Pakistan issues AI guidelines for civil servants — Dawn
In Pakistan, employees of government institutions and public-sector organizations have been advised not to use personal email inboxes, unapproved devices, commercial cloud services, or public artificial intelligence tools for work involving official or sensitive information. The basic digital security rules are set out in the National Cybersecurity Handbook 2026-27, Dawn reports.
The handbook was issued by Pakistan’s National Cyber Emergency Response Team, PKCERT, and the Ministry of Information Technology and Telecommunication. The document defines basic operational standards for digital security at public-sector institutions. It states that cybersecurity is a shared responsibility, as the actions of every user may affect the confidentiality, integrity, and availability of government information resources.
Restrictions on AI tools
Officials should not enter classified government documents, official emails, software code, or citizens’ personal data into public artificial intelligence platforms. Employees are advised to use only AI tools approved by their agencies and to remove names and sensitive information from prompts or uploaded files.
AI-generated results must be reviewed by people, including for accuracy and potential security implications. The handbook also warns against installing unauthorized AI extensions and plugins, as well as providing such tools with administrative credentials, API keys, or passwords.
More current news is available on the UA.News Telegram channel Telegram.
Official email and devices
Only official email addresses should be used for government correspondence and agency work. Personal accounts, including Gmail and Yahoo, should not be used except in exceptional cases with agency authorization. Forwarding official emails to personal inboxes is also prohibited.
Official addresses should not be used to register on shopping, gaming, or social media websites. Civil servants must work only on authorized government devices, while using a personal device requires prior authorization and compliance with established security requirements. The use of only authorized cloud services and approved applications is also stipulated.
The document calls for the prompt reporting of cyber incidents, including attempted unauthorized access, ransom demands, suspicious emails, unusual deletion or modification of files, and unexplained system behavior.