NITDA Cautions Organisations, Staff Against Putting Sensitive Data Into ChatGPT, Gemini, Claude, Copilot
By Aboki Forex —
The National Information Technology Development Agency (NITDA) has warned organisations and their staff against entering personal, classified or confidential information into public artificial intelligence (AI) tools such as ChatGPT, Gemini, Claude and Copilot.
The warning came in an advisory posted on X on Saturday through the agency's Computer Emergency Readiness and Response Team (CERRT.NG). NITDA flagged data protection and security risks tied to the use of public Large Language Models (LLMs) for drafting, research and other work-related tasks.
Why public AI tools are a risk
NITDA said information entered into public AI platforms may no longer remain under the control of the organisation that provided it. Such data could be retained, logged or used by the service provider to train AI models.
Staff using these tools, the agency said, could inadvertently expose Personally Identifiable Information (PII), classified government information or confidential organisational data.
Where PII is involved, NITDA said the exposure could amount to a personal data breach. That, it warned, could violate applicable data protection laws and carry legal consequences.
The agency also said disclosure of classified, official-use or confidential information to external AI providers could compromise national security and public trust, while exposing organisations and individual staff to disciplinary or legal action.
What NITDA wants organisations to do
NITDA advised organisations and their employees not to enter confidential, classified, official-use or personal data into public AI platforms.
It recommended using only organisation-approved AI tools for official work. Where AI tools must be used, it said PII and other sensitive information should be removed, anonymised or pseudonymised first.
Users should also review the privacy and data-handling terms of any AI platform before use. Internal documents should not be uploaded unless specifically authorised.
The agency urged organisations and their staff to comply with existing AI, information security and data protection policies when using AI tools.
Employee mistakes remain a big breach driver
The advisory fits a pattern of recent warnings. A Nairametrics report in August 2026, based on Verizon's 2026 Data Breach Investigations Report, found that ordinary employee mistakes accounted for 8% of breaches. That includes cases where workers sent company data to personal accounts for convenience. Misdelivery, such as sending data to the wrong recipient, accounted for 64% of errors.
NITDA issued a separate warning in May 2026 about DeepLoad, an AI-powered malware capable of stealing browser-stored credentials and sensitive information. Organisations were told to sensitise staff, strengthen system monitoring and review browser extensions for unauthorised installations.
In June 2026, the Nigeria Data Protection Commission (NDPC) announced plans to review the Nigeria Data Protection Act to specifically address emerging technologies including artificial intelligence, big data and robotics.
For Nigerian businesses, the message is direct. AI tools can speed up drafting and research, but anything typed into a public model may sit outside the company's control. Firms that let staff use them without a written policy now carry the breach risk, the regulatory risk and the reputational cost.