CIPESA Weighs in on Kenya’s Draft Guidance Notes on AI and Emerging Technologies

By Raylenne Kambua |

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) submitted comments on two draft Guidance Notes that Kenya’s Office of the Data Protection Commissioner (ODPC) opened for public participation: one on Artificial Intelligence (AI), and another on Emerging Technologies.

The draft Notes provide guidance to entities on how to make sure their AI systems and emerging technologies comply with the Data Protection Act, 2019. While this is a positive step toward the responsible adoption and deployment of AI and emerging technologies, CIPESA highlights gaps the ODPC should address to ensure these technologies are governed in a rights-respecting, transparent, and accountable manner.

CIPESA’s Comments on the Draft Guidance Note on AI

A first set of concerns relates to how the AI Note fits with other legal frameworks. The Note cites only national laws, yet AI in Kenya operates within a wider regional and international framework, which risks regulatory inconsistency. Continental frameworks such as the AU Continental AI strategy, the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) and the AU Data Policy Framework offer guidance on AI development and harmonised data governance.

The Note requires entities to conduct adequacy assessments before transferring AI-processed personal data across borders. Although intended to protect privacy, this requirement could trigger blanket data localisation and impede cross-border AI inference and cloud computing capabilities. CIPESA recommends aligning these assessments with the AU Data Policy Framework and the African Continental Free Trade Area (AfCFTA) Protocol on Digital Trade to balance privacy safeguards with Africa’s digital trade ambitions.

As AI is increasingly deployed as an assistive technology, it risks excluding persons with disabilities when training data and biometric information are developed without their input. CIPESA observes that the Note omits Article 54 of the Constitution of Kenya, which protects persons with disabilities. Incorporating this provision would align the guidance with other standards, which set a benchmark for how regulation can protect groups that AI systems often overlook.

Furthermore, the draft Note lacks cross-references to the ODPC’s 2025 Guidance Note for Processing Children’s Data, and the Children Act, 2022, which enforces online protection and the best-interest principle for minors. This shortcoming creates disharmony among related efforts on children’s protection.

The submission points to the 2025 High Court judgment against Worldcoin, which found that iris data from hundreds of thousands of Kenyans was processed without a Data Protection Impact Assessment (DPIA). The Note’s biometric provisions prohibit only real-time surveillance without legal authority. This leaves retrospective analysis of stored facial or iris images unregulated, even though it carries equivalent privacy risks. CIPESA advocates mandatory pre-deployment registration with the ODPC and submission of DPIAs before any biometric data processing begins.

As generative AI spreads, so do its risks, such as hallucination. CIPESA recommends implementing verifiable content records and labelling requirements, such as watermarking or equivalent disclosure, for synthetic media used in decisions affecting individuals. This aligns with constitutional consumer rights under Article 46 and supports digital trust in continental trade involving automated electronic services covered by the AfCFTA Digital Trade Protocol.

The AI shaping Kenyans’ daily consumption centres around algorithmic feeds rather than enterprise chatbots. CIPESA argues that if AI laws regulate only technical enterprise tools while ignoring social media algorithms and content curation systems, they risk missing the AI that mostly shapes consumers’ public discourse. Global and local platforms that process Kenyan users’ data must also be subject to algorithmic governance and regular audits.

CIPESA also notes that the Note’s high-risk AI table omits information systems deployed in political and electoral environments. This is despite political opinion being classified as sensitive personal data under major data protection laws, and the AI Bill, 2026 addressing synthetic political content. CIPESA recommends adding categories for AI in political communication, voter micro-targeting, and synthetic political media ahead of the 2027 general election.

Other recommendations concern who the rules protect and who they hold to account. Kenya’s data annotators, content moderators, and reinforcement learning from human feedback (RLHF) workers help train both local and foreign AI models. However, the Note’s obligations focus entirely on end-user rights. CIPESA calls for extending data protection rights to this workforce, including protections over performance and monitoring data collected about them.

The Note requires entities to register with the ODPC as data controllers or processors before deploying any AI system that processes personal data. However, it does not address the separate Commissioner-maintained public register of high-risk AI models that is proposed under the AI Bill, 2026. CIPESA recommends clarifying how registration functions will be divided between the ODPC and the prospective AI Commissioner.

Regarding Digital Public Infrastructure such as interoperable digital identity systems, the Social Health Authority’s premium assessments, and the Kenya Revenue Authority’s automated eTIMS processes, CIPESA advises mandatory pre-deployment DPIAs, equity assessments before deployment, publicly disclosed methodologies, and human review guarantees.

Finally, AI governance is incomplete if it regulates companies but leaves government and security agencies outside meaningful oversight and accountability. CIPESA warns that without accountability for state use of AI in public services and surveillance, critical systems remain unmonitored. Citizens should be able to challenge public sector AI decisions just as they can challenge those of private entities.

CIPESA’s Comments on the Draft Guidance Note on Emerging Technologies

CIPESA also submitted comments on the Draft Guidance Note on Emerging Technologies. On cloud computing, it cautions that restricting systems tied to “the strategic interests of the state” risks becoming a de facto data localisation rule. CIPESA recommends confining data localisation to cases where a specific statutory requirement applies, in line with the AfCFTA Digital Trade Protocol and the AU Data Policy Framework’s emphasis on responsible intra-African data flows.

The submission advocates a complete prohibition on real-time remote biometric identification and indiscriminate mass surveillance in public spaces. It warns against using biometric categorisation to infer sensitive traits, alongside AI-based emotion recognition in schools and workplaces. Law enforcement remote biometric identification must require legal authorisation, judicial warrant, and independent oversight.

To strengthen impact assessments, CIPESA suggests publishing executive summaries of all DPIAs, excluding trade secrets, on a public High-Risk Technology Register before deployment. This would improve transparency and accountability and build public trust in high-risk emerging technology deployments.

Concerning automated decisions, CIPESA recommends meaningful human review by a reviewer with real authority to overturn or modify the outcome, not a rubber stamp. This should apply specifically to decisions on employment, credit, insurance, healthcare, social protection, immigration, and policing. To reduce the compliance burden, CIPESA recommends simplified registration and DPIA templates.

Building on CIPESA’s Wider Work on Kenya’s AI Governance

The two submissions follow CIPESA’s August 2026 submission on the Draft Kenya AI and Other Emerging Technologies Policy, which raised similar concerns about institutional independence and biometric safeguards at the policy level. They also draw on the Navigating the Implications of AI on Digital Democracy in Kenya report and its regional companion. The AI Guidance Note’s argument on algorithmic feeds echoes Kenya Doesn’t Have an AI Regulation Gap, It Has an Accountability Gap and Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa.

Read CIPESA’s full comments on the Draft Guidance Notes on AI here and on Emerging Technologies here.

It’s Almost Time For FIFAfrica26! Discover the Agenda. Meet the Speakers

By FIFAfrica |

This time next week, FIFAfrica26 will be underway in Mauritius!

The conversations we have been planning, the ideas we have been shaping, and the connections we have been looking forward to will finally shift into actions, debates, and new learning!

Across four days, FIFAfrica26 will bring together conversations on digital democracy and civic participation, AI and emerging technologies, data governance and sovereignty, platform accountability, digital inclusion, digital economy and trade, movement building, and digital security and safety.

Here is what you can look forward to:

  • Two days of engaging pre-event sessions (Be sure to sign up, as spaces are limited!)
  • Two days of an action-packed main event agenda, with in-depth sessions featuring speakers from across Africa and beyond. Be sure to explore the Agenda and meet the Speakers!
  • A Digital Rights Fun Run – come ready with your running shoes!
  • A Digital Reality Walk through Paths, Traps and Safe Passages.
  • An exhibition where you can discover new work, explore resources and meet the people behind some of the amazing digital rights work happening across the continent.

FIFAfrica is a unique opportunity to discover new work and organisations, exchange ideas and insights, make connections, and encounter conversations that expand how you think about the digital rights ecosystem. There will be plenty of opportunities to connect, contribute and make FIFAfrica26 your own.

Visit the FIFAfrica website for more information.

African Lawyers Must Move From Using AI to Shaping its Governance

By Patricia Ainembabazi |

Artificial Intelligence (AI) is rapidly changing legal practice, presenting challenges for effective and accountable governance, professional responsibility, and the protection of clients’ rights and interests. Lawyers must develop institutional capabilities and learn how to verify AI-generated legal research and evidence, protect confidential information, challenge harmful automated decisions, and participate in shaping the policies governing these technologies.

These issues were at the heart of the AI Masterclass held during the 2026 Pan African Lawyers Union (PALU) Conference in Cairo, Egypt, themed “The African Lawyer in the Age of AI”. The masterclass was convened by the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) and the African Legal Information Institute (African LII).

The discussions recognised that AI competence is increasingly becoming part of professional responsibility. Lawyers are already using AI for research, legal drafting and review, due diligence, and case preparation. However, while these tools can improve efficiency, they also introduce risks around confidentiality, legal privilege, client data, hallucinated authorities, intellectual property, bias and professional negligence.

Through a practical exercise involving an AI-generated legal opinion containing fabricated authorities and unsupported conclusions, participants considered a fundamental professional principle: “the lawyer remains responsible for the work, even where AI assisted in producing it”.

The session consequently emphasised a source-first approach to AI-assisted legal research. The African LII and National Legal Information Institutes (LIIs) provide authoritative primary legal sources that lawyers can use to ground and verify AI-generated analysis.

Participants explored a workflow that starts by locating the relevant primary law, providing authoritative source material to an AI tool, constructing a controlled legal prompt, and then checking the response against the original source. This approach is particularly important in jurisdictions where legal information may be fragmented and general-purpose AI systems may produce incomplete, outdated, or fabricated legal authorities.

The Cairo AI masterclass builds on CIPESA’s efforts to enhance the capacity of legal practitioners in technology governance and digital rights. Indeed, as part of the upcoming Forum on Internet Freedom in Africa (FIFAfrica26) slated for September 28 – October 1, 2026, in Mauritius, CIPESA and PALU will convene a litigation surgery and a session on how Bar Associations can champion internet freedom in Africa.

The AfricanLII, CIPESA and PALU masterclass reinforced AI literacy and professionalism for lawyers. Already, AfricanLII has trained more than 400 lawyers from across the continent on AI, including in Dakar, Abidjan, Accra and Dar es Salaam.

Beyond responsible use of AI, the masterclass addressed how lawyers can respond when algorithmic systems contribute to discriminatory decisions, unlawful biometric surveillance, technology-facilitated gender-based violence, exclusion from public services and opaque algorithmic scoring. This raised emerging litigation questions around access to algorithmic evidence, explainability, discovery and disclosure, expert evidence, jurisdiction, liability and appropriate remedies.

The evidentiary implications are equally significant. Deepfakes, fabricated documents, and synthetic media complicate traditional assumptions about the authenticity and reliability of evidence. Lawyers will increasingly need to interrogate provenance, authentication and admissibility when AI-generated or manipulated material enters the evidentiary record.

The masterclass connected these practical challenges to Africa’s wider regulatory environment. Its central proposition was that lawyers should not wait for comprehensive AI legislation before engaging with AI governance processes. Existing laws, such as those on data protection, already regulate significant aspects of AI use, while gaps in those frameworks create new opportunities for legal practice, litigation and policy advocacy. Lawyers must therefore be present not only in courtrooms but also in the policy processes where the rules governing AI are being designed.

The deliberations identified priorities for law firms, bar associations, judiciaries, governments and civil society organisations. They include continuing professional development, model AI-use policies, strategic litigation, judicial guidance, regulatory engagement, procurement transparency and stronger collaboration between lawyers and technologists.

The masterclass pointed to seven practical actions for African lawyers and bar associations:

  1. Develop professional AI-use policies for law firms and bar associations with clear guidance on confidentiality, privilege, client data, verification of AI-generated work, professional supervision, and responsibility for AI-assisted legal advice.
  2. Adopt source-first AI-assisted legal research, where AI outputs do not substitute authoritative legal sources. Lawyers should ground prompts in primary law and independently verify propositions, citations and authorities before relying on them.
  3. Bar associations should engage judiciaries and public institutions on procurement transparency, human oversight, data governance, evidentiary integrity and mechanisms for challenging AI-assisted decisions.
  4. Lawyers should begin testing existing constitutional, administrative, data protection and other legal remedies through litigation where algorithmic systems affect rights, while developing strategies for obtaining and interrogating algorithmic evidence.
  1. Lawyers and bar associations should monitor national AI strategies and regulatory consultations, make coordinated submissions and ensure that emerging policy frameworks incorporate human rights, due process, transparency, accountability and access to remedy.
  2. Bar associations, law societies and African legal-policy organisations should seek representation in processes such as the UN Global Dialogue on AI Governance, AI for Good, the Internet Governance Forum, the Africa AI Governance Summit and specialist law-and-governance conferences.
  3. African lawyers should, beyond attending conferences, submit proposals, contribute evidence from African jurisdictions, shape standards and negotiating positions, and build coalitions capable of translating global principles into enforceable domestic and regional safeguards.

Ultimately, the masterclass demonstrated that lawyers have a role throughout the AI lifecycle: advising on responsible use, assessing legal and rights risks, challenging harmful systems, scrutinising AI-generated evidence, shaping procurement safeguards, and participating in policy and regulatory processes.

The key issue facing the African legal profession is no longer whether lawyers will encounter AI within their practice. It is whether the profession will simply use technologies and operate under rules designed by others or actively shape how AI is deployed and governed across the continent.

Beyond AI Safety: Why Africa Needs Sovereignty and Agency in Global AI Governance  

By Lillian Nalwoga |

As artificial intelligence reshapes economies and everyday life, the essential question for African countries is not simply whether AI will be safe. It is whether African societies will have the power, infrastructure, skills, resources, and representation to shape how AI is built and used.

The Inaugural UN Global Dialogue on AI, held in July 2026, among its priorities called for the need for “safe and inclusive AI” among others. However, the message from African delegates pointed to a broader concern. Safety without sovereignty and agency is not enough. Delegates pointed to limiting factors such as the lack of access to computing power, locally relevant data, technical expertise, financing, and meaningful influence over global AI rules. The speed of AI development intensifies these challenges. The preliminary report of the Independent International Scientific Panel on AI rightly warns that technological advances are moving faster than governments’ ability to adapt. This could create risks that can be severe, further worsening existing inequalities and undermine digital rights. The report further notes that steps to close these gaps do exist, but they require sustained investment in Member States’ capacity to shape, evaluate, and deploy AI.

Many African countries are now developing AI strategies and policies with the goal to harvest opportunities and mitigate AI risks. However, regulating alone without the necessary infrastructure, data, and human capacity are unlikely to deliver the desired outcomes. Moreover, as noted in the preliminary report, current global AI systems often overlook indigenous languages and cultures resulting in inaccurate outputs and systems that are poorly suited to local realities.

The need to protect data sovereignty was another issue that emerged clearly from the dialogue. Africa member states emphasized the need to have control over how their data is used, while ensuring that cross-border data arrangements are fair and mutually beneficial. For this to manifest, African countries would require access to computing capacity, high-quality data, skilled talent, sustainable financing, reliable electricity, and robust digital infrastructure to support meaningful AI development.

These concerns were further highlighted by the governments of Rwanda and Uganda, who noted that more than half of the world’s data centers are located in just a handful of wealthy countries, while Africa possesses less than 1 percent of global AI computing capacity. This systemic inequality risks entrenching dependence on foreign platforms, cloud providers, and AI models that are not designed for African contexts. Despite its significant contribution to the global AI economy in terms of critical mineral resources and social data, Africa is still too often positioned as a consumer rather than a shaper of AI technologies, standards, and governance.

This imbalance cannot be solved by ethical principles alone. From an African perspective, AI governance is not only a regulatory exercise; it is an infrastructure, development, and justice agenda. African member states at the Dialogue reinforced this message. Government delegates from Rwanda and Kenya for instance highlighted the need to expand access to infrastructure and financing, invest in skills and talent, reduce regulatory fragmentation, and build on regional initiatives such as the Africa Declaration on Artificial Intelligence. Other delegates similarly stressed that AI must be transparent, accountable, and subject to meaningful human oversight. The protection of underrepresented languages, cultures, and data, as well as concrete forms of international cooperation, was also highlighted.

The priorities identified by African stakeholders. This distinction should define the future of the Dialogue. Unlike what was seen at the India AI Summit, the UNGDIA drew many high-level African government delegations, who clearly voiced the continent’s priorities for advancing AI. African participation and that of the Global South must go beyond consultation after key decisions have been made. Stakeholders from the Global South should play a leading role in setting priorities, developing standards, and monitoring AI implementation. The challenge for the Dialogue is therefore not only to identify risks but also to ensure that countries have the capacity to prevent them and to benefit from AI on fair and equitable terms. The choice should not be between innovation and rights. The Dialogue must ensure that AI advances development without compromising dignity, privacy, equality, or democratic participation. This is also anchored in calls by civic actors from the Global South, who have long called for not merely inclusion in global AI discussions but also a South-led rights-based AI paradigm grounded in planetary limits, democratic participation, and intergenerational justice. Additionally, CIPESA’s research on AI impact in Africa has highlighted the need for a human-rights approach to AI regulation and the adoption of a human- centred AI governance in Africa, through deliberated and inclusive approaches.

Moreover, the UN Global Dialogue on AI can make a meaningful contribution by moving from issuing broad statements to practical, measurable actions anchored in Africa’s sovereignty, agency, and capacity to shape its own digital future. As the dialogue moves into its intersessional phase, it must shift from discussion to action. Global South governments and civil society are demanding equal footing in AI governance, and the UN must listen. One way to do this would be for the UN to champion a consolidated fund for AI development and capacity building in the Global South. The UN Secretary-General suggested creating a Global Fund on AI with a target of $3 billion to facilitate building basic AI capacity in developing countries. According to him, this is “less than one per cent of the annual revenue of a single tech company.” If successfully adopted, it could help launch AI development initiatives in many Global South countries. However, relying solely on tech companies is unlikely to address Africa’s and the wider Global South’s AI challenges. That is why African countries are calling for a holistic approach to AI investment. The 2025 Africa Declaration on Artificial Intelligence proposes the creation of a $60 billion Africa AI Fund financed by public, private, and philanthropic capital. The fund will support AI infrastructure, African AI businesses, workforce development, and domestic research capacity. It still remains unclear when these funds will take effect.

Nonetheless, more efforts are still needed to create public awareness on the ethical use of AI while also strengthening civil society voices in advocating for human rights respecting AI development.

FIFAfrica26 is calling! How Will You Answer?

By FIFAfrica |

Accept the call and come ready to “Be The Experience”!

At the upcoming Forum on Internet Freedom in Africa 2026 (FIFAfrica26), be ready to do lots of the following:

  • Connect and meet people beyond your usual networks.
  • Question by bringing the difficult questions.
  • Learn by stepping into conversations beyond your usual area of work
  • Contribute through sharing your experience, ideas and perspective
  • Collaborate and find people you can build with
  • Experience and make the Forum your own!

As you enjoy the weekend, take a little time to think about what you are bringing to FIFAfrica26, what you hope to take away, and the conversations you want to be part of.

We look forward to engaging with you more next week as we get closer to the Forum.

Until then, get ready to Accept the Call and #BeTheExperience!

If you haven’t yet registered for FIFAfrica26, you can still do so here.