AI Biosecurity: East Africa’s Business Safety Test
Artificial intelligence is usually sold to businesses as a tool for efficiency, prediction and growth. In health and biotechnology, the promise is even larger. AI can help researchers analyse complex data, identify promising drug candidates and shorten parts of the research process. Yet the same advance creates an uncomfortable business question. What happens when a commercially useful AI system also develops capabilities that could assist harmful biological activity? For East Africa, this is becoming a question about investment, corporate responsibility and whether existing regulators are looking at the same risk from different directions.
The immediate trigger for this discussion is Bill Gates’s essay,
“The turbulent AI era is here. The choices we make now are critical,” published
on Gates Notes on 26 August 2026. Gates argued that AI could bring major
benefits in health while also creating serious dangers if powerful systems are
misused. Reuters reported the same day that one of his concerns is the
possibility of AI making biological attacks easier and that he favours stronger
international oversight rather than leaving the problem entirely to voluntary
industry action. His warning matters, but East African businesses should read
it through a local question: what does such a risk mean for a region actively
trying to attract AI, biotechnology and health innovation?
East Africa is not standing outside the AI economy. Kenya launched
its Artificial Intelligence Strategy 2025–2030 in March 2025 around digital
infrastructure, data and AI governance, and research, innovation and
commercialisation. Rwanda’s National AI Policy presents responsible AI as part
of an ambition to use the technology for economic growth and private-sector
development. Uganda has been developing a National AI and Emerging Technologies
Strategy through consultations involving health, agriculture, finance,
education, manufacturing, tourism and research. At regional level, the East
African Community adopted an AI Declaration in April 2026 supporting
responsible national AI frameworks, regional research and commercialisation,
and a Regional AI Technologies Fund.
Those policies make economic sense. Businesses want tools that can
improve diagnosis, agricultural productivity, pharmaceutical research and
logistics. Governments also want local companies to participate in global AI
value chains. The difficulty is that the law often separates technology
regulation from biological risk. An ICT ministry may think about data and
digital infrastructure. A health regulator may think about medicines and
patient safety. A biosafety or biosecurity body may focus on biological materials,
research facilities and dangerous organisms. A company developing or importing
an advanced AI model can sit between all three.
That is where the real business issue begins. The problem may not be
an absence of relevant rules, but responsibility divided across rules created
for different risks. A company can comply with data-protection requirements and
still face a separate safety question about what its model can do. A laboratory
can satisfy ordinary research procedures while relying on an external AI system
whose capabilities were never assessed locally. Compliance in one part of the
business may therefore create false comfort in another.
The World Health Organization offers a useful starting point. Its
2022 Global Guidance Framework for the Responsible Use of the Life Sciences
treats dual-use research as a shared responsibility involving governments,
researchers, funders, publishers, security actors and the private sector. “Dual
use” means that knowledge or technology developed for a beneficial purpose may
also be capable of harmful use. Importantly, Uganda became the first country in
the WHO African Region to pilot that framework. WHO’s March 2025 report on the
Uganda pilot expressly recognised the convergence of life sciences,
biotechnology and artificial intelligence as both an opportunity and a source
of risk.
That experience gives the region a practical foundation. East Africa
already has experience asking how useful life-science research should be
governed where knowledge may also be misused. The next challenge is to extend
that thinking beyond the physical laboratory. An advanced AI system may become
relevant to biosecurity before anyone has handled a biological sample or
entered a research facility. The legal and commercial question can arise
earlier, at the stage of model access, product design, deployment or
procurement.
This suggests a different approach to business regulation. Instead
of asking only what type of company is using AI, regulators and firms should
ask what the system can actually do. A general office chatbot and a specialised
model capable of supporting sophisticated biological research should not
automatically receive the same scrutiny merely because both are called AI. The
useful dividing line is capability. The greater the ability of a system to
assist sensitive biological work, the stronger the case for enhanced testing,
controlled access, monitoring and documented responsibility.
For businesses, this could become a new form of due diligence.
Companies already investigate financial, cybersecurity, privacy and
anti-corruption risks before major transactions or deployments. AI used in
sensitive biological environments may require what could be called a bio-capability
risk review. Its purpose would not be to turn company lawyers into
scientists. It would force a governance question before deployment: does this
system possess functions that create a biological safety or security concern,
and if so, who is responsible for assessing and controlling that concern?
That question has contractual consequences. A hospital, research
institute or biotechnology company buying access to an advanced AI service may
need more than promises about uptime and data security. It may need information
about safety testing, restrictions on dangerous uses, incident reporting,
access controls and circumstances in which a risky function can be suspended.
Investors may also ask whether a company working at the intersection of AI and
life sciences has credible safeguards. What begins as a public-law concern can
quickly become a financing and commercial risk.
The regional dimension is equally important. On 23 July 2026, the
East African Community announced the operationalisation of the Uganda Virus
Research Institute as the EAC Regional Centre of Excellence in Virology. The
Centre is intended to strengthen advanced virology research, laboratory
training, disease surveillance and preparedness for threats including Ebola and
Marburg. This is a positive health-security development, but it also shows why
AI governance and biological governance should not mature in separate rooms. A
region investing in both advanced AI and advanced biological research has
reason to connect the two regulatory conversations.
Regional coordination could also reduce fragmented compliance. An AI
or biotechnology company serving several EAC markets may otherwise face
different expectations in each jurisdiction, or no clear expectation at all.
The EAC’s 2026 AI Declaration already recognises regional coordination in AI
policy, research, infrastructure and commercialisation. Biosecurity should
enter that discussion where advanced AI systems have meaningful biological
capabilities. Common principles could establish a minimum regional understanding
of risk assessment, corporate responsibility, reporting and cooperation without
requiring identical national laws.
There is, however, a danger in regulating too aggressively. East
Africa should not create rules that discourage legitimate medical research,
agricultural biotechnology or technology investment. Treating every biological
use of AI as inherently dangerous would be unrealistic and economically costly.
The better approach is proportionate regulation. Low-risk uses should remain
easy to deploy. Greater oversight should follow evidence of greater capability
and potential harm. This protects innovation while recognising that some
systems deserve closer scrutiny.
The deeper lesson is that AI biosecurity is becoming a business-law
problem because commercial decisions determine which systems enter the market,
who can access them, what safeguards are built into them and who bears the cost
when controls fail. East Africa’s advantage is that much of its AI regulatory
architecture is still being built. The region can connect AI governance with
existing biosafety, biosecurity and public-health institutions before
institutional separation becomes difficult to reverse.
Bill Gates’s warning should therefore be treated as a prompt rather
than a policy blueprint. East Africa does not need to copy an American or
European model, nor choose between innovation and safety. It needs rules suited
to its own markets, research institutions and regulatory capacity. The useful
starting point is simple: where an AI system acquires meaningful biological
capabilities, responsibility should not disappear in the space between the
technology company, the laboratory and the regulator. For East African
business, that may become one of the most important tests of responsible AI
growth.
Source note. This article is based on Bill Gates, “The turbulent AI
era is here. The choices we make now are critical” (Gates Notes, 26 August
2026), Reuters reporting on Gates’s proposals for AI oversight and
biological-risk controls, Kenya’s Artificial Intelligence Strategy 2025–2030,
Rwanda’s National AI Policy, Uganda’s ongoing National AI and Emerging
Technologies Strategy process, the East African Community Declaration on
Artificial Intelligence of 2026, the World Health Organization’s Global Guidance
Framework for the Responsible Use of the Life Sciences and its report on
Uganda’s pilot of that framework, and the East African Community’s 2026
establishment of the Uganda Virus Research Institute as the EAC Regional Centre
of Excellence in Virology.
Suggested citation
Ronald Serwanga, “AI
Biosecurity: East Africa’s Business Safety Test” East Africa Legal Insight (1
September 2026).