Top
MAMBO ExplainsExplainers

Kenya's emerging technology sandbox deadline is here. What happens next?

The CA sandbox gives selected innovators a supervised route to test AI, 5G, 6G, IoT, cybersecurity and digital-content products before full market deployment.

Kenyan technology product entering a regulated sandbox for supervised AI, telecom and cybersecurity testing.
AI-generated illustration by tecMAMBO

Kenya's Communications Authority set 30 July 2026 as the final application date for its 2026/27 Emerging Technologies Regulatory Sandbox.

The programme gives selected innovators a controlled environment in which to test products that do not fit neatly inside existing ICT rules. The target areas include artificial intelligence, 5G and 6G applications, IoT and machine-to-machine communication, cybersecurity, spectrum technologies, digital broadcasting and over-the-top services.

A sandbox can shorten the journey from experimental product to lawful commercial service. It is not permission to ignore regulation while wearing a startup hoodie.

What you need to know

  • Applications were invited from innovators, researchers and technology companies.
  • The stated deadline is 30 July 2026.
  • Applicants need a Kenyan company or an equivalent ICT licence from another jurisdiction.
  • Successful products are expected to enter the Kenyan market after testing.
  • The CA evaluates consumer benefit, test readiness, risk controls and the need for supervised testing.
  • Acceptance does not a commercial licence.

What is a regulatory sandbox?

A regulatory sandbox is a supervised testing programme. It allows a company to trial a new product with a limited group of users, controlled scope and agreed safeguards while the regulator studies how existing law applies.

That is useful when technology moves faster than formal rulemaking.

A startup testing an AI-managed telecom service, dynamic spectrum-sharing system or new cybersecurity product may face rules written before the product category existed. Launching without guidance risks enforcement. Waiting for a complete legal framework can kill the experiment before anyone knows whether it works.

The sandbox creates a middle path. The company explains what it wants to test, who may be affected, which risks exist and what success looks like. The regulator sets boundaries and observes the result.

Which technologies are in scope?

The CA's invitation covered 5G and 6G applications, IoT, M2M communications, OTT services, digital broadcasting, cybersecurity, spectrum management, AI and accessibility technologies.

The breadth matters because modern products cross sectors. A connected agriculture sensor may use licensed spectrum, cloud software, AI forecasting and mobile payments. A streaming platform may raise questions about broadcasting, content rules, data protection and network capacity.

The sandbox lets the regulator inspect the system rather than pretending each component lives alone.

Who was eligible to apply?

Applicants need to show more than an interesting idea.

The CA expects an incorporated Kenyan company or a business licensed by an equivalent ICT regulator elsewhere. The applicant must intend to introduce the product in Kenya after a successful sandbox exit.

The application asks for registration records, founder or director information, management CVs, a business model and an exit strategy. Most importantly, the product should be ready for a real test.

A sandbox is not an incubator for an unfinished pitch deck. The applicant must describe test scenarios, expected outcomes, consumer protection measures, risks and mitigation.

What happens after the deadline?

The CA first screens eligibility and evaluates applications. Selected companies then agree on a test plan that can define the product, user group, test duration, data to collect, consumer disclosures, security controls, incident reporting, performance measures and exit requirements.

During testing, the regulator can request information, modify conditions or stop the trial if risks become unacceptable.

At the end, the product may proceed toward commercial approval, require further changes or fail to exit successfully. A credible sandbox must be willing to say no.

Why startups should care

Regulatory uncertainty is expensive. Investors hesitate when a founder cannot explain whether a product is legal. Enterprise customers avoid tools that might be blocked. Engineering teams spend money before discovering that licensing or data rules make the model unworkable.

Early regulatory contact can expose those problems while they are still fixable. A sandbox can also create evidence about safety, consumer benefit and operational risk.

Still, founders should not treat regulator access as endorsement. The CA's presence does not make the product secure, profitable or desirable.

What the CA should publish

After selection and testing, the CA should publish the number of applications, broad technology categories, selection criteria, consumer safeguards, non-confidential outcomes, exit decisions and policy lessons.

Confidential business information deserves protection. Complete opacity does not. A sandbox can otherwise become a private consultation service for a few connected firms.

What a strong applicant should prepare now

Even after the formal application deadline, the preparation checklist remains useful for future sandbox calls and any follow-up questions from the regulator.

A serious applicant should be able to explain the product without hiding behind technical vocabulary. What problem does it solve? Which rule is uncertain? Why can the product not be tested safely through an ordinary commercial launch? Which users are exposed to risk, and what compensation or correction process exists if something goes wrong?

The company should also prepare evidence around data protection, cybersecurity, accessibility and consumer communication. A product that handles personal information should identify the lawful basis for collection, data-retention period, access controls and deletion process. A network or IoT product should define how security patches are delivered and how compromised devices are removed.

Financial planning matters too. Sandbox testing can require legal work, engineering changes, reporting and customer support without producing normal commercial revenue. Founders should budget for the test itself and for the changes the CA may require before market entry.

The strongest applications will not argue that regulation is an obstacle. They will show that supervised testing is the fastest credible way to answer a specific regulatory question.

The tecMAMBO take

Kenya's technology sandbox is a promising tool, but its value begins after applications close.

The real questions are which companies are selected, how risks are measured, whether users understand that they are part of a test and what the CA learns.

A sandbox should reduce uncertainty without reducing accountability.

Done well, it gives innovation a legal runway. Done badly, it becomes a waiting room with better branding.

FAQ

When was the Kenya technology sandbox deadline?

The Communications Authority set 30 July 2026 as the deadline for the 2026/27 application window.

Can an individual developer apply?

The published eligibility information expects a Kenyan-incorporated company or an applicant licensed by an equivalent ICT regulator.

Does sandbox admission provide a commercial licence?

No. Admission permits supervised testing under agreed conditions. Further approval may be required before full deployment.

Which technologies can enter the sandbox?

The call includes AI, 5G and 6G, IoT, M2M, cybersecurity, OTT services, broadcasting, spectrum technology and accessibility.

Can the CA stop a sandbox test?

Yes. A regulator can impose conditions, require changes or stop a test when risks or non-compliance justify intervention.

Sources

Ask MAMBO

Have a plain-English question about this topic? Send it in and we may answer it in a future guide.

Ask a question