CBK warns banks against use of AI to reject or approve loans
Business
By
Brian Ngugi
| Sep 13, 2026
In recent years, a majority of Kenyan banks have quietly embedded Artificial Intelligence (AI) into the core of their operations.
A tier-one lender, for instance, uses machine learning models to score borrowers and approve mobile loans at a rate of Sh1.5 billion a day.
Another lender’s customers chat with an AI assistant on WhatsApp that checks balances and transfers funds. Yet another bank feeds every fraud incident into an AI system that learns to spot the next one.
This is, however, set to change under new rules. Now the banking regulator wants to see the machines and these AI tools before the banks switch them on.
READ MORE
Mombasa tea auction trades 6.5 million kgs
Ruto's Tata Chemicals tantrum spooks investors ahead of polls
What machines still can't do on a project team
Kenya emerges as key market for global wellness brand
State okays Japanese brewer's Sh388b takeover of Diageo's EABL stake
FKE: Investing in women leaders is good for business
Fish firm gets global food certification
Tea factory embraces value addition to boost consumption, farmer earnings
Financial sector pushes for stronger data systems to boost credit access
Co-op Bank leads list of Kenyan lenders in Forbes World top 500
Under newly published sweeping draft rules by the Central Bank of Kenya (CBK), banks would be required to obtain written approval from the regulator before deploying any AI system a pre-approval requirement that no major jurisdiction around the world currently imposes on financial institutions, according to a review by The Standard.
The CBK published the draft Guidance Note on Artificial Intelligence on Thursday. A 2025 Central Bank survey earlier found that half of all licenced institutions had already adopted AI solutions, including 66 per cent of commercial banks.
The top applications were credit risk assessment (65 per cent), cybersecurity (54 per cent), customer service (43 per cent), electronic Know-Your-Customer (41 per cent), and fraud risk management (40 per cent).
The practical effect and use are visible across the sector. The machine learning scoring models analyse mobile money transaction histories and behavioural patterns to decide who gets a loan and on what terms.
The models have widened their credit-eligible pool and lifted mobile lending. Banks also use AI for credit analytics, customer lifecycle modelling, and risk monitoring, enabling more granular scoring and early detection of distressed accounts.
Some banks have also deployed AI to fight fraud, feeding each new incident into the system to improve detection.
The CBK’s own survey found that 92 per cent of commercial banks, 100 per cent of microfinance banks, and 100 per cent of credit reference bureaus wanted the regulator to issue AI guidance. The draft guidance would transform how these systems are built, deployed, and monitored. Pre-approval becomes mandatory. “Institutions shall seek approval of the Central Bank before deployment of AI systems,” the draft rules state.
Applications must be accompanied by a Data Governance and Artificial Intelligence Checklist covering data sources, training data representativeness, bias testing by location, gender and age, security testing, model validation, and decommissioning plans.
Banks would have to demonstrate that training data is “representative of the real-world scenario that the AI application will operate in” and that the model has been tested on “real-world data.”
Critical decisions also now require human intervention going forward. Any AI-driven outcome with a “significant legal, financial, or similarly substantive effect” on a customer, explicitly including credit denial, fraud flagging, account freezing, and pricing adjustments, would trigger a right to human review.
The reviewer must have “appropriate authority, training, and competence” and access to “all data points used by the AI, the logic behind the decision, and any additional information provided by the customer.” For banks, that means an AI-rejected loan application could no longer be final. A human would have to review it, explain the reasoning, and potentially overturn it. Bias testing becomes a precondition, not an afterthought.
Banks would have to conduct bias impact assessments before deployment and embed “Fairness-by-Design” into model development.
They would be required to “mitigate discriminatory outcomes based on protected attributes such as race, gender, ethnicity, religion, nationality, disability, or age” and ensure AI services “do not inadvertently exclude or disadvantage vulnerable groups, for instance, customers who lack access to smartphones.”
The draft explicitly prohibits digital redlining using proxies like postal code to deduce race or ethnicity.
Agentic AI is equally classified as high-risk. This, in simple terms, means any AI system capable of “independently initiating actions, interacting with external systems, executing transactions or materially affecting the institution’s operations” would be subject to enhanced governance, independent review, and continuous monitoring.
Banks would be barred from deploying such systems unless they can demonstrate effective human oversight, the ability to suspend or terminate, and complete audit logs.
The systems would be prohibited from modifying their own objectives or operating parameters without authorisation.
Generative AI gets guardrails. Banks would have to adopt acceptable use policies, validate outputs, manage hallucination risks, and “ensure that material decisions are not based solely on unverified outputs generated by AI systems".
They would also have to establish “baseline metrics for factual consistency".
Incident reporting also tightens under the new rules. Banks would have to notify the CBK within 24 hours of any AI incident “materially affecting service availability, confidentiality, or integrity".
A final report would be due within 24 hours of resolution, with quarterly summaries by the fifth day after each quarter.
The CBK’s pre-approval requirement places Kenya at the most interventionist end of a global spectrum, bankers say.
The European Union’s AI Act classifies credit scoring systems as high-risk and imposes extensive obligations for bias monitoring, customer transparency, documented risk assessments, and human oversight, but does not require regulatory approval before deployment.
In the United States, the Federal Reserve, OCC, and FDIC updated their model risk management guidance in April 2026 but explicitly excluded generative and agentic AI from its scope, saying that “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance".
The UK’s FCA published its Mills Review in July 2026, concluding that the existing regulatory framework provides a “strong foundation” and recommending adaptation rather than AI-specific rules.
Singapore’s Monetary Authority has taken a collaborative approach, publishing a 173-page AI Risk Management Toolkit developed with 24 industry partners, including case studies from DBS and other banks. It sets supervisory expectations but does not mandate pre-approval.
Qatar is, however, the closest parallel to CBK. Its central bank issued AI guidelines in 2024 requiring pre-approval for high-risk systems, even before a firm signs a purchase agreement. But Qatar’s financial sector is far smaller and less AI-dependent than Kenya’s.
“The CBK is saying, ‘We’re going to regulate this now, and we’re going to do it through the licensing process we already have,’” said a Nairobi-based banking consultant who reviewed the documents.
“The Americans have essentially said, ‘We don’t know how to regulate this yet, so we’re going to wait.’ It’s a very different philosophy.”
The rules place ultimate responsibility on bank boards. Directors would have to approve a Data Governance Strategy, Data Governance Policy, Data Governance Framework, AI Strategy, AI Policy, and AI Risk Management Framework.
They would also have to establish a Data Governance Committee and a Model Risk Committee, and ensure independent audit of AI systems at least once a year.
“The board of directors holds the ultimate responsibility for guiding the ethical development and use of AI in their institutions,” the draft states.
For Kenya’s largest banks, which have invested heavily in AI infrastructure and data science teams, the new rules would require a fundamental shift in how models are developed and deployed.
Credit scoring models, currently deployed at scale, would need to pass through a regulatory checklist before any update.
Conversational AI tools which handle tasks like balance checks and fund transfers would need to disclose to customers that they are interacting with an AI system.
Fraud detection systems, which flag suspicious transactions in real time, would be subject to human-review requirements for any flagged activity that leads to account freezing.
For smaller institutions and digital credit providers, the compliance burden could be heavier.
The CBK survey found that limited AI-skilled staff, high costs, and data governance challenges were already obstacles to adoption. The pre-approval requirement adds a regulatory hurdle before any system can be tested in production.
CBK has invited public comments on all documents by November 7, 2026, with submissions to be sent to fin@centralbank.go.ke.