Artificial intelligence is developing at a pace that traditional regulatory systems were never designed to accommodate. Governments are responding with national strategies, legislation, regulatory frameworks and ethical principles. But an increasingly important question is emerging: can regulation keep pace with the technology it is intended to govern?
The question is no longer simply whether AI should be regulated. It is whether legal, regulatory and enforcement systems can adapt quickly enough as AI moves from generating content to taking actions, interacting with systems and increasingly operating with a degree of autonomy. This is no longer a theoretical discussion.
Some of the most significant developments in AI safety are no longer simply about what models can say, but what they can do.
In July 2026, during internal cybersecurity evaluations, OpenAI reported that its models circumvented controls designed to isolate them from the internet and accessed OpenAI and Hugging Face systems. OpenAI said the models exploited vulnerabilities and gained unintended access to third-party systems.
The context matters: these were controlled evaluations and do not demonstrate that AI systems are routinely behaving this way in ordinary use, but they demonstrate an important shift.
As AI systems become more capable and increasingly agentic, the distinction between an AI system producing an output and taking an action becomes increasingly significant.
A parallel finding came from the UK AI Security Institute (AISI). In August 2026, AISI disclosed that during a routine cyber evaluation carried out under deliberately permissive test conditions — open internet access, with some safety filters disabled — AI agents under test took sustained, unsanctioned action against real people and organisations, including an attempt to insert malicious code into a public open-source project by fabricating online identities to socially engineer a human maintainer into approving it.
AISI said its investigations found no evidence of resulting real-world harm. Taken together with the OpenAI case, the pattern is notable not only for what the incidents involved, but for how they came to light — one was self-disclosed by the developer, the other surfaced by an independent evaluator. Both matter, but relying solely on the former leaves governance dependent on companies choosing to report on themselves.
We are no longer asking only whether the AI-generated answer was accurate. We also need to ask what the AI can do, what systems and permissions it has, what happens when it behaves unexpectedly — and who is accountable.
Legislation and regulation take time. The European Union’s AI Act illustrates this: it entered into force in 2024, with provisions applying in stages, and governance and general-purpose AI obligations began applying in 2025, while certain high-risk rules extend into 2027 and 2028. [European Commission, 2026]
There are good reasons for phased implementation — regulation requires consultation, legislation, technical standards, guidance and institutional capacity. But AI does not develop according to legislative timetables.
A capability emerging today may be substantially different by the time the corresponding regulatory requirement becomes enforceable. This creates what I would describe as the AI regulatory gap: the space between the speed at which AI capabilities evolve and the speed at which legal and regulatory systems can respond.
There is also a second gap: accountability. UN Secretary-General António Guterres put this plainly at the UN General Assembly’s 81st session in September 2026: the danger is not technology, but technology without accountability — capability without oversight, decision-making without transparency. [Guterres, UNGA81, 2026].
Imagine an AI agent is authorised to perform a legitimate business task but, through an unexpected chain of actions, accesses information it was not authorised to access or causes harm. Who is responsible? The employee who deployed it? The organisation that gave it access? The developer? The cloud provider? The integrator? Or potentially several parties at once, across several jurisdictions?
The UK Competition and Markets Authority has already settled one part of this in the consumer protection context: businesses remain responsible for what their AI agents do, even where the agent is supplied by a third party. [UK CMA, 2026].
But that clarity doesn’t extend to the rest of the stack. As the AI supply chain grows more complex — model developers, cloud providers, data providers, application developers, system integrators, end users — questions of duty of care, human oversight, security controls, transparency and liability become harder to resolve.
The answer is not necessarily to legislate faster for the sake of legislating faster — poorly designed regulation can create its own risks. The more useful question is whether regulatory capability can become more responsive.
That could include regulatory sandboxes, structured AI incident reporting, stronger requirements for logging and human oversight, risk assessments for high-impact AI systems, technical standards that can evolve more quickly than primary legislation, clearer accountability across the AI supply chain and international regulatory information-sharing.
The objective should not be regulation that changes every time a new model is released — it should be regulation that can respond when the nature of the risk changes.
What that looks like in practice depends on where it’s being built. This conversation is particularly important for Africa, but it should not begin from the assumption that African countries are simply waiting to catch up. Nigeria is already building an AI ecosystem.
Its National AI Strategy sets out a framework for AI development, adoption, governance and institutional capacity, while NCAIR supports research, development and adoption of AI and other emerging technologies. [Nigeria National AI Strategy, 2025].
The opportunity now is to ensure that governance, oversight, cybersecurity and institutional capability evolve alongside that innovation.
Nigeria’s governance conversation is already moving in that direction. Alongside its National AI Strategy and existing institutions, there are legislative proposals including the National Artificial Intelligence Commission (Establishment) Bill, 2025. The National Digital Economy and E-Governance Bill, 2025 also contains proposed AI regulatory functions including risk monitoring, horizon scanning, audits, investigations and enforcement. The Bill remains within the legislative process. [National Assembly of Nigeria, 2026]. As these Bills move through the legislative process, two provisions would do more than most to close the gaps described above.
First, a statutory requirement that organisations deploying AI in critical business or public-service functions maintain detailed incident and decision logs, producible to regulators or courts when legally required — rather than relying on the organisation to self-report, or on public databases that we already know underrepresent African incidents.
Second, explicit designation of a lead accountable party in any multi-vendor AI deployment, rather than leaving liability to be worked out after harm occurs. Without that clarity, the Bills risk creating institutions with the mandate to investigate AI harm but no reliable record to investigate, and no clear party to hold to account when they do.
This raises practical questions: who monitors emerging AI risks, who oversees high-impact deployments, who investigates significant incidents, who addresses international providers operating in the Nigerian market, and how responsibility should be coordinated across data protection, cybersecurity, financial services, telecommunications and other regulators. These questions become increasingly important as AI moves from experimentation into critical business and public services. It mirrors what the African Union itself has called for — in its 2024 Continental AI Strategy and a 2025 high-level policy dialogue — governance that is agile and inclusive enough to adapt as AI risks change, rather than fixed at the moment it is written. [African Union, 2024; 2025].
There is another gap that deserves more attention: knowing when AI-related harm is actually happening. Research from the AI Incident Database found that between February 2020 and July 2026, incidents from African countries represented approximately 1.3 per cent of incidents reported in the OECD AI Incidents and Hazards Monitor and 4.2 oer cent of records in the AI Incident Database. [AI Incident Database, 2026].
The researchers caution that this should not be interpreted as evidence that Africa experiences fewer AI harms — public databases depend on incidents being identified and reported, while monitoring of AI harms across Africa remains underdeveloped. A lack of reported incidents is therefore not necessarily the same thing as a lack of incidents.
If AI adoption is increasing but the ability to identify, report and investigate AI-related harm is not developing at the same pace, regulators may be making decisions with incomplete information. Effective AI governance therefore requires more than rules — it requires visibility.
Left unresolved long enough, accountability questions like these don’t stay in policy documents — they end up in front of a judge, weighing whether human oversight was reasonable, whether the risk was foreseeable, whether the organisation understood the system’s limitations, and — where responsibility is distributed across an AI supply chain — which party carries legal responsibility. We should not wait for every answer to emerge through individual incidents and litigation; the legal and regulatory conversation needs to happen alongside technological development.
There is a danger at both ends. Regulation that moves too slowly can leave citizens, businesses and governments exposed to risks that have already changed. But regulation that is unnecessarily rigid can create barriers to innovation, particularly in economies still building their digital and technological capacity.
The answer is not to choose between innovation and regulation. It is to build governance capable of supporting both. The question we should increasingly be asking is not simply “What rules do we need for AI?” It is: “What regulatory capability do we need to govern a technology that will continue to change?”
AI governance cannot be a policy document written today and reviewed several years later while the technology evolves every few months. It needs to be an evolving capability — bringing together policy, technical expertise, cybersecurity, assurance, legal accountability, incident reporting, enforcement and international cooperation.
The future of AI regulation may depend less on our ability to predict every technological development and more on our ability to build institutions capable of responding responsibly when the next one arrives.
For Nigeria, that starts now, while the National AI Commission Bill and the Digital Economy Bill are still being written rather than after they are enacted. For businesses deploying AI in the meantime, it means not waiting for that legislation to arrive before establishing their own incident logging, human oversight and clear internal accountability for what their AI systems do.
The organisations that build that discipline now will be the ones prepared when either a regulator or a court asks them to explain it.
-Chika Amadi is a Cybersecurity & AI Governance Leader and Founder & CEO of M516 Cyber Solutions Ltd. She is a former Bank of England Senior Cyber Security Consultant, with over 15 years’ experience across cybersecurity, digital risk and financial services. She can be contacted at [email protected].

