Kenya - AI Code of Practice (DKS 3007:2024)
DKS 3007:2024 Information technology — Artificial Intelligence — Code of Practice for AI Applications
Kenya
RAI-KE-NA-D3ITAXX-2024DKS 3007:2024 is a Draft Kenya Standard published by the Kenya Bureau of Standards (KEBS) that provides a code of practice for the responsible development, deployment and use of AI applications. The draft (opened for public consultation 8 April 2024 — consultation closed 13 June 2024) references international guidance (ISO/IEC standards, NIST AI RMF and the EU AI Act) and focuses on trustworthiness, risk management, testing and ongoing performance monitoring of AI systems.
Summary
Read full text ↗Plain English
Overview
DKS 3007:2024 (Information technology — Artificial Intelligence — Code of Practice for AI Applications) was prepared by the Kenya Bureau of Standards (KEBS) as a Draft Kenya Standard to provide recommended good practices for organisations that develop, provide or use AI systems. The draft is described as a 43‑page code of practice setting out approaches to establish trust (transparency, explainability, controllability), identifying engineering pitfalls and threats, and recommending technical and organisational methods to achieve availability, resilience, reliability, accuracy, safety, security and privacy in AI systems. KEBS notified the draft internationally to the WTO/TBT Committee (notification symbol G/TBT/N/KEN/1604). The draft was opened for public consultation on 2024-04-08 and the public consultation closed on 2024-06-13; the WTO notification listed a proposed adoption date of 2024-09-30. KEBS subsequently listed a published Kenya Standard product KS 3007:2025 (Information technology — Artificial Intelligence — Code of practice for AI Applications) on its standards webstore, indicating progression from the DKS draft to a published national standard. (See public notification and draft text: https://members.wto.org/crnattachments/2024/TBT/KEN/24_02705_00_e.pdf and KEBS webstore listing: https://webstore.kebs.org/index.php?product_id=19208&route=product%2Fproduct). Some third‑party report pages referencing the notification are also publicly available (for example: https://web.wtocenter.org.tw/en/Page/138/397590).
Definitions
The draft adopts and aligns terminology with existing ISO/IEC AI vocabulary (for example KS ISO/IEC 22989) and defines key terms used in the Code including 'AI system', 'provider', 'user', 'trustworthiness', 'risk', 'verification', 'validation' and 'monitoring' to ensure consistency across governance and technical recommendations. The Code references ISO/IEC concept and terminology standards as its definitional basis to promote interoperability of terms and to reduce ambiguity in governance and technical requirements. (Referenced summary: https://web.wtocenter.org.tw/en/Page/138/397590).
Governance and Institutional Framework
The draft recommends organisational governance arrangements to support the responsible development, deployment and lifecycle management of AI systems. Recommended elements include: senior management accountability for AI systems; designated AI risk owners or custodians; cross‑functional committees for AI oversight; processes for review and sign‑off of AI deployments; and integration with existing management systems such as information security and quality management. The draft encourages alignment with a management‑system approach (for example KS ISO/IEC 42001 where applicable) so that AI oversight and risk management are embedded in established organisational processes. The Code is framed as a non‑binding code of practice (guidance) rather than mandatory law; practical uptake will depend on voluntary adoption by organisations, incorporation into procurement or contractual requirements, or reference by sectoral regulators. (See KEBS notification materials and draft text: https://members.wto.org/crnattachments/2024/TBT/KEN/24_02705_00_e.pdf; secondary summary: https://web.wtocenter.org.tw/en/Page/138/397590).
Key Focus Areas
- Trustworthiness: recommendations to promote transparency, explainability and controllability of AI systems, enabling appropriate human oversight.
- Risk assessment and risk management: lifecycle risk identification, categorisation and mitigation aligned to an organisation’s context and the AI system’s risk profile.
- Data governance and privacy‑respecting design: requirements for data quality, provenance, lineage and protection measures that respect applicable data protection law.
- Verification, validation and testing: expectations for design‑time and run‑time testing, including performance testing, robustness testing, adversarial testing and stress testing.
- Documentation and accountability: model cards, technical documentation, data lineage records and governance artefacts to demonstrate due diligence and support traceability.
- Monitoring and performance evaluation: continuous monitoring and metrics to detect degradation, bias, safety issues or security incidents during operation.
- Security and resilience: recommendations to achieve availability, reliability, resilience and secure operation of AI systems.
- Incident response and redress: arrangements for incident detection, response, remediation and where appropriate user redress or escalation mechanisms.
Implementation Framework
The Code sets out non‑binding good practice across the AI lifecycle and is intended as a national reference that organisations of any size or type can adopt to support trustworthy AI implementations. Implementation expectations include documented governance arrangements; performed and recorded risk assessments; embedding data governance and privacy‑by‑design; applying verification and validation regimes; maintaining documentation such as model cards and data lineage; and establishing monitoring and incident response processes. The draft expressly positions itself as guidance rather than a mandatory technical regulation, intending to support quality and trustworthy AI across public and private sectors. KEBS later listed a published Kenya Standard product KS 3007:2025 on its standards webstore as the published national standard available for purchase, indicating the draft progressed to a published standard (see KEBS webstore: https://webstore.kebs.org/index.php?product_id=19208&route=product%2Fproduct). Public notification and draft materials were provided through the WTO notification process (see: https://members.wto.org/crnattachments/2024/TBT/KEN/24_02705_00_e.pdf).
Monitoring and Evaluation
The draft requires or recommends continuous monitoring and performance evaluation during operation, with specific emphasis on monitoring for accuracy, fairness, robustness, safety and security. It encourages organisations to define run‑time controls and metrics, log and retain operational data for auditing, and perform periodic reviews of model performance against expectations and risk profiles. Monitoring is linked to incident detection, incident response and remediation processes, and to mechanisms for corrective action, model retraining or retirement where performance has degraded or risks materialise. The Code therefore frames monitoring as an integral part of the AI lifecycle to detect emergent issues and to provide evidence of ongoing due diligence. (Summary references: https://web.wtocenter.org.tw/en/Page/138/397590).
Penalties, Liability, and Appeals
As a code of practice, DKS 3007:2024 does not itself prescribe statutory penalties, liability rules or an administrative appeals process. Enforcement in practice depends on voluntary uptake, incorporation into procurement or contractual requirements, or reference and adoption by sectoral regulators. If KEBS standards are incorporated into regulatory instruments, procurement rules or contractual terms, compliance expectations and any associated penalties or liabilities would then be determined by those instruments or contracts rather than by the Code itself.
Relationship to Other Instruments
The Code explicitly cross‑references multiple international AI and software‑quality standards (for example KS ISO/IEC 5339, KS ISO/IEC 22989, KS ISO/IEC 23894, KS ISO/IEC 42001 and SQuaRE quality models) and situates itself as national guidance aligned to global best practice. It is intended to complement Kenya’s legal framework such as the Data Protection Act (2019) and relevant ICT/cybersecurity legislation by providing technical and organisational guidance for AI systems. The document is designed to be used alongside other relevant national and international instruments where those instruments apply.
International Alignment
The draft references and maps to international instruments and frameworks such as ISO/IEC AI standards, the NIST AI Risk Management Framework (AI RMF) and the EU AI Act as either normative or informative references. KEBS notified the draft to the WTO/TBT Committee (notification symbol G/TBT/N/KEN/1604) as part of the international notification and comment process, and the draft materials were made available through the WTO notification/CRN attachment process. The Code aims to align national practice with recognised international approaches to AI governance, risk management, testing and assurance. (WTO notification and draft: https://members.wto.org/crnattachments/2024/TBT/KEN/24_02705_00_e.pdf; additional summary reporting: https://web.wtocenter.org.tw/en/Page/138/397590).
Implementation Timeline
| Date | Event |
|---|---|
| 2024-04-08 | Public consultation opened (DKS 3007:2024 draft opened for public comment). |
| 2024-04-19 | WTO notification published (G/TBT/N/KEN/1604) and draft circulated via WTO notification channels. |
| 2024-06-13 | Public consultation closed (end of comment period for the draft). |
| 2024-09-30 | Proposed adoption date (per WTO notification) listed as target date for adoption. |
| 2025-01-01 | KEBS webstore listing for KS 3007:2025 (catalogue entry indicating the related Kenya Standard was made available for purchase). |
Compliance Checklist
| Requirement | Description |
|---|---|
| Risk assessment | Perform and document AI system risk assessments proportionate to the system’s context and potential impacts; maintain records of identified risks and mitigations. |
| Data governance | Maintain data quality, provenance, lineage and privacy protections; conduct privacy impact assessments where applicable. |
| Verification & validation | Implement testing regimes covering performance, robustness, adversarial and stress testing during design and prior to deployment. |
| Documentation | Prepare and retain documentation such as model cards, design specifications, data lineage and decision‑logic descriptions to support transparency and accountability. |
| Monitoring | Establish run‑time monitoring, metrics and alerts to detect performance drift, bias, safety or security incidents; define thresholds for remediation or model retirement. |
| Governance | Assign senior management accountability, designate AI risk owners, implement cross‑functional oversight committees and integrate AI oversight with existing management systems. |
| Incident response & redress | Define incident response procedures, remediation steps and channels for escalation and redress where individuals are adversely affected. |
| Human oversight | Provide for appropriate human oversight/control measures consistent with the AI system’s risk profile and operational context. |
Sources and References
| Source | URL |
|---|---|
| WTO — Full notification / public review draft (DKS 3007:2024) | https://members.wto.org/crnattachments/2024/TBT/KEN/24_02705_00_e.pdf |
| Kenya Bureau of Standards (KEBS) — Webstore listing for KS 3007:2025 | https://webstore.kebs.org/index.php?product_id=19208&route=product%2Fproduct |
Kenya has adopted a new national standard, KS 3007:2025, which provides a code of practice for any organisation in Kenya that develops, provides, or uses Artificial Intelligence (AI) systems. This standard, developed by the Kenya Bureau of Standards (KEBS), aims to guide businesses and public bodies in building and deploying AI responsibly and ethically.
The standard applies to all organisations involved with AI systems, offering a framework for establishing trust and managing risks. It outlines several key practices: - **Trustworthiness**: AI systems should be transparent, explainable, and controllable, allowing for appropriate human oversight. - **Risk Management**: Organisations must identify, assess, and mitigate potential harms throughout the AI system's lifecycle. - **Data Governance**: Requirements for high-quality data, clear data origins, and strong privacy protections that align with Kenya’s Data Protection Act. - **Continuous Monitoring**: Expectations for thorough testing, validation, and ongoing performance evaluation to detect issues like bias, degradation, or security vulnerabilities during operation.
Unlike a mandatory law, KS 3007:2025 is a non-binding code of practice, meaning it does not directly prescribe statutory penalties or liability. Its practical uptake depends on voluntary adoption by organisations, its incorporation into procurement or contractual requirements, or reference by other sectoral regulators. The standard was formally adopted around September 30, 2024, and the published version, KS 3007:2025, became available on the KEBS webstore from January 1, 2025.
A practical pitfall for organisations is to assume that because it’s a non-binding standard, it can be ignored. In reality, it establishes a national benchmark for good practice in AI. This means that while not directly enforceable by law, it can easily become a de facto requirement through business partnerships, supply chain agreements, or future regulatory frameworks that reference it, making compliance a commercial or operational necessity.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 8 marked completePlain-English obligations under Kenya - AI Code of Practice (DKS 3007:2024). Not legal advice — verify against the official text before relying on it.
- #1Important⏰ Before deployment and ongoing
Applies to: Organisations developing, providing, or using AI systems.
“Perform and document AI system risk assessments proportionate to the system’s context and potential impacts.”
- #2Important⏰ Before deployment and ongoing
Applies to: Organisations developing, providing, or using AI systems.
“Maintain data quality, provenance, lineage and privacy protections; conduct privacy impact assessments where applicable.”
- #3Important⏰ During design and prior to deployment
Applies to: Organisations developing or providing AI systems.
“Implement testing regimes covering performance, robustness, adversarial and stress testing during design and prior to deployment.”
- #4Important⏰ Before deployment and ongoing
Applies to: Organisations developing, providing, or using AI systems.
“Prepare and retain documentation such as model cards, design specifications, data lineage and decision‑logic descriptions.”
- #5Important⏰ During operation
Applies to: Organisations deploying or using AI systems.
“Establish run‑time monitoring, metrics and alerts to detect performance drift, bias, safety or security incidents.”
- #6Important⏰ Before deployment and ongoing
Applies to: Organisations developing, providing, or using AI systems.
“Assign senior management accountability, designate AI risk owners, implement cross‑functional oversight committees.”
- #7Important⏰ Before deployment and ongoing
Applies to: Organisations deploying or using AI systems.
“Define incident response procedures, remediation steps and channels for escalation and redress where individuals are adversely affected.”
- #8Important⏰ Before deployment and ongoing
Applies to: Organisations deploying or using AI systems.
“Provide for appropriate human oversight/control measures consistent with the AI system’s risk profile and operational context.”
Related Regulations
Kenya National Artificial Intelligence Strategy 2025–2030
Kenya93% similar
Motion on the Formulation of a Regulatory Framework on Artificial Intelligence (National Assembly Motion)
Kenya92% similar
Kenya AI Regulation Overview
Kenya91% similar
Kenya Robotics and Artificial Intelligence Society Bill 2023
Kenya90% similar
Media Handbook for Reporting on Artificial Intelligence in Kenya (Media Council of Kenya draft)
Kenya90% similar
© Regulations.AI — created on 13-Jun-2026