Think Before You Prompt: NITDA Sounds Alarm Over Nigerians Feeding NIN, BVN, and Medical Data to AI Chatbots

The National Information Technology Development Agency has issued an urgent public advisory warning Nigerians against sharing sensitive personal and financial identifiers, including National Identification Numbers, Bank Verification Numbers, personal photographs, and medical test results, on artificial intelligence platforms.

The warning comes as citizens increasingly deploy consumer AI assistants, including OpenAI's ChatGPT, Anthropic's Claude, Google Gemini, Microsoft Copilot, and Meta AI, to assist with workplace assignments, schoolwork, recruitment processes, medical inquiries, and everyday personal tasks.

In a formal regulatory notice titled "Advisory on the Safe Use of AI Platforms" published on Monday, the technological watchdog cautioned that most users submit sensitive material into chatbots without understanding that third-party vendors routinely retain, store, and process prompts on foreign servers outside individual control.

"Information entered into an AI platform may be retained, logged, used to train the provider’s AI models," NITDA stated, underscoring that confidential records lodged in external Large Language Models risk being compromised during third-party data breaches, leaving individuals exposed to impersonation, identity theft, and financial fraud.

The regulatory agency highlighted that the dangers extend beyond individual identity theft to enterprise and sovereign exposure, noting that the unauthorised disclosure of classified government or corporate documents to external model providers compromises national security and public trust while subjecting organisations to statutory liability under data protection laws.

Beyond data leakage, NITDA cautioned users against the uncritical acceptance of AI-generated advice, warning that automated models frequently output inaccurate, fabricated, or outdated answers with an authoritative tone, creating severe real-world hazards when relied upon for health, legal, academic, or financial decision-making.

To mitigate these systemic vulnerabilities, the agency instructed the public to consistently remove, anonymise, or pseudonymise personally identifiable information before entering prompts, verify platform privacy terms, and refrain from uploading non-public workplace files without explicit authorisation.

NITDA further directed public and private institutions to establish enterprise-level AI governance frameworks that define approved productivity tools, establish data-handling boundaries, and enforce compliance with existing national information security frameworks.

Reinforcing its cybersecurity campaign on social media, the agency urged users to exercise strict restraint when engaging with generative engines, concluding its advisory with a clear behavioural directive: "Think Before You Prompt".

Post a Comment

Please Select Embedded Mode To Show The Comment System.*

Previous Post Next Post