Skip to content

PKCERT to government staff: no classified files or source code in AI tools

The National Cybersecurity Handbook 2026-27 sets rules for using ChatGPT-style tools at work. Strip names, never paste credentials, and use only approved tools.

Searchable EditorialPublished 2 min read
An office computer, as PKCERT issues rules on using AI tools with government data
An office computer, as PKCERT issues rules on using AI tools with government dataPhoto: Steve Parker / Flickr, CC BY 2.0

Pakistan's National Cyber Emergency Response Team (PKCERT) has issued rules for government employees using public artificial intelligence tools, in the National Cybersecurity Handbook 2026-27, built on the Pakistan Information Security Framework (PISF) 2026.

The short version: government staff may use AI tools, but not with government data.

What staff must not put into an AI tool

  • Classified documents
  • Official emails
  • Software source code
  • Citizens' personal information

That last one is the broadest and the most likely to be breached in ordinary work. A clerk pasting a list of applicants into a chatbot to sort it, or an officer asking a model to summarise a complaint file, is handing citizens' data to a system outside government control.

The rules staff must follow

  • Use only AI tools approved by your own department.
  • Remove names and identifiers from prompts and from any file you upload.
  • Never share passwords, administrative credentials or API keys with an AI tool.
  • Do not install unauthorised AI extensions or plugins on official devices.
  • Verify AI-generated content for accuracy and security before using it.
  • Report any accidental disclosure to your departmental IT or cybersecurity team immediately.

Why this is being issued now

The gap the handbook addresses is not malice, it is convenience. Free AI tools are faster than the internal systems most departments run, so staff use them. Anything typed into a consumer AI service leaves the department's network, and in most consumer tiers it may be retained by the provider.

The requirement to strip identifiers before prompting is the one rule that survives contact with real work. It lets an officer get help drafting or summarising without exporting a citizen's CNIC, address or case history.

What it means if you are not a government employee

The same rules are worth borrowing. If you are a freelancer handling client data, an accountant with client returns, or a doctor with patient notes, the exposure is identical and you have no departmental IT team to report to.

Three things to do today:

  1. Check what you have already pasted. Most AI tools keep a chat history you can review and delete.
  2. Turn off training on your data where the tool offers the setting.
  3. Strip identifiers by habit, not by intention. Replace names with "Client A" before you paste, every time.

The handbook contains no stated penalty for a breach, and no specific AI platform is named. It refers to public AI tools generically.

Related: the government is separately moving to set a minimum age for social media. If you want to know which SIMs are registered against your own CNIC, see our CNIC SIM check guide.

Frequently asked questions

What are Pakistani government employees banned from putting into AI tools?
Classified documents, official emails, software source code and citizens' personal information, under the National Cybersecurity Handbook 2026-27 issued by PKCERT. Staff must also never share passwords, administrative credentials or API keys.
Can government staff in Pakistan use ChatGPT at work?
Only tools approved by their own department, and only with names and sensitive identifiers removed from prompts and uploaded files. Unauthorised AI extensions and plugins may not be installed on official devices.
Comments

Sources

Tags:PKCERTcybersecurityartificial intelligencegovernmentdata privacy
Topics:PTA

Reader comments 0

No comments yet. Say something useful.

More in AI