NITDA Cautions On Sharing NIN, BVN With AI

Nigeria’s technology regulator has told citizens and organisations to stop entering sensitive personal information into artificial intelligence platforms, warning that details such as National Identification Numbers, Bank Verification Numbers, bank information, photographs and medical results could end up stored outside the user’s control.

The caution came in an advisory titled “Advisory on the Safe Use of AI Platforms”, issued at the weekend by the National Information Technology Development Agency through its Computer Emergency Readiness and Response Team. The agency published it on its website and on its X handle, closing with the line, “Think Before You Prompt.”

According to NITDA, Nigerians are turning in growing numbers to chatbots and assistants like ChatGPT, Claude, Gemini, Copilot and Meta AI for schoolwork, business, job applications, health questions and private matters, often without weighing what happens to the data they type in. The agency said information entered into such platforms “may be retained, logged, used to train the provider’s AI models”, and could surface later in a data breach, opening the door to identity theft, impersonation or financial fraud.

The agency’s concern runs beyond privacy. It cautioned that AI tools can return answers that sound confident but are inaccurate or out of date, and that acting on them in health, legal, financial or academic decisions could cause real harm. Its advice is practical: strip out, anonymise or pseudonymise identifying details before prompting, check a platform’s privacy and data handling terms first, and avoid uploading internal documents without authorisation.

For workplaces, NITDA went further, urging organisations to adopt AI governance policies that spell out approved tools, permitted uses, data handling rules and clear lines of accountability. The agency noted that staff who mishandle classified or official information through public AI systems could expose their employers, and themselves, to disciplinary or legal consequences, and in the case of government data, to risks touching national security.

The timing fits a wider pattern of official anxiety about where AI meets data protection. In the same week, NITDA flagged rising sextortion cases involving AI generated explicit images, and in May it alerted the public to DeepLoad, a strain of AI powered malware built to steal credentials saved in web browsers. Its September launch of the 2026 Cybersecurity Awareness Month, themed “Together for a Safer Cyberspace”, carried a similar message against uploading personal, financial or corporate information to unfamiliar platforms.

The warning lands on fertile ground. Nigeria recorded more than 119,000 data breaches in the first three months of 2025, by figures cited in industry analyses of the country’s cybersecurity landscape, and estimates put annual losses to cybercrime at close to 500 million dollars, with cumulative losses between 2019 and 2025 running to about 3 billion dollars. Those numbers frame why a regulator would single out the newest channel through which personal data now flows out of users’ hands.

The legal backdrop matters too. The Nigeria Data Protection Act, signed into law in June 2023, treats the exposure of personally identifiable information as a personal data breach and requires affected organisations to notify the Nigeria Data Protection Commission within 72 hours. Under the Act, controllers of major importance face penalties of up to the greater of 10 million naira or 2 per cent of annual gross revenue, and the Commission has shown willingness to enforce, including a 766.2 million naira fine on MultiChoice Nigeria and action against Meta.

Whether that framework is equipped for AI is itself under review. The NDPC said in June 2026 that it intends to seek amendments to the Act to address artificial intelligence, robotics and big data, with its chief executive, Dr Vincent Olatunji, pointing to concerns around automated profiling, bias, consent and accountability for machine made decisions. The National Assembly began a parallel review of the law in May, with the Senate Committee on ICT and Cybersecurity citing the pace of AI adoption and new international cybercrime obligations.

What the advisory does not do is impose any binding rule. It carries the weight of guidance rather than regulation, and its effectiveness will depend on whether individuals and institutions change habits that are already deeply set. Many users treat AI assistants as private, trusted spaces, and the convenience of pasting a full document or a complete set of personal details is precisely what the agency is asking people to give up.

For now, the practical takeaway for Nigerians is narrow and clear. The agency is not telling anyone to stop using AI, which it acknowledges has become central to work and study. It is drawing a line around what should never go into the prompt box, and asking users to verify what comes out before they rely on it.