Mugambi Laibuta

The dominant professional conversation on artificial intelligence casts the Advocate as a user of AI tools. This paper argues that the more consequential role is that of advisor to clients who build, procure, deploy and operate AI systems, and that competent advisory work in this role demands mastery of a risk landscape far broader than data protection. Drawing on the Constitution of Kenya, 2010, the Data Protection Act, the Computer Misuse and Cybercrimes Act, the Employment Act, the sector-specific regulatory frameworks, intellectual property statutes and the emerging AI regulatory agenda, the paper makes four contributions. It situates data protection within a wider frame of data governance and cybersecurity; it proposes structured legal risk assessment as the Advocate’s core method; it insists on precise identification of the sector regulations and controls governing each deployment; and it maps the advisory mandate across eight stages of the AI lifecycle, from conception to decommissioning. The Kenyan content moderation litigation against Meta and Sama is examined as an early demonstration of how AI-adjacent labour claims will be pleaded and adjudicated. The paper concludes that working knowledge of constitutional law, data governance, cybersecurity, employment law, intellectual property, surveillance governance, sectoral regulation and commercial contracting is not an aspirational profile for the Kenyan AI advisor. It is the minimum level of competence that the scale and complexity of AI-enabled harm now demands.