Nigeria's National AI Strategy: What Institutional Leaders Need to Know
Most conversations about AI regulation in Nigeria default to "we're waiting for the rules." That's a comfortable position, and it's also incorrect. The rules that apply to your institution's use of AI today are already in force — they just aren't AI-specific yet, and the strategy that will eventually make them AI-specific is still being built.
What the NAIS actually is
Nigeria's National Artificial Intelligence Strategy (NAIS) was finalised in September 2025, led by the Federal Ministry of Communications, Innovation and Digital Economy (FMCIDE), with the National Information Technology Development Agency (NITDA) and its National Centre for Artificial Intelligence and Robotics (NCAIR) as the main implementing bodies. It sets a five-year vision, running 2025 to 2029, aimed at positioning Nigeria as a global leader in what the strategy calls "ethical and inclusive AI innovation." It is organised around three broad goals — economic growth, social development, and technological advancement — delivered through five operational pillars.
| Pillar | What it covers |
|---|---|
| Infrastructure | Computing capacity, data centres, and the connectivity Nigeria's AI ambitions depend on |
| Ecosystem development | Partnerships, talent development, and innovation hubs supporting Nigerian AI companies and researchers |
| Sector adoption | Accelerating AI use across agriculture, healthcare, education, finance, and public services |
| Responsible AI | Ethics standards, a proposed AI Ethics Expert Group, and a national ethics assessment framework |
| Governance | A proposed independent AI Governance Regulatory Body and a National AI Risk Management Framework |
The strategy sets genuinely ambitious workforce targets — equipping at least 70% of Nigeria's young workforce (ages 16 to 35), including 50% women, with AI-related skills. It also explicitly builds on the Nigeria Data Protection Act 2023 as its data-governance backbone, rather than trying to duplicate it.
The gap institutional leaders need to know about
Here is the part that doesn't make it into most summaries of the strategy. As of independent policy review in early 2026, the strategy's own capstone institution — the independent AI Governance Regulatory Body proposed under the governance pillar — had not yet been constituted, and NITDA's own Code of Practice for AI, expected to give the strategy practical teeth, had not yet been finalised. In the interim, governance functions have been sitting with NITDA itself, which several policy analysts have flagged as a structural conflict of interest, since NITDA is simultaneously a driver of AI adoption and its proposed regulator.
Waiting for Nigeria's AI-specific rulebook to be finished before building internal AI governance is waiting for a document that, as of today, doesn't have a finish date.
What already applies, regardless of the gap above
This is the point that matters practically. Nigeria's institutions are not in a regulatory vacuum while the NAIS's governance architecture is completed. The Nigeria Data Protection Act 2023 already applies in full to any AI system processing personal data — which covers most institutional AI use cases in tax, banking, health, and citizen services. An institution deploying an AI system today has to meet NDPA's requirements now: a lawful basis for processing, data subject rights, data protection impact assessments for higher-risk processing, and appropriate security measures. None of that is contingent on the AI Governance Regulatory Body being seated.
What this means for your institution, practically
- Don't wait for the sector-specific AI code. Build internal governance now against NDPA and the general principles already published in the NAIS draft; align it later when the formal Code of Practice lands, rather than starting from zero at that point.
- Watch which sector you sit in. The strategy singles out finance, health, and other sectors handling sensitive or high-stakes decisions as more likely to face "high-risk" classification once the governance pillar is operational — banks and health institutions have less runway than most.
- Assign clear internal ownership now. The absence of an external regulator is not the absence of accountability — boards and permanent secretaries are still answerable for how AI systems in their institution behave, under existing law.
The NAIS is a genuinely competent strategic document, and its ambition for Nigeria's place in the global AI economy is well-founded. But a strategy document is not the same as an operating governance framework, and the distance between the two is exactly where institutional risk currently sits.
Staurus Training's Governing AI: Risk, Procurement & Data workshop is built specifically to help boards and senior management put internal AI governance in place now, aligned to NDPA today and adaptable as Nigeria's AI-specific framework matures.
See the Programme