Kenya’s growing use of artificial intelligence is raising urgent questions: Who controls the technology and its data, and who is accountable when automated systems affect people’s lives?
These questions came to the fore during a recent parliamentary webinar on artificial intelligence, where lawmakers, government officials and digital rights experts examined how Kenya should govern the rapidly developing technology.
John Kiarie, chair of the National Assembly’s Communication, Information and Innovation Committee, posed a central question: “Who is coding the code?”
He said Africa must ask who defines the problems AI is designed to solve, whose knowledge and data train the systems, who controls the infrastructure and who benefits.
Kiarie also raised concerns about cross-border data sharing as countries become increasingly connected through digital systems.
For Kiarie, the issue is not simply whether Africa adopts AI, but whether it retains control over its data, knowledge, infrastructure and digital future.
He warned that Africa risks becoming part of what he called “digital plantations” if it supplies data, labour and knowledge while others control the technology and its economic value.
When “the computer has said so” is not enough
Kiarie also questioned the growing reliance on automated decisions.
He referred to the familiar response, “computer imesema” — “the computer has said so” — and argued that this cannot end a citizen’s interaction with an institution.
“AI is increasingly capable of generating content, ranking people, and making recommendations,” he said, raising new questions about responsibility when decisions affect citizens.
He cited risks including denial of loans or employment, deepfakes, voice impersonation and automated decisions that could undermine people’s rights.
Kiarie said human beings must remain able to question decisions made by machines.
He also called for safeguards around traditional and community knowledge, including informed consent, attribution and fair sharing of benefits where such knowledge is used commercially.
Permission to record information, he argued, should not automatically amount to permission for every future use of that information.
AI systems must be monitored
Jessy Maruti, chief executive officer of Kenya’s Information and Communications Technology Authority (ICTA), said governance must continue throughout an AI system’s lifecycle, not end when it is deployed.
Institutions, he said, must monitor threats, incidents, complaints and unexpected harm, and be ready to reassess or retire systems where necessary.
Maruti stressed the need for auditable evidence.
“A policy statement saying that an AI system is safe is not enough! Institutions should be able to demonstrate that the required safeguards are actually working.”
He also highlighted cybersecurity risks across the AI lifecycle, including unauthorised access, data leaks, compromised components, unsafe code and changing system behaviour.
The safeguards he outlined included access controls, encryption, testing, logging, incident response and the ability to revert to manual processes when necessary.
Who should be responsible?
Maruti said AI governance requires clearly defined responsibilities across government.
Parliament, he said, should establish policy, legal limits and accountability mechanisms.
The ICT Authority can set standards and provide shared platforms and assurance mechanisms, while sector regulators establish requirements for specific fields.
The institution deploying an AI system should remain accountable for its outcomes, data, procurement, monitoring and eventual retirement.
Independent oversight bodies should be able to examine legality, rights impacts and whether safeguards are working.
He argued that coordination must produce decisions and evidence, not more committees without authority.
A risk-based approach
Maruti proposed a risk-based approach to AI governance.
Low-risk systems, such as productivity tools, would require basic safeguards such as transparency and security.
Higher-risk systems would require stronger controls, including impact assessments, human review and ongoing monitoring.
For high-risk systems affecting rights, public benefits, employment, law enforcement or safety, he proposed independent review, external validation, public registers, meaningful appeals and regular audits.
He said certain uses may pose unacceptable risks and should be prohibited.
The level of oversight, he said, should reflect the likelihood and severity of harm, the number and vulnerability of people affected, and whether the consequences can be reversed.
Human rights cannot be left behind
Dr Grace Githaiga of KICTANet said the AI debate must remain firmly grounded in human rights.
She highlighted privacy, equality, human dignity, freedom of expression and access to information as key concerns.
Githaiga said AI should not be viewed as a choice between innovation and human rights.
Instead, she argued, protecting rights and building public confidence are necessary for sustainable innovation.
She also pointed to the implications of AI for freedom of expression and access to information, particularly as Kenya approaches another election period.
“AI can make information more accessible and support translation, but it can also influence what people see and amplify misinformation,” she said.
Public institutions using AI must continue to give citizens access to authoritative information and remain accountable for the systems they deploy.
Policy is not the same as law
Githaiga distinguished between government policy and legislation.
Policy, she explained, sets national direction, priorities and institutional arrangements.
Legislation creates enforceable obligations, rights, duties, regulatory powers, sanctions and remedies.
She said Parliament can identify genuine gaps in the existing legal framework and create enforceable safeguards where necessary.
However, she cautioned that Kenya already has many laws and that the more immediate challenge may be enforcing existing provisions.
Parliament, she said, must also scrutinise government procurement and deployment of AI, fund regulatory institutions and ensure meaningful public participation.
Language and inclusion
The discussion also examined whether AI systems reflect Africa’s linguistic and cultural diversity.
Githaiga said human-centred AI must protect dignity, freedom of expression, cultural and linguistic diversity, accessibility and inclusion.
The concern was illustrated during the webinar through a demonstration of an AI-generated message in Kiswahili.
The demonstration raised broader questions about how African languages are represented in AI systems and whether people can participate equally when technology does not accommodate their language or circumstances.
The speakers also stressed the need to include persons with disabilities and other groups often excluded when digital systems are designed without their participation.
Githaiga put the principle simply:
“Technology serves people, people do not serve technology.”
Parliament’s role
The discussion ultimately returned to Parliament’s role.
Kiarie said Parliament’s responsibilities extend beyond legislation to oversight, budgeting, public participation and ensuring Kenya develops the infrastructure and skills needed to participate meaningfully in the AI economy.
He proposed a “Committee of the Future” to help Parliament anticipate emerging technologies, commission independent evidence and connect public debate to legislation and budgets.
Parliament could also use AI for Hansard, comparing Bills, translating material and organising public submissions, provided safeguards protect confidentiality, traceability and human verification.
The two-hour webinar underscored a shared concern: AI governance must keep pace with technology while protecting citizens. Maruti emphasised continuous oversight, Githaiga placed human rights at the centre, and Kiarie returned to the question of who controls the systems.
Who is coding the code, and who will bell the cat when something goes wrong?
By Nelly Moraa Nyangorora













