The era of governing artificial intelligence by aspiration has ended — and on this continent it ended first in Nairobi. Kenya's Artificial Intelligence Bill converts what was voluntary guidance into legal obligation, and in doing so sets the terms of AI governance in Africa for the decade ahead.
We have watched this pattern before. Kenya's Data Protection Act of 2019 followed the European precedent, and within a few years its logic had rippled through the region. Boards that had treated privacy as a compliance afterthought spent those years catching up at cost. AI governance is repeating that cycle — at considerably greater speed.
Governance, plainly defined, is the system of inventories, controls, independent audits and named accountability by which an organisation proves its AI does what it claims. The Bill demands three things of that system. One, a complete inventory of the AI in use — including the unsanctioned tools employees have already adopted. Two, independent audit: internal assurance no longer suffices where decisions touch hiring, lending or pricing. Three, named accountability — a person, not a committee, answerable for each system.
Nigeria, South Africa and Rwanda are drafting their own instruments, and the African Union has set a continental strategy in motion. For organisations operating across African markets, the practical counsel is simple: treat the Kenyan standard as a floor, not a ceiling. Those that do will convert regulation into advantage — proof of responsible AI is becoming a condition of the contracts, capital and partnerships that matter.
Read the full column at Business Daily Africa