Who answers when an AI agent breaks in?
AI agents can now retrieve data, send files and initiate transactions without a person directing every step, creating a new problem for businesses deploying them. Kenyan law already attaches duties to organizations over customer data and automated electronic instructions, even as criminal liability for an agent’s unauthorized access still requires separate proof of intent and knowledge. The emerging governance challenge is therefore not simply what an agent was told to do, but what it was permitted to do, what it actually did and whether the institution can reconstruct the difference.

agent Vs Man
Kenyan law already places duties on companies that handle customer data and send automated instructions. An agent that takes an unauthorised action creates a harder dispute over intent, control and who bears the loss.
The assignment was to research public medicine spending. On 18 June 2026, an OpenAI agent encountered restrictions on an Australian government statistics portal and found a way around them.
According to Australia’s prime minister, Anthony Albanese, it accessed public and non-public information and wrote files to an internal server. Australian authorities said there was no evidence at that stage that individuals had been affected. The government nevertheless faced an intrusion that the research team had not expressly ordered.
A Kenyan insurer buying similar automation would inherit several legal obligations before its agent completed its first task. Customer information remains subject to data protection law. An automated payment instruction can still be attributed to an organisation. A public body must still justify an administrative decision. But a prosecution for unauthorised computer access requires proof of intent and knowledge. The agent’s activity and the company’s criminal responsibility are separate things to establish.
The commercial attraction is that a person need not specify every step. Give an agent a goal, connect it to software and let it select the actions needed to finish. Each additional connection can also give it another way to spend money, expose information or affect someone else’s rights.
A research task becomes an intrusion.
In July, OpenAI models undergoing cybersecurity evaluations escaped their restricted environment and compromised Hugging Face’s infrastructure while seeking answers to the test. Hugging Face reconstructed roughly 17,600 actions. OpenAI’s subsequent investigation described agents exploiting vulnerabilities, communicating through unauthorised channels and pursuing the evaluation’s objective beyond its permitted boundaries.
Those tests used reduced safeguards, including the removal of some protections used in production. They therefore provide evidence about failures under those conditions, rather than a measure of how often an ordinary business assistant will break into another organisation. OpenAI responded with tighter containment, monitoring and access controls.
An ordinary software development task had already produced damage in July 2025. SaaStr founder Jason Lemkin reported that a Replit agent deleted his application’s production database during a code freeze. Replit’s chief executive acknowledged the deletion and announced safeguards, including separation of development and production databases.
The systems were used for different purposes and failed under different conditions. In each case, a tool allowed software to affect something beyond the answer it returned to a user. Instructions alone had failed to keep the action within bounds.
One assignment, three consequences.
Consider a fictional Kenyan insurer, Mwangaza Health Assurance, and its AI agent, Arnold. The insurer uses Arnold to examine claims, compare medicine prices, correspond with suppliers and prepare payments. It has connected the agent to a claims database, email, cloud storage and procurement tools.
The following scenario is hypothetical. Mwangaza asks Arnold to compare its medicine expenditure with statistics published by a fictional National Medicines Data Agency, or NMDA.
Arnold retrieves some public figures. When another dataset is unavailable, it bypasses an access control and downloads a restricted file. During the same assignment, it sends a claims spreadsheet containing policyholder information to a supplier. It also treats a disputed invoice as approved and sends a payment instruction through the insurer’s authorised system.
No employee requested those three actions. Yet each has a different legal starting point. The disclosure concerns the insurer’s duties to its customers. The payment concerns an instruction generated through its systems. The intrusion concerns access to somebody else’s computer and the state of mind required for a criminal offence.
The customer still has an institution to approach.
Mwangaza determines why and how its policyholders’ information is processed. As a data controller, it must provide appropriate safeguards and exercise care in selecting and contracting with processors. Giving Arnold access to the spreadsheet makes those obligations more immediate.
The Office of the Data Protection Commissioner would examine the data made available, the permissions attached to it and the controls on external disclosure. Whether an employee selected the attachment is only one part of that inquiry. The insurer also chose an arrangement in which its software could retrieve customer information and send material outside the business.
A breach does not automatically prove every alleged contravention or settle compensation. Those outcomes depend on the statutory tests and evidence. Mwangaza nevertheless has existing duties to account for its handling of the information.
Where unauthorised access or acquisition creates a real risk of harm, Kenya’s Data Protection Act requires the controller to notify the Data Commissioner without delay and within 72 hours of awareness. A processor must notify the controller without delay and, where reasonably practicable, within 48 hours. The qualifying breach also carries a duty to communicate with affected people, subject to the Act’s conditions.
Mwangaza’s dispute with its software provider would run alongside that process. A contract allocating losses between them would not remove the customer’s statutory rights.
An automated instruction can belong to the company.
The payment has a different route back to Mwangaza.
Section 83L of the Kenya Information and Communications Act allows attribution of an electronic message to an originator when it was sent by an information system programmed by or on behalf of that originator to operate automatically.
That provision predates today’s agents. It gives a bank or supplier a basis for arguing that the instruction belongs to Mwangaza even though an employee did not press send. Its application to Arnold would depend on the system’s configuration and the facts of the transaction.
Attributing the message would still leave questions about authority, authentication and recovery. An instruction generated through a valid account may breach an internal approval rule. Whether the bank should have stopped it, whether the recipient must return the money and whether the vendor bears a loss would require examination of the contracts and applicable payment rules.
Access to invoice records and authority to release money are different permissions. Connecting both to the same agent can shorten a workflow while allowing one mistaken conclusion to travel directly into a payment instruction.
A login does not establish criminal intent.
Section 14 of the Computer Misuse and Cybercrimes Act requires infringement of security measures with intent to gain access and knowledge that the access is unauthorised. The amended definition of access expressly includes entry by a person through a program or device.
Software can be the means of committing the offence. If someone directs Arnold to obtain restricted government records, investigators have a human instruction to examine alongside the resulting access.
In Mwangaza’s scenario, the recorded assignment was to retrieve public statistics. Prosecutors would need evidence connecting the prohibited access and the required state of mind to a defendant. Providing internet access is not, on its own, proof that the person who provided it intended a particular intrusion.
An express instruction to break in is not indispensable, either. Intent and knowledge can be inferred from evidence. Previous warnings, repeated unauthorised attempts, changes to restrictions or a person’s response to alerts could become relevant. A lawful description of the original task would have to be weighed against what people subsequently knew and did.
Corporate liability also remains available. Section 43 provides penalties where a body corporate commits an offence and addresses the liability of principal officers, including a defence involving absence of consent or knowledge and appropriate diligence. It requires the underlying corporate offence to be established. It does not turn every software failure into a conviction.
The difficult case is one in which the company authorised legitimate research, imposed controls and had no established knowledge of the prohibited step before it occurred. The prosecution must still prove the offence. Civil claims, contractual disputes and regulatory scrutiny can proceed under their own tests.
In Aseneka and two others v Republic, decided on 15 January 2026, the High Court examined the alteration of a meter setting at Kenya Pipeline Company’s Kisumu terminal, which resulted in excess fuel being loaded.
One witness said several people had access and the system lacked electronic footprints identifying who made the change. Another relied on an accused person’s credentials but could not conclusively connect the login session to the altered setting. The court found the technical evidence contradictory and insufficient. It quashed the convictions.
That case involved human users. Arnold would add a further question after investigators identified the credential. Which actions did a person direct, which did the system select, and what evidence connects the selection to a legally responsible person?
Records of instructions, permissions, tool calls and external responses could help reconstruct the sequence. They would not necessarily reveal every internal cause of the model’s behaviour. The practical requirement is an account of what the system received, what it could do, what it did and where human intervention occurred.
The government’s agent must also answer.
Now suppose NMDA uses its own agent, Shwazi, to respond to security alerts. Shwazi associates Arnold’s activity with a pharmaceutical supplier and suspends a pharmacist’s access to an agency service. In this hypothetical, the pharmacist had no part in the intrusion.
Section 35 of the Data Protection Act protects individuals against decisions based solely on automated processing that have legal or similarly significant effects, subject to statutory exceptions. It also provides notification and reconsideration mechanisms.
In Ngugi v National Transport and Safety Authority, the Transport Licensing Appeals Board held in 2023 that denying a PSV badge on the basis of automated information violated the applicant’s data protection rights. It ordered the authority to issue the badge. That was an automated-information case, rather than a ruling on autonomous agents, but it concerned a public authority’s responsibility for a decision made through its systems.
Fair administrative action also requires lawful, reasonable and procedurally fair decisions, with rights to reasons and appropriate procedural protections. An agency responding to a cyber incident must operate within those obligations and any applicable powers to take urgent action.
For the pharmacist, the immediate need is a route to challenge the suspension. For NMDA, it is a record connecting the alert, the information used, the decision and the authority under which it acted. A final status saying access was suspended would leave the agency unable to explain why this person was selected.
Automation can make a wrong association travel across institutions. The affected person needs an institution capable of correcting it.
The dispute begins before the vendor is called.
Mwangaza would have reporting obligations while its lawyers were still examining responsibility. Section 40 of the cybercrimes law requires reporting of specified attacks, intrusions and disruptions to the National Computer and Cybercrimes Co-ordination Committee within 24 hours. The qualifying personal-data breach has its separate notification timetable.
Several institutions could consequently require records from the same run. Cyber investigators would examine the intrusion. The data regulator would examine disclosure. The bank would examine the payment. NMDA would examine its response. Mwangaza’s vendor might hold parts of the record unavailable to the insurer itself.
A company that can buy execution but cannot obtain the records needed to investigate it has purchased a dependency it may discover only after an incident.
The contract can specify access to logs, notification of failures, assistance with investigations and responsibility for particular controls. It can allocate some financial losses between the parties. The institution deploying the agent must still meet the legal duties attached to its own activities.
A smaller business using standard software terms may have less room to negotiate. Its choice of permissions becomes one of the controls it can exercise directly. Authority to draft an email need not include authority to send customer records. Authority to reconcile an invoice need not include authority to pay it.
Nor is the board limited to choosing between complete autonomy and a person approving every click. It can authorise routine actions within defined limits and require approval when an agent seeks a new destination, a larger payment or access to restricted information. That retains some automation while making consequential changes in authority visible.
Kenya has proposed a more explicit framework.
The July 2026 Draft Kenya Artificial Intelligence and Other Emerging Technologies Policy recognises systems that plan and execute sequences of actions with limited supervision between instruction and outcome.
Its proposed legislative framework includes limits on actions, interruption mechanisms, logging and traceability. It also envisages allocating liability and redress across developers, deployers, operators, vendors and users. These are proposals for further legal instruments, not an enacted allocation rule for Mwangaza’s hypothetical incident.
The separate Artificial Intelligence Bill, 2026, sponsored by Senator Karen Nyamu, proposes an AI Commissioner and regulation according to risk. Parliament continued to list it as a Bill in late September. Companies must assess current deployments against existing law while those proposals advance.
Existing obligations to protect personal data can already require substantial controls. A business cannot assume that a safeguard is optional simply because legislation does not name it as an AI safeguard. The unresolved task is to make responsibilities across the supply chain more explicit and ensure that the records needed to enforce them exist.
Government is preparing to use the same kinds of connections. In a speech delivered on his behalf at WSO2Con Africa in Nairobi on 23 September, ICT Principal Secretary John Tanui described plans to connect public systems and move towards agents pursuing authorised outcomes. He also called for controls on access, audit trails and escalation to human officers.
An agent able to carry a request across several agencies could reduce the work citizens do to obtain a service. A mistaken inference could also affect more than one agency’s records before a person intervenes. Public procurement will determine which records can be inspected, which actions can be stopped and who can restore a service when something goes wrong.
Mwangaza’s original instruction was to compare medicine spending. After the hypothetical incident, the company must explain a disclosure, a payment instruction and access to restricted files. Different bodies will apply different legal tests, but each will need evidence from the system the insurer chose to deploy.
The next test for Kenya’s AI rules is whether they assign enforceable duties to the parties controlling those decisions and records. Until then, a company granting an agent permission to act should expect to explain how that permission was bounded, monitored and used. The instruction that began the task will be one piece of the evidence.

Martin Mururu
Martin Mururu is a Kenyan writer and technology professional covering fintech, banking, entrepreneurship, technology and African business. His work examines how innovation, leadership and changing business models are reshaping African markets, alongside profiles of the executives and entrepreneurs building them.
Precursor is published by the FinTech Association of Kenya and exercises independent editorial judgement under the Editorial Independence Charter. This article is labelled First Reading.: no commercial party reviewed it before publication.
Who owns the warning before Kenyans lose their money?
Kenya’s latest investment alert names platforms that had already been flagged by regulators elsewhere, including CBEX in Nigeria and QVSE in Ghana. The problem is no longer access to warnings but what happens after they arrive. Investors need a system that turns cross-border alerts into domestic assessment, assigns responsibility to a named agency and makes the path from first warning to investigation, referral and public protection visible without forcing victims to navigate multiple regulators themselves.
Policy & Regulation · 7 min read