Pakistan’s National CERT issued a new advisory warning organizations against the cybersecurity risks of uncontrolled generative AI use. The advisory urged organizations to block sensitive information from leaking to public and unapproved AI platforms. It carries the title “Safe and Secure Use of Generative Artificial Intelligence (GenAI) Tools and Platforms.”
The advisory highlighted “Shadow AI” as a key concern. Specifically, National CERT defined it as unauthorized use of public chatbots, coding assistants, browser extensions, and third-party AI services. According to the agency, this unauthorized adoption exposes sensitive information, intellectual property, credentials, and source code. As a result, organizational data ends up on external platforms without oversight.
Beyond data leakage, National CERT also flagged several technical risks. These include prompt injection attacks, insecure AI-generated code, and compromised third-party AI models. Additionally, the advisory warned about malicious integrations and inaccurate AI outputs. Therefore, the agency called for mandatory human review of all AI-generated code before deployment or publication.
In response to these threats, organizations must now establish a mandatory Generative AI Acceptable Use Policy. This policy should define approved, restricted, and prohibited uses of AI tools. Furthermore, organizations must maintain a centrally vetted registry of approved AI tools, models, plugins, and APIs. Meanwhile, they should restrict access to all unauthorized services.
On the technical side, National CERT recommended extending data loss prevention controls to AI interfaces. Similarly, access monitoring and endpoint security should cover AI platforms. These controls help detect sensitive data submissions and suspicious API activity. The agency also urged alignment with the NIST AI Risk Management Framework and the OWASP Top 10 for LLM Applications.
For incident response, National CERT directed organizations to contain unauthorized access immediately. After that, they should preserve evidence, revoke compromised credentials or API keys, and investigate exposure. Consequently, any incidents involving AI data leaks, prompt injection, or supply chain compromise must go directly to National CERT Pakistan.
