The organisations best placed to use AI well will be those that can explain, govern and improve the decisions it shapes

A customer asks a bank why a payment was blocked. The contact-centre agent can see that an automated fraud control intervened, but cannot explain what information shaped the result, whether a person reviewed it or how the customer can have it reconsidered. The immediate question may appear to concern an algorithm. The practical failure is broader: the bank cannot clearly account for a decision that its workflow allowed AI to influence.

That is the issue now coming into view in Kenya. On 21 July 2026, Kenya’s Ministry of Information, Communications and the Digital Economy published a call for comments on its Draft Kenya Artificial Intelligence and Other Emerging Technologies Policy. The draft is not enacted law, and its final wording, implementation arrangements and enforcement status may change. Yet it signals that AI use will increasingly be judged through the transparency, accountability and human control of the wider decision system.

Responsible AI is not a layer of compliance added after deployment. It is the operating discipline that lets an institution use AI without losing control of consequential decisions.

That matters far beyond technology companies. Banks, insurers, telecoms, employers, public agencies, health providers and development programmes are already incorporating AI into customer support, fraud controls, document handling, case management, marketing and internal productivity. The challenge is no longer to find a tool. It is to know when the tool has begun to shape outcomes that deserve explanation, review and correction.

A policy signal with operational consequences

Reporting on the Kenyan draft has highlighted proposed expectations that people should know when they are interacting with AI, when automation materially shapes decisions affecting them, and when public content has been generated or substantially altered by AI. It also points towards explainability, auditability and meaningful human oversight for higher-risk applications.

These are often presented as governance principles. For an operating organisation, they are design requirements. A customer-service assistant needs a route to a person when the issue exceeds its competence. A model used in credit, recruitment or eligibility needs a defined decision owner, a way to examine the data and rules that influenced the outcome, and a process for correcting mistakes. A supplier contract cannot transfer that responsibility away.

Kenya’s draft should therefore be read as a prompt to prepare, rather than as an excuse for premature claims about new legal obligations. The Kenya Artificial Intelligence Strategy 2025–2030 already set out the country’s ambition to build an ethical, inclusive AI ecosystem. The July policy consultation makes the operational questions harder to avoid.

The governance gap is usually hidden inside the workflow

Most organisations do not start with an “AI programme”. They begin with a service pressure: contact-centre volumes are rising, fraud investigations are slow, staff are buried in documents, or managers need faster reporting. A team adopts a platform feature, a vendor adds automation, or a business unit pilots a generative-AI assistant.

The model may be technically sound, yet the workflow around it can still be weak. A staff member may receive a recommendation without understanding its limits. A customer may be told to trust an automated answer without knowing how to challenge it. A manager may have a dashboard for model performance but no visibility into complaints, overrides or failed handovers.

This is why an AI inventory is more valuable than another tool demonstration. It reveals where AI is actually embedded: in purchased software, cloud services, outsourced operations, decision-support tools and staff productivity practices. It also exposes which uses have moved beyond assistance into material influence over a person’s access to services, money, work, safety or rights.

The important distinction is consequence. An internal writing assistant and a model that influences a lending decision should not carry the same controls. Treating every use case as high risk creates bureaucracy that teams evade. Treating every use case as low risk invites damage that leaders cannot explain.

Transparency is more than a chatbot notice

A disclosure that a person is speaking to an AI system is often necessary. It is rarely enough.

Useful transparency tells people what role the system is playing, what happens to their request next, and where human judgement remains available. If automation has materially shaped a significant outcome, a person needs a meaningful route to ask questions, correct relevant information or seek review. That requires language that is clear to a customer or citizen, rather than language written solely for a legal or technical audience.

The point is not to reveal proprietary model details or overwhelm people with technical documentation. It is to prevent a familiar institutional failure: a consequential decision becomes opaque because each participant can point elsewhere. The vendor points to the deployer; the business unit points to the algorithm; the call centre points to a policy it cannot interpret.

A decision is only governable when the institution can say what the system did, who remained responsible, and how an affected person can seek correction.

That proposition also improves internal management. A team that cannot describe an AI system’s purpose, data inputs, decision role and escalation route is unlikely to detect where the system is producing operational friction or unequal outcomes.

Human oversight fails when intervention is impossible

“Human in the loop” is reassuring language, but it can conceal an empty control. Review is not meaningful when staff must approve hundreds of outputs without context, cannot override an outcome, lack time to investigate exceptions, or are not trained to recognise when a system has failed.

A practical oversight model gives people authority as well as presence. It identifies circumstances in which a case must be escalated, makes relevant evidence available to the reviewer, records interventions and feeds recurring problems back into system improvement. It also makes clear who owns the service outcome once AI has been introduced.

This is particularly relevant in environments where records are incomplete, service access varies and a customer may share a device or rely on an assisted channel. An incorrect automated decision does not remain a technical error. It can become a wasted journey, a blocked payment, a missed opportunity or an exclusion from a programme that has no easy appeal route.

African institutions have an opportunity here. Many are building AI-enabled services while broader digital systems are still evolving. That makes it possible to embed human handovers, multilingual communication, assisted-service channels and audit trails early, instead of attempting to retrofit them into a deeply entrenched legacy process.

Measure the service, not only the model

Technical accuracy matters, but it cannot be the sole measure of success. A fraud model may reduce false positives overall while creating disproportionate friction for a particular customer segment. A case-ranking tool may save staff time while delaying urgent cases. A chatbot may answer common queries efficiently but fail to transfer complex requests to a capable person.

The relevant measures sit across the whole decision system: how often staff override recommendations; how long a customer waits after an automated handover; whether data problems recur; where complaints arise; and whether service quality differs across groups or channels. These indicators belong alongside accuracy, uptime and cost.

A leadership dashboard should answer a service question. Is AI helping the organisation make faster, fairer and more reliable decisions? If it only reports that a model is live, it has missed the point.

This approach is also commercially sensible. Organisations that instrument their AI workflows can identify where automation is genuinely reducing effort, where it is simply moving work to customers or staff, and where a flawed process needs redesign before more technology is added.

Readiness starts with a manageable sequence

The first move is not to create a large governance bureaucracy. It is to establish visibility and ownership around the use cases that matter most.

Discover. Map where AI is already used, which decisions it affects, what data it relies on and who may be harmed by a poor outcome. Pay particular attention to systems that influence access to financial services, employment, public programmes, health support or other essential services.

Design. Classify use cases by consequence. Define the disclosure, human-review, incident and supplier-management patterns appropriate to each level. Agree the limited set of indicators that leadership needs to see.

Build and enable. Add audit trails, escalation routes and clear ownership to priority workflows. Test them with real cases, not only technical scenarios. Train managers and frontline teams to recognise failures, intervene competently and use what they learn to improve the service.

This is not an attempt to predict every future regulation. It is a way to build a more reliable organisation now.

The competitive advantage is accountable deployment

The organisations that benefit from AI will not necessarily be those that announce the most pilots. They will be those that can turn useful automation into dependable services: services with sound data, accountable decisions, competent people and feedback loops that surface harm before it becomes institutional distrust.

Kenya’s draft policy is a useful moment for leaders to ask whether their AI systems are merely installed or genuinely governable. The answer will increasingly shape customer confidence, procurement credibility, regulatory readiness and the organisation’s ability to scale an AI capability without accumulating quality debt.

Organisations assessing high-impact AI use cases can begin by mapping existing decision workflows, data controls and human escalation routes. Xelius supports this work through responsible AI governance, data and decision-systems assessment, and the design of accountable digital services.