Nigeria’s technology regulator warns organisations against putting personal, confidential and classified information into public AI tools
The corporate AI revolution has created a new information-security problem that many organisations are only beginning to understand: employees can now move sensitive corporate information into sophisticated AI systems with the same ease with which they once sent an email.
Nigeria’s National Information Technology Development Agency (NITDA) has issued a warning to organisations and their employees against entering personal, classified or confidential information into public artificial intelligence tools including ChatGPT, Gemini, Claude and Copilot. The warning was reported on October 4 following an advisory from NITDA’s Computer Emergency Readiness and Response Team.
The warning is significant because AI adoption is rapidly becoming decentralised inside organisations. Employees do not necessarily wait for a board-approved AI strategy before using AI. A marketing executive may paste a campaign brief into a chatbot. A lawyer may ask an AI system to review a contract. An accountant may upload financial information to summarise a report. A human-resources officer may use AI to analyse employee information.
Each action may appear harmless when considered individually. Collectively, however, they create a new corporate data-governance problem.The risk is not simply that an employee is using AI. It is that the employee may not know exactly what happens to the information after it is submitted, what contractual protections apply, what data-retention arrangements exist, where information may be processed, or whether confidential material is being exposed outside the organisation’s approved technology environment.
The Problem with the Free AI Revolution
The extraordinary convenience of public AI tools is precisely what makes the governance problem difficult. Traditional enterprise software usually goes through procurement. IT departments assess it. Security teams review it. Legal departments negotiate contracts. Data-protection officers examine how information is processed. Generative AI has changed that sequence.
An employee can discover a powerful tool in the morning and begin using it for corporate work before the organization’s technology, legal or compliance teams know the tool exists. This is sometimes called shadow AI: the organizational use of AI systems outside formal governance structures.
For boards and senior executives, the issue is therefore moving from technology adoption to technology governance. The appropriate corporate response is unlikely to be simply banning AI. Such bans can be difficult to enforce and may push usage further underground. A more sophisticated response is to create clear rules about what employees may and may not put into public AI systems.
Companies need to classify information according to sensitivity and establish corresponding AI-use rules. Publicly available information may be acceptable. Internal information may require an approved enterprise AI environment. Personal data, trade secrets, strategic plans, customer information, passwords, unpublished financial information and confidential legal documents may require much stronger controls.
The second requirement is training. Employees need to understand that a chatbot is not simply a smarter version of Google. It is a system into which information is being submitted and processed according to the provider’s technical and contractual architecture.
AI Governance Becomes Everyone’s Job
The NITDA warning also has an important implication for marketing and communications professionals. Marketing teams are among the heaviest users of generative AI because the technology is particularly effective at producing drafts, campaign concepts, social-media content, audience analysis and creative variations.
But marketing departments also handle valuable information: customer databases, campaign strategies, unreleased products, pricing plans, media strategies and proprietary consumer insights. The temptation to paste that information into an AI tool can therefore create risks that are invisible at the point of use. This is where AI governance needs to become part of corporate culture rather than merely an IT policy.
The most effective organizations will eventually treat AI literacy in much the same way they treat cybersecurity awareness. Employees will be expected to know not only how to use AI, but how to use it safely. For CEOs, the strategic challenge is to create an environment in which employees can experiment with AI without turning experimentation into uncontrolled data exposure.
BrandiQ Takeaway
The question for businesses is no longer whether employees will use AI. It is whether they will use it safely. AI adoption without data governance can turn productivity gains into corporate risk. The smartest organisations will therefore build AI policies that encourage.



