Logo
FrontierNews.ai

Kenya's AI Governance Gap: Why Regulators Are Scrambling to Protect Workers and Voters

Kenya's Office of the Data Protection Commissioner released draft guidance notes on artificial intelligence, but civil society organizations are flagging significant gaps that could leave vulnerable workers and electoral systems unprotected. The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) submitted detailed comments highlighting how the current framework focuses on end-user rights while overlooking the people who actually train AI systems and the political contexts where these tools pose the greatest risks.

Who Is Being Left Out of Kenya's AI Rules?

One of the most striking oversights in Kenya's draft guidance concerns the invisible workforce behind AI development. Data annotators, content moderators, and workers involved in reinforcement learning from human feedback (RLHF), which is a technique where human reviewers rate AI outputs to improve system behavior, help train both local and foreign AI models deployed across Kenya. Yet the proposed rules focus entirely on protecting end-users, not the people doing the labeling work.

CIPESA argues that these workers deserve explicit data protection rights, including safeguards over performance and monitoring data collected about them. This represents a fundamental gap in how AI governance is typically framed, which usually centers on consumer privacy rather than worker protections in the AI supply chain.

The guidance also omits protections for persons with disabilities, despite Kenya's Constitution explicitly protecting this group. The draft notes fail to reference Article 54 of Kenya's Constitution and do not require that training data and biometric information be developed with input from disabled communities, risking AI systems that exclude or harm these populations.

Why Are Electoral Systems and Political AI a Blind Spot?

Kenya faces a 2027 general election, yet the draft AI guidance contains a notable absence: it does not classify AI systems deployed in political and electoral environments as high-risk. This is particularly concerning given that political opinion is classified as sensitive personal data under major data protection laws, and Kenya's AI Bill, 2026 specifically addresses synthetic political content.

CIPESA recommends adding explicit categories for AI used in political communication, voter micro-targeting, and synthetic political media before the election cycle intensifies. The organization also notes that algorithmic feeds on social media platforms, which shape public discourse far more than enterprise chatbots, remain largely unregulated. If AI laws regulate only technical tools while ignoring the algorithms that determine what Kenyans see online, they miss the AI systems with the greatest influence on daily life.

How Can Kenya Strengthen Its AI Governance Framework?

CIPESA has outlined several concrete steps that Kenya's regulators should take to address these gaps:

  • Biometric Data Safeguards: Mandate pre-deployment registration with the Office of the Data Protection Commissioner and require Data Protection Impact Assessments before any biometric data processing begins, not just for real-time surveillance but also for retrospective analysis of stored facial or iris images.
  • Synthetic Media Transparency: Implement verifiable content records and labeling requirements, such as watermarking or equivalent disclosure, for synthetic media used in decisions affecting individuals, aligning with constitutional consumer rights.
  • Algorithmic Audits: Require global and local platforms processing Kenyan users' data to undergo regular algorithmic governance audits, ensuring that content curation systems are subject to meaningful oversight.
  • Digital Public Infrastructure Accountability: Mandate pre-deployment Data Protection Impact Assessments, equity assessments, publicly disclosed methodologies, and human review guarantees for government AI systems like digital identity platforms and automated tax processes.
  • Government and Security Oversight: Extend accountability mechanisms to state use of AI in public services and surveillance, ensuring citizens can challenge public sector AI decisions just as they can challenge private entity decisions.

CIPESA also flagged concerns about how Kenya's guidance fits within regional and international frameworks. The draft notes cite only national laws, yet AI in Kenya operates within a wider continental context, including the African Union Continental AI strategy, the Malabo Convention on Cyber Security and Personal Data Protection, and the African Union Data Policy Framework.

The organization warned that overly restrictive data localization requirements, while intended to protect privacy, could impede cross-border AI inference and cloud computing capabilities that are essential for Africa's digital trade ambitions under the African Continental Free Trade Area (AfCFTA) Digital Trade Protocol.

What Happens When AI Governance Fails?

Kenya has already seen the consequences of inadequate AI oversight. In 2025, a High Court judgment against Worldcoin found that iris data from hundreds of thousands of Kenyans was processed without a required Data Protection Impact Assessment. This case underscores why CIPESA's recommendations for mandatory pre-deployment registration and impact assessments are not theoretical concerns but practical necessities.

The broader challenge facing Kenya reflects a global tension in AI governance: regulators must balance innovation with protection, cross-border data flows with privacy safeguards, and enterprise tools with the algorithmic systems that shape public discourse. Kenya's draft guidance notes represent progress, but without addressing the gaps CIPESA has identified, the framework risks protecting some stakeholders while leaving others vulnerable to AI systems they cannot see or challenge.

CIPESA's submission follows an earlier August 2026 submission on Kenya's Draft AI and Other Emerging Technologies Policy, which raised similar concerns about institutional independence and biometric safeguards, suggesting that these governance gaps have persisted across multiple policy documents.