Nigeria has no AI statute, and after a check at the issuing bodies' own domains on 17 August 2026 it has no AI guideline that binds a private operator either. What binds is the Nigeria Data Protection Act 2023, administered by the Nigeria Data Protection Commission, applied to systems that happen to be models. NITDA, the agency this guide is named for, publishes thirty six regulatory instruments and none of them is about artificial intelligence. Nigerian operators whose systems serve EU users remain within scope of the EU AI Act's extraterritorial provisions regardless of where their infrastructure sits, and for most of them that, not Nigerian law, is the binding AI regime. This guide sets out what is actually there.
Key takeaways
- Nigeria has no AI statute and no AI-specific regulatory instrument that binds a private operator. The Nigeria Data Protection Act 2023 is the operative law for any AI system that processes personal data.
- The Nigeria Data Protection Act 2023, signed 12 June 2023, applies to the processing of personal data of Nigerian residents by automated means. The Nigeria Data Protection Commission (NDPC) administers the Act and has enforcement powers including administrative fines. AI systems that make or substantially inform consequential decisions about data subjects engage NDPA obligations directly.
- NITDA is the primary government technology body and issues real instruments on cloud computing, IT project clearance, electronic invoicing and interactive computer service platforms. Its regulations register carries no artificial intelligence instrument. Its one AI document is an AI Transformation Roadmap dated 11 March 2025, which sets the Agency's own direction and imposes nothing.
- No AI-specific instrument from the Central Bank of Nigeria, the Nigerian Communications Commission, the Securities and Exchange Commission or the health regulators could be read at their own domains on 17 August 2026. That does not mean a supervisor will not ask about a model. It means an operator should ask its own regulator directly rather than rely on a published account of rules that could not be found.
- Nigerian operators offering AI-enabled services to EU residents are within scope of Regulation (EU) 2024/1689 (the EU AI Act) for those deployments. The application deadline for Annex III high-risk systems is 2 December 2027, deferred by the Digital Omnibus, which has been in force since 27 July 2026. The Article 5 prohibitions, the Article 50 transparency duties, the general purpose AI obligations and Article 4 AI literacy were not deferred and have been enforceable since 2 August 2026.
- An AI governance programme built to EU AI Act standard will comfortably exceed what Nigerian law currently requires. The gap an operator should worry about is data protection compliance under the NDPA, which is a real and separately enforced obligation, not an AI framework.
The Nigerian AI regulatory landscape in brief
Nigeria is Africa's most populous country and its largest economy by nominal GDP, with a technology sector concentrated in Lagos that has produced significant fintech, healthtech, and agritech activity over the past decade. The Nigerian government treats AI as a strategic priority, and NITDA published an AI Transformation Roadmap on 11 March 2025 setting out its own intended direction. That ambition has not translated into a statutory framework, and, on the evidence of the issuing bodies' own publication indexes, it has not translated into a published national strategy or a regulatory guideline either.
The architecture that exists in 2026 is characteristic of early-stage AI governance in high-growth markets: a data protection statute with clear implications for automated decision-making, a technology regulator producing advisory guidance that carries de facto weight without statutory penalty backing, a national strategy that signals direction without creating binding obligations, and sector regulators who have moved ahead of national legislation to establish domain-specific expectations. This architecture requires disaggregated compliance analysis. The questions an operator must answer are: does your AI system process personal data of Nigerian residents (NDPA applies); do you operate in a sector regulated by CBN, NCC, SEC, or health authorities (sector guidance applies); does your system produce outputs used by EU residents (EU AI Act extraterritorial provisions apply); and are you engaged with Nigerian government procurement (Strategy alignment is a de facto criterion)?
The answers determine which obligations are legally binding and which represent voluntary best practice that signals alignment with the government's regulatory trajectory. The trajectory is clearly toward greater formalisation. Operators who build governance infrastructure consistent with international standards now will face a smaller compliance gap when Nigeria's legislative framework matures.
NITDA: the primary technology regulator
The National Information Technology Development Agency was established by the NITDA Act 2007 as the primary government body for information technology development and regulation in Nigeria. NITDA sits within the Federal Ministry of Communications, Innovation and Digital Economy and is responsible for developing and enforcing IT standards, policies, and guidelines across the public and private sectors.
NITDA maintains a public register of the instruments it issues. On 17 August 2026 that register listed thirty six guidelines, policies, standards and codes of practice, covering cloud computing, electronic invoicing, digital literacy, blockchain, 5G, public internet access, interactive computer service platforms and the 2019 Nigeria Data Protection Regulation. None of them is an artificial intelligence instrument. This guide previously described a NITDA National AI Policy of 2021 and set out the principles it articulates. That document is not in NITDA's register of regulations or in its publications list, and the description has been withdrawn.
The one artificial intelligence document NITDA publishes under its own name is the AI Transformation Roadmap, dated 11 March 2025 and listed in its publications section. A roadmap is a plan for what the Agency intends to do. It is not a guideline, it is not in the regulations register, and it does not create obligations for a private operator. This guide previously stated that NITDA published Guidelines on Artificial Intelligence in 2023, and set out four requirements those Guidelines were said to impose: contextual explainability, pre-deployment risk assessment, human oversight of consequential decisions, and data governance duties. No such document appears at nitda.gov.ng, and every one of those requirements has been withdrawn. An operator should not be building controls against them.
The practical position is therefore narrower than the title of this guide suggests. NITDA is a real regulator with real instruments, and several of them will touch an AI deployment incidentally: the cloud computing guidelines if the system runs on cloud infrastructure, the IT project clearance guidelines if the customer is a federal public institution, the code of practice for interactive computer service platforms if the product carries user generated content. What NITDA does not currently publish is any instrument that regulates artificial intelligence as such. The binding layer for an AI operator in Nigeria is data protection law, not NITDA guidance.
The national AI strategy: what could and could not be found
This guide previously described a National AI Strategy 2024, attributed it to the Federal Ministry of Communications, Innovation and Digital Economy with NITDA as co-lead, and listed seven strategic pillars. On 17 August 2026 the Ministry's own public resources section listed its reports, policies, forms and white papers, and contained no artificial intelligence strategy. NITDA's publications section contained no such document either. The seven pillars, and the account below of what the ethical and responsible AI pillar establishes, could not be read at either issuing body and have been withdrawn.
The withdrawal matters more than it might appear. A set of principles that an operator can point to in a procurement response, or design a governance programme around, is only useful if it exists and if its wording is the wording the government actually used. Six invented principles are worse than none, because they produce documentation that answers a question no Nigerian regulator asked.
What can be said at source is this. Nigeria's government treats AI as a priority and NITDA has published an AI Transformation Roadmap, dated 11 March 2025, setting out its own intended direction. Neither that roadmap nor any strategy document creates an obligation on a private operator. An operator bidding for Nigerian public sector work should ask the contracting institution directly which document it expects alignment with, rather than assuming a published national framework exists to be aligned with.
The Strategy also addresses international cooperation explicitly, and specifically flags alignment with the EU AI Act and the OECD AI Principles as objectives. This is relevant to operators navigating both Nigerian and EU regulatory environments: the Strategy's architects were deliberately converging Nigerian AI governance direction with international frameworks. An operator whose programme satisfies the OECD AI Principles (for which see the OECD AI principles operator guide on this site) will find significant overlap with Strategy requirements.
The Nigeria Data Protection Act 2023 and automated decision-making
The Nigeria Data Protection Act 2023 (NDPA) was signed into law on 12 June 2023, replacing the earlier Nigeria Data Protection Regulation 2019 (NDPR) which had been issued by NITDA. The NDPA is primary legislation with a dedicated regulatory authority, the Nigeria Data Protection Commission (NDPC), established under the Act with investigation and enforcement powers.
The NDPA applies to the processing of personal data of natural persons in Nigeria, including processing outside Nigeria where the purpose relates to offering goods or services to persons in Nigeria or monitoring the behaviour of persons in Nigeria. This extraterritorial scope means that an operator processing data of Nigerian residents from infrastructure located outside Nigeria is subject to the Act for that processing.
For AI operators, the NDPA's core obligations engage in the following scenarios. Where an AI system processes personal data to make or substantially inform a consequential decision about a data subject (a credit decision, insurance pricing, employment screening, access to healthcare, or government service eligibility), the operator is a data controller under the Act. The data controller must have a lawful basis for processing the personal data that the AI system uses. In most commercial contexts, this will be consent (which must be freely given, specific, informed, and unambiguous) or legitimate interest (which requires a balancing test and must not override the data subject's fundamental rights). Processing without a lawful basis exposes the controller to enforcement action by the NDPC.
The Act's purpose limitation principle requires that personal data be collected for specified, explicit, and legitimate purposes and not processed in a manner incompatible with those purposes. An AI system trained on data collected for one purpose that is then repurposed to make decisions for a different purpose without a fresh lawful basis is likely to be in breach of purpose limitation. This has direct implications for operators who retrain models on customer data or who repurpose data collected in one product context for AI applications in another.
Data accuracy obligations under the NDPA require controllers to take reasonable steps to ensure that personal data used in processing is accurate and, where necessary, kept up to date. For AI systems that rely on historical data to make predictions about current behaviour (credit scoring, fraud detection, recidivism prediction), accuracy obligations require ongoing data quality monitoring and mechanisms to correct inaccurate inputs that have influenced AI outputs.
The NDPA does not contain a provision directly equivalent to Article 22 of the EU General Data Protection Regulation, which gives data subjects the right not to be subject to fully automated decisions that significantly affect them without human review. However, the Act's general provisions on data subjects' rights to access information about their data and to object to processing that violates their rights engage the transparency and human oversight requirements of automated decision-making systems. This guide previously stated that the NDPC has published guidance setting an expectation that operators explain the basis of automated decisions and provide human review. The Commission's own resources section, checked on 17 August 2026, lists the Act in four languages, annual reports, registration guidance notices, a code of conduct, a public sector circular and a privacy by design white paper. It carries no guidance on automated decision making and none on artificial intelligence. That attribution has been withdrawn.
The Act provides for administrative sanctions, and the amounts differ according to whether the controller or processor is one of major importance. The specific figures previously given here are not reproduced, because the Act's text and the General Application and Implementation Directive are published by the Commission only as PDFs that could not be read by automated retrieval on 17 August 2026. An operator that needs the number should take it from the Act itself at ndpc.gov.ng rather than from a secondary account of it. What is confirmed at the Commission's own site is that it operates a registration regime for data controllers and processors, maintains a public register of those of major importance, licenses data protection compliance organisations, and runs a breach reporting channel.
Sector regulators and AI-specific obligations
Central Bank of Nigeria
The Central Bank of Nigeria is the primary regulator for banks, microfinance institutions, payment service providers, and other financial institutions in Nigeria. The CBN has issued risk management guidelines for financial institutions that address the use of algorithmic and AI-driven decision-making in credit, fraud detection, customer onboarding, and customer service. The core requirements that emerge from CBN guidance are model risk management, explainability for credit decisions, audit trail maintenance, and bias monitoring.
Model risk management requirements mean that AI models used for credit underwriting and risk assessment must be subject to the same validation, back-testing, and ongoing monitoring procedures that apply to statistical models. A bank using a machine learning system for credit scoring must be able to demonstrate to CBN examiners that the model has been independently validated, that its performance is monitored against defined metrics, and that there is a documented process for managing model failure or unexpected behaviour. These requirements align with the Basel Committee on Banking Supervision's guidance on the use of machine learning in financial risk management, which CBN has referenced in its own publications.
Explainability requirements mean that AI-driven credit decisions must be capable of being explained to affected customers in terms they can understand. A fully opaque model that produces a credit refusal without a human-interpretable basis is inconsistent with CBN guidance on fair treatment of customers. Operators running AI credit systems in Nigeria must implement interpretation layers that translate model outputs into communicable reasons.
The CBN's guidelines on Open Banking also have implications for AI operators: financial data shared under Open Banking arrangements is subject to data protection requirements that layer on top of the NDPA, and AI systems that consume Open Banking data feeds for financial analysis or credit decisions must manage data governance across both regulatory frameworks.
Nigerian Communications Commission
The Nigerian Communications Commission regulates telecommunications services and has issued consumer protection guidance that addresses AI-driven customer interactions. The NCC's Consumer Code of Practice for Licensed Operators includes provisions on automated customer service systems: consumers must be informed when they are interacting with an automated system rather than a human agent, and operators must provide accessible human escalation paths for consumers who request them.
This disclosure requirement is directly relevant to operators deploying AI chatbots, virtual assistants, or automated call centre systems in the Nigerian telecommunications market. The NCC's position mirrors the EU AI Act's transparency obligation for AI systems intended to interact with natural persons (Article 50 of Regulation 2024/1689), under which such systems must disclose their AI nature at the start of interaction. For operators already complying with Article 50 for their EU deployments, extending the disclosure mechanism to Nigerian deployments addresses NCC requirements at minimal incremental cost.
Securities and Exchange Commission
Nigeria's Securities and Exchange Commission has addressed AI in the context of algorithmic trading and AI-assisted investment advice. SEC guidance requires that algorithmic trading strategies be registered with the Commission and subject to pre-deployment testing. For investment advisers and fund managers using AI to generate or screen investment recommendations, SEC expects that AI-generated outputs be reviewed by qualified human professionals before being communicated to clients.
The SEC's AI guidance reflects a recognition that AI systems operating at scale in capital markets can amplify systemic risk if governance is inadequate. Operators in Nigeria's growing capital markets technology segment should treat SEC guidance as establishing binding operational requirements for their AI deployments in this sector, including registration, testing, and human oversight obligations that are not captured by the NDPA alone.
Health regulators
The National Health Insurance Authority and the Federal Ministry of Health have issued guidance on the use of AI in healthcare diagnosis, treatment recommendation, and insurance claims processing. The guidance requires that AI diagnostic tools deployed in clinical settings be registered as medical devices where they meet the definition of a medical device under Nigerian law, and that clinical AI systems be subject to clinical validation studies before deployment. Operators should consult current NAFDAC guidance on AI medical devices to confirm applicable registration requirements.
For AI operators in the healthtech segment, this creates a compliance pathway distinct from the NDPA: registration, clinical validation, and ongoing performance monitoring as conditions for deployment in clinical contexts. Operators entering the Nigerian health AI market should engage with NAFDAC (the National Agency for Food and Drug Administration and Control) on device classification before deployment.
EU AI Act extraterritorial exposure for Nigerian operators
Regulation (EU) 2024/1689, which entered into application in phases from August 2024, extends the EU AI Act's reach beyond EU-established entities. Article 2(1) of the Act applies it to providers that place AI systems on the EU market or put them into service in the EU, regardless of establishment, and to operators whose AI systems produce outputs used in the EU. A Nigerian company operating a recruitment AI platform that is used by European employers to screen candidates, a Nigerian fintech operating a credit scoring system that assesses EU-resident borrowers, or a Nigerian content moderation platform processing the posts of EU users: each is within scope of the Act for those deployments.
The practical consequence is that Nigerian operators with EU-facing AI products face two distinct regulatory environments simultaneously. For the EU-directed deployments, they must comply with the EU AI Act's provider and deployer obligations, including technical documentation (Article 11), risk management system (Article 9), data and data governance (Article 10), transparency and provision of information (Article 13), human oversight (Article 14), accuracy and robustness (Article 15), and conformity assessment procedures for Annex III high-risk systems. For the Nigeria-directed components of the same product, they must comply with the NDPA, NITDA guidelines, and applicable sector guidance.
The Annex III high-risk application date has moved. The Digital Omnibus reached political agreement on 7 May 2026, was approved by the Council on 29 June 2026 and entered into force on 27 July 2026 as Regulation (EU) 2026/1744. Annex III high-risk obligations now apply from 2 December 2027 and Annex I from 2 August 2028. This is adopted law, not a proposal. What was not deferred, and what has been enforceable since 2 August 2026, is the Article 5 prohibitions, the Article 50 transparency duties, the general purpose AI obligations and the Article 4 AI literacy duty. A Nigerian operator with an EU-facing chatbot owes the Article 50 disclosure now, whatever its high-risk classification timetable.
High-risk AI system categories under Annex III of the EU AI Act that are frequently relevant to Nigerian operators serving EU markets include: AI systems used in employment and workers management (including recruitment screening and CV sorting); AI systems used in access to essential private services (including credit scoring and insurance risk assessment); AI systems used in education and vocational training; and AI systems intended to be used by or on behalf of public authorities for law enforcement or border control. An operator in Nigeria operating in any of these categories for EU-facing deployments should treat EU AI Act compliance as a binding obligation, not a voluntary framework.
For a detailed analysis of how the EU AI Act applies to operators outside the EU, see the EU AI Act extraterritorial reach guide on this site.
Insurance and liability coverage for AI operators in Nigeria
The market for AI-specific liability insurance in Nigeria is at an early stage. Nigerian insurers do not currently offer dedicated AI liability products comparable to those available in EU or US markets. Operators deploying AI systems that carry material liability exposure (automated credit decisions, clinical AI, AI-driven fraud detection with false-positive risk) are likely to rely on professional indemnity, technology errors and omissions, and general commercial liability policies that have not been specifically designed for AI risk profiles.
For Nigerian operators with EU-facing AI deployments, cover written in more developed markets may be the more appropriate instrument. Munich Re's aiSure, distributed with Mosaic Insurance since 26 February 2026 with an initial capacity of 15 million in euros, US dollars or Canadian dollars, is a performance guarantee that settles on measurable performance data and requires technical due diligence before cover is written. Armilla is a Lloyd's coverholder writing a standalone AI liability policy with limits up to USD 25 million per organisation, and states that cover is not available in all jurisdictions. Both underwrite the governance quality of the system, so documented data governance, human oversight and monitoring are priced, not just declared.
The connection between insurance underwriting and AI governance quality is the same in the Nigerian context as in more mature markets: a well-documented, well-governed AI system with clear human oversight mechanisms, audit trails, and bias monitoring is a better insurance risk than one that lacks these features. Building governance infrastructure that satisfies NDPA requirements and EU AI Act obligations simultaneously reduces both regulatory exposure and insurance cost.
How Nigeria compares to other African and global jurisdictions
The honest comparative picture, after this check, is that Nigeria sits in the same place as most of its continental peers rather than ahead of them. It has a modern data protection statute with a functioning commission behind it, which is more than many jurisdictions have. It does not have an AI instrument that binds a private operator, and neither does Kenya, whose binding layer is likewise section 35 of its Data Protection Act, 2019. The African Union Executive Council endorsed a Continental Artificial Intelligence Strategy at its 45th Ordinary Session in Accra on 18 and 19 July 2024, which coordinates member states without binding operators in any of them.
Relative to the major global frameworks, Nigeria's approach resembles the United States federal position: advisory at the national level, sector-based at the regulatory level, without a comprehensive statute. The difference is that the US has a deeper ecosystem of sector AI guidance (particularly from the Office of the Comptroller of the Currency, the Consumer Financial Protection Bureau, and the Equal Employment Opportunity Commission) and a more developed voluntary framework ecosystem (the NIST AI Risk Management Framework 1.0 of January 2023 and its Generative AI Profile, NIST AI 600-1, of July 2024). For a comparison across the US, EU, and UK approaches, see the three-jurisdiction liability comparison on this site.
The EU AI Act is the most structurally demanding framework with which Nigerian operators must engage, both because of its extraterritorial reach and because of the technical specificity of its requirements. Nigeria's domestic framework, in its current form, does not approximate the EU's product-safety model for AI systems. There is no Nigerian equivalent of Annex III high-risk classification, no mandatory conformity assessment procedure, and no centralised AI system registry. An operator who has completed EU AI Act conformity assessment for a high-risk system will have produced documentation and implemented governance mechanisms that substantially exceed current Nigerian domestic requirements for the same system.
What operators should do now
The absence of a comprehensive Nigerian AI statute does not mean Nigeria is a low-governance market for AI deployment. The NDPA, NITDA guidelines, sector regulatory guidance, and EU AI Act extraterritorial obligations together create a substantive and multi-layered compliance environment. The following steps represent the practical compliance priorities for operators deploying AI in Nigeria in 2026.
First, assess NDPA applicability to your AI deployment. If your AI systems process personal data of Nigerian residents, the Act applies regardless of where you process that data. Confirm that you have a lawful basis for each processing activity and that your data governance practices satisfy purpose limitation, accuracy, and security requirements. The Act does not contain a provision equivalent to Article 22 of the GDPR, and the Commission has published no guidance on automated decision making, so the controls that matter are the ordinary ones: lawful basis, purpose limitation, accuracy and security, applied to a system that happens to be a model.
Second, check NITDA's regulations register for the instruments that actually touch your deployment, rather than for an AI guideline. Cloud computing, IT project clearance for federal public institution customers, and the code of practice for interactive computer service platforms are the ones most likely to apply. Document your governance posture anyway, in a form that can be presented on request, but do not represent it as compliance with a NITDA AI guideline.
Third, identify which sector regulator governs your activities and ask it directly. This guide previously set out AI-specific requirements attributed to the Central Bank of Nigeria, the Nigerian Communications Commission, the Securities and Exchange Commission, the National Health Insurance Authority and NAFDAC. None of those requirements could be read at the regulators' own domains on 17 August 2026, and they have been withdrawn. That is not the same as saying no such expectations exist. Sector regulators supervise through examination and correspondence as much as through published instruments, and a bank deploying a credit model in Nigeria should expect model validation questions from the CBN whether or not a circular names artificial intelligence. The point is that this desk cannot tell you what those requirements say, and neither can anything that quotes this desk.
Fourth, assess your EU AI Act exposure. If any component of your AI deployment produces outputs used by EU residents, map those components against the EU AI Act's risk classification. For Annex III high-risk systems, initiate or continue conformity assessment procedures. The Digital Omnibus deferral is adopted and in force, so the Annex III date is 2 December 2027. Do not read that as a blanket delay: the Article 5 prohibitions, the Article 50 transparency duties, the GPAI obligations and Article 4 AI literacy were never deferred and are enforceable now.
Fifth, document your AI governance programme in a form that is legible across both Nigerian and EU regulatory expectations. A governance documentation set that includes system purpose and scope, training data description and governance, risk assessment findings, testing and validation records, human oversight mechanisms, incident response procedures, and monitoring arrangements will satisfy the audit requirements of NITDA guidelines, NDPC data protection obligations, and EU AI Act technical documentation requirements simultaneously. Building one documentation set that satisfies both environments is more efficient than maintaining separate governance artefacts for each jurisdiction.
Frequently asked questions
Does Nigeria have a standalone AI law in 2026?
No. Nigeria has no AI statute, and a check of NITDA's regulations register, NITDA's publications and the Federal Ministry's public resources on 17 August 2026 found no AI policy, AI guideline or national AI strategy at any of them. The binding instrument for an AI operator is the Nigeria Data Protection Act 2023.
What is NITDA's role in AI governance?
NITDA, established by the NITDA Act 2007, is Nigeria's primary body for information technology policy and regulation, and it issues instruments that will touch an AI deployment incidentally, on cloud computing, IT project clearance for federal public institution customers, and interactive computer service platforms. It does not currently publish any instrument regulating artificial intelligence as such. Its one AI document is the AI Transformation Roadmap of 11 March 2025, a statement of the Agency's own plans.
What does the Nigeria Data Protection Act 2023 require for AI systems?
The NDPA, signed into law on 12 June 2023, applies to the processing of personal data of Nigerian residents by automated means. Where an AI system processes personal data to make or substantially inform a consequential decision about a data subject, the operator is a data controller under the Act and must have a lawful basis for processing, respect purpose limitation, ensure data accuracy, and implement appropriate technical and organisational safeguards. The NDPC has enforcement powers including administrative fines.
Is there a Nigerian national AI strategy operators should align with?
None could be found. The Federal Ministry of Communications, Innovation and Digital Economy's public resources section and NITDA's publications section, both checked on 17 August 2026, list no national artificial intelligence strategy. This guide previously described one with seven pillars and six ethical principles, and that description has been withdrawn. An operator bidding for Nigerian public sector work should ask the contracting institution which document it expects alignment with.
Are Nigerian operators subject to the EU AI Act?
Yes, if they place AI systems on the EU market or their AI systems produce outputs used in the EU. Regulation (EU) 2024/1689 applies extraterritorially: a Nigerian company operating an AI system whose outputs are used by EU residents is within scope for those deployments. High-risk system obligations under Annex III (including technical documentation, conformity assessment, and registration) apply. The deadline for Annex III high-risk systems is 2 December 2027, deferred by the Digital Omnibus, in force since 27 July 2026.
What sector regulators govern AI in Nigeria?
The Central Bank of Nigeria (CBN) governs AI in banking and financial services, with guidance on model risk management, explainability, and bias monitoring for credit and fraud AI. The Nigerian Communications Commission (NCC) requires disclosure when consumers interact with automated systems. The Securities and Exchange Commission (SEC) governs algorithmic trading and AI investment advice. The National Health Insurance Authority and NAFDAC govern AI in healthcare and medical device contexts. For operators in these sectors, the relevant regulator's guidance creates the binding AI compliance floor beyond the NDPA baseline.
References
- Nigeria Data Protection Act 2023, signed into law 12 June 2023. National Assembly of the Federal Republic of Nigeria.
- Nigeria Data Protection Commission, resources section, checked 17 August 2026 at ndpc.gov.ng. Carries the Act in four languages, annual reports, registration guidance notices, a code of conduct, a public sector circular and a privacy by design white paper. No guidance on automated decision making and none on artificial intelligence.
- NITDA, AI Transformation Roadmap, 11 March 2025. Verified at nitda.gov.ng. The only artificial intelligence document NITDA publishes.
- NITDA, regulations register, checked 17 August 2026 at nitda.gov.ng. Thirty six instruments, none on artificial intelligence.
- Federal Ministry of Communications, Innovation and Digital Economy, public resources, checked 17 August 2026 at fmcide.gov.ng. No national artificial intelligence strategy listed.
- NITDA Act 2007, National Information Technology Development Agency Act, Federal Republic of Nigeria.
- Central Bank of Nigeria, Nigerian Communications Commission, Securities and Exchange Commission and NAFDAC: no AI-specific instrument could be read at any of these regulators' own domains on 17 August 2026. Earlier references to such instruments have been withdrawn.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (EU AI Act). Official Journal of the European Union, 12 July 2024.
- EU AI Act, Annex III (high-risk AI system categories), Article 2(1) (scope including extraterritorial application), Article 9 (risk management), Article 10 (data and data governance), Article 11 (technical documentation), Article 13 (transparency), Article 14 (human oversight), Article 50 (transparency obligations for AI systems interacting with natural persons).
- Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026. Annex III high-risk obligations apply from 2 December 2027, Annex I from 2 August 2028.
- Directive (EU) 2024/2853 on liability for defective products (Product Liability Directive), entered into force 9 December 2024. Relevant to AI system defect liability for operators placing systems on the EU market.
- OECD AI Principles, 2019, revised 3 May 2024. Organisation for Economic Co-operation and Development.
- NIST AI Risk Management Framework 1.0, National Institute of Standards and Technology, January 2023.
- Munich Re, aiSure, distributed with Mosaic Insurance from 26 February 2026, initial capacity 15 million in euros, US dollars or Canadian dollars.
- Armilla, standalone AI liability policy, limits up to USD 25 million per organisation. Lloyd's coverholder.
- Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal). AI chatbot liability case: Air Canada held liable for its AI agent's misrepresentation. Frequently cited in AI liability analysis.
- Mata v. Avianca, Inc., 22-cv-1461 (S.D.N.Y. 2023). Sanctions imposed on attorneys who submitted AI-generated hallucinated case citations without verification.