Governance & data protection · Toolkit 03
The Nigeria AI Compliance Register
Six instruments govern AI in Nigeria today. None of them are in the National AI Strategy. This is the working register for finding out which apply to you, and what you can currently evidence.
5 pages · status verified 21 August 2026 · PDF
A look inside
| Instrument | Status | The obligation that bites |
|---|---|---|
| NDPA 2023 s.37 | In force | Human oversight of automated decisions with material effect. Right to contest. |
| NDPC GAID 2025 | In force | Mandatory DPIAs for high-risk AI. 72-hour breach notification. |
| NCC Code | In force | Notify before deploying AI in telecoms. 48-hour breach — stricter than the NDPA. |
Three of the six. The document carries all of them, the scoping filter, the register, and what a regulator would actually accept as evidence for each.
The rule it turns on
You are not assessed against the strategy. You are assessed against the stack — and the stack is live.
What’s in it
- All six in-force instruments, with the obligation in each that actually bites
- A ten-minute filter for which ones apply to your organisation
- The register itself — applies, evidence held, named owner, gap and date
- What a regulator would accept as evidence, obligation by obligation
- Eight open questions that would change the register, to re-check quarterly
- The two gaps we find most often, both visible in a single question
Related reading, ungated: the AI governance non-negotiables and our full analysis of Nigeria’s National AI Strategy.
