CIPESA Urges Kenya to Align and Strengthen Its Draft AI Policy

By Raylenne Kambua |

In August 2026, the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) submitted a detailed set of recommendations to the Committee on the Draft Kenya Artificial Intelligence (AI) and Other Emerging Technologies Policy, 2026. The submission calls for closer alignment of Kenya’s policy with regional and international AI frameworks, alongside stronger protections for fundamental human rights.

The submission emphasises the need for Kenya to strike a balance between its aspirations for AI governance and strong safeguards that protect human rights, people, and democratic values. Without these, the nation risks developing systems that are innovative but exclusive, unfair, and harmful.

CIPESA argues that since Kenya is simultaneously advancing multiple AI-related processes, including a national AI strategy, a proposed AI Bill, and this draft AI policy, there is a need to align and harmonise the different proposed frameworks to ensure coherence and mitigate the risks of duplication and contradictory provisions.

For example, under section 3.5.1, the Policy commits the government to develop a dedicated AI and other Emerging Technologies Governance Act to provide the legal framework for its governance in Kenya, including the establishment, powers, and functions of the Council, without acknowledging that a similar Bill is already before the Senate.

Kenya’s policy direction is influenced by constitutional obligations as well as wider regional and international commitments that underscore the importance of human rights, accountability, transparency, and inclusiveness. According to CIPESA’s submission, Kenya should incorporate these principles into legally binding policy measures rather than just mentioning them.

The submission further encourages collaboration within the East African region and across the African continent, pointing to the value of shared standards, combined knowledge, and coordinated advocacy in strengthening governance outcomes.

CIPESA’s Navigating the Implications of AI in Kenya report also highlights that AI is reshaping digital participation, information access, and democracy in Kenya. In the absence of explicit protections and clear safeguards, AI systems can perpetuate discrimination, facilitate surveillance, violate people’s right to privacy, restrict freedom of expression, and undermine livelihoods. A rights-based approach that includes mandatory human rights impact assessments will ensure that potential harms are identified and mitigated before systems are deployed.

While the draft policy outlines institutional structures and governance ambitions, CIPESA argues that effective oversight will depend on institutional independence, clear powers, and meaningful accountability. The submission raises concerns about the proposed AI Council’s institutional independence and recommends giving it explicit authority to audit, obtain information, enforce compliance, and report directly to Parliament.

In automated systems, decision-making processes are often opaque and distributed across multiple actors. CIPESA therefore recommends clearly defining responsibilities and liability so that individuals harmed by AI systems have effective redress mechanisms.

Effective AI governance requires technical expertise, resources, and coordination across multiple agencies, yet many institutions in Kenya remain under-resourced. Therefore, proposed governance frameworks should be realistic about the state’s ability to implement and enforce stronger oversight mechanisms by investing in institutional capacity and talent retention.

According to CIPESA’s research, AI content moderation on major platforms is built largely for the Global North, with low-resource African languages. Many AI systems deployed in African contexts are trained on datasets that do not reflect local realities, leading to biased outcomes with direct implications for fairness, inclusion, and accuracy. This necessitates strong local data ecosystems and locally relevant content moderation systems and languages.

Kenya’s 2025 High Court ruling on the Worldcoin iris-scanning project affirmed the need for stronger data protection measures and integration with AI-specific legislation. According to CIPESA, incorporating pre-deployment oversight would transform AI governance from a reactive to a proactive model, particularly regarding sensitive biometric data.

AI systems are resource-intensive, consuming a lot of energy and requiring large amounts of water for data centre cooling. They also emit carbon and ultimately contribute to electronic waste. The submission recommends environmentally sustainable approaches, including independent third-party verification of environmental disclosures and publication of verified information in the public Registry.

The African Union AI Strategy identifies disinformation as a distinct risk. AI can influence public discourse by deciding which information is promoted, suppressed, or amplified. Disinformation, manipulation, targeted harassment, technology-facilitated gender-based violence (TFGBV), and AI-generated deepfakes can create particular risks in civic and democratic spaces, with disproportionate effects on women and other vulnerable groups. CIPESA proposes explicit recognition of these threats, implementation of gender impact assessments for high-risk systems, and stronger oversight of AI use in elections, political advertising, and content moderation.

Another recommendation is the inclusion of civil society representation at the steering committee, which is the top decision-making level. This is to ensure meaningful participation and alignment with the African Union AI Strategy and the UNESCO Recommendation on the Ethics of AI, which call for inclusive, multi-stakeholder involvement in AI governance, especially where major decisions are made.

Inclusion and public participation also require accessible language and processes that enable broader public engagement with what are often complex and technical issues, through investments in digital literacy and public awareness.

The submission further underscores the importance of labour rights and the often invisible workforce behind AI systems, many of whom work in unfavourable conditions. By highlighting the need for fair labour standards, protections, and recognition of data work, CIPESA also recommends including the workforce that sustains AI ecosystems in high-level policy discussions.

Explainability and transparency are essential to accountable AI governance. For people to trust AI systems, they need to understand how AI-driven decisions are made and contest results they believe to be unfair.  To prevent AI systems from being treated as black boxes beyond public scrutiny, there must be clear documentation, disclosure standards, and rights to explanation. This builds accountability and trust, especially in high-risk sectors like public services, healthcare, and finance.

Finally, CIPESA highlights the necessity of continuous policy review and adaptation, emphasising that governance frameworks must remain adaptable and responsive as AI technologies evolve quickly. This includes establishing mechanisms for periodic review, stakeholder feedback, and iterative policy development to ensure that regulations remain relevant and effective over time.

CIPESA’s recommendations provide a mechanism to close the gap between ambition and accountability as Kenya works to finalise its AI policy. The decisions made at this point will influence not only the development, deployment, and application of AI but also the distribution of its benefits and risks.

Key recommendations from CIPESA:

  1. Align Kenya’s AI policy and legislation to avoid duplication and conflicting provisions.
  2. Make human rights and gender impact assessments mandatory for high-risk AI systems.
  3. Strengthen the independence and powers of AI oversight institutions, including audit, enforcement, and redress.
  4. Protect workers across the AI value chain, including data annotators and content moderators.
  5. Require environmental accountability for AI, including disclosure and independent verification of energy, water, emissions, and e-waste impacts.
  6. Ensure transparency and meaningful participation, including stronger safeguards for AI-generated political content and a formal role for civil society in AI governance.

Read the full submission here: CIPESA Submission on Kenya’s Draft AI and Emerging Technologies Policy.

Civil Society and the Fight for Big Tech Accountability in Africa

By CIPESA Writer |

As digital platforms become central to how Africans communicate, access information, conduct business, and participate in public life, the question of who holds these companies accountable has become increasingly urgent.

Technology companies exercise considerable influence over personal data, online visibility, advertising markets, content moderation, and, increasingly, artificial intelligence systems. Yet CIPESA’s work on platform governance shows that having laws and regulations does not always translate into effective oversight of multinational technology companies.

These concerns were at the centre of the Big Tech Accountability Summit on July 30, 2026, where CIPESA’s Policy and Advocacy Officer, Patricia Ainembabazi, spoke on the panel “How Civil Society and Public Interest Litigation Drive Big Tech Data Protection Accountability in Africa.”

The discussions focused on the role civil society can play in triggering enforcement, the barriers to holding multinational companies accountable across borders, and the institutional reforms and policies needed to strengthen accountability. A key point from the discussion was that adopting data protection laws and establishing regulators does not automatically guarantee enforcement.

Across Africa, many regulators operate with limited financial resources, insufficient specialised personnel, fragmented mandates, and varying levels of institutional independence. They are nevertheless expected to oversee companies with substantial financial, technical, and legal capacity. Much of the evidence required to establish violations, including information about algorithms, data flows, and internal risk assessments, also remains under the control of the companies themselves.

This imbalance means that civil society can play an important role. As Patricia Ainembabazi noted, civil society organisations document harms, aggregate the experiences of affected users, undertake legal and technical research, file regulatory complaints, support strategic litigation, and sustain public scrutiny.

Similar concerns regarding tech accountability had been raised earlier on July 7, 2026, during the Humanising Big Tech Accountability webinar, where panelists argued that holding platforms accountable requires concerted efforts and a multistakeholder approach, including through storytelling and narrative building.

Uganda’s data protection case against Google LLC illustrates the importance of citizen-led accountability. The complaint was brought by four Ugandan data subjects, while CIPESA subsequently documented and amplified its wider significance. CIPESA highlighted how the case transformed an abstract privacy right into a concrete enforcement action against one of the world’s largest technology companies. The case also demonstrated the importance of testing the application of national data protection obligations to multinational companies operating across borders.

From western Africa, Nigeria offers another important example. A joint investigation by the Federal Competition and Consumer Protection Commission and the Nigeria Data Protection Commission resulted in a USD 220 million penalty against Meta and WhatsApp, which was subsequently upheld by the Competition and Consumer Protection Tribunal. The case demonstrates that African regulators can build credible enforcement actions against multinational platforms. It also raises the broader question of whether such penalties ultimately lead to lasting compliance and changes in corporate behaviour.

CIPESA’s recent analysis, Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa further show that countries are experimenting with different approaches to regulating platform power. South Africa’s Media and Digital Platforms Market Inquiry examined the influence of dominant platforms on local journalism and secured commitments from several major companies. Uganda’s prolonged restriction on Facebook presents a contrasting experience, where the social and economic costs were borne by users and businesses without clearly producing greater accountability from the platform.

These examples show that the ability of individual African countries to influence global technology companies depends not only on having laws but also on regulatory capacity, market size, and political leverage.

The challenge extends beyond data protection. CIPESA has documented how weaknesses in platform governance affect freedom of expression, access to information, civic participation, and gender equality. Inadequate local language content moderation, technology-facilitated gender-based violence (TFGBV), and rapidly spreading disinformation demonstrate how failures in platform accountability translate directly into harms for African users. Effective platform governance, therefore, needs to address not only content moderation but also pay attention to data governance, competition, algorithmic transparency, market concentration, and access to effective remedies.

For civil society and regulators, one of the major challenges is regulatory fragmentation. A technology company may collect data in one country, process or store it in another, and make key decisions elsewhere. Different national laws, procedures, and institutional capacities can allow companies to challenge jurisdiction or respond selectively across markets. Regulators and civil society organisations may also lack the resources to undertake sophisticated technical audits or sustain lengthy litigation.

As such, CIPESA has called for a shift beyond isolated national enforcement towards the domestication of the African Union-backed cross-border enforcement mechanism, bringing together data protection, competition, consumer protection, and communications regulators.

While regional approaches begin to emerge, the COMESA Competition Commission’s investigation into Meta across its member states illustrates the potential for collective oversight of platform power. CIPESA’s research similarly argues that no African country can effectively address systemic platform power in isolation and calls for stronger institutions, deeper regulatory cooperation, rights-respecting regulation, and greater transparency from technology companies.

Ultimately, civil society must be integral to this accountability architecture, not merely consulted after decisions have been taken, but as a source of complaints, research, community evidence, and independent oversight. Stronger Big Tech accountability in Africa will also depend on regulators that have the resources and independence to act, accessible remedies for affected users, coordinated regional enforcement, and sustained public interest advocacy.

During the Humanising Tech Accountability webinar, CIPESA emphasised the need for civil society actors to proactively engage in research and advocacy that centers and amplifies the impact of unchecked big tech companies’ practices on people’s lives. It is only when people understand the impact of practices and manifestations such as TFGBV or the spread of disinformation on their fundamental human rights, such as freedom of expression, access to information, civic participation, and gender equality, that they will aggressively demand platform reforms and accountability.

Through our research, policy engagement, and advocacy on data governance, privacy, platform governance, and digital rights, CIPESA continues to contribute to building an African digital ecosystem in which technological power is matched by meaningful accountability.

Shaping the Agenda for the Forum on Internet Freedom in Africa 2026 (FIFAfrica26): Thank You for Your Proposals

FIFAfrica26 |

The organisers of the upcoming Forum on Internet Freedom in Africa 2026 (FIFAfrica26) extend sincere appreciation to everyone who submitted a session proposal or travel support application in response to the recent Call.

We received over 450 submissions, reflecting a rich diversity of interests spanning the current digital rights landscape in Africa and their intersections with global dynamics. The submissions collectively reflected the pressing issues shaping digital rights, online freedoms, and internet governance across the continent while also highlighting the vibrant community working to advance internet freedom in Africa.

Successful Applicants

Successful applicants have been notified directly. We are excited to confirm that their sessions and contributions will form the core of the Forum’s agenda. We look forward to working closely with them to shape the programme and to bringing their insightful proposals to life during the Forum.

For Those Not Selected

If you have not received a success notification, please know that this does not reflect a lack of value in your submission. The volume of high-quality proposals far exceeded the available session slots, and difficult decisions had to be made. We remain grateful for your engagement and encourage you to stay connected with the Forum as there will be future opportunities to contribute.

Next Steps in the Process

  • The FIFAfrica26 agenda will be shared publicly in the coming weeks.
  • All applicants will continue to receive Forum updates and are warmly invited to attend as participants online or in person.
  • Registration to attend the Forum remains open: secure your seat here.

Plan Your Travel to Mauritius

The Forum will be hosted at the InterContinental Resort, Fort Coastal Road, MU, Balaclava 21306, Mauritius. All participants, those receiving travel support from CIPESA and other partners as well as independent participants, should refer to the FIFAfrica26 travel note and plan accordingly.

Thank you once again for your time, expertise, and commitment to building a free, open, and inclusive internet in Africa. We look forward to engaging with you online or in person at FIFAfrica26.

Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa

By CIPESA Writer |

Digital platforms have become central to how millions of Africans access news, organise politically, run businesses, and participate in public life. Yet the companies that operate these platforms make far-reaching decisions about what people see online, whose voices are amplified, and how public debate unfolds, often with limited accountability to the communities they affect.

As platforms increasingly rely on artificial intelligence and automated systems to recommend, rank, and moderate content, questions about transparency, oversight, and responsibility have become more urgent.

Governments across Africa are beginning to answer the question of who governs the platforms in different ways. CIPESA’s latest policy brief, Platform Governance in Africa: Emerging Models and Policy Priorities, examines how Nigeria, South Africa, and Uganda have confronted platform power, what their experiences reveal about the limits of national regulation, and why regional cooperation is becoming increasingly important.

Three Countries, Three Approaches

Nigeria has shown that African regulators can build credible cases and prevail in court. Following a joint investigation by the Federal Competition and Consumer Protection Commission and the Nigeria Data Protection Commission, Meta was found to have appropriated Nigerian users’ data without consent, abused its dominant market position, and treated Nigerian consumers less favourably than users elsewhere. In July 2024, regulators imposed a USD 220 million fine, which was later upheld on appeal.

Yet the case also illustrates the limits of enforcement. When the payment deadline expired in June 2025, neither Meta nor the regulator had publicly confirmed whether the fine had been paid. Nigeria demonstrated that regulators can win legal battles. Whether those victories translate into lasting changes in platform behaviour remains an open question.

South Africa has taken a different approach. Rather than relying primarily on financial penalties, the Competition Commission’s Media and Digital Platforms Market Inquiry sought to address how dominant platforms affect the sustainability of local journalism. The inquiry secured binding commitments from Google, Meta, TikTok, and Microsoft, including a ZAR 688 million (USD 41.6 million) media support package from Google. It represents one of Africa’s most ambitious efforts to address platform power through competition oversight, although its long-term impact will depend on sustained political commitment and regulatory capacity.

Uganda’s experience offers a different lesson. A government-ordered restriction on Facebook, imposed in January 2021 after Meta removed accounts linked to government-affiliated influence operations, has now lasted more than five years. The costs have largely been borne by Ugandan users and businesses, highlighting the wider social and economic consequences of unresolved disputes between governments and global platforms.

The Limits of Acting Alone

These cases highlight a central challenge of platform governance in Africa: legal authority does not always translate into practical leverage over global technology companies. Also, it is apparent that market size matters. Nigeria and South Africa, as two of Africa’s largest digital markets, secured stronger responses from platforms than Uganda did. Most African economies are considerably smaller than Meta’s annual profits, limiting the pressure individual governments can exert on multinational companies.

This reality is driving growing interest in regional approaches. The ongoing investigation by the Common Market for Eastern and Southern Africa (COMESA) Competition Commission into Meta’s practices across 21 member states reflects a shift towards collective oversight of platform power. By acting together, governments have greater potential to address competition, data governance, and digital market concerns than they do individually.

Why Platform Governance Matters

Platform governance is often discussed in terms of regulation and competition, yet users ultimately experience its consequences. During the conflict in Ethiopia’s Tigray region, platforms struggled to moderate harmful content in Tigrinya and Amharic. In one widely documented case, Facebook posts targeting university professor Meareg Amare remained online for days after being reported and were removed only after he had been killed.

Across Africa, women journalists, politicians, and activists continue to face technology-facilitated gender-based violence that platform governance systems have struggled to address effectively. These failures can discourage participation in public life and narrow the diversity of voices represented online.

Meanwhile, coordinated disinformation campaigns continue to spread faster than moderation and fact-checking systems can respond. A 2025 analysis in Kenya documented a coordinated campaign that generated more than 150,000 views in less than two weeks, illustrating how quickly harmful narratives can circulate before effective interventions are possible.

What Needs to Change

The policy brief argues that platform governance in Africa must extend beyond content moderation to broader questions of accountability, competition, data governance, and algorithmic transparency. Addressing these challenges will require governments to pursue rights-respecting regulation, regulators to strengthen oversight of platform systems, regional bodies to deepen cooperation, and platforms to provide greater transparency about how automated systems shape online experiences.

Platform governance in Africa is no longer only about removing harmful content. It is about who controls the infrastructure of public communication, on what terms, and with what accountability to the people who depend on it.

The experiences of Nigeria, South Africa, and Uganda show that African governments are increasingly willing to confront platform power. They also demonstrate that no African country can do so effectively in isolation. Building a more accountable digital future will require stronger institutions, deeper regional cooperation, and platforms that are genuinely responsive to the societies they serve.

To explore the evidence, country case studies, and policy recommendations in greater detail, read CIPESA’s full policy brief, Platform Governance in Africa: Emerging Models and Policy Priorities.

What Global South Civil Society Wants from AI Governance

By CIPESA Writer |

As global discussions on the future of Artificial Intelligence (AI) governance take place at the AI for Good Global Summit and the Global Dialogue on AI Governance, questions about who shapes AI systems, whose interests they serve, and how affected communities can participate in decision-making are becoming increasingly urgent.

The Collaboration on International ICT Policy for East & Southern Africa (CIPESA) is pleased to share this joint statement by the Global Digital Justice Forum and the Global South Alliance, of which it is a member. The statement reflects concerns that CIPESA has consistently raised through its research and policy engagement, namely, current approaches to AI development risk deepening existing inequalities, and meaningful AI governance requires stronger corporate accountability, equitable data governance, and investment in public-interest AI infrastructure.

Through submissions to national AI strategies in Africa, analysis of AI governance trends across 14 African countries, and engagement with global AI policy discussions, CIPESA has consistently advocated for inclusive, rights-based approaches that ensure communities most affected by AI developments have a meaningful role in shaping its future.

The statement below brings together civil society perspectives from across the Global South and calls for an AI governance approach grounded in human rights, equity, public interest, and meaningful participation.

Joint Statement issued by the Global Digital Justice Forum and the Global South Alliance in the lead-up to the Global Dialogue on AI Governance

July 2026

The current trajectory of Artificial Intelligence (AI) innovation has consolidated the neocolonial structures of development. Today, a handful of US and Chinese transnational corporations dominate global AI systems. Driven by massive capital, semiconductor manufacturing dominance, and hyperscale cloud infrastructure, these companies control over 90% of global AI data center capacity. Their market capitalization exceeds the combined national income of many countries in the Global South. The wealth and power amassed by these corporations come at a staggering cost, borne disproportionately by the South. From the devalued, dehumanizing labor that is essential for training AI models to the critical minerals, land, energy, and water, communities in the South continue to provide the scaffolding for the AI economy and society, without the voice and power to shape and benefit from this paradigm. These systemic injustices also perpetuate deep dependencies on current and future infrastructures — over which communities lack control and sovereign agency.

The Global Digital Justice Forum (GDJF) and the Global South Alliance (GSA) believe that the emerging AI order lacks legitimacy; it grants unbridled impunity to powerful corporations, while reducing humanity and nature to objects of limitless extraction. The many summits and conversations about AI governance have failed to tackle these core issues. 

Against this backdrop, we exhort the UN Global Dialogue on AI Governance to deliver on a South-led AI paradigm, anchored in a vision of rights-based development, respectful of planetary boundaries, and committed to intergenerational justice and human rights. We urge that the Global Dialogue on AI Governance commit to the following.

  • End AI extractivism 

A ‘move-fast-break-things’ approach to digital innovation aids profit, not people. In particular, the systemic and collective risks and harms associated with the violation of human rights, the erosion of democratic processes, the abuse of the environment, and the discrimination and invisibility of marginalized citizens in AI-driven decision-making in public services remain consistently ignored and underplayed in international consensus declarations. AI innovation must embrace the precautionary principle. It must be ethically and transparently developed, democratically accountable, and grounded in a globally agreed minimum floor for meaningful and dignified work, pluralistic knowledge, diversified economies, and planetary flourishing.

  • Apply the Common But Differentiated Responsibilities (CBDR) principle in international AI cooperation

The reckless path of data and AI technologies, designed and controlled by a few, has led to predatory value capture, strengthening the geo-economic and geo-political power of a handful of corporate actors and countries. The human and planetary costs arising from such opportunism are indeed a common concern. However, power diff erentials in international economic law have led to a status quo where trade, taxation, and Intellectual Property regimes clearly disadvantage developing countries, disproportionately enabling a massive transfer of wealth from the South to the North. This seriously undermines the development of digital infrastructure and human and institutional capabilities in developing countries. Such asymmetry must be remedied through global commitments to underwrite the development of regenerative, locally-led, AI infrastructures and models in the South.

  • Address corporate impunity in data and AI value chains

A global moratorium on the sale and use of AI systems that pose a high risk to human rights (such as remote biometric recognition, social scoring, spyware, and AI-driven autonomous weapons) is urgently needed. The proposed UN Binding Treaty on Transnational Corporations (TNCs) to hold global businesses accountable for human rights violations and environmental degradation in supply chains needs to be adopted without delay and appropriately future-proofed against the specific risks of harms and abuses in data and AI value chains.

  • Design a data governance framework that delivers on global equity

A ‘one-size-fits-all’ policy playbook for cross-border data flows governance will not deliver on equitable development. Development sovereignty must be recognized as a core principle in the global governance of cross-border data flows. Furthermore, the governance of the non-personal data commons requires a societal approach that includes safeguards for collective privacy and the rights of communities to steward the use and re-use of their data resources in innovation ecosystems, together with strong personal data protection rights.

  • Invest in the development of global public compute

The foundational infrastructure of compute is controlled by a few corporations. Even open-source AI models are often dependent on closed/proprietary infrastructure systems for their hosting and distribution. To ensure that data science and AI innovation deliver on public innovation, a global facility for public compute is needed. A ‘CERN for AI’ could support a distributed network of AI research centers coordinated by a central hub and provide access to innovators and researchers from developing countries.

The current trajectory of AI innovation is not working for the majority. The Global Dialogue on AI Governance must move the needle with conviction and courage towards people’s participation, planetary wellbeing, and public value. Anything less will not do justice to the people of the South.

Please find the links to prior submissions from GDJF and GSA to official consultations of the Global Dialogue below:
GDJF’s April 2026 submission
GSA’s April 2026 submission