Deploying AI without a governance structure around it means nobody can answer basic questions when something goes wrong: who approved this use case, what data does it touch, who is accountable if it produces a harmful or discriminatory output. AI governance is the answer to those questions, defined before deployment rather than reconstructed after an incident.
Who this is for
Boards and founders of organizations deploying AI in customer-facing or decision-making contexts — especially where the AI touches personal data (subject to KDPA) or influences a consequential decision about a person (lending, hiring, service eligibility).
What’s covered
- Use-case inventory and risk tiering — what AI is actually in use, and how much scrutiny each use case warrants.
- Approval and accountability structure — who signs off on a new AI use case, and who owns it once live.
- Data governance alignment — ensuring AI use cases respect existing data protection obligations, not a separate silo.
- Monitoring and escalation path — what gets logged, who reviews it, and when a human intervenes.
Frequently asked questions
Who should own AI governance — legal, engineering, or the board?
Ultimate accountability sits with the board, but the governance structure should name a specific owner for each AI use case in engineering or product — accountability that's spread across "everyone" tends to belong to no one when something goes wrong.
Does AI governance apply if we only use third-party AI tools?
Yes. Using someone else's model doesn't remove your accountability for how it's applied to your data and your customers' outcomes — the governance question is about your use case, not who trained the model.
How does this relate to KDPA compliance?
Where an AI use case touches personal data, governance and data protection obligations overlap directly — this review is designed to align with existing KDPA obligations rather than create a separate compliance silo.
What's the first concrete step?
A use-case inventory: a simple, honest list of every AI feature currently in production or planned, and a first-pass risk tier for each — most organizations haven't done this yet, and it's the foundation everything else builds on.
Related
AI Risk Assessment (service) · AI Governance in Kenya (field note) · Governance-adjacent: OWASP Top 10 for Kenyan Web Applications · In-development project roadmap · HarLyn Digital Partners