The National Information Technology Development Agency (NITDA), the ICT policy implementing arm of the Federal Ministry of Communications, Innovation, and Digital Economy, has issued an advisory which provides practical guidance for individuals and organisations seeking to benefit from artificial intelligence (AI) while reducing exposure to privacy, security, and information risks.
NITDA warned members of the public against sharing sensitive personal and organisational information on AI platforms, citing potential risks to privacy, data security, and the reliability of AI-generated responses.
It issued wide-ranging recommendations, including limiting the personal information entered into AI systems, checking platforms’ privacy terms, securing confidential documents, and establishing clear institutional policies for the responsible use of AI.
The advisory, issued by the Computer Emergency Readiness and Response Team Nigeria (CERRT.NG) under reference number NITDA-0926-003, highlighted the growing use of AI chatbots and assistants for schoolwork, business, job applications, health questions, and personal matters.
It identified platforms such as ChatGPT, Claude, Gemini, Copilot, and Meta AI as examples of tools increasingly used by members of the public, while cautioning that information users enter or upload may be stored outside their control.
According to the advisory, users may unknowingly disclose sensitive details, including identification numbers, bank information, photographs, medical results and information about family members, without fully understanding how such information could be handled by AI service providers.
NITDA warned that information entered into AI platforms may be retained, logged, or used to train the providers’ AI models.
It said personal details shared through these platforms could potentially be exposed in a data breach or exploited for identity theft, impersonation, and financial fraud.
The agency also cautioned that AI tools can generate answers that sound confident but are inaccurate or outdated, warning that acting on such responses in health, legal, financial, or academic matters could cause real harm.
The advisory underscored the need for users to understand the potential consequences of sharing information with AI systems and to exercise caution when using them for sensitive personal or professional activities.
NITDA recommended that organisations should implement an organisation-wide AI governance or AI transformation policy specifying approved tools, permitted uses, data-handling rules, and accountability arrangements for AI use.
The policy, according to the advisory, should provide clear guidance on AI applications employees may use, the purposes for which they may be deployed, and the safeguards required when handling sensitive information.
The agency also advised organisations and individuals to remove, anonymise, or pseudonymise personally identifiable information and other sensitive details before using AI tools.
Users were further urged to verify the privacy and data-handling terms of AI platforms before using them and to avoid uploading internal organisational documents unless specifically authorised.
The advisory called on users to follow their organisations’ AI, information security and data protection policies when working with AI platforms.
The recommendation places responsibility on organisations to establish clear rules governing AI use and on employees to comply with those rules to reduce the risk of unauthorised disclosure of confidential information.
Although AI tools can offer practical benefits, the advisory stressed that users should not assume information shared with an AI platform will remain private or outside the service provider’s data-handling processes.
CERRT.NG also advised members of the public to seek further information through its official channels, including by email at cerrt@nitda.gov.ng and on its website at www.cerrt.ng.



