The Case and Its Sedimentation
On March 6, 2026, the Kenyan Court of Appeal overturned criminal penalties for the publication of “false information” online, a move that removed a pillar of the Cybercrimes Act 2018. This ruling, which invalidates sections 22 and 23 of the law, is not an isolated event but a symptom of the growing tension between traditional legal frameworks and the evolution of digital infrastructure. The Kenya case reveals a broader mechanism: the struggle to define the limits of freedom of expression in a context where identity verification tools and AI training are becoming instruments of control.
The decision, sought by organizations such as the Bloggers Association of Kenya (BAKE), is not only a victory for content creators. It is a signal that the digital governance model, based on ambiguous laws and punitive sanctions, is encountering resistance. The Court emphasized the vagueness of the regulations and their impact on constitutional freedoms, creating a breach in the wall that separates analog law from the digital context.
Architecture and Vulnerability
The Kenyan case is set against a broader landscape of technical and legal vulnerabilities. According to a Smile ID report, in 2025, a criminal network used 100 fake faces to launch 160,000 verification attacks on African fintech platforms. This data reveals a paradox: while governments seek to regulate the digital realm with legal tools, the infrastructure itself becomes a target for attacks that exploit the same identification logics that the laws seek to protect.
The Court’s decision regarding the Cybercrimes Act 2018 introduces a point of disruption. By eliminating criminal penalties, the judicial system recognized that repression is no longer sufficient to manage the complexities of the digital world. This does not mean abandoning protection, but rather redefining control mechanisms. The ruling highlighted that freedom of expression cannot be compatible with regulations that allow for the arrest of journalists and bloggers for unproven “falsities.”
Symbiosis and Conflicts
The debate becomes more complex with the entry of global actors. The investigation into Ray-Ban Meta Smart Glasses, conducted by Oversight Labs, shows how Nairobi has become a crucial node in AI training. The group has asked the Office of the Data Protection Commissioner to verify whether the data collected by the glasses is being used without consent. This case highlights a problematic symbiosis: while Kenya hosts artificial intelligence infrastructure, its laws fail to protect local data.
“This is not just a win for content creators or journalists. It is a win for every Kenyan who uses the internet to speak truth to power,” said Kennedy Kachwanya, president of BAKE. His statement underscores how the battle for digital freedom is not only about professionals, but about the entire population.
The Court’s decision and the investigation into Meta reveal a contradiction: while governments seek to regulate the digital realm with legal tools, technology companies export control models that bypass local legislation. This creates a breeding ground for conflicts that cannot be resolved either through repression or deregulation.
Scenario and Responsibility
Kenya is not an isolated case. Its experience foreshadows a global trend: the struggle to define the boundary between protection and repression in the digital realm. The Court has opened a window, but the political and economic cost of maintaining this openness will be high. Who will pay the price for a more transparent system? Technology companies, which will have to adapt their business models to stricter regulations, or governments, which will have to invest in more sophisticated control infrastructure?
I believe that the answer cannot be singular. Responsibility will be distributed: companies will have to be accountable for the transparency of their algorithms, governments will have to ensure that laws are adapted to the digital context, and citizens will have to acquire tools to exercise control over their data. Only through this imperfect symbiosis can a model of digital governance be built that does not sacrifice freedom at the altar of security.
Photo by Boitumelo on Unsplash
Texts are autonomously processed by Artificial Intelligence models