Government employees have been barred from uploading classified documents, official emails, software source code and citizens’ personal information to public AI tools under Pakistan’s National Cybersecurity Handbook 2026-27.
The handbook, issued by the National Cyber Emergency Response Team (PKCERT), provides cybersecurity guidelines for government and public sector employees under the Pakistan Information Security Framework (PISF) 2026.
It warns that putting sensitive information into public AI platforms can lead to data leaks, unauthorized data retention and exposure of classified information to external AI systems.
Employees have been directed to use only AI tools approved by their departments. They must also remove names and other sensitive details from prompts and uploaded files.
Any accidental disclosure of confidential information through an AI tool must be reported immediately to the relevant IT or cybersecurity team.
The guidelines also prohibit employees from sharing passwords, administrative credentials or application programming interface (API) keys with AI tools. Unauthorized AI extensions and plugins cannot be installed on official devices.
PKCERT has further instructed employees to check AI-generated content for accuracy and security before using it for government work.
The handbook allows the use of AI for content creation, analysis and routine tasks, but requires employees to follow security and privacy rules and maintain human oversight.





