Executive Summary
Businesses that deploy Artificial Intelligence (AI) systems, move personal data across borders, or process identity data in Nigeria are operating in a materially different legal environment than they were twelve months ago. Four developments stand out:
▶ Africa's AI governance is hardening: The African Union's Continental AI Strategy has entered its implementation phase (2025–2030), and Nigeria's National Artificial Intelligence Strategy (September 2025) signals a shift from policy aspiration toward enforceable governance. In the absence of AI-specific legislation in Nigeria, the data protection law (the Nigeria Data Protection Act 2023 (NDPA) already serves as the operative legal constraint on AI systems.
▶ Cross-border transfers face heightened scrutiny: The General Application and Implementation Directive (GAID) 2025, effective 19 September 2025, has operationalized the NDPA's transfer regime. Transfers are treated as high-risk processing requiring impact assessments, documented transfer instruments and records of processing, against a backdrop of remedial fees of up to ₦10 million or 2% of annual gross revenue and markedly stricter audit enforcement signalled for 2026.
▶ Localization obligations are expanding: The National Cloud Policy 2025 requires sovereign data classified at Levels 3 and 4 of the National Data Classification Framework to be hosted exclusively in Nigeria. Cloud architecture is now a legal question, not merely a technical one.
▶
Identity data now carries criminal risk: The National Identity Management Commission (NIMC) Act 2026, subjects the National Identity Database to the NDPA, adopts a consent-first access regime for the National Identification Number (NIN), and imposes minimum criminal penalties of five years' imprisonment or ₦10 million for individuals and ₦20 million for corporate bodies, with personal exposure for responsible officers.





