ZMS Legal
Request a consultation
← Back to Insights

Efficient. Sound. Innovative. · 22 September 2026 · Banking & Finance

CBK has joined the chat on the AI governance conversation

CBK has published draft AI guidance for the banking sector. Even as soft law, it may reshape procurement, contracts and compliance for banks, fintechs, vendors and virtual asset businesses.

The Central Bank of Kenya (CBK) has published a Draft Guidance Note on Artificial Intelligence in the Banking Sector for public review, as part of a broader update to Prudential Guidelines (PGs), Risk Management Guidelines (RMGs) and Draft Domestic Systemically Important Banks (D-SIBs) Framework. 1 The consultation package includes draft guidance on artificial intelligence, cybersecurity and third-party technology services.

The AI draft, dated August 2026, would create a supervisory architecture covering: 2

  • board accountability and senior-management oversight;
  • data governance and model-risk management;
  • consumer safeguards, transparency and human review;
  • third-party oversight, auditability and contractual controls;
  • incident reporting; and
  • specific controls for generative AI and agentic AI.

The compliance perimeter will extend beyond banks

Although the draft is directed primarily at regulated financial institutions, its commercial effect is likely to reach much further. Any business that supplies technology, data, infrastructure or AI-enabled services to a regulated institution may be drawn into the compliance perimeter through procurement standards, contractual warranties, audit rights and incident-reporting obligations.

This may include:

  • digital service providers and cloud platforms;
  • AI developers and fintech companies;
  • identity-verification providers;
  • blockchain analytics companies; and
  • virtual asset businesses that support or depend on regulated financial institutions.

That wider commercial reach makes the legal character of the draft especially important. Even if the final instrument operates as guidance rather than primary legislation, its practical effect may still be felt through supervision, procurement and contractual assurance.

Guidance may be “soft law”, but the risks are hard

The legal force of regulatory guidance must be stated carefully. Guidance notes are not automatically equivalent to Acts of Parliament, regulations or statutory instruments.

Their effect depends on the enabling statute, the language used, the body issuing them, the process followed and whether the document is final or merely consultative. In the United States, for example, the Securities and Exchange Commission expressly states that staff guidance is not legally binding because it represents staff views.

The United Kingdom’s Financial Conduct Authority, by 3 contrast, distinguishes mandatory rules in its Handbook from other guidance and policy materials. 4 Yet it would be a serious mistake to conclude that guidance can safely be ignored. Regulators use guidance to explain how they interpret legislation, how they expect regulated entities to organise compliance and what evidence they will seek during supervision.

It can shape licensing decisions, inspections, enforcement priorities, remediation orders and assessments of whether boards and senior managers exercised reasonable oversight. Guidance therefore often has powerful practical and evidential force, even where it does not independently create an offence.

That distinction is central to the CBK document. As at 17 September 2026, it is a draft issued for public review, not a final instrument in force.

Its provisions should therefore be described as 5 proposed requirements. However, the draft itself cites section 57(1) of the Central Bank of Kenya Act, section 33(4) of the Banking Act and section 48(2A) of the Microfinance Act as the authority under which CBK may issue guidelines to institutions.

If finalised under the applicable statutory 6 framework, regulated institutions should expect the final text to carry substantial supervisory weight.

Lessons from ODPC guidance notes: Notes operationalises binding duties

Kenya’s Office of the Data Protection Commissioner (ODPC) illustrates how sector guidance can translate broad statutory duties into operational expectations. The ODPC has published guidance on consent, data-protection impact assessments, cross-border transfers, biometric data, digital credit providers, communications, education, health data and other processing contexts. 7 The binding duties arise primarily from the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021.

The Act regulates personal-data processing, creates data-subject rights and imposes obligations on controllers and processors. It specifically addresses automated decision-making, data-protection impact assessments and data protection by design and by default.

The General Regulations add operational detail, including requirements relating to 8 automated individual decision-making, processor contracts, privacy by design, breach notification and impact assessments. 9 ODPC guidance does not replace those laws. It explains how the regulator expects organisations to comply with them in particular settings.

The ODPC’s guidance for digital credit providers, for example, addresses lawfulness, fairness, transparency, purpose limitation, minimisation, security, lawful bases and data-subject rights in digital lending. The enforcement environment 10 gives that guidance practical importance: the ODPC has previously announced audits of digital lenders and warned that failure to cooperate with the Office may constitute an offence under the Act.11 The lesson for market participants is straightforward: read the underlying statute first, then read the regulator’s guidance as a map of supervisory expectations.

A narrow debate over whether a guidance note is formally “binding” can miss the larger risk. The law creates the duty; the guidance often tells you what credible compliance is expected to look like.

What CBK proposes

The draft applies to institutions licensed under the Banking Act and Microfinance Act, as well as credit reference bureaus, money remittance providers, non-deposit-taking credit providers licensed under the Central Bank of Kenya Act and non-operating holding companies. It would 12 apply where an institution develops its own AI or relies on a third party for AI systems, processes or functions.

Area Proposed expectation Board-approved data strategy, data policy, AI strategy, AI

Governance

policy and AI risk-management framework. Proposed prior CBK approval, supported by a detailed data-

Deployment

governance and AI checklist. Inventory, independent validation, testing, monitoring, stress

Model risk

testing, explainability and model-drift controls. Clear disclosure, meaningful explanations, human review of

Consumers

critical decisions and dedicated complaints channels. Due diligence, contractual controls, cybersecurity, data

Third parties

ownership, portability, oversight and exit planning. Proposed notification within 24 hours for material AI incidents,

Incidents

followed by resolution and quarterly reports. These are not superficial disclosure requirements.

They would require institutions to establish controls across the entire AI lifecycle, from planning and acquisition to training, deployment, monitoring and retirement. The proposed checklist seeks evidence on data sources, representativeness, encryption, security testing, bias, accountability, explainability, validation, stress testing, vendor controls and decommissioning. 13

The vendor trap: indirect regulation through contracts

For digital service providers, the most consequential provision may be the simplest: a financial institution remains accountable for AI supplied by a third party. The draft expects due diligence on service dependencies, concentration risk, contracts, data ownership and portability, cybersecurity, transparency and exit strategies.

It also expects third-party vendors to comply with the institution’s AI and data-governance policies. 14 That changes the commercial test. A product will not be judged only on speed, accuracy or price.

A regulated client will also ask whether it can govern the product, explain its output, obtain logs, detect drift, investigate incidents, meet regulatory deadlines and exit without operational collapse. Vendors that cannot supply credible evidence may become unbankable, however innovative their technology appears.

Compliance readiness by way of contractual diligence is becoming product readiness.

Why virtual asset service providers should care

Virtual asset service providers (VASPs) are not expressly listed as a standalone category in the draft merely because they conduct virtual-asset activities. Direct application will depend on the licences held, corporate structure and regulated activities.

But exclusion from the list does not equal isolation from the regime. VASPs frequently depend on banks, payment providers, cloud platforms, identity-verification systems and transaction-monitoring tools.

They may use AI for wallet screening, sanctions checks, fraud detection, customer risk-rating and behavioural analytics. If they supply a regulated institution, process its customer data or form part of its outsourced service chain, CBK- inspired requirements may arrive through contracts and assurance reviews.

A VASP should therefore be able to answer six questions:

  1. Can its automated decisions be explained?
  2. Can a qualified human intervene?
  3. Are datasets lawfully obtained and representative?
  4. Can discriminatory outcomes be identified and corrected?
  5. Are material actions fully logged?
  6. Can it alert a regulated client quickly enough for the client to meet the proposed 24-hour incident-notification period?

The raised bar: Boards, not algorithms, carry accountability

The draft places primary responsibility on boards. Boards would approve the institution’s data and AI strategies, policies and risk frameworks; define permitted and prohibited uses; establish governance committees; allocate resources; maintain stakeholder communication; and ensure independent review at least annually.

Senior management would operationalise those decisions, 15 while risk functions, internal audit and external audit would provide challenge and assurance. This allocation is deliberate.

AI risk cannot be delegated entirely to data scientists, IT departments or external vendors. Decisions about credit, pricing, fraud, account access and customer treatment engage legal duties, risk appetite and institutional values.

They belong within the core of enterprise governance.

Power to the people! Consumers would gain meaningful rights

The draft’s consumer provisions are among its strongest. Institutions would disclose when customers are interacting with AI, explain AI-enabled services in plain language and provide information about data categories, risks and limitations.

On request, customers would receive a clear explanation of the data, variables and factors informing an AI decision. 16 For critical decisions, including credit denial, fraud flagging, account freezing and pricing adjustments, customers would be entitled to request human intervention, contest the outcome and provide supporting information. The reviewer would need appropriate authority, training and access to relevant information, and must exercise independent judgment rather than merely endorsing the machine’s recommendation. 17

Generative AI Vs agentic AI: different risks, different controls

For generative AI, the draft calls for acceptable-use rules, protection of customer and proprietary information, output validation, controls for hallucination, intellectual-property consideration, prompt management and staff training. Material decisions should not rest solely on unverified generated output.

Agentic AI receives stricter treatment. A system capable of initiating actions, interacting with external systems, executing transactions or materially affecting operations would be classified as high risk.

It would require defined authority limits, continuous monitoring, human intervention, complete audit logs and a reliable ability to suspend or terminate the system. For developers of 18 autonomous financial agents, oversight and kill-switch capability must be designed in, not bolted on later.

The bottom line

The draft is not binding today. Its signal is nevertheless unmistakable.

CBK intends AI in financial services to be governed through board accountability, consumer fairness, data protection, operational resilience, explainability, third-party control and regulatory visibility. For banks, fintechs, digital service providers and virtual asset businesses, that turns compliance into a market-access capability.

Organisations that prepare early will be better placed to win regulated clients, pass due-diligence reviews and deploy trusted systems. Those that delay may discover that compliance requires more than rewriting a policy.

It may require redesigning the product, the data architecture, the contracts and the decision process on which the business already depends.

Keep the conversation open

The draft is still under consultation, and its legal, operational and commercial effects will continue to develop. We will monitor the consultation process, any revisions to the text, CBK’s eventual implementation approach and the implications for regulated institutions and their technology partners.

Footnotes and Sources

1. Central Bank of Kenya, “Draft CBK Prudential Guidelines, Risk Management Guidelines, Guidance Notes, and Framework for Domestic Systemically Important Banks,” 10 September 2026, https://www.centralbank.go.ke/2026/09/10/draft-cbk-prudential-guidelines-risk- management-guidelines-guidance-notes-and-framework-for-domestic-systemically- important-banks/.

2. Central Bank of Kenya, Draft Guidance Note on Artificial Intelligence in the Banking Sector (August 2026), Parts II-IV and Annexes I-VII.

3. U.S. Securities and Exchange Commission, “Staff Guidance,” last reviewed 17 March 2026, https://www.sec.gov/rules-regulations/staff-guidance.

4. Financial Conduct Authority, “Handbook of Rules and Guidance,” updated 8 September 2025, https://www.fca.org.uk/about/how-we-regulate/handbook.

5. Central Bank of Kenya, public consultation page, 10 September 2026; Draft Guidance Note, cover and Part I.

6. Draft Guidance Note, para. 1.3.

7. Office of the Data Protection Commissioner, “Guidelines,” https://www.odpc.go.ke/guidelines-2/.

8. Data Protection Act, 2019, Cap. 411C, ss. 31, 35 and 41, Kenya Law, https://new.kenyalaw.org/akn/ke/act/2019/24/eng@2022-12-31.

9. Data Protection (General) Regulations, 2021, regs. 22, 24-28 and 37-53, Kenya Law, https://new.kenyalaw.org/akn/ke/act/ln/2021/263/eng@2022-01-14/publication.

10. Office of the Data Protection Commissioner, Guidance Note for Digital Credit Providers (December 2023), https://www.odpc.go.ke/wp-content/uploads/2024/02/ODPC-Guidance- Note-for-Digital-Credit-Providers.pdf.

11. Office of the Data Protection Commissioner, “ODPC to Audit 40 Digital Lenders and Issues Enforcement Notice Against a Health Service Provider,” 5 October 2022, https://www.odpc.go.ke/wp-content/uploads/2024/02/Approved-Press-Release-on- DCP039s-and-Health-Provider-1-1.pdf.

12. Draft Guidance Note, paras. 1.2 and 2.2.

13. Draft Guidance Note, paras. 4.5-4.8 and Annex III.

14. Draft Guidance Note, para. 4.9.

15. Draft Guidance Note, paras. 2.3 and 4.1-4.3.

16. Draft Guidance Note, para. 4.15.1.

17. Draft Guidance Note, para. 4.15.2.

18. Draft Guidance Note, paras. 4.10-4.11.

Editorial note: This article is a general regulatory analysis, not legal advice. The CBK document discussed is a draft as at 17 September 2026 and may change following consultation.

Disclaimer: This article is for general information only and does not constitute legal advice on any specific matter. For advice tailored to your circumstances, please contact ZMS Legal directly.

Have questions about this topic?

Speak directly with one of our partners.

Contact us