Artificial intelligence has moved faster than almost anyone predicted. The early AI models served as search engines and fact checkers, however, today, systems like ChatGPT and Claude write code, draft contracts, diagnose symptoms, and increasingly act on our behalf such as booking flights, managing schedules, executing multi-step tasks with minimal human oversight. This shift, from AI that answers questions to AI that takes action, is why the conversation around AI safety has become urgent.
AI safety, in simple words, is the effort to ensure that AI systems behave as intended, remain under meaningful human control, and don't produce outcomes that harm individuals, institutions, or society. It is not one discipline but several woven together. It covers areas such as technical safety (making models behave reliably and predictably), accountability (knowing who answers for an AI system's decisions), and governance (the laws, standards, and institutions that keep all of this in check).
Most public conversation about AI safety jumps straight to the more large scale deployment of AI models such as autonomous weapons, runaway superintelligence and mass unemployment. Those are real long-term concerns. But the more immediate, practical risks are quieter. They are evident in our day to day activities. These include concerns such as a hiring algorithm trained on biased data, a medical AI making unexplainable decisions, a country with no legal framework to hold an AI system accountable when it causes harm. These are the gaps that need attention today. What follows lays out three of the most important gaps, followed by a real-world look at what happens when governance doesn't keep pace with technology.
Gap One: The Data Gap
Every AI model is a reflection of the data it was trained on. Large language models are built on enormous datasets, some of it structured (organized, labeled information, like spreadsheets) and some unstructured (raw text, images, and audio scraped from across the internet). Training itself typically falls into two camps: supervised learning, where data is labeled with the "correct" answers to guide the model, and unsupervised learning, where the model looks for patterns on its own.
The problem is that data quality and representativeness are rarely guaranteed. If a dataset underrepresents certain languages, cultures, or demographics, the resulting AI system will behave unfairly for the people missing from that data. This is often invisible until the system is already in use. The data gap is, in many ways, the root of most other AI safety problems: a model can only be as fair, accurate, or safe as the information it learned from.
Gap Two: The Accountability Gap
As AI systems take on more autonomous, "agentic" roles which can be defined as making decisions and taking actions with less direct human input, the question of who is accountable becomes harder to answer. Two models are commonly used to keep humans in the picture:
Human-in-the-loop, where a person must review and approve an AI's output before it takes effect.
Human-on-the-loop, where a person monitors the system and can intervene, but doesn't approve every action individually.
Though too much human oversight slows AI down and limits its usefulness, too little, and accountability erodes. In the United States, proposals such as the Algorithmic Accountability Act reflect an emerging principle: AI systems should be accountable, not self-dependent. In practice, this means requiring human validation of AI-generated decisions in consequential settings, and pushing for explainable AI systems that can show their reasoning rather than operating as a black box. Explainability becomes especially important for agentic AI, where a model isn't just answering a question but independently taking real-world actions.
Gap Three: The Governance Gap
Effective AI governance requires regulating two things at once: the data that feeds AI systems, and the models themselves. Governments and institutions generally have four levers available to do this:
AI law: binding legislation with legal consequences.
AI enforcement: the mechanisms and authority to act when rules are broken.
AI risk management systems: internal frameworks that companies and institutions use to assess and mitigate risk.
AI standards: technical benchmarks that define what "safe" or "acceptable" actually means in practice.
The need for effective AI governance cannot be overemphasized because it is only when we have laws that we can enforce remedy.
When AI Governance Fails: A Case Study
These gaps aren't theoretical, they play out differently depending on where in the world you look, and nowhere is that more visible than in the ongoing conversation about the state of AI governance across Africa. A useful way to understand this is through the lens of a talk exploring exactly that question: what happens when AI governance doesn't keep pace with AI adoption.
The reality is actually scary and concerning. Sixteen African countries currently have AI strategies, but strategies are not laws. A strategy signals intent; a law creates enforceable obligation. In addition to this, the continent currently has no dedicated AI safety institute, meaning that even where novel or uncommon risks emerge, there's often no institutional body equipped to study or regulate them. And even in cases where there is a push to develop local AI systems, there's frequently no research institute in place to independently test or validate them before deployment.
The consequence is a reduced ability to negotiate on equal footing with the world's leading AI labs and technology providers.
Reclaiming Leverage
The encouraging part of this conversation is that governance leverage isn't limited to writing laws after the fact. It can be exercised at multiple points across the AI lifecycle: data, development, testing, procurement, deployment, and monitoring. Each stage represents an opportunity to set conditions, demand transparency, or require local validation rather than simply accepting AI systems as finished products handed down from elsewhere.
This reframes AI governance as an ongoing, active practice. Governments, institutions, and even individual organizations don't have to wait for a system to be fully built and deployed to start asking hard questions about how it was trained, what data it used, how its decisions can be explained, and who is accountable when something goes wrong.
