The National Information Technology Development Agency (NITDA) has warned organisations and their staff against entering personal, classified or confidential information into public artificial intelligence (AI) tools such as ChatGPT, Gemini, Claude and Copilot.
NITDA issued the warning in an advisory posted on X on Saturday through its Computer Emergency Readiness and Response Team (CERRT.NG).
The agency highlighted the data protection and security risks associated with the use of public Large Language Models (LLMs) for drafting, research and other work-related tasks.
NITDA said information entered into public AI platforms may no longer remain under the control of the organisation that provided it and could be retained, logged or used by the service provider to train AI models.
According to the advisory, staff using public AI tools could inadvertently expose Personally Identifiable Information (PII), classified government information or confidential organisational data.
NITDA said such exposure could constitute a personal data breach where PII is involved, potentially violating applicable data protection laws and resulting in legal consequences.
It also warned that disclosure of classified, official-use or confidential information to external AI providers could compromise national security and public trust, while potentially exposing organisations and staff members to disciplinary or legal consequences.
The agency advised organisations and their staff not to enter confidential, classified, official-use or personal data into public AI platforms.
NITDA recommended using only organisation-approved AI tools for official work and removing, anonymising or pseudonymising PII and other sensitive information before using AI platforms.
The agency also advised users to review the privacy and data-handling terms of AI platforms before use and not to upload internal documents unless specifically authorised.
NITDA urged organisations and their staff to comply with existing AI, information security and data protection policies when using AI tools.
Recent cybersecurity reports and regulatory actions have highlighted the risks organisations face from employee mistakes, cyber threats and weak data protection practices.
A Nairametrics report in August 2026, based on Verizon’s 2026 Data Breach Investigations Report, found that ordinary employee mistakes accounted for 8% of breaches, including cases where workers sent company data to personal accounts for convenience. The report also found that misdelivery, such as sending data to the wrong recipient, accounted for 64% of errors.
NITDA has also issued several warnings about emerging cybersecurity threats facing organisations and individuals.
In May 2026, NITDA warned organisations and individuals about DeepLoad, an AI-powered malware capable of stealing browser-stored credentials and sensitive information. The agency advised organisations to sensitise staff, strengthen system monitoring and review browser extensions for unauthorised installations.
In June 2026, the Nigeria Data Protection Commission (NDPC) announced plans to review the Nigeria Data Protection Act to specifically address emerging technologies including artificial intelligence, big data and robotics.



