SCAIO · AI Safety & Governance

Safety, Alignment, Governance, Regulation

Four words people constantly mix up — untangled in about ten minutes. The vocabulary the rest of the conversation depends on.

SCAIO · scaio.org
Why this primer exists

These four words get used as if they mean the same thing. They don't.

Read a week of AI coverage and you'll see "safety," "alignment," "governance," and "regulation" swapped in and out almost at random. The blur is not harmless: it makes debates circular, lets people argue past each other, and produces policy that aims at the wrong target.

They are four distinct things, operating at four different levels — from a property of the model itself all the way out to the law of the land. Here is a clean map.

The one-line map

Four levels, from the model outward.

01 · Alignment

Does it try to do what we intend?

A technical property of the system itself.

02 · Safety

Will it avoid causing harm?

The broader engineering goal. Includes alignment.

03 · Governance

Who decides, and how?

The rules, processes, and accountability around it.

04 · Regulation

What does the law require?

Government rules with legal force. A subset of governance.

Level one · the narrowest

Alignment: getting a system to actually pursue what we intend.

Alignment is a technical property of an AI system: does it reliably try to do what its designers and users actually want — including the things they didn't think to spell out?

The problem is harder than it sounds. We train systems on proxies (approval, scores, examples), not on our true intentions, and a capable system can satisfy the proxy while missing the point — optimizing the letter of the instruction against its spirit. Alignment research is the work of closing that gap.

Plain version: alignment is about the system's goals — whether it's trying to do the right thing at all.

Level two · broader

Safety: making sure the system doesn't cause harm.

Safety is the larger engineering goal that contains alignment. A system can be well-aligned and still be unsafe — if it's unreliable, insecure, or misused. Safety covers all of it:

Level three · the institutional layer

Governance: who gets to decide, and how they're held to account.

Governance steps out of the technology entirely and into people and institutions. It's the set of rules, processes, roles, and accountability structures that determine how AI gets built, bought, deployed, and overseen — inside a company, an agency, a university, or a state.

Governance is where most of the practical action is, because it's the layer ordinary organizations actually control. An impact assessment before deployment, a human-review requirement, a procurement checklist, a disclosure rule, a named accountable official — all governance.

Level four · the legal layer

Regulation: the part of governance that carries the force of law.

Regulation is a subset of governance — the rules set by government that you must follow, with penalties if you don't. The EU AI Act, a state law on AI in hiring, an agency procurement standard: all regulation.

The key insight: regulation is one tool of governance, not the whole of it. Plenty of good AI governance is voluntary, contractual, or professional — and plenty happens long before, or entirely without, a statute. Conflating "governance" with "regulation" is how people end up believing nothing can be done until a law passes. Not true.

How they nest

Two of these live in the machine; two live in the institution.

In the system

Alignment ⊂ Safety

Alignment is one ingredient of safety. Safety is the whole recipe for a system that doesn't cause harm — alignment plus robustness, security, and misuse resistance.

In the institution

Regulation ⊂ Governance

Regulation is the legally-binding slice of governance. Governance is the whole set of choices about who decides and how — most of which don't require a law.

The boundaries are debated at the edges — but as a working map, this keeps a conversation honest.

One example, all four lenses

An AI tool that flags benefits claims for denial.

A few more terms you'll hear

The working vocabulary, defined.

EvalsStructured tests measuring what a model can and can't do. The backbone of knowing whether a system is safe for a given use.
Red-teamingDeliberately attacking a system to find failures and harmful outputs before deployment.
InterpretabilityResearch into seeing why a model produced an output — opening the black box.
RLHFReinforcement Learning from Human Feedback — training a model toward responses people prefer. An alignment technique.
GuardrailsConstraints placed around a deployed system to limit what it will do. A safety/governance tool.
Frontier modelThe most capable current generation of general-purpose models — where the hardest safety questions concentrate.

Most unproductive AI arguments are really vocabulary problems. "Is AI safe?" and "Should AI be regulated?" are different questions with different answers — and you can't reach either one if the words keep sliding around."

Why this primer comes first
Why it matters for South Carolina

Different problems live at different levels.

A legislator worried about AI mostly has governance and regulation levers — what to require, disclose, and review. Those work whether or not the underlying model is perfectly aligned.

The deepest alignment and safety questions are largely solved (or not) by the handful of labs building frontier models — not in Columbia. Knowing which problems a state can actually act on, and which it can only prepare for, is the difference between effective policy and theater.

Part of the series

AI Safety & Governance at SCAIO.

This primer is part of SCAIO's neutral, sourced series on AI safety, governance, regulation, and alignment. Start with the editorial — Between Doom and Denial — and browse the rest at scaio.org/safety.

scaio.org · jimmy@scaio.org

1 / 13 Exit