Governance & data protection · Toolkit 03

The Nigeria AI Compliance Register

Six instruments govern AI in Nigeria today. None of them are in the National AI Strategy. This is the working register for finding out which apply to you, and what you can currently evidence.

5 pages · status verified 21 August 2026 · PDF

A look inside

InstrumentStatusThe obligation that bites
NDPA 2023 s.37In forceHuman oversight of automated decisions with material effect. Right to contest.
NDPC GAID 2025In forceMandatory DPIAs for high-risk AI. 72-hour breach notification.
NCC CodeIn forceNotify before deploying AI in telecoms. 48-hour breach — stricter than the NDPA.

Three of the six. The document carries all of them, the scoping filter, the register, and what a regulator would actually accept as evidence for each.

The rule it turns on

You are not assessed against the strategy. You are assessed against the stack — and the stack is live.

What’s in it

  • All six in-force instruments, with the obligation in each that actually bites
  • A ten-minute filter for which ones apply to your organisation
  • The register itself — applies, evidence held, named owner, gap and date
  • What a regulator would accept as evidence, obligation by obligation
  • Eight open questions that would change the register, to re-check quarterly
  • The two gaps we find most often, both visible in a single question

Related reading, ungated: the AI governance non-negotiables and our full analysis of Nigeria’s National AI Strategy.