Artificial Intelligence Bill, 2026, high-risk system obligations
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Proposed: draft date not recorded.
An AI risk obligations rule binding public and private bodies.
As of 5 September 2026.
What it requires
- This measure is a bill and binds nobody yet; what follows is what it would require if it is enacted in this form.
- Conduct a risk assessment and a human-rights impact assessment before deploying a high-risk system, and maintain human oversight of it.
- Keep records of data inputs, training datasets, outputs and performance metrics for at least five years.
- Obtain explicit consent from a person, or their legal representative, before generating or manipulating their image, voice or likeness, and label the output as AI-generated.
Who checks it
Audit expectation
continuous
Who audits it
Self, Regulator
Where the report goes
Kept
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
This measure is a Senate bill and binds nobody yet. As drafted, a provider or deployer of a high-risk system would have to conduct a risk assessment and a human-rights impact assessment before deployment, ensure transparency, traceability and explainability of the system's decision-making, keep records of training data and performance for at least five years, and obtain explicit consent before generating or manipulating a person's image, voice or likeness.
The Artificial Intelligence Commissioner would maintain a public register of high-risk systems, including those used by county governments.
When LexLint raises it
high_risk_decisionsprocesses_voicegenerates_content
Read the law
official Bill text, Kenya Gazette Supplement, Kenya Law (new.kenyalaw.org)