Pakistan’s National Cyber Emergency Response Team has issued a Cybersecurity Handbook for 2026–27 that tells government employees and public-sector organisations not to place sensitive official information in public AI systems.
The guidance says classified documents, official emails, source code and citizens’ personally identifiable information should not be entered into public AI platforms. Staff are advised to use AI tools authorised by their departments, remove sensitive information from prompts and have AI-generated output reviewed by humans.
The handbook also addresses personal email accounts, unapproved devices and commercial cloud services. National CERT says the guidance translates existing Pakistani information-security rules and policies into practical standards for public-sector users.
