Insights / Regulatory & Compliance

Can an AI Agent Perform Your DPO or MLRO Function in Kenya?

By Clay & Associates Advocates · 6 min read ·

Technology and compliance team reviewing AI system code and data governance controls in Kenya

Kenyan businesses are adopting AI agents for compliance monitoring, transaction screening and document review faster than the law is settling what those tools may actually do. A specific question now comes up often enough to need a direct answer: can an AI agent hold the designated Data Protection Officer or Money Laundering Reporting Officer role itself, or automate enough of that role’s substance to matter, under Kenyan law. The short answer is that the statutes assume a natural person, and the honest case for anything more automated is narrower than the marketing around “AI compliance officers” suggests.

The DPO Role Is Built Around a Person

Section 24 of the Data Protection Act, 2019 requires certain controllers and processors to designate a Data Protection Officer, and describes the DPO’s functions in terms that presuppose human judgment: advising the entity and its employees on data protection obligations, monitoring compliance with the Act, cooperating with the Data Commissioner, and acting as a contact point for the regulator and for data subjects. Section 35 separately gives data subjects the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them, subject to limited exceptions. Read together, these provisions create an awkward position for an AI agent acting as DPO: the very officer meant to safeguard against unaccountable automated decision making would itself be an unaccountable automated decision maker. The Act does not define “officer” or “designate” in a way that admits a non-human appointee, and the Interpretation and General Provisions Act, Cap 2, defines “person” to include a body of persons, corporate or unincorporate, but nothing in that definition extends to software.

The Honest Counter-Argument

A fair reading has to acknowledge the counter-argument some practitioners raise: the statute requires a designated DPO, but does not itself prohibit that person from being heavily assisted by AI tools in discharging the role, provided the designated natural person remains the one who exercises judgment, signs off on the entity’s regulatory position, and is accountable to the Data Commissioner. On this view, an AI agent can legitimately triage data subject requests, flag anomalies in processing registers, or draft breach notification content, so long as a human DPO reviews and owns the output. That is a materially different proposition from an AI agent holding the role, and it is the one that current Kenyan law can accommodate without strain.

The MLRO Role Carries the Same Structure, With a Sharper Edge

Regulation 12 of the Proceeds of Crime and Anti-Money Laundering Regulations, 2023 requires a reporting institution to appoint a Money Laundering Reporting Officer at management level, with responsibility for receiving internal disclosures, assessing whether a suspicious transaction report should be filed with the Financial Reporting Centre, and maintaining the institution’s compliance programme under the officer’s duties as set out in regulation 12(7). A “management level” appointment is inherently a natural-person concept under Kenyan company and employment law; a role cannot sit at a management level within an organisational hierarchy unless it is held by an individual with the authority and accountability that management level implies. The suspicious transaction reporting judgment itself, weighing incomplete and sometimes contradictory information about a customer’s conduct against a legal standard of suspicion, is also the kind of contextual judgment call that sits uneasily with full automation, and a wrong call carries real consequences: an MLRO who fails to report carries personal exposure under the Proceeds of Crime and Anti-Money Laundering Act quite apart from any liability the institution faces.

Where the Law Is Still Unsettled

Kenya does not yet have a data protection or anti-money laundering provision that speaks directly to AI agents performing compliance functions, and readers should treat anything beyond the statutory text above as informed prediction rather than settled law. The Data Protection (General) Regulations, 2021 and the POCAMLA Regulations were both drafted before generative AI compliance tools were commercially widespread, and neither the Office of the Data Protection Commissioner nor the Financial Reporting Centre has published guidance specifically addressing AI-assisted or AI-delegated compliance functions. Kenya’s broader AI governance framework is also still developing: a draft national AI strategy and related policy proposals have been under discussion, but as of this article’s publication no AI-specific statute has been enacted that would override or clarify the position under the Data Protection Act or the POCAMLA Regulations. Businesses should treat this as an active area to monitor rather than a settled gap they can safely build around.

What This Means in Practice

An entity that wants to use AI agents to support its data protection or anti-money laundering compliance function can do so, but the designated DPO or MLRO must remain a natural person who exercises real oversight, not a rubber stamp on the AI system’s output. Document what the AI tool does and does not decide, keep a human review step before any output that affects a data subject’s rights or triggers a suspicious transaction report, and make sure the designated officer’s employment contract and job description reflect actual decision-making authority rather than a supervisory role over a system that is, in substance, already making the calls. An arrangement that looks on paper like human oversight but functions in practice as automated decision making by another name is the arrangement most likely to draw regulatory scrutiny if either role’s decisions are ever challenged.

How We Can Help

Clay & Associates Advocates advises regulated businesses on structuring data protection and anti-money laundering compliance functions, including where AI tools fit into that structure. Our analysis of data protection compliance under the DPA covers the underlying framework a DPO operates within, and our guide to MLRO appointment and outsourcing under POCAMLA addresses the officer’s statutory duties in full. Contact our Regulatory & Compliance practice to review your current compliance structure.

Sources: The Data Protection Act, 2019, sections 24 and 35; The Proceeds of Crime and Anti-Money Laundering Regulations, 2023, regulation 12; The Interpretation and General Provisions Act, Cap 2, section 3(1).

Frequently asked questions

Can an AI system legally be designated as a company’s Data Protection Officer in Kenya?
No. Section 24 of the Data Protection Act describes DPO functions in terms that presuppose a natural person exercising judgment and accountability, and nothing in Kenyan law extends the definition of “person” for this purpose to software.

Can an AI agent do most of the practical work of the MLRO role?
It can assist with monitoring and flagging, but the “management level” appointment required by regulation 12 and the suspicious transaction reporting judgment itself must remain with a natural person who is personally accountable for the institution’s reporting obligations.

Is there Kenyan AI-specific legislation that changes this position?
Not yet. Kenya’s AI governance framework, including a national AI strategy, has been under discussion, but no enacted AI-specific statute currently overrides or clarifies the Data Protection Act or the POCAMLA Regulations on this point.

What is the practical risk of using AI tools without proper human oversight in these roles?
If the designated officer’s role is, in substance, a rubber stamp on AI-generated decisions rather than genuine oversight, the arrangement may not satisfy the statutory requirement for a designated, accountable natural person, exposing the institution and the officer personally if a decision is later challenged.

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more