Banks, law firms and hospitals hold the information Nigerians most expect to stay private: account histories, privileged case files, patient records. Their staff are also under constant time pressure, which is exactly the condition in which people reach for ChatGPT and paste in whatever they are working on. For these organisations, "just ban it" fails twice. The work still needs doing, and the ban simply moves the behaviour onto personal phones, out of sight.
The alternative this article explores is the one at the heart of our hub piece, Your Staff Are Already Using ChatGPT: Why Nigerian Companies Need Private AI: give staff a sanctioned AI that runs on a server the organisation owns, on its own premises, so sensitive data never leaves the building.
An important note: this article describes the regulatory landscape in general terms to explain why private AI is relevant. It is not legal advice. Your data protection officer, compliance team and legal counsel should confirm how any AI deployment fits your obligations.
The Regulatory Backdrop, in General Terms
The Nigeria Data Protection Act 2023 (NDPA) sets the framework for processing personal data, and the Nigeria Data Protection Commission (NDPC) is the regulator. Its broad principles will be familiar to anyone who has worked with data protection elsewhere: process personal data lawfully and for a defined purpose, collect no more than you need, keep it secure, keep it no longer than necessary, and take care when it moves outside Nigeria. The Act gives particular protection to sensitive personal data, which includes health information. We cover the Act's relevance to AI in more depth in NDPA 2023 and Generative AI: Keeping Company Data Inside Nigeria.
Banks have an additional layer. In general terms, the Central Bank of Nigeria expects the institutions it supervises to manage technology and outsourcing risk, maintain strong cybersecurity and protect customer information. Professional bodies set confidentiality duties for lawyers and clinicians. None of this mentions any particular AI product, but all of it bears on where client and patient data is processed and who can see it.
Sector by Sector
| Sector | Data that must stay protected | High-value AI uses | Key cautions |
|---|---|---|---|
| Banks and financial services | Customer identities, account and transaction data, credit files, internal risk reports | Policy and procedure Q&A, drafting customer correspondence, summarising credit memos, internal knowledge search | Access by role, audit logs, alignment with information security and outsourcing policies |
| Law firms | Privileged client files, contracts, litigation strategy, due diligence material | First-draft documents, clause search across precedents, summarising bundles, research notes | Matter-level access separation, partner review of every output, no client data in public tools |
| Hospitals and clinics | Patient records, diagnoses, test results, insurance details | Discharge summary drafts, protocol and guideline Q&A, administrative letters, staff training material | Clinician review, strict access control, never a diagnostic decision-maker |
Banks
The quickest wins in a bank are internal: a private assistant that answers questions from the bank's own policy manuals, product guides and circulars, and drafts routine correspondence. Customer-facing use comes later, if at all. Because the server sits inside the bank's own network, it can be placed in an appropriate security zone, connected to the bank's directory for sign-in, and logged like any other internal system. That is a much easier conversation with information security than staff using public tools on their own initiative.
Law firms
Legal work is mostly reading and writing, which is what language models do best. A private server lets associates summarise a bundle, search precedents for a clause or produce a first-draft letter without a client's papers ever leaving the firm. The structural safeguard is matter-level separation: document collections mapped to the teams working on each matter, as described in our local RAG guide. The professional safeguard is that a qualified lawyer reviews everything before it goes anywhere.
Hospitals
Hospitals gain most on administration and documentation: drafting discharge summaries and referral letters for a clinician to check, answering staff questions from clinical protocols, preparing training material. They are also where the stakes of a wrong answer are highest, so private AI should assist clinicians and never make clinical decisions. Power is a particular concern; the AI server should sit on the same protected supply as other critical systems, not on a socket in a back office.
What Private AI Solves, and What It Doesn't
| Concern | How a private AI server helps | What you still need |
|---|---|---|
| Data leaving the organisation | Prompts, documents and answers stay on your server | Rules on what staff may still put into cloud tools |
| Cross-border transfer | Processing happens in Nigeria, on your premises | Advice on any other systems that transfer data |
| Who sees what | Per-group document collections and accounts | Role design, joiner and leaver processes |
| Accountability | Usage can be logged on infrastructure you control | Someone who reviews the logs, and a retention rule |
| Wrong answers | Answers can cite their source document | Mandatory professional review for regulated output |
The honest summary: a private server removes the biggest uncontrolled risk, sensitive data being pasted into services outside your control, but it is one control among several, not a compliance certificate. Our article on shadow AI in Nigerian workplaces explains why that uncontrolled risk is usually the biggest one.
Questions Your Compliance Team Will Ask
Bringing these to the first meeting saves weeks of back and forth:
- Where exactly does data go? · onto one server on your premises; nothing is sent to a model provider.
- Who can access it? · named accounts in defined groups, ideally tied to your existing directory, removed when staff leave.
- What is logged, and for how long? · a decision for you to make and document, not a default to accept.
- How is it updated? · models and software are updated through a controlled change process, which can be fully offline.
- What happens if it fails? · staff fall back to normal working; the AI is an assistant, not a dependency for regulated processes.
A Hybrid Policy Still Makes Sense
Even in regulated organisations, not every task touches regulated data. Marketing copy, public research and generic coding questions can go to an approved cloud AI with appropriate contractual terms, where frontier models do the job better. The policy line is drawn by data, not by department: anything with customer, client or patient information goes to the private system; everything else may use the approved cloud tool.
The Hardware Regulated Clients Choose
Sector doesn't change the sizing logic; user count, model size and document volume do. What regulated clients often add is resilience: ECC memory, redundant power and a server chassis that belongs in a rack. Sephora's AI Series tiers, all priced inc. VAT:
- AI Research, ₦8,800,000 · i7-14700K, 64GB DDR5, RTX 4070 Ti Super 16GB. A pilot team of roughly 5–15 light concurrent users on 7–14B models.
- AI Professional, ₦18,600,000 · i9-14900K, 128GB, RTX 4090 24GB. Roughly 15–50 staff on quantised 14–32B models.
- AI Lab, from ₦25,000,000 · Threadripper or Xeon W, 256GB ECC, 2× RTX 4090 or RTX A6000, 1600W redundant PSU, server chassis. Company-wide and 70B-class models; around 200 staff means AI Lab or multiple servers, by consultation.
For branches, field clinics or offsite work, our portable AI server article covers a flight-case version. Every install includes UPS and inverter planning for Nigerian grid conditions, and for hospitals especially, integration with the existing critical power setup. The wider design questions are covered in AI inference servers for business applications.
If you run IT, risk or operations in a bank, law firm or hospital, book a private-AI consultation. We will work alongside your compliance and security teams to design a deployment they can sign off. You can also ask Kitan, our site assistant, or message us on WhatsApp at +234 707 096 6669.