Nigeria has moved quickly to establish one of the most developed AI governance frameworks in Africa. The country built its approach in layers consisting of a national strategy, foundational data protection legislation, and sector-specific rules that regulators such as the Central Bank of Nigeria (CBN), and the National Identity Management Commission (NIMC) are actively enforcing. This multi-layered structure is what has allowed Nigeria to move from governance nonchalance to continental leadership in a remarkably short window of time.

That governance framework generally falls into two broad categories: national strategy and legislation, and institutional oversight. Each plays a different role, the former sets direction and intent, while the later puts that intent into practice.

The National AI Strategy

Nigeria's National Artificial Intelligence Strategy (NAIS) was published in September 2025 by the Federal Ministry of Communications, Innovation and Digital Economy (FMCIDE), with the National Information Technology Development Agency (NITDA) serving as a key implementing body. It sets out a five-year vision, running from the beginning of 2025 to the end of 2029, built around economic growth and competitiveness, social development and inclusion, and technological advancement and leadership.

In scope, NAIS is centered on ethical deployment, local economic empowerment, and digital sovereignty. This is a deliberate signal that Nigeria wants to be a producer and shaper of AI systems, not merely a consumer of AI built elsewhere. The strategy draws on international reference points, including the UNESCO Recommendation on the Ethics of AI and the U.S. AI Risk Management Framework, while tailoring its priorities and limiting its scope to local realities such as a young, digitally active population and a fast-growing tech startup ecosystem.

The Nigeria Data Protection Act

While Nigeria does not yet have a standalone AI law, the Nigeria Data Protection Act (NDPA) of 2023 enforced by the Nigeria Data Protection Commission (NDPC) currently functions as the country's most important binding instrument shaping how AI is built and used. Though not AI-specific, the NDPA's requirements around consent, data handling, and accountability directly shape how organizations design and deploy AI systems, and the NDPC has been increasingly active in enforcement through audits and compliance notices.

Institutional Oversight

Beyond national policy, oversight is also happening at the state and sector level, filling gaps that a single federal strategy cannot cover on its own. Lagos, Nigeria's largest economic and digital hub, has moved to publish the country's first subnational AI guidelines. Framed explicitly as guidance rather than binding policy, they are intended to steer developers and companies toward responsible AI practices.

There are also sector-specific guidelines like those from the CBN which has taken an active role in regulating AI in financial services, including sandbox programs that evaluate the explainability and fairness of AI-powered fintech tools before granting approval. Also the Nigerian Communications Commission (NCC) plays a similar role in telecommunications, covering areas such as automated customer service and network optimization.

This local and sector-led approach means that, in practice, much of Nigeria's AI governance today is happening through the interpretation of existing rules by active regulators and that a complete AI law is still non-existent in the country.

Nigeria's Global Standing

Nigeria's governance efforts have translated into a measurable jump in international standing. According to the 2026 Global Index on Responsible AI (GIRAI), published by the Global Center on AI Governance, Nigeria ranks 38th globally out of 135 countries assessed with an overall score of 45.9 out of 100. This makes the country the highest-ranked in Africa, ahead of every other country on the continent.

The jump is especially striking in context: in the index's inaugural 2024 edition, Nigeria ranked just 80th globally with a score of 7.21. A rise of 42 places in two years reflects real, documented progress including the launch of the National AI Strategy, investment in digital skills programs, and growing civil society participation in AI policy discussions.

At the same time, the index's authors caution that having strong policies in place is not the same as having enforceable safeguards or widespread responsible deployment. Nigeria's challenge going forward is closing that gap between paper progress and practice.

Nigeria's National AI Strategy targets adoption across seven priority sectors: agriculture, education, healthcare, finance, public services, telecommunications, and industry and manufacturing (still emerging). Adoption is uneven across these sectors, and roughly falls into three tiers. Finance and telecommunications lead the pack, at an estimated 48% adoption, driven by well-resourced institutions using AI for fraud detection, credit scoring, and network optimization. The middle tier comprising agriculture, healthcare, education, and public services sits around 34%, reflecting steady but more constrained progress. Industry and manufacturing remain the most nascent, at roughly 11% adoption, held back by infrastructure costs, unreliable electricity, and limited access to computing power.

Nigeria's position becomes clearer when placed alongside its regional peers. The same 2026 GIRAI report that placed Nigeria first in Africa ranked Egypt second and Kenya third among African countries. Nigeria's score of 45.93 more than doubled the African regional average of 21.79 and above the global average of 35.

GIRAI report identifies several challenges facing Nigeria's neighbors, where countries often have AI strategies without binding AI laws, and where dedicated AI safety institutions remain rare. Nigeria's advantage lies in having moved further and faster along several fronts at once: a published national strategy, an enforceable data protection law already in effect, an active subnational governance experiment in Lagos, and sector regulators like the CBN and NCC that are already issuing practical guidance while the federal legislation is yet to catch up.

Where Nigeria still resembles its regional peers, however, is in the space between policy and practice. Kenya has drawn attention for strong grassroots AI adoption; South Africa has leaned on stronger existing infrastructure and data protection law; Rwanda has built government readiness through a dedicated National AI Policy. Each country is solving a different piece of the same puzzle. What the comparison makes clear is that no single African country has yet closed all three gaps—data, accountability, and governance completely.