AI Law and Regulation in Nigeria
Introduction
The regulation of artificial intelligence (AI) in Nigeria is an emerging and rapidly evolving field. While Nigeria currently lacks a comprehensive AI-specific statute, the legal landscape is shaped by the National Artificial Intelligence Policy framework, existing data protection legislation, and sectoral regulatory instruments. The Nigerian government has positioned AI as a strategic priority for economic diversification and digital transformation, balancing innovation promotion with the need to address ethical, legal, and societal concerns.
National AI Policy Framework
In 2023, the Federal Ministry of Communications, Innovation and Digital Economy launched the National Artificial Intelligence Policy (NAIP) as a strategic roadmap for AI development and deployment in Nigeria. The policy identifies priority sectors including agriculture, healthcare, education, financial services, and national security. It emphasizes ethical AI principles, data governance, digital infrastructure, and skills development. The National Centre for Artificial Intelligence and Robotics (NCAIR), established under the National Information Technology Development Agency (NITDA), serves as the primary institutional driver of AI policy implementation.
Data Protection as AI Governance
The Nigeria Data Protection Regulation (NDPR) 2019, issued by NITDA, establishes the foundational framework for data protection that directly impacts AI systems processing personal data. The NDPR imposes obligations on data controllers and processors regarding consent, data minimization, purpose limitation, and data security. The Nigeria Data Protection Act 2023 (NDPA) subsequently elevated data protection to statutory status, establishing the Nigeria Data Protection Commission (NDPC) as an independent regulatory authority. AI systems that process personal data must comply with the NDPA’s requirements for lawful processing, data subject rights, and cross-border data transfer restrictions.
Sectoral AI Regulation
Various sectoral regulators exercise authority over AI applications within their domains. The Central Bank of Nigeria (CBN) issues guidelines for digital financial services, including AI-driven credit scoring, fraud detection, and robo-advisory services. The National Communications Commission (NCC) regulates AI applications in telecommunications. The National Health Research Ethics Committee (NHREC) oversees AI applications in healthcare, particularly clinical decision support systems. The Securities and Exchange Commission (SEC) has issued rules on digital asset investments that may intersect with AI trading algorithms.
Intellectual Property and AI
The intersection of AI and intellectual property law raises complex questions under Nigerian law. The Copyright Act 2022 does not expressly address AI-generated works, though the requirement of human authorship remains a threshold issue for copyright protection. The Patents and Designs Act similarly requires human inventorship. The Nigerian Copyright Commission has initiated policy discussions on AI and copyright, focusing on text and data mining exceptions, liability for AI-generated infringing content, and the protection of AI training datasets.
Ethical AI and Human Rights
Nigerian courts and regulators are increasingly attentive to the human rights implications of AI deployment. The National Human Rights Commission (NHRC) has issued guidance on AI and human rights, emphasizing non-discrimination, procedural fairness, and accountability in automated decision-making. Chapter IV of the 1999 Constitution guarantees fundamental rights including privacy, freedom of expression, and freedom from discrimination, all of which are engaged by AI systems. The Evidence Act 2011 governs the admissibility of electronic evidence, including AI-generated evidence, requiring reliability assessments and proper authentication.
Cybersecurity and AI
The Cybercrimes (Prohibition, Prevention) Act 2015 imposes criminal liability for offenses involving computer systems and networks, including AI systems used in furtherance of criminal activity. The Act also establishes duties for service providers and critical infrastructure operators. NITDA’s Cybersecurity Guidelines require AI system deployers to implement appropriate security measures, conduct risk assessments, and report cybersecurity incidents.
Conclusion
Nigeria’s AI legal landscape is characterized by incremental, sectoral regulation rather than comprehensive AI-specific legislation. The National AI Policy framework provides strategic direction, while existing laws on data protection, intellectual property, and cybersecurity create a baseline regulatory environment. As AI technologies proliferate, Nigerian lawmakers face the challenge of developing agile regulatory frameworks that promote innovation while protecting fundamental rights and addressing emerging risks.