This systematic scoping review examines the intersection of artificial intelligence governance and cybersecurity policy in Nigeria, a critical area of inquiry given the nation's rapidly digitising economy and escalating AI-enabled cyber threats. Nigeria's digital economy, valued at over $13 billion and projected to reach approximately $27 billion by 2030, has become a fertile ground for sophisticated cybercriminal activities including deepfake financial fraud, automated phishing campaigns, and adversarial attacks on machine learning systems. Annual cybercrime losses now exceed $800 million, creating a trust deficit that deters foreign direct investment and threatens national economic stability.
Despite this escalating threat landscape, Nigeria's legislative and governance frameworks have struggled to keep pace with technological velocity. The Cybercrimes Act of 2015, conceived in a pre-generative AI era, lacks specific provisions addressing algorithmic manipulation, autonomous agent crimes, and decentralised finance vulnerabilities. The Nigeria Data Protection Act 2023 and the National Artificial Intelligence Strategy provide foundational elements but remain structurally inadequate for the current threat environment. The 2024 amendments to the Cybercrimes Act expanded offense definitions and reduced reporting timelines, yet they do not explicitly criminalise AI-specific threats such as deepfake-enabled fraud.
This review adopts the Joanna Briggs Institute methodology for scoping reviews and follows PRISMA-ScR reporting guidelines. A systematic search will be conducted across eight electronic databases (Scopus, Web of Science, Google Scholar, HeinOnline, SSRN, African Journals Online, IEEE Xplore, ACM Digital Library) and twelve grey literature sources including government agencies, regulatory bodies, and international organisations. Eligibility criteria encompass peer-reviewed articles, policy documents, legislative texts, technical reports, and conference proceedings published between 2015 and 2025 that address AI governance, cybersecurity policy, or regulatory frameworks in Nigeria.
The review addresses five research questions: (1) How have cyber threats evolved from traditional social engineering to AI-enhanced adversarial attacks? (2) What is the efficacy of existing legal frameworks in addressing AI-driven cybercrime? (3) What are the proposed pillars of the National AI Strategy and their feasibility constraints? (4) How does Nigeria's approach compare with Singapore, the United States, and Kenya? (5) What comprehensive governance framework can position AI regulation as a tool for national security defence?
Data will be extracted using a standardised charting form and analysed through thematic content analysis. Expected outcomes include: (a) a mapped landscape of AI governance and cybersecurity literature in Nigeria; (b) identification of significant regulatory gaps in addressing algorithmic manipulation, deepfake financial fraud, and autonomous agent crimes; (c) assessment of the National AI Strategy's operational feasibility against structural constraints including infrastructure deficits, talent shortages, and fragmented coordination; (d) comparative policy insights from Singapore's trust-based model, the United States' security-first approach, and Kenya's data sovereignty focus; and (e) a comprehensive governance framework incorporating legislative amendment, algorithmic auditing, polycentric governance, sovereign infrastructure investment, and specialised judicial processes.
The findings will inform policy recommendations for Nigerian government agencies including NITDA, CBN, ONSA, and NCC, and contribute to scholarly discourse on AI governance in developing economies. The review protocol was developed in accordance with JBI and PRISMA-ScR standards to ensure methodological rigour, transparency, and replicability.