By Iroyin Yoruba Television
Nigeria's National Information Technology Development Agency has warned organisations and their employees against entering personal, classified, official-use or confidential information into publicly available artificial-intelligence platforms, saying careless use of generative AI could create serious data-protection and cybersecurity risks.
The warning was issued as artificial intelligence becomes increasingly common in Nigerian workplaces, with employees using tools capable of drafting documents, summarising information, conducting research, generating computer code, analysing material and assisting with a wide range of professional tasks.
The National Information Technology Development Agency, NITDA, said the convenience provided by public AI systems should not lead organisations to abandon established rules governing confidential information.
The agency's Computer Emergency Readiness and Response Team issued the advisory as part of its continuing cybersecurity awareness efforts.
NITDA specifically warned against placing sensitive information into public large language model platforms without appropriate authorisation and safeguards.
The warning applies to a wide range of information that organisations may handle during normal operations.
This includes personally identifiable information, confidential business documents, classified government material, internal reports, financial information, customer records and other information that organisations have a legal or contractual obligation to protect.
The agency's concern is that once sensitive information is transferred into an external AI service, the organisation may have less control over how the information is processed, stored or retained.
Employees who use public AI tools may not always understand what happens to information after it has been uploaded.
A worker may copy an internal report into an AI chatbot to obtain a summary, for example, without considering whether the document contains confidential information.
Another employee may paste customer information into an AI system while attempting to draft a response or analyse a complaint.
A programmer could also upload portions of proprietary source code while asking an AI assistant to identify a software problem.
Each of these actions can create a potential information-security risk if the organisation has not approved the use of that platform for such material.
NITDA therefore advised organisations to establish clear policies governing the use of artificial intelligence by employees.
The agency said staff should use only AI tools approved by their organisations when handling official work.
Where AI platforms are permitted, employees should understand what information can safely be entered and what information must remain within protected organisational systems.
The warning comes at a time when generative AI is becoming increasingly integrated into professional activities.
Businesses, government agencies, educational institutions and individuals are using AI to improve productivity.
The technology can reduce the amount of time required to perform routine tasks and can assist workers with activities that previously required considerable manual effort.
But the rapid adoption of AI has also created new challenges for cybersecurity and data protection.
One of the most important challenges is the gap between technological capability and user awareness.
An employee may understand how to use an AI system without understanding the security consequences of uploading confidential information.
The ease with which information can be copied and pasted into an AI platform makes the problem particularly difficult.
Traditional information-security controls are often designed around established corporate systems.
Employees may be required to use secure email, protected file-sharing platforms and company-approved software.
Public AI tools can introduce a new pathway through which information leaves the organisation.
A worker may not regard an AI chatbot as an external data processor in the same way they would regard an outside contractor or cloud service provider.
Yet from a data-security perspective, sending information to an external platform can have significant implications.
NITDA warned that information submitted to public AI platforms could potentially be retained, logged or processed by service providers in accordance with their applicable systems and policies.
The agency therefore encouraged organisations to understand the privacy and data-handling terms of AI platforms before permitting their use for official purposes.
That means organisations should not rely solely on employees to make individual decisions about sensitive information.
Management and technology departments need to establish clear rules.
Those rules should identify which AI systems are approved, what categories of information employees may submit, what information is prohibited and what procedures should be followed when AI is used for official work.
Training is equally important.
Employees need practical examples of what constitutes sensitive information and how seemingly harmless information can become problematic when combined with other data.
For example, a document that contains names, telephone numbers, addresses and identification information may appear ordinary when viewed separately.
When combined, however, those details can create a significant privacy risk.
Financial institutions, hospitals, government agencies and large corporations may face particularly serious consequences if sensitive information is exposed.
They may hold large volumes of customer and employee data that are protected by law.
A data breach can result in financial losses, regulatory investigations, reputational damage and loss of public confidence.
For government institutions, the consequences can be even more serious when classified or security-related information is involved.
NITDA warned that the unauthorised disclosure of classified or official-use information to external AI providers could create national-security concerns.
The agency also highlighted the possibility of disciplinary or legal consequences for employees who improperly disclose protected information.
The warning does not mean organisations should stop using artificial intelligence.
Instead, NITDA is encouraging a more controlled approach to AI adoption.
The agency recommended that organisations use approved AI systems for official work and apply appropriate safeguards before employees submit information.
Where personally identifiable information is involved, NITDA recommended removing, anonymising or pseudonymising sensitive details before information is submitted to an AI system where such use is authorised.
Anonymisation can reduce the possibility of identifying individuals from the information being processed.
Pseudonymisation can also provide an additional layer of protection by replacing identifying information with artificial identifiers.
However, those techniques must be implemented properly.
Simply deleting a person's name may not always be sufficient if other information in the document can still identify the individual.
Organisations therefore need data-protection specialists and information-security teams to determine how sensitive information should be handled.
The issue is becoming increasingly important because AI systems are being integrated into everyday business processes.
Customer-service teams may use AI to draft responses.
Marketing departments may use AI to create campaigns.
Human-resources departments may use AI to organise applications and prepare documents.
Legal departments may use AI to review large volumes of text.
Financial teams may use AI to analyse information.
Technology departments may use AI to generate or review computer code.
Each of these applications can potentially involve sensitive information.
The challenge is therefore not limited to one department.
It affects the entire organisation.
NITDA's warning also highlights the importance of understanding the difference between public and enterprise AI systems.
Public AI services may be designed for broad consumer and business use, while enterprise systems can provide additional administrative, security and data-governance controls.
Organisations must nevertheless assess the specific terms and technical configuration of any system before allowing sensitive information to be processed.
A paid or enterprise product should not automatically be assumed to be safe for every type of information.
Security depends on how the system is configured, what contractual protections exist, where data is processed and how access is controlled.
Organisations should therefore conduct proper risk assessments before introducing AI into sensitive workflows.
They should also establish procedures for reporting incidents.
If an employee accidentally submits confidential information to an unauthorised AI service, the incident should be treated seriously.
The organisation needs to determine what information was disclosed, when the disclosure occurred, who could potentially access it and whether regulatory notification is required.
Rapid response can reduce the consequences of a data incident.
Employees should therefore know exactly who to contact when an AI-related data mistake occurs.
The growing use of AI also creates a new responsibility for technology managers.
They must balance innovation with security.
Completely prohibiting AI may prevent organisations from benefiting from productivity improvements.
Allowing unrestricted AI use, however, can expose organisations to unacceptable risks.
The better approach is controlled adoption.
Organisations can identify approved use cases, establish technical safeguards and train employees while continuing to benefit from artificial intelligence.
This approach is particularly important in Nigeria, where AI adoption is expanding rapidly across both public and private sectors.
The federal government has been promoting digital transformation and artificial intelligence as part of efforts to strengthen the country's technology economy.
NITDA itself has been involved in several AI initiatives, including efforts to develop Nigerian AI capabilities and encourage local innovation.
The agency's warning therefore reflects an attempt to ensure that AI adoption develops alongside stronger cybersecurity practices.
Nigeria's digital economy increasingly depends on the ability to maintain public trust.
People are more likely to use digital services when they believe their information is secure.
If repeated data breaches or careless AI practices expose customer information, confidence in digital platforms could decline.
That could slow adoption of useful technologies.
The problem extends beyond large corporations.
Small businesses are also increasingly using AI tools.
A small company may use a public chatbot to draft invoices, analyse customer complaints, prepare contracts or write marketing material.
Without formal cybersecurity departments, smaller businesses may be less likely to understand the risks involved in uploading sensitive information.
NITDA's warning is therefore relevant to organisations of all sizes.
Small businesses should establish basic rules even if they do not have large technology teams.
Employees should understand that customer records, passwords, financial documents, identification information and confidential business information should not be entered into public AI tools without proper approval.
The same principle applies to individuals.
People should be cautious about entering sensitive personal information into AI systems simply because the platform appears convenient.
Personal identification numbers, bank information, passwords, medical documents and private correspondence should be treated carefully.
AI systems can be useful without requiring users to provide unnecessary personal information.
Users can often describe a problem in general terms instead of uploading the complete sensitive document.
For example, someone seeking help with a business letter may remove names, account numbers and other identifying information before asking an AI system to improve the wording.
That simple step can reduce exposure.
NITDA's advisory also highlights the need for greater public understanding of AI privacy.
Many users understand AI primarily through its ability to produce text, images, code and other material.
The data-processing implications are less visible.
Users may focus on the answer produced by an AI system without considering what information they supplied to obtain that answer.
As AI becomes more deeply integrated into society, that understanding will become increasingly important.
Cybersecurity education must therefore evolve alongside technology.
Training programmes should teach not only traditional issues such as passwords, phishing and malware but also the safe use of generative AI.
Employees should learn how to recognise situations in which AI can be used safely and situations in which human judgement and secure systems are required.
The warning also comes as criminals themselves increasingly exploit artificial intelligence.
Cybercriminals can use AI to improve phishing messages, impersonate individuals, generate convincing fraudulent communications and automate certain attacks.
Organisations therefore face a situation in which AI can simultaneously improve productivity and increase the sophistication of threats.
That makes responsible adoption essential.
NITDA's message is ultimately about maintaining control over information.
Artificial intelligence can be a powerful tool, but organisations must determine what information it is allowed to access and how that information is handled.
The convenience of obtaining an instant summary or generating a document should not override established data-protection responsibilities.
As Nigerian businesses and government institutions expand their use of AI, the quality of their internal governance will become increasingly important.
Clear policies, employee training, approved technology platforms, technical safeguards and incident-response procedures will all play a role.
The technology itself cannot solve the problem.
Responsible human decisions remain necessary.
NITDA's latest warning therefore serves as a reminder that the rapid expansion of artificial intelligence must be accompanied by equally rapid improvements in cybersecurity awareness.
For Nigerian organisations, the objective should not be to avoid AI but to use it safely.
That means understanding what information can be shared, what information must remain protected and what controls should be applied before AI becomes part of an official workflow.
The agency's advice is particularly timely as more Nigerian workers experiment with AI tools for everyday tasks.
A single careless upload may appear insignificant to an individual employee, but when sensitive information is involved, the consequences can extend to customers, businesses, government institutions and national security.
Responsible AI adoption will therefore require a culture in which employees think about data protection before they think about convenience.
Nigeria's digital future will increasingly depend on artificial intelligence, but trust will remain one of the foundations of that future.
Protecting sensitive information must therefore remain a central part of the country's technology transformation.