← Governance Research Brief

Governance Research Brief No. 1 · 4 September 2026

When the Algorithm Enters the Government File

A practitioner's reading of seven recent studies on sovereign AI, public administration and the judgement for which government must remain answerable.

Anyone who has worked inside government will recognise the authority carried by a file whose cardboard cover has softened at the edges and whose minute sheet bears several shades of ink. It may concern a hospital, a road, a licence or the release of funds, although its physical appearance rarely reveals the weight of the decision travelling inside it. One officer has assembled the facts, another has recorded a technical opinion, somebody in Finance has confirmed whether money exists, a legal adviser has entered a caution in the margin, and the responsible authority will eventually sign beneath a recommendation that can be retrieved, questioned and, if necessary, defended.

The government file has never guaranteed wisdom or fairness, since files disappear, inconvenient advice is sometimes ignored, and a perfectly documented decision can still be mistaken. Its importance lies in giving public judgement a route through the institution and leaving behind enough of that journey for another person to ask who knew what, who advised whom, and who accepted responsibility when the decision was made.

Kenya's administrative history contains another kind of record, one fashioned for control and divorced from accountable judgement. The Registration of Natives Ordinance was enacted in 1915 and implemented after the First World War. By 1920, African men leaving the reserves were being fingerprinted and issued with the certificate that became known as the kipande, which carried identity and employment information needed by the colonial state and settler employers. It became a deeply resented feature of colonial labour administration; the information it held was inseparable from the power being exercised through it.

The kipande and a modern digital platform belong to different political worlds, and collapsing them into one lineage would weaken both the history and the argument. They sit together here for one reason: each directs attention to the way an administrative instrument acquires the purposes of the political order that puts it to work. Government receives information through categories, and those categories influence who becomes visible, which account is believed, what movement is permitted, where resources are directed and how an official is expected to act. Although the machinery changes from one period to another, public officials still have to ask whose purposes its categories and decisions carry.

Years in government have taught me that a policy approved in a conference room has only begun its administrative life. Its real character appears later, when a public officer with an incomplete record, a limited budget, a crowded waiting area and a citizen expecting an answer must decide what the institution will actually do. Artificial intelligence is moving into precisely that part of government, through systems that draft, search, classify, predict, recommend and, increasingly, initiate action.

My reason for beginning the Governance Research Brief is to read research from inside the realities of administration, without the comfortable distance from which institutions can appear more coherent than they are. I am interested in work that can survive contact with a ministry, a county treasury, a hospital, a procurement committee and the legal duty to give an account of a public decision. Kenya supplies the immediate institutional setting; experience across the Global South reveals how questions of infrastructure, dependence and capability are shared without being identical; and the wider world matters because the models, standards, contracts and commercial relationships shaping our choices are frequently made elsewhere.

For this first edition, I selected seven new and recent publications dealing with governmental model evaluation, responsible AI in health, national AI strategies, financial stability, agentic systems, application-layer regulation and G20 technology policy. Three were published during the previous seven days, with the remaining four appearing between eight and thirty days earlier. I would rather widen the period honestly than fill a weekly quota with commentary that adds little to public understanding.

What a public value looks like in a tender

The paper I would first place on a procurement officer's desk is the study by Laurens Samson, Iva Gornishka, Gossa Lô, Yuki M. Asano and Sennay Ghebreab, undertaken with domain experts from a Dutch municipal organisation. Their paper, From Values to Benchmarks, takes familiar public-service concerns and turns them into tests that can be applied when choosing a language model. More than thirty multilingual and Dutch-specific models were examined for factual accuracy, willingness to acknowledge uncertainty, social bias, energy consumption, financial cost and transparency concerning training data.

None of the models came out ahead on every measure, which makes the study more useful to a procurement committee than a neat winner would have been. Better performance tended to require more money and energy, while bias followed no convenient relationship with either price or general quality. The result I found most revealing was the separation between factuality and honesty. A model could answer many questions correctly and still be poor at admitting when it lacked enough knowledge to answer another one safely.

For an experienced administrator, the separation between accuracy and candour is familiar: competence includes the ability to recognise when the record is insufficient, when another department must be consulted, when legal advice is needed and when an apparently straightforward matter should be held back instead of being pushed towards a confident conclusion. Fluency can conceal the absence of that restraint when a language model produces an elegant paragraph about a citizen's eligibility, a county regulation or a procurement rule while inventing the authority upon which its answer supposedly rests.

Public procurement in Kenya therefore requires a different standard from the commercial leaderboard. If a model will assist with permits, benefits, legal drafting, health information or responses to citizens, it needs to be tested against the vocabulary, documents and circumstances of Kenyan administration. Kiswahili and Kenyan English are an obvious beginning, although the constitutional recognition of linguistic diversity requires a wider ambition where a service affects communities that encounter the state through other languages or accessible communication formats.

The tests would also have to follow the work, which means that a model intended for a county revenue office should be challenged with local legislation, exemptions, ambiguous records and questions from citizens unfamiliar with official terminology. One intended for health communication must be examined for factual restraint, cultural comprehension and its handling of circumstances in which referral advice cannot be followed easily. A system used for policy drafting should be required to distinguish a genuine statute, circular or court decision from a plausible invention.

A shared public-sector evaluation capability would spare forty-seven counties and numerous national agencies from trying to assess the same suppliers separately. Information and communication technology specialists would be necessary, although they could not define public value on their own. Procurement officers, lawyers, records managers, language specialists, professional regulators, frontline staff and service users would have to shape the tests because choices involving cost, candour, bias, environmental burden and acceptable error belong to public administration as much as they belong to computer science.

Such a service could establish a national baseline and retain modules for particular sectors and counties. A model that performs adequately in a central department may behave differently when presented with county legislation, local names, code-switching, incomplete records or a service pathway that depends upon several institutions. Reassessment would also be essential whenever the provider changes the model, since government cannot assume that a system carrying the same commercial name will continue to behave as it did when the contract was awarded.

The county is where readiness becomes real

The World Health Organization's Report of the Knowledge Community on Responsible Artificial Intelligence in Health moves the discussion away from model selection and into the conditions found inside health systems. It records a five-week structured dialogue involving researchers, policy officials and digital-health experts from 105 countries, who repeatedly returned to weak governance, fragmented or biased data, uncertain accountability and inadequate AI literacy. WHO is careful to say that the participants did not form a statistically representative sample, so the report is best read as informed institutional experience with no claim to the authority of a global survey.

The participants kept returning to one practical conclusion: deployment must move at the pace permitted by validation, workforce capability, data, public participation and the institution's willingness to delay or reject a system that it cannot govern responsibly. That discipline is easy to endorse in principle and much harder to practise after a funding agreement, launch date and public promise have been fixed.

In county health administration, readiness is experienced through details that disappear easily from a national presentation. A digital triage system may have passed a sound technical assessment while the facility receiving it has intermittent connectivity, incomplete patient records, no biomedical technician nearby and a referral hospital several hours away. The clinical officer may retain authority to override the recommendation in theory, while workload, limited training and uncertainty about managerial support make that discretion difficult to exercise in practice.

Those operational differences make devolution part of the design itself, particularly under Article 174 of Kenya's Constitution, which associates devolved government with accountable power, recognition of diversity, self-government, accessible services, equitable resources and decentralisation from the capital. Those commitments are relevant when a nationally acquired system enters a county function. The platform may be common, but the service environments into which it arrives are neither administratively nor materially uniform.

A workable intergovernmental arrangement would preserve national standards for safety, rights and interoperability while allowing counties to establish whether their facilities, staff and service pathways satisfy the conditions for use. That requires a readiness assessment with consequences, rather than a form completed for the project record. Where staffing, validation, referral capacity or incident management is inadequate, an authorised person must be able to postpone deployment without being treated as an obstacle to innovation.

The human-oversight language used in many AI policies needs the same practical treatment; the presence of a person somewhere in a workflow does not by itself establish meaningful supervision. The responsible officer needs access to relevant information, sufficient professional standing to challenge the system, time to undertake the review and an alternative procedure when the technology is unavailable or unsafe. The institution must preserve the model version, relevant inputs, recommendation and subsequent official action so that an adverse event can be reconstructed without relying entirely upon the supplier.

The consequences are especially visible in health, where a poor recommendation may cause immediate harm, although the administrative principle applies equally to social protection, taxation, land, licensing and recruitment. A central system can reduce inconsistency and make services easier to reach, while its failure modes will still emerge through local records, workloads and institutional relationships. Government will learn about those failures only if frontline officers and citizens have a credible route for reporting them and if somebody with budgetary and managerial authority is required to respond.

Sovereignty eventually reaches the contract

Roxana Radu's World Bank background paper, The Global Landscape of National AI Strategies, examines more than eighty national strategies published between 2017 and June 2025, together with patterns of investment in supercomputing. Her comparison covers sovereign, market-led and hybrid approaches across income groups and shows how differently governments are handling infrastructure, regulation, international cooperation, environmental cost and workforce change.

Grand declarations become harder to sustain against Radu's evidence: a country can publish an impressive sovereign-AI strategy and remain dependent upon external providers for cloud infrastructure, model updates, specialist personnel, evaluation tools and the licences under which essential services operate. It can also spend heavily on computing infrastructure without creating enough demand, skills or administrative capacity to use that investment well.

For Kenya, sovereignty would be more usefully approached as a division of capabilities than as a race to possess every component of the AI supply chain. Certain public assets and responsibilities require strong national control, including sensitive government data, identity and authentication functions, cybersecurity, public standards and the institutional knowledge needed to specify and supervise systems. Other capabilities, especially expensive evaluation facilities, advanced research and negotiations with global firms, may gain strength through the East African Community or the African Union. Commercial services will continue to play a legitimate role, provided that dependence upon them is known and governed.

The procurement contract is where this question loses its diplomatic polish and becomes a set of enforceable rights, duties and contingencies. Government needs to know whether its data will be used to improve a provider's products, whether an auditor can inspect relevant records, how model changes will be notified, how quickly incidents must be disclosed, whether decisions can be reproduced, what happens during an outage, and how information and services will be transferred when the relationship ends. Local data hosting answers one part of sovereignty, while control over updates, interfaces, expertise and continuity may determine whether the institution can act independently when circumstances become difficult.

Andrew Bailey's letter from the Financial Stability Board to G20 finance ministers and central bank governors illustrates the stakes. The letter identifies the possible effect of frontier AI on the speed, scale and economics of cyber threats as the most immediate AI concern for the financial system, placing responsible model release and operational resilience within the work of financial supervision.

Kenya has good reason to read this beyond the boundaries of banking regulation. Mobile money, government payments, revenue collection and digitally mediated services now carry economic and public functions whose interruption would be felt across households and institutions. If several banks or public services depend upon the same cloud, model or cybersecurity provider, failure at that provider becomes more than a matter for individual contract management. Regulators and procuring authorities need a shared view of concentration, recovery capability and the circumstances under which an external technical dependency acquires systemic importance.

A serious assessment of sovereignty would examine failure scenarios as closely as it examines the assurances accompanying a successful launch. It would ask whether essential work can continue if a supplier withdraws a service, whether government can reconstruct a disputed decision after a model update, whether data can be moved in a usable form, and whether the institution has enough internal knowledge to supervise a replacement. Ownership may be visible in company records or on the walls of a data centre, whereas operational control is revealed when something goes wrong.

Responsibility follows the exercise of power

The Indian legal paper in this week's selection approaches the problem at the level of the application instead of concentrating upon the underlying model. In Governing AI Applications in India, Vishal Chaudhary argues that India already possesses laws and regulators dealing with data protection, cybersecurity, consumer protection, professional standards and specific digital harms; those instruments remain fragmented when applied to systems that generate, recommend, rank, persuade or act in consequential settings.

His proposed architecture combines baseline duties, obligations for high-impact applications, sector schedules and rights for affected people, with responsibility distributed across model providers, developers, integrators, platforms and deploying institutions. It is an ambitious individual proposal and should not be mistaken for an account of settled Indian law. The part I would carry into Kenya is its insistence that responsibility remains with the institution exercising consequential power, even where much of the technical chain belongs to other organisations.

Kenya does not need to wait for a new national AI regulator before the institutions already exercising public authority begin to govern the systems entering their domains. Authorities responsible for health, finance, education, public service, procurement, data protection and county administration already possess mandates that can be brought to bear. Common national duties could deal with records, impact assessment, security, explanation and redress, while sector bodies determine what those duties require in the circumstances of a medical recommendation, a recruitment shortlist, a tax assessment or a county licence.

In Assessing Company Contributions to Societal Resilience, Catherine Simons, Alexander K. Saeri, Peter Slattery and Neil Thompson extend responsibility in another direction by examining how companies deploying AI agents affect society's capacity to withstand and govern the consequences. Their paper adapts a societal-resilience framework around vulnerability, coping and adaptation, and demonstrates it through a structured review of Microsoft's public documentation. The method remains a prototype, and the study does not establish that its indicators predict resilience under real conditions.

Read from the procurement committee's side of the table, the framework prompts questions that ordinary product demonstrations rarely answer. Does the system generate records detailed enough to support an independent investigation after harm occurs? Can an automated action be reversed through a procedure that the responsible public institution controls? Will the provider disclose incidents promptly and preserve the earlier model versions needed to reconstruct disputed actions? Are users able to interrupt the agent, and can the institution continue operating without it? Does the deployment strengthen the public body's ability to learn, or does every serious problem have to be returned to a supplier whose technical account the buyer cannot independently test?

The imbalance between formal responsibility and technical capacity is especially acute across much of the Global South. A ministry or county may remain legally answerable for a service while the supplier possesses the deeper knowledge of how the system behaves. Governments can reduce that imbalance by pooling technical assessments, exchanging incident information, commissioning independent tests and negotiating common contractual expectations through regional institutions.

The G20 Innovation Ministerial Statement and the Carolina Principles for Emerging Technologies carry these administrative questions into the diplomatic room. Ministers agreed upon six broad areas involving pro-innovation policy, opportunity and prosperity, technical skills, intellectual property, AI standards and supply chains, with the African Union participating in the meeting. Agreement across the G20 has political value, although the text speaks with greater detail about research, commercialisation and trusted deployment than it does about redress, labour consequences, citizen participation and concentrated corporate power.

A public administrator learns to read official statements through both their commitments and their absences. Terms such as “trusted technology” acquire force only after somebody establishes who certifies the system, whose evidence is accepted and what happens when confidence is misplaced. Intellectual-property rules determine whether countries can inspect, adapt and replace the systems upon which their institutions depend. Supply-chain partnerships may bring infrastructure and investment while leaving control of the most valuable knowledge, interfaces and decisions elsewhere.

Kenya and other African states should engage these arrangements as active rule-makers whose constitutional and development priorities may differ from those of the countries and companies designing the technology. International cooperation is valuable when it enlarges domestic capability, widens access to research and improves bargaining power. It becomes less attractive when flexibility is demanded from the regulator while contractual certainty and intellectual-property protection are reserved for the supplier.

What I would ask before the approval minute is signed

If a major public-sector AI proposal arrived for approval, the first question I would ask concerns evaluation. Has the system been tested on the languages, records, laws and service conditions in which it will operate, and has that assessment examined uncertainty, bias, cost, environmental burden and accessibility alongside general performance? I would also want to know who conducted the test, whether the institution can repeat it independently and what will trigger reassessment after a change in the model.

The second question concerns the authority to stop, including which named officer, regulator, professional body or county institution may delay, restrict or discontinue the system when legality, data, staffing or service readiness is inadequate. An escalation procedure without a person who can act, a budget that can support the alternative and protection against pressure from an implementation deadline offers the appearance of control without its substance.

The third question concerns the distribution of capability across national institutions, regional arrangements and commercial providers. Which elements must Kenya own because they carry sovereign or security significance, which can be developed more effectively with regional partners, and which may be purchased under contracts that preserve auditability, portability, resilience and exit? The answer will differ across sectors, although the analysis should be made before dependence becomes embedded in routine administration.

For all its defects, the government file carried an institutional memory of the authority exercised through it. The older paper trail made it possible, at least in principle, to identify the document considered, the advice offered, the officer who recommended and the authority who approved. An AI-supported decision may involve a dataset assembled by one party, a model built by another, an application configured by a third and a public officer who sees only the final recommendation. Unless government deliberately reconstructs the chain of responsibility, technological sophistication can leave the citizen facing a decision for which every participant claims to have supplied only one component.

The kipande belonged to an administration in which legibility ran overwhelmingly in one direction: the African subject became extensively visible to a coercive authority, while the authority's purposes and decisions remained beyond meaningful challenge. Present systems can serve a radically different public order and offer genuine gains in translation, access, early detection of risk and relief from repetitive work. Those gains will be consistent with democratic government only where citizens can also see enough of the institution to know who acted, which information counted, how to contest an error and where responsibility finally rests.

I want this weekly brief to sustain a conversation between research and administration. New papers will be assessed for the quality of their evidence, the limits of their claims and the institutional work required to make their proposals useful. Kenya will remain the principal address of the inquiry, with devolution and implementation treated as part of the argument rather than appended after the important decisions have already been made. The Global South will be approached as a field of varied experience, not a single category, while international developments will be read for the ways in which they distribute capability, risk and bargaining power.

When an algorithm becomes part of a government file, the record must still identify who recommended the system, who tested it, who accepted its risks, who may suspend it and who will answer the citizen when the result is wrong. The fact that technology has been supplied by the market cannot be allowed to obscure where responsibility sits; judgement exercised in the name of the public remains a governmental duty for which the institution must be prepared to answer in full.

The seven readings

  1. Laurens Samson, Iva Gornishka, Gossa Lô, Yuki M. Asano and Sennay Ghebreab, “From Values to Benchmarks: Evaluating Large Language Models for Governmental Use in Dutch”, 10 August 2026.
  2. WHO Regional Office for Europe, “Report of the Knowledge Community on Responsible Artificial Intelligence in Health”, 1 September 2026.
  3. Roxana Radu, World Bank, “The Global Landscape of National AI Strategies”, 25 August 2026.
  4. Andrew Bailey, Financial Stability Board, “FSB Chair's Letter to G20 Finance Ministers and Central Bank Governors”, 31 August 2026.
  5. Catherine Simons, Alexander K. Saeri, Peter Slattery and Neil Thompson, “Assessing Company Contributions to Societal Resilience: Extending the Societal Capacity Assessment Framework to Agentic AI”, 27 August 2026.
  6. Vishal Chaudhary, “Governing AI Applications in India: A Regulatory Architecture for Generative, Recommender, Agentic and High-Impact Systems”, 10 August 2026.
  7. G20 Innovation Ministers, “G20 Innovation Ministerial Statement” and “Carolina Principles for Emerging Technologies”, 2 September 2026.

Historical and constitutional context: “Biometrics, Race Making, and White Exceptionalism: The Controversy over Universal Fingerprinting in Kenya”; and the Constitution of Kenya, 2010, especially Articles 6 and 174.

Ahmed Nadhir Omar is a public systems thinker and health governance practitioner working across public administration, institutional capability and the political economy of technology.

Connect on LinkedIn ↗