Africa’s tech hub is writing its first rules for artificial intelligence — but critics warn the draft law could chill the very innovation it aims to protect.
By Grace Wanja
Kenya’s Senate has begun deliberations on the Artificial Intelligence Bill, 2026, the country’s first comprehensive attempt to regulate how AI systems are developed, deployed and used — a legislative landmark that places Kenya alongside the European Union and a handful of nations bold enough to write the rules before the technology writes them.
The Bill, sponsored by nominated Senator Karen Nyamu, sets out a framework to govern AI technologies with the stated aim of ensuring that artificial intelligence is developed in a manner that is ethical, transparent and accountable, while safeguarding human rights, data protection and public welfare. Nyamu introduced the legislation after manipulated AI-generated images of her circulated online — a personal experience that appears to have helped shape the bill’s sharp focus on synthetic media and digital impersonation.
At the heart of the proposed law is a new institutional architecture. The bill establishes three oversight bodies: the Office of the Artificial Intelligence Commissioner as the primary enforcement body responsible for registering AI systems, conducting audits and investigating compliance breaches; the Artificial Intelligence Authority, tasked with creating national AI strategies and setting technical and ethical standards; and the Artificial Intelligence Advisory Council, a consultative group of experts that advises the government on global AI trends and emerging risks.
The regulatory model is risk-based. High-risk AI systems would face stringent governance, transparency, data protection and record-keeping requirements, with broader disclosure duties applying across all risk categories. The Bill is modelled in part on the EU AI Act, reflecting international norms while raising concerns around regulatory scope, certainty and proportionality. Crucially, the legislation grants Kenyan citizens new digital rights, including the right to know how an AI system reached a decision that significantly affects them — such as a loan rejection — and the right to request that a qualified human representative review an automated decision.
The Bill’s teeth are sharp. It proposes criminal penalties of up to KSh5 million and imprisonment of up to two years, depending on the nature of the offence. Individuals or entities that misuse AI — particularly to create false, harmful or deceptive content such as deepfakes — may be subject to more severe sanctions. For a country where AI-generated disinformation has already reached political rallies and social media feeds, the criminalisation of harmful deepfakes represents a legitimate policy response. The question is whether the law can draw the line cleanly enough.
Free speech advocates worry that broad enforcement provisions could be weaponised to silence political satire, parody or legitimate dissent. Without a clear distinction between a malicious deepfake and a comedic or educational use of AI, critics argue the law risks becoming a tool for digital censorship. Industry voices have raised a parallel concern: an MSME that relies on an AI image-generation tool developed by a third-party provider could potentially face liability if the resulting content is later found to be misleading — an outcome that could freeze innovation before it starts.
The Bill has been published as a Senate Bill but has not yet been tabled before the Senate in full, and because it concerns county governments, it must also be considered by the National Assembly before it can be presented for presidential assent. That road is long. But the direction of travel is clear. As artificial intelligence rapidly infiltrates critical sectors — from automated credit scoring and medical diagnostics to predictive policing and human resources — the potential for unchecked algorithmic bias and massive privacy violations has reached critical mass.
Kenya built its reputation as Africa’s Silicon Savannah by moving fast. Regulating the technology that now powers that economy will require the legislature to move carefully — and to remember that a law that protects citizens from AI is only as good as its ability to tell the difference between a threat and an innovation.