Mulwana CTO Robert Jenkins says AI's real risk is missing regulations

post-title

Mulwana CIO, Robert Jenkins Sibbechai, believes the biggest gap in how organisations use AI isn't the technology itself but the absence of any rules governing what it's allowed to do with the data it's fed. He explains why this complicates cybersecurity and how a decade of oversharing on social media set the stage for it.

Robert Jenkins Sibbechai doesn't think the next big cyber threat will look anything like what IT departments spent the last twenty years preparing for. 

"It is no longer a place where I am attacking you to deny you a service, which is also still possible, but now attackers want data," he says."

That shift, in Robert’s view, didn't begin with AI at all. Rather, it began with how comfortable people became handing over information about themselves long before AI entered the picture. This shift, according to him, can be traced back to the rise of social media as a mass data-collection exercise that trained a generation to volunteer their location, habits and relationships without a second thought.

"People are sharing data about themselves with artificial intelligence. You don't even need to stalk them. They're already telling you where they are," he says.

Regulation, not resistance

Nevertheless, Robert is still a proponent of AI. In fact, his organisation has already adopted AI tools to speed up debugging, draft communications, and even to build a change-management tool in-house rather than buying one off the shelf. 

His worry around AI is the absence of any real boundary around what staff can share with AI systems while using them well. This is further worsened by the fact that no one knows where this data lands and neither can anyone affirm the security of that data and how it is used.

Even more frustrating to him is the fact that Internal data classifications offer little protection once an employee pastes something into a chat window. 

"Even in those classifications, you have no control over what a user will share with AI. The one thing I really need right now as a CIO is regulation on AI," he says. 

The cybersecurity issue

Further, Robert believes that AI has also complicated the cybersecurity landscape. 

"While I apply AI to protect my infrastructure, there's a guy out there who is applying AI to find how best they can attack me," he says. 

It's a world away from the threats he remembers from his student days where viruses could only spread as fast as someone could carry it from one flash disk to the next and there was some semblance of control.

At Mulwana, which spans three separate businesses, Robert has leaned on cloud-based, preconfigured systems partly because they let him monitor security posture across all three from a single view rather than running independent infrastructure for each. 

"I can have them in a bird's eye view instead of running three different data centres," he says.

Related articles

AI still needs a human touch, says Reliance Insurance IT head

At the CIO of the Future Summit in Dar es Salaam, tech leaders discussed AI's impact on daily operations. Among the panelists was Imani Mwanri, head of IT at Reliance Insurance, who urged tech leaders to embrace AI while warning against abandoning human oversight. 

Build AI around local priorities, says IALE institute CEO Dr Allen Mutono

At the CIO of the Future Summit held at the Dar es Salaam Serena on 11 September, Dr Allen Mutono delivered a keynote address that challenged IT leaders to think carefully about how AI is deployed in African organisations. He also urged CIOs to equip their teams for an AI-enabled workplace while keeping human judgement at the centre.

How AI is arming cybercriminals, according to four tech leaders

AI has not only made work easier for organisations, but it has also added a layer of complexity when dealing with cybersecurity. Across different conversations, Jacqueline Madara, head of ICT at Machakos University, Yuki Ouchi, head of digital products and e-commerce at KFC Kenya, James Kwezi, digital transformation manager at AFR Rwanda, and Alex Siboe Wekunda, CIO at Stanbic Bank Kenya, weigh in on how AI is reshaping the threat on the other side of the firewall.

Erick Ngwiri unpacks why organisations get data wrong 

Erick Ngwiri has spent 17 years helping organizations turn complex, scattered information into decisions they can act on. Within that time he has seen why most organisations still get data wrong, and what it takes to fix it, one clear problem at a time. 

How three tech leaders are building impact outside work 

Beyond the day to day activities involved in running a tech department, tech leaders also engage in different community building initiatives in their free time. Paul Kioi, head of technology at ICEA Lion , Paul Njoroge, head of ICT at Hand in Hand Eastern Africa, and Raymond Machary, principal ICT officer at Ocean Road Cancer Institute, reveal how their off-duty passions sharpen their leadership and uplift their communities. 

How Uzma Qureishi oversaw Aga Khan Hospital's bold EHR leap

In 2022, Uzma Qureishi, Senior Manager of EHR Operations at Aga Khan Hospital Nairobi, led one of the boldest bets of her career, overseeing the institution's transition to a paperless system. The transition wrote the hospital into the region's history books as the first hospital in East Africa to run a full Electronic Health Record (EHR) system, namely MEDITECH Expanse.

IT heads weigh in on cybersecurity's talent problem 

A 2025 PwC report placed knowledge and skills gaps among the top challenges organisations face when implementing AI for cyber defence. Mpesa Africa’s head of cybersecurity Tim Theuri, Ecobank Uganda’s head of IT Juliet Kyomugisha and WASREB’s head of IT Brenda Anzagi weigh in on the challenge of finding talent in IT.

Top