Kenya's central bank has put a draft AI guidance note out for public comment that would give customers a right to human review of adverse AI decisions and require an annual AI deployment register to be filed with the regulator

CBK Drafts AI Rulebook for Kenyan Banks. The Leveraged Years regulation briefing card.

It binds nobody. This is a draft out for public comment, and the thing to read it for is its verbs rather than its duties. Agentic AI is written in shall throughout. Generative AI, immediately before it, is written in should.

The short version

Bottom line: A draft out for public comment. It binds nobody. CBK invited comments to the address in its Public Notice by 7 November 2026, and the draft fixes no date on which it would take effect.

Who this affects: Boards and senior management, chief risk officers, model validation and model risk teams, data protection officers, internal audit and market conduct functions at Kenyan banks, microfinance banks, credit reference bureaus, money remittance providers and non-deposit-taking credit providers, plus their AI vendors.

Issue date: Two dates sit on the same package. The draft's own cover reads AUGUST 2026. The operative act, its issuance for public participation, is the Public Notice closing CENTRAL BANK OF KENYA / SEPTEMBER 10, 2026. Comments close 7 November 2026.

What changed: Nothing binding changed. CBK put a dedicated AI guidance note into public participation for the first time as part of a wider review of its Prudential Guidelines, Risk Management Guidelines, Guidance Notes and the D-SIBs Framework.

Analysis: The consumer-facing provisions at 4.15 are the ones drafted hardest. So is the whole of the agentic AI section. Model risk management, by contrast, is drafted entirely in should.

Primary sources: CBK Public Notice inviting comments, 10 September 2026 · Guidance_Notes.zip, containing the Draft Guidance Note on Artificial Intelligence

Instrument (EN)
Draft Guidance Note on Artificial Intelligence in the Banking Sector
Authority
Central Bank of Kenya, Bank Supervision Department
Jurisdiction
Kenya
Status
Draft, issued for public participation. Not made, not in force
Bindingness
Binds nobody. Paragraph 2.2 states the draft would set minimum expectations and would not supersede existing legislation, regulations and guidelines
Issue date / next deadline
Cover date AUGUST 2026; issued for public participation 10 September 2026. Comments close 7 November 2026
Legal basis
Stated at paragraph 1.3 as Section 57(1) of the Central Bank of Kenya Act, Section 33(4) of the Banking Act and Section 48(2A) of the Microfinance Act
Document
One of three drafts inside Guidance_Notes.zip, alongside drafts on Cybersecurity and on Third-Party Technology Service Providers
Primary source
https://www.centralbank.go.ke/wp-content/uploads/2026/09/Public-Notice-Invitation-for-Comments-from-the-Public-on-the-Draft-Revised-Prudential-Guidelines-Risk-Management-Guidelines-Guidance-Notes-and-the-Domestic-Systemically-Important-Banks-.pdf

The consumer provisions are the hardest-drafted part of the draft

This is a draft out for comment and it creates no duty on any institution today. Read on that footing, paragraph 4.15.2 is the clause with the most force in it. It opens: "Customers must have the right to request and obtain human intervention in the review of significant, adverse decisions made by AI systems, to challenge the decision, and to provide supporting data."

The draft then sets out what that review would have to look like if the note were made. The reviewer would need appropriate authority, training and competence. The reviewer would need access to all data points used by the AI and, in the draft's own qualifier, "the logic behind the decision, to the extent possible". Institutions would have to establish and disclose expected timeframes for resolution, and after the review communicate the outcome with the reasoning behind the human reviewer's decision.

Critical decision is a defined term at 1.4.8 of the draft, and the definition is where the scope actually sits: an AI-driven outcome with a significant legal, financial or similarly substantive effect on a customer, including but not limited to credit denial, fraud flagging, account freezing and pricing adjustments. Fraud flagging and account freezing inside that list would reach machinery that an institution may not think of as a customer-facing decision at all.

Paragraph 4.15.1 carries the disclosure side. Among its limbs, the draft would treat each update of an AI system as a latest version requiring customer notification, and would have institutions collect customer consent to accept the risks associated with AI use before providing the service.

The verbs are not uniform, and the split is worth a comment letter

Nothing here is in force, so no verb in the draft obliges anyone yet. The interesting fact is that the drafters did not pick one verb and stay with it. Across the note, should appears 76 times, shall 44 times and must 30 times.

The split is visible at section level. Paragraph 4.10 of the draft, on generative AI, is written entirely in should: under the draft, institutions should ensure their AI strategies and policies are updated, should ensure material decisions are not based solely on unverified outputs generated by AI systems, and should establish baseline metrics for factual consistency. There is no shall in it.

Paragraph 4.11, on agentic AI, immediately after, is written entirely in shall. Under the draft, an agentic AI system capable of independently initiating actions, interacting with external systems, executing transactions or materially affecting the institution's operations would be classified as high-risk: the text reads that such a system "shall be classified as a high-risk AI system and shall be subject to enhanced governance and independent review". If the note were made, institutions would not be able to deploy or use agentic AI systems unless they had established appropriate governance, risk management and control measures commensurate with the nature, scale and complexity of the system. Human oversight, predefined authority limits, complete audit logs of material actions and decisions, and continuous monitoring would all sit under shall in the same paragraph.

Paragraph 4.8 of the draft, on model risk management, runs the other way. Under that unmade text, independent validation, periodic review, bias and fairness baselines, explainability, stress testing and supply chain model risks for third parties, fourth parties and n-th parties are all framed with should. Whether that reads as deliberate calibration or as drafting drift is a question for the comment period, and our reading of the pattern is ours rather than a statement of CBK's intent.

Two dates on one package, and why it matters which one you cite

The draft's cover page reads DRAFT GUIDANCE NOTE ON ARTIFICIAL INTELLIGENCE IN THE BANKING SECTOR / AUGUST 2026. The Public Notice that put it into public participation closes CENTRAL BANK OF KENYA / SEPTEMBER 10, 2026 and asks for comments by November 7, 2026.

Both are on the record and neither is wrong. The August stamp is on the document; the September date is on the act. We take the operative date to be 10 September 2026, because that is when the document was issued for public participation, and we say so rather than quietly picking one.

The Public Notice frames the exercise under Article 118 of the Constitution and sections 4(a) and 5(3)(a) and (b) of the Statutory Instruments Act, 2013, and covers a wider package than AI alone: draft Prudential Guidelines, Risk Management Guidelines, Guidance Notes and the Domestic Systemically Important Banks Framework. The AI note is one of three Guidance Notes in a single zip file, and it is not linked as its own document.

The population is wider than banks

Paragraph 1.2 applies the draft to institutions licensed under the Banking Act, institutions licensed under the Microfinance Act, and then to Credit Reference Bureaus, Money Remittance Providers and Non-deposit-taking Credit Providers licensed under the Central Bank of Kenya Act, plus Non-Operating Holding Companies. Credit bureaus and digital credit providers being inside the application clause matters more than the headline suggests.

CBK's own 2025 survey, summarised at paragraph 2.5, is the context CBK sets out. CBK reported that 50 percent of surveyed institutions had adopted AI solutions, comprising 66 percent of commercial banks, 57 percent of microfinance banks and 43 percent of digital credit providers, and that all credit reference bureaus indicated non-adoption. CBK reported the top three applications as credit risk assessment at 65 percent, cybersecurity at 54 percent and customer service at 43 percent. Those are figures the regulator published about its own survey, not independently verified counts.

CBK also reported that 93 percent of respondents recommended that it issue comprehensive guidance on AI, covering governance and compliance, risk management, and incident management and reporting. CBK does not say in terms that the draft is the answer to that recommendation. What paragraph 2.5 says, immediately after the survey findings, is that in view of these developments CBK has issued this Guidance Note, and we put the two side by side on that footing rather than a causal one.

The filings the draft would create

Part V is short and it is where the ongoing work would sit, if the note were ever made. Institutions would provide CBK with a register of their AI models, systems and services in the Annex IV format, submitted immediately upon the Guidance Note taking effect and thereafter by the 5th day after the end of every financial year. The draft does not say when that effect would begin, so the first register has no date attached to it.

Incident reporting in the draft runs on two 24-hour clocks and a quarterly return. Under the draft, which is not in force, institutions should notify CBK within 24 hours of an AI incident materially affecting service availability, confidentiality or integrity, and should submit a resolution report within 24 hours of resolving a critical incident, covering cause, origin as internal or third party, remedial actions and lessons learned. Quarterly reports would go by the 5th day after quarter end.

AI incident is defined in the draft at 1.4.3 as events where AI models produce harmful, biased or unintended outcomes, degrade materially in performance, or are compromised. Material degradation in performance sitting inside that definition is the limb worth arguing about during the comment period, because if the note were made it would convert model drift into a reportable event.

What we did not verify

What we opened: the CBK Public Notice PDF in full, the Guidance_Notes.zip bundle from centralbank.go.ke, and the 45-page Draft Guidance Note on Artificial Intelligence in the Banking Sector extracted from it and read as text, including Parts I to V and the annex list. We also loaded the CBK news page dated 10 September 2026 and confirmed that it links Guidance_Notes.zip.

What we did not open: the draft Prudential Guidelines, the draft Risk Management Guidelines, the draft D-SIBs Framework, the two sibling Guidance Notes on Cybersecurity and on Third-Party Technology Service Providers, the CBK AI survey report cited at footnote 2, and the Kenya AI Strategy 2025-2030. We did not read Annexes I to VII line by line, and we describe them only by the headings and the reporting cadence given in Part V.

What we refuse to claim: we do not say any Kenyan institution is required to do anything, because this is a draft in public participation. We do not say it is Kenya's first AI instrument or the first by an African central bank, because the document makes no such claim and we did not test it. We do not say CBK intends the should and shall split to carry different weight, because the draft does not say so; the counts are ours and the inference from them is ours. We give no date for the note taking effect, because the draft sets none. The survey percentages are CBK's own reported findings and we present them as such.

Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.

Key compliance takeaway

If you run AI anywhere in a Kenyan licensed institution, the comment window to 7 November 2026 is the cheapest moment to deal with two things. The first is the definition of critical decision at 1.4.8, because fraud flagging and account freezing sit inside it and some institutions may not treat those as customer decisions at all. The second is the reporting cadence in Part V, which would have an AI deployment register due immediately on the note taking effect, with no lead time drafted in and no effect date fixed.

Source File

https://www.centralbank.go.ke/wp-content/uploads/2026/09/Public-Notice-Invitation-for-Comments-from-the-Public-on-the-Draft-Revised-Prudential-Guidelines-Risk-Management-Guidelines-Guidance-Notes-and-the-Domestic-Systemically-Important-Banks-.pdf

Download Guidance_Notes.zip from the CBK site and open the Artificial Intelligence PDF inside it. Confirm four things: the application clause at 1.2 and that it names credit reference bureaus and non-deposit-taking credit providers, the definition of critical decision at 1.4.8, the opening sentence of 4.15.2, and the register and 24-hour clocks in Part V.

Customers must have the right to request and obtain human intervention in the review of significant, adverse decisions made by AI systems, to challenge the decision, and to provide supporting data. ยท Draft Guidance Note on Artificial Intelligence in the Banking Sector, paragraph 4.15.2, issued for public participation 10 September 2026

FAQ

Does this bind Kenyan banks now?

No. It is a draft issued for public participation on 10 September 2026, with comments invited to 7 November 2026. It creates no duty on any institution, and the draft fixes no date on which it would take effect.

Which institutions would it cover?

The draft's paragraph 1.2 would cover institutions licensed under the Banking Act and the Microfinance Act, and also credit reference bureaus, money remittance providers and non-deposit-taking credit providers licensed under the Central Bank of Kenya Act, plus non-operating holding companies.

What would the right to human review actually involve?

Paragraph 4.15.2 opens with a right to request and obtain human intervention in significant adverse AI decisions. The draft would have the reviewer hold appropriate authority, training and competence, have access to the data points used and to the logic behind the decision to the extent possible, and would require disclosed resolution timeframes and a reasoned outcome.

Where is the draft published?

It is not linked as a standalone document. It sits inside Guidance_Notes.zip on the CBK website, with two other drafts on cybersecurity and on third-party technology service providers. The Public Notice that put the package out for comment is a separate PDF.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}