Kenya's Ministry of ICT and Digital Economy opened public participation on the draft National AI and Other Emerging Technologies Policy on July 27, 2026, with submissions due August 4 to a dedicated Committee on AI and Other Emerging Technologies (AllAfrica). The draft, built by a multi-stakeholder Technical Working Group since November 2025 with KICTANet, the British High Commission, the EU, Germany and Canada, proposes four governance tiers topped by a National AI Steering Committee, a new central regulatory council, a Kenya AI Safety Institute, and a public AI registry.
That would be unremarkable policy housekeeping, except Kenya already has a bill doing much of the same work through a different door. The Artificial Intelligence Bill, 2026, sponsored by nominated Senator Karen Nyamu, was published in the Senate on February 19, 2026 (Kenya Law) and proposes its own institutional stack: an Office of the AI Commissioner, an AI Authority, and an AI Advisory Council, layered on top of a risk-tiered compliance regime borrowed from the EU AI Act. As Tech Policy Press has reported, the bill "is not informed by that process nor by the AI strategy launched last year, and risks getting ahead of the policy it should be grounded in" — a direct, on-record acknowledgment that the two efforts are not talking to each other (Tech Policy Press).
The steelman for moving fast
There is a real case for urgency. AI-enabled harms are already landing in Kenyan courts and newsrooms: deepfakes used to defame politicians, and credit-scoring algorithms that a 2025 cross-country study found were consistently biased against women-led businesses in Kenya, Nigeria and South Africa (TechCabal). A legislature that waits for a perfectly sequenced, multi-year policy-then-law process risks leaving those harms unaddressed for years. Senator Nyamu's bill is a legitimate attempt to close that gap, and its core instinct — that AI-generated content impersonating real people needs disclosure rules — is sound and consistent with global practice.
Where it goes wrong
The execution undercuts the instinct. The bill sets a flat penalty ceiling of KES 5 million and up to two years' imprisonment for deepfake and deceptive-AI-content violations, applying the same ceiling to "mass surveillance systems" and to satirical AI images, with no carve-out for "evidently artistic, satirical or fictional" content of the kind the EU AI Act it otherwise imitates provides (Tech Policy Press). That ambiguity has teeth: Kenya has already seen arrests over AI-generated political content, and a bill that cannot distinguish a meme from a disinformation campaign will chill the former to catch the latter.
ODPC already does most of this job
The deeper problem is institutional stacking. Kenya's Office of the Data Protection Commissioner already functions as the country's de facto AI regulator, enforcing the Data Protection Act, 2019 against algorithmic harms without needing AI-specific statute. ODPC's own guidance frames this explicitly: organisations deploying AI must run Data Protection Impact Assessments and respect data-subject rights under existing law, full stop — it does not carve out a separate AI compliance track (ODPC). ODPC has also already shown it can act: its KSh 4.55 million (~$35,000) fine against Roma School in 2023 for publishing children's images without consent remains the country's reference enforcement case for automated data harms (TechCabal).
Legal analysis of the Senate bill has flagged exactly this collision: the bill ties high-risk AI compliance to the Data Protection Act while creating a new Commissioner, Authority and Advisory Council that sit alongside ODPC and the Communications Authority, and warns MSMEs would face "conflicting or duplicative requirements" from multiple regulators policing the same AI system (Oraro & Company). A four-tier policy council and a statutory AI Commissioner both claiming jurisdiction over the same chatbot or credit-scoring model is not defence-in-depth; it is two agencies a founder must satisfy to ship one product.
The proportionate path
Kenya does not need to choose between speed and coherence — it needs to sequence them. The honest reading of both processes is that the ministry's policy consultation, running through August 4, is the right forum to decide whether Kenya needs a standalone AI Commissioner at all, before the Senate locks one into statute. Where AI harms are data harms — biased scoring, non-consensual imagery, unlawful profiling — ODPC already has the mandate and, per its Roma School enforcement, the willingness to act. Where they are not — safety-critical systems, mass surveillance infrastructure — a narrower, risk-tiered statute with clear satire and speech carve-outs would do more for Kenyan innovators and Kenyan speech than a second regulator duplicating ODPC's job. The Senate should pause Nyamu's bill until the ministry's policy — and Cabinet's read on institutional design — is settled, not the other way around.