1. Home
  2. Blog
  3. AI for Nigerian Businesses
  4. AI Policy for Nigerian Businesses: What to Put in It and How to Make It Stick

AI Policy for Nigerian Businesses: What to Put in It and How to Make It Stick

Business colleagues planning in an office — an article about AI policy for Nigerian businesses

Your staff are already using AI. The realistic choice is not whether AI enters the business but whether it does so with rules, and whether those rules are written in a way anyone will follow.

The failure modes are predictable. A policy copied from an overseas template refers to laws that do not apply here and processes the business does not have. A policy written by a lawyer runs to fourteen pages and is never opened again. A policy that simply forbids AI moves the activity to personal phones, where nothing can be seen or controlled.

What works is shorter and more specific: a document that answers the questions staff actually have, names the approved tools, and gets reviewed as tools change. This article sets out what to put in it, what to leave out, and how to roll it out so it survives contact with the business.

What an AI policy is for

An AI policy exists to answer, in advance, the questions that would otherwise be decided individually and inconsistently by whoever is at a keyboard.

  • May I use this tool?
  • May I put this information into it?
  • Do I need to check the output, and how carefully?
  • Do I have to tell anyone AI was involved?
  • What do I do if it produces something wrong, and who do I ask when the policy does not cover my situation?

A policy that answers those five questions clearly is more useful than one covering twenty topics vaguely. It also does something commercially valuable: it lets you answer a client, a bank or a corporate procurement team who asks what your position on AI is — a question Nigerian firms are increasingly being asked in tenders and supplier onboarding.

Policy, governance and standards: what is different

These three terms are used interchangeably and should not be.

AI policyAI governanceTechnical standards
Question it answersWhat are staff allowed to do?Who decides, oversees and is accountable?How must systems be built?
AudienceEveryone in the businessDirectors, owners, senior managersDevelopers, vendors, IT
Typical length2–4 pagesTerms of reference, register, review cycleTechnical documentation
Changes whenTools or rules changeStructure or risk appetite changesArchitecture changes

A small business needs the policy first. Governance structures matter once AI is embedded in decisions that affect customers or money, and technical standards matter once you are building rather than buying. Writing all three at once for a fifteen-person company produces documents nobody uses.

The ten sections your policy needs

  1. Purpose and scope. One paragraph: why the policy exists, who it applies to (employees, contractors, interns, agencies working on your behalf), and which activities it covers.
  2. Definitions in plain language. What you mean by AI tools, generative AI, AI features inside existing software, and customer-facing AI. Keep it to a few lines; staff do not need a taxonomy.
  3. Approved tools. A named list, with what each is approved for. This is the section people actually read, and the one that changes most often — keep it as a maintained appendix so the policy body stays stable.
  4. Data rules. What may and may not be entered, tied to your data classification. State plainly that customer identity data, bank details, staff records and signed contracts do not go into unapproved tools.
  5. Human review requirements. Which outputs must be checked and by whom. Differentiate: internal drafts need a sense check; anything sent to a customer, published, submitted to a regulator or used in a financial calculation needs substantive review by a competent person.
  6. Prohibited uses. Be specific and short. Typically: impersonating a real person, generating misleading content, making employment or credit decisions without human review, producing legal or medical advice for clients without professional review, and circumventing security controls.
  7. Disclosure. When AI involvement must be declared to customers, clients or staff, and in what form.
  8. Accountability. The person who uses the output owns it. AI is never an acceptable explanation for an error that reached a customer.
  9. Approval route. How to request a new tool or a new use case, who decides, and how long it takes.
  10. Incidents and review. How to report a problem — wrong output that reached a customer, data entered by mistake, a suspicious result — plus the policy owner's name and the review date.

Two optional sections earn their place in some businesses: intellectual property and client-work rules for agencies and consultancies, and recruitment-specific rules where AI touches CV screening.

Deciding your permitted-use rules

Most businesses find it easier to decide by task than by tool. The grid below is a starting point to adapt, not a standard to copy.

TaskTypical positionRequired control
Drafting internal documents, emails, summariesPermittedWriter checks facts before sending
Research and explanationPermittedVerify anything load-bearing against a primary source
Writing or reviewing codePermittedCode review, no production credentials or live customer data
Customer-facing copy, proposals, quotationsPermitted with reviewNamed person approves before it goes out
Analysing customer or staff dataRestrictedDe-identify first, or use an approved internal system
Screening job applicationsRestrictedHuman decides; AI may summarise but not rank or reject
Credit, pricing or disciplinary decisionsRestrictedHuman decides and records the reason
Legal, tax, medical or regulatory conclusionsNot permitted as final outputQualified professional reviews and signs
Generating images of real people or brandsNot permitted without consentLegal and reputational risk
Automated bulk outreachRestrictedConsent and messaging rules apply

Write your own version of this grid, agree it with managers, and put it in the policy. It is the single most useful page in the document.

Disclosure: when to tell customers and staff

Disclosure is where Nigerian businesses most often ask for guidance, because expectations are still forming. A defensible position rests on three principles.

Disclose when a person would reasonably want to know. A customer talking to a chat assistant should be able to tell it is not a human, and should be told how to reach one. An applicant whose CV is processed by an automated system should know that.

Disclose where a decision affects someone. Where AI contributes to a decision about a person — credit, employment, access to a service — explain that automated processing is involved and provide a review route. This is also relevant under the Nigeria Data Protection Act 2023; confirm the specific requirements with the Nigeria Data Protection Commission or a qualified adviser.

Do not over-disclose routine assistance. Using AI to help draft a proposal that a named person reviewed and stands behind does not usually need a label, any more than using a spell checker does. The accountability sits with the person who signed it. Blanket AI disclaimers on ordinary work tend to undermine confidence without informing anyone.

For client-service businesses, add one line to your engagement terms describing how AI may be used on client work and what safeguards apply. Corporate clients increasingly ask, and having the answer written down is faster than negotiating it in every contract.

Approval route for new tools and new use cases

Without a route, staff either stop asking or stop complying. Keep it light.

  1. Request. A short form or email: what tool, what task, what data tier is involved, what it replaces.
  2. Screen. The policy owner checks vendor terms against your register: training on your data, retention, processing location, sub-processors, deletion.
  3. Decide. Approve, approve with conditions (for example, internal data only, or with redaction), or decline with a reason.
  4. Record. Add to the approved tools appendix with the date the terms were checked.
  5. Communicate. Tell the team what was approved; most requests are shared needs.

Set a service standard — a decision within five working days — and hold to it. A slow approval process is the most common reason policies are ignored in practice.

What changes for Nigerian businesses

The NDPA 2023 is the anchor, not overseas regulation. Policies copied from European or American templates cite frameworks that do not apply and miss the obligations that do. Reference the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Commission, and point staff to a named internal contact rather than to foreign regulators. Where sector rules apply — financial services, health, education — reference the relevant Nigerian regulator.

Personal devices and personal accounts are the norm. Many Nigerian staff work partly from their own phones. A policy that assumes company-issued laptops and managed browsers will not describe reality. Address personal-device use explicitly, and reduce the incentive by providing an approved tool that works on a phone.

WhatsApp is a work system. Sales, support, supplier coordination and approvals happen there. Your policy needs a position on AI tools that read or generate WhatsApp content, because those conversations are full of customer personal data.

Currency and subscription realities shape the approved list. AI subscriptions are usually priced in US dollars, so what the business can sanction may be limited. Better to approve one or two tools the business will actually pay for than to publish a long list of theoretical options that staff cannot access.

Electricity and connectivity affect verification habits. Where connections drop, staff work around problems rather than reporting them. Make reporting a wrong output easy — a WhatsApp message to a named person is fine — rather than requiring a formal ticket.

Client contracts may go further than your policy. Some corporate and public-sector clients restrict AI use on their work entirely. Check engagement terms before extending a permission, and make that check part of the approval route for client-facing teams.

Example (hypothetical): a Lagos marketing agency

This is an illustrative scenario, not a Linestech client.

An agency of twenty-two staff produces campaigns for Nigerian consumer brands. Copywriters and designers use AI daily. Two problems surface in the same month: a client asks in a pitch whether the agency uses AI and how it protects their material, and a junior writer uploads a client's unreleased product brief to a free tool to summarise it.

The policy the agency writes runs to three pages:

  1. Approved tools appendix: one business-tier assistant for all staff, one image tool approved for concept work only, one transcription tool for interviews.
  2. Data rules: client briefs, unreleased campaign material, pricing and contracts are confidential and go only into the approved assistant. Consumer research containing personal data is de-identified first.
  3. Task grid: concepting, drafting and research permitted; final client-facing copy requires named review; AI-generated imagery may not be used in final deliverables without written client agreement; no generated likeness of any real person.
  4. Client disclosure: a standard clause in proposals stating how AI is used in the creative process, what is never sent to third-party tools, and that a human is accountable for every deliverable.
  5. Accountability: the account lead owns anything that reaches a client, whatever produced the first draft.
  6. Approval route: a request form to the operations manager, decision within five working days.
  7. Incidents: report to the operations manager the same day; the agency will contact the client where their material was involved.
  8. Review: every six months, or sooner if a client or the law requires.

The commercial effect is the one the agency did not expect: the disclosure clause becomes an asset in pitches, because most competitors cannot answer the question at all.

How much does it cost to put an AI policy in place?

Indicative 2026 Nigerian ranges. Actual costs vary with business size, sector and how much is done internally.

ItemWhat it involvesIndicative cost
Internally written policyManagement time, a template, a legal read-throughLargely internal time
Policy drafted with external supportWorkshops, data classification, drafting, task grid₦300,000 – ₦1,500,000
Legal reviewA Nigerian lawyer checking NDPA alignment and employment implications₦150,000 – ₦800,000
Staff training sessionOne to two hours, practical, with worked examples₦100,000 – ₦500,000
Approved tool subscriptionsBusiness-tier AI accountsUS$20 – US$60 per user per month typically
Annual review and updateRe-checking vendor terms, revising the tool list₦100,000 – ₦500,000 per year

A small Nigerian business can produce a good policy internally in a week of part-time work using the ten sections above. The cost that matters is not the document; it is the subscriptions that give staff a legitimate alternative to personal accounts.

Rolling it out so people actually follow it

  1. Survey first. Ask what people are already using and for what. The answers shape the tool list and reveal the real risks.
  2. Draft with the people who will follow it. Include a writer, a developer, someone in finance and someone customer-facing.
  3. Keep it to three pages with the tool list as a separate, easily updated appendix.
  4. Run one practical session. Walk through five real scenarios from your own business and ask the room what the policy says to do. Adjust anything that causes argument.
  5. Give staff the approved tool the same week. A policy that restricts before it enables gets ignored.
  6. Put it where work happens. A pinned message in the team group and a link in the onboarding pack beat a document buried in a shared drive.
  7. Name the contact. One person to ask, by name, reachable on the channel the team actually uses.
  8. Include it in onboarding for new staff and contractors.
  9. Review incidents openly. When something goes wrong, discuss the control that was missing rather than the person who missed it.
  10. Set the review date in the calendar with an owner attached.

Reviewing and updating the policy

AI tools change faster than most corporate documents. Build for that.

  • Separate the stable part from the volatile part. Principles, data rules and accountability change slowly. The approved tool list changes often. Keep them in different documents so the list can be updated without reissuing the policy.
  • Review the tool register at least every six months, re-checking vendor terms on training, retention and processing location.
  • Review the policy itself annually, or sooner if the law changes, a significant incident occurs, or you deploy a customer-facing AI system.
  • Track what the policy did not cover. Every approval request that fell outside the rules is a signal for the next revision.
  • Version and date every issue, and note what changed. Corporate clients and auditors ask.

Mistakes to avoid

  • Copying an overseas template. It will cite the wrong law and describe processes you do not have.
  • Writing it entirely in legal language. If staff cannot tell what to do on a Tuesday afternoon, it is not a policy.
  • Banning AI outright. Use moves to personal phones, and you lose all visibility.
  • Publishing rules without providing tools. Restriction without an alternative guarantees non-compliance.
  • A tool list inside the main document. It goes stale within weeks and makes the whole policy look outdated.
  • No named owner. Unowned policies are never reviewed and never enforced.
  • Blanket disclosure on everything. It dilutes the disclosures that genuinely matter.
  • Ignoring contractors and agencies. They often handle your most sensitive material.
  • Treating the policy as the whole programme. It sets the rules; data controls, training and governance make them real.

Conclusion

A good AI policy is short, specific to your business, and paired with a tool people can actually use. Cover the ten sections, decide permitted use by task rather than by tool, keep the approved list in a separate appendix, set a light approval route with a five-day standard, disclose where a person would reasonably want to know, and name an owner with a review date. Anchor it to the Nigeria Data Protection Act 2023 rather than to overseas frameworks, address personal devices and WhatsApp because that is how Nigerian businesses work, and review the tool register every six months. Written internally, the main cost is management time plus the subscriptions that make compliance possible.

If you want an AI policy that fits how your business actually operates, along with the data controls and staff briefing that make it more than a document, Linestech can help you assess current AI use, draft the rules with your team and set up the approval and review process.

Frequently asked questions

Is an AI policy legally required in Nigeria?

There is no standalone statute requiring a document titled "AI policy" as of 2026. However, obligations under the Nigeria Data Protection Act 2023 around lawful processing, security and automated decisions apply to AI use, and a written policy is the practical way to demonstrate that you manage them. Confirm your specific obligations with the Nigeria Data Protection Commission or a qualified adviser.

How long should the policy be?

Two to four pages for the policy itself, plus a separately maintained tool list. Larger or regulated organisations need more detail, but length should come from sector-specific rules rather than from generic material. If staff will not read it in ten minutes, it will not change behaviour.

Who should write it?

A named internal owner, usually operations, IT or whoever handles data protection, drafting with input from the teams affected and a legal read-through before issue. Writing it entirely externally produces a document that describes a business other than yours.

Should we let staff use their personal AI subscriptions for work?

Preferably not, because you cannot control the data terms, enforce settings or see usage. The practical answer is to provide a business-tier account and permit personal tools only for public-tier information. Where budget genuinely prevents this, state the restriction clearly and enforce the data rules strictly.

What should the policy say about AI-generated content that turns out to be wrong?

That the person who used or sent the output is accountable for it, and that outputs going to customers, regulators or into financial calculations require substantive review by a competent person. Add a reporting route so errors are raised quickly rather than concealed.

Do we need to tell clients we use AI on their work?

For service businesses, a short clause in your engagement terms describing how AI may be used and what safeguards apply is good practice and increasingly expected in tenders. Check each client's own contract too, since some restrict AI processing of their material entirely.

How does an AI policy relate to our existing IT and data protection policies?

It should reference them rather than duplicate them. Your acceptable-use, information-security and data-protection policies already cover access, passwords and personal data. The AI policy adds what is specific: which AI tools are approved, what may be entered into them, review requirements and disclosure.

What if we have no IT department?

Then the owner or a senior manager holds the policy, and you keep it simple: one approved tool, a one-page data rule, a task grid, and a named person to ask. Many Nigerian SMEs run this well without technical staff. Buy external help for the initial draft and the annual review rather than for day-to-day administration.

Sources and further reading

Figures, platform rules and regulations change. These are the primary references behind this article and the places to check before you act on it.