Kenya has taken another significant step towards regulating artificial intelligence (AI) and emerging technologies. Following the launch of the National Artificial Intelligence Strategy 2025–2030, the Ministry of Information, Communications and the Digital Economy has published the Draft Kenya Artificial Intelligence and Emerging Technologies Policy, 2026 (Draft AI Policy) for public participation, with comments due by 4 August 2026.
RELATED: Kenya’s Artificial Intelligence Bill, 2026 – Proposed too soon?
Beyond establishing governance principles for AI, the Draft AI Policy proposes a roadmap for legislative reform across existing legal frameworks, signaling that AI regulation is expected to become embedded throughout Kenya’s broader digital economy.
What you need to watch out for
AI regulation without borders
One of the most significant developments is the Draft AI Policy’s broad extraterritorial reach. The proposed framework extends to foreign AI providers and related service providers whose systems are procured, deployed, accessed or relied upon in Kenya, or whose outputs are used in Kenya or have ‘direct and foreseeable effects’ within the country.
This approach does not currently establish a clear threshold based on whether an AI system or service is intentionally offered or directed to the Kenyan market.
The framework also contemplates recognition of compliance with substantially equivalent foreign regulatory regimes. However, such recognition would be subject to an adequacy assessment by the Cabinet Secretary, and the criteria and process for determining equivalence will need to be determined in the enabling regulation or otherwise by the regulatory authority.
The Draft AI Policy also reflects an objective of digital sovereignty, with Kenya seeking to retain oversight and decision-making authority over AI systems, data and digital infrastructure that affect its jurisdiction. This approach underpins the AI Draft Policy’s extraterritorial scope and its emphasis on safeguarding national interests, constitutional values and public trust.
Responsibility will no longer rest with one player
Recognising that AI systems are rarely designed, deployed and operated by a single organisation, the Draft AI Policy indicates that future implementing legislation will provide for allocation of liability, accountability, insurance, and redress across developers, deployers, operators, vendors, and users, supported by requirements relating to transparency, explainability and auditability.
This marks a significant shift towards shared accountability, with organisations expected to understand and manage their role in the AI lifecycle while supporting regulatory oversight, enforcement and effective redress.
Sovereignty and strategic autonomy
The Draft AI Policy elevates data and model sovereignty to a standalone pillar – ‘Sovereignty and Strategic Autonomy’, reflecting concern that Kenya’s AI ecosystem remains heavily dependent on foreign platforms, cloud infrastructure, compute resources and proprietary models with limited domestic control over critical systems, data and the models built on them.The Draft AI Policy’s approach to data and system sovereignty rests on three linked pillars:
- data localisation and controlled cross-border data flow for sensitive/strategic datasets;
- a sovereign cloud and workload classification strategy based on a tiered approach mandating domestic hosting for ‘critical’ systems while permitting hybrid or commercial cloud for lower-risk workloads; and
- a broader strategic-autonomy agenda covering compute capability, talent, and regional infrastructure leadership.
Beyond risk: Governing AI across its lifecycle
While the Draft AI Policy adopts a risk-based approach to AI regulation, its governance ambitions extend well beyond risk classification.
The proposed framework focuses not only on the risks posed by AI systems, but also on how organisations design, deploy, monitor and remain accountable for them throughout their lifecycle. Organisations should expect governance obligations spanning:
- AI governance and accountability –this covers responsibility across the AI value chain, incident reporting, oversight and allocation of liability and responsibilities
- Incident reporting requirements – this is the investigation, and response mechanisms for AI-related failures, misuse, cybersecurity incidents, and safety events.
- Human oversight and user protection – this includes safeguards against manipulative or deceptive AI systems and mechanisms for complaints, appeals and redress.
- Workforce and vulnerable group protections – this introduces protections for children, vulnerable groups and statutory standards of care for organisations developing and deploying AI and workers involved in AI development.
- Intellectual property and data governance – this addresses training data, text-and-data mining, AI-generated outputs and the protection of Kenyan creative works, language resources, traditional knowledge and cultural heritage.\
- Content moderation – these are the transparency and authenticity requirements needed to address synthetic media, deepfakes and AI-generated content.
Looking ahead
The Draft AI Policy does not itself create legally binding obligations. However, it provides a clear indication of the direction of travel for Kenya’s emerging AI governance framework.
Organisations developing, deploying or procuring AI systems should begin assessing how the proposed framework may affect their AI governance structures, compliance programmes and deployment strategies. Early preparation will be key as Kenya moves towards a more comprehensive approach to AI regulation.

































