Skip to content
TrustList
News

Nigeria's NITDA advises organisations not to put confidential or personal data into public AI tools

Editorial

By TrustList Editorial

Nigeria's IT development agency, through its emergency response team, has advised staff not to enter personal, classified or confidential data into public AI chatbots, to use organisation-approved tools and to anonymise data first.

About Nigeria's NITDA advises organisations not to put confidential or personal data into public AI tools

Nigeria's NITDA advises organisations not to put confidential or personal data into public AI tools

4 October 2026 — Nigeria's National Information Technology Development Agency (NITDA) has advised organisations and their staff not to enter personal, classified or confidential information into public AI chatbots, according to a Nairametrics report of 4 October 2026. The advisory was posted on X by the agency's Computer Emergency Readiness and Response Team (CERRT.NG).

Not yet independently verified. Single source: one outlet's report of an advisory NITDA posted on X; we have not read the post itself or found it on NITDA's website. It is guidance, not a binding rule. We will update this when it can be confirmed, and remove this note.

What the advisory says

According to the report, NITDA warned that information typed into public large-language-model tools can be retained, logged or used by the provider to train its models. Staff using such tools could expose personally identifiable information, classified government information or confidential company data, and NITDA said such exposure could amount to a personal data breach.

The agency's recommendations, as reported:

  • use only AI tools that your organisation has approved for official work;
  • remove, anonymise or pseudonymise personal and sensitive information before using any AI platform;
  • review the privacy terms and data-retention settings of the tools you use;
  • do not upload internal documents to public AI services without authorisation.

Who is affected

Government bodies and businesses in Nigeria, and any company whose Nigerian staff use public AI assistants for work. Under Nigeria's data protection law, an organisation is responsible for personal data its staff disclose, so guidance from the country's IT regulator is a signal of how such incidents may be judged.

What to do

  1. Publish an AI acceptable-use policy that says which tools are approved and what data may never be entered.
  2. Provide an approved option, such as an enterprise AI service with data-retention controls, so staff are not pushed towards consumer tools.
  3. Turn off training on your data where your AI vendor allows it, and record that setting.
  4. Train staff to remove names, account numbers and other identifiers before using AI for drafting or analysis.
  5. Add AI-related disclosure to your data-breach response plan.

Why it matters for buyers

This is guidance rather than a rule, but it follows the line regulators elsewhere are taking: the organisation, not the AI vendor, answers for what its people share. Buyers evaluating AI assistants for teams in Nigeria should favour products with admin controls, retention settings and audit logs that let them show they followed NITDA's advice.

Sources

Categories & features