AI Governance Glossary: Plain-English Terms for Africa

Plain-English definitions of AI governance, risk, data protection and generative AI terms, with notes on the EU AI Act and African data laws.

AI governance in Africa · Frameworks · Laws and policy by country · Questions to ask · Glossary · Ideas and quotes · Free AI governance tools · Work with Stanislaus
Acceptable use policy
A short internal rulebook that tells staff which AI tools they may use, for what, with which data, and what is forbidden. It is the fastest first step in AI governance. Sources: [1] [2]
Accountability
The principle that a named person or body answers for an AI system's outcomes and can show the steps taken to make it safe and lawful. Blaming the algorithm is not accountability. Sources: [1] [2]
African Union Continental AI Strategy
The AU's strategy for a development-focused, ethical approach to AI across member states, endorsed by the AU Executive Council in July 2024. It is a policy framework, not binding law. Sources: [1] [2]
Agentic AI
AI systems that can plan and take actions on their own, such as sending emails, moving money or changing records, rather than only producing text. They raise the stakes on permissions, logging and human approval. Sources: [1] [2]
AI governance
The rules, roles and routines an organisation uses to decide which AI to use, how to use it safely and lawfully, and who answers for the results. Sources: [1] [2] [3]
AI incident
An event in which an AI system causes or nearly causes harm, such as a wrong decision about a person, a data leak or a safety failure. Under the EU AI Act, providers must report serious incidents involving high-risk systems to authorities. Sources: [1] [2] [3]
AI inventory
A register of every AI system an organisation builds, buys or uses, with its purpose, owner, data, risk rating and status. Also called an AI register. You cannot govern what you have not listed. Sources: [1] [2]
AI literacy
The skills and understanding people need to use AI well and recognise its risks. Article 4 of the EU AI Act has required providers and deployers to address it since 2 February 2025; the 2026 Digital Omnibus reworded it as a duty to take measures to support AI literacy rather than to guarantee a level. Sources: [1] [2] [3] [4] [5]
AI system
Under the EU AI Act, a machine-based system that operates with some autonomy, may adapt after deployment, and infers from its inputs how to generate outputs such as predictions, content, recommendations or decisions. The definition is close to the OECD's. Sources: [1] [2] [3]
AIGP
The Artificial Intelligence Governance Professional certification from the IAPP, a global association of privacy professionals. The exam launched in 2024 and tests knowledge of AI governance, law and risk management. Sources: [1] [2]
Automated decision-making
A decision about a person made by technology without meaningful human involvement. Nigeria's NDPA (section 37), Kenya's Data Protection Act (section 35) and South Africa's POPIA (section 71) all restrict decisions based solely on automated processing that have legal or similarly significant effects. Sources: [1] [2] [3] [4] [5]
Bias
Systematic error that leads an AI system to treat some people or groups worse than others, often inherited from unrepresentative training data or from past human decisions. Sources: [1] [2]
Conformity assessment
The process of showing that a high-risk AI system meets the EU AI Act's requirements before it is placed on the market, either through the provider's own checks or through an independent notified body. Sources: [1] [2]
Cross-border transfer
Sending personal data, or giving access to it, outside the country where it was collected. Many AI tools are hosted abroad, so using them can be a transfer that needs a legal mechanism under laws such as Nigeria's NDPA. Sources: [1] [2]
Data controller
The organisation that decides why and how personal data is processed, and carries primary responsibility under data protection law. Sources: [1] [2]
Data processor
An organisation that processes personal data on a controller's behalf and under its instructions. Most AI vendors act as processors for their business customers, which must be set out in a contract. Sources: [1] [2]
Data protection impact assessment
A structured assessment, done before processing starts, of the risks a project poses to people's personal data and how those risks will be reduced. Data protection laws including Nigeria's NDPA 2023 require one for high-risk processing, which often includes AI. Sources: [1] [2]
Deepfake
Image, audio or video generated or altered by AI that convincingly shows real people, places or events that did not happen. The EU AI Act requires deployers to disclose deepfakes they create. Sources: [1] [2]
EU AI Act
Regulation (EU) 2024/1689, the EU's risk-based AI law, in force since 1 August 2024 and applying in stages. It was amended in 2026 by the Digital Omnibus on AI (Regulation (EU) 2026/1744), which moved the main high-risk deadlines back. It can apply to organisations outside the EU. Sources: [1] [2] [3] [4] [5] [6]
Explainability
The ability to give a meaningful account of why an AI system produced a particular output, in terms the affected person or reviewer can understand. Sources: [1] [2]
Fairness
The goal that an AI system's outcomes do not disadvantage people unjustly. There are several competing statistical definitions, so an organisation has to choose and document which one it applies and why. Sources: [1] [2]
Fine-tuning
Further training of an existing model on a smaller, specific dataset to adapt it to a task or style. If that data includes personal data, data protection law applies to it. Sources: [1] [2]
General-purpose AI model
An AI model trained on large amounts of data that can competently perform a wide range of distinct tasks and can be built into many downstream systems. Large language models are the main example. The EU AI Act places specific duties on their providers, applicable since 2 August 2025. Sources: [1] [2] [3] [4] [5]
Guardrails
Technical and procedural controls that keep an AI system within acceptable behaviour, such as input and output filters, topic limits, approval steps and usage caps. Sources: [1]
Hallucination
When a generative AI model produces content that sounds confident but is false or invented, such as a fake citation or a wrong figure. NIST calls this confabulation. Treat it as a standing property of the technology, not a rare bug. Sources: [1] [2]
High-risk AI system
In the EU AI Act, AI that is itself a regulated product, or a safety component of one, and AI used in listed sensitive areas such as employment, education, credit scoring and access to public services. These systems carry the heaviest obligations, now due to apply from 2 December 2027 for listed uses and 2 August 2028 for regulated products. Sources: [1] [2] [3] [4] [5]
Human oversight
Designing and running an AI system so that competent people can understand its outputs, intervene, overrule it or stop it. It must be real, not a rubber stamp on decisions people cannot question. Sources: [1] [2]
ISO/IEC 42001
The international standard for an AI management system, published in December 2023. It sets out how an organisation establishes, runs and improves its governance of AI, and it can be independently certified. Sources: [1] [2] [3]
Lawful basis
The legal ground on which personal data is processed. Nigeria's NDPA lists consent, contract, legal obligation, vital interests, public interest and legitimate interests. Consent is one option, not the only one. Sources: [1] [2]
Model card
A short document published with a model describing what it is for, how it was trained and evaluated, its known limitations and uses to avoid. It is a practical transparency tool. Sources: [1]
Model drift
The gradual decline in a model's performance as real-world conditions move away from the data it was trained on, for example when inflation or a currency change alters spending patterns. Sources: [1]
NIST AI RMF
The US National Institute of Standards and Technology's voluntary AI Risk Management Framework 1.0, released in January 2023. It organises AI risk work into four functions: Govern, Map, Measure and Manage. A Generative AI Profile (NIST AI 600-1) followed in July 2024. Sources: [1] [2] [3]
Post-market monitoring
The provider's ongoing collection and review of data on how an AI system performs once it is in use, so problems are found and fixed. It is required for high-risk systems under the EU AI Act. Sources: [1] [2]
Prohibited AI practices
Uses the EU AI Act bans outright, such as social scoring, manipulative techniques that cause significant harm, and untargeted scraping of facial images to build recognition databases. The bans have applied since 2 February 2025. Sources: [1] [2] [3]
Prompt injection
An attack in which instructions hidden in user input or in content the AI reads, such as an email or web page, make the model ignore its rules or take actions it should not. Sources: [1] [2]
Provenance
The traceable record of where data, content or a model came from and how it was changed. For content, it lets people check whether an image or text was AI-generated. Sources: [1] [2]
Provider and deployer
Two key roles in the EU AI Act. The provider develops an AI system or model and places it on the market under its own name; the deployer uses it under its own authority. Most African businesses are deployers, but a firm that builds its own product is a provider. Sources: [1] [2]
Red teaming
Deliberately attacking an AI system, as an adversary would, to find harmful outputs, security weaknesses or ways to bypass its safeguards before real users do. Sources: [1]
Retrieval-augmented generation
A technique where a generative AI model looks up relevant documents from a trusted source before answering, so responses are grounded in your own content. It reduces hallucination but does not remove it. Sources: [1] [2]
Shadow AI
AI tools used by staff without the organisation's knowledge or approval, typically free chatbots used with work data. It is the most common AI risk in African workplaces I see, and banning it rarely works. Sources: [1]
Synthetic data
Artificially generated data that mimics the statistical patterns of real data. It can reduce privacy risk and fill gaps, but it can also carry over or amplify the biases of the data it was modelled on. Sources: [1] [2]
Third-party AI risk
The risk that comes from AI you buy or that is built into suppliers' products, including how vendors use your data, change their models and handle failures. Sources: [1] [2]
Training data
The data used to build or adapt an AI model. Its quality, representativeness, legality and provenance largely determine how the model behaves and whose interests it serves. Sources: [1] [2]
Transparency
Being open with people about when and how AI is used, what it does and its limits. It ranges from telling a customer they are talking to a chatbot to publishing model documentation. Sources: [1]
Watermarking
Embedding a signal in AI-generated content, visible or hidden, that marks it as machine-made. The EU AI Act requires providers of generative AI to mark synthetic outputs in a machine-readable way. Sources: [1] [2] [3]

How this page was made. Parts of these pages were drafted and researched with the help of AI tools, then reviewed and checked against the sources linked beside each claim. AI can get things wrong and laws change, so treat this as general information, not legal advice: the linked sources are the authority, and you should take qualified advice before relying on anything here. Spotted an error? Tell me and I will fix it. Last checked 7 October 2026. See the terms.

By Stanislaus Martins. Stanislaus Martins is Managing Director, Sub-Saharan Africa at Aleph, the digital advertising group, with teams in Lagos, Nairobi, Johannesburg and Cape Town. He has spent over two decades in marketing, digital business and technology across Sub-Saharan Africa, including roles as Head of Digital Business at Insight Publicis, VP of Growth Marketing and Advertising at Jumia Nigeria, and Agency Partner for Sub-Saharan Africa at Meta. He holds an MBA, is a Fellow of the Chartered Institute of Marketing (UK) and of NIMN, and is Immediate Past President of ADMARP. He has completed the AI Governance online course from Saïd Business School, University of Oxford, and Google Cloud's Gen AI: Beyond the Chatbot course, and is preparing for the IAPP AIGP certification. He runs the AI in Nigeria 2026 survey. He helps organisations put AI to work with clear ownership, sensible risk controls and evidence they can show customers, regulators and boards.