Pakistan's National CERT, the country's cybersecurity agency, bars officials from uploading classified data to public AI tools and requires department approved systems with human oversight.
Pakistan's National CERT has barred government employees from uploading classified documents, official emails, software source code, and citizens' personal data to public AI tools. Officials are now directed to use only department-approved AI systems, with mandatory human review of any AI-generated material used in official work.
The binding document is the National Cyber Security Handbook 2026-27, released by the country's cybersecurity agency under the Pakistan Information Security Framework 2026 and surfaced by ProPakistani. Corroborating coverage from TechJuice, PhoneWorld, and Tribune describes the same rules.
Officials must scrub names and sensitive details from prompts and files before use, and any accidental disclosure of confidential information must be reported immediately to the cybersecurity team. Passwords, administrative logins, and API keys may not be shared with AI tools at all. Unapproved AI extensions and plug-ins are banned on official devices.
The handbook sits inside a broader 90-day cybersecurity strategic action plan tied to the PISF 2026 rollout, per Bloom Pakistan. The handbook names a default-deny but does not list approved tools, define "public AI" operationally, or specify monitoring, leaving officials with a clear "don't paste" rule and little guidance on which approved tools to use instead.