
Uganda is writing a national AI policy. The Ministry of ICT is leading it, a national stakeholders consultation on UNESCO’s AI Readiness Assessment Methodology was held in May 2026, and civil society has already begun arguing about what it should contain. None of that gives a Ugandan business a date to plan against. What it does give is roughly eighteen months of warning about the shape of what is coming, and the organisations that use the warning will spend a fraction of what the ones who wait will spend.
Key Takeaways
- Uganda has no dedicated AI statute. Until one arrives, the Data Protection and Privacy Act 2019 and its 2021 Regulations are the live instrument governing what AI may do with information about people.
- The national AI policy is in drafting through the Ministry of ICT, with a UNESCO readiness consultation held in May 2026 and civil society pressing for a rights-centred approach.
- Comparable frameworks elsewhere converge on the same features: risk classification, human oversight in sensitive sectors, documentation, transparency and a route of redress for people affected by automated decisions.
- Every one of those features is cheaper to build now than to retrofit, and four of them are things a well-run organisation would want anyway.
- The single highest-return action available today is unglamorous: know what you hold, know who owns it, and know whether you are registered with the Personal Data Protection Office.
Where things actually stand
Three things are true at once, and confusing them is where most of the bad advice in this market comes from.
First, there is no AI law in Uganda. Anyone telling you that your AI use is currently illegal, or currently unregulated, is wrong in both directions.
Second, there is a data protection law, and it applies fully. The Data Protection and Privacy Act 2019, read with the Data Protection and Privacy Regulations 2021, governs the processing of personal data regardless of which tool does the processing. A large language model is not an exemption. The principles of lawful and fair processing, purpose limitation, minimisation, accuracy, security and retention apply to a chat window exactly as they apply to a spreadsheet.
Third, a national AI policy is being written. The Ministry of ICT is leading it. A national stakeholders consultation on the UNESCO AI Readiness Assessment Methodology took place in May 2026. CIPESA, the regional ICT policy organisation, has publicly urged a rights-centred approach to the strategy. This is a live process with genuine engagement, not an announcement.
What the policy will probably require
Nobody outside the drafting process knows the text. But AI frameworks across jurisdictions have converged on a recognisable set of features, and the UNESCO methodology Uganda is using as its readiness lens pushes in the same direction. It is reasonable to plan against these, with the caveat that any of them could land differently:
| Likely feature | What it would mean for an ordinary organisation |
|---|---|
| Risk classification of AI uses | Most business uses would sit in a low or minimal tier with light obligations. The ones that touch credit, employment, health, education or security would not |
| Human oversight in sensitive sectors | A named person must be able to review and reverse a consequential decision. Many organisations already believe they do this and could not evidence it |
| Documentation and record-keeping | What system, what data, what purpose, who approved it. A register, in other words |
| Transparency | Telling people when they are dealing with a machine, and when a decision about them was informed by one |
| Redress | A route for someone to challenge an automated outcome and have a person look at it |
| Registration or notification for higher-risk systems | Uganda already operates a registration regime for data controllers and processors, so an AI equivalent would not be a new administrative concept here |
Notice how many of those are governance rather than technology. That is the point. Almost nothing on that list requires a different tool. Most of it requires somebody to write down what is already happening and put a name against it.
The obligation that already exists and that most organisations have not resolved
Section 29 of the Data Protection and Privacy Act 2019, read with regulation 15(1) of the 2021 Regulations, requires data collectors, data processors and data controllers to register with the Personal Data Protection Office. On the published position there is no size threshold. A sole trader keeping customer phone numbers falls under the same requirement as a bank, and it reaches private companies, NGOs, public bodies and foreign entities processing the personal data of people in Uganda.
Registration runs for one year, with renewal to be applied for within three months before expiry, and an annual compliance report to the Office within 90 days after the end of each financial year. Failure to register is an offence, liable on conviction to a fine or imprisonment not exceeding three months, or both.
Regulator practice on the scope of registration has moved since the Regulations were made, and guidance has been issued and revised, so the sensible step is to check the Office’s current published position and take advice on whether and in what capacity your organisation must register. What is not sensible is leaving an obligation with a criminal penalty attached in the “we should look into that” pile while investing in AI tooling.
Five things worth doing before the policy lands
1. Count what you are already doing
Ask your teams, without blame, which AI tools they use. The answer is always longer than management expects, and it always includes tools nobody thinks of as AI: meeting transcription, translation, the assistant inside the office suite. You cannot govern what you have not counted, and this exercise takes an afternoon.
2. Name two people
Someone who owns AI decisions, and someone who owns data protection. They can be the same person in a small organisation. What matters is that the names are written down, because every obligation in every likely version of the policy needs a person to attach to.
3. Write the red list
One page saying what may never be entered into an AI tool: personal data about identifiable people, special categories such as health and financial position, credentials, unsigned contracts, and anything a client or donor gave you under terms that limit its use. This single page prevents most real incidents, and it is useful the day you adopt it rather than the day a law commences.
4. Put a human in front of consequential decisions
If your organisation uses any system to rank, score or screen people, establish now that a named person reviews the individual cases and that the review is recorded. Every plausible version of the coming policy will require this, every serious donor already expects it, and it is the right thing to do irrespective of both.
5. Resolve the registration question
Check the Personal Data Protection Office’s current guidance, establish your position, and diarise the renewal. This is the one item on the list with a criminal penalty attached and it is entirely administrative.
What not to do
Do not wait. The temptation to pause AI adoption until the rules are clear is understandable and expensive, because the preparation the rules will demand is the same preparation that makes AI adoption work in the first place: knowing your data, naming an owner, keeping a register, putting a person in front of decisions about people. An organisation that does those four things is both better governed and better at deploying AI, in that order.
Do not buy a compliance product for a law that does not exist yet. Do not commission a strategy document. And do not assume that because there is no AI statute, there is no exposure. The 2019 Act is not a placeholder. It is the law, it has been for seven years, and it is what a regulator or a court would apply to an AI incident tomorrow morning.
The honest summary
A national AI policy is coming, its shape is guessable, and none of the preparation it will demand is wasted if the final text surprises everyone. The organisations that will find compliance cheap are the ones that spent the waiting period writing down what they already do. The ones that will find it expensive are the ones that spent it waiting.
Sources
- Data Protection and Privacy Act 2019 (Uganda), in particular the processing principles and section 29 on registration.
- Data Protection and Privacy Regulations 2021, regulation 15(1).
- UNESCO, national stakeholders consultation on the AI Readiness Assessment Methodology, Uganda, May 2026.
- CIPESA, commentary urging a rights-centred approach to Uganda’s AI strategy, May 2026.
- Published legal analyses of Uganda’s expected AI regulatory direction, including risk classification, human oversight requirements and redress mechanisms.
Position stated as at 21 August 2026. This is not legal advice. Regulator guidance changes; verify the current position before acting.
