Kenya launched its National AI Strategy 2025-2030 in March 2025, a policy document that sets direction on AI capacity, infrastructure, and governance but is not itself enforceable law. What actually binds an AI operator in Kenya today is older and narrower: the Data Protection Act, 2019, and specifically its automated decision-making protections, enforced by the Office of the Data Protection Commissioner. This guide sets out what is currently binding, what the National AI Strategy signals for the years ahead, and how Kenya's position compares to the EU AI Act and to the African Union's continental coordination effort.

Key takeaways

  • Kenya has no enacted, horizontal AI statute in 2026. The Ministry of Information, Communications and the Digital Economy launched the National AI Strategy 2025-2030 in March 2025 as policy direction, not binding law.
  • The Data Protection Act, 2019, gives individuals a right under section 35 not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, closely modelled on Article 22 of the EU GDPR.
  • The Office of the Data Protection Commissioner (ODPC), operational since 2020, enforces the Data Protection Act and is the closest thing Kenya currently has to an AI-adjacent regulator, given how much AI-driven harm in practice runs through automated data processing.
  • Kenya's National AI Strategy was developed within the African Union's Continental AI Strategy, endorsed by the AU Assembly in July 2024, which sets a coordination framework for AI governance across member states without itself being directly binding on any one state.
  • An operator with an EU AI Act or GDPR-aligned compliance programme will, in most respects, meet or exceed Kenya's current binding requirements, but should treat the Data Protection Act's automated-decision provisions as an active, enforceable obligation rather than a formality.

Background: the National AI Strategy as direction, not law

Kenya's Ministry of Information, Communications and the Digital Economy launched the National AI Strategy 2025-2030 in March 2025, positioning Kenya as an early mover among African nations on formal AI policy. The strategy sets out priorities across AI infrastructure investment, workforce development, research capacity, and governance principles, and situates Kenya's approach within the wider East African and continental context. It is, by design, a policy and investment framework rather than a statute: it does not create new offences, does not establish a dedicated AI regulator, and does not impose enforceable obligations on private operators deploying AI systems in Kenya.

Operators should read the National AI Strategy as a strong signal of where Kenyan AI governance is heading, including likely future emphasis on data infrastructure, algorithmic accountability, and sector-specific AI guidance, rather than as a source of binding obligations today. The strategy's governance chapter references the need for updated legal and regulatory frameworks, which indicates that a more comprehensive statutory response is anticipated, but as of mid-2026 no draft AI bill has been formally tabled before the Kenyan Parliament.

What is actually binding today: the Data Protection Act, 2019

The Data Protection Act, 2019, enacted in November 2019, is Kenya's principal data protection statute and the most consequential binding law for AI operators processing personal data in Kenya. It establishes registration requirements for data controllers and processors, core data protection principles broadly comparable to the GDPR's, and, most relevantly for AI systems, a specific right addressing automated decision-making.

Section 35 of the Act gives a data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, subject to defined exceptions such as decisions necessary for entering into or performing a contract at the data subject's request, or decisions authorised by law with suitable safeguards. This provision is closely modelled on Article 22 of the EU GDPR, and its practical effect is direct: any AI agent making or materially influencing a consequential decision about an individual using their personal data, in categories such as credit assessment, employment screening, or insurance underwriting, falls within the scope of a right the Data Protection Act makes enforceable.

The Office of the Data Protection Commissioner (ODPC), established under the Act and operational since 2020, enforces these provisions. The ODPC has powers to investigate complaints, issue enforcement notices, and impose administrative penalties for non-compliance. For AI operators, ODPC enforcement action, not a future AI-specific statute, is the current binding compliance risk in Kenya.

The African Union's Continental AI Strategy and Kenya's place within it

In July 2024, the African Union Assembly endorsed a Continental AI Strategy, establishing a shared framework across AU member states covering AI governance principles, capacity building, data infrastructure, and coordinated positions on international AI standards discussions. The Continental AI Strategy is a coordination instrument rather than directly binding law: it does not itself create obligations enforceable against private operators in any single member state, and its force depends on individual states translating its principles into domestic policy and, eventually, legislation.

Kenya's National AI Strategy 2025-2030 was developed with explicit reference to this continental context, and Kenya has positioned itself as an active participant in AU-level AI governance discussions. Operators tracking the likely direction of Kenyan AI regulation should treat continued AU-level coordination, alongside any Kenyan sector-specific guidance from bodies such as the Communications Authority of Kenya or the Central Bank of Kenya, as the most probable near-term source of new AI-specific obligations, ahead of a comprehensive national AI statute.

Comparison with the EU AI Act

Set against the EU AI Act, Kenya's current framework is data-protection-led rather than a horizontal, risk-tiered AI regulation. The Data Protection Act's section 35 automated-decision right addresses one specific, important category of AI harm, consequential automated decisions about individuals, but does not extend to the fuller set of obligations the EU AI Act imposes on high-risk AI systems under Articles 9 through 17: documented risk management, technical documentation, logging, transparency, and human oversight as free-standing requirements independent of whether a specific automated decision was made. There is no Kenyan equivalent of a conformity assessment procedure, no risk-tiered classification system comparable to Annex III, and no turnover-based penalty regime comparable to Article 99.

The practical implication for global operators is similar to the pattern seen in other pre-legislative jurisdictions in this network: an organisation that has built a compliance programme for the EU AI Act will, in most respects, exceed what Kenyan law currently requires. The risk runs the other way for Kenya-focused or Kenya-only operators, who may not have built governance infrastructure consistent with where Kenyan law is heading, given the direction signalled by both the National AI Strategy and the African Union's Continental AI Strategy.

Practical implications for operators

Three steps are proportionate for an operator active in Kenya in 2026. First, treat Data Protection Act compliance, and specifically the section 35 automated-decision-making right, as the binding floor for any AI system that makes or materially influences a consequential decision about an individual in Kenya, and confirm you can offer the safeguards the Act requires, including a mechanism for the individual to contest the decision and request human review. Second, register with the ODPC as a data controller or processor if your AI deployment's data processing brings you within the Act's registration requirements, and confirm your data governance documentation would satisfy an ODPC enforcement notice. Third, monitor the National AI Strategy's implementation and any sector-specific guidance from the Communications Authority of Kenya or the Central Bank of Kenya, since these are the most likely near-term sources of new binding obligations ahead of a comprehensive AI statute.

For the wider African regulatory landscape this guide sits within, see the South Africa AI regulation guide and the Nigeria AI regulation guide. For the EU deployer obligations that remain the highest-stringency benchmark against which any pre-legislative regime is measured, see the Article 26 deployer obligations guide on agentliability.eu. Operators assembling documentation evidence for cross-border AI governance programmes that include Kenya may also find the Agent Certified methodology useful as a structured reference framework.

The gap to track. Kenya's binding AI-relevant obligations today run through the Data Protection Act, 2019 and ODPC enforcement, not through the National AI Strategy, which remains a policy document with no confirmed legislative timetable as of 2026. A formal AI bill tabled before Parliament, not a further strategy update, is the development most likely to change this picture materially.

Frequently asked questions

Does Kenya have an enacted AI law in 2026?

No. Kenya has not enacted a dedicated AI statute. The Ministry of Information, Communications and the Digital Economy launched Kenya's National AI Strategy 2025-2030 in March 2025, which sets policy direction and investment priorities but is not itself binding law. As of 2026 the strategy has not been converted into a horizontal AI statute, and AI-relevant obligations that are actually enforceable in Kenya today sit inside the Data Protection Act, 2019.

Does Kenya's Data Protection Act address automated decision-making by AI?

Yes. The Data Protection Act, 2019 gives data subjects a right, under section 35, not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them, subject to defined exceptions. This provision is closely modelled on Article 22 of the EU GDPR and is the clearest current statutory hook for AI-driven decisions in Kenyan law, enforced by the Office of the Data Protection Commissioner.

Which authority enforces AI-related data obligations in Kenya?

The Office of the Data Protection Commissioner (ODPC), established under the Data Protection Act, 2019 and operational since 2020, enforces the Act's provisions, including the automated decision-making protections in section 35. The ODPC has powers to investigate complaints, issue enforcement notices, and impose administrative penalties for breaches. No dedicated AI regulator exists separately from the ODPC as of 2026.

How does Kenya's approach compare to the EU AI Act?

Kenya's current framework is data-protection-led rather than a horizontal, risk-tiered AI statute. The Data Protection Act's automated-decision-making right is narrower in scope than the EU AI Act's Annex III high-risk categories and Articles 9 to 17 obligations, and there is no Kenyan equivalent of a conformity assessment regime or a turnover-based AI penalty tier. The National AI Strategy 2025-2030 signals an intention to build more comprehensive AI governance over time, aligned with the African Union's Continental AI Strategy, but as of 2026 it remains a policy document rather than binding law.

How does the African Union's Continental AI Strategy relate to Kenya's national approach?

The African Union Assembly endorsed a Continental AI Strategy in July 2024, setting a shared framework for African Union member states on AI governance, capacity building, and data infrastructure. Kenya's National AI Strategy 2025-2030 was developed within this continental context and references AU-level coordination on AI. The Continental AI Strategy itself is not directly binding on Kenya or any member state; it functions as a coordination framework that individual states, including Kenya, are expected to translate into domestic policy and, eventually, legislation.

References

  1. Ministry of Information, Communications and the Digital Economy (Kenya). National Artificial Intelligence Strategy 2025-2030, launched March 2025.
  2. Data Protection Act, No. 24 of 2019 (Kenya), enacted November 2019. Section 35, right in relation to automated decision-making.
  3. Office of the Data Protection Commissioner (Kenya) (ODPC), established under the Data Protection Act, 2019, operational since 2020.
  4. African Union Assembly. Continental Artificial Intelligence Strategy, endorsed July 2024.
  5. Regulation (EU) 2016/679 (GDPR), Article 22, referenced for comparison as the model underlying Kenya's section 35 automated-decision-making right.
  6. Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), for comparison, including Articles 9 to 17 (high-risk obligations), Article 26 (deployer obligations), and Article 99 (penalties).