Nigeria - Market Insights
Law Over Borders Comparative Guide: Artificial Intelligence Law Guide
Artificial Intelligence Law Guide
Artificial intelligence regulation in Nigeria: An overview of the legal and policy framework
Nigeria is embracing artificial intelligence (AI) across fintech, healthcare, agriculture, telecommunications, education, and public services. While AI promises economic growth and innovation, it also raises significant legal, ethical, and societal risks including algorithmic bias, lack of transparency, privacy infringements, liability gaps, and cybersecurity threats.
As of May 2026, Nigeria does not have a comprehensive standalone AI Act. Regulation remains fragmented and indirect, anchored primarily in the Nigeria Data Protection Act (NDPA) 2023, supported by the non-binding National Artificial Intelligence Strategy (NAIS) 2025, sector-specific guidelines, and emerging legislation such as the National Digital Economy and E-Governance Bill 2025. This framework draws inspiration from international standards (OECD AI Principles, UNESCO AI Ethics Recommendations, and elements of the EU AI Act) while aiming to balance innovation with responsible governance.
What national laws and policies primarily regulate AI in Nigeria?
The principal instruments are:
- Nigeria Data Protection Act (NDPA) 2023. The NDPA is the cornerstone for AI regulation, as most AI systems process personal data. It governs automated decision-making and profiling.
- National Artificial Intelligence Strategy (NAIS) 2025. This is a comprehensive policy roadmap issued by the Federal Ministry of Communications, Innovation and Digital Economy (FMCIDE) in collaboration with the National Information Technology Development Agency (NITDA) and the National Centre for Artificial Intelligence and Robotics (NCAIR). It outlines ethical governance under Pillar 5 but is non-binding.
- National Digital Economy and E-Governance Bill 2025 (pending enactment, expected passage around March 2026). This bill contains dedicated provisions (Chapter Five, Parts XI and XII) on ethical AI governance, risk classification, obligations, regulatory sandboxes, and enforcement.
- Proposed AI-Specific Bill (2023). This bill was sponsored by Hon. Sada Soli and has passed its first reading. It proposes a National Artificial Intelligence Council as apex regulator, mandatory registration/licensing, and risk-based controls.
- NITDA Internet Code of Practice 2026 (Chapter Five). This code comprises sector-specific rules for Internet Access Service Providers (IASPs) deploying AI tools in network management and customer engagement processes.
Supporting laws include:
- Constitution of the Federal Republic of Nigeria 1999 (as amended) — section 37 (right to privacy).
- Nigerian Communications Commission (NCC) Act 2003 — consumer protection and fair competition in AI-driven telecom services.
- Cybercrimes (Prohibition, Prevention, etc.) Amendment Act 2024 — cybersecurity for AI systems.
- Intellectual property laws (Copyright Act 2022, Patents and Designs Act, Trademarks Act).
- Sector-specific rules (e.g., CBN guidelines on robo-advisory services).
To whom do the laws apply?
The NDPA applies to data controllers and processors (including AI developers and deployers) who:
- are domiciled, resident, or operating in Nigeria;
- process personal data of data subjects in Nigeria; or
- process personal data within Nigeria.
Under the NITDA Internet Code of Practice 2026 (“Internet Code”), additional obligations apply specifically to Internet Access Service Providers (IASPs) deploying AI for network management or customer engagement. AI “actors” under the NAIS and emerging Bill include developers, deployers, importers, and users of AI systems. Both natural and juristic persons are covered. The framework targets high-impact sectors such as finance, healthcare, employment, law enforcement, and critical infrastructure.
What is the territorial scope of the law?
The NDPA has extraterritorial reach where personal data of Nigerian residents is processed, regardless of the location of the AI system. The emerging Digital Economy Bill is expected to extend oversight to cross-border AI services affecting Nigeria. The NAIS and Internet Code encourage alignment with international standards.
What AI systems or operations are regulated?
“Processing” under the NDPA includes automated operations on personal data relevant to AI. The emerging Bill introduces risk classification. The NITDA Internet Code of Practice 2026 (section 5.4) specifically regulates AI deployment by IASPs in network management and customer engagement (e.g., non-human interfaces on complaint platforms). Regulatory sandboxes are proposed for controlled testing.
Are there specific definitions or categories of AI subject to higher protection?
The NDPA defines “automated decision-making” (section 65). The emerging Bill is expected to classify systems by risk level. Higher protections apply to high-risk AI and sensitive personal data. The Internet Code requires prior notification and safeguards for AI tools affecting network integrity or consumer data.
What requirements must be fulfilled to develop or deploy AI systems?
AI systems processing personal data must comply with NDPA lawful bases (section 25). High-risk AI systems are subject to requirements such as DPIAs, risk assessments, transparency, and human oversight.
Under the NITDA Internet Code of Practice 2026 (section 5.4.1–5.4.2), IASPs must:
- Notify the Nigeria Data Protection Commission (NDPC) prior to deployment, detailing affected services, timelines, and sunsetting plans.
- Notify impacted subscribers (especially for non-human interfaces).
- Ensure there is no breach of network integrity, cybersecurity frameworks, or consent rules.
- Maintain capability to withdraw AI tools if required.
What obligations apply to AI developers, deployers, and users?
The key obligations (NDPA, sections 24, 27–28, 39–40, reinforced by NAIS, emerging Bill, and Internet Code) are:
- Fair, lawful, transparent, and accountable processing.
- Bias mitigation, explainability, and human oversight.
- Security safeguards and breach notification (72 hours to NDPC).
- For IASPs: Compliance with anti-spam rules, takedown procedures for unlawful content, and collaboration with law enforcement.
What rights do individuals have in relation to AI systems?
Section 37 of the NDPA grants the right not to be subject to solely automated decisions with legal or significant effects, with rights to human intervention, to express a view, and to contest decisions. Additional rights include access, rectification, erasure, and complaint to the NDPC. The Internet Code supports consumer notification and redress for AI-affected services.
What rules regulate specific AI issues such as transparency, bias, and IP?
- Transparency and explainability are required, particularly for customer-facing AI systems.
- Bias discrimination risks must be identified and mitigated.
- Intellectual property and cybersecurity are governed by existing laws and the Internet Code.
- Unlawful content is subject to takedown notices requiring compliance within 24 hours, and IASPs are not subject to a general monitoring obligation.
What rules govern cross-border aspects or international cooperation?
NDPA transfer rules (sections 41–43) apply. Nigeria also participates in international AI initiatives, including the Bletchley Declaration and the African Union Continental AI Strategy.
What are the investigatory and enforcement powers of the regulator?
The NDPC enforces data-related AI issues. NITDA/NCC oversee the Internet Code. Regulators can investigate, issue orders, mandate audits, and require takedowns. The emerging Bill proposes expanded powers including suspension of high-risk AI.
What are the sanctions and remedies for non-compliance?
- Administrative fines (NDPA) — up to the greater of NGN 10 million or 2% of annual gross turnover. Similar penalties under the emerging Bill and Code violations.
- Compensation, profit disgorgement, and criminal sanctions (fines/imprisonment).
- Civil actions and judicial review available.
Conclusion
Nigeria’s AI regulatory landscape is evolving rapidly from a policy-driven, data-protection-centric foundation, strengthened by sector-specific rules (such as the NITDA Internet Code of Practice 2026), towards dedicated legislation. Proactive compliance with the NDPA, alignment with the NAIS, preparation for the Digital Economy Bill, and adherence to IASP-specific requirements will position organisations to responsibly harness AI while minimising legal risks.