Nigeria’s Computer Emergency Readiness and Response Team has warned individuals and organisations against entering sensitive personal, government or corporate information into public AI platforms, urging users to anonymise data and verify AI generated information before relying on it.
As artificial intelligence becomes increasingly embedded in everyday life, Nigeria’s National Information Technology Development Agency (NITDA) is warning citizens and organisations to pay closer attention to what they share with AI platforms.
The warning was issued through NITDA’s Computer Emergency Readiness and Response Team (CERRT.NG) in an advisory on the safe use of AI platforms.
CERRT.NG is responsible for cybersecurity incident response, threat intelligence and security awareness aimed at protecting Nigeria’s digital infrastructure and users.
The advisory comes at a time when generative AI tools such as ChatGPT, Gemini, Claude, Copilot and Meta AI are increasingly being used for research, writing, education, business operations, job applications and personal questions.
While these tools can significantly improve productivity, NITDA says users must understand that information entered into an AI system can create privacy and security risks.
The danger of putting sensitive information into AI
One of the central concerns raised by NITDA is the information users submit when interacting with AI systems.
People may paste documents, upload files or type personal information into an AI chatbot without considering what happens to that information after it has been submitted.
According to the advisory, information entered into an AI platform may potentially be retained, logged or used to train the provider’s AI models, depending on the platform’s policies and settings.
This means users should not automatically assume that information shared with an AI chatbot remains entirely within their personal or organisational control.
For businesses and government institutions, the consequences could be particularly serious.
An employee who uploads an internal document to a public AI service in order to summarise it, rewrite it or extract information could inadvertently expose confidential organisational information to an external service.
The same risk applies to government records, customer information, employee records, financial information and other sensitive materials.
Nigerians warned against sharing personal information
The warning also has implications for ordinary AI users.
People increasingly turn to AI platforms for help with health questions, financial decisions, schoolwork, job applications and other personal matters.
However, users may sometimes provide more information than is necessary to receive an answer.
This could include identification numbers, banking information, photographs, medical records, addresses, telephone numbers, employment information or other personally identifiable information.
NITDA’s warning is that users should think carefully before providing such information to an AI platform.
If sensitive personal information is exposed through a data breach or otherwise mishandled, it could potentially contribute to risks such as identity theft, impersonation, fraud or other forms of abuse.
“Anonymise your prompts”
One of the key recommendations from CERRT.NG is for users to remove, anonymise or pseudonymise personally identifiable information and other sensitive details before using AI platforms.
In practical terms, this means users should avoid providing information that directly identifies a person when that information is not necessary for the AI task.
For example, instead of asking an AI system to analyse a document containing a customer’s full name, telephone number, address and identification number, a user could remove those details first and replace them with generic labels.
Rather than:
“Analyse this complaint from John Doe, whose phone number is…”
A safer approach would be to remove the identifying information and provide only the details required for the task.
The principle is simple: give an AI system the minimum information it needs to perform the task.
Organisations urged to establish AI policies
NITDA’s warning extends beyond individual users.
Organisations are encouraged to develop clear AI governance or AI transformation policies that define how employees can use AI tools.
Such policies should establish:
- Which AI platforms employees are permitted to use.
- What information can and cannot be entered into AI systems.
- Which AI applications are approved for official work.
- How personal and confidential information should be handled.
- Who is responsible for approving AI use cases.
- How AI-generated information should be reviewed and verified.
- What employees should do if sensitive information is accidentally exposed.
This is increasingly important as employees adopt AI tools faster than many organisations can develop internal rules governing their use.
An employee may use an AI chatbot to draft an email, analyse a spreadsheet, summarise a report or generate code without realising that the information being processed could be commercially or legally sensitive.
“Do not upload internal documents without authorisation”
CERRT.NG also advises users against uploading internal organisational documents to AI platforms unless they have specific authorisation to do so.
This is particularly relevant for organisations handling sensitive information.
Documents such as contracts, customer databases, employee records, financial reports, unpublished research, legal documents, strategic plans and government records should not automatically be treated as suitable material for public AI tools.
Before uploading such material, users should determine whether their organisation permits it and whether the AI platform provides appropriate privacy and security controls.
Check the platform’s privacy terms
NITDA also recommends that users review the privacy and data-handling terms of AI platforms before using them.
This is important because different AI providers may have different approaches to how user information is collected, stored, processed and used.
Users should therefore avoid assuming that every AI platform handles information in exactly the same way.
For organisations, reviewing these terms should form part of the process for approving an AI platform for official use.
AI can be wrong even when it sounds confident
The cybersecurity concern is not the only warning contained in the broader guidance on responsible AI use.
AI systems can generate responses that appear convincing while containing inaccurate, incomplete or outdated information.
This creates particular risks when people use AI for high-stakes decisions.
Users should therefore verify AI-generated information before relying on it, particularly in areas such as:
Health: AI-generated information should not automatically be treated as professional medical advice.
Legal matters: Users should verify legal information with appropriate professionals and authoritative sources.
Finance: AI-generated financial information should be independently checked before making important financial decisions.
Education and research: AI-generated facts, references and quotations should be verified against reliable sources.
The broader lesson is that AI should be treated as a tool that assists human decision-making, rather than an unquestionable authority.
What Nigerians should do before using AI
For everyday users, the CERRT.NG warning can be translated into a simple checklist.
1. Think before you prompt
Ask yourself whether the information you are about to enter is something you would be comfortable sharing with an external technology provider.
2. Remove sensitive information
Delete names, identification numbers, financial details, addresses, medical information and other unnecessary personal information.
3. Do not upload confidential documents without permission
If you are using AI for work, check your organisation’s policy before uploading internal documents.
4. Use approved AI tools
Organisations should identify and approve the AI platforms employees are allowed to use for official tasks.
5. Read the privacy policy
Understand how the platform handles information before submitting sensitive material.
6. Verify AI-generated information
Do not assume that an answer is correct simply because it is confidently written.
7. Report mistakes quickly
If sensitive organisational or personal information is accidentally submitted to an AI platform, users should follow their organisation’s incident-reporting and data-protection procedures.
Why the warning matters for Africa’s AI future
NITDA’s advisory highlights a challenge that is becoming increasingly important across Africa.
African countries are actively pursuing AI adoption to improve healthcare, education, financial services, agriculture, government and other sectors.
But greater AI adoption also means more people will be interacting with AI systems and potentially sharing sensitive information with them.
For Africa’s emerging AI ecosystem, responsible adoption therefore cannot focus only on access to AI tools and AI skills.
It must also include data protection, cybersecurity, digital literacy, AI governance and accountability.
As organisations encourage employees to experiment with AI and governments explore AI-powered public services, users need to understand both the benefits and risks associated with the technology.
The goal should not be to discourage the use of AI.
Instead, NITDA’s warning points to the need for a more responsible approach: use AI, but understand what you are sharing; use AI for productivity, but protect sensitive information; and use AI for answers, but verify those answers before acting on them.
The bottom line
Generative AI is rapidly becoming part of everyday digital life in Nigeria.
But the ease with which users can paste information into a chatbot can create a false sense of security.
A confidential document, customer record or personal identification detail can be submitted to an AI system in seconds.
CERRT.NG’s message is therefore straightforward: think before you prompt.
For individuals, that means protecting personal information.
For businesses, it means establishing clear AI-use rules.
For government institutions, it means protecting sensitive and classified information.
And for Nigeria’s wider AI ecosystem, it means ensuring that the country’s embrace of artificial intelligence is matched by equally strong attention to cybersecurity, privacy and responsible innovation.
As AI becomes more powerful, knowing what not to share with it may become just as important as knowing how to use it.
