Kenya targets OpenAI, Meta in foreign AI models control plan
This story has significance for readers across Kenya and beyond.
Kenya seeks to regulate artificial intelligence (AI) models used in the country or affecting residents, even when the companies that own them do not have local operations.
A new proposal by the ICT Ministry extends the government’s control to overseas tech firms such as ChatGPT maker OpenAI and Facebook’s parent Meta, whose AI systems are increasingly being adopted by Kenyan businesses, government offices and private users.
It gives the government powers to hold tech firms accountable if their products, services, or data systems are accessed or used in Kenya, regardless of where the company is headquartered.
The regulatory model, technically referred to as extraterritorial jurisdiction, is similar to that adopted by the European Union (EU). The regional bloc routinely fines tech giants whose products infringe on Europeans' privacy and safety.
“This policy applies to any entity outside Kenya that provides AI or other emerging technologies systems or services whose outputs are used within Kenya, or which have direct and foreseeable effects on individuals, rights, or public interests in Kenya,” reads the draft AI policy.
The guidelines cover software vendors, cloud service providers, compute providers, AI model developers, data intermediaries, data annotation providers and public-sector technology suppliers used locally.
“This policy adopts an effects-based jurisdictional approach, consistent with international best practice in data protection and consumer protection law,” says the policy.
Such an approach allows a government, regulator, or court to exercise legal authority over companies or individuals located outside its physical borders, as long as their action causes direct consequences within the regulating country's territory.
This means international AI companies whose products are used in Kenya – including OpenAI’s GPT models, Anthropic’s Claude and Meta’s Llama – could be required to comply with Kenyan AI rules even if they have no physical presence in the country.
Google, which owns the Gemini AI model, and Microsoft, the developer of the MAI series of models, already have Kenyan offices.
Depending on the type of AI system, Kenya will require tech companies to conduct risk assessments of their AI products, ensure transparency for users – including explicit labelling of AI-generated content – implement human oversight measures, and meet cybersecurity standards.
The government says it will classify all AI systems according to the level of risk they pose, maintain a central register of high-risk AI systems requiring oversight, and periodically review risk classifications as technology evolves.
Kenya’s AI policy does not spell out which systems are considered ‘high risk.’ But it borrows from the European AI Act, which classifies systems used in critical infrastructure, education, healthcare, law enforcement, border management or elections as ‘high-risk’.
Such systems face stricter rules.
Kenya’s draft policy also requires AI system vendors to disclose information on data sources, model limitations, cybersecurity measures, human oversight arrangements, auditability and redress mechanisms.
It further seeks to compel international companies bidding for government AI contracts to forge partnerships with local tech firms.
Meanwhile, public institutions would be required to conduct AI impact assessments before deploying high-risk systems in areas such as healthcare, education, taxation, policing, justice, employment and public services.
The government also plans to maintain a public register of AI systems deployed across the public sector, except where national security considerations apply.
The policy further introduces labour protections for AI content moderators and data annotators employed by outsourcing firms serving international tech companies.
It proposes minimum standards for written contracts, access to mental health support, and a fair pay framework benchmarked against international rates.
“Support the development and integration of fair and transparent pay standards for AI and other emerging technologies value chain workforce,” reads the draft policy.
This follows years of complaints by Kenyan content moderators working on projects for companies such as OpenAI and Meta over psychological trauma and low pay.
Kenya has not yet specified the regulatory obligations or penalties that will apply to the tech companies.
The EU enforces compliance with its AI and data protection laws by levying huge fines calculated as a percentage of a company’s total worldwide annual turnover, which can reach up to 20 percent.
In some cases, non-EU companies must designate a formal physical or legal representative inside an EU member state to act as a point of contact for regulatory authorities.
Reporting originally appeared via Business Daily. Read the full source for additional context.