Pakistan Bars Government Staff From Sharing Sensitive Data With Public AI Tools

Pakistan has introduced new cybersecurity guidelines warning government employees against sharing sensitive official information with publicly available artificial intelligence tools.

Under the National Cybersecurity Handbook 2026–2027, government and public-sector personnel are prohibited from uploading classified documents, official emails, software source code and citizens’ personal information to public AI platforms.

The handbook has been issued by the National Cyber Emergency Response Team (PKCERT) as a practical cybersecurity guide for employees, officers and technical personnel working across federal and provincial governments as well as public-sector organizations.

The guidelines are based on the Pakistan Information Security Framework (PISF) 2026, along with other applicable cybersecurity policies, laws and regulations. PKCERT says the handbook is intended to establish consistent security practices across government institutions.

Officials have been warned that entering confidential information into public AI systems can create cybersecurity and privacy risks. Such information could potentially be exposed through data leaks, unauthorized retention or external AI processing and training systems.

Government employees have instead been instructed to use only AI tools and platforms approved by their respective departments. The guidelines also call for sensitive details to be removed from prompts and uploaded files before AI systems are used for official work.

The restrictions extend beyond documents and personal information. Government personnel have also been told not to share passwords, administrative credentials or application programming interface keys with AI tools.

Officials are additionally prohibited from installing unauthorized AI extensions or plugins on government devices, according to the reported guidelines.

At the same time, the handbook does not prohibit the use of artificial intelligence altogether. AI tools can still be used for activities such as content generation, analysis and routine tasks, provided that appropriate security safeguards and privacy requirements are followed.

PKCERT has also emphasized human oversight by instructing officials to review AI-generated material for accuracy and security before incorporating it into government work.

The broader handbook covers several areas of cybersecurity, including data and asset protection, access and network security, vulnerability management, incident response, business continuity and disaster recovery.

The new guidance reflects the growing challenge governments face as AI tools become increasingly common in everyday professional workflows. While such platforms can assist with drafting, analysis and other routine tasks, using them with confidential government information can introduce additional security risks.

PKCERT has described cybersecurity as a shared responsibility and said the handbook is intended to help government personnel protect the confidentiality, integrity and availability of national information assets.

For government employees, the central message is that AI can be used as a workplace tool, but sensitive government data, credentials and personal information must remain protected and should not be entered into unapproved public AI systems.