You give your new house help a key to your front door. In her first week, she stumbles upon the spare key to your neighbour's gate under a flowerpot, lets herself in, photographs his sensitive paper documents and shares them on the estate's WhatsApp group.
By evening, the whole estate knows how much your neighbour owes his landlord.
Nothing is stolen. Nobody asked her to share the sensitive information. She was just being helpful. Very, very helpful.
That, more or less, is what OpenAI admitted to last month.
The company behind ChatGPT has been testing AI "agents". These programs don't stop at answering your question. They go off and do the task themselves. Think of the colleague who replies "noted" and then actually does the thing. Rare, I know.
On 25 September, OpenAI said some of its agents had wandered into United States government websites. At the Department of Education, they found developer keys that unlock government data. At America's markets regulator, the SEC, they collected information and posted it elsewhere online.
The Education Department says it found no damage. The SEC says no private information was touched. OpenAI has stopped training its newest models, its second pause in three months, and says it will restart "only when we are confident that we have additional safeguards."
Every headline since then has asked whether AI is dangerous. Almost nobody is asking where the off-switch is.
For Rwanda, that is the whole question. When a foreign AI agent does something nobody asked it to do inside a Rwandan system, can we switch it off?
These tools are coming here, and some arrive here first. In January, OpenAI and the Gates Foundation launched Horizon 1000, a $50 million programme to bring AI into 1,000 primary health clinics across Africa by 2028. It starts in Rwanda.
It should. Sub-Saharan Africa is short of roughly 5.6 million health workers. A tool that helps one nurse get through a long queue is worth having. And in June, Cabinet approved a National AI Agency to steer all of this.
In America, the answer to the off-switch question is getting clearer. On 25 September, the chair of the US Federal Trade Commission, Andrew Ferguson, rejected the idea that AI agents act on their own. The company is responsible, he argued, because "the man who wielded the hammer ought to suffer the consequences of his conduct."
Good. But in America, the man with the hammer, the house he broke into and the court that judges him all sit in the same country.
Ours won't.
Going back to the house help. When she misbehaves, you call her in and take the key back that same afternoon. Now imagine she was hired, trained and paid by an agency in California, and only that agency can reprimand her. You call to complain. Your call is very important to them. Please hold.
While world leaders met at the UN last month, Senegal's Seydina Moussa Ndiaye had a name for this. He called it "colonial AI", where outsiders control the computing power, the data and the rules. You don't have to like the phrase to see the problem.
Borrowed AI comes with borrowed rules.
This reaches your desk too. Your bank or your ministry could be running agents next year, and somebody in the office will hold the keys. It might be you. Congratulations on your promotion.
Treat the agent like a new house help in her first week. Give her access to the front door, not the whole compound. Then check what she actually did before you believe what she says she did.
For the new AI Agency, the job is to write our terms before the tools write them for us. Where do the logs live, and which Rwandan office gets the call to resolve such issues when they arise? Ideally one that picks up the phone.
Here is my test. When Horizon 1000 reaches its thousandth clinic, ask whether a Rwandan official can take back control without phoning California.
If the answer is yes, we built something.
If it is not, we are only renting it. And that's a data safety disaster waiting to happen.
The writer is Head of Business and AI at Global Kwik Koders and co-founder of RWAiGHT.