AI regulatory compliance in Kenya is often described as an emerging discipline. The more useful framing is that a defensible compliance posture can be built today, using laws, standards, and regulatory guidance that are already in force. Organisations across banking, fintech, SACCOs, insurance, manufacturing, NGOs, and the public sector are increasingly being asked – by regulators, customers, donors, and counterparties – to demonstrate how they comply with the current AI regulatory landscape. The good news is that the building blocks already exist.
This article maps the current state of AI regulatory compliance in Kenya. It covers the Kenya Standard KS 3007:2025, the Data Protection Act, 2019 and the supervision of the Office of the Data Protection Commissioner, the sectoral regulatory overlay from the Central Bank of Kenya, the Capital Markets Authority, the Insurance Regulatory Authority, and the SACCO Societies Regulatory Authority, the policy direction set out in the National AI Strategy 2025-2030, the extraterritorial reach of the EU AI Act for organisations serving European customers, and the role of international frameworks – ISO/IEC 42001 and the NIST AI Risk Management Framework – in anchoring compliance.
The article focuses on what is in force today. As Kenya’s AI regulatory environment evolves over the coming years, organisations that build on these existing anchors will be positioned to absorb new requirements without restructuring their compliance posture.
The Current Shape of AI Regulatory Compliance in Kenya
AI regulatory compliance in Kenya rests on five anchors that are already binding or actively applied. The first is the Data Protection Act, 2019, which directly governs automated decision-making affecting individuals. The second is KEBS KS 3007:2025, the published Kenyan Code of Practice for AI applications. The third is the sectoral guidance from financial services regulators, which applies existing prudential, conduct, and consumer protection rules to AI-enabled processes. The fourth is the National AI Strategy 2025-2030, which establishes policy direction. The fifth is the broader international framework – the EU AI Act for those with European exposure, and ISO/IEC 42001 and NIST AI RMF for those seeking globally credible governance structures.
Together, these anchors give organisations a clear basis for AI regulatory compliance in Kenya. They do not replicate the comprehensive AI legislation seen in some other jurisdictions, but they do create a workable compliance perimeter that boards, regulators, and external assessors can recognise.
KEBS KS 3007:2025: The Published Standard for AI Practice
The Kenya Bureau of Standards has published KS 3007:2025 as a Code of Practice for AI applications. It is the first dedicated Kenyan standard for AI, and it serves as a national reference point for organisations seeking to demonstrate responsible practice. The standard addresses governance, risk management, transparency, fairness, security, ethics, and incident handling. While voluntary, alignment with KS 3007:2025 supports AI regulatory compliance in Kenya by giving organisations a recognised local benchmark.
Many organisations are adopting KS 3007:2025 as the explicit reference in their AI policies and governance documents. The advantage is local legitimacy: when a board, a customer, or a counterparty asks what standard the organisation is following, KS 3007:2025 is a credible Kenyan answer. The standard is also broadly compatible with ISO/IEC 42001 and the NIST AI Risk Management Framework, so adopting it does not foreclose international alignment.
The Data Protection Act, 2019 and Automated Decision-Making
The Data Protection Act, 2019 is the single most consequential law for AI regulatory compliance in Kenya today. Section 35 of the Act restricts decisions made solely on automated processing – including profiling – where they produce legal effects or similarly significant effects on a data subject. Where such automated decisions are made, the Act requires that the data subject is informed, has the right to express a view, has the right to contest the decision, and has the right to human intervention.
Most consequential AI use cases fall within this provision. A credit scoring model approving or declining a loan, a fraud detection system blocking a transaction, an insurance algorithm denying a claim, an employment tool screening a job application, or a public service eligibility tool determining a benefit all carry automated decision-making implications. AI regulatory compliance in Kenya, in practice, starts with mapping these use cases against Section 35 and building the required human oversight, transparency, and contestability mechanisms.
The Office of the Data Protection Commissioner (ODPC) supervises compliance with the Act and has issued guidance on Data Protection Impact Assessments. Most high-risk AI processing requires a DPIA, which becomes a key compliance artefact that boards, regulators, and external assessors can review. The ODPC also has powers to investigate, issue enforcement notices, and impose administrative penalties for breaches, which makes early engagement with Data Protection Act requirements a practical priority.
Sectoral Regulatory Overlay
Kenya does not yet have AI-specific sectoral regulations, but sector regulators have signalled – and in some cases stated directly – that AI-enabled processes fall within existing prudential, conduct, and consumer protection rules. AI regulatory compliance in Kenya therefore includes layering AI controls onto existing sectoral compliance obligations.
Central Bank of Kenya
The Central Bank of Kenya supervises banks, microfinance banks, foreign exchange bureaux, payment service providers, and digital credit providers. CBK’s existing ICT risk management guidelines, outsourcing guidelines, consumer protection rules, and AML/CFT obligations apply directly to AI-enabled processes. Banks deploying AI in credit decisioning, fraud monitoring, customer onboarding, or transaction surveillance must therefore demonstrate that the AI systems meet existing prudential expectations – including model documentation, vendor due diligence, change management, and ongoing monitoring.
Capital Markets Authority
The Capital Markets Authority supervises securities markets, fund managers, investment advisers, and stockbrokers. AI applications in algorithmic trading, robo-advisory, portfolio risk modelling, and market surveillance fall within CMA’s existing market conduct and fitness rules. Firms using these tools must address explainability and audit trail requirements that AI complicates but does not eliminate.
Insurance Regulatory Authority
The Insurance Regulatory Authority supervises insurers, reinsurers, and brokers. AI in underwriting, pricing, claims processing, and fraud detection sits within IRA’s existing conduct and consumer protection framework. The Authority’s requirements on fair treatment of customers and complaint handling apply equally to AI-driven decisions.
SACCO Societies Regulatory Authority
The SACCO Societies Regulatory Authority supervises deposit-taking SACCOs. AI use cases in member analytics, credit decisioning, and operational efficiency must align with existing prudential and member protection rules. The growing use of fintech partnerships by SACCOs introduces additional vendor AI considerations that fall within SASRA’s outsourcing expectations.
Media Council of Kenya and Sector-Specific Bodies
Outside financial services, the Media Council of Kenya has issued guidance on the use of AI in journalism. The Communications Authority oversees telecommunications operators using AI in network management, content moderation, and customer service. The Public Service Commission and ministries setting digital service standards influence AI use in the public sector. Each sector-specific body adds an additional layer to AI regulatory compliance in Kenya.
The National AI Strategy 2025-2030: Policy Direction
The National AI Strategy 2025-2030 sets Kenya’s policy direction for AI adoption. It promotes responsible AI development, ethics, capacity building, and AI infrastructure investment. While the Strategy itself is not a binding legal instrument, it shapes the priorities of government, regulators, and public sector procurement. Organisations whose AI governance language and risk approach align with the Strategy’s responsible AI principles position themselves favourably for public sector partnerships and for adapting to future regulatory developments.
The Extraterritorial Reach of the EU AI Act
For Kenyan organisations exporting goods or services into the European Union, providing AI-enabled services to European customers, or partnering with European businesses, the EU AI Act has direct relevance. The Act applies extraterritorially to providers placing AI systems on the EU market, regardless of where the provider is established, and to deployers using AI systems whose output is used in the EU. Kenyan exporters in horticulture and manufacturing, business process outsourcers serving European clients, fintechs with European customers, and Kenyan AI vendors selling into Europe all need to consider EU AI Act obligations alongside AI regulatory compliance in Kenya.
The EU AI Act uses a four-tier risk model: unacceptable, high, limited, and minimal risk. Most consequential business AI – credit scoring, recruitment, biometric identification, critical infrastructure – falls in the high-risk category and carries substantive obligations on risk management, data governance, transparency, human oversight, and post-market monitoring. The penalties for non-compliance are significant and applicable to non-EU providers.
International Frameworks That Anchor AI Regulatory Compliance in Kenya
Two international frameworks have become the practical foundation on which AI regulatory compliance in Kenya rests. ISO/IEC 42001:2023 is the first international standard for AI management systems. It mirrors the structure of ISO 27001 for information security and is designed for organisations to implement, audit internally, and ultimately certify. The NIST AI Risk Management Framework, published by the United States National Institute of Standards and Technology, provides a flexible, risk-based approach to AI governance, mapping, measurement, and management.
Adopting these frameworks alongside KEBS KS 3007:2025 gives organisations a defensible position. ISO/IEC 42001 provides the management system structure. NIST AI RMF provides the risk management depth. KS 3007:2025 anchors the framework locally. The Data Protection Act and sectoral guidance provide the binding legal obligations. Together, this stack supports AI regulatory compliance in Kenya in a way that is recognisable to international counterparties, defensible to local regulators, and operationally workable for the business.
An AI Regulatory Compliance Readiness Roadmap
For most organisations, a structured readiness exercise for AI regulatory compliance in Kenya can be completed in three months. The first month focuses on inventory and mapping: identifying the AI footprint, mapping use cases against Section 35 of the Data Protection Act, identifying sectoral overlay, and noting EU AI Act exposure where relevant. The second month focuses on gap assessment and remediation planning: comparing the current state against KEBS KS 3007:2025, ISO/IEC 42001, and applicable sectoral expectations. The third month focuses on implementation: closing high-priority gaps, preparing DPIAs for high-risk use cases, and establishing ongoing compliance monitoring.
The roadmap follows the FNJ Prevent, Detect, Respond compliance model. Prevent: build the policies, training, and approval gates that stop non-compliant AI from being deployed in the first place. Detect: monitor live AI systems for drift, bias, and compliance breaches. Respond: have a defined process for handling incidents, ODPC notifications, customer complaints, and corrective action.
How FNJ & Associates Supports AI Regulatory Compliance in Kenya
FNJ & Associates provides AI regulatory compliance advisory across banking, fintech, SACCOs, insurance, manufacturing, NGOs, and the public sector in Kenya and East Africa. Our engagements cover regulatory mapping against the Data Protection Act, 2019, KEBS KS 3007:2025, sectoral guidance, and the EU AI Act where relevant. We design compliance frameworks anchored to ISO/IEC 42001 and the NIST AI Risk Management Framework, and we prepare Data Protection Impact Assessments for high-risk AI use cases.
We also help operationalise AI regulatory compliance in Kenya through Trigarc Compliance by FNJ & Associates – tracking regulatory obligations, AI use cases, DPIA status, ODPC engagement, incident management, and board reporting on a single platform. This keeps compliance live and visible to management on an ongoing basis, rather than reactive at the point of inspection or audit.
Frequently Asked Questions
What is the most important law for AI regulatory compliance in Kenya today?
The Data Protection Act, 2019 is currently the most consequential law because it directly governs automated decision-making affecting individuals. Section 35 restricts decisions made solely by automated means where they produce significant effects on data subjects, requiring human intervention, transparency, and contestability. Most high-risk AI use cases also require a Data Protection Impact Assessment, which the Office of the Data Protection Commissioner supervises.
Is KEBS KS 3007:2025 mandatory?
KS 3007:2025 is a voluntary Kenyan standard published by the Kenya Bureau of Standards as a Code of Practice for AI applications. While not legally binding, it has become the de facto national reference point for responsible AI practice in Kenya. Many organisations adopt it explicitly in their AI policies because it provides a recognised local benchmark for regulators, customers, donors, and counterparties.
Does AI regulatory compliance in Kenya require a separate compliance framework, or can it be integrated with existing compliance functions?
It should be integrated with the existing compliance function rather than run separately. AI regulatory compliance in Kenya draws on data protection compliance, sectoral compliance, vendor management, ICT risk management, and consumer protection – all of which most organisations already have. The AI dimension adds specific controls (risk tiering, model documentation, bias testing) on top of these existing functions, rather than replacing them.
Does the EU AI Act apply to Kenyan organisations?
Yes, where there is European exposure. The EU AI Act applies extraterritorially to providers placing AI systems on the EU market and to organisations whose AI outputs are used in the EU. Kenyan exporters serving European customers, fintechs with European users, business process outsourcers serving European clients, and Kenyan AI vendors selling into Europe should assess their EU AI Act obligations alongside their AI regulatory compliance in Kenya.
Can FNJ & Associates help us achieve AI regulatory compliance in Kenya?
Yes. FNJ & Associates provides AI regulatory compliance advisory across all major sectors in Kenya and East Africa. We map your AI footprint against the Data Protection Act, KEBS KS 3007:2025, sectoral guidance, and the EU AI Act where applicable. We design compliance frameworks anchored to ISO/IEC 42001 and the NIST AI RMF, prepare DPIAs, and operationalise compliance through Trigarc Compliance. Contact us via fnjassociates.co.ke to schedule a consultation.
| Navigate AI Regulatory Compliance in Kenya FNJ & Associates helps organisations across Kenya understand and implement the requirements of the Data Protection Act, 2019, KEBS KS 3007:2025, sectoral regulatory guidance, and the extraterritorial reach of the EU AI Act. Our compliance advisory covers regulatory mapping, gap assessment, DPIA preparation, and operationalisation through Trigarc Compliance. Visit fnjassociates.co.ke to schedule a consultation with our AI compliance advisory team. |
| About FNJ & Associates FNJ & Associates is a professional services firm offering audit and assurance, tax advisory, compliance, forensic audit, ERP implementation, and corporate training services across Kenya and East Africa. Our Trigarc Compliance platform helps organisations automate regulatory compliance tracking and reporting. Visit us at fnjassociates.co.ke to learn more. |

