Skip to content

Legal landscape & sources

NAGF uses a source hierarchy so assessors do not collapse binding law, sector conditions, policy and future readiness into one “compliance” claim.

Documentation source check: 21 July 2026. This records the public-documentation review, not a permanent statement that every source remains unchanged.

LaneMeaningHow to assess
Enacted lawLegislation currently in forceDetermine scope, role and facts; assess compliance
Binding directive or regulatory codeInstrument issued under relevant authorityConfirm addressee, commencement, scope and current status
Sector rule or guidanceRule, licence condition, guideline or official sector expectationApply only when the actor, activity, product and trigger match
Regulator statement or status noticeCurrent official interpretation, enforcement or status informationRecord date and check for later notices or court action
Policy strategyNational strategy or policy directionAssess readiness and alignment, not statutory breach
Proposed billDraft legislation without an effective dateAssess future readiness; do not report current non-compliance
Best practiceResponsible-AI or assurance practiceUse as readiness guidance, not binding legal authority
Inferred mappingCross-framework relationshipUse for navigation only; verify the primary obligation

The assessment includes routes anchored to official sources such as:

The item advisory identifies its particular source. Follow that source rather than assuming a general AI rule.

Depending on route, the module includes source-led checks involving:

  • NDPC for data protection.
  • NITDA and public authorities for digital-government and technology governance.
  • NIMC for digital identity.
  • CBN for regulated financial services and payments.
  • NAICOM for insurance.
  • PenCom for pensions.
  • SEC Nigeria for capital markets and robo-advice.
  • NCC for telecommunications.
  • NAFDAC, NHIA and health authorities for health-related systems.
  • NCAA for civil aviation and remotely piloted aircraft systems.
  • FCCPC for consumer protection and relevant digital lending status.
  • INEC and relevant media authorities for election and media contexts.
  • ngCERT, ONSA and sector authorities for cyber and critical-infrastructure routes.

Regulator names are not substitutes for an applicability analysis. Identify the licensed or regulated actor, activity, product, system function and trigger.

Some matters require explicit current-status checking. Examples include:

  • Proposed legislation with no commencement date.
  • Rules affected by litigation or an official enforcement suspension.
  • Harmonisation or policy directions awaiting detailed implementation.
  • Regulator registers and circulars that change over time.

Record:

  • Source title and issuing authority.
  • Publication and effective date where available.
  • Retrieval or verification date.
  • Current status.
  • Exact provision or route relied upon.
  • Reviewer and next legal-watch date.

Do not:

  • Treat the National AI Strategy as an enacted AI Act.
  • Treat a proposed digital-economy bill as current law.
  • Infer a universal data-localisation rule from the NDPA.
  • Infer a universal AI-incident notification to every digital regulator.
  • Describe every synthetic-content risk as subject to one general deepfake prohibition.
  • Apply a financial, health, telecoms or aviation requirement without the sector trigger.
  • Rely on a superseded secondary summary over a current official source.
  • Official primary source opened.
  • Status and effective date checked.
  • Actor, role, activity and jurisdiction match.
  • Current-law and readiness lanes remain separate.
  • Litigation or suspension status checked where relevant.
  • Provision and assessor interpretation recorded.
  • Qualified legal review obtained for material uncertainty.
  • Next legal-watch date set.