The National Information Technology Development Agency (NITDA) has warned organisations and their employees against entering personal, classified or confidential information into public artificial intelligence tools such as ChatGPT, Gemini, Claude and Copilot.
The warning comes as businesses, government institutions and individuals increasingly turn to AI platforms for drafting documents, research, analysis, coding and other work-related tasks. While these tools can significantly improve productivity, NITDA says careless use could expose sensitive information to external service providers and create serious data protection and cybersecurity risks.
Growing Use of AI Creates New Security Risks
Artificial intelligence has rapidly become part of everyday professional activities.
Employees can now use AI assistants to summarise reports, prepare presentations, analyse information, draft correspondence and perform other tasks that previously required considerable time.
However, the convenience also creates a new security challenge.
When workers copy internal documents, customer information or confidential communications into a public AI platform, they may lose control over where that information goes and how it is handled.
Consequently, NITDA is urging organisations to establish clear rules around the use of AI rather than allowing employees to decide individually what information they can submit.
Sensitive Information Could Leave Organisational Control
According to NITDA, information entered into public AI platforms may potentially be retained, logged or used by service providers for various purposes, including model development or training, depending on the platform and its applicable terms.
That means an employee who simply wants an AI tool to improve a document could unintentionally expose information belonging to a company, government institution, customer or another individual.
The agency specifically highlighted Personally Identifiable Information, classified government information and confidential organisational data as areas of concern.
Moreover, the risk becomes greater when employees upload entire internal documents rather than providing general or anonymised information.
Personal Data Could Trigger Legal Consequences
NITDA also warned that exposing personal information through public AI platforms could constitute a personal data breach where applicable requirements are violated.
This creates a responsibility for organisations to understand what information their employees handle and how that information moves through digital systems.
Businesses routinely manage names, addresses, identification details, financial records, customer communications, employee information and other sensitive data.
Therefore, allowing staff to upload such information into unapproved AI platforms without proper controls could create unnecessary exposure.
Beyond the immediate security concern, organisations could also face regulatory, disciplinary or legal consequences where sensitive information is improperly disclosed.
Classified Information Requires Greater Protection
The warning becomes even more significant for government institutions and organisations handling classified or official-use information.
NITDA cautioned that disclosure of classified, official-use or confidential information to external AI providers could compromise national security and public trust.
For government agencies, therefore, the issue extends beyond ordinary data protection.
Sensitive information can include policy documents, internal communications, security information, strategic plans and other materials that should remain within authorised systems.
Consequently, employees should not assume that an AI tool is safe simply because it is widely used or operated by a well-known technology company.
NITDA Recommends Approved AI Tools
To reduce the risks, NITDA advised organisations to use only AI tools that have been approved for official work.
This means employers should establish policies specifying which AI platforms employees can use and what categories of information they can submit.
In addition, organisations should train staff to recognise sensitive information before using AI systems.
Such training can help employees understand that seemingly harmless details may become sensitive when combined with other information.
Remove Sensitive Information Before Using AI
NITDA also recommended removing, anonymising or pseudonymising personally identifiable information and other sensitive data before entering information into AI platforms.
For example, instead of submitting a document containing real customer names, identification numbers and contact details, an employee could replace those details with fictional or generic placeholders before requesting assistance from an AI system.
This approach can preserve some of the usefulness of AI while reducing unnecessary exposure.
However, anonymisation should not become an excuse for careless handling of data. Organisations still need to determine whether the remaining information could identify individuals or reveal confidential business information.
Employees Should Review AI Privacy Terms
NITDA further urged users to review the privacy and data-handling terms of AI platforms before using them.
This is particularly important because different AI services can have different approaches to data retention, account settings, enterprise controls and model improvement.
Therefore, employees should not treat all AI platforms as though they operate under identical privacy conditions.
Organisations should also consider whether a platform meets their internal security requirements before authorising employees to use it for professional tasks.
Internal Documents Should Not Be Uploaded Without Permission
Another major recommendation from NITDA is that employees should not upload internal documents unless they have specific authorisation.
This is especially relevant because AI tools make it easy to upload files and request instant summaries, analysis or rewriting.
An employee may consider such an action routine, but the document could contain information that the organisation has a legal or contractual obligation to protect.
Consequently, organisations need clear approval procedures that tell employees when AI-assisted document processing is permitted and when it is prohibited.
AI Productivity Must Come With Responsibility
The warning does not mean organisations should abandon artificial intelligence.
Instead, it highlights the need to balance productivity with responsible data management.
AI can help businesses and public institutions improve efficiency, automate repetitive tasks and support decision-making. However, those benefits can quickly become liabilities when organisations fail to control what information enters external systems.
NITDA therefore urged organisations and their employees to comply with existing AI, information security and data protection policies when using AI tools.
A New Digital Discipline for Nigerian Organisations
As AI adoption continues to expand, data protection will increasingly become an everyday responsibility rather than an issue reserved for cybersecurity specialists.
Every employee who uses an AI assistant effectively becomes part of an organisation’s information-security chain.
A single careless upload can potentially expose information that took years to collect or protect.
Therefore, organisations need clear policies, staff training, approved platforms and effective monitoring to ensure that AI adoption does not undermine their security.
Ultimately, NITDA’s warning sends a straightforward message: AI can be a powerful workplace tool, but confidential information should never be treated as disposable input.
As Nigerian organisations embrace artificial intelligence, responsible data handling will be essential to ensuring that technological progress strengthens productivity without compromising privacy, security or public trust.
