Pakistan has introduced new restrictions on government staff AI use under its National Cybersecurity Handbook 2026-27. The rules bar employees from uploading classified documents, official emails, software source code and citizens’ personal information to public artificial intelligence tools. The National Cyber Emergency Response Team, known as PKCERT, issued the handbook based on the Pakistan Information Security Framework 2026.
The document sets out practical cybersecurity guidelines for government and public sector employees. It warns that entering sensitive information into public AI platforms could cause data leaks and unauthorized retention. Furthermore, it cautions that classified national data could leak into external AI training models.
PKCERT instructs officials to use only AI tools approved by their respective departments. Officials must also strip names and other sensitive details from prompts and uploaded files before submission. Additionally, employees must immediately report any accidental disclosure of confidential data to their departmental IT or cybersecurity teams.
The rules also prohibit government personnel from sharing passwords, administrative credentials and application programming interface keys with AI tools. The handbook further bars employees from installing unauthorized AI extensions or plugins on official devices. Meanwhile, PKCERT directs officials to verify AI-generated content for accuracy and security before using it in government work.
However, the handbook does not ban AI tools altogether. Instead, it allows their use for content generation, analysis and routine tasks. Still, that use must meet security safeguards, privacy requirements and human oversight standards.
The move reflects growing global concern over how public sector employees interact with commercial AI platforms. Governments elsewhere have introduced similar restrictions after incidents involving accidental data exposure through AI tools. Therefore, PKCERT’s handbook positions Pakistan among the countries actively formalising AI governance for public employees.
Officials say the guidelines aim to balance productivity gains from AI adoption against genuine security risks. PKCERT plans to update the handbook periodically as government staff AI use expands across departments. This approach reflects lessons learned from real-world data exposure incidents worldwide.












