As the Corporate Affairs Commission moves to integrate artificial intelligence into business registration and compliance, Nigeria’s data protection regulator is warning that automation cannot outrun privacy, human oversight and accountability.
From online registration to an AI agent
For years, the promise of digitising Nigeria’s corporate registry has been relatively straightforward: fewer queues, less paperwork and faster business registration.
Artificial intelligence is now changing that ambition.
The Corporate Affairs Commission (CAC) is preparing to move beyond a digital registry toward what it describes as an “intelligent corporate registry”, with AI expected to play a role in business registration, compliance guidance, error detection and other processes.
The initiative was a central focus of the CAC’s 2026 Annual Retreat in Bauchi, held under the theme “Artificial Intelligence at Scale: Advancing an Intelligent Corporate Registry for Efficient and Trusted Service Delivery.”
But at the same event, Nigeria’s data protection regulator delivered a warning that could become more important than the technology itself.
Representatives of the Nigeria Data Protection Commission (NDPC), Abubakar Bello Adamu and Abubakar Mahmud, told participants that existing data protection obligations under the Nigeria Data Protection Act 2023 must extend into AI systems and their training processes.
For high-risk automated decision-making, they emphasised the importance of Data Protection Impact Assessments (DPIAs), human oversight, algorithmic auditability and transparent model controls.
That intervention exposes the central issue surrounding Nigeria’s AI-powered public sector ambitions:
Building the system may be the easy part. Governing the system may be much harder.
The data problem hiding underneath the AI
A corporate registry is not an ordinary database.
The CAC’s mandate includes registering businesses and organisations, maintaining a public registry and overseeing corporate compliance and record-keeping.
Its ecosystem can therefore contain information connected to companies, directors, shareholders, persons with significant control and other individuals associated with corporate entities.
The CAC’s Beneficial Ownership Register illustrates the sensitivity of this ecosystem.
The public register contains information concerning Persons with Significant Control (PSCs) and is designed to increase transparency around who ultimately owns or controls corporate entities. The system is also built around machine-readable data exchange.
Now consider what happens when AI is introduced into an environment containing this scale and variety of information.
The AI system does not merely need access to data. It needs to interpret data.
An algorithm could potentially be used to identify suspicious patterns, flag inconsistent information, recommend a registration category, assess whether an application requires additional review or prioritise cases for human officers.
Each of those uses introduces a different form of risk.
A mistake in a search engine is inconvenient.
A mistake in a government registry can affect whether someone registers a business, how quickly they receive a service or how they are treated by a public institution.
Nigeria’s data protection law already anticipates some of this
The NDPC’s warning is not a new principle created specifically for CAC’s AI project.
Nigeria’s Data Protection Act already establishes significant rights for data subjects, including the right not to be subjected to certain forms of automated decision-making.
The Act also provides a framework for Data Protection Impact Assessments where processing is likely to create high risks to people’s rights and freedoms.
The NDPC’s guidance identifies situations including profiling, automated decision-making with legal or similarly significant effects, systematic monitoring, processing sensitive personal data and deployment of innovative technologies that may create significant privacy risks.
This creates an important distinction that deserves greater public attention.
AI does not sit outside Nigeria’s existing data protection framework simply because it is AI.
If a government agency takes an existing administrative process and inserts a machine-learning model into it, the underlying privacy responsibilities do not disappear.
If anything, the complexity increases.
The “human in the loop” question
The NDPC’s emphasis on human-in-the-loop oversight may sound like a technical detail.
It is not.
It goes to the heart of accountability.
Suppose an AI system flags a business application as potentially fraudulent.
Who makes the final decision?
If a human officer simply accepts whatever the algorithm recommends, is that genuinely human oversight?
Or is the human merely rubber-stamping the machine?
This is one of the most important governance questions Nigeria will have to answer as AI moves deeper into government.
Human oversight only works when the human decision-maker has enough information, authority and time to challenge the system.
Otherwise, “human in the loop” can become a procedural label rather than a meaningful safeguard.
The NDPC’s call for algorithmic auditability and transparent model controls therefore matters.
Government needs to know not only what an AI system decided, but also enough about the system’s operation to investigate why it reached that outcome.
What happens when AI makes the wrong call?
This is where the conversation about AI in government needs to move beyond efficiency.
The usual argument for automation is speed.
And speed matters.
Nigeria has millions of entrepreneurs and informal businesses that need formalisation, access to financial services and government programmes.
Automated checks could reduce errors and compliance guidance could make formalisation easier.
But public-sector AI should not be evaluated only by how quickly it completes transactions.
It should also be evaluated by what happens when it fails.
An AI system could misunderstand a Nigerian business description.
It could misinterpret a person’s name.
It could incorrectly associate information with the wrong individual.
It could flag legitimate activity as suspicious.
It could produce different results depending on language.
Those risks become particularly interesting when the CAC introduces Nigerian languages into the system.
The promise and problem of multilingual AI
The decision to support Hausa, Yoruba, Igbo and Nigerian Pidgin is potentially one of the most important aspects of the CAC’s proposed system.
For many Nigerians, language remains a barrier to interacting with government technology.
A voice-enabled system that allows entrepreneurs to explain their businesses naturally could make formalisation significantly more accessible.
But multilingual AI introduces another governance challenge:
Does the system understand all five languages equally well?
AI systems do not automatically become culturally or linguistically accurate simply because developers add a language option.
Nigeria’s languages contain different structures, expressions, contexts and varieties. Nigerian Pidgin, for example, can change considerably according to region and context.
If the AI misunderstands a business description in one language more frequently than another, then an apparently inclusive system could produce unequal outcomes.
The question should therefore not simply be: “Does the AI speak Hausa, Yoruba, Igbo and Pidgin?”
It should be: “Does the AI perform reliably and fairly across those languages?”
That distinction is crucial.
The NIN connection raises the stakes
The proposed CAC architecture also reportedly involves identity verification through the National Identification Number, with verification through the National Identity Management Commission’s systems.
This creates another layer in the data ecosystem.
A future registration process could involve a chain connecting:
Applicant → AI interface → CAC → identity verification → corporate registry → compliance systems.
The more systems that become interconnected, the more important questions of data minimisation, access control, retention, interoperability and breach response become.
This is why the NDPC’s intervention at the CAC retreat should not be treated as a routine regulatory presentation.
It is effectively a warning about the architecture of Nigeria’s emerging digital state.
Nigeria is building more than an AI registry
There is a bigger story developing here.
Across government, Nigeria is increasingly experimenting with artificial intelligence as a tool for public administration.
The CAC is one example.
The NDPC itself has been pushing the idea that AI governance must be embedded into the country’s broader digital transformation rather than treated as an afterthought.
Nigeria’s corporate transparency infrastructure is also becoming increasingly data driven.
The Beneficial Ownership Register is already designed to make ownership information searchable and machine readable, while the CAC is pushing for greater interoperability between different beneficial ownership databases.
The convergence of these developments points toward something bigger:
Nigeria is gradually constructing a data infrastructure in which government systems can increasingly exchange, analyse and act on information about citizens and organisations.
AI could make that infrastructure considerably more powerful.
It could also make mistakes considerably more consequential.
The cybersecurity question cannot be separated from AI
There is another issue that deserves attention: security.
An AI-powered corporate registry would become an attractive target because of the value of the information it processes.
The NDPC representatives specifically placed AI governance alongside cybersecurity at the CAC retreat.
That is important because AI introduces new attack surfaces.
A government system could potentially face manipulated inputs, compromised data, unauthorised access to models or supporting infrastructure, or attempts to influence automated decisions.
There is also a more basic problem:
AI is only as trustworthy as the data and infrastructure surrounding it.
If inaccurate information enters the system, automation can reproduce that error at scale.
If a vulnerable system is compromised, automation can potentially accelerate the consequences.
And if an AI model is trained or fine tuned using data that should not have been used for that purpose, the problem becomes both a privacy and governance issue.
The question Nigerians should be asking
The excitement around AI in government often focuses on what the technology can do.
Nigeria’s corporate registry conversation should add another question:
What should the technology be allowed to do?
There is a fundamental difference between using AI to help a citizen complete a form and allowing AI to make consequential decisions about that citizen.
The first is primarily an efficiency question.
The second is a governance question.
Nigeria’s regulators therefore need to establish clear boundaries around automated decisions before these systems become deeply embedded in public administration.
That includes determining:
• Which CAC decisions can be automated?
• Which decisions must always involve a human officer?
• How will applicants challenge an AI-generated decision?
• How will CAC explain an automated decision to a citizen?
• How will algorithmic errors be investigated?
• How frequently will models be independently audited?
• How will performance be tested across Nigerian languages?
• What data can be used to train or improve the system?
• How long will personal information be retained?
• Which technology vendors will have access to the data?
• Where will the data and AI infrastructure be hosted?
• What happens when the AI system is wrong?
These questions should be answered before automation becomes infrastructure.
The opportunity is enormous, but so is the responsibility
There is a compelling case for CAC’s AI ambitions.
A multilingual, voice-enabled corporate registry could make it easier for entrepreneurs across Nigeria to formalise their businesses without needing to understand complicated bureaucratic processes.
Automated checks could reduce errors.
AI could help identify inconsistencies and potential fraud.
Real-time compliance guidance could reduce dependence on intermediaries.
And faster registration could improve Nigeria’s broader business environment.
But Nigeria’s experience with digital transformation should also teach policymakers something:
A government platform is not successful simply because it is digital.
The next generation of public technology must be judged by whether it is trustworthy.
That means privacy by design.
Security by design.
Human oversight by design.
And accountability by design.
Nigeria’s AI governance test
The CAC’s proposed intelligent registry could ultimately become a model for how Nigeria deploys AI across government.
If done well, it could demonstrate that African governments do not have to choose between technological innovation and citizens’ rights.
If done poorly, it could create a different precedent: one where automated systems quietly become decision-makers before the rules governing them have caught up.
The NDPC’s intervention at the CAC retreat therefore deserves to be read as more than a compliance reminder.
It is an early warning about the direction of Nigeria’s digital state.
The country is moving from asking “Can government use AI?” to a much harder question:
“How should government use AI when the decisions affect real people?”
That is the question Nigeria will have to answer before the intelligent corporate registry becomes truly intelligent.
And perhaps more importantly, before it becomes too deeply embedded to change.
