CIPESA Weighs in on Kenya’s Draft Guidance Notes on AI and Emerging Technologies

By Raylenne Kambua |

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) submitted comments on two draft Guidance Notes that Kenya’s Office of the Data Protection Commissioner (ODPC) opened for public participation: one on Artificial Intelligence (AI), and another on Emerging Technologies.

The draft Notes provide guidance to entities on how to make sure their AI systems and emerging technologies comply with the Data Protection Act, 2019. While this is a positive step toward the responsible adoption and deployment of AI and emerging technologies, CIPESA highlights gaps the ODPC should address to ensure these technologies are governed in a rights-respecting, transparent, and accountable manner.

CIPESA’s Comments on the Draft Guidance Note on AI

A first set of concerns relates to how the AI Note fits with other legal frameworks. The Note cites only national laws, yet AI in Kenya operates within a wider regional and international framework, which risks regulatory inconsistency. Continental frameworks such as the AU Continental AI strategy, the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) and the AU Data Policy Framework offer guidance on AI development and harmonised data governance.

The Note requires entities to conduct adequacy assessments before transferring AI-processed personal data across borders. Although intended to protect privacy, this requirement could trigger blanket data localisation and impede cross-border AI inference and cloud computing capabilities. CIPESA recommends aligning these assessments with the AU Data Policy Framework and the African Continental Free Trade Area (AfCFTA) Protocol on Digital Trade to balance privacy safeguards with Africa’s digital trade ambitions.

As AI is increasingly deployed as an assistive technology, it risks excluding persons with disabilities when training data and biometric information are developed without their input. CIPESA observes that the Note omits Article 54 of the Constitution of Kenya, which protects persons with disabilities. Incorporating this provision would align the guidance with other standards, which set a benchmark for how regulation can protect groups that AI systems often overlook.

Furthermore, the draft Note lacks cross-references to the ODPC’s 2025 Guidance Note for Processing Children’s Data, and the Children Act, 2022, which enforces online protection and the best-interest principle for minors. This shortcoming creates disharmony among related efforts on children’s protection.

The submission points to the 2025 High Court judgment against Worldcoin, which found that iris data from hundreds of thousands of Kenyans was processed without a Data Protection Impact Assessment (DPIA). The Note’s biometric provisions prohibit only real-time surveillance without legal authority. This leaves retrospective analysis of stored facial or iris images unregulated, even though it carries equivalent privacy risks. CIPESA advocates mandatory pre-deployment registration with the ODPC and submission of DPIAs before any biometric data processing begins.

As generative AI spreads, so do its risks, such as hallucination. CIPESA recommends implementing verifiable content records and labelling requirements, such as watermarking or equivalent disclosure, for synthetic media used in decisions affecting individuals. This aligns with constitutional consumer rights under Article 46 and supports digital trust in continental trade involving automated electronic services covered by the AfCFTA Digital Trade Protocol.

The AI shaping Kenyans’ daily consumption centres around algorithmic feeds rather than enterprise chatbots. CIPESA argues that if AI laws regulate only technical enterprise tools while ignoring social media algorithms and content curation systems, they risk missing the AI that mostly shapes consumers’ public discourse. Global and local platforms that process Kenyan users’ data must also be subject to algorithmic governance and regular audits.

CIPESA also notes that the Note’s high-risk AI table omits information systems deployed in political and electoral environments. This is despite political opinion being classified as sensitive personal data under major data protection laws, and the AI Bill, 2026 addressing synthetic political content. CIPESA recommends adding categories for AI in political communication, voter micro-targeting, and synthetic political media ahead of the 2027 general election.

Other recommendations concern who the rules protect and who they hold to account. Kenya’s data annotators, content moderators, and reinforcement learning from human feedback (RLHF) workers help train both local and foreign AI models. However, the Note’s obligations focus entirely on end-user rights. CIPESA calls for extending data protection rights to this workforce, including protections over performance and monitoring data collected about them.

The Note requires entities to register with the ODPC as data controllers or processors before deploying any AI system that processes personal data. However, it does not address the separate Commissioner-maintained public register of high-risk AI models that is proposed under the AI Bill, 2026. CIPESA recommends clarifying how registration functions will be divided between the ODPC and the prospective AI Commissioner.

Regarding Digital Public Infrastructure such as interoperable digital identity systems, the Social Health Authority’s premium assessments, and the Kenya Revenue Authority’s automated eTIMS processes, CIPESA advises mandatory pre-deployment DPIAs, equity assessments before deployment, publicly disclosed methodologies, and human review guarantees.

Finally, AI governance is incomplete if it regulates companies but leaves government and security agencies outside meaningful oversight and accountability. CIPESA warns that without accountability for state use of AI in public services and surveillance, critical systems remain unmonitored. Citizens should be able to challenge public sector AI decisions just as they can challenge those of private entities.

CIPESA’s Comments on the Draft Guidance Note on Emerging Technologies

CIPESA also submitted comments on the Draft Guidance Note on Emerging Technologies. On cloud computing, it cautions that restricting systems tied to “the strategic interests of the state” risks becoming a de facto data localisation rule. CIPESA recommends confining data localisation to cases where a specific statutory requirement applies, in line with the AfCFTA Digital Trade Protocol and the AU Data Policy Framework’s emphasis on responsible intra-African data flows.

The submission advocates a complete prohibition on real-time remote biometric identification and indiscriminate mass surveillance in public spaces. It warns against using biometric categorisation to infer sensitive traits, alongside AI-based emotion recognition in schools and workplaces. Law enforcement remote biometric identification must require legal authorisation, judicial warrant, and independent oversight.

To strengthen impact assessments, CIPESA suggests publishing executive summaries of all DPIAs, excluding trade secrets, on a public High-Risk Technology Register before deployment. This would improve transparency and accountability and build public trust in high-risk emerging technology deployments.

Concerning automated decisions, CIPESA recommends meaningful human review by a reviewer with real authority to overturn or modify the outcome, not a rubber stamp. This should apply specifically to decisions on employment, credit, insurance, healthcare, social protection, immigration, and policing. To reduce the compliance burden, CIPESA recommends simplified registration and DPIA templates.

Building on CIPESA’s Wider Work on Kenya’s AI Governance

The two submissions follow CIPESA’s August 2026 submission on the Draft Kenya AI and Other Emerging Technologies Policy, which raised similar concerns about institutional independence and biometric safeguards at the policy level. They also draw on the Navigating the Implications of AI on Digital Democracy in Kenya report and its regional companion. The AI Guidance Note’s argument on algorithmic feeds echoes Kenya Doesn’t Have an AI Regulation Gap, It Has an Accountability Gap and Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa.

Read CIPESA’s full comments on the Draft Guidance Notes on AI here and on Emerging Technologies here.

African Lawyers Must Move From Using AI to Shaping its Governance

By Patricia Ainembabazi |

Artificial Intelligence (AI) is rapidly changing legal practice, presenting challenges for effective and accountable governance, professional responsibility, and the protection of clients’ rights and interests. Lawyers must develop institutional capabilities and learn how to verify AI-generated legal research and evidence, protect confidential information, challenge harmful automated decisions, and participate in shaping the policies governing these technologies.

These issues were at the heart of the AI Masterclass held during the 2026 Pan African Lawyers Union (PALU) Conference in Cairo, Egypt, themed “The African Lawyer in the Age of AI”. The masterclass was convened by the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) and the African Legal Information Institute (African LII).

The discussions recognised that AI competence is increasingly becoming part of professional responsibility. Lawyers are already using AI for research, legal drafting and review, due diligence, and case preparation. However, while these tools can improve efficiency, they also introduce risks around confidentiality, legal privilege, client data, hallucinated authorities, intellectual property, bias and professional negligence.

Through a practical exercise involving an AI-generated legal opinion containing fabricated authorities and unsupported conclusions, participants considered a fundamental professional principle: “the lawyer remains responsible for the work, even where AI assisted in producing it”.

The session consequently emphasised a source-first approach to AI-assisted legal research. The African LII and National Legal Information Institutes (LIIs) provide authoritative primary legal sources that lawyers can use to ground and verify AI-generated analysis.

Participants explored a workflow that starts by locating the relevant primary law, providing authoritative source material to an AI tool, constructing a controlled legal prompt, and then checking the response against the original source. This approach is particularly important in jurisdictions where legal information may be fragmented and general-purpose AI systems may produce incomplete, outdated, or fabricated legal authorities.

The Cairo AI masterclass builds on CIPESA’s efforts to enhance the capacity of legal practitioners in technology governance and digital rights. Indeed, as part of the upcoming Forum on Internet Freedom in Africa (FIFAfrica26) slated for September 28 – October 1, 2026, in Mauritius, CIPESA and PALU will convene a litigation surgery and a session on how Bar Associations can champion internet freedom in Africa.

The AfricanLII, CIPESA and PALU masterclass reinforced AI literacy and professionalism for lawyers. Already, AfricanLII has trained more than 400 lawyers from across the continent on AI, including in Dakar, Abidjan, Accra and Dar es Salaam.

Beyond responsible use of AI, the masterclass addressed how lawyers can respond when algorithmic systems contribute to discriminatory decisions, unlawful biometric surveillance, technology-facilitated gender-based violence, exclusion from public services and opaque algorithmic scoring. This raised emerging litigation questions around access to algorithmic evidence, explainability, discovery and disclosure, expert evidence, jurisdiction, liability and appropriate remedies.

The evidentiary implications are equally significant. Deepfakes, fabricated documents, and synthetic media complicate traditional assumptions about the authenticity and reliability of evidence. Lawyers will increasingly need to interrogate provenance, authentication and admissibility when AI-generated or manipulated material enters the evidentiary record.

The masterclass connected these practical challenges to Africa’s wider regulatory environment. Its central proposition was that lawyers should not wait for comprehensive AI legislation before engaging with AI governance processes. Existing laws, such as those on data protection, already regulate significant aspects of AI use, while gaps in those frameworks create new opportunities for legal practice, litigation and policy advocacy. Lawyers must therefore be present not only in courtrooms but also in the policy processes where the rules governing AI are being designed.

The deliberations identified priorities for law firms, bar associations, judiciaries, governments and civil society organisations. They include continuing professional development, model AI-use policies, strategic litigation, judicial guidance, regulatory engagement, procurement transparency and stronger collaboration between lawyers and technologists.

The masterclass pointed to seven practical actions for African lawyers and bar associations:

  1. Develop professional AI-use policies for law firms and bar associations with clear guidance on confidentiality, privilege, client data, verification of AI-generated work, professional supervision, and responsibility for AI-assisted legal advice.
  2. Adopt source-first AI-assisted legal research, where AI outputs do not substitute authoritative legal sources. Lawyers should ground prompts in primary law and independently verify propositions, citations and authorities before relying on them.
  3. Bar associations should engage judiciaries and public institutions on procurement transparency, human oversight, data governance, evidentiary integrity and mechanisms for challenging AI-assisted decisions.
  4. Lawyers should begin testing existing constitutional, administrative, data protection and other legal remedies through litigation where algorithmic systems affect rights, while developing strategies for obtaining and interrogating algorithmic evidence.
  1. Lawyers and bar associations should monitor national AI strategies and regulatory consultations, make coordinated submissions and ensure that emerging policy frameworks incorporate human rights, due process, transparency, accountability and access to remedy.
  2. Bar associations, law societies and African legal-policy organisations should seek representation in processes such as the UN Global Dialogue on AI Governance, AI for Good, the Internet Governance Forum, the Africa AI Governance Summit and specialist law-and-governance conferences.
  3. African lawyers should, beyond attending conferences, submit proposals, contribute evidence from African jurisdictions, shape standards and negotiating positions, and build coalitions capable of translating global principles into enforceable domestic and regional safeguards.

Ultimately, the masterclass demonstrated that lawyers have a role throughout the AI lifecycle: advising on responsible use, assessing legal and rights risks, challenging harmful systems, scrutinising AI-generated evidence, shaping procurement safeguards, and participating in policy and regulatory processes.

The key issue facing the African legal profession is no longer whether lawyers will encounter AI within their practice. It is whether the profession will simply use technologies and operate under rules designed by others or actively shape how AI is deployed and governed across the continent.

Beyond AI Safety: Why Africa Needs Sovereignty and Agency in Global AI Governance  

By Lillian Nalwoga |

As artificial intelligence reshapes economies and everyday life, the essential question for African countries is not simply whether AI will be safe. It is whether African societies will have the power, infrastructure, skills, resources, and representation to shape how AI is built and used.

The Inaugural UN Global Dialogue on AI, held in July 2026, among its priorities called for the need for “safe and inclusive AI” among others. However, the message from African delegates pointed to a broader concern. Safety without sovereignty and agency is not enough. Delegates pointed to limiting factors such as the lack of access to computing power, locally relevant data, technical expertise, financing, and meaningful influence over global AI rules. The speed of AI development intensifies these challenges. The preliminary report of the Independent International Scientific Panel on AI rightly warns that technological advances are moving faster than governments’ ability to adapt. This could create risks that can be severe, further worsening existing inequalities and undermine digital rights. The report further notes that steps to close these gaps do exist, but they require sustained investment in Member States’ capacity to shape, evaluate, and deploy AI.

Many African countries are now developing AI strategies and policies with the goal to harvest opportunities and mitigate AI risks. However, regulating alone without the necessary infrastructure, data, and human capacity are unlikely to deliver the desired outcomes. Moreover, as noted in the preliminary report, current global AI systems often overlook indigenous languages and cultures resulting in inaccurate outputs and systems that are poorly suited to local realities.

The need to protect data sovereignty was another issue that emerged clearly from the dialogue. Africa member states emphasized the need to have control over how their data is used, while ensuring that cross-border data arrangements are fair and mutually beneficial. For this to manifest, African countries would require access to computing capacity, high-quality data, skilled talent, sustainable financing, reliable electricity, and robust digital infrastructure to support meaningful AI development.

These concerns were further highlighted by the governments of Rwanda and Uganda, who noted that more than half of the world’s data centers are located in just a handful of wealthy countries, while Africa possesses less than 1 percent of global AI computing capacity. This systemic inequality risks entrenching dependence on foreign platforms, cloud providers, and AI models that are not designed for African contexts. Despite its significant contribution to the global AI economy in terms of critical mineral resources and social data, Africa is still too often positioned as a consumer rather than a shaper of AI technologies, standards, and governance.

This imbalance cannot be solved by ethical principles alone. From an African perspective, AI governance is not only a regulatory exercise; it is an infrastructure, development, and justice agenda. African member states at the Dialogue reinforced this message. Government delegates from Rwanda and Kenya for instance highlighted the need to expand access to infrastructure and financing, invest in skills and talent, reduce regulatory fragmentation, and build on regional initiatives such as the Africa Declaration on Artificial Intelligence. Other delegates similarly stressed that AI must be transparent, accountable, and subject to meaningful human oversight. The protection of underrepresented languages, cultures, and data, as well as concrete forms of international cooperation, was also highlighted.

The priorities identified by African stakeholders. This distinction should define the future of the Dialogue. Unlike what was seen at the India AI Summit, the UNGDIA drew many high-level African government delegations, who clearly voiced the continent’s priorities for advancing AI. African participation and that of the Global South must go beyond consultation after key decisions have been made. Stakeholders from the Global South should play a leading role in setting priorities, developing standards, and monitoring AI implementation. The challenge for the Dialogue is therefore not only to identify risks but also to ensure that countries have the capacity to prevent them and to benefit from AI on fair and equitable terms. The choice should not be between innovation and rights. The Dialogue must ensure that AI advances development without compromising dignity, privacy, equality, or democratic participation. This is also anchored in calls by civic actors from the Global South, who have long called for not merely inclusion in global AI discussions but also a South-led rights-based AI paradigm grounded in planetary limits, democratic participation, and intergenerational justice. Additionally, CIPESA’s research on AI impact in Africa has highlighted the need for a human-rights approach to AI regulation and the adoption of a human- centred AI governance in Africa, through deliberated and inclusive approaches.

Moreover, the UN Global Dialogue on AI can make a meaningful contribution by moving from issuing broad statements to practical, measurable actions anchored in Africa’s sovereignty, agency, and capacity to shape its own digital future. As the dialogue moves into its intersessional phase, it must shift from discussion to action. Global South governments and civil society are demanding equal footing in AI governance, and the UN must listen. One way to do this would be for the UN to champion a consolidated fund for AI development and capacity building in the Global South. The UN Secretary-General suggested creating a Global Fund on AI with a target of $3 billion to facilitate building basic AI capacity in developing countries. According to him, this is “less than one per cent of the annual revenue of a single tech company.” If successfully adopted, it could help launch AI development initiatives in many Global South countries. However, relying solely on tech companies is unlikely to address Africa’s and the wider Global South’s AI challenges. That is why African countries are calling for a holistic approach to AI investment. The 2025 Africa Declaration on Artificial Intelligence proposes the creation of a $60 billion Africa AI Fund financed by public, private, and philanthropic capital. The fund will support AI infrastructure, African AI businesses, workforce development, and domestic research capacity. It still remains unclear when these funds will take effect.

Nonetheless, more efforts are still needed to create public awareness on the ethical use of AI while also strengthening civil society voices in advocating for human rights respecting AI development.

CIPESA Urges Kenya to Align and Strengthen Its Draft AI Policy

By Raylenne Kambua |

In August 2026, the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) submitted a detailed set of recommendations to the Committee on the Draft Kenya Artificial Intelligence (AI) and Other Emerging Technologies Policy, 2026. The submission calls for closer alignment of Kenya’s policy with regional and international AI frameworks, alongside stronger protections for fundamental human rights.

The submission emphasises the need for Kenya to strike a balance between its aspirations for AI governance and strong safeguards that protect human rights, people, and democratic values. Without these, the nation risks developing systems that are innovative but exclusive, unfair, and harmful.

CIPESA argues that since Kenya is simultaneously advancing multiple AI-related processes, including a national AI strategy, a proposed AI Bill, and this draft AI policy, there is a need to align and harmonise the different proposed frameworks to ensure coherence and mitigate the risks of duplication and contradictory provisions.

For example, under section 3.5.1, the Policy commits the government to develop a dedicated AI and other Emerging Technologies Governance Act to provide the legal framework for its governance in Kenya, including the establishment, powers, and functions of the Council, without acknowledging that a similar Bill is already before the Senate.

Kenya’s policy direction is influenced by constitutional obligations as well as wider regional and international commitments that underscore the importance of human rights, accountability, transparency, and inclusiveness. According to CIPESA’s submission, Kenya should incorporate these principles into legally binding policy measures rather than just mentioning them.

The submission further encourages collaboration within the East African region and across the African continent, pointing to the value of shared standards, combined knowledge, and coordinated advocacy in strengthening governance outcomes.

CIPESA’s Navigating the Implications of AI in Kenya report also highlights that AI is reshaping digital participation, information access, and democracy in Kenya. In the absence of explicit protections and clear safeguards, AI systems can perpetuate discrimination, facilitate surveillance, violate people’s right to privacy, restrict freedom of expression, and undermine livelihoods. A rights-based approach that includes mandatory human rights impact assessments will ensure that potential harms are identified and mitigated before systems are deployed.

While the draft policy outlines institutional structures and governance ambitions, CIPESA argues that effective oversight will depend on institutional independence, clear powers, and meaningful accountability. The submission raises concerns about the proposed AI Council’s institutional independence and recommends giving it explicit authority to audit, obtain information, enforce compliance, and report directly to Parliament.

In automated systems, decision-making processes are often opaque and distributed across multiple actors. CIPESA therefore recommends clearly defining responsibilities and liability so that individuals harmed by AI systems have effective redress mechanisms.

Effective AI governance requires technical expertise, resources, and coordination across multiple agencies, yet many institutions in Kenya remain under-resourced. Therefore, proposed governance frameworks should be realistic about the state’s ability to implement and enforce stronger oversight mechanisms by investing in institutional capacity and talent retention.

According to CIPESA’s research, AI content moderation on major platforms is built largely for the Global North, with low-resource African languages. Many AI systems deployed in African contexts are trained on datasets that do not reflect local realities, leading to biased outcomes with direct implications for fairness, inclusion, and accuracy. This necessitates strong local data ecosystems and locally relevant content moderation systems and languages.

Kenya’s 2025 High Court ruling on the Worldcoin iris-scanning project affirmed the need for stronger data protection measures and integration with AI-specific legislation. According to CIPESA, incorporating pre-deployment oversight would transform AI governance from a reactive to a proactive model, particularly regarding sensitive biometric data.

AI systems are resource-intensive, consuming a lot of energy and requiring large amounts of water for data centre cooling. They also emit carbon and ultimately contribute to electronic waste. The submission recommends environmentally sustainable approaches, including independent third-party verification of environmental disclosures and publication of verified information in the public Registry.

The African Union AI Strategy identifies disinformation as a distinct risk. AI can influence public discourse by deciding which information is promoted, suppressed, or amplified. Disinformation, manipulation, targeted harassment, technology-facilitated gender-based violence (TFGBV), and AI-generated deepfakes can create particular risks in civic and democratic spaces, with disproportionate effects on women and other vulnerable groups. CIPESA proposes explicit recognition of these threats, implementation of gender impact assessments for high-risk systems, and stronger oversight of AI use in elections, political advertising, and content moderation.

Another recommendation is the inclusion of civil society representation at the steering committee, which is the top decision-making level. This is to ensure meaningful participation and alignment with the African Union AI Strategy and the UNESCO Recommendation on the Ethics of AI, which call for inclusive, multi-stakeholder involvement in AI governance, especially where major decisions are made.

Inclusion and public participation also require accessible language and processes that enable broader public engagement with what are often complex and technical issues, through investments in digital literacy and public awareness.

The submission further underscores the importance of labour rights and the often invisible workforce behind AI systems, many of whom work in unfavourable conditions. By highlighting the need for fair labour standards, protections, and recognition of data work, CIPESA also recommends including the workforce that sustains AI ecosystems in high-level policy discussions.

Explainability and transparency are essential to accountable AI governance. For people to trust AI systems, they need to understand how AI-driven decisions are made and contest results they believe to be unfair.  To prevent AI systems from being treated as black boxes beyond public scrutiny, there must be clear documentation, disclosure standards, and rights to explanation. This builds accountability and trust, especially in high-risk sectors like public services, healthcare, and finance.

Finally, CIPESA highlights the necessity of continuous policy review and adaptation, emphasising that governance frameworks must remain adaptable and responsive as AI technologies evolve quickly. This includes establishing mechanisms for periodic review, stakeholder feedback, and iterative policy development to ensure that regulations remain relevant and effective over time.

CIPESA’s recommendations provide a mechanism to close the gap between ambition and accountability as Kenya works to finalise its AI policy. The decisions made at this point will influence not only the development, deployment, and application of AI but also the distribution of its benefits and risks.

Key recommendations from CIPESA:

  1. Align Kenya’s AI policy and legislation to avoid duplication and conflicting provisions.
  2. Make human rights and gender impact assessments mandatory for high-risk AI systems.
  3. Strengthen the independence and powers of AI oversight institutions, including audit, enforcement, and redress.
  4. Protect workers across the AI value chain, including data annotators and content moderators.
  5. Require environmental accountability for AI, including disclosure and independent verification of energy, water, emissions, and e-waste impacts.
  6. Ensure transparency and meaningful participation, including stronger safeguards for AI-generated political content and a formal role for civil society in AI governance.

Read the full submission here: CIPESA Submission on Kenya’s Draft AI and Emerging Technologies Policy.

Rethinking Africa’s Approach to the Politics of AI Governance and Regulation

By Paul Kimumwe |

The past few years have witnessed a growing urgency for frameworks that regulate and harness the development and implementation of new and emerging technologies, especially Generative Artificial Intelligence (Gen AI).

At the international and regional level, the United Nations (UN) and the African Union (AU) have established norms through resolutions, strategies and guidelines to affirm the relationship between technology and human rights, and provide benchmarks for Member States developing rights-respecting AI governance and regulatory frameworks.

In March 2024, the UN adopted a landmark resolution on the promotion of “safe, secure and trustworthy” artificial intelligence (AI) systems that also benefit sustainable development. The resolution also calls upon Member States and other stakeholders “to refrain from or cease the use of artificial intelligence systems that are impossible to operate in compliance with international human rights law or that pose undue risks to the enjoyment of human rights.”

The 2024 resolution reaffirmed that “the same rights that people have offline must also be protected online, including throughout the life cycle of artificial intelligence systems.” It called upon member states to ensure that national AI governance and regulatory frameworks “promote safe, secure and trustworthy artificial intelligence systems” that are inclusive and benefit everyone in an equal manner.

In August 2025, the UN adopted resolution 79/325, establishing the Independent International Scientific Panel on AI and Global Dialogue on AI Governance. It aims to provide a platform to discuss international cooperation, share best practices and lessons learned, and to facilitate open, transparent and inclusive discussions on AI governance. However, a year earlier, in July 2024, the AU adopted the Continental AI Strategy, which emphasises the development of robust governance regimes for AI founded on ethical principles, democratic values, human rights, and the rule of law, in line with the AU  Agenda 2063.

Both the UN resolutions on AI and the AU continental strategy came on the backdrop of other AI-related policy guidelines such as Center for AI and Digital Policy’s 2018 Universal Guidelines for AI, the Organization for Economic Cooperation and Development (OECD) 2019 AI Principles / G20 AI Guidelines, the United Nations Education Scientific and Cultural Organization (UNESCO’s) 2021 Recommendation on the Ethics of AI, and the European Union Commission’s (EUC) 2024 European Union AI Act.

Many African countries have been actively developing AI-related laws, policies, and strategies. Rwanda was the first to adopt a national AI policy in 2019, followed by Ghana’s National Artificial Intelligence Strategy in October 2022, Egypt’s National Artificial Intelligence Strategy in January 2025, and Kenya’s own strategy in May 2025. Benin, Côte d’Ivoire, Ethiopia, Mauritius, Nigeria, Tunisia, Zambia, and Zimbabwe are among others that have developed AI policies or strategies. Others, such as Burkina Faso, Guinea, Lesotho, Mali, Namibia, and Uganda, are still at different stages in developing their AI policies or strategies.

A case of history repeating itself?

While all these have been welcome developments in the governance and regulation of AI, studies show that the adoption of international and regional human rights instruments and national laws, policies and strategies is often just the first step in a long process. If not well managed, it often results in provisions that are, although of a progressive nature, are hard to implement and fail to address local needs and realities.

This is because the process of drafting these laws and strategies in many developing contexts is often devoid of meaningful multistakeholder consultations and engagement. Moreover, there has also been a tendency to adopt and replicate models from the global North, whose texts, while progressive, have faced strong resistance from Member States as they sometimes do not align with local contexts and cultural norms.

For example, many African countries, including Algeria, Ethiopia, Cameroon, Kenya, Mauritius, Namibia, Rwanda, South Africa, and Uganda, expressed strong reservations about certain provisions contained in the Protocol to the African Charter on Human and People’s Rights on the Rights of Women in Africa (Maputo Protocol).

Additionally, most of these models are state-centric and grounded in frameworks that create a distinct binary between duty-bearers and rights-holders, but do not articulate how and what each party needs to do to ensure meaningful implementation of the initiatives.

While the state-centric and rights-based approaches may seem attractive, in practice, their relevance in advancing digital rights is often undermined, especially when the prescribed provisions and action points do not align with the country’s current social, economic and political realities. Indeed, cases abound in which initial promises have fizzled over time due to the political leadership’s inaction (and sometimes unwillingness) to fully adopt and implement the resolutions or strategies.

For example, it took almost nine years for the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) to enter into force on June 8, 2023, after its adoption in 2014. Indeed, more countries (40) have enacted data protection laws as compared to those that have ratified (16), highlighting a disconnect between national legal reforms and their commitment to continental frameworks. Similarly, the AU Protocol to the African Charter on Human and Peoples’ Rights on the Rights of Persons with Disabilities in Africa, adopted on January 30, 2018, took six years to enter into force, after the 15th ratification was achieved.

More critically, however, the lack of political will often reflect in the absence of clearly defined funding mechanisms for the implementation of these policies and strategies. As a result, even well-designed and progressive frameworks face implementation challenges due to structural flaws and insufficient funding.

For example, while Africa has scored highly in enacting Data Protection laws, which have become central to ongoing AI governance frameworks, one issue affecting their effective implementation is the lack of clear funding mechanisms for the regulatory bodies responsible for oversight and implementation. Other challenges include weak governance structures that deny these oversight bodies financial, decisional and operational independence and place them under the supervision of political appointees rather than parliament.

Designing for Failure?

Apart from Kenya, most African countries that have developed or are in the process of developing an AI strategy or policy do not provide for budgetary allocations or estimates for the implementation of their AI strategies, laws or policies. Countries such as Rwanda provide for a project-level funding framework, while others, such as Egypt and Mauritius, rely on programmatic budgets to fund the implementation of their strategies.

Even then, while implementation of Kenya’s National Artificial Intelligence Strategy (2025–2030) was costed at KSh 152 billion over a period of five years, a review of Kenya’s 2026/27 national budget shows no dedicated funding allocation for the strategy. Instead, the Sh8.6 billion allocated to the ICT sector mainly targets the expansion of broadband access, the strengthening of digital skills, and the digitisation of government services.

Additionally, in countries such as Ethiopia and Rwanda, while the policies provide for the establishment of an implementation body, several functions have been split across different ministries, departments and agencies (MDAs), which, in practice, would pose a significant challenge to meaningful execution.

For example, Rwanda’s AI policy mandates the Responsible AI office under the Ministry of ICT and Innovation to be responsible for effective tech implementation. It also positions the Rwanda Utilities Regulatory Authority (RURA) as the technical regulator responsible for developing ethical AI guidelines and principles, and the National Cyber Security Authority (NCSA) to oversee data protection compliance relevant to AI systems.

In Ethiopia, the policy designates the Ethiopian Artificial Intelligence Institute (EAII) as the national coordinating body responsible for implementation, standards development, and capacity building, and the Ministry of Innovation and Technology is responsible for providing policy oversight. Other sectoral agencies, such as the Ethiopian Communications Authority (ECA), the Ministry of Health, and the National Bank, have mandates over telecommunications and data matters, health-sector-related AI, and financial AI, respectively.

While a multisectoral approach to policy and strategic implementation can improve cohesiveness and legitimacy, the approach is prone to risks such as divergent priorities, internal conflicts, power struggles, and regulatory fragmentation, which are likely to affect how the policies and strategies are executed.

Implications for the Future of AI Governance and Regulation

In many African countries, the development of AI governance and regulatory structures is still in its infancy and presents a unique opportunity for Africans to shape their own destiny on how AI should be developed and deployed in ways that respond to and respect local needs and contexts.

Enactment of AI-specific Laws

In many countries, governments are relying on existing laws, such as data protection, communications, and cyber-related legislation, alongside the AI policies and strategies being developed. Given the evolving nature of AI, countries need to work towards enacting AI-specific laws that clearly define and contextualise AI.

Empowering the Oversight Bodies

As currently structured, many of the existing and proposed oversight bodies are either not yet operational or lack a clear mandate and sufficient resources for effective oversight. Additionally, many of them are situated within fragmented regulatory environments with overlapping responsibilities, which results in uncoordinated implementation. It is important, therefore, that the mandate of the oversight bodies and resources are clearly defined and guaranteed to ensure independence and eliminate the possibility of political interference.

Meaningful Stakeholder Participation

Having empowered stakeholders who are meaningfully engaged and participate in the development processes for policies, laws and strategies is critical to ensuring that the resulting instruments address real needs, are people-centred and implementable, and have government buy-in, as reflected in the government’s funded priorities.

Adopting a Human Rights-Centred Approach

A 2025 study by CIPESA shows that in many countries, the adoption of a human rights-centred approach to AI governance remains aspirational due to gaps in implementation, technical capacity, and stakeholder engagement in policy development and implementation. It is important, therefore, that current efforts prioritise safeguarding fundamental human rights and freedoms, enhancing human capabilities over replacement, and ensuring meaningful human control, transparency, fairness, and inclusivity in AI systems.