
Kenya’s AI policy proposes one of the country’s most ambitious digital regulatory frameworks to date, extending oversight to artificial intelligence systems used within Kenya even when their developers operate abroad. The proposal would place companies such as OpenAI, Meta and Anthropic within the scope of Kenyan rules if their AI models are accessed locally or produce effects that reach Kenyan individuals, businesses or public institutions.
The approach reflects a wider effort to establish clear governance for technologies that have become part of everyday business operations, government services and consumer applications.
The draft policy adopts what regulators describe as an effects-based jurisdiction. Instead of limiting oversight to companies with offices in Kenya, the proposal applies to AI providers whose systems are used in the country or have direct and foreseeable consequences for people and institutions within Kenya.
That means AI developers behind products such as ChatGPT, Claude and Llama could be required to comply with Kenyan requirements even without maintaining a physical presence in the country. Google and Microsoft already operate local offices, but the proposal extends beyond companies with established Kenyan operations.
The model closely resembles regulatory approaches used in the European Union, where authorities exercise oversight over digital services offered to European residents regardless of where the provider is headquartered.
The proposal also follows a broader direction that Kenya has pursued across the digital economy. Recent tax and financial reporting reforms have expanded oversight of foreign digital service providers, cryptocurrency platforms and cross-border financial information, reflecting a policy preference that participation in Kenya’s digital market carries regulatory responsibilities alongside commercial opportunities.
Rather than treating every AI application the same, the policy proposes a framework based on risk.
Although Kenya has not yet published its own list of high-risk AI systems, the draft draws on principles similar to those found in the European AI Act. Systems deployed in areas such as healthcare, education, policing, justice, elections and critical infrastructure would be expected to face closer scrutiny than lower-risk applications.
Depending on the level of risk, AI providers could be required to conduct risk assessments before deployment, explain model capabilities and limitations, and disclose data sources where appropriate. Furthermore, they may need to label AI-generated content clearly, maintain human oversight, implement cybersecurity safeguards, and support robust auditing and redress mechanisms.
The government also proposes maintaining a central register for high-risk AI systems and reviewing risk classifications as technology evolves.
The draft extends beyond private technology companies.
Government agencies would need to complete AI impact assessments before deploying high-risk systems in areas including taxation, healthcare, education, employment, policing, justice and public service delivery.
A public register would also record AI systems used across government, except where national security considerations prevent disclosure.
The procurement framework introduces another notable requirement. International technology companies seeking government AI contracts would be expected to work with Kenyan technology firms, a provision intended to encourage local participation, knowledge transfer and domestic capability development.
The proposal also reaches into the workforce supporting artificial intelligence.
Kenya has become an important destination for AI data annotation and content moderation, with thousands of workers employed through outsourcing companies that support global technology platforms.
The draft policy introduces minimum standards covering written employment contracts, mental health support, grievance procedures and transparent pay practices. It also calls for compensation frameworks that take international benchmarks into account for AI data annotators, content moderators and AI quality evaluators.
These measures respond to concerns raised in recent years over psychological harm, workplace conditions and compensation for employees who review harmful online material or prepare training data used by modern AI models.
The draft policy fits within a broader regulatory agenda taking shape across Kenya’s digital economy.
The Competition Authority of Kenya has already indicated that artificial intelligence, algorithms and Big Data will become a larger focus of competition enforcement. The Authority is investing in digital forensic capabilities as businesses adopt automated pricing systems, machine learning and data-driven decision making.
Taken together, the ICT Ministry’s draft policy and the Competition Authority’s plans point toward a governance model that extends beyond AI safety. Technology regulation, competition oversight, public procurement and labour standards are beginning to operate as connected parts of a wider digital policy framework.
Despite its broad scope, the proposal leaves several important questions unresolved.
The draft does not specify financial penalties for non-compliance or identify which agency will lead enforcement efforts. Additionally, it leaves unaddressed whether overseas companies will need local representatives, as well as the legal process for enforcing obligations against providers with no physical presence in Kenya. Finally, Kenya’s final definition of high-risk AI systems remains unspecified.
Those details will determine how the framework operates in practice once the policy progresses into legislation or supporting regulations.
The draft AI policy shows that Kenya is moving beyond encouraging AI adoption toward defining how the technology should be governed.
Rather than focusing on a single issue, the framework combines technology oversight, public sector accountability, workforce protections, procurement requirements and cross-border regulatory authority.
If adopted, the policy would place Kenya among the African countries with one of the most comprehensive approaches to AI governance. It would also reinforce a broader regulatory direction that has emerged across digital taxation, competition policy and financial oversight: digital services that reach Kenyan users are expected to meet Kenyan standards, regardless of where the companies behind them are based.
Download the free Kaspersky SMB Cybersecurity Guide here to learn how businesses can move beyond traditional antivirus and build a more resilient approach to cybersecurity.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to editorial@techtrendsmedia.co.ke




