cd /news/ai-policy/pakistan-bans-officials-from-using-p… · home topics ai-policy article
[ARTICLE · art-134501] src=insideai.news ↗ pub= topic=ai-policy verified=true sentiment=· neutral

Pakistan Bans Officials From Using Public AI Tools for Classified Data

Pakistan's National Computer Emergency Response Team (PKCERT) banned government employees from uploading classified documents, official emails, or citizens' personal data to public AI tools, publishing the restriction in the National Cyber Security Handbook 2026-27 under the Pakistan Information Security Framework 2026. The handbook requires officials to strip names, identification numbers, and addresses from prompts before submission, bars sharing passwords, administrative login credentials, or API keys with any AI system, prohibits unapproved AI extensions and plug-ins on government devices, and mandates direct human oversight of all AI-generated material entering official work. PKCERT said public platforms often retain prompts and may train future models on submitted content, creating a severe risk of data leakage, and requires immediate reporting of any disclosure to an employee's cybersecurity team.

by read3 min views1 publishedSep 19, 2026
Pakistan Bans Officials From Using Public AI Tools for Classified Data
Image: Insideai (auto-discovered)

September 19, 2026, (Inside AI) — Pakistan's National Computer Emergency Response Team (PKCERT) has issued a sweeping ban on government employees up classified documents, official emails, or citizens' personal data to public artificial intelligence tools. The restriction, published in the National Cyber Security Handbook 2026-27, establishes the first comprehensive operational rules for AI use across the country's public sector.

The handbook, which anchors the Pakistan Information Security Framework 2026, targets everyday workplace habits rather than exotic threats. Officials may no longer paste official correspondence into chatbots, run government source code through open models, or feed citizen records into any consumer AI service. PKCERT warned that such practices create a severe risk of data leakage, because public platforms often retain prompts and may train future models on submitted content.

Why Public Prompts Became a Security Liability #

The policy arrives as governments worldwide confront a quiet but costly problem. Consumer AI tools store user inputs by default, and several high-profile incidents in the past two years have exposed sensitive material through prompt logs. In one widely cited case, employees at a multinational firm accidentally leaked internal strategy documents after pasting them into a public chatbot for summarization.

Pakistan's approach goes further than simple prohibition. The handbook requires officials to sanitize every prompt before submission. Names, identification numbers, addresses, and other identifying details must be stripped from files in advance. If a disclosure happens anyway, employees must report it immediately to their cybersecurity team.

Read: China to Help Pakistan Build AI-Powered Law Enforcement Center

The rules also ban sharing passwords, administrative login credentials, or API keys with any AI system. That clause addresses a growing attack vector. Security researchers have documented cases where attackers tricked AI assistants into revealing credentials embedded in conversation history. PKCERT's guidance treats such leaks as reportable incidents, not mere mistakes.

Department-approved AI tools remain the only sanctioned option for daily workflows. The handbook prohibits installing unapproved AI extensions and plug-ins on government-issued devices, closing a side door that many agencies overlook. Browser add-ons and productivity plug-ins often request broad permissions, and a single rogue extension can siphon data from every open tab.

Human Sign-Off Becomes Non-Negotiable #

Perhaps the most consequential provision concerns output. No AI-generated material may enter official government work without direct human oversight. Officials must vet every automated response for both factual accuracy and security compliance. The rule acknowledges a reality that AI researchers have long emphasized: language models produce confident errors, and in government settings those errors can carry legal or diplomatic weight.

The emphasis on human review aligns with guidance from the National Institute of Standards and Technology, which has urged organizations to treat AI outputs as draft material requiring verification. Pakistan's framework effectively converts that recommendation into a binding requirement for public servants.

The handbook also signals that AI adoption inside Pakistan's government will proceed under permanent security conditions. Every future integration must satisfy privacy, supervision, and audit requirements. That stance mirrors moves by the European Union, whose AI Act imposes similar obligations on public bodies deploying high-risk systems.

Read: South Korea to develop new security guidelines for autonomous AI agents

For now, the immediate effect is procedural. Officials must change how they draft, research, and code. The longer effect may be cultural. By requiring sanitization before every prompt and human review after every output, PKCERT is teaching a generation of public servants that AI is a tool to be governed, not a colleague to be trusted.

── more in #ai-policy 4 stories · sorted by recency
── more on @pakistan's national computer emergency response team 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/pakistan-bans-offici…] indexed:0 read:3min 2026-09-19 ·