Nigeria's National Digital Economy and E-Governance Bill is in its third reading in the Senate and, according to ICT Committee Chairman Shuaib Salisu, could reach presidential assent within weeks. At 78 pages, it is the most ambitious attempt by an African legislature to build a binding, risk-tiered framework for artificial intelligence — and it arrives with real institutional weight behind it: the bill has moved through first and second readings, absorbed amendments in 2024, 2025 and 2026 to align with UN Convention against Cybercrime standards, and carries the backing of NITDA Director-General Kashifu Inuwa Abdullahi (THISDAYLIVE; naltf.gov.ng).
What the Bill Actually Does
The framework sorts AI systems into four categories by consequence: minimal-risk tools like chatbots and recommendation engines, limited-risk systems that influence non-critical decisions, high-risk deployments such as credit scoring, hiring tools, health diagnostics and identity verification, and an unacceptable-risk tier — public biometric surveillance and social scoring — that is prohibited outright (Techpoint Africa). The National Information Technology Development Agency (NITDA) becomes the enforcement backbone: it can demand documentation, issue directives, and block non-compliant systems, with fines set at the greater of ₦10 million or 2% of annual revenue (Techpoint Africa). Sections 62 and 63 of the underlying bill give NITDA's digital-technology rules primacy over conflicting provisions elsewhere in Nigerian law and authorize administrative sanctions on both private companies and public institutions (TechCabal).
This is a defensible starting point. Nigeria's AI adoption is accelerating faster than its regulatory capacity, and a bright-line prohibition on social scoring and mass biometric surveillance closes off the most dangerous use cases before they take root, rather than litigating them retroactively after harm occurs. A risk-tiered structure — rather than a blanket licensing regime — also signals to founders and investors that a chatbot and a hiring algorithm will not face the same compliance burden, which is the right instinct for a market still building its digital economy base.
The Gap Nobody Is Filling
But the bill regulates AI deployment without regulating AI harm. It says nothing about who compensates a Nigerian denied a loan by a flawed credit-scoring model, misdiagnosed by a health-AI tool, or wrongly flagged by an identity-verification system now legally sanctioned for high-risk use. Administrative fines paid to NITDA do not reach the injured party. Nigerian legal scholars have been explicit about why this matters: writing in August 2026, Peter Akhihiero argues Nigerian law leaves courts without an adequate doctrinal basis to compensate AI-caused harm, describing existing tort remedies as "imperfect" and frequently leaving victims "without compensation" (nigerianlawguru.com). A companion analysis identifies three distinct failure points: a doctrinal gap, where negligence, vicarious liability and strict liability all presume a identifiable human actor or a physical "escape" of harm that autonomous software simply does not fit; a structural gap, where Nigeria has no mandatory requirement that developers document how a system functions or disclose its use to affected people; and an institutional gap, where courts, regulators and the practicing bar largely lack the technical grounding to evaluate AI evidence at all (TheNigeriaLawyer).
That is a real doctrinal vacuum, not an academic quibble. Strict liability in Nigerian tort law traces to Rylands v Fletcher and its requirement that something dangerous "escape" from land — a fact pattern with no application to a cloud-hosted scoring model. Product liability statutes predate software entirely. And negligence collapses when a harm emerges from a machine-learning system whose developer, deployer and end-user all had partial, non-overlapping control over the outcome. A regulator empowered to fine a company ₦10 million for non-compliance does nothing to help the individual harmed by a compliant one.
Getting the Sequencing Right
The fix is not to slow the bill down or load it with EU AI Act-style ex ante liability rules that would deter the very deployment NITDA's risk tiers are designed to permit. A civil-liability regime bolted onto a still-forming market risks over-correcting into exactly the kind of blanket exposure that chills investment in the limited- and minimal-risk tiers this bill otherwise gets right. The more proportionate path is what several African jurisdictions have already signaled interest in: a narrow, high-risk-tier-only compensation mechanism — paired with the disclosure obligations that TheNigeriaLawyer's authors flag as structurally absent — that gives courts a statutory hook without extending liability exposure to a hiring chatbot or a customer-service assistant.
Nigeria has the rare advantage of legislating AI governance before, not after, a high-profile harm forces a reactive statute. NITDA's four-tier structure is a genuine template for the continent. But a framework that tells companies precisely how to deploy AI while leaving courts with no doctrine to compensate the people that deployment injures is only half a law. Lawmakers still have weeks, per Salisu's own timeline, to add a liability schedule before third reading closes — after assent, doing so requires a fresh bill.