August 4, 2026 marked the close of the public participation period for Kenya’s Draft AI and Emerging Technologies Policy.
Since the draft’s release in July, headlines have largely focused on provisions that could require foreign AI companies such as Meta and OpenAI to comply with Kenya’s regulatory framework.
However, the headlines only tell part of the story. The draft policy contains a much broader vision for how artificial intelligence could shape Kenya’s future.
In this extensive analysis, we’ll cover what the Draft Kenya AI and Emerging Technologies Policy is, the rationale behind it, its scope, the enforcement structure, its potential effects on the country’s stakeholders, and the challenges that could determine its success.
Table of Contents
What is the Draft Kenya AI and Emerging Technologies Policy?
The policy is a national framework that sets out how AI and other emerging technologies should be developed, deployed, governed, and used in Kenya.
The draft policy is centered around 9 thematic pillars:
- Research, Innovation and Commercialization Ecosystem Development
- Sectoral Applications of AI and other Emerging Technologies
- Capacity and Human Capital Development
- Environmental Sustainability and Green Intelligence
- Governance, Legal, and Regulatory Frameworks
- Data Ecosystem Management
- Ethics, Safety, Security, and Inclusion
- Infrastructure and Digital Readiness
- Sovereignty and Strategic Autonomy
Rationale: Why is the Policy Being Introduced?
As AI adoption accelerates globally, the Kenyan government believes a dedicated national framework is needed to maximize the technology’s benefits while managing its associated risks.
Below are some of the key rationales behind the proposed policy.
a) National Coherence
Kenya already has several instruments that have slowly shaped the nation’s approach to AI and other emerging technologies. These include the Data Protection Act (2019), the Computer Misuse and Cybercrimes Act (2018), the National ICT Policy (2019), the Digital Master Plan (2022–2032), the National AI Strategy (2025–2030), and the AI Code of Practice (DSK 3007:2024).
Governance responsibilities are distributed across multiple institutions, including the Communications Authority, the Office 18 of the Data Protection Commissioner, the Kenya Bureau of Standards (KEBS), and the ICT Authority.
While this set-up has been somewhat useful so far, there is no integrated national framework covering the full lifecycle of AI and other emerging technologies systems. This has resulted in gaps in oversight, accountability, and risk management.
The Draft Kenya AI and Emerging Technologies Policy is meant to pull them into one coherent structure.
b) Economic Opportunity
According to PwC and the McKinsey Global Institute, AI could contribute $15.7T to the global economy by 2030, while generative AI alone could generate up to $103B annually across Africa.
Kenya’s digital economy is also expanding quickly and is projected to contribute KSh 662B to the GDP by 2028. However, this comes at a time when the country is battling with a growing workforce and persistent youth unemployment.
As such, the government views AI as an opportunity to boost productivity, create new industries, and diversify the economy.
Without a coordinated national framework, Kenya risks falling behind in AI adoption, becoming increasingly dependent on foreign technologies, and missing opportunities to compete in the global digital economy.
c) Technological Sovereignty
Much of the world’s digital infrastructure remains concentrated outside Africa, with the continent accounting for less than 1% of global data centre capacity. As a result, data generated within Kenya is often stored, processed, and monetized elsewhere.
The draft policy therefore seeks to strengthen Kenya’s technological sovereignty by promoting local AI infrastructure, expanding national research capacity, and improving control over critical data and digital assets.
d) Environmental Considerations
AI and other emerging technology systems require significant computational resources. This has implications on energy consumption and environmental sustainability.
At the same time, these technologies offer opportunities to support climate resilience, with applications in agriculture, disaster response, and energy management.
The draft policy seeks to help balance AI’s environmental footprint and its potential to drive more sustainable development.
e) Constitutional Rights Delivery
As AI becomes more integrated into everyday life, concerns around bias, discrimination, and opaque decision-making continue to grow.
The draft policy proposes a governance framework that promotes transparency, accountability, and responsible AI deployment to safeguard fundamental rights.
f) State Capability
Building a competitive AI ecosystem requires far more than developing advanced AI models. It depends on the entire value chain, including digital infrastructure, energy, talent, standards, governance, and international collaboration.
The draft policy therefore proposes treating AI and other emerging technologies as strategic national capabilities rather than standalone technologies.
Achieving this will require coordinated investment and implementation across government, industry, academia, civil society, county governments, and international partners.
Scope of the AI Policy
The draft policy not only outlines how Kenya intends to govern artificial intelligence but also defines its scope.
In this analysis, we’ll focus on the technologies, actors, jurisdictions, and temporal coverage to which the policy will potentially apply. We’ll also talk about the specific scenarios where the policy would not apply.
Technology Scope
The draft Policy will apply to AI and other ‘emerging technologies’. The draft defines emerging technologies as technologies that meet two or more of the following criteria:
- They are evolving rapidly with uncertainty regarding long-term development.
- They have the potential to converge with AI or other technologies to create new capabilities or risks.
- They are not comprehensively governed by existing Kenyan legislation.
- They raise governance, ethical, safety, or rights-related issues not adequately addressed by current frameworks.
Actor and Jurisdictional Scope
The draft policy extends beyond organizations based in Kenya. It applies to a broad range of individuals and entities.
The policy will apply to:
- All public, private sector, and civil society entities operating within Kenya.
- Any person or entity physically present or operating within the territory of Kenya.
- Kenyan citizens and permanent residents, to the extent consistent with international law.
- Any entity outside Kenya that provides AI or other Emerging Technologies systems or services whose outputs are used within Kenya, or which have direct and foreseeable effects on individuals, rights, or public interests in Kenya.
- Any public-sector procurement or deployment of AI or other Emerging Technologies by the Government of Kenya or any county government, regardless of where such systems are developed, hosted, or maintained.
Important notes:
i) For entities outside Kenya, compliance may be demonstrated through adherence to a substantially equivalent legal or regulatory framework. This will be determined through an adequacy assessment by the Cabinet Secretary responsible for ICT.
ii) The policy will apply to vendors, cloud service providers, compute providers, model providers, data intermediaries, data annotation providers, AI assurance providers, public sector technology suppliers and foreign entities whose AI systems are procured, deployed, accessed or relied upon by public or private actors in Kenya.
Temporal Scope
The draft policy is intended to apply throughout the entire lifecycle of AI and other emerging technologies.
This means its provisions extend from the earliest stages of research and design through development, training, testing, procurement, deployment, use, monitoring, incident reporting, accountability, redress, standards development, infrastructure, skills development, oversight, and environmental management.
The draft policy also outlines how compliance would be phased in once it comes into effect:
- New AI systems introduced after the policy takes effect would be expected to comply once the relevant implementing regulations come into force.
- Existing (legacy) AI systems would be given a two-year transition period, during which operators must complete and submit a retrospective risk assessment together with a remediation plan.
- High-risk legacy systems would be required to achieve full compliance within three years.
Note: The Cabinet Secretary responsible for ICT would have the authority to extend the transition periods where compliance within the standard timeframe is demonstrably impractical.
Exclusion Thresholds
While the draft policy has a broad scope, it also identifies situations where its requirements would not apply. These exclusions are meant to avoid imposing unnecessary regulatory obligations on low-risk technologies and limited-use cases.
The policy will thus not apply to:
- Simple computational systems that do not employ machine learning, statistical learning, or adaptive algorithms.
- AI or emerging technologies used solely for research and development in controlled environments, provided they are not deployed for operational use or public interaction.
- Individual end-users using consumer AI or other emerging technology tools for personal, non-commercial purposes, provided such use does not adversely affect the rights of others.
Who Will Enforce Kenya’s AI Rules?

According to the draft, the Ministry of Information, Communications and the Digital Economy (MICDE) shall serve as the anchor institution for implementation of the policy.
However, enforcement will run through a four-tier structure, with a new regulator at its center.
A National AI and Other Emerging Technologies Steering Committee, chaired by the Cabinet Secretary MICDE, would set strategic direction.
Below it, a statutory National AI and Other Emerging Technologies Council would act as the central regulatory authority. The Council would be led by a Director and supported by a Governing Board, a Technical Advisory Forum, and five directorates: Policy and Standards; Compliance and Risk; Regulatory Sandbox; Advisory and Capacity Building; and Safety and Security.
The Council’s powers are significant. It will issue binding guidelines and standards, oversee testing of frontier AI models, run the national AI risk classification and regulatory sandbox, maintain a National AI Registry, conduct compliance audits, and publish national compliance reports. It will answer to the MICDE and to Parliament while keeping independent regulatory judgment.
Day-to-day coordination will sit with an MICDE Secretariat, supported by Technical Working Groups aligned to each policy pillar.
Sector regulators keep their existing roles, including the Office of the Data Protection Commissioner, the Communications Authority, the Kenya Bureau of Standards, the Central Bank of Kenya, and NEMA.
A separate Kenya AI Safety Institute would handle testing, benchmarking, red-teaming, and incident analysis. Every county would name a County AI Focal Point to coordinate local implementation.
What does the Draft AI Policy Mean for Kenya’s Stakeholders?
If implemented, the Draft AI and Emerging Technologies Policy would affect far more than government institutions. It has the potential to reshape how startups, developers, businesses, public agencies, and citizens interact with artificial intelligence.
Below are some of the most significant implications for each stakeholder group.
Startups & Developers
Funding
- The policy proposes establishing a National AI and Data Infrastructure Facility to finance compute infrastructure, AI-ready data systems, green data centres, and shared digital infrastructure. It also proposes research grants, commercialization funding, and county-level AI readiness grants to help move innovative ideas from research to market.
Commercial Gain
- One of the draft’s most notable proposals is to use government procurement to support locally developed AI solutions. Since the government is Kenya’s largest technology buyer, procurement preferences for local innovation could create significant commercial opportunities for startups and developers building AI products.
Regulatory Certainty
- The policy introduces a clearer governance structure by defining the responsibilities of a National AI Council alongside existing sector regulators. This would provide startups and developers with greater certainty about which standards apply to their AI systems and who is responsible for enforcing them.
AI Testing & Sandboxes
- The draft proposes regulatory sandboxes and controlled testing environments where developers can evaluate AI systems before large-scale deployment. It also introduces trusted research environments for working with sensitive datasets and establishes the Kenya AI Safety Institute to oversee testing, benchmarking, and independent evaluation of high-risk AI systems.
Standards & Open Data
- Developers should also expect higher standards around documentation and data governance. The policy proposes mandatory dataset provenance, national metadata standards, open government data frameworks, and a register of high-value datasets covering sectors such as agriculture, healthcare, financial inclusion, and education.
Businesses
Compliance
- Rather than introducing a blanket licence for AI, the draft adopts a risk-based approach. Higher-risk AI systems would face stricter requirements, including impact assessments, incident reporting, transparency obligations, and clearly defined liability across developers, deployers, vendors, and users.
Investment
- The policy seeks to encourage fair competition by addressing issues such as vendor lock-in, market concentration, and data portability. This could make it easier for businesses to adopt AI solutions and reduce dependence on proprietary ecosystems.
Innovation
- Businesses may also benefit from proposed financing mechanisms, including compute credits and reviews of taxes and duties affecting GPUs, AI accelerators, cloud infrastructure, and research equipment.
Government
AI Adoption for Public Service Delivery
- The draft policy encourages the government to integrate AI across key sectors, including healthcare, agriculture, education, public administration, transport, justice, and public safety. It also supports initiatives such as the National African Languages and Voice AI Programme to improve accessibility and efficiency.
National AI Governance
- Rather than regulating AI through multiple disconnected institutions, the policy proposes a coordinated governance framework. Together, the responsible institutions would help ensure AI is developed and deployed consistently across the country.
Public Procurement & Accountability
The government also intends to change how it procures and deploys AI technologies.
- The policy proposes a Government AI Digital Marketplace to support the acquisition of AI solutions. This will come with standardized procurement requirements to improve accountability when acquiring AI solutions.
- Public institutions will be expected to carry out AI impact assessments, maintain appropriate documentation, and ensure that high-risk AI systems are transparent, auditable, and subject to human supervision.
Citizens
Privacy
- The policy strengthens scrutiny of personal data used to train AI models by expanding the role of the Office of the Data Protection Commissioner. It also introduces provenance and traceability requirements designed to improve transparency around training datasets.
Consumer Protection
- Citizens would be entitled to greater transparency when interacting with AI systems. The draft proposes disclosure requirements for AI-generated content, automated decision-making, synthetic media, and deepfakes, alongside safeguards for biometric systems and autonomous AI agents.
Digital Inclusion
- The policy promotes accessible and inclusive AI by supporting local languages, participatory design, and measurable inclusion targets across counties, gender, age, and disability groups.
Rights
- Where AI systems make decisions that can significantly affect an individual’s rights or access to services, the draft requires mechanisms for human review, appeals, and redress. It also proposes stronger protections for vulnerable groups while prohibiting manipulative or deceptive AI system design.
Potential Challenges
While Kenya’s Draft AI and Emerging Technologies Policy presents an ambitious vision for the country’s digital future, translating that vision into reality won’t be easy.
Developing a national AI ecosystem requires more than policy. It demands significant investment, technical capacity, regulatory coordination, and long-term commitment from both the public and private sectors.
Below are some of the key challenges that could influence how successfully the policy is implemented.
Infrastructure Constraints
Artificial intelligence relies on high-performance computing infrastructure, reliable electricity, cloud services, and fast internet connectivity.
Although Kenya has made significant progress in expanding connectivity, limited domestic AI computing capacity remains a major challenge.
Access to high-performance GPUs and AI accelerators remains limited, and the high cost of importing AI hardware further increases the financial burden. Kenya also relies heavily on foreign cloud providers, creating challenges around data governance, pricing, and long-term digital sovereignty.
In addition, interoperability limitations, connectivity disparities, and cloud governance gaps could affect the speed at which AI systems are deployed and integrated across the country.
Funding Gap
Delivering the ambitions outlined in the draft policy will require sustained financial investment.
Expanding digital infrastructure, supporting AI research, funding innovation programmes, strengthening public institutions, and developing AI skills all require significant resources.
While the policy encourages collaboration with the private sector and development partners, securing long-term funding will likely be one of the biggest determinants of its success.
The scale of the funding gap should not be ignored. According to a UNCTAD World Investment Report, developing countries received $9B in ICT infrastructure investment in 2024 against an estimated need of $62B.
Skill and Workforce Gaps
Kenya cannot regulate or build AI without people who understand it.
The skills gap runs through the whole system. There is no unified competency framework yet. AI is not systematically integrated into school curricula. Teacher capacity is limited.
This is, however, consistent with global trends since only a few countries have developed structured AI education.
Nonetheless, Kenya’s public-sector technical capacity to procure, deploy, and oversee AI systems is thin. This is especially so in critical sectors where the government wants to leverage AI, including agriculture, health, finance, and education itself.
There’s also a retention problem. Many skilled professionals opt to leave the country for more competitive international opportunities.
Environment and Sustainability
Artificial intelligence relies on data centres to store data, run AI models, and provide the computing power needed for AI applications.
Kenya has the second largest number of data centres in Africa (19), which is a plus. However, the projected AI growth will most likely require more data centers. This will in turn increase demand for energy, water, land, and hardware lifecycle management.
While Kenya has a strong renewable energy base, the extra energy requirements might be a problem considering the country has been grappling with uneven connectivity and power outages.
Additionally, large data centres can use up to 5 million gallons of water per day for cooling. This is a significant amount considering that about 80% of Kenya’s land is arid or semi-arid.
Regulatory Coordination and Enforcement
Introducing policies is often easier than implementing them.
Kenya has made some progress in strengthening its regulatory institutions. Nevertheless, challenges such as bureaucratic inefficiencies, uneven enforcement, and corruption continue to affect the implementation of policies across sectors.
Sure, the draft AI policy proposes governance structures and oversight mechanisms. But even well-designed frameworks can struggle to achieve their intended outcomes when oversight is inconsistent or institutional coordination is weak.
Effective enforcement will require strong coordination across government agencies, regulators, educational institutions, and industry stakeholders.
Keeping Pace with AI
The draft policy endorses a risk-based and lifecycle approach to AI governance. This means the regulatory measures are intended to remain proportionate, adaptive, and responsive as the technology evolves.
However, AI is advancing far more quickly than most regulatory frameworks. By the time policies are implemented, new technologies, business models, and risks may already have emerged.
For this reason, policymakers will need to remain vigilant and regularly review the framework to ensure Kenya’s AI policy remains relevant.
Conclusion: A Serious Framework That’s Still To Come
The most important part of this draft policy is not the clause about foreign companies. It is the architecture underneath and what it represents.
Kenya is proposing to move from voluntary codes and scattered guidance to a statutory regulator, a dedicated Act, mandatory impact assessments, a public register, and enforceable duties toward AI systems.
That is the same direction the European Union and other major economies have taken, adapted to Kenya’s own constraints.
However, the gap between a draft policy and a working regulator is where most of the risk sits.
The next few months and years will determine whether this becomes just another policy document or the foundation of Kenya’s AI ecosystem.