The government just officially barred its employees from uploading classified documents to public artificial intelligence (AI) tools. Consequently, this decisive move aims to mitigate the growing risks of data leaks associated with sharing sensitive information on open platforms.
Strict Rules Regarding the Use of Public AI Tools
The National CERT (PKCERT) introduced these restrictions through the newly issued National Cyber Security Handbook 2026-27. This document effectively establishes the principles of the Pakistan Information Security Framework 2026.
Under these new guidelines, officials cannot use public AI platforms to process official emails or analyze software source code. Furthermore, the framework strictly prohibits uploading the personal data of citizens to any public AI tool. According to the National CERT, feeding sensitive information into these open platforms creates a severe risk of data leakage. Therefore, the government directed all officials to use only department-approved AI tools for their daily workflows.
Mandatory Data Sanitization & Security Protocols
The handbook also lays down strict operational protocols for safe AI usage. Before using any AI prompt, officials must proactively remove all names and sensitive details from their files. If an accidental disclosure of confidential information occurs, employees must report the incident to the cybersecurity team immediately.
Additionally, the government has explicitly warned its staff to protect system access. Government employees must never share passwords, administrative login details, or API keys with AI tools.
Human Oversight & Approved Extensions Only
The security restrictions extend directly to software add-ons. The new guidelines officially ban the installation of unapproved AI extensions and plug-ins on all government-issued devices.
Moreover, officials cannot blindly trust automated outputs. Any AI-generated content intended for government work requires thorough vetting for both accuracy and security. Ultimately, the National CERT emphasized that no AI-generated material can be used in official matters without direct human oversight. Moving forward, the government’s integration of AI will remain strictly subject to ongoing security, privacy, and supervision requirements.
