comprehensive AI law or sector-specific AI provisions embedded within existing frameworks (financial services, healthcare, labour, data protection, cybersecurity). Panellists leaned toward the sectoral approach, arguing that:
- AI is “a tool,” not a single technology — its risks and appropriate liability regimes differ significantly by sector (e.g., financial credit scoring vs. healthcare vs. labour platforms).
- The Bill’s treatment of cybersecurity is described as only “in passing” (Section 26(f) simply references “robustness, accuracy and cybersecurity” without elaboration).
- Algorithmic management of labour — where platforms exert employer-like control (task allocation, pricing, deactivation) without being classified as employers — is not adequately addressed, despite Section 33 acknowledging AI-driven job displacement and recommending upskilling.
- A prior government review of 23 statutes (including labour law) for AI-readiness was cited as a preferable complementary approach to a single omnibus bill.
Lessons from Global AI Governance Models
- The EU AI Act is not seen as a ready-made template: its risk categories reflect political compromise as much as empirical evidence, and its resourcing assumes an economic scale Kenya does not have. Its implementing instruments were phased in gradually — a sequencing the Bill’s rushed timeline does not mirror.
- The US approach was noted as fragmented across executive orders (contrasting Biden-era AI safety orders with a subsequent Trump-era executive order) and agency-specific guidance (e.g., NIST’s risk management framework, Colorado’s anti-discrimination law).
- China was cautioned against as a misunderstood model — it operates via a patchwork of specific instruments (generative AI measures, algorithmic recommendation regulation, deep synthesis/deepfake rules) rather than one unified law, backed by state-directed infrastructure investment Kenya does not currently have.
- Extraterritorial reach: the Bill was criticised for reading as a purely domestic instrument, with no apparent mechanism to address AI tools, models, and infrastructure imported from or operated by foreign companies — a significant gap given Kenya’s heavy reliance on imported AI tools.
- Regional harmonisation (East African Community, African Union, the Malabo Convention) was repeatedly emphasised as more valuable than borrowing directly from the EU/US/China, given shared Global South context and the leverage a unified regional voice could have with major cloud and platform providers.
Intellectual Property Questions (Raised but Unaddressed in the Bill)
An audience question on AI and copyright drew attention to unresolved issues the Bill does not currently address:
- Whether commercial gains from AI-generated outputs (e.g., AI-generated music monetised on streaming platforms) belong to the end user, the developer/platform, or both.
- How liability would be apportioned where an AI-generated output causes harm classified as “unacceptable risk.”
- The lack of a single global consensus on AI-output IP ownership (jurisdictions such as Australia, the US, and Estonia have taken different positions), suggesting Kenya’s approach should be informed by its chosen regulatory model (risk-based vs. liability-based vs. prescriptive).
Dispute Resolution
On whether a dedicated AI tribunal is needed, panellists were skeptical, arguing AI is not a single “solution” but a cross-cutting technology — comparable to ICT generally. The preferred approach is enforcing AI-related harms through existing sector mechanisms (ODPC for automated decision-making/data protection breaches, courts for negligence claims, criminal justice system for criminalised conduct), provided that AI-specific rights are properly embedded within each sector’s existing laws.
Closing Views
All three panellists converged on a common recommendation: the Bill is premature. Suggested reasons included:
- Kenya’s AI Strategy and forthcoming AI/emerging technology and data governance policies had not yet been finalised or allowed to inform the Bill.
- A measured, sequenced approach — developing implementing instruments and codes of practice before primary legislation — was preferred over rushing to be a regional “first mover.”
- Sector-specific guidance (as seen in comparator markets developing AI strategies for individual sectors like healthcare before broader legislation) was suggested as a more practical interim step.
- One panellist suggested the Bill’s current substance more closely resembles a “deepfake control bill” than comprehensive AI legislation.
Source: DPGSK webinar recording. For more sessions on data privacy, data governance, and technology law, follow DPGSK on LinkedIn or visit datprivacyke.africa.