Contextualising the AI Bill 2026 within Kenya’s Evolving AI Governance Ecosystem

The Artificial Intelligence(AI) Governance landscape in Kenya has been evolving toward a more deliberate, strategic approach to building responsible, ethical AI Governance structures. This trajectory has been characterised by key initiatives, including the development of the Kenya National AI Strategy 2025-20301 and the ongoing development of the National AI & Emerging Tech Policy, which began in November 2025.2 Kenya’s approach to AI governance has so far favoured a soft-law approach, arguably appropriate given the evolving AI landscape and the need to balance innovation and regulation.

Notably, there is an increasingly evident shift from soft-law to hard-law frameworks, with early attempts to legislate AI, such as the proposed Robotics and AI Society Bill, ultimately not progressing. More recently, i.e., in 2025, Member of Parliament Hon. Marianne Kitany introduced a motion to develop a comprehensive regulatory AI framework.3 At the time, the motion was grounded in the Country’s growing AI adoption and noted risks associated with unregulated AI, including disinformation, privacy violations, algorithmic bias, job displacement, and broader forms of social manipulation.4 The motion proposed not only the establishment of a regulatory framework but also the development of ethical guidelines and public awareness initiatives to promote the responsible use of AI.5

The momentum on AI regulation has continued to grow, characterised by the recent tabling of the AI Bill 2026, signalling a move toward formalised, binding AI Regulation.6 However, the bill has sparked critical debate and discourse with key questions emerging as to whether Kenya’s AI ecosystem has reached sufficient maturity to justify the shift to hard law, whether the bill clearly articulates regulatory parameters grounded in the Country’s specific AI use cases, observable risks and harms, whether it adequately addresses areas of innovation, infrastructure and data as well as issues on compliance and institutional oversight. Additionally, the tabling of the bill raises questions about the procedural context in which it was introduced, noting the absence of a finalised National AI Policy, with the process still ongoing, that would ideally have provided the necessary normative and strategic foundation for the legislation.

It is against this evolving landscape that this commentary seeks to situate the AI bill. The commentary will critically examine the extent to which the Bill addresses Kenya’s AI governance needs, highlighting areas that align with existing frameworks, notable gaps, and identifiable limitations.

Overview of the AI Bill

The bill outlines key objectives, providing a framework for AI governance, ensuring ethical, accountable, and transparent use of AI, fostering innovation in AI, safeguarding human rights, data protection, and public welfare; promoting AI literacy, establishing the office of the AI commissioner and aligning with international standards on AI.7

Distinctly, the bill proposes the development of institutional functions through the establishment of the Office of the Artificial Intelligence Commissioner(OAIC), with an AI Commissioner, an independent corporate body with enforcement power, including the risk assessments of AI systems.8 The mandate of the office being, to carry out audits and post market surveillance of AI systems, risk assessment of AI systems, the deveolopment of policies guidelines and standards on AI governance, promoting responsible development, deployment and use of AI, establishing and managing regulatory sandboxes, advising national and county governments on matters relating to policy intergation of AI and promoting pubic awareness and education on AI.9

Of note, the office is also given the mandate to require production of records and issue enforcement notices or administrative fines for non-compliance.10 An Advisory Committee on AI, comprising experts, is also established under the bill to advise the commissioner on emerging trends, workforce transition strategies, and the development of ethical guidelines.11

Further, the bill proposes a risk-based regulatory classification that categorises AI technologies on the basis of the severity of threat posed to health, safety, fundamental rights, the environment and societal welfare.12 The bill suggests rigorous compliance obligations for high-risk systems and a prohibition on unacceptable risk systems. 13Additionally, deployers must conduct risk and human rights impact assessments prior to deployment and ensure systems are transparent, traceable and explainable.14

Provisions for establishing regulatory sandboxes are prescribed to provide controlled environments for testing new AI innovations under regulatory supervision. Provisions addressing the impact of AI on the workforce are also noted, with a requirement that mitigation measures, such as reskilling, be implemented to address job displacement. The bill also proposes an enforcement mechanism through the provision on offences and penalties. The offences include,15

  • Deploying unacceptable risk systems

  • Failure to conduct requisite assessments for high-risk AI

  • Failure to comply with disclosure requirements

  • Workforce impact violations

  • Non-compliance with regulatory sandbox requirements and safeguards

  • Misuse of AI in the public sector

  • Unauthorised generation and distribution of synthetic media

  • Violation of ethical guidelines, obstruction of the duties of the OAIC

The penalties are divided into two tiers, i.e., serious offences and other offences. Serious offences carry penalties of up to 5 million shillings, imprisonment for up to two years, or both.16 Serious offences include violations related to unacceptable risk, high-risk assessments, sandboxes, workforce impact, public-sector misuse, and synthetic media.17 On the other hand, other offences attract a penalty of up to one million shillings, imprisonment of up to six months, or both. The violations here relate to transparency, ethical guidelines, or obstruction.

What Does the Bill Get Right and What Are the Gaps?

Discourse around the bill has raised various criticisms regarding the key issues it addresses. AI governance is layered; therefore, any attempt at regulation must be structured first to consider the local context of the AI ecosystem, as well as both technical and legal parameters, and further adopt a foresight approach for longevity and sustainability.

Given the current discourse on the bill, there are notable areas the bill attempts to address. The bill acknowledges the need for insituionalisation of AI governance through the establishment of outlines key areas with respect to institutionalisation of AI governance through the establishment of the OAIC,18 in as much as the establishment of this office raises contention with respect to its purpose raising the questions as to whether the office can be established under already existing existing compliance and oversight bodies such as the office of the data protection commissioner as established under the Data Protection Act 2019.

The Bill recognises key ethical and human rights considerations which are central to AI governance. Kenya’s AI Readiness Assessment report, in its evaluation of Kenya’s ethical AI landscape, noted gaps in Kenya’s governance frameworks for AI, particularly regarding the protection and promotion of human rights within the AI ecosystem.19 Additionally, borrowing from the Global Index on Responsible AI (June 2024), Kenya scored low (8.79 out of 100), especially poorly in the Human Rights and AI dimension, with a score of 6.03 out of 100.20 The dimension covers include thematic areas such as bias and unfair discrimination, children’s rights, cultural and linguistic diversity, data protection and privacy, gender equality, labour protection, and public participation and awareness.21 The bill has addressed some of the identified thematic areas, while others have not been adequately addressed.

Areas of innovation are captured only lightly through the provisions on regulatory sandboxes, which in turn necessitate closer scrutiny of the bill’s definition of regulatory sandboxes and of whether the provisions provide sufficient detail to describe the core purpose for which such sandboxes would be established. The Act defines a regulatory sandbox in its simplest definition as a controlled environment for testing artificial intelligence under regulatory oversight. Data Sphere Initiative, offers a comprehensive definition of a regulatory sandbox to be ‘a framework to pilot innovative solutions under regulatory guidance where the collaboration helps identify potential risks and develop appropriate regulations before broader deployment, enabling a more responsive regulatory environment.’ the approach in definition offers a more wholistic component within which regualroty sandox in the context of the Bill can be considered covering the wider scope of of its purpose being both regulatory and operational.

The bill in addressing offences and penalties addresses harms of AI channelled through synthetic media; however, this offers a narrow scope to the extent of harms that can be addressed by the hard law, further limiting the same to generative AI, noting that generative AI is but one component of AI, and it will continue to evolve beyond having impacts on effect through synthetic media. There is therefore a need to clearly consider, in its totality, not only immediate harms but also to make intentional provisions that apply foresight and account for the evolving nature of AI. One would argue that the risk classification model introduced in the bill would help mitigate and/or address future harms; however, no clear or set criteria have been established in the act, in consideration of already existing AI use cases in the County, to ensure effective implementation of the classification model.

Alignment with the Kenya AI Strategy 2026

The Kenya AI Strategy, developed in 2025, marked a key introduction into developing concrete and actionable parameters with respect to building AI governance structures in Kenya.22 Seemingly, the bill as presented preempts key parameters that must be in place before binding laws can be enacted. The bill aligns with the strategy to the extent that it calls for agile governance frameworks, as reflected in the oversight mechanisms presented therein. Additionally, it reflects social alignment by providing for workforce protection, with the strategy identifying workforce displacement as a key concern. Literacy and inclusion are also captured within the strategy as cross-cutting enablers essential for ensuring the equitable sharing of AI benefits. The bill seemingly operationalises this under the mandate of the commissioner, implementing AI literacy programs at both national and county levels.23However, the strategy’s literacy component goes beyond public awareness to encompass technical skills and curriculum changes.

Conclusion

While the bill provides for notable areas necessary for AI regulation, it remains underdeveloped in critical areas, including contextual grounding in Kenya’s existing AI use cases, limited foresight in addressing evolving AI harms not linked to generative AI, and a lack of clarity on operational mechanisms such as regulatory sandboxes and risk classification criteria. As a result, there is a risk that the law, in its current form, may struggle to be implemented effectively. Consequently, the bill should not be viewed as a final regulatory solution but as part of an iterative governance process, requiring alignment with ongoing policy developments and the refinement of its scope to better reflect local realities, ensuring that Kenya’s regulatory approach is not only robust but also effective and sustainable.

2 David Indeje, Kenya’s AI & Emerging Technologies Policy: Government Perspectives (KICTANET , 2026)<https://www.kictanet.or.ke/kenyas-ai-emerging-technologies-policy-government-perspectives/>

3 ‘House Resumes with Key Bills on the Docket.’ https://parliament.go.ke/node/22818

5 ibid

7 Part II

8 Section 4-,5

9 Section 6

10 Section 10

11 Section 11

12 Section 25(1)

13 Section 25(2)

14 Section 26(1a-b)

15 Section 35

16 Section 35 (2a-b)

17Section 34a

18 n8

19 UNESCO, ‘Kenya :Artificial Intelligence Readiness Assessment Report.’ <https://unesdoc.unesco.org/ark:/48223/pf0000392693>

20 ibid

21 ibid

22 n1

23 Section 10(1)f

Stay Updated

Subscribe to our newsletter to receive the latest research, publications, and blog posts directly in your inbox.