By Joyce Kimani
Nairobi, Kenya: While relaxing at home, 23-year-old Valerie Shigholi Kulola encountered the dark side of the internet. A friend forwarded a TikTok video to her, revealing that a stranger had utilized her photos to produce an unauthorized, AI-generated erotic dance video. This digital manipulation falsely depicted Kulola as being in a romantic relationship with the owner of the account.
“The first thing that crosses your mind is, ‘What if a family member sees it? What would they think or say about me? What do they think about this specific situation?”
Deepfakes are highly realistic digital modifications of audio, video, or imagery created through artificial intelligence to depict people doing or saying things that do not represent the reality. This is a rapidly escalating variation of technology-driven gender abuse, a reality starkly illustrated by Kulola’s situation. Indeed a recently released report indicates that women are the primary subjects in 96% of the deepfake frameworks available for public download.
Kulola immediately alerted her social media followers that the video was fake, then began searching for help.
“One of the hardest parts was not knowing where to turn or what protections existed,” says Kulola.
Following the advice of her followers, she reached out to the National Cyber Incident Reporting Hub and other platforms. She anticipated that the authorities would promptly take down the content and penalize the perpetrators, but she was instead faced with a discouragingly tedious process.
“When you try to report these cases, it is email after email and a frustrating wait for a response. The paperwork gets confusing as organisations start asking questions like ‘Was it a deepfake or what kind of manipulation?’ and categorising them becomes tiring. I do not even know who I am reporting to,” she said.
The video was eventually removed by the person who had posted it, but the experience left Kulola wondering whether existing laws offer adequate legal protection.

Although Kenya possesses legal frameworks covering cybercrime, identity theft, and data protection, survivors of AI-driven abuse face major obstacles in securing prompt and clear legal solutions.
This gap remains despite the fact that the Computer Misuse and Cybercrimes Act penalizes cyber harassment and the publication of false details, while the Data Protection Act governs the exploitation of personal data.
Robbin Omeka Nyakundi, an intellectual property expert and CEO of the Anika Initiative, explains that these existing laws were simply not drafted with artificial intelligence in mind. For example, the Sexual Offences Act fails to address AI-generated content, leaving women whose likenesses are exploited to create explicit materials without straightforward legal recourse.
He explains that courts also lack established frameworks for handling such cases, and evidence challenges, such as proving which AI system generated specific content, remain unresolved.
Content creators like Kulola are banking on the Artificial Intelligence Bill, which aims to establish a legal framework for AI development and use. Among other provisions, it requires clear disclosure of synthetic media to prevent misuse and establishes oversight through an Artificial Intelligence Commissioner.
Wendy Kuyoh, an advocate of the High Court and an expert in technology law and data protection, welcomes the bill’s recognition of synthetic media as a specific risk.
“If somebody uses AI to make it appear that a Kenyan politician or a woman appeared in an intimate video, it would not be treated as online gossip but rather as AI-generated harm,” she explains.
The bill also requires consent to use someone’s image, voice, or likeness to create AI content.
“Legally, this allows victims to ask, ‘Did I authorise or consent to this?’ and ‘Was the content clearly marked as synthetic?’ If the answer is no, it indicates a clear violation,” explains Kuyoh.
“Now, as a recourse under the bill, victims can file a complaint with the AI regulator once the office is established,” she adds.
To prevent the spread of harmful synthetic media and the reputational damage caused by the misuse of a person’s image, the bill outlines ethical guidelines. Violations could result in a fine of up to one million shillings, a prison sentence of up to six months, or both.
Nevertheless, because the proposed legislation lacks civil remedies, survivors may not receive timely assistance. Omeka points out that victims of non-consensual intimate deepfake content face lengthy investigations and potential prosecutions that can take years, all while the damaging material continues to spread online.
He asserts that real protection demands civil mechanisms such as emergency injunctions and immediate takedown rights that operate at the rapid pace of the internet rather than the slow speed of criminal proceedings.

Furthermore, Omeka questions how effectively the proposed law can be enforced against international technology platforms. He highlights that many deepfakes targeting women and activists are hosted on foreign platforms like Meta, TikTok, and Telegram. Because the bill’s jurisdiction over these global entities remains ambiguous, offshore providers with minimal local presence may not comply with its regulations.
Kuyoh emphasizes that the bill should incorporate explicit protocols for preserving evidence, defined timelines for filing complaints, and victim compensation. The true measure of success, she notes, is not merely whether the law denounces deepfakes, but whether it empowers victims to quickly remove harmful content, address the source, and effectively repair the harm.
Additional apprehensions center on balancing individual protection with the freedom of expression. In a memorandum submitted to the Senate, the Bloggers Association of Kenya (BAKE) expresses support for regulating malicious AI content but maintains that the bill must explicitly exempt satire, parody, education, and artistic works to safeguard legitimate expression.
“Vague deepfake rules fail to distinguish between malicious fraud and legitimate satire or digital art,” reads the memorandum, pointing out that a comedian using a “face-swap” filter for a joke could face two years in prison.
“Do not allow the fight against deepfakes to become a tool for silencing the creative community,” reads part of the memorandum.
Kulola wants a law that protects survivors and provides clearer guidance on how to respond to such attacks.
“What I hope the AI law creates is a system where survivors do not have to feel powerless. Knowing where to report so that action will be taken and that the law recognises what happened to you is important. It is also key to know that you are not left to navigate the situation alone,” she adds.
Kulola’s experience highlights the need for legal protection and empowerment to navigate the challenges posed by emerging technologies. While the AI bill represents a step forward, survivors and advocates hope that AI policies will protect citizens and foster a culture of responsible AI use and digital citizenship.
This article was produced as part of the Gender+AI Reporting Fellowship, with support from the Africa Women’s Journalism Project (AWJP) in partnership with DW Akademie. The journalist used AI-assisted research tools to review and summarise relevant policy and research documents, identify patterns, surface data points for independent verification, and extract key statistics. All reporting, analysis, editorial decisions, fact-checking, and final wording were done by the reporter, in line with Talk Africa’s editorial standards.













