Nigeria - National AI Policy

National Artificial Intelligence Policy (NAIP)

Nigeria

RAI-NG-NA-NAINXXX-2023
Draft(Being written or scoped)
PolicyGovernance and OversightRisk ManagementData Protection and Privacy
Export PDF

The National Artificial Intelligence Policy (NAIP) is a draft national-level policy developed to guide the responsible development, deployment and governance of AI across Nigeria. Prepared under the direction of the Federal Ministry of Communications, Innovation and Digital Economy and led by the National Information Technology Development Agency (NITDA), the NAIP aims to maximise socio-economic benefits while managing risks to rights, security and public trust.

Overview

The draft National Artificial Intelligence Policy (NAIP) is a government-led, cross-sectoral policy framework intended to guide Nigeria’s adoption and governance of AI. Commissioned by the Federal Ministry of Communications, Innovation and Digital Economy and coordinated by the National Information Technology Development Agency (NITDA) with technical support from the National Centre for Artificial Intelligence and Robotics (NCAIR), the NAIP sets out principles, institutional roles and high-level obligations to promote innovation while protecting rights and safety. The NAIP complements Nigeria’s data protection architecture (see Nigeria Data Protection Commission — NDP Act 2023) and links to the Federal Ministry’s broader strategy (see National AI Strategy initiative).

Definitions

The policy defines key terms to create a shared operational vocabulary: "Artificial Intelligence" (systems that interpret data, identify patterns and take actions with varying degrees of autonomy); "AI system" (the technically assembled model, data pipelines and runtime environment); "developer" (entity that designs or trains a model); "deployer/operator" (entity that operates or places an AI system into production); "high-risk system" (systems that materially affect rights or safety, e.g., healthcare diagnostics, credit scoring, criminal justice); "data controller/processor" (as defined in the NDP Act 2023); and "conformity assessment" (third-party or regulatory checks of compliance with technical and ethical standards). Clear, operational definitions are central to risk classification and enforcement measures.

Governance and Institutional Framework

The NAIP proposes a multi-layer institutional model. NITDA is the lead coordinating agency for technical standards, policy development and stakeholder engagement. The Federal Ministry (FMCIDE) provides strategic direction and inter-ministerial coordination. NCAIR leads research, capacity-building and public sector pilot projects. The Nigeria Data Protection Commission (NDPC) enforces data protection obligations and advises on privacy impact tests. The draft also proposes creation of a national AI advisory council composed of government, industry, civil society and academic representatives to supervise risk classification, standards adoption and public consultation. Implementation relies on public-private partnerships and regional coordination with sub-national authorities. For background on the Ministry’s initiative see FMCIDE: National AI Strategy initiative and the National Centre for AI & Robotics pages (NCAIR).

Key Focus Areas

NAIP’s substantive priorities cluster into several focus areas: (1) Rights and Ethics — policies and operational controls to prevent discrimination, protect privacy and maintain human oversight; (2) Risk Management — a risk-based classification that scales obligations to system impact and reach; (3) Safety, Testing and Evaluation — mandatory pre-deployment testing, robustness checks, adversarial resilience and post-deployment monitoring; (4) Transparency and Documentation — model cards, data provenance, audit logs and explainability for high-impact systems; (5) Data Protection and Privacy — alignment with the Nigeria Data Protection Act 2023 and requirements for lawful basis, consent management and secure data handling; (6) Security — model and infrastructure security, secure development lifecycle, and incident reporting; (7) Market Surveillance and Conformity — registration, certification and market oversight for critical systems; (8) Accountability & Liability — clear allocation of responsibilities between developers, deployers and public bodies, plus accessible redress mechanisms; and (9) Capacity & Economic Policy — talent development, public procurement, research funding and incentives for local AI industry growth. Each focus area contains operational actions that agencies can convert into standards, guidelines and sectoral instruments.

Implementation Framework

The draft prescribes a phased implementation built around policy instruments and enabling measures. Phase 1: policy adoption, stakeholder consultations and establishment of governance bodies. Phase 2: development of technical standards, conformity assessment procedures and sectoral guidance in health, finance, public procurement and security domains. Phase 3: roll-out of registration and market surveillance for high-risk systems, public procurement mandates and national capacity building programs including research grants and talent initiatives. The policy recommends establishing a National AI Fund or leveraging existing innovation funds to finance pilot projects and R&D. Implementation also relies on cooperation with international standard bodies and bilateral partners to leverage best practice standards and interoperability frameworks.

Monitoring and Evaluation

The NAIP includes monitoring and evaluation (M&E) design features: periodic reporting by agencies, key performance indicators (KPIs) for adoption and safety, public dashboards for transparency, external independent evaluations and scheduled policy reviews. The monitoring framework emphasises incident reporting, audits of deployed systems, and measurable targets for capacity (e.g., number of trained AI researchers, startup grants distributed). Where feasible, the policy recommends publishing anonymised performance metrics to enable civil society oversight and independent research.

Penalties, Liability, and Appeals

Although primarily policy-level, the NAIP recommends administrative and civil enforcement mechanisms to ensure compliance: administrative fines, remedial orders (fix or withdraw systems), suspension of deployment, and public notices of non-compliance. It also recommends clarifying civil liability regimes so affected persons have access to compensation and sets out procedural paths for appeal. The draft calls for coordination with existing legal instruments (e.g., the Nigeria Data Protection Act 2023, cybercrime and consumer protection laws) and suggests legislative steps where administrative powers are insufficient.

Relationship to Other Instruments

NAIP is designed to complement — not replace — sectoral regulation. It explicitly references the Nigeria Data Protection Act 2023 (NDP-Act), the Cybercrimes Act, consumer protection and financial sector rules (e.g., Central Bank and SEC guidance for automated advisory services). The policy calls for harmonised guidance across ministries and regulators to prevent regulatory gaps and overlaps, and to ensure that AI-specific measures are consistent with existing obligations on data protection, intellectual property and sector-specific safety rules.

International Alignment

The draft places importance on international cooperation. It proposes aligning Nigeria’s technical and governance standards with global instruments such as OECD AI principles, ISO/IEC AI standards, and engagement in multilateral fora to ensure cross-border interoperability and safe data flows. It highlights the role of international partnerships in capacity building, joint research and standards adoption while preserving national policy space to address local contexts and risks.

Implementation Timeline

PhasePeriodKey actions
Phase 02022–2023Stakeholder consultations, draft completion (NITDA draft March 2023).
Phase 12023–2024Establish governance bodies, publish strategy white paper (FMCIDE August 2023), begin standards drafting.
Phase 22024–2025Publish National AI Strategy (NAIS draft Aug 2024), pilot conformity assessment and registration for priority sectors.
Phase 32025–2027Scale market surveillance, integrate AI procurement rules, implement capacity programs and legislative proposals where required.

Compliance Checklist

RequirementWhoAction
Data protection complianceAll deployersAlign with NDP Act 2023: lawful basis, DPO, records of processing.
AI Impact AssessmentHigh-risk system developers/deployersConduct and publish assessments before deployment.
Documentation & loggingDevelopers/OperatorsMaintain model cards, provenance and audit logs for 3+ years.
Security measuresDevelopers/OperatorsImplement secure SDLC, penetration tests and incident reporting.

Sources and References

SourceType
National Information Technology Development Agency (NITDA)Primary Source
Federal Ministry of Communications, Innovation & Digital Economy (NAIS initiative)Primary Source
National AI Strategy draft (NC-AIR / NITDA, 2024 PDF)Primary Source
Nigeria Data Protection Commission – NDP Act 2023Primary Source
Plain English

The National Artificial Intelligence Policy (NAIP) is a draft framework from Nigeria designed to guide the responsible development, deployment, and governance of AI systems across all sectors, impacting anyone who creates or uses AI in the country.

This policy applies broadly to entities that design or train AI models (developers) and those that operate or put AI systems into production (deployers/operators). It aims to establish a comprehensive regulatory environment for AI across Nigeria.

At its core, the NAIP introduces a risk-based approach, meaning obligations will scale depending on an AI system's potential impact on rights or safety. "High-risk systems"—such as those in healthcare diagnostics, credit scoring, or criminal justice—will face stricter requirements. Key obligations include: - Mandatory pre-deployment testing and ongoing monitoring for safety and robustness. - Requirements for transparency and documentation, including "model cards," data origin records, and audit logs for high-impact systems. - Strict adherence to data protection and privacy principles, aligning with Nigeria’s existing Data Protection Act 2023.

While still a draft, the NAIP outlines a multi-year phased implementation plan, with initial steps like establishing governance bodies and drafting technical standards already underway (2023-2024). Piloting conformity assessments and registration for priority sectors is planned for 2024-2025, with full market surveillance and capacity-building programs scaling up through 2027. This means the framework is actively being built, even if not fully effective yet.

To ensure compliance, the policy recommends various enforcement mechanisms. These include administrative fines, orders to fix or withdraw non-compliant systems, suspension of deployment, and public notices of non-compliance. It also seeks to clarify civil liability, allowing affected individuals to seek compensation.

A crucial practical pitfall is that the policy clearly distinguishes between the responsibilities of "developers" and "deployers." Companies must carefully define these roles and allocate accountability in their contracts and internal processes to avoid unexpected liabilities as specific standards emerge.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under Nigeria - National AI Policy. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalKey Focus Areas: Data Protection and Privacy

    Applies to: All deployers of AI systems.

    alignment with the Nigeria Data Protection Act 2023 and requirements for lawful basis, consent management and secure data handling
  2. #2CriticalKey Focus Areas: Risk ManagementBefore deployment

    Applies to: Developers and deployers of high-risk AI systems.

    AI Impact Assessment... Conduct and publish assessments before deployment.
  3. #3CriticalKey Focus Areas: Security

    Applies to: Developers and operators of AI systems.

    Implement secure SDLC, penetration tests and incident reporting.
  4. #4CriticalKey Focus Areas: Safety, Testing and EvaluationBefore placing on market

    Applies to: Developers and deployers of AI systems.

    mandatory pre-deployment testing, robustness checks, adversarial resilience and post-deployment monitoring
  5. #5CriticalKey Focus Areas: Market Surveillance and ConformityBefore placing on market

    Applies to: Providers of critical AI systems.

    registration, certification and market oversight for critical systems
  6. #6ImportantKey Focus Areas: Rights and Ethics

    Applies to: Developers and deployers of AI systems.

    policies and operational controls to prevent discrimination, protect privacy and maintain human oversight
  7. #7ImportantKey Focus Areas: Transparency and Documentation

    Applies to: Developers and operators of high-impact AI systems.

    Maintain model cards, provenance and audit logs for 3+ years.
  8. #8ImportantKey Focus Areas: Safety, Testing and Evaluation

    Applies to: Deployers/operators of AI systems.

    post-deployment monitoring
  9. #9ImportantKey Focus Areas: Risk Management

    Applies to: Developers and deployers of AI systems.

    a risk-based classification that scales obligations to system impact and reach
  10. #10ImportantKey Focus Areas: Accountability & Liability

    Applies to: Developers and deployers of AI systems.

    clear allocation of responsibilities between developers, deployers and public bodies
  11. #11ImportantMonitoring and Evaluation

    Applies to: Deployers/operators of AI systems.

    incident reporting, audits of deployed systems

© Regulations.AI — created on 13-Jun-2026