Nigeria - AI Code of Practice (2025)
Draft Code of Practice for Artificial Intelligence (NITDA)
Nigeria
RAI-NG-NA-DCPAIXX-2025Nigeria - AI Code of Practice (2025) is Draft in Nigeria as of 9 Sep 2026.
RegulationGovernance and OversightRisk ManagementData Protection and PrivacyThe Draft Code of Practice for Artificial Intelligence, released by Nigeria's National Information Technology Development Agency (NITDA) in 2025, sets out safety, transparency, and risk management rules for AI providers and deployers. Currently a Draft, it proposes mandatory risk assessments and incident reporting to be monitored by NITDA.
Summary
This entry records the National Information Technology Development Agency’s (NITDA) Draft Code of Practice for Artificial Intelligence (AI). NITDA has been developing national AI policy and strategy documents since 2022 and, as part of that programme, has signalled the preparation of a dedicated Code of Practice for AI to operationalise ethical, safety and regulatory expectations for AI tools (including generative AI). The draft is intended as a non-sector-specific code to set baseline requirements for AI system providers, deployers, public sector procurers and large platform operators that affect Nigerians. Key themes in the draft include governance and institutional responsibilities, risk-based classification of systems, mandatory risk assessments and impact assessments, transparency and user notice obligations, human oversight, data protection and privacy safeguards, cybersecurity requirements, documentation and record-keeping (including logging for audits), conformity assessment and registration for higher-risk systems, incident reporting and market surveillance, and enforcement measures including administrative penalties and remedial actions.
The draft reflects Nigeria’s broader AI policy ecosystem (the National AI Policy/Strategy and the establishment of the National Centre for Artificial Intelligence and Robotics — NCAIR) and is positioned to complement existing instruments such as the Nigeria Data Protection Regulation (NDPR) and Cybercrimes Act. Because NITDA’s work tracks international developments, the draft draws on international models (notably the EU AI Act and other plurilateral guidance) while asserting Nigeria-specific approaches — for example, considerations for local content, language inclusivity, and constraints of Nigerian infrastructure. The draft emphasises stakeholder engagement and public consultation as part of its finalisation, and the agency has invited contributions to the national AI policy and strategy processes. As a draft regulation, the Code proposes procedural obligations for providers (e.g., risk management systems, pre-deployment assessments, mandatory transparency notices, human oversight and complaint mechanisms), investigatory powers for regulators and provisions for cooperation with other sectoral regulators (finance, health, communications). It also outlines proposed thresholds for higher-risk classification, though many quantitative thresholds are left to the final text and implementing guidance. The Code seeks to balance innovation-supporting measures such as regulatory sandboxes and incentives for trustworthy AI with enforceable measures to protect fundamental rights and public safety. This entry compiles available official announcements and public sources that indicate the draft's existence and summarises typical content and compliance implications based on NITDA’s announced direction and comparative international practice.
Full article
Read full text ↗Overview
The Draft Code of Practice for Artificial Intelligence is a NITDA-led instrument intended to set national baseline standards for the development, deployment and use of AI technologies in Nigeria. It is framed to operationalise the principles of the National Artificial Intelligence Policy and the National AI Strategy developed by the National Centre for Artificial Intelligence and Robotics (NCAIR) under NITDA. The Code is drafted as a risk-based, technology-neutral framework describing obligations for AI system providers, operators and procurers, with a focus on protecting fundamental rights, ensuring data protection and promoting cybersecurity. NITDA has publicly announced its work on AI policy and the Code and has invited stakeholder contributions as part of its consultation process; see NITDA’s public engagement and the NCAIR strategy documents for context and background. For official engagement, NITDA has historically used its website and dedicated forms and portals to solicit inputs and publish drafts and related strategy documents, and the Code is intended to sit alongside other national instruments such as the Nigeria Data Protection Regulation (NDPR). For details about NITDA’s AI strategy and consultation process, see NITDA and NCAIR materials and the public call for contributions.
Definitions
The Draft Code establishes key definitions to ensure clarity and consistent application. Definitions typically include: "Artificial Intelligence system" (a system that performs tasks with varying degrees of autonomy using models, algorithms or rule-based logic); "AI provider" (entity that develops or supplies an AI system for use); "operator/deployer" (entity that deploys or makes an AI system available for use); "high-risk AI" (systems whose malfunction or bias may significantly affect fundamental rights, safety, health, or critical services); "personal data" (as adopted from the NDPR); "human oversight" (measures enabling human intervention in decision-making); and "conformity assessment" (procedures to verify that systems meet required standards). The Code cross-references existing statutory terms used in the NDPR and Cybercrimes Act to maintain legal coherence and to make data protection obligations immediately applicable when an AI system processes personal data.
Governance and Institutional Framework
The draft situates NITDA as the lead technical regulator responsible for establishing technical standards, coordinating with sector regulators and supervising compliance for AI systems deployed or having material effect in Nigeria. It envisages cooperative governance arrangements with the Federal Ministry of Communications, Innovation and Digital Economy (FMCIDE), the National Centre for Artificial Intelligence and Robotics (NCAIR), the Nigerian Communications Commission (NCC), the National Broadcasting Commission (NBC) and sectoral bodies such as the Central Bank of Nigeria (for fintech/financial services) and regulatory health agencies for clinical AI. The Code proposes an AI Ethics Expert Group to provide advisory opinions, as well as a registry function (or interoperable registries) for higher-risk systems to facilitate market surveillance and incident response. Institutional coordination mechanisms include mandatory information-sharing protocols, joint inspection powers and memoranda of understanding for cross-regulatory enforcement. NITDA’s public announcements and NCAIR strategy documents outline similar institutional roles and have been used to shape the draft’s governance architecture.
Key Focus Areas
The Draft Code concentrates on a number of substantive requirements: 1) Risk management: mandatory risk assessment processes from design through lifecycle, including mitigation plans. 2) Safety, testing and evaluation: pre-deployment testing, validation datasets, robustness checks, accuracy reporting and post-deployment monitoring. 3) Transparency and disclosure: user-facing notices describing AI use, system capabilities, limits and contact points; provenance and labeling of synthetic content; and disclosures to authorities on demand. 4) Data protection and privacy: compliance with the Nigeria Data Protection Regulation (NDPR) including lawful basis for processing, data minimisation, retention limits and data subject rights. 5) Fundamental rights: measures to prevent discriminatory outcomes, disparate impacts, and protection of vulnerable groups. 6) Conformity and registration: obligations for higher-risk AI systems to submit technical documentation, risk assessments, and possibly undergo third-party conformity assessments before market entry. 7) Cybersecurity and model security: baseline security controls for models, supply chain integrity, vulnerability management and incident reporting obligations. 8) Accountability and documentation: maintenance of technical documentation, data governance records and logs sufficient to enable audits and investigations. 9) Liability and redress: guidance on provider and deployer liability, remedial measures and accessible grievance mechanisms for affected persons. 10) Enforcement and penalties: a graduated enforcement regime including notices, remediation orders and administrative fines or sanctions. These themes mirror international best practice while integrating Nigeria-specific governance objectives.
Implementation Framework
The Code proposes a phased implementation approach. Early stages prioritise high-impact categories (public sector procurement, critical infrastructure, health and finance) and require immediate risk management and transparency measures. Mid-term steps include establishment of registries, formal conformity assessment pathways and publication of technical standards for testing and certification. Longer-term measures include institutional capacity-building, creation of data and model access protocols for regulators (for lawful investigations), and incentives such as sandboxes to support local innovation. The draft indicates that NITDA will publish implementing guidance and technical standards, and will establish a compliance helpdesk and sandbox regime to operationalise the code. The Code therefore combines mandatory duties with supportive mechanisms to allow businesses and research institutions to adapt. For the design of regulatory sandboxes and staged deployment, see the National AI Strategy and NITDA stakeholder materials.
Monitoring and Evaluation
Monitoring combines market surveillance, provider reporting and periodic audits. The draft describes obligations for incident reporting (security breaches, safety incidents and systemic failures) and periodic risk reviews (e.g., annual or on-material-change). NITDA is enabled to demand technical documentation, logs and model documentation on request to investigate harms. The Code also proposes key performance indicators for oversight, such as the number of compliance audits, time to remediation, and measures of fairness and accuracy for monitored systems. Mechanisms for independent evaluation (academic or third-party auditors) and public transparency reports from regulated entities are also recommended, forming a continuous improvement loop where empirical findings inform updates to technical guidance.
Penalties, Liability, and Appeals
The draft adopts a graduated enforcement model: guidance and notices for low-level breaches, mandatory remediation plans and corrective orders for mid-level breaches, and administrative fines or suspension for serious or repeated violations. The Code clarifies civil liability exposure remains available under existing tort and contract law, and it provides for administrative penalties where appropriate. It includes rights to an administrative appeal against NITDA’s enforcement decisions and envisages mechanisms for judicial review consistent with Nigerian administrative law. The draft emphasises proportionality, remedial focus, and due process, while reserving strong measures for AI systems that cause significant harm to life, liberty, or fundamental rights.
Relationship to Other Instruments
The Code is designed to complement and not replace existing laws: it cross-references the Nigeria Data Protection Regulation (NDPR) for privacy obligations, the Cybercrimes Act for offences related to misuse and hostile automation, sectoral statutes (banking, health) for domain-specific compliance, and the Companies and Allied Matters Act for corporate accountability where relevant. It proposes coordination clauses requiring entities to maintain compliance with sectoral regulators and to notify relevant agencies of cross-cutting risks. The Code also leverages NITDA’s existing mandates under the NITDA Act to issue technical standards and codes of practice and is intended to be read alongside the National AI Strategy and NCAIR operational guidance (see NITDA and NCAIR).
International Alignment
While tailored to Nigeria’s context, the Draft Code explicitly references international instruments and best practices to ensure cross-border interoperability. It draws on the risk-based approach of the European Union’s AI Act, OECD AI principles and multilateral standards for transparency, safety testing and data governance. It emphasises cooperation on cross-border investigations, mutual legal assistance for cybersecurity incidents, and harmonisation with global norms to facilitate trade in AI services. The draft balances adoption of international norms with Nigeria-specific provisions such as local content promotion, language accessibility, and technical capacity-building to support domestic innovation. Public statements from NITDA and analysis by international legal firms note the agency’s intention to leverage global frameworks while preserving policy space for national priorities.
Implementation Timeline
| Milestone | Indicative Timing |
|---|---|
| Public consultation opened (policy and code discussion) | 2022–2025 (rolling) |
| Publication of National AI Strategy (NCAIR) | August 2024 (strategy published) |
| Draft Code prepared (consultation draft) | 2025 (drafting and stakeholder engagements) |
| Target finalisation & implementing guidance | Planned phased adoption — to be confirmed in final instrument |
Sources and References
| Source | Type |
|---|---|
| National Artificial Intelligence Strategy 2024 | Government Website |
| AI Transformation Roadmap | Government Website |
Requirements for a company
What an organisation has to do under Nigeria - AI Code of Practice (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.
Must do
13- Establish lifecycle risk assessment processes and mitigation plans.AI system providers and operators
- Comply with the Nigeria Data Protection Regulation (NDPR).AI system providers and operators processing personal data
- Implement measures to prevent discriminatory outcomes and protect vulnerable groups.AI system providers and operators
- Submit technical documentation and risk assessments for higher-risk AI systems.Providers of higher-risk AI systems
- Undergo third-party conformity assessments for higher-risk AI systems.Providers of higher-risk AI systems
- Conduct pre-deployment testing, robustness checks, and post-deployment monitoring.AI system providers and operators
- +7 more in the table below
Must not do
0Nothing in this category.
Should do
1- Publish public transparency reports.Regulated entities
Should not do
0Nothing in this category.
Who must do what
The obligations under Nigeria - AI Code of Practice (2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | AI system providers and operators | Establish lifecycle risk assessment processes and mitigation plans. “mandatory risk assessment processes from design through lifecycle, including mitigation plans.” | Before placing on market | Key Focus Areas (Risk management) | Critical |
| 2 | AI system providers and operators processing personal data | Comply with the Nigeria Data Protection Regulation (NDPR). “compliance with the Nigeria Data Protection Regulation (NDPR) including lawful basis for processing.” | — | Key Focus Areas (Data protection and privacy) | Critical |
| 3 | AI system providers and operators | Implement measures to prevent discriminatory outcomes and protect vulnerable groups. “measures to prevent discriminatory outcomes, disparate impacts, and protection of vulnerable groups.” | Before placing on market | Key Focus Areas (Fundamental rights) | Critical |
| 4 | Providers of higher-risk AI systems | Submit technical documentation and risk assessments for higher-risk AI systems. “obligations for higher-risk AI systems to submit technical documentation, risk assessments.” | Before market entry | Key Focus Areas (Conformity and registration) | Critical |
| 5 | Providers of higher-risk AI systems | Undergo third-party conformity assessments for higher-risk AI systems. “possibly undergo third-party conformity assessments before market entry.” | Before market entry | Key Focus Areas (Conformity and registration) | Critical |
| 6 | AI system providers and operators | Conduct pre-deployment testing, robustness checks, and post-deployment monitoring. “pre-deployment testing, validation datasets, robustness checks, accuracy reporting and post-deployment monitoring.” | Before placing on market | Key Focus Areas (Safety, testing and evaluation) | Critical |
| 7 | AI system providers and operators | Report security breaches, safety incidents, and systemic failures. “obligations for incident reporting (security breaches, safety incidents and systemic failures).” | — | Monitoring and Evaluation | Important |
| 8 | AI system providers and operators | Provide user-facing notices describing AI use, capabilities, and limits. “user-facing notices describing AI use, system capabilities, limits and contact points.” | Before placing on market | Key Focus Areas (Transparency and disclosure) | Important |
| 9 | AI system providers and operators | Label synthetic content to indicate its provenance. “provenance and labeling of synthetic content.” | Before placing on market | Key Focus Areas (Transparency and disclosure) | Important |
| 10 | AI system providers and operators | Implement baseline security controls for AI models and supply chain integrity. “baseline security controls for models, supply chain integrity, vulnerability management.” | — | Key Focus Areas (Cybersecurity and model security) | Important |
| 11 | AI system providers and operators | Maintain technical documentation, data governance records, and logs for audits. “maintenance of technical documentation, data governance records and logs sufficient to enable audits and investigations.” | — | Key Focus Areas (Accountability and documentation) | Important |
| 12 | AI system providers and operators | Provide accessible grievance mechanisms for affected persons. “accessible grievance mechanisms for affected persons.” | — | Key Focus Areas (Liability and redress) | Important |
| 13 | AI system providers and operators | Conduct periodic risk reviews, such as annually or upon material change. “periodic risk reviews (e.g., annual or on-material-change).” | Annually or upon material change | Monitoring and Evaluation | Important |
| 14 | Regulated entities | Publish public transparency reports. “public transparency reports from regulated entities are also recommended.” | — | Monitoring and Evaluation | Recommended |
Related Regulations
Nigeria - National AI Policy
Nigeria95% similar
Nigeria - AI Technology Control (HB 942)
Nigeria95% similar
Nigeria - National AI Strategy
Nigeria95% similar
Nigeria - AI Guidelines for Legal Profession
Nigeria93% similar
Nigeria - AI and Robotics Regulation Bill (RAI-NG-NA-ENIAIXX-2024)
Nigeria92% similar
Nigeria - Lagos - AI Guidelines (LSAGXXX-2025)
Nigeria92% similar
Nigeria - AI and Robotics Institute (HB 601)
Nigeria90% similar
Kenya - AI Code of Practice (DKS 3007:2024)
Kenya90% similar
More AI regulation in Nigeria
© Regulations.AI · updated on 13 Jun 2026 · reviewed against official sources on 9 Sep 2026 using Gemini 3.6 Flash