The National Information Technology Development Agency (NITDA) has issued a warning to businesses about the growing use of artificial intelligence (AI) tools by employees, which could create new data-security risks. According to NITDA, staff entering sensitive information into public AI platforms could expose confidential information, putting businesses at risk of data breaches. The agency's Computer Emergency Readiness and Response Team (CERRT.NG) has urged organisations to take precautions to prevent such exposure.

NITDA specifically cautioned against employees using public AI tools such as ChatGPT, Gemini, Claude, and Copilot without authorisation. The agency noted that information entered into these public Large Language Models could be retained, logged, or used by providers, taking sensitive data beyond the organisation's control. This could lead to severe consequences, including regulatory action, legal costs, reputational damage, and loss of competitive advantage.

The exposure of personally identifiable information could amount to a data breach, while disclosure of classified information could create national security risks. In light of these risks, NITDA has advised organisations to allow only approved AI tools, anonymise sensitive information before processing, and review the privacy terms of AI platforms. By taking these precautions, businesses can mitigate the risks associated with AI adoption.

The warning comes as businesses increasingly use AI for drafting, research, customer service, and analysis to improve productivity. According to Verizon's 2026 Data Breach Investigations Report, human error accounted for 8 per cent of breaches, while misdelivery accounted for 64 per cent of errors. This highlights the need for businesses to be vigilant about data security.

NITDA has also warned about the risks of AI-powered malware, such as DeepLoad, which is capable of stealing browser credentials. In May, the agency issued a warning about this type of malware, emphasising the need for businesses to be aware of the potential risks associated with AI. The Nigeria Data Protection Commission is currently reviewing the Nigeria Data Protection Act to address emerging technologies, including AI.

The lesson for companies is that AI adoption cannot be separated from data governance. As businesses increasingly use AI to improve productivity, they must also take steps to ensure that their data is secure. This includes implementing robust data governance policies and procedures, as well as educating employees about the risks associated with AI.

The NITDA warning highlights the need for businesses to be proactive about data security in the face of increasing AI adoption. By taking steps to mitigate the risks associated with AI, businesses can ensure that they are using these tools safely and securely. This will help to prevent data breaches and protect sensitive information.

Key points

  • NITDA warns businesses of data-security risks associated with employee use of public AI tools.
  • Agency advises organisations to allow only approved AI tools, anonymise sensitive information, and review AI platform privacy terms.
  • AI adoption must be accompanied by robust data governance policies and procedures to prevent data breaches.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.