CIPESA calls for stronger safeguards in Kenya’s AI and emerging technology rules
CIPESA has submitted recommendations on Kenya’s draft guidance notes for AI and emerging technologies. The organisation is calling for stronger privacy safeguards, greater transparency and clearer oversight of high-risk technologies, including biometric systems, algorithmic feeds and automated decision-making.
The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) has submitted comments on two draft guidance notes published by Kenya’s Office of the Data Protection Commissioner (ODPC). The documents cover artificial intelligence and emerging technologies and aim to guide organisations on compliance with Kenya’s Data Protection Act, 2019.
CIPESA said the guidance is a step towards more responsible use of these technologies but identified several areas that it believes require further clarification and stronger safeguards.
On the AI guidance, CIPESA called for Kenya’s rules to be aligned with regional frameworks, including the African Union Data Policy Framework, the AU Continental AI Strategy and the Malabo Convention. It also warned that requirements for assessing cross-border data transfers could lead to broad data localisation if not aligned with existing regional rules.
The organisation also highlighted gaps concerning children and persons with disabilities. It recommended that the guidance reference Kenya’s constitutional protections for persons with disabilities, as well as existing rules on children’s data and the Children Act, 2022.
Biometric technologies were another area of concern. Referring to a 2025 High Court ruling involving Worldcoin, CIPESA argued that the draft should require data protection impact assessments and registration before biometric data processing begins. It also called for stronger safeguards covering the analysis of stored biometric data.
CIPESA further recommended requirements for identifying synthetic media, including watermarking or equivalent disclosures when such content is used in decisions affecting individuals. It argued that regulation should also cover algorithmic feeds and content curation systems, rather than focusing only on enterprise technologies.
The organisation also called for political communication, voter micro-targeting and synthetic political media to be included among high-risk uses, particularly ahead of Kenya’s 2027 general election.
CIPESA’s recommendations extend beyond users of technology. It called for data protection rights for workers involved in data annotation, content moderation and other activities supporting the development of AI systems. It also asked for clearer division of registration responsibilities between the ODPC and the proposed AI Commissioner.
For public-sector systems, including digital identity, social protection and tax platforms, CIPESA recommended mandatory impact assessments, equity assessments, public disclosure of methodologies and meaningful human review.
On emerging technologies, CIPESA called for tighter limits on data localisation requirements for cloud computing. It also recommended prohibiting real-time remote biometric identification and indiscriminate mass surveillance in public spaces, alongside safeguards against biometric categorisation and emotion recognition in schools and workplaces.
The organisation proposed that summaries of impact assessments for high-risk technologies be published before deployment. It also called for human reviewers to have genuine authority to overturn or modify automated decisions in areas such as employment, credit, healthcare, insurance, social protection, immigration and policing.
CIPESA said the submissions build on its previous work on Kenya’s AI policy and digital democracy. The organisation’s full submissions address both the draft AI Guidance Note and the draft Emerging Technologies Guidance Note.
