The regulatory landscape
Kenya has no single AI statute yet, but a real regulatory perimeter is already forming around AI through data protection law, consumer protection, sectoral regulation (financial services, health, telecommunications) and emerging policy guidance from the Office of the Data Protection Commissioner.
Founders should treat AI compliance as a moving target shaped by these adjacent frameworks rather than waiting for a dedicated AI act.
Data protection first
Every AI product that processes personal data falls within the Data Protection Act, 2019. That includes training data, inference inputs, model outputs that can identify a person, and any human-in-the-loop pipeline.
- Establish a lawful basis for processing — consent, contract or legitimate interest.
- Map all data flows including third-party model providers and processors.
- Document data minimisation, retention and deletion practices.
- Run a Data Protection Impact Assessment for higher-risk use cases.
Building an AI governance posture
A defensible AI governance posture is documented, repeatable and proportionate to risk. The objective is not paperwork — it is to give founders, investors and regulators confidence that decisions are auditable and that risk is actively managed.
- A short internal AI policy.
- Model and dataset inventory.
- Vendor and processor due diligence.
- Human oversight and escalation paths.
Practical steps for founders
Most early-stage founders do not need a full compliance program on day one. They need clear documentation of data sources, a defensible privacy notice, contracts with model providers that allocate risk sensibly, and a basic governance framework that can grow with the company.
