regulation · Effective Jan 1, 2025
NG regulates AI through General Application and Implementation Directive (GAID) of the NDPA.
General Application and Implementation Directive (GAID) of the NDPA · effective 2025
Updated 60 days ago · 3 sources · confidence: medium
Overview
Nigeria’s approach to Artificial Intelligence (AI) regulation is characterized by a strategic shift from general digital economy policies to specific, risk-based governance frameworks. As the most populous nation in Africa and a significant hub for technological innovation, Nigeria has positioned AI as a cornerstone of its National Digital Economy Policy and Strategy (NDEPS) 2020–2030. The federal government, primarily through the Federal Ministry of Communications, Innovation and Digital Economy (FMCIDE), views AI not merely as a technical challenge but as a developmental tool capable of diversifying the economy away from oil dependence. This philosophy, termed "developmental regulation," seeks to create an enabling environment for startups and researchers while establishing guardrails to protect fundamental rights and national security. The government’s "Renewed Hope" agenda specifically highlights the role of emerging technologies in job creation, aiming to train millions of Nigerians in technical skills, including AI development and ethics, through initiatives like the 3MTT program. The maturity level of Nigeria's AI regulation has accelerated significantly between 2023 and 2025. Following the enactment of the Nigeria Data Protection Act (NDPA) in 2023, the government launched the National Artificial Intelligence Strategy (NAIS) in late 2024. This strategy serves as the foundational blueprint for all subsequent regulatory actions, including the drafting of the NITDA Code of Practice for AI and several legislative bills currently under review by the National Assembly. Nigeria’s regulatory maturity is now transitioning from policy-driven guidance to statutory enforcement, with a focus on creating a dedicated National AI Commission to centralize oversight and standard-setting across all federal agencies. This evolution reflects a broader continental trend where Nigeria seeks to lead the African Union’s efforts in establishing a unified AI governance framework that respects local cultural contexts while meeting global safety standards.
Regulatory approach
Nigeria utilizes a hybrid regulatory approach that combines horizontal data protection laws with sectoral guidelines and emerging AI-specific draft regulations. The primary horizontal pillar is the NDPA 2023, which governs the data processing activities essential to AI training and deployment. Complementing this is a "risk-based" framework proposed in the National AI Strategy and the NITDA Draft Code of Practice. This framework categorizes AI systems into tiers—Minimal, Medium, and High Risk—based on their potential impact on public safety, fundamental rights, and critical infrastructure. High-risk systems, such as those used in biometric identification, automated credit scoring, or critical infrastructure management, are subject to more stringent transparency, documentation, and human oversight requirements. This tiered approach is designed to be flexible, allowing the government to update risk classifications as the technology evolves without needing to overhaul the primary legislation. The regulatory philosophy is also notably "co-regulatory" and "inclusive." The government frequently employs public-private partnerships and multi-stakeholder workshops to draft its instruments, as seen in the development of the National AI Policy (NAIP) which involved over 120 researchers and industry experts. While the current landscape relies heavily on "soft law" (policies and guidelines), the active consolidation of Bills in the House of Representatives indicates a move toward a "prescriptive" statutory model. This transition aims to provide legal certainty for international investors while ensuring that AI deployments align with Nigerian ethical standards, local content requirements, and linguistic diversity. By fostering a "Nigeria AI Collective," the government encourages self-regulation among tech hubs while maintaining the authority to intervene when public interest is at stake, particularly regarding algorithmic bias and the digital divide. The governance of AI in Nigeria is currently distributed across several key federal agencies, though legislative efforts are underway to centralize this oversight. The National Information Technology Development Agency (NITDA) serves as the lead technical regulator. Under the NITDA Act, it is responsible for developing technical standards, issuing codes of practice, and fostering the local AI ecosystem through its National Centre for Artificial Intelligence and Robotics (NCAIR). NCAIR acts as the primary research and testing hub, providing the technical expertise required for conformity assessments and the development of the National AI Strategy. It also manages the National AI Trust, a proposed mechanism to ensure that AI development is funded and executed in a manner that prioritizes the public good and ethical considerations. The Nigeria Data Protection Commission (NDPC) plays an equally vital role by enforcing the data privacy standards that underpin AI development. The NDPC’s mandate includes registering Data Controllers of Major Importance, auditing AI-driven data processing, and investigating breaches. Additionally, the Federal Ministry of Communications, Innovation and Digital Economy (FMCIDE) provides high-level policy leadership and coordinates inter-ministerial efforts to ensure AI alignment with national economic goals. Future governance is expected to involve a dedicated National AI Ethics Commission or a consolidated regulatory body as proposed in current legislative bills. This new body would likely take over the licensing of high-risk AI systems, leaving NITDA to focus on technical standards and the NDPC to focus on data privacy, thereby creating a specialized tripartite oversight structure.
Enforcement & penalties
Enforcement mechanisms for AI-related activities in Nigeria are currently anchored in the penalty framework of the NDPA 2023. For violations involving personal data—such as unauthorized training on sensitive datasets or failing to provide transparency in automated decisions—the NDPC can impose tiered administrative fines. For Data Controllers and Processors of Major Importance (DCPMIs), fines can reach up to ₦10,000,000 or 2% of their annual gross revenue from the preceding year, whichever is greater. For other entities, the ceiling is ₦2,000,000 or 2% of gross revenue. The NDPC also has the power to issue "stopping orders," which can legally halt the deployment of a non-compliant AI system until remediation is achieved. This is a significant deterrent for companies whose business models rely on continuous data processing. Beyond administrative fines, the proposed AI-specific Bills (HB 942 and HB 601) introduce more specialized sanctions, including the revocation of licenses for high-risk AI providers and potential criminal liability for the malicious use of AI in spreading disinformation or compromising national security. The appeals process is handled through administrative reviews by the respective agencies (NITDA or NDPC), followed by judicial review in the Federal High Court. The GAID 2025 also introduces the "Standard Notice to Address Grievance" (SNAG), which empowers citizens to demand direct remedial action from AI deployers before escalating to the Commission. This "remedial fee" system encourages companies to settle disputes with data subjects directly, reducing the burden on the regulatory bodies while ensuring that individuals receive compensation for harms caused by algorithmic errors or privacy violations.
Data protection
Nigeria’s data protection framework is the most mature component of its AI governance landscape. The NDPA 2023 provides a comprehensive set of rights for data subjects, including the right to object to automated decision-making and the right to data portability. The Act is heavily influenced by international standards like the GDPR but includes specific provisions for the Nigerian context, such as the recognition of local customary privacy expectations. It mandates that any AI system processing the personal data of Nigerians must have a clear lawful basis, such as consent or legitimate interest, and must undergo a Data Protection Impact Assessment (DPIA) if the processing poses a high risk to individuals. This DPIA must specifically evaluate the potential for algorithmic bias and the security of the data throughout the AI training pipeline. The framework was further operationalized in 2025 through the General Application and Implementation Directive (GAID). The GAID introduces a classification system for data controllers based on the scale of their processing (Ultra-High, Extra-High, and Ordinary-High Level), which directly impacts AI developers who handle massive datasets. It also clarifies cross-border data transfer rules, requiring AI companies to use Standard Contractual Clauses or ensure that the destination country has an adequate level of protection. This ensures that the data used to train global AI models remains protected under Nigerian law, regardless of where the servers are located. Furthermore, the NDPC utilizes Data Protection Compliance Organizations (DPCOs)—private sector firms licensed to audit and assist companies in achieving compliance—creating a unique decentralized enforcement model that scales with the growing AI industry.
Sector-specific rules
In addition to horizontal regulations, Nigeria has begun implementing sector-specific AI rules to address unique risks in high-impact industries. In the legal profession, the Nigerian Bar Association (NBA) issued the "Guidelines for the Use of AI in the Legal Profession" in 2024. These guidelines mandate human oversight of AI-generated legal work, prohibit the abdication of professional judgment to algorithms, and require lawyers to disclose the use of AI to their clients. This represents one of the first professional-body-led AI regulations in Africa, focusing on maintaining the integrity of the judicial system and preventing the submission of AI-generated "hallucinations" as legal evidence. The NBA guidelines also emphasize the duty of confidentiality, reminding practitioners that inputting client data into public AI models may constitute a breach of professional ethics. The financial sector is governed by the Central Bank of Nigeria (CBN), which has integrated AI oversight into its broader fintech and cybersecurity frameworks. While a standalone "Financial AI Act" does not yet exist, the NAIS 2024 identifies finance as a priority sector for "demonstration projects." AI systems used for credit scoring or fraud detection must comply with existing consumer protection and anti-discrimination rules, ensuring that algorithms do not unfairly penalize certain demographics. Similarly, in healthcare, the National AI Strategy proposes the development of clinical AI standards in collaboration with the Federal Ministry of Health. These standards aim to ensure that diagnostic algorithms are tested for accuracy and bias within the Nigerian population before being deployed in hospitals, addressing the "data gap" where medical AI trained on Western datasets may not perform accurately for African patients.
International alignment
Nigeria actively aligns its AI regulatory framework with international norms to ensure interoperability and attract global investment. The National AI Strategy explicitly references the OECD Principles on Artificial Intelligence and the UNESCO Recommendation on the Ethics of AI. Nigeria’s risk-based classification system—distinguishing between minimal and high-risk systems—is a direct conceptual alignment with the EU AI Act. By adopting these familiar categories, Nigeria aims to reduce the compliance burden for multinational AI providers operating within its borders while maintaining high safety standards. This alignment is also intended to facilitate Nigeria’s participation in the global digital economy, ensuring that Nigerian AI products can be exported to markets with stringent regulatory requirements. Regionally, Nigeria is a leading voice in the development of the African Union (AU) Continental AI Strategy and the implementation of the Malabo Convention on Cybersecurity and Personal Data Protection. The government emphasizes "AI for Africa," focusing on local language models (LLMs) and infrastructure that addresses the specific needs of the Global South, such as agricultural optimization and infectious disease tracking. Nigeria has also engaged in bilateral discussions with partners in the UK and the US regarding AI safety and cybersecurity. These international collaborations are intended to ensure that Nigerian AI standards are recognized globally, facilitating the export of Nigerian-developed AI solutions and participation in international AI safety summits. The goal is to move Nigeria from being a mere consumer of AI to a significant contributor to the global AI governance discourse.
What's next
The most significant upcoming development in Nigeria’s AI landscape is the expected passage and consolidation of the various AI Bills currently before the 10th National Assembly. Legislators are working to merge the Control of Usage of AI Technology Bill (HB 942) and the National AI and Robotic Sciences Bill (HB 601) into a single, comprehensive National AI Act. This Act is expected to formally establish a National AI Commission with the power to license high-risk AI systems and manage a national registry of AI deployments. This would move Nigeria from a policy-led regime to a fully statutory regulatory environment, providing the legal teeth necessary for long-term enforcement. The government is also exploring the creation of a National AI Fund to support local startups that adhere to these new ethical standards. Furthermore, NITDA is expected to finalize its Code of Practice for AI in late 2025, which will provide the technical specifications for conformity assessments and bias auditing. The government also plans to launch several "Regulatory Sandboxes" as outlined in the NAIS 2024. These sandboxes will allow AI startups to test innovative solutions in a controlled environment with relaxed regulatory requirements, provided they adhere to core ethical principles. This "test-and-learn" approach is particularly aimed at sectors like agritech and edutech. As the 2020–2030 digital roadmap progresses, stakeholders should also expect new directives on Generative AI, specifically targeting the labeling of synthetic content and the prevention of deepfakes in political processes, ensuring that AI does not undermine democratic stability or public trust.
regulation · Effective Jan 1, 2025
regulation · Effective Jan 1, 2025
strategy · Effective Aug 1, 2024
policy · Effective Jan 1, 2024
guideline · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
act · Effective Jun 13, 2023
policy · Effective Jan 1, 2023
regulation · Effective Jan 1, 2022
policy · Effective Jan 1, 2019
act · Effective n/a
code_of_ethics · Effective Jan 1, 2020
strategy · Effective Jan 1, 2023
policy · Effective Jan 1, 2024
advisory
Lead technical regulator for ICT and AI standards.
data_protection
Supervisory authority for data privacy and NDPA enforcement.
advisory
Technical arm of NITDA for AI research and testing.
central_coordinator
Policy oversight and national digital strategy.
May 14, 2026 · law_amended
Internet Code of Practice enters into force, covering AI and emerging technologies
Open source →Apr 1, 2026 · news
President Tinubu announces deployment of AI-enabled camera networks to combat insecurity in Plateau State
Open source →Mar 9, 2026 · law_amended
Nigeria Central Bank orders fintechs to comply with automated AML regulations covering AI
Open source →Feb 12, 2026 · law_amended
Nigerian Communications Commission issues guidance notes on Internet Code of Practice 2026
Open source →Jan 12, 2026 · law_amended
Nigeria set to pass AI law by end of March 2026
Open source →Aug 3, 2025 · law_amended
Nigeria SEC calls for unified regulation, AI surveillance to support digital asset boom
Open source →May 19, 2025 · news
Central Bank of Nigeria launches consultation on automated anti-money laundering baseline standards, covering AI
Open source →May 2, 2025 · news
Nigeria developing AI policy to safeguard press freedom, says information minister
Open source →Apr 29, 2025 · law_amended
Nigeria to update Communications Law for AI, 5G, Cybersecurity
Open source →Mar 20, 2025 · guideline_issued
NHRC announces plans for AI guidelines and other initiatives
Open source →Feb 10, 2025 · news
Paris Charter on AI signed
Open source →Nov 26, 2024 · law_amended
Nigeria introduces national AI bill
Open source →Oct 11, 2024 · law_amended
NITDA calls for Africa’s active role in global AI regulation
Open source →Oct 9, 2024 · law_amended
JAMB registrar demands regulations on use of AI in academics
Open source →Aug 1, 2024 · news
Nigeria releases National AI Strategy
Open source →May 21, 2024 · guideline_issued
Nigeria set to unveil national framework to regulate use of AI
Open source →Apr 14, 2024 · law_amended
Nigeria aims to be key player in AI regulation and development
Open source →Mar 15, 2024 · news
NCC advocates responsible AI to guarantee consumer rights
Open source →Aug 27, 2023 · news
Nigeria mulls AI strategy, to engage researchers
Open source →Jun 13, 2023 · law_amended
Nigeria Data Protection Bill passed into law
Open source →No tracked international memberships yet
Last checked May 26, 2026