AI Usage Policy for Kenyan Organisations: What It Should Cover
The direct answer: a workable AI usage policy for a Kenyan organisation covers eight things — approved tools, forbidden data, verification duties, disclosure rules, procurement of new tools, sector obligations, training expectations, and who owns the policy. It fits on one to two pages. Longer documents get ignored; absent ones get improvised.
Why does a Kenyan organisation specifically need this?
Two reasons beyond the universal ones. First, the Data Protection Act puts obligations on how personal data is processed — and pasting customer records into a public AI tool is processing. Second, adoption here is happening bottom-up: staff found the tools before management did, so the real choice is between governed use and ungoverned use, not between use and no use.
The eight sections
- 1. Approved tools. Name them. "Use good judgement" is not a tool list. State which accounts (organisational, not personal) and which tiers.
- 2. Data rules. The heart of the policy: what may never be entered into any external AI tool — customer personal data, employee records, unpublished financials, anything under NDA. Give examples; abstractions fail under deadline pressure.
- 3. Verification. AI output is a draft, not an authority. Anything leaving the organisation — reports, client emails, board papers — carries a named human who checked it. Facts, figures, and citations get verified against sources.
- 4. Disclosure. When must AI assistance be declared — internally, to clients, in published work? Pick a rule and write it down; ambiguity here is where trust incidents come from.
- 5. New tools. A lightweight path for staff to propose tools, so the policy does not become the reason people go underground.
- 6. Sector obligations. Banks, insurers, health, legal, and NGOs layer their regulator's expectations here.
- 7. Training. Policy without capability is theatre. State who gets trained on what, and that governed use is an expectation of the role, not a hobby.
- 8. Ownership and review. One named owner; review every six months — the tools change faster than annual cycles.
What makes policies fail?
Three patterns: policies written as prohibition lists (staff route around them), policies nobody was trained on (they are shelfware within a month), and policies with no owner (they fossilise). The fix for all three is the same — treat the policy as the syllabus for training, not a legal artefact. That is how we deliver it inside FuKazee's corporate training: the policy conversation happens with the hands-on work, so the rules arrive attached to capability. Related reading: why rollouts fail without this layer.
Where do you start on Monday?
Draft the one-pager with sections 1–3 only. Circulate it, train against it, and add the rest within the quarter. Want a working session to get it done? Message us on WhatsApp.