The 3 questions every Nigerian CEO should ask before adopting AI in 2026.
Every conversation I have with a Nigerian chief executive in 2026 eventually arrives at the same crossroads: the board has mandated AI, the vendors are queuing at the door, and the CEO is trying to separate genuine transformation from expensive theatre. This framework will not tell you which vendor to hire. It will tell you whether you are asking the right questions before you do.
Who is accountable when the model is wrong?
Before you sign any AI contract, run a simple thought experiment: your AI system makes a bad credit decision, misroutes a logistics shipment, or produces a discriminatory outcome in an HR process. Who, by name and by title, stands in front of your board, your regulator, and your customer and says, "this was our failure, and here is what we have done to fix it"?
In most AI deployments I have audited across West Africa, that question produces silence. There is a vendor SLA, a model card buried in a contract appendix, and a vague understanding that "the algorithm decided." None of that will satisfy the Nigeria Data Protection Commission when a data subject lodges a complaint. None of it will satisfy CBN when an AI-driven credit model is found to exhibit demographic bias.
The NDPA 2023 is explicit: data controllers; meaning your organisation, not your AI vendor; are responsible for automated decision-making that produces legal or similarly significant effects on data subjects. Article 32 of the Act creates a right to explanation that travels to your door, not your vendor's.
"The model decided" is not a governance structure. It is a liability gap.
What you should demand, before any deployment:
- 01A named AI accountable owner in your organisation; a person, not a team.
- 02A written model card that specifies the training data, known failure modes, and acceptable use boundaries.
- 03An override protocol: what triggers human review, who conducts it, and how long it takes.
- 04Incident response runbooks that name your DPO, your legal counsel, and the NDPC notification pathway.
If your vendor cannot supply a model card and your legal team cannot identify the override protocol, you are not ready to deploy. You are ready to be regulated.
Where does our data go; and who profits from it after we pay?
Nigerian enterprise data is among the most commercially valuable on the continent. Your customer transaction histories, your clinical records, your logistics movement patterns; these are assets that global AI companies would pay significant sums to train on. Many of them are training on it right now, through the SaaS agreements your procurement teams signed without reading the data-handling schedules.
The question of data sovereignty has moved from an ideological position to a commercial and regulatory one. NDPA 2023 restricts cross-border transfer of personal data unless specific adequacy or contractual conditions are met. NITDA's local content framework imposes additional considerations on data processed in support of government contracts. CBN's cloud computing framework for financial institutions creates hard requirements for certain categories of customer data.
But beyond compliance, consider the competitive dimension. If your operational data trains the model your competitor also uses via the same SaaS platform, you have contributed to the erosion of your own differentiation. The value of proprietary operations data compounds. Every day you allow it to be extracted for a vendor's training corpus is a day you are subsidising a competitor's intelligence advantage.
Sovereign AI is not nationalism. It is compound interest on the only asset that does not depreciate.
The due diligence questions that every CEO should put in writing to every AI vendor:
- 01Does our data leave Nigeria? If yes, to which jurisdiction, under which legal instrument?
- 02Is our data used to train or improve your models, even in aggregated or anonymised form?
- 03Can we retrieve or delete our data; including embeddings, fine-tuning weights, and cached responses; upon contract termination?
- 04Where are your model inference endpoints located, and who has administrative access to those servers?
Any vendor who cannot answer these in plain English, in writing, within five business days, is not a vendor you should trust with your most sensitive operational data.
What is our ROI horizon; and are we measuring the right things?
The most common failure mode in Nigerian enterprise AI adoption is not technical. It is financial. Specifically, it is a mismatch between the ROI horizon that the board expects and the ROI horizon that AI systems actually deliver.
AI transformation is not a software procurement event. It is an operational change management programme with a software component. The organisations in Nigeria that have achieved genuine AI-driven returns; a Tier-2 bank that automated 60% of its loan origination workflow, a logistics company that reduced last-mile spoilage by 34%; did so over 18 to 36 months of iterative deployment, not a 90-day implementation sprint.
This matters because the vendor ecosystem is structured to sell you the 90-day narrative. It is cleaner to close a deal on, and the failure mode is yours, not theirs, once the implementation phase ends and the retainer begins.
Equally important is what you measure. Most AI ROI frameworks are borrowed from ERP implementations and are poorly suited to AI systems. They measure cost displacement (headcount removed, hours saved) but not value creation (decisions improved, risks avoided, markets accessed). A fraud-detection model that prevents ₦200 million in losses this quarter does not appear in any standard cost-reduction dashboard unless you built the measurement framework before you deployed.
The ROI on AI compounds. But only if you measure it before deployment, not after the vendor leaves.
What a sound AI ROI framework should include:
- 01Baseline metrics captured before deployment, not estimated retroactively.
- 02Both efficiency metrics (throughput, cycle time, error rate) and outcome metrics (revenue, risk, customer experience).
- 03A 24-month measurement window with quarterly review gates, not a 90-day post-implementation review.
- 04Cost-of-delay calculations: what does it cost each quarter you do not deploy, not just what does it cost to deploy?
The framework in practice
These three questions are not a checklist to hand to your CTO. They are a governance posture. They signal to your organisation, your vendors, your regulators, and your board that you are treating AI as a governed operational capability, not a technology experiment.
The Nigerian CEOs who will lead their sectors in 2028 are making these decisions in 2026. Not because they are early adopters; the early adopter window closed in 2024. Because they understand that the competitive moat in the agentic-AI era is not access to models. It is the organisational capability to deploy them responsibly, measure them honestly, and own the outcomes when they fall short.
The question is not whether to adopt AI. That decision has already been made by your market. The question is whether you adopt it as a principal or as a passenger.