NITDA warns workers against feeding sensitive data into public AI tools

NITDADA

From Adanna Nnamani, Abuja

The National Information Technology Development Agency (NITDA) has warned organisations and their employees against entering personal, classified or confidential information into public artificial intelligence (AI) tools such as ChatGPT, Gemini, Claude and Copilot.

The agency issued the warning in an advisory posted on X on Saturday through its Computer Emergency Readiness and Response Team (CERRT.NG), highlighting data protection and security risks associated with the use of public Large Language Models (LLMs).

NITDA said information entered into public AI platforms may no longer remain under the control of the organisation that provided it, as such data could be retained, logged or used by service providers to train AI models.

The agency warned that employees using public AI tools for drafting, research and other work-related tasks could inadvertently expose Personally Identifiable Information (PII), classified government information or confidential organisational data.

According to NITDA, where personal data is involved, such exposure could constitute a personal data breach, potentially resulting in violations of applicable data protection laws and legal consequences.

It also warned that disclosure of classified, official-use or confidential information to external AI providers could compromise national security and public trust, while exposing organisations and employees to disciplinary or legal consequences.

To mitigate the risks, NITDA advised organisations and their employees not to enter confidential, classified, official-use or personal data into public AI platforms.

The agency recommended that organisations use only approved AI tools for official work and remove, anonymise or pseudonymise personally identifiable information and other sensitive data before using AI platforms.

NITDA also urged users to review the privacy and data-handling terms of AI platforms before using them and warned against uploading internal documents unless specifically authorised.

The agency further called on organisations and their staff to comply with existing AI, information security and data protection policies when using AI tools.

The warning comes amid growing concerns over the risks associated with employee use of AI platforms and other digital tools in the workplace.

NITDA has previously issued cybersecurity alerts on emerging threats, including AI-powered malware capable of stealing browser-stored credentials and sensitive information, while the Nigeria Data Protection Commission (NDPC) has also indicated plans to review the data protection framework to address emerging technologies such as artificial intelligence, big data and robotics.

 

 

 

 

Breaking news & top stories

Stay connected with The Sun Newspaper

Get breaking news, exclusive stories, and live updates delivered straight to your phone. Join thousands of readers already following us on Whatsapp Channel and Telegram.

Breaking news & top stories

Follow The Sun Newspaper

Get live updates & exclusive stories delivered straight to your phone.