NITDA Warns Nigerians Against Sharing Sensitive Data With AI Chatbots
NITDA Warns Nigerians Against Sharing Sensitive Data With AI

Nigeria's information technology regulator, the National Information Technology Development Agency (NITDA), has issued a public advisory urging citizens to refrain from sharing sensitive personal details with artificial intelligence platforms, citing significant privacy and security risks.

The advisory, released through NITDA's Computer Emergency Readiness and Response Team (CERRT.NG) under reference number NITDA-0926-003, addresses the growing reliance on AI chatbots for everyday tasks. The agency noted that many Nigerians now use AI tools such as ChatGPT, Claude, Gemini, Copilot, and Meta AI for schoolwork, job applications, health queries, and business matters, which has led some users to share information that could put them at risk.

Data Types That Put Users at Risk

Among the types of data that Nigerians commonly submit to AI platforms, the agency highlighted National Identification Numbers (NIN), Bank Verification Numbers (BVN), bank account details, photographs, medical results, and personal information about family members. CERRT.NG warned that once this information is entered into an AI system, users may lose direct control over it, as such data may be stored, logged, or used to train the AI provider's models.

The agency also cautioned that a data breach could expose this information to third parties, potentially creating opportunities for identity theft, impersonation, and financial fraud. Beyond data privacy, CERRT.NG raised concerns about the accuracy of AI-generated responses, noting that AI tools can deliver answers that sound authoritative but are factually wrong or based on outdated information. Acting on such responses in areas such as health, law, finance, or education could cause harm to users.

Guidelines for Safer AI Use

NITDA issued fresh guidelines for individuals and organisations to use AI platforms more safely. Organisations were specifically warned against uploading internal documents to AI tools unless such use has been formally authorised. The agency called on companies to establish AI governance or AI transformation policies that clearly define approved tools, permitted use cases, data-handling rules, and accountability for AI use.

The advisory further urged users to follow existing AI, information security, and data protection policies within their organisations. Members of the public seeking further guidance can reach CERRT.NG at cerrt@nitda.gov.ng.

Recommended Measures for Data Protection

CERRT.NG outlined several recommended measures, including implementing an organisation-wide AI governance or AI transformation policy that defines approved tools, permitted use cases, data-handling rules, and accountability for AI use. Users are advised to remove, anonymise, or pseudonymise personally identifiable information (PII) and sensitive information before using AI tools, and to verify the AI platform's privacy and data-handling terms before use.

Other recommendations include not uploading internal documents unless specifically authorised, and following the organisation's AI, information security, and data protection policies. The advisory comes amid broader government efforts to promote digital skills, including the recent launch of the Digital Training Academy (DTA), a free skills programme targeting 32,000 Nigerians across the country's 36 states and the FCT, run in partnership with Coursera, offering free learning licences to successful applicants.