How East African Countries Are Regulating AI, and Where the Region Still Has No Rules
Banks across the region are already using AI to approve loans. Hospitals are piloting AI-assisted diagnostics. Retailers are forecasting demand with machine learning models, developments we've tracked across How AI Is Transforming Banking Across East Africa and elsewhere on this blog. Almost none of it currently operates under a binding, AI-specific law anywhere in East Africa. Every country in the region is somewhere on a spectrum between "actively drafting rules" and "hasn't started," and the gap between Kenya's regulatory ambition and Uganda's still-forming policy is wide enough that a company compliant in one market may have no equivalent obligations at all in the next.
Here's where each country actually stands, and where the real gaps sit.
Kenya: Furthest Along, Still Not Binding
Kenya has moved faster than anywhere else in the region, but even its most advanced instrument isn't law yet. The country launched its National AI Strategy 2025-2030 on 27 March 2025, a non-binding blueprint built around three pillars: AI infrastructure, data governance, and research and commercialisation. That was followed by a Draft AI and Other Emerging Technologies Policy, published for public comment through 4 August 2026, which notably proposes extraterritorial scope, meaning it could apply to foreign AI companies serving Kenyan users even without a local presence.
Kenya has also gone further than any of its neighbours by tabling an actual AI Bill in 2026, which would create a standalone statutory framework built around a new Artificial Intelligence Commissioner, an independent office tasked with risk assessments, policy development, and public AI literacy. Notably, legal researchers at Strathmore University's CIPIT have flagged that the Bill arrived before the underlying National AI Policy was even finalised, an unusual sequencing that raises real questions about whether the legislative foundation is as settled as the bill's ambition suggests. Until any of this passes, Kenya's only enforceable AI-relevant rules remain older, general-purpose laws: the Data Protection Act 2019, which restricts fully automated decisions with legal or significant effects on individuals, and the Computer Misuse and Cybercrimes Act 2018.
Rwanda: First Mover, Still Governing Through Soft Law
Rwanda holds a genuine claim to being Africa's AI policy pioneer. Its Cabinet approved the continent's first comprehensive National AI Policy in April 2023, organised around six pillars covering skills, research, infrastructure, public sector adoption, private sector growth, and ethical governance. Rwanda backed that policy with real institutional follow-through, establishing a Responsible AI Office within its Ministry of ICT and Innovation, and cementing its position by hosting the 2025 Kigali Global AI Summit, where 49 African countries signed the Africa Declaration on Artificial Intelligence.
But like Kenya's strategy, Rwanda's National AI Policy is explicitly a guidance document, not binding law. The country's actual enforceable "hard law" for anything AI touches is Law No. 058/2021 on the Protection of Personal Data and Privacy, which governs the personal data AI systems inevitably rely on, alongside Rwanda's National Cyber Security Authority. Rwanda leads the region on vision and coordination. It hasn't yet converted that lead into dedicated AI legislation any more than Kenya has.
Uganda: Still Deciding Which Path to Take
Uganda sits meaningfully behind both. As of mid-2025, the Ministry of ICT and National Guidance had only just begun drafting a national AI policy, with officials still weighing whether to pursue a formal standalone AI policy or a lighter, sector-by-sector approach, a decision the ministry indicated it hoped to make by the end of 2025. A dedicated Ugandan AI law is now projected for late 2025 or 2026, expected to eventually include a national AI governance authority, risk-based classification for AI systems, and mandatory human oversight in sectors like healthcare and finance, but none of that exists in enforceable form today. In the meantime, Uganda's National Information Technology Authority (NITA-U) is building internal AI assurance and testing capacity ahead of whatever framework eventually lands, while AI-powered facial recognition and surveillance tools are already being deployed by security agencies well ahead of any governing rulebook.
Tanzania: Sector Guidance Before a National Framework
Tanzania's approach has so far been the most fragmented of the four. Rather than starting with an overarching national policy, the government has moved sector by sector: the Ministry of Education, Science and Technology published National Guidelines for Artificial Intelligence in Education in January 2025, while a broader National AI Strategy Framework followed from the Ministry of Communication and Information Technology in July 2025, informed by a UNESCO AI readiness assessment involving more than 240 stakeholders across Dar es Salaam, Zanzibar, and Dodoma. More recently, Tanzanian officials have signalled plans for a dedicated institution to coordinate AI research, policy, and applications nationally, though its structure, funding, and timeline remain undisclosed. Tanzania currently has no binding, cross-sector AI law at all, only a strategy framework, one sector-specific set of guidelines, and a proposed institution that doesn't yet exist.
The Regional Layer That Doesn't Exist Yet
Zoom out to the continental level and the picture becomes clearer, and more concerning for anyone trying to operate across borders. The African Union adopted its Continental AI Strategy in July 2024, followed by the Africa Declaration on AI signed in Kigali in April 2025. Both are important norm-setting exercises, and both are explicitly non-binding, designed to encourage "unified national approaches" rather than impose one. Notably, one of the AU's own briefings on the strategy pointed out that Africa's AI compute capacity accounts for just 1% of the global total, a reminder that governance is only one part of a much bigger infrastructure gap, one we explored in Why Investors Are Betting on East Africa's Invisible Technology.
Crucially, there is no East African Community-level AI framework at all right now, nothing equivalent to the EU AI Act operating regionally. Each of the four countries above is regulating independently, at a different pace, with no coordination mechanism forcing alignment. For a startup or investor operating across Kenya, Uganda, Tanzania, and Rwanda simultaneously, that means compliance is a moving target that looks different in every market, a dynamic that echoes what we found comparing tax regimes in What East Africa's Digital Services Tax Actually Means for Startups.
What This Actually Means Right Now
For founders and investors, the practical takeaway isn't "wait for clarity." It's that the region's only genuinely enforceable AI-adjacent rules today are the older, general-purpose laws already on the books, data protection acts, cybercrime statutes, and consumer protection legislation, not anything AI-specific. Kenya's proposed extraterritorial scope and AI Commissioner, Uganda's promised risk-based classification system, and Tanzania's yet-to-be-formed regulatory institution are all still on paper. Companies building AI products for East African users right now are, in practice, operating in the gap between where these governments say they're headed and where the law actually sits today, and the startups that treat that gap as a reason to build responsibly early, rather than a reason to wait, are the ones likely to be best positioned once each country's rules finally take effect.

Comments