7. Legal Tech: AI in Health Research – Legal and Ethical Issues
Context and Background
Artificial intelligence is moving rapidly from the margins of Nigeria’s health sector into clinics, laboratories, universities and public-health institutions. Algorithms are increasingly being used to analyse medical images, predict disease outbreaks, identify patterns in electronic health records, support drug discovery and assist clinicians in making diagnostic decisions. At institutions such as the University College Hospital, Ibadan, the Lagos University Teaching Hospital, the National Hospital, Abuja, and research centres linked to the Nigeria Centre for Disease Control and Prevention (NCDC), data-driven tools are becoming part of conversations about how to address chronic shortages of doctors, radiologists, pathologists and specialist health workers.
The promise is substantial. Nigeria’s population, projected to continue growing sharply over the coming decades, faces a dual health burden: persistent infectious diseases such as malaria, tuberculosis and Lassa fever, alongside rising rates of diabetes, cancer, hypertension and cardiovascular disease. Artificial intelligence could help healthcare providers process large volumes of information more quickly, identify high-risk patients earlier and extend expertise to underserved rural communities.
Yet the same technologies raise difficult questions about privacy, consent, accountability and power. When a hospital shares thousands of patient scans with a technology company developing a diagnostic tool, who has authorised that use? When an algorithm trained primarily on foreign populations produces an erroneous result for a Nigerian patient, who is legally responsible? And when health data generates commercial value, do patients whose information made the innovation possible have any meaningful stake in the benefits?
These questions are no longer theoretical. They sit at the centre of a growing legal and ethical debate over whether Nigeria’s existing health, data-protection and professional-regulation laws are sufficient for the age of machine learning.
“The privacy of citizens, their homes, correspondence, telephone conversations and telegraphic communications is hereby guaranteed and protected.”
— Section 37, Constitution of the Federal Republic of Nigeria 1999 (as amended)
Although the constitutional text predates the digital health revolution, its underlying protection of privacy has become increasingly relevant to the handling of sensitive medical information. The challenge is translating broad constitutional principles into enforceable safeguards for complex systems that collect, combine and analyse data on an unprecedented scale.
The Expansion of AI in Nigerian Health Research
AI tools in health research are often presented as neutral technical instruments. In reality, they are built on human choices: which data is collected, whose medical histories are included, what outcomes are prioritised and what assumptions are embedded in the algorithm. These choices can have profound consequences in Nigeria, where health data is unevenly distributed across regions, income groups and healthcare facilities.
Large tertiary hospitals in Lagos, Abuja, Ibadan and Kano may possess more digitised records than primary health centres in rural communities. Consequently, an algorithm trained on data from urban hospitals may be less accurate when used in communities with different disease patterns, genetics, environmental exposures, languages or access to care. A predictive system that appears highly effective in a private hospital serving affluent patients may perform poorly in a public facility with intermittent electricity, incomplete records and delayed laboratory results.
Researchers also increasingly rely on cross-border collaborations. Nigerian patient data may be stored on cloud servers outside the country, accessed by foreign academic institutions or processed by multinational technology firms. Such arrangements can support scientific advancement, but they also create questions over jurisdiction, data transfers and whether Nigerian institutions retain meaningful control over information gathered from local communities.
The regulatory environment is developing. The Nigeria Data Protection Act 2023, administered by the Nigeria Data Protection Commission (NDPC), established a statutory framework for personal-data processing. The Act treats health information as sensitive personal data deserving heightened protection. Meanwhile, the National Health Act 2014, the National Code of Health Research Ethics, professional standards issued by bodies such as the Medical and Dental Council of Nigeria, and research-ethics oversight by the National Health Research Ethics Committee (NHREC) all have relevance.
But these instruments were not designed as a unified AI governance regime. They do not comprehensively answer the distinctive questions raised by autonomous or semi-autonomous decision-support systems, opaque algorithms and commercial data ecosystems.
Informed Consent in the Age of Big Data
From a Signature to Meaningful Understanding
Informed consent has long been a cornerstone of medical ethics and research governance. Traditionally, it requires that participants understand the nature of a study, its risks, potential benefits, alternatives and their right to withdraw. In AI research, however, consent is more difficult to obtain in a meaningful form.
Data collected for one purpose may later be reused for another. A patient who consented to treatment at a hospital may not have anticipated that anonymised or pseudonymised records could be used years later to train a commercial diagnostic system. Nor may the patient understand the implications of combining medical information with demographic, genetic, behavioural or location data.
The problem is especially acute where consent forms are lengthy, technical and written in legalistic English. Nigeria is linguistically diverse, and many patients may have limited access to clear explanations in their preferred language. A signature or thumbprint on a form cannot by itself establish that a person understood how their information might be processed, shared or monetised.
Under the Nigeria Data Protection Act, consent must be freely given, specific, informed and unambiguous where consent is relied upon as the lawful basis for processing. Health researchers may in some cases rely on other lawful bases, including legal obligations, public interest or scientific research subject to safeguards. But the availability of an alternative legal basis should not become an excuse for excluding patients from decisions about the use of intensely personal information.
Legal scholars argue that AI research requires a more dynamic model of consent. Rather than treating consent as a one-time administrative event, institutions could adopt layered notices, periodic updates and digital mechanisms allowing participants to understand and manage future uses of their data. Such systems must nevertheless remain accessible to people without smartphones, reliable internet access or digital literacy.
Ethics committees also face a difficult balancing exercise. Broad consent can make valuable longitudinal research possible, particularly in public-health emergencies. But overly broad consent can become ethically hollow if it gives researchers virtually unlimited discretion to repurpose data. The essential question is whether a participant can reasonably understand the categories of future research and the organisations that may gain access to the information.
Ownership, Control and the Commercial Value of Health Data
The language of “ownership” is frequently used in debates about medical data, but the law is more complicated than the slogan suggests. Nigerian law does not provide a simple rule stating that a patient owns every piece of information generated through medical treatment in the same way that a person owns a physical object.
Patients have privacy interests, data-protection rights and expectations of medical confidentiality. Healthcare providers may have legal duties to maintain records. Researchers and institutions may hold intellectual-property rights in databases, software, inventions and scientific findings. Technology companies may claim proprietary interests in the models they develop. These overlapping claims can leave patients with limited control even though their health histories are the raw material of the system.
The concern is not merely philosophical. Health data has enormous economic value. A large, well-curated collection of Nigerian radiology images, pathology results or genomic information could be used to develop products sold across Africa and beyond. If the benefits accrue primarily to foreign companies, elite universities or private investors, while the communities that supplied the data see no improvement in healthcare, the arrangement risks replicating older patterns of extractive research.
Nigeria’s history of public-health research makes these concerns particularly sensitive. Communities that have experienced inadequate access to medicines, weak clinical infrastructure or exclusion from the benefits of scientific research may reasonably question whether promises of innovation will translate into equitable outcomes.
Data-governance agreements should therefore be transparent about access, retention periods, commercialisation, intellectual-property rights and benefit-sharing. Hospitals and universities should not sign opaque contracts that permit technology vendors to reuse patient information for unrelated product development. Where data is shared internationally, institutions should assess whether foreign recipients offer protections consistent with Nigerian law and whether contractual safeguards are enforceable in practice.
Legal and Policy Analysis
Existing Law Offers Protection, but Not Complete Answers
The Nigeria Data Protection Act 2023 is an important foundation. It requires data controllers and processors to process personal data lawfully, fairly and transparently; to adopt appropriate security measures; and to respect data-subject rights. For health institutions deploying AI, this means data protection cannot be treated as a compliance exercise delegated solely to an information-technology department. It must be integrated into research design, procurement, clinical governance and staff training.
Data minimisation is particularly important. An AI developer should not receive more identifying information than is necessary for the defined research purpose. De-identification, pseudonymisation, access controls, encryption and audit logs should be standard safeguards. Yet anonymisation is not a complete solution: sophisticated techniques can sometimes re-identify individuals when supposedly anonymous datasets are combined with other sources of information.
The National Health Act 2014 reinforces the importance of confidentiality and patient rights, while the National Code of Health Research Ethics requires ethical review for human-subject research. But neither framework sets detailed standards for algorithmic explainability, bias testing, continuous post-deployment monitoring or the validation of AI tools across Nigeria’s diverse populations.
There is also uncertainty over liability. If a clinician follows an AI recommendation that leads to a missed cancer diagnosis or an incorrect prescription, potential defendants may include the doctor, hospital, software developer, device distributor or data provider. Existing principles of negligence, professional misconduct, product liability and contract law may apply, but they were not developed for systems in which the reasoning behind a recommendation may be difficult to explain.
A court considering such a dispute would likely ask whether the clinician met the applicable standard of care, whether the hospital adequately vetted the technology, whether warnings were provided and whether the defect caused the patient’s injury. But proving causation may be difficult where an algorithm operates as a “black box” or where medical decisions involve several interacting factors.
The Case for a Specific AI Regulatory Framework
Legal experts increasingly argue that Nigeria needs a dedicated AI Regulatory Framework rather than relying solely on scattered provisions across data-protection, health, consumer and professional laws. Such a framework should classify medical AI systems according to risk. A hospital scheduling tool should not face the same regulatory burden as an algorithm that recommends cancer treatment or predicts suicide risk.
High-risk clinical systems should be subject to pre-deployment assessment, independent validation, clear documentation, cybersecurity testing and human oversight. Developers should demonstrate that a system has been tested using data relevant to Nigerian patients and clinical conditions. Regulators should also require ongoing monitoring, because an algorithm’s performance can deteriorate when disease patterns, equipment, populations or clinical practices change.
Crucially, the law should reject the idea that AI can replace professional judgment in high-stakes care. A clinician must retain authority to question, override or disregard an automated recommendation. Patients should also be told, in comprehensible terms, when AI materially influences diagnosis or treatment.
Innovation in health technology is not ethically defensible merely because it is efficient. It must also be lawful, accountable, explainable and fair to the people whose data and lives are affected.
Impact and Future Outlook
If responsibly governed, AI could help Nigeria close serious healthcare gaps. It could support overburdened clinicians, improve disease surveillance, reduce diagnostic delays and strengthen research on conditions affecting African populations that have historically been underrepresented in global datasets. It could also stimulate a domestic health-technology sector, creating opportunities for Nigerian researchers, software engineers, legal practitioners and entrepreneurs.
But poorly regulated adoption could deepen inequality. Wealthier hospitals may obtain sophisticated systems while underfunded facilities are left behind. Biased algorithms may produce lower-quality care for rural, poor or marginalised communities. Data breaches could expose patients to stigma, discrimination or financial exploitation, particularly in relation to HIV status, mental-health conditions, fertility treatment and genetic information.
The path forward requires coordinated action. The National Assembly, the NDPC, the Federal Ministry of Health and Social Welfare, NITDA, professional councils, universities and civil-society organisations should develop rules that connect data protection with clinical safety and research ethics. Hospitals should establish multidisciplinary AI governance committees involving doctors, lawyers, ethicists, patient representatives, cybersecurity experts and data scientists.
Above all, patient rights must remain central. Nigeria does not have to choose between technological innovation and ethical healthcare. A strong legal framework can make innovation more trustworthy, encourage responsible investment and ensure that AI serves the public interest rather than turning patients into passive sources of commercially valuable data.
The defining test will be whether Nigerian law evolves quickly enough to ensure that the country’s health-data future is built on consent, fairness, accountability and public confidence.
