Kenya Expanded Its Cybercrime Law. The Courts Have Already Drawn a Boundary.
Kenya’s Computer Misuse and Cybercrimes (Amendment) Act No. 17 of 2025 expanded definitions, offences and court powers. In July 2026, the High Court struck down two overbroad provisions, drawing an important boundary between cyber enforcement and constitutional rights.
The amendment was assented to on 15 October 2025 and commenced on 4 November. It added definitions for cybercrime, identity theft, computer misuse and virtual assets, revised offences and introduced additional orders involving online systems and content.
The current position cannot be understood by reading the enactment alone. A compliance summary that still presents every 2025 provision as intact is already stale.
The law reaches modern attack and fraud patterns
The amendments broaden the statutory vocabulary around unauthorised activity, identity misuse, systems, virtual assets and cyber-enabled crime. They also increase the relevance of the Act to mobile money, platform abuse and offences where computers amplify harm.
For security teams, legal definitions affect evidence handling and escalation. Incident records should distinguish unauthorised access, interference, fraud, identity misuse and other conduct without making premature conclusions about criminal liability.
Court orders remain a key enforcement path
The amended framework allows courts to order removal of specified unlawful content or closure and deactivation of systems, websites or devices in defined cases. An authorised person may apply to court for such orders.
This judicial path matters. It creates a point at which necessity, scope, evidence and safeguards can be tested rather than leaving a platform or network operator to act on an informal demand.
The administrative blocking power did not survive
On 2 July 2026, the High Court struck down section 6(1)(j)(a), which had empowered the National Computer and Cybercrimes Coordination Committee to disable access to websites and applications suspected of carrying specified unlawful material.
The Court found that the provision gave an administrative body sweeping censorship power without adequate judicial safeguards. It treated the mechanism as unconstitutional prior restraint affecting expression and media freedom.
A vague cyber-harassment offence also fell
The Court also invalidated section 27(1)(b), which criminalised communication considered likely to cause another person to commit suicide. The ruling found the wording vague and speculative, without sufficient precision for a criminal offence.
The judgment does not erase the cybercrime law. It removes two provisions while leaving the remaining framework to operate. Platform, legal and security teams should update playbooks rather than treating the litigation as an all-or-nothing outcome.
What organisations should do now
- Update legal summaries to reflect the July 2026 judgment.
- Route content-removal and system-disabling demands through legal review.
- Require a clear statutory or court basis before taking restrictive action.
- Preserve evidence without expanding access beyond what is authorised.
- Train incident teams on the amended offence definitions.
- Monitor any appeal, replacement amendment or new AI-focused reform.
Cybersecurity law needs a version history
Kenya’s experience shows why legislative monitoring cannot stop at assent. Regulations, commencement, interim orders and constitutional judgments can change the operational position quickly. The most reliable control is a maintained legal version mapped to concrete response actions.
Sources and legal texts
- Kenya Law: Computer Misuse and Cybercrimes (Amendment) Act No. 17 of 2025
- Kenya Law: consolidated Computer Misuse and Cybercrimes Act
- ICJ Kenya: summary of the High Court judgment of 2 July 2026
This article provides general information and is not legal advice.
Continue the series: Africa Cyber & Digital Law Series index


