CIPESA Weighs in on Kenya’s Draft Guidance Notes on AI and Emerging Technologies

By Raylenne Kambua |

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) submitted comments on two draft Guidance Notes that Kenya’s Office of the Data Protection Commissioner (ODPC) opened for public participation: one on Artificial Intelligence (AI), and another on Emerging Technologies.

The draft Notes provide guidance to entities on how to make sure their AI systems and emerging technologies comply with the Data Protection Act, 2019. While this is a positive step toward the responsible adoption and deployment of AI and emerging technologies, CIPESA highlights gaps the ODPC should address to ensure these technologies are governed in a rights-respecting, transparent, and accountable manner.

CIPESA’s Comments on the Draft Guidance Note on AI

A first set of concerns relates to how the AI Note fits with other legal frameworks. The Note cites only national laws, yet AI in Kenya operates within a wider regional and international framework, which risks regulatory inconsistency. Continental frameworks such as the AU Continental AI strategy, the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) and the AU Data Policy Framework offer guidance on AI development and harmonised data governance.

The Note requires entities to conduct adequacy assessments before transferring AI-processed personal data across borders. Although intended to protect privacy, this requirement could trigger blanket data localisation and impede cross-border AI inference and cloud computing capabilities. CIPESA recommends aligning these assessments with the AU Data Policy Framework and the African Continental Free Trade Area (AfCFTA) Protocol on Digital Trade to balance privacy safeguards with Africa’s digital trade ambitions.

As AI is increasingly deployed as an assistive technology, it risks excluding persons with disabilities when training data and biometric information are developed without their input. CIPESA observes that the Note omits Article 54 of the Constitution of Kenya, which protects persons with disabilities. Incorporating this provision would align the guidance with other standards, which set a benchmark for how regulation can protect groups that AI systems often overlook.

Furthermore, the draft Note lacks cross-references to the ODPC’s 2025 Guidance Note for Processing Children’s Data, and the Children Act, 2022, which enforces online protection and the best-interest principle for minors. This shortcoming creates disharmony among related efforts on children’s protection.

The submission points to the 2025 High Court judgment against Worldcoin, which found that iris data from hundreds of thousands of Kenyans was processed without a Data Protection Impact Assessment (DPIA). The Note’s biometric provisions prohibit only real-time surveillance without legal authority. This leaves retrospective analysis of stored facial or iris images unregulated, even though it carries equivalent privacy risks. CIPESA advocates mandatory pre-deployment registration with the ODPC and submission of DPIAs before any biometric data processing begins.

As generative AI spreads, so do its risks, such as hallucination. CIPESA recommends implementing verifiable content records and labelling requirements, such as watermarking or equivalent disclosure, for synthetic media used in decisions affecting individuals. This aligns with constitutional consumer rights under Article 46 and supports digital trust in continental trade involving automated electronic services covered by the AfCFTA Digital Trade Protocol.

The AI shaping Kenyans’ daily consumption centres around algorithmic feeds rather than enterprise chatbots. CIPESA argues that if AI laws regulate only technical enterprise tools while ignoring social media algorithms and content curation systems, they risk missing the AI that mostly shapes consumers’ public discourse. Global and local platforms that process Kenyan users’ data must also be subject to algorithmic governance and regular audits.

CIPESA also notes that the Note’s high-risk AI table omits information systems deployed in political and electoral environments. This is despite political opinion being classified as sensitive personal data under major data protection laws, and the AI Bill, 2026 addressing synthetic political content. CIPESA recommends adding categories for AI in political communication, voter micro-targeting, and synthetic political media ahead of the 2027 general election.

Other recommendations concern who the rules protect and who they hold to account. Kenya’s data annotators, content moderators, and reinforcement learning from human feedback (RLHF) workers help train both local and foreign AI models. However, the Note’s obligations focus entirely on end-user rights. CIPESA calls for extending data protection rights to this workforce, including protections over performance and monitoring data collected about them.

The Note requires entities to register with the ODPC as data controllers or processors before deploying any AI system that processes personal data. However, it does not address the separate Commissioner-maintained public register of high-risk AI models that is proposed under the AI Bill, 2026. CIPESA recommends clarifying how registration functions will be divided between the ODPC and the prospective AI Commissioner.

Regarding Digital Public Infrastructure such as interoperable digital identity systems, the Social Health Authority’s premium assessments, and the Kenya Revenue Authority’s automated eTIMS processes, CIPESA advises mandatory pre-deployment DPIAs, equity assessments before deployment, publicly disclosed methodologies, and human review guarantees.

Finally, AI governance is incomplete if it regulates companies but leaves government and security agencies outside meaningful oversight and accountability. CIPESA warns that without accountability for state use of AI in public services and surveillance, critical systems remain unmonitored. Citizens should be able to challenge public sector AI decisions just as they can challenge those of private entities.

CIPESA’s Comments on the Draft Guidance Note on Emerging Technologies

CIPESA also submitted comments on the Draft Guidance Note on Emerging Technologies. On cloud computing, it cautions that restricting systems tied to “the strategic interests of the state” risks becoming a de facto data localisation rule. CIPESA recommends confining data localisation to cases where a specific statutory requirement applies, in line with the AfCFTA Digital Trade Protocol and the AU Data Policy Framework’s emphasis on responsible intra-African data flows.

The submission advocates a complete prohibition on real-time remote biometric identification and indiscriminate mass surveillance in public spaces. It warns against using biometric categorisation to infer sensitive traits, alongside AI-based emotion recognition in schools and workplaces. Law enforcement remote biometric identification must require legal authorisation, judicial warrant, and independent oversight.

To strengthen impact assessments, CIPESA suggests publishing executive summaries of all DPIAs, excluding trade secrets, on a public High-Risk Technology Register before deployment. This would improve transparency and accountability and build public trust in high-risk emerging technology deployments.

Concerning automated decisions, CIPESA recommends meaningful human review by a reviewer with real authority to overturn or modify the outcome, not a rubber stamp. This should apply specifically to decisions on employment, credit, insurance, healthcare, social protection, immigration, and policing. To reduce the compliance burden, CIPESA recommends simplified registration and DPIA templates.

Building on CIPESA’s Wider Work on Kenya’s AI Governance

The two submissions follow CIPESA’s August 2026 submission on the Draft Kenya AI and Other Emerging Technologies Policy, which raised similar concerns about institutional independence and biometric safeguards at the policy level. They also draw on the Navigating the Implications of AI on Digital Democracy in Kenya report and its regional companion. The AI Guidance Note’s argument on algorithmic feeds echoes Kenya Doesn’t Have an AI Regulation Gap, It Has an Accountability Gap and Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa.

Read CIPESA’s full comments on the Draft Guidance Notes on AI here and on Emerging Technologies here.

State of Internet Freedom In Africa Report

2025 State of Internet Freedom In Africa Report Documents the Implications of AI on Digital Democracy in Africa

By Juliet Nanfuka | 

The 2025 edition of the Forum on Internet Freedom in Africa (FIFAfrica25) concluded on a high note with the unveiling of the latest State of Internet Freedom in Africa (SIFA) report. Titled Navigating the Implications of AI on Digital Democracy in Africa, this landmark study unpacks how artificial intelligence is shaping, disrupting, and reimagining civic space and digital rights across the continent.

Drawing on research from 14 countries (Cameroon, Egypt, Ethiopia, Ghana, Kenya, Mozambique, Namibia, Nigeria, Rwanda, Senegal, South Africa, Tunisia, Uganda, and Zimbabwe), the report documents both the immense promise and the urgent perils of AI in Africa. It highlights AI’s potential to strengthen democratic participation, improve public services, and drive innovation, while also warning of its role in amplifying surveillance, disinformation, and exclusion. 

Using a qualitative approach, including literature review and key informant interviews, the report shows that AI is rapidly transforming how Africans interact with technology, yet AI also amplifies existing vulnerabilities, introduces new challenges that undermine fundamental freedoms, and deepens existing inequalities.

The report notes that the political environment is a crucial determinant of AI’s trajectory, with strong democracies generally enabling a positive outcome. Top performers in freedom and governance indices such as South Africa, Ghana, Namibia, and Senegal are more likely to set the standard to AI rollout in Africa. Conversely, countries with lower democratic credentials such as Cameroon, Egypt, Ethiopia, and Rwanda risk constraining AI’s potential or deploying it to amplify digital authoritarianism and political repression.  

Countries such as South Africa, Tunisia and Egypt that have a higher internet access and technological development, Gross Domestic Product (GDP) per capita, and score highly on the Human Development Index (HDI), are more likely to lead in AI. Meanwhile, countries with lower or weaker levels of digital infrastructure face greater challenges and higher risks of AI replicating and worsening existing divides. Such countries include Cameroon, Mozambique and Uganda.

The political environment is a crucial determinant of AI’s trajectory, with strong democracies generally enabling a positive outcome. Economic and developmental status also dictates the capacity for AI development and adoption. 

Despite these challenges, the report documents that AI offers substantial value to the public sector by improving service delivery and enhancing transparency. Governments are leveraging AI tools for efficiency, such as the South African Revenue Services (SARS) AI Assistant for tax assessments and Nigeria’s Service-Wise GPT for streamlined governance document access. In Kenya, the Sauti ya Bajeti (Voice of the Budget) platform fosters fiscal transparency by allowing citizens to query and track government expenditures. Furthermore, countries like Tunisia and Uganda are using AI models within tax bodies to detect fraud, while Rwanda is deploying AI for judicial system improvements and identity management at borders.

The private sector and academic institutions are driving AI-inspired innovation, particularly in the areas of FinTech, AgriTech, and Natural Language Processing (NLP). For the latter, notable efforts to localise AI include Tunisia’s TUNBERT model for Tunisian Arabic, and Ghana’s Khaya, an open-source AI-powered translator tailored for local languages. In Ghana, the DeafCanTalk, is an AI-powered app that enables bidirectional translation between sign language and spoken language, and has enhanced accessibility for deaf users. Rwanda has integrated AI into healthcare using drone delivery systems for medical supplies, while Cameroon and Uganda use AI to assist farmers with pest identification. 

However, despite increasing investment, such as the ongoing USD 720 million investment in compute power by Cassava Technologies across hubs in South Africa, Egypt, Kenya, Morocco, and Nigeria, Africa receives  significantly lower AI funding than global counterparts.

Moreover, while AI is gaining traction across many sectors, the proliferation of AI-generated misinformation and disinformation is a pervasive and growing challenge that poses a critical threat to electoral integrity. During South Africa’s 2024 elections, deepfake videos were circulated to manipulate perceptions and endorse political entities. Similarly, during elections and protests in Kenya and Namibia, deepfake technology and automated campaigns were used to discredit opponents. 

The report also documents that governments are deploying AI-powered surveillance technologies, which has led to widespread privacy violations and a chilling effect on freedoms. For example, pro-government propagandists in Rwanda utilised Large Language Models (LLMs) to mass-produce synthetic messages on social media, simulating authentic support and suppressing dissenting voices. Meanwhile, algorithmic bias and exclusion are producing discriminatory outcomes, particularly against low-resource African languages. Also, AI-based content moderation is often ineffective because it lacks contextual understanding and fails to capture local nuance.

A key finding in the report is that across the continent, the pace of AI development far outstrips regulatory readiness. None of the 14 study countries has AI-specific legislation. Instead, fragmented laws on data protection, cybercrime, and copyright are stretched to cover AI, but remain inadequate. Data protection authorities are under-resourced, under-staffed, and often lack the technical expertise required to audit or govern complex AI systems.

Although many national AI strategies are emerging, they prioritise economic growth while neglecting human rights and accountability. This is also fuelled by policy processes that are often opaque and dominated by state actors, with limited multistakeholder participation.

The report  stresses that without deliberate, inclusive, and rights-centred governance, AI risks entrenching authoritarianism and exacerbating inequalities. 

To avoid the current trajectory that AI is taking in Africa, in which AI risks entrenching authoritarianism and exacerbating inequalities, the report calls for a human-centred AI governance framework built on inclusivity, transparency, and context. 

It also makes recommendations, including enacting comprehensive AI-specific legislation, instituting mandatory human rights impact assessments, establishing empowered AI and data governance institutions, and promoting rights-based advocacy. Others are building technical capacity across governments, civil society and media, and developing policies that prioritise equity and human dignity alongside innovation.

AI offers Africa the opportunity to foster innovation, strengthen democracy, and drive sustainable development. This edition of the State of Internet Freedom in Africa report provides an evidence-based roadmap to ensure that Africa’s digital future remains open, inclusive, and rights-respecting.Find the report here.