Last Updated 2 hours ago by Kenya Engineer
Kenya now has a National Artificial Intelligence Strategy, a draft Artificial Intelligence and Other Emerging Technologies Policy and a proposed Artificial Intelligence Bill.
Each instrument responds to a genuine need. Together, however, they could produce duplicated institutions, conflicting responsibilities and a compliance system that Kenya lacks the technical capacity to operate.
That concern is at the centre of recommendations submitted by the Collaboration on International ICT Policy for East and Southern Africa to the committee reviewing the draft policy.
CIPESA has called for closer alignment among Kenya’s AI instruments, mandatory human-rights and gender assessments for high-risk systems, stronger independent oversight, worker protections and verified disclosure of AI’s environmental effects.
These are stakeholder recommendations, not adopted government policy. They nevertheless provide a useful basis for testing whether Kenya is building one coherent governance system—or several frameworks competing to regulate the same technology.
Three instruments, different roles
| Instrument | Principal role | Central emphasis | Emerging concern |
|---|---|---|---|
| National AI Strategy 2025–2030 | Development roadmap | Infrastructure, data, research, innovation and commercialisation | Ambitions require budgets, computing capacity and measurable delivery |
| Draft AI and Emerging Technologies Policy, 2026 | Broad governance and institutional framework | Nine pillars, risk classification, sustainability, sovereignty and proposed national council | May create structures overlapping with the proposed law |
| Artificial Intelligence Bill, 2026 | Proposed binding legislation | Oversight, investigation, sanctions and AI Commissioner | Institutional design differs from the policy’s proposed council |
The strategy, launched in 2025, is principally developmental. It seeks to position Kenya as a regional AI hub through digital infrastructure, data ecosystems, research, innovation and talent.
The 2026 draft policy goes further. It proposes a unified framework covering nine pillars, including sectoral applications, infrastructure readiness, safety, sustainability, data management and strategic autonomy. It also proposes a National AI and Other Emerging Technologies Council.
The proposed bill, meanwhile, envisages an Office of the AI Commissioner with investigative, enforcement and regulatory responsibilities.
The obvious question is whether Kenya needs both a council and a commissioner—and, if it does, how their powers would differ.
Unless this is resolved before enactment and implementation, developers could face multiple registration and reporting channels, while agencies dispute who has authority when a harmful system is deployed.
Risk classification needs a testing infrastructure
The draft policy’s use of risk categories is broadly sensible. An entertainment recommendation tool should not face the same level of scrutiny as an AI system used in medical diagnosis, credit decisions, policing or infrastructure control.
The challenge begins when risk classification moves from policy language to engineering practice.
Who determines that a system is high-risk? What evidence must a developer provide? Which laboratories or auditors can test it? What standards will they use? How will government assess a foreign proprietary model whose training data and internal parameters are not disclosed?
For a high-impact system, an audit may need to examine data quality, cybersecurity, bias, explainability, reliability, human oversight and performance under unusual conditions.
Average accuracy is not enough. A predictive-maintenance model could appear highly accurate while missing the rare failures capable of causing catastrophic equipment damage. A medical model may perform well overall while being less reliable for populations underrepresented in its training data.
Kenya will need independent technical expertise, recognised testing standards and credible accreditation. Creating a legal obligation to audit AI without building an auditing profession could reduce compliance to paperwork.
Environmental reporting must become measurable
CIPESA recommends verified disclosure of energy use, water consumption, emissions and electronic waste associated with AI systems.
The recommendation is important because AI is often presented as an intangible cloud service. In reality, it operates through data centres containing servers, storage, networking systems, power-conversion equipment and cooling infrastructure.
Kenya’s renewable-heavy electricity mix could give the country a lower-carbon advantage for hosting digital infrastructure. But renewable generation on the national grid does not remove questions about demand, peak capacity, backup diesel generation or transmission constraints.
Data-centre reporting could include:
- Total electricity consumption
- Power usage effectiveness
- Source and carbon intensity of electricity
- Backup-generator fuel consumption
- Water usage effectiveness
- Cooling technology and water source
- Hardware replacement cycles
- Electronic-waste recovery and disposal
- Capacity and location of computing workloads
Disclosure must be designed carefully. Overly broad obligations could expose commercially or nationally sensitive infrastructure information. Reporting should therefore be standardised and proportionate, with more demanding requirements for large computing facilities and high-impact systems.
Cooling water requires local context
Water consumption differs sharply by data-centre design.
Air-cooled systems may use less direct water but consume more electricity under certain conditions. Evaporative cooling can reduce electrical demand while increasing water use. Closed-loop systems can reduce ongoing consumption but still require careful thermal design.
Kenya cannot simply import reporting thresholds from cooler or water-abundant regions. Nairobi’s climate, grid characteristics and water constraints differ from those of Mombasa, Naivasha or northern Kenya.
Planning authorities should consider electricity capacity, fibre routes, heat rejection, water stress and opportunities to use non-potable or recycled water when evaluating very large facilities.
This is where AI governance becomes unmistakably an engineering issue.
Electronic waste will grow with computing demand
AI infrastructure depends on specialised processors that may be replaced as workloads and hardware generations change. Batteries, servers, networking equipment and cooling components also have finite lives.
Kenya already faces challenges in the collection and safe processing of electronic waste. Large AI and cloud operators should maintain asset inventories and work with licensed recyclers, with documented chains of custody for retired equipment.
However, premature replacement should not be encouraged in the name of innovation. Procurement policies can require modularity, repairability, secure data erasure and responsible resale or reuse where equipment remains functional.
The workforce question extends beyond software developers
CIPESA’s call for worker protection highlights data annotators and content moderators—workers who often experience insecure employment or exposure to distressing material.
The wider AI workforce also includes electrical engineers, data-centre technicians, cybersecurity professionals, cooling specialists, network engineers and independent assessors.
Kenya’s strategy should connect training to these physical and assurance roles. Otherwise, the country may develop more AI users while remaining dependent on foreign firms for the most critical infrastructure and testing functions.
Kenya needs a single implementation architecture
Before finalising the policy or enacting legislation, government should publish a reconciliation framework showing:
- Which instrument creates each institution
- The legal authority and limits of each body
- Which systems must register and with whom
- How existing regulators retain sectoral authority
- How the ODPC, Communications Authority and KEBS participate
- Which standards apply to high-risk systems
- How appeals, investigations and enforcement work
- Who verifies environmental and safety disclosures
- How implementation will be financed
The goal should not be to regulate AI through one enormous institution. Healthcare, finance, communications and transport regulators will continue to require sector-specific authority.
What Kenya needs is a clear coordinating architecture—one that establishes common AI principles and testing requirements without duplicating the work of existing agencies.
CIPESA’s submission correctly identifies the risk of fragmented accountability. The engineering concern is just as important: Kenya could create sophisticated audit and disclosure obligations before it has the standards, laboratories, data and skilled personnel needed to enforce them.
A coherent system would align the strategy’s development ambitions, the policy’s governance direction and the legislation’s enforceable obligations. Anything less may produce a crowded regulatory landscape in which responsibility becomes hardest to locate precisely when an AI system causes harm.

























