The National Information Technology Development Agency (NITDA) has issued a warning to organizations and individuals in Nigeria against sharing sensitive information with public artificial intelligence (AI) tools. In an advisory posted on X, the agency's Computer Emergency Readiness and Response Team, CERRT.NG, cautioned against entering personal, classified, or confidential information into AI platforms like ChatGPT, Gemini, Claude, and Copilot. This warning comes as a result of potential data protection and cybersecurity risks associated with using public AI tools for work-related tasks.

According to NITDA, using public AI tools for tasks such as drafting documents and research could expose organizations to significant risks. The agency warned that information entered into public AI platforms may no longer remain fully under the control of the organization that provided it. This is because such information could be stored, logged, or used by service providers for various purposes, including training AI models. As a result, workers using public AI tools could accidentally expose sensitive information, including Personally Identifiable Information, classified government information, or confidential organizational data.

NITDA emphasized that exposing personal information could amount to a data breach and may violate data protection laws, potentially leading to legal consequences. Furthermore, sharing classified, official use, or confidential information with external AI providers could threaten national security and public trust. The agency warned that organizations and their employees could face disciplinary or legal consequences if sensitive information is improperly disclosed. This highlights the importance of handling sensitive information with care when using AI tools.

To mitigate these risks, NITDA advised organizations and their employees not to enter confidential, classified, official use, or personal information into public AI platforms. Instead, the agency recommended that organizations use only AI tools approved for official work. Additionally, users were advised to remove, anonymise, or pseudonymise personal and other sensitive information before entering it into AI platforms. NITDA also urged users to carefully review the privacy and data handling policies of AI platforms before using them.

The warning comes amid growing concerns about the risks organizations face from employee mistakes, cyberattacks, and poor data protection practices. A report published by Nairametrics in August, based on Verizon’s 2026 Data Breach Investigations Report, found that ordinary employee mistakes accounted for eight per cent of data breaches. Moreover, sending information to the wrong recipient accounted for 64 per cent of errors. This highlights the need for organizations to prioritize data security and take proactive measures to prevent data breaches.

NITDA has continued to issue warnings about emerging cybersecurity threats. In May, the agency warned organizations and individuals about DeepLoad, an AI-powered malware capable of stealing browser-stored passwords and other sensitive information. This warning underscores the importance of staying vigilant and taking proactive measures to protect against evolving cybersecurity threats. By doing so, organizations and individuals can minimize the risks associated with using AI tools.

In response to growing concerns about data security, the Nigeria Data Protection Commission announced plans to review the Nigeria Data Protection Act to address emerging technologies, including artificial intelligence, big data, and robotics. This move aims to ensure that the country's data protection laws remain relevant and effective in addressing the challenges posed by emerging technologies. Meanwhile, NITDA's warning serves as a reminder for organizations and individuals to exercise caution when using AI tools and to prioritize data security.

Key points

  • NITDA warns Nigerians against sharing sensitive information with public AI tools like ChatGPT and Gemini.
  • Using public AI tools for work-related tasks could expose organizations to data protection and cybersecurity risks.
  • NITDA advises organizations to use only AI tools approved for official work and to handle sensitive information with care.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.