From Data Governance to AI Governance: Lessons for Building a Responsible AI Ecosystem

Artificial intelligence (AI) now sits at the centre of global development discourse and rightly so. Few technologies in recent history have  the capacity either to accelerate human development  or profoundly restructure  the social and economic systems that have defined modern civilisation. Despite the urgency of these challenges, the appropriate governance framework for managing this powerful and often unpredictable technology remains unsettled. Governments, multilateral organisations, and private sector actors broadly agree that effective governance is essential for ensuring that AI systems deliver societal benefits while mitigating harm. However, key questions remain contested: What form should governance take? Who should lead the process—states, private firms, international institutions, or multi-stakeholder coalitions? And how can governance keep pace with technological innovation without limiting its potential?

Complicating the issues further are powerful geopolitical and economic incentives. Nations increasingly view AI leadership as a strategic priority tied to economic competitiveness and national security. In such a context, AI governance is often perceived not as an essential element for responsible innovation but as a potential barrier to  technological advancement. 

While historical precedents for governing AI-like technologies are limited, the broader challenge of regulating emerging technologies within complex innovation ecosystems is not new. One particularly relevant domain is data governance—the set of rules, standards, and institutional arrangements that govern how data are collected, processed, shared, and used. Over the past two decades, data governance has emerged as a well-developed policy field, shaping global debates around privacy, digital rights, cross-border data flows, digital taxation and platform accountability.

Indeed, contemporary discussions around AI governance have in many ways evolved out of earlier debates on data governance. The rapid emergence of generative AI systems around 2022 accelerated this shift, bringing renewed attention to how data, algorithms, and computational power interact to shape economic and social outcomes.

Against this backdrop, this article highlights critical lessons from data governance that can inform the global search for effective AI governance frameworks. Drawing on the experience of digital policy development over the past decade, it outlines pathways for moving beyond conceptual debates toward actionable governance models capable of balancing AI’s enormous potential with its significant risks.

Is There a Drift Between AI Governance and Data Governance?

While the extent to which data governance  influences AI governance is not debatable, there are emerging views that the two fields are addressing separate issues. One side of the argument indicates that the two are inseparable. From this perspective, AI systems are fundamentally dependent on data, meaning that governance interventions aimed at regulating data flows, quality, and ownership are inherently also regulating AI outcomes. According to  this viewpoint, data governance primarily concerns the input phase in the digital value chain, while AI governance addresses the outputs and impacts of algorithmic systems. Taken together, the two phases constitute a continuous governance framework spanning the entire lifecycle of data-driven technologies.

However, AI development has not linearly followed the best ideal of data governance, as AI training data sidesteps data privacy conditions and even broader intellectual property. Furthermore most current efforts to govern AI devote relatively little attention to issues related to data, including major initiatives such as the EU AI Act and  US President Joe Biden’s executive order on AI. This suggests the emergence of a conceptual drift between the two fields. While closely related, AI governance is increasingly being treated as a distinct domain with its  policy priorities and institutional arrangements.

Figure 1: Trends in Usage of AI and Data Governance in the Literature 

Evidence of this shift can be observed in the evolution of policy discussions and terminology. We used the Google Ngram Viewer to track this evolution, as shown in Figure 1.  The concept of “AI governance” appeared in policy discussions around 2018 with the regulatory concerns largely embedded within broader analysis of data governance which was  already a decade-old field at the time. However, the rapid development of generative AI systems has catalysed a growing body of scholarship and policy initiatives explicitly focused on AI governance. Table 1 also highlights the key domains of each approach, which are interrelated but not overlapping. 

DomainData Governance AI Governance 
Primary FocusPrivacy, ownership, and flow.Algorithmic bias, safety, and agency.
Core MechanismConsent and encryption.Model transparency and red teaming.
Regulatory AimProtecting the input (The Person).Controlling the output (The Intelligence).

In this sense, while data governance and AI governance remain closely linked, there are growing reasons to treat them as analytically distinct policy domains. First, the scale and potential impact of AI technologies raise unique governance concerns that extend beyond traditional data regulation. Managing risks associated with autonomous systems implications for the labour market and large-scale algorithmic decision-making  for human rights and political governance. Second, while data governance primarily addresses the management of data resources, AI governance increasingly focuses on the behaviour, accountability, and impact of algorithms systems themselves.

Recognising this distinction is important for designing governance frameworks that are sufficiently comprehensive without conflating different  policy challenges. A critical review of decades of data governance reflects mixed performance with key success stories sitting side by side with an enormous unmet governance gap and sometimes unintended negative effects. The experience of data governance offers several important lessons for policymakers seeking to design effective oversight frameworks. We highlight five key lessons below. 

What AI Governance Can Learn from Data Governance

  1. Governance Models Reflect Geopolitical Interests

Digital governance frameworks are rarely neutral. Rather, they often reflect broader geopolitical dynamics and competing visions of the global digital order. The evolution of data governance regimes over the past decade illustrates this trend clearly, with distinct regulatory models emerging across major digital powers. The European Union has emphasised rights-based regulation focused on privacy and data protection; the United States has largely favoured market-driven innovation with limited federal oversight; while China has pursued a state-centric model that integrates data governance with national security and industrial policy.

AI governance is likely to follow a similar trajectory. Diverging governance frameworks are already emerging, shaped by differences in political institutions, economic priorities, and national security strategies. These fragmented approaches have important implications for the global digital ecosystem. In particular, the extraterritorial reach of major regulatory regimes—such as the EU’s digital regulations—can impose significant compliance and capacity burdens on developing countries that often lack the institutional and technical resources to meet complex regulatory requirements.

At the same time, fragmented governance regimes risk creating regulatory silos that encourage firms to relocate data processing and unethical AI development to jurisdictions with weaker oversight. Such dynamics can undermine global efforts to ensure responsible AI development and equitable digital governance.

In principle, a multilateral governance approach offers the most effective pathway for managing these challenges. Harmonised frameworks can reduce regulatory fragmentation and ensure that compliance expectations do not differ  dramatically across jurisdictions. Yet achieving such alignment remains difficult, particularly when major powers view digital governance as an extension of strategic competition.

Despite these constraints, progress toward a coordinated global framework remains both possible and necessary. Even within a tiered or pluralistic governance landscape, international agreements can establish baseline principles and minimum standards that guide national regulation. Such global frameworks would not replace national policies but could provide a common foundation upon which countries—particularly developing economies—can build stronger and more context-appropriate AI governance systems. The African Data Policy Framework is an example of such a tiered framework that allows for national governments to set their  data policies with standards established at the regional levels.  

2. Regulation Alone Does Not Resolve Power Imbalances

Experience with data governance demonstrates that no regulatory model is without unintended consequences. For instance, the European Union’s General Data Protection Regulation (GDPR) strengthened global data protection standards, but it also created compliance barriers for many firms and governments in developing countries. While these pressures have encouraged the adoption of domestic data protection laws across Africa and other regions, they have also exposed variation in institutional readiness and technical capacity across the continent. 

Other governance models illustrate similar trade-offs. China’s state-centered approach to digital governance has become a reference point for governments seeking stronger control over digital infrastructure and online information flows, sometimes at the expense of digital and human rights. Meanwhile, the largely market-driven approach in the United States has enabled rapid technological innovation but has also concentrated significant power in large private technology firms, creating challenges for competition and limiting the growth of African local digital enterprises.

Each model therefore delivers important benefits while simultaneously creating new layers of exclusion or barriers for certain actors. AI technologies will inevitably produce winners and losers across economies and labour markets. Ensuring that governance frameworks account for these distributional impacts will therefore be crucial. AI governance will likely require similar complementary interventions beyond policy and regulatory frameworks. 

For example, policies that support workers displaced by automation—such as reskilling programmes, social protection measures, or even forms of universal basic income—may become increasingly important components of broader AI governance strategies. International cooperation will also be necessary to ensure that developing economies are not left behind in the global AI transition.

The experience of digital governance in Europe provides a useful illustration. The European Union’s broader data governance in Africa initiatives have combined regulation with investments in infrastructure, institutional capacity, and policy development. These efforts have helped strengthen governance capabilities not only within Europe but also indirectly in Africa, where they have supported the development of emerging data governance frameworks.

3. Aligning Actors in AI Governance is the most critical 

Data governance debates have often been characterised by a division among key stakeholders. Public sector and civil society organisations have tended to emphasise safeguards—focusing on issues such as digital privacy, data protection, data localisation, and digital rights. In contrast, private sector actors have largely prioritised enabling conditions for innovation, including investments in digital infrastructure, expanded data sharing, and regulatory flexibility that allows new technologies to scale.

These differing priorities are not inherently problematic, as they reflect the legitimate interests and perspectives of different actors within the digital ecosystem. However, the lack  of early cooperation among stakeholders has often led  to fragmented policy environments, with diverse  groups advocating for regulatory approaches that sometimes conflict with each other . In many jurisdictions, this dynamic has slowed the development of coherent data governance frameworks and created uncertainty for both policymakers and market participants.

AI governance has an opportunity to avoid some of these challenges by fostering earlier alignment among key actors. This multi-stakeholder approach has been a defining feature of many successful digital governance initiatives. Due to  the complexity and rapid evolution of AI technologies, no single institution or sector possesses the expertise or authority necessary to regulate them effectively. Governments play a critical role in setting legal frameworks and ensuring accountability, but private sector actors hold much of the technical knowledge and infrastructure that underpin AI systems. At the same time, civil society organisations and academic institutions provide essential oversight, research, and advocacy to ensure that governance frameworks protect public interests.

Bringing these actors together early in the policy process can help reduce fragmentation, improve policy legitimacy, and create governance models that are both adaptive and practical. In the context of AI—where technological change often outpaces regulatory capacity—such collaborative governance approaches may prove particularly important for ensuring that innovation proceeds in ways that are both responsible and socially beneficial.

4. Regulating digital platforms presents a highly complex and evolving challenge

Regulating large digital platforms presents a fundamental challenge for modern governance systems due to several factors. First, many of these platform institutions command economic resources, technical expertise, and global reach that exceed those of nation-states. Their transnational operations allow them to navigate regulatory environments strategically, often avoiding litigation or shifting operations across jurisdictions with relative ease. As a result, governments frequently find themselves attempting to regulate actors whose scale and influence exceed traditional regulatory frameworks.

Second, a common ethos within the digital innovation ecosystem has long been the “build first, fix later” approach—prioritising rapid technological development while addressing risks only after they materialise. While this model has accelerated innovation, it has also exposed significant governance gaps, particularly when technologies scale globally before appropriate safeguards are in place.

For this reason, early regulatory engagement can be advantageous, even when regulatory frameworks are imperfect at the outset. Waiting for technologies to fully mature before introducing governance mechanisms may allow harmful dynamics to become deeply entrenched and difficult to reverse. However, early intervention inevitably carries trade-offs. Initial regulatory frameworks may contain design flaws, unintended consequences, or implementation challenges.

Policymakers must therefore accept that some degree of policy experimentation is unavoidable. Effective governance in rapidly evolving technological environments requires regulators to tolerate a certain level of error and adjustment. The objective should not be to design perfect rules from the outset, but rather to create governance systems that can learn and adapt over time.

The experience of data governance provides a valuable lesson in this regard: that big platform firms are difficult to control and regulate for developing countries. The leading role of the EU in strong data governance systems supports many African countries to also implement data governance frameworks. A similar global leader is required to ensure better regulation of AI emerging from these same platform firms. 

Conclusion

Getting AI governance right will be critical to social and economic development in the coming decades. Despite the complexity and ambiguity of the AI policy landscape, data governance knowledge can provide  significant guidance. This analysis highlights key lessons—both successes and persistent challenges—from data governance that can inform emerging approaches to AI governance.

Effective AI governance will require flexibility, continuous learning, and timely policymaking. Historically, governance frameworks have often lagged behind technological innovation. However, in the case of AI, such delays carry particularly significant consequences. Slow or reactive policy responses risk amplifying social and economic harms while missing opportunities to shape AI development in ways that advance public welfare. Proactive, adaptive governance is therefore essential to ensure that AI systems contribute to inclusive and sustainable development both now and in the future.