The Enforceability Premium: Reading the 2026 Global Index on Responsible AI
What the GIRAI 2nd Edition means for African financial regulators, the fintechs they license, and the capital watching both.
The second edition of the Global Index on Responsible AI (GIRAI), published this year by the Global Center on AI Governance, is the most comprehensive measurement of AI governance ever assembled: 135 countries, more than 68,000 data points, gathered by country-level researchers working in their own languages and legal systems. Its headline finding is blunt. Nearly every government now professes a commitment to responsible AI 128 of 135 show some form of it , yet the global average score is roughly 35 out of 100, and where frameworks exist, evidence of implementation appears in only 55% of cases. In the Global South, that falls to 45%. In Africa, the regional implementation ratio is 40%, the lowest of any region measured.
Most coverage of the Index will dwell on that gap between promise and protection. For readers of this publication, the more consequential finding sits one layer down, in the data on enforceability and it explains why a piece of Kenyan capital markets regulation may matter more to Africa's AI trajectory than any national AI strategy published this decade.
Soft law is cheap, and the market knows it!
Since the first edition in 2024, Global South countries have driven much of the world's expansion in AI governance. The average number of policy areas covered by frameworks in these countries rose 83%, from 2.5 to 4.7. On paper, this is convergence with the Global North, whose coverage grew 35% over the same period.
But the composition of that growth tells a different story. In the Global South, 78% of the framework cases the Index recorded are non-binding strategies, white papers, guidelines, voluntary principles. Of the 76 enforceability gains recorded between editions worldwide, Global North countries account for 67. The EU AI Act alone drives 51 of them. The Global South contributed nine.
Anyone who has worked in financial markets will recognise the pattern, because finance prices this distinction instinctively. A strategy document is a signal; a licensing regime with supervisory teeth is a constraint. Compliance budgets, product roadmaps, and investment committee memos respond to the second, not the first. The GIRAI authors describe a "growing governance asymmetry" in which Global South countries adopt the language of responsible AI without the legal instruments to make it enforceable. In capital markets terms: the region is long on disclosure of intent and short on covenants.
The report's own explanation is worth taking seriously. This is not a deficit of legal imagination Peru's Supreme Decree 115-2025-PCM establishes binding obligations across 13 of the Index's indicators, the widest of any Global South country, and Uruguay has legislated platform-worker rights that most of Europe has not. The constraint is bargaining power. Governments courting AI investment, dependent on infrastructure and models they cannot yet replace, hesitate to bind the actors they are trying to attract.
Kenya's position: mid-table, and instructively lopsided
Kenya scores 39.53 in the 2026 edition, ranking 50th globally and third in Africa, behind Nigeria (45.93) and Egypt (41.26). The average African score is 21.79 the lowest regional mean in the Index , so Kenya sits well above its regional peers while remaining far from the European frontier, where Norway leads at 74.20, followed by Italy, Ireland, France, and the Netherlands.
The dimensional breakdown is where it gets interesting. Kenya's strongest showings are in Ethics and Sustainability (52.91) and AI Use in Public Service (47.94). Its weakest, strikingly, is Inclusion and Diversity at 22.88 a curious result for a country whose National AI Strategy 2025–2030 makes cultural preservation a guiding principle and explicitly positions local-language NLP as a tool for democratising access. The Index gives Kenya credit for that strategy's framing, citing its ambition to build chatbots in local languages and enrich AI systems with Kenyan cultural values. But a strategy is precisely the kind of non-binding instrument the enforceability data discounts, and the score reflects it.
Kenya also appears in the report in a less flattering, more revealing role: as the instructive example of AI's material constraints. The Index cites Kenya's decision to discontinue a large-scale geothermal data centre partnership, a facility whose projected energy demand approached one-third of the country's current generation capacity. For infrastructure financiers, that single data point should reframe diligence on African data-centre assets. Energy availability is no longer an operating assumption; it is the binding constraint, and sovereign counterparties have now demonstrated willingness to walk away from billion-dollar commitments over it.
The instrument the report is asking for already exists
The GIRAI's first two priorities for the next phase of responsible AI are to hold public-sector AI to a higher standard and to establish "binding floors in high-risk areas." Its authors are candid that omnibus national AI laws remain rare and slow, and that most Global South frameworks cannot, on their own, "provide binding rights, impose legal obligations, or hold public and private actors accountable."
Here is the argument the AI governance community has largely missed, and where African financial regulators deserve more credit than the aggregate scores suggest: sectoral financial regulation is quietly building the binding floors the Index calls for.
Kenya's Capital Markets Authority is the clearest case. Legal Notice 197 of 2025 establishes a licensing regime for robo-advisory and algorithm-driven investment services, with a compliance deadline of December 2026. It is binding. It attaches to a supervisor with enforcement machinery, examination powers, and licence-revocation authority that already exist no new oversight body needs to be legislated, funded, and staffed. It imposes exactly the obligations the GIRAI finds scarce: algorithmic accountability, disclosure to the regulator, human oversight requirements, and consumer redress channels through an established complaints architecture.
Measured against the Index's own framework, an instrument like LN 197 does more enforceable work in its domain than most national AI strategies do across all of theirs.
And this is not a Kenyan idiosyncrasy it is a continental pattern, and the strongest evidence for the thesis is that the same move is happening independently in market after market, each time through a regulator that already exists.
Look at Nigeria, the Index's top-ranked African country. Its 45.93 owes far more to binding instruments than to its (non-binding) national AI strategy. The Nigeria Data Protection Commission's 2025 General Application and Implementation Directive now mandates data-protection impact assessments for high-risk processing meaning a fintech deploying an AI credit model without a documented DPIA is already non-compliant. The Federal Competition and Consumer Protection Commission's 2025 digital-lending rules go further, explicitly targeting opaque "black box" lending by requiring transparency in how rates are set and prohibiting discriminatory pricing. Most strikingly, the Central Bank of Nigeria has signalled a move toward SupTech using its own AI to audit fintech algorithms for bias and stability in real time. That is a regulator not merely writing an enforceable floor but building the machinery to police it, and none of it required a new AI-specific institution.
Ghana is running almost the same play on almost the same clock. Under Notice BG/GOV/SEC/2025/35, the Bank of Ghana began licensing digital credit service providers from November 2025, with unlicensed lenders given until June 2026 to register or face enforcement a structural mirror of Nairobi's December 2026 deadline, issued by a central bank rather than a securities regulator but doing the identical work. Tanzania got there earlier still: the Bank of Tanzania's 2021 Digital Credit Regulations already require every digital lender to register and report on ownership, interest charges, and complaint resolution.
The pattern suggests a thesis for African AI governance that the Index gestures at but does not quite name: the fastest route to binding protection in the Global South runs through regulators that already have teeth securities authorities, central banks, competition commissions, data-protection commissions not through new AI-specific institutions that must be built from nothing. Only 28 countries worldwide have independent AI oversight bodies. Nearly every country has a securities regulator, a banking supervisor, and increasingly a data protection authority. In Kenya it is the CMA. In Nigeria, the NDPC, FCCPC, and CBN. In Ghana, the central bank. Different doors, same room.
There is a counterargument worth acknowledging. Sectoral regulation is, by design, partial. A robo-advisory licensing regime does nothing for algorithmic hiring, predictive policing, or public-sector welfare systems and the Index's grimmest findings sit precisely there. Only 18% of countries require disclosure of their governments' own algorithmic systems; in Africa, framework coverage of that indicator is zero. Sectoral floors can also produce the fragmentation the report warns about, where protection depends on which regulator happens to have jurisdiction. The point is not that financial regulators can substitute for comprehensive AI governance. It is that they are, right now, the most functional enforcement infrastructure Africa has and the December 2026 compliance deadline in Nairobi will generate implementation evidence of exactly the kind the Index's third edition, covering October 2025 through September 2027, is designed to capture.
What financial-sector readers should take from the Index
Three implications stand out for this publication's audience.
First, enforceability is becoming a screenable variable. The GIRAI dataset is open and free at global-index.ai, disaggregated by country, dimension, and pillar. For investors assessing regulatory risk in African fintech or for fintechs deciding where a compliance-first posture confers advantage the binding-versus-non-binding coverage data is a genuinely new input. A market with binding algorithmic accountability rules and a functioning supervisor is a different risk (and a different moat for compliant incumbents) than a market with an aspirational strategy.
Second, the labour findings are an underpriced ESG exposure. Labour protection frameworks exist in only 5% of African countries , Egypt and Ethiopia , while the World Bank estimates 154 to 435 million online gig workers globally, with Global South demand growing fastest. The data labellers and content moderators sustaining AI supply chains, many of them in Nairobi, remain almost wholly unprotected. For investors with portfolio exposure to BPO and data-services companies, the regulatory direction of travel signalled by Mexico, Uruguay, Chile, and Singapore all now legislating on algorithmic management is the leading indicator.
Third, the material economy of AI is now a governance issue with balance-sheet consequences. The Index finds only 27% of countries have any framework on AI's environmental impact, and 83% of those are non-binding. Kenya's suspended data centre shows what happens when the gap between AI infrastructure ambition and energy reality closes abruptly. Viet Nam's binding power-usage-effectiveness standard for greenfield data centres (PUE below 1.4) offers a preview of the disclosure and efficiency obligations likely to reach African markets and the projects that anticipate them will price better.
The GIRAI's authors close by arguing that responsible AI must move "from promise to practice." African financial regulators the CMA in Nairobi, the NDPC, FCCPC and CBN in Abuja, the Bank of Ghana in Accra with imperfect coverage but real enforcement power, are already several steps down that road, in more markets than the aggregate scores reveal. The Index doesn't credit them for it yet. Its third edition, capturing exactly the window in which these deadlines bite, might.
The Global Index on Responsible AI, 2nd Edition (2026), was produced by the Global Center on AI Governance with data covering 1 November 2023 to 30 September 2025. The full dataset for all 135 countries is freely available at global-index.ai. Citation: Adams, R., Adeleke, F., Alayande, A., Abdella, S.E., Florido, A., Junck, L., & Grossman, N. (2026). Global Index on Responsible AI 2026 (2nd Edition). South Africa: Global Center on AI Governance, CC BY 4.0.
Frontier Finance AI covers artificial intelligence and capital markets across Africa and Asia.