Africa and Europe Are Building Rival AI Governance Models. Here's Why It Matters.
Two major regions are moving forward with AI governance frameworks that reflect fundamentally different philosophies about who should control artificial intelligence systems and how. Europe is emphasizing pragmatic, risk-based rules that allow innovation to flourish, while Kenya is taking a more assertive approach centered on digital sovereignty and shared accountability across the entire AI ecosystem.
What's Driving These Different Regulatory Approaches?
Europe's approach, crystallized in the EU AI Act, focuses on creating workable rules that balance innovation with safety. OpenAI, one of the world's largest AI companies, has endorsed two Codes of Practice developed through multi-stakeholder processes: the General-Purpose AI Code of Practice and the Code of Practice on Transparency of AI-Generated Content. These frameworks emphasize that rules must be "pragmatic, proportionate and risk-based in order to advance governance while supporting innovation".
Kenya, by contrast, is taking a broader approach with its Draft Artificial Intelligence and Emerging Technologies Policy, 2026. Rather than focusing narrowly on high-risk systems, Kenya's framework addresses how AI systems are designed, deployed, monitored, and governed throughout their entire lifecycle. The policy was published for public comment with a deadline of August 4, 2026.
How Do These Frameworks Differ in Scope and Reach?
One of the most striking differences is how far each framework extends beyond national borders. Kenya's Draft AI Policy applies not only to local organizations but also to foreign AI providers whose systems, services, or outputs are used in Kenya or have "direct and foreseeable effects" within the country. This extraterritorial reach is significantly broader than Europe's approach, which focuses on systems offered or directed to the EU market.
Kenya's framework also elevates data and model sovereignty to a standalone pillar, reflecting concern that Kenya's AI ecosystem remains heavily dependent on foreign platforms, cloud infrastructure, and proprietary models with limited domestic control. The policy contemplates three linked approaches:
- Data Localization: Requiring sensitive or strategic datasets to remain within Kenya or be subject to controlled cross-border data flows.
- Sovereign Cloud Strategy: Mandating domestic hosting for critical systems while permitting hybrid or commercial cloud arrangements for lower-risk workloads.
- Strategic Autonomy: Building domestic compute capability, talent, and regional infrastructure leadership to reduce dependence on foreign AI providers.
Europe's approach, by contrast, emphasizes transparency and provenance without explicitly mandating data localization. OpenAI's commitment to the Code of Practice on Transparency of AI-Generated Content relies on two complementary systems: Content Credentials, which help content carry detailed context about its origins, and SynthID watermarks, which preserve identification signals when metadata is lost during sharing across platforms.
Who Bears Responsibility Under Each Framework?
Kenya's Draft AI Policy represents a significant shift toward shared accountability. Rather than placing responsibility on a single organization, the framework allocates liability, accountability, insurance, and redress across developers, deployers, operators, vendors, and users. Organizations will be expected to understand and manage their role in the AI lifecycle while supporting regulatory oversight and enforcement.
Europe's approach, while also emphasizing shared responsibility, focuses more on transparency and external expert input. OpenAI has committed to extensive model testing prior to release, publishing system cards with major releases, bringing outside experts into model testing through its Red Teaming Network, and maintaining a public Model Spec that explains how the company shapes model behavior.
How to Prepare for Divergent AI Governance Frameworks
Organizations developing, deploying, or procuring AI systems should begin preparing for a world where different regions impose different requirements. Here are the key steps:
- Assess Your Geographic Footprint: Determine which regions your AI systems operate in or affect, and understand that Kenya's extraterritorial reach means even foreign companies may need to comply if their systems are used there.
- Document Your AI Lifecycle: Kenya's framework requires organizations to govern AI across design, deployment, monitoring, and accountability phases. Create documentation showing how your organization manages each stage.
- Implement Transparency Measures: Both frameworks emphasize transparency, so invest in provenance systems, watermarking, and clear documentation of AI-generated content and model behavior.
- Establish Incident Reporting Processes: Kenya's policy requires investigation and response mechanisms for AI-related failures, misuse, cybersecurity incidents, and safety events. Develop clear protocols now.
- Plan for Data Governance: If you operate in Kenya, understand that the country is moving toward data localization requirements for sensitive datasets and may require domestic hosting for critical systems.
OpenAI has already begun adapting its governance in practice. The company launched an EU Cyber Action Plan in May 2026, working with EU and national cyber agencies, private sector partners, and critical infrastructure operators to equip them with advanced cyber models while managing misuse risks through its Trusted Access for Cyber program.
Kenya's approach signals that developing nations are not simply adopting European or American regulatory models wholesale. Instead, they are building frameworks that reflect their own strategic priorities, including digital sovereignty and the need to build domestic AI capabilities. As more countries develop their own AI governance frameworks, companies will need to navigate an increasingly complex patchwork of requirements.
The divergence between Europe's pragmatic, risk-based approach and Kenya's lifecycle-focused, sovereignty-centered framework suggests that the global AI governance landscape will remain fragmented for the foreseeable future. Organizations that invest in understanding these differences now will be better positioned to operate effectively across multiple regulatory regimes as implementation continues.