Artificial Intelligence Regulatory Tracker
Monitoring AI Governance Across Africa and International Markets
Artificial-intelligence regulation is developing rapidly. Governments, regulators and standards bodies are considering how AI systems should be designed, procured, deployed and supervised.
The Amstel Consulting Artificial Intelligence Regulatory Tracker is intended to help organisations follow significant AI-policy, legislative and regulatory developments in Nigeria, across Africa and in selected international markets.
The Tracker focuses on developments that may affect privacy, data protection, governance, cybersecurity, accountability and organisational risk.
What We Monitor
The Tracker may cover:
- AI legislation and proposed legislation
- Government strategies and national AI policies
- Regulatory consultations
- Data-protection authority guidance
- Automated decision-making requirements
- AI risk-management frameworks
- Governance and accountability standards
- Transparency and explainability
- Bias and discrimination
- Human oversight
- Procurement and vendor governance
- Generative AI
- Cybersecurity and model security
- Children and vulnerable individuals
- AI use in employment, finance, healthcare and public services
- International standards and regional initiatives
Jurisdictional Coverage
Nigeria
Monitoring of Nigerian legislation, strategies, regulatory guidance and public-sector initiatives relevant to artificial intelligence, data protection and digital governance.
View Nigeria DevelopmentsOther African Jurisdictions
Selected developments from African countries and regional institutions that may influence AI governance, cross-border services or organisations operating in more than one African market.
View African DevelopmentsInternational Developments
Selected international developments that may be relevant to African organisations, multinational businesses, technology providers and organisations serving customers in other jurisdictions.
View International DevelopmentsHow to Read the Tracker
Each entry should contain:
- Jurisdiction: The country or regional body concerned
- Authority: The responsible government, regulator or standards body
- Development: Law, bill, policy, guidance, consultation or enforcement action
- Status: Proposed, under consultation, adopted, in force or withdrawn
- Relevant date: Publication, adoption, commencement or consultation deadline
- Organisations affected: The likely scope of application
- Key implications: A concise explanation of the development
- Recommended action: Practical points for organisations to consider
- Official source: A link to the responsible authority or original document
- Last verified: The date on which the entry was checked
Tracker Status Definitions
A proposal, bill or policy has been announced but has not yet been formally adopted.
The responsible authority is accepting stakeholder input or reviewing a proposed framework.
The measure has been formally approved but may not yet be fully effective.
The measure has commenced and may create current obligations.
The publication explains regulatory expectations or recommended practices but may not itself constitute legislation.
The proposal or publication is no longer current or has been replaced.
Featured Topics
AI and Data Protection
AI systems frequently depend on large volumes of personal data. Organisations should assess lawful processing, transparency, data minimisation, accuracy, security, individual rights and the use of data for training or model improvement.
Automated Decision-Making
Systems that evaluate, recommend or make decisions about individuals can create significant privacy, fairness and accountability risks.
Relevant questions include:
- Is personal data being used?
- Does the system make or materially influence decisions?
- Could the outcome significantly affect an individual?
- Is meaningful human oversight available?
- Can the organisation explain and challenge the result?
- Are bias, accuracy and discrimination risks being assessed?
Generative AI in the Workplace
Employees may enter confidential, personal or commercially sensitive information into generative-AI systems without understanding how that information will be stored or reused.
Organisations should consider:
- An acceptable-use policy
- Approved and prohibited tools
- Confidentiality restrictions
- Personal-data controls
- Human review requirements
- Intellectual-property risks
- Vendor and security assessments
- Training and incident reporting
AI Vendor Due Diligence
Before acquiring or integrating an AI service, organisations should understand:
- What data the system receives
- Where information is stored and processed
- Whether submitted data is used for model training
- Which sub-processors are involved
- How long data is retained
- What security controls are available
- How decisions can be reviewed
- How the service can be terminated
- Whether data can be returned or deleted
- Whether the vendor provides sufficient audit information
AI Governance Readiness
Organisations do not need to wait for comprehensive AI legislation before introducing responsible governance.
Practical steps may include:
- Identify AI systems already being used.
- Record their purpose, owner, provider and data inputs.
- Classify systems according to risk.
- Assess privacy, security, fairness and operational impact.
- Establish approval requirements for higher-risk systems.
- Define acceptable and prohibited uses.
- Conduct vendor due diligence.
- Introduce human oversight and escalation procedures.
- Train employees.
- Monitor performance, incidents and regulatory developments.
Submit a Regulatory Development
Regulators, researchers, professional bodies and other stakeholders may notify us of relevant AI-governance developments.
Submissions should include:
- Jurisdiction
- Issuing authority
- Title of the development
- Publication date
- Official source
- Brief explanation of its relevance
Submission does not guarantee publication. Each proposed entry should be reviewed against an authoritative source before it is added to the Tracker.
Methodology and Limitations
The Tracker is an informational monitoring resource. Entries should be based primarily on legislation, government publications, regulatory sources and recognised standards bodies.
Although reasonable efforts may be made to keep entries current, regulatory developments can occur quickly. The absence of a development from the Tracker does not mean that no relevant law, policy or regulatory requirement exists.
The Tracker should display the date on which each entry was last verified. Older entries should be reviewed before they are relied upon.
Speak With an AI Governance Consultant
Evaluate algorithmic risk, establish internal acceptable-use frameworks, and ensure your automated decision systems adhere to lawful data protection standards.
Speak With an AI Governance ConsultantImportant Disclaimer
The Artificial Intelligence Regulatory Tracker is provided for general information and educational purposes. It does not constitute legal advice, a comprehensive statement of the law or confirmation that a particular AI system is compliant.
Organisations should obtain advice based on the jurisdictions in which they operate, the nature of the AI system, the data involved and the potential effect on individuals.