
Pakistan bans govt staff from using public AI tools for classified data, emails, code, and citizen info under new cyber handbook.
Pakistan has prohibited government employees from uploading classified documents and sensitive information to public artificial intelligence (AI) tools under new cybersecurity rules. The National Cyber Emergency Response Team (National CERT) issued the National Cyber Security Handbook 2026-27, which sets out strict guidelines for AI use in government affairs.
The handbook, framed under the Pakistan Information Security Framework 2026, bars officials from sharing government emails, software source code, and citizens’ personal data on public AI platforms. According to the National CERT, feeding sensitive information into such tools “carries the risk of data leaks and unauthorised use.” Officials are now required to use only AI tools and platforms approved by their respective departments.
The directive instructs employees to strip names and other sensitive details from AI prompts and files before submission. Any accidental disclosure of confidential information must be reported immediately to the relevant IT or cybersecurity team, the handbook states. It also warns against installing unapproved AI extensions or sharing administrative credentials, API keys, or passwords with AI systems.
“The handbook addresses the risks associated with artificial intelligence, marking it as an expanding area of concern within cybersecurity,” a government document noted. Officials are further told that AI-generated outputs must undergo human review for accuracy and security implications before use in official work.
