Kenya's Proposed AI Policy Could Redistribute Economic Value Across Its Digital Economy
Key Takeaways
- •The draft policy classifies AI as strategic national infrastructure alongside sectors such as transport, energy, and telecommunications.
- •It calls for investment in domestic compute capacity, sovereign cloud infrastructure, secure data systems, connectivity, sustainable energy, and AI testing facilities.
- •The policy would apply to foreign AI systems used in Kenya or affecting people and businesses in the country, extending oversight across the AI lifecycle.
- •Banks, fintechs, insurers, hospitals, telcos, and government agencies would inherit responsibilities for how third-party AI systems are deployed and monitored.
- •Universities are assigned a central role in building skills, generating intellectual property, creating datasets, and supporting local AI innovation.

Kenya has long pursued its ambition to become Africa's artificial intelligence hub. The country has championed sovereign AI infrastructure, supported continental declarations calling for greater local computing capacity, and secured hosting rights for the 2027 Responsible AI in the Military Domain summit. Kenya's broader tech ambitions build on its reputation as "Silicon Savannah," a moniker earned through innovations like M-Pesa that demonstrated the country's capacity to produce, not just consume, globally significant technology.
Now, its proposed Artificial Intelligence and Emerging Technologies Policy sets out one of the government's most detailed blueprints yet for how it intends to regulate, build, and commercialise AI. It arrives alongside similar efforts across the continent, including the African Union's 2024 continental AI strategy and Rwanda's ongoing AI regulatory work, positioning Africa's policy landscape as one of the world's most active emerging regions for AI governance.
The draft policy goes well beyond narrow regulation. It seeks to reshape the economics of artificial intelligence in Kenya by encouraging investment in local infrastructure, imposing new obligations on companies that deploy AI, and giving consumers greater control over how algorithms influence their lives. In doing so, it redraws the balance between those likely to benefit from the AI transition and those who stand to lose.
If adopted, the policy would begin redistributing the costs, opportunities, and economic value of one of the world's fastest-growing technologies—creating clear winners and losers across Kenya's digital economy.
From AI adopter to AI producer
Throughout the global AI boom, Kenya, like much of Africa, has been an enthusiastic adopter rather than a creator. Businesses have integrated AI chatbots into customer service. Banks have experimented with AI-powered fraud detection and credit scoring. Hospitals are exploring machine learning to improve diagnosis. Government agencies have incorporated AI into broader digital transformation strategies.
Yet the infrastructure powering this transformation remains overwhelmingly foreign. The world's leading AI models are developed primarily in the United States and China. The specialised chips that power them are manufactured largely by Nvidia, an American company, while much of the cloud infrastructure Kenyan businesses rely on is hosted abroad. As a result, a significant share of the economic value generated by AI flows to global technology companies rather than remaining in Kenya.
Kenya's proposed AI policy starts from the premise that this dependence is more than a commercial reality—it is a strategic vulnerability. The draft identifies reliance on foreign cloud and computing infrastructure as one of the country's biggest structural weaknesses, arguing that dependence on externally hosted systems weakens data sovereignty, reduces national control over digital assets, and limits the country's ability to capture value created by AI.
The government's response is ambitious. Rather than treating AI as just another digital technology, the policy classifies it as strategic national infrastructure, placing it alongside sectors such as transport, energy, and telecommunications.
"Kenya's ambition is to position itself not only as a user of AI… but also as a producer, deployer, regulator, investor destination, and trusted international partner within the intelligent economy," the policy states.
That distinction is significant. Much of the global debate around AI regulation has focused on mitigating harm—from deepfakes, misinformation, and algorithmic bias to surveillance and discrimination. Kenya's proposal addresses those concerns as well, but it also asks a broader economic question: who should own the infrastructure, talent, intellectual property, and investment opportunities created by AI?
The biggest winners may not be AI companies
The immediate beneficiaries of Kenya's strategy are unlikely to be AI companies themselves. Instead, the biggest winners could be the industries that make artificial intelligence possible.
The proposed policy calls for investment in domestic compute capacity, sovereign cloud infrastructure, secure data systems, digital connectivity, sustainable energy, and national AI testing capabilities. It argues that affordable access to computing resources should become a national priority rather than a commercial afterthought.
In doing so, it broadens the very definition of AI infrastructure. The conversation extends beyond software developers building models to encompass data centres, fibre networks, cloud providers, electricity systems, and high-performance computing facilities capable of training sophisticated algorithms.
This reflects a growing global consensus: the AI race is being won not only by those writing algorithms but by those controlling the infrastructure that powers them. For Kenya, whose digital economy has historically depended on imported technology infrastructure, the proposal signals an effort to capture more of the AI value chain locally.
The framework also represents a significant shift in industrial policy. Traditionally, the Kenyan government has allowed private markets to determine where technology investment flows. The proposed approach is more interventionist, using regulation, public procurement, research funding, and institutional coordination to strengthen domestic AI capabilities. If successful, it could benefit data-centre operators, cloud infrastructure providers, universities, chip researchers, and companies developing AI products for African languages and local markets.
Startups gain a government willing to pick a side
For years, Kenya's technology policy has focused primarily on creating an enabling environment for innovation. The AI proposal goes much further.
It commits the government to expanding research funding, commercialising locally developed technologies, establishing centres of excellence, improving intellectual property protection, and using public procurement to support home-grown innovation—provided that quality and value-for-money standards are met.
That commitment matters. Public procurement remains one of the country's largest technology markets. Redirecting even a fraction of government spending towards domestic AI companies could create opportunities that private venture capital has struggled to provide.
The proposal also acknowledges that Kenya's AI ambitions cannot rest solely on foreign technology platforms. It calls for deeper collaboration between universities, government, and industry, alongside greater investment in research and development, and support for commercialising innovations that too often fail to make the journey from laboratory to marketplace.
For local startups, the message is clear: the government now views AI companies not simply as technology businesses but as strategic national assets.
Universities move to the centre
One of the proposal's most significant yet easily overlooked features is the central role it assigns to universities. Rather than treating higher education merely as a supplier of talent, the policy positions universities as critical partners in building Kenya's AI ecosystem.
They are expected to develop skilled professionals, generate intellectual property, advance AI models for African languages, produce high-quality datasets, and reduce the country's dependence on imported technologies. This approach reflects a growing recognition that long-term AI competitiveness is built on research capacity.
Countries leading today's AI race, such as the US and China, invested heavily in universities and research institutions decades before large language models (LLMs) became commercially viable. Kenya appears intent on following a similar, albeit smaller, path. Under the proposal, universities would become engines of innovation—producing patents, datasets, testing facilities, and commercial spin-offs to support the domestic AI industry.
Stricter obligations for global technology firms
If the policy promises new opportunities for local companies, it also signals a more demanding operating environment for global technology firms such as OpenAI and Anthropic.
The draft applies not only to Kenyan businesses but also to foreign companies whose AI systems are used in Kenya or whose outputs have "direct and foreseeable effects" on people, businesses, or public interests in the country. It extends to cloud providers, model developers, data intermediaries, AI assurance firms, and technology suppliers whose products are deployed in Kenya, regardless of where those systems are developed or hosted.
Like the EU's AI Act and GDPR before it, the draft asserts authority over AI systems whose effects are felt within Kenya, regardless of where they originate. This marks a subtle but important departure from earlier technology regulation, which often focused on policing digital platforms after harm had occurred. It also builds on Kenya's existing Data Protection Act of 2019, which established the Office of the Data Protection Commissioner and introduced principles of consent, transparency, and accountability that the AI policy now extends to algorithmic systems.
Kenya instead proposes oversight spanning the entire AI lifecycle—from research and model development to deployment, monitoring, incident reporting, and eventual retirement—while assigning clear responsibilities to developers, deployers, operators, and users. Systems deemed to pose greater risks would face stricter requirements for auditing, explainability, and human oversight.
For companies such as OpenAI, Google, Microsoft, and Anthropic, many of the obligations will be familiar, reflecting regulatory approaches already taking shape in Europe. But for businesses that have treated Africa primarily as an expansion market with relatively light oversight, the message is different. Kenya is signalling that access to one of the continent's largest digital economies will increasingly depend on compliance with locally determined rules rather than voluntary commitments.
Banks, insurers, fintechs, and hospitals face new compliance burdens
The businesses most immediately affected may not be technology companies at all. Banks, fintechs, insurers, telcos, hospitals, and government agencies increasingly use AI systems developed by third parties. Under the proposed rules, they would also inherit responsibilities for how those systems are deployed.
The policy treats AI not merely as software purchased from vendors but as systems capable of influencing rights, opportunities, and access to essential services. Organisations using those systems therefore remain accountable for their outcomes.
For banks, that could mean greater scrutiny of automated credit decisions and fraud detection systems. For employers, it raises questions about AI-assisted recruitment and performance management. Healthcare providers deploying diagnostic tools could face higher expectations around oversight, documentation, and human review. Government agencies automating public services may be required to demonstrate that AI-assisted decisions remain transparent and subject to human supervision.
The new policy suggests that AI should augment human judgement rather than replace it.
"Humans shall retain meaningful control over systems that affect individual rights, safety, or access to essential services," the policy states, adding that high-risk systems should allow intervention, review, and clear allocation of responsibility.
That emphasis suggests compliance costs are likely to extend well beyond technology procurement. Organisations may need to document how algorithms reach decisions, establish mechanisms for human review, retain audit records, and ensure accountability when automated systems fail. For sectors already subject to heavy regulation, such as banking and insurance, AI governance could add another layer of operational oversight.