AI Biosecurity: East Africa’s Business Safety Test

 Artificial intelligence is usually sold to businesses as a tool for efficiency, prediction and growth. In health and biotechnology, the promise is even larger. AI can help researchers analyse complex data, identify promising drug candidates and shorten parts of the research process. Yet the same advance creates an uncomfortable business question. What happens when a commercially useful AI system also develops capabilities that could assist harmful biological activity? For East Africa, this is becoming a question about investment, corporate responsibility and whether existing regulators are looking at the same risk from different directions.

The immediate trigger for this discussion is Bill Gates’s essay, “The turbulent AI era is here. The choices we make now are critical,” published on Gates Notes on 26 August 2026. Gates argued that AI could bring major benefits in health while also creating serious dangers if powerful systems are misused. Reuters reported the same day that one of his concerns is the possibility of AI making biological attacks easier and that he favours stronger international oversight rather than leaving the problem entirely to voluntary industry action. His warning matters, but East African businesses should read it through a local question: what does such a risk mean for a region actively trying to attract AI, biotechnology and health innovation?

East Africa is not standing outside the AI economy. Kenya launched its Artificial Intelligence Strategy 2025–2030 in March 2025 around digital infrastructure, data and AI governance, and research, innovation and commercialisation. Rwanda’s National AI Policy presents responsible AI as part of an ambition to use the technology for economic growth and private-sector development. Uganda has been developing a National AI and Emerging Technologies Strategy through consultations involving health, agriculture, finance, education, manufacturing, tourism and research. At regional level, the East African Community adopted an AI Declaration in April 2026 supporting responsible national AI frameworks, regional research and commercialisation, and a Regional AI Technologies Fund.

Those policies make economic sense. Businesses want tools that can improve diagnosis, agricultural productivity, pharmaceutical research and logistics. Governments also want local companies to participate in global AI value chains. The difficulty is that the law often separates technology regulation from biological risk. An ICT ministry may think about data and digital infrastructure. A health regulator may think about medicines and patient safety. A biosafety or biosecurity body may focus on biological materials, research facilities and dangerous organisms. A company developing or importing an advanced AI model can sit between all three.

That is where the real business issue begins. The problem may not be an absence of relevant rules, but responsibility divided across rules created for different risks. A company can comply with data-protection requirements and still face a separate safety question about what its model can do. A laboratory can satisfy ordinary research procedures while relying on an external AI system whose capabilities were never assessed locally. Compliance in one part of the business may therefore create false comfort in another.

The World Health Organization offers a useful starting point. Its 2022 Global Guidance Framework for the Responsible Use of the Life Sciences treats dual-use research as a shared responsibility involving governments, researchers, funders, publishers, security actors and the private sector. “Dual use” means that knowledge or technology developed for a beneficial purpose may also be capable of harmful use. Importantly, Uganda became the first country in the WHO African Region to pilot that framework. WHO’s March 2025 report on the Uganda pilot expressly recognised the convergence of life sciences, biotechnology and artificial intelligence as both an opportunity and a source of risk.

That experience gives the region a practical foundation. East Africa already has experience asking how useful life-science research should be governed where knowledge may also be misused. The next challenge is to extend that thinking beyond the physical laboratory. An advanced AI system may become relevant to biosecurity before anyone has handled a biological sample or entered a research facility. The legal and commercial question can arise earlier, at the stage of model access, product design, deployment or procurement.

This suggests a different approach to business regulation. Instead of asking only what type of company is using AI, regulators and firms should ask what the system can actually do. A general office chatbot and a specialised model capable of supporting sophisticated biological research should not automatically receive the same scrutiny merely because both are called AI. The useful dividing line is capability. The greater the ability of a system to assist sensitive biological work, the stronger the case for enhanced testing, controlled access, monitoring and documented responsibility.

For businesses, this could become a new form of due diligence. Companies already investigate financial, cybersecurity, privacy and anti-corruption risks before major transactions or deployments. AI used in sensitive biological environments may require what could be called a bio-capability risk review. Its purpose would not be to turn company lawyers into scientists. It would force a governance question before deployment: does this system possess functions that create a biological safety or security concern, and if so, who is responsible for assessing and controlling that concern?

That question has contractual consequences. A hospital, research institute or biotechnology company buying access to an advanced AI service may need more than promises about uptime and data security. It may need information about safety testing, restrictions on dangerous uses, incident reporting, access controls and circumstances in which a risky function can be suspended. Investors may also ask whether a company working at the intersection of AI and life sciences has credible safeguards. What begins as a public-law concern can quickly become a financing and commercial risk.

The regional dimension is equally important. On 23 July 2026, the East African Community announced the operationalisation of the Uganda Virus Research Institute as the EAC Regional Centre of Excellence in Virology. The Centre is intended to strengthen advanced virology research, laboratory training, disease surveillance and preparedness for threats including Ebola and Marburg. This is a positive health-security development, but it also shows why AI governance and biological governance should not mature in separate rooms. A region investing in both advanced AI and advanced biological research has reason to connect the two regulatory conversations.

Regional coordination could also reduce fragmented compliance. An AI or biotechnology company serving several EAC markets may otherwise face different expectations in each jurisdiction, or no clear expectation at all. The EAC’s 2026 AI Declaration already recognises regional coordination in AI policy, research, infrastructure and commercialisation. Biosecurity should enter that discussion where advanced AI systems have meaningful biological capabilities. Common principles could establish a minimum regional understanding of risk assessment, corporate responsibility, reporting and cooperation without requiring identical national laws.

There is, however, a danger in regulating too aggressively. East Africa should not create rules that discourage legitimate medical research, agricultural biotechnology or technology investment. Treating every biological use of AI as inherently dangerous would be unrealistic and economically costly. The better approach is proportionate regulation. Low-risk uses should remain easy to deploy. Greater oversight should follow evidence of greater capability and potential harm. This protects innovation while recognising that some systems deserve closer scrutiny.

The deeper lesson is that AI biosecurity is becoming a business-law problem because commercial decisions determine which systems enter the market, who can access them, what safeguards are built into them and who bears the cost when controls fail. East Africa’s advantage is that much of its AI regulatory architecture is still being built. The region can connect AI governance with existing biosafety, biosecurity and public-health institutions before institutional separation becomes difficult to reverse.

Bill Gates’s warning should therefore be treated as a prompt rather than a policy blueprint. East Africa does not need to copy an American or European model, nor choose between innovation and safety. It needs rules suited to its own markets, research institutions and regulatory capacity. The useful starting point is simple: where an AI system acquires meaningful biological capabilities, responsibility should not disappear in the space between the technology company, the laboratory and the regulator. For East African business, that may become one of the most important tests of responsible AI growth.

Source note. This article is based on Bill Gates, “The turbulent AI era is here. The choices we make now are critical” (Gates Notes, 26 August 2026), Reuters reporting on Gates’s proposals for AI oversight and biological-risk controls, Kenya’s Artificial Intelligence Strategy 2025–2030, Rwanda’s National AI Policy, Uganda’s ongoing National AI and Emerging Technologies Strategy process, the East African Community Declaration on Artificial Intelligence of 2026, the World Health Organization’s Global Guidance Framework for the Responsible Use of the Life Sciences and its report on Uganda’s pilot of that framework, and the East African Community’s 2026 establishment of the Uganda Virus Research Institute as the EAC Regional Centre of Excellence in Virology.

Suggested citation

Ronald Serwanga, “AI Biosecurity: East Africa’s Business Safety Test” East Africa Legal Insight (1 September 2026).