Reporting snapshot · 19 September 2026. The National Cyber Emergency Response Team's (National CERT) National Cybersecurity Handbook 2026-27, which bars government employees from feeding classified and other sensitive data into public AI tools, was reported by Pakistani media on 18-19 September. The handbook is an operational guidance document rather than a statute, and the mechanism for enforcing its prohibitions on individual employees had not been spelled out when this article was published.
What happened
Pakistan’s National CERT has issued a cybersecurity handbook for 2026-27 that bars government employees from uploading classified documents and other sensitive information to public artificial intelligence (AI) tools, directing them instead to use only AI platforms approved by their departments. The guidance, carried in the National Cybersecurity Handbook issued under the Pakistan Information Security Framework (PISF) 2026, was reported by The Express Tribune on 19 September and by Pakistan Today’s Profit desk and Dawn on 18 September.
The handbook tells officials that entering sensitive classified government data into public AI platforms poses “severe risks” of data leakage and unauthorised retention by the AI tools themselves. Beyond classified documents, it prohibits the sharing of official government emails, software source code and citizens’ personal information through public AI platforms. Employees are instructed to strip names and other sensitive details from prompts and files before using such tools, and to report any accidental disclosure immediately to their departmental IT or cybersecurity team.
What the AI rules require
The handbook does not ban AI outright. It acknowledges that AI tools can help generate content, analyse information, automate routine tasks and support decision-making, but it makes clear that their use “must be balanced with appropriate security, privacy, and human oversight”. Officials may use only AI tools and platforms that their departments have approved. AI-generated output used for official work must be reviewed by a human for accuracy and security before it is acted on, and must not be used without that oversight.
The guidance also prohibits sharing passwords, administrative login credentials and API keys with AI tools, and bars installing unapproved AI extensions or plugins on government devices. The handbook describes the use of AI in government affairs as governed by three principles — security, privacy and human oversight — and warns that classified national data submitted to external AI systems could end up being retained or used by those services.
The wider handbook
The 34-page document, prepared by the National CERT under the Ministry of IT and Telecommunications, is described as a baseline operational standard for digital security across public-sector entities. It translates requirements from the Pakistan Information Security Framework 2026, the National Cyber Security Policy 2021 and the CERT Rules 2023 into practical instructions for federal and provincial employees, officers and technical personnel.
It is organised into eight domains: secure use of official email, device security, password security, data security, internet security, removable media, secure remote access and incident response. The email guidance requires officials to use government email accounts for official correspondence, to avoid forwarding official emails to personal inboxes, and not to register official addresses on shopping, gaming or social-media sites. Only authorised government devices are to be used for official work, and access to sensitive applications such as e-Office and classified government portals from personal devices is barred.
The handbook also cautions against “shadow IT” — hardware, software or digital tools used for official work without prior approval — and requires officials to use only sanctioned cloud services and approved applications, warning that uploading sensitive government information to personal cloud accounts or unvetted AI tools can lead to data leakage and unauthorised retention. It advises keeping personal and official social-media accounts separate and warns that publicly available information can be combined by attackers into detailed profiles of potential targets.
Incident reporting and enforcement
The incident-response domain is the most operationally prescriptive. Officials suspecting a compromise are told to isolate the affected machine by disconnecting its network cable or turning off Wi-Fi, but explicitly not to power the device off or restart it, since that can destroy evidence needed for forensic investigation. Reporting is mandatory rather than discretionary: under the CERT Rules 2023, organisations must report cybersecurity incidents to the National CERT through approved channels, either directly or via organisational, provincial or sectoral CERTs. The handbook warns that delayed disclosure gives an intrusion more time to spread before anyone outside the affected office knows it happened.
For serious incidents, National CERT teams may conduct investigations and digital forensics. Affected organisations are required to provide access to relevant infrastructure and logs, preserve digital evidence and implement containment and remediation measures, and are warned against altering or overwriting logs, firewall records or memory dumps before forensic collection. Networks that have been compromised should not be reconnected until clearance is provided.
Why the AI guidance matters now
The AI section is new relative to earlier iterations of Pakistani government cybersecurity guidance, and it responds to a genuine and growing risk: employees pasting sensitive material into consumer chatbots and other public AI services as a shortcut. The handbook’s authors appear to be trying to write policy fast enough to keep pace with how government work is actually being done, rather than waiting for a high-profile leak to force the issue. The guidance is also a marker of Pakistan’s wider move to formalise cyber governance, following the cabinet’s approval of the Pakistan Information Security Framework 2026 in August, the framework under which the handbook operates.
The rules sit alongside other steps Pakistan has taken this year to shape its digital and AI environment, including the National CERT’s advisory in March warning that hostile actors could exploit supply chains to target critical infrastructure, and the registration framework for cybersecurity consultants introduced in April under PISF.
What is still uncertain
The most important open question is enforcement. The handbook is guidance — a set of baseline practices for employees — rather than a law, and neither the handbook nor the media reports set out a specific disciplinary or legal consequence for an individual employee who feeds classified data into a public AI tool. The CERT Rules provide the machinery for organisational reporting, but how aggressively departments audit employee use of AI tools, and what happens in practice to a civil servant who breaches the rules, remains to be seen.
It is also unclear how far the guidance reaches in practice. The handbook is directed at federal and provincial government staff and public-sector organisations, but it does not, by itself, bind private companies or citizens. The document itself concedes that following it does not guarantee complete immunity from sophisticated cyber threats, and it calls for continuous monitoring, updating and enforcement of technical controls by departmental IT teams independent of any single employee’s conduct.
Whether the handbook changes behaviour will depend on whether departments treat it as a living standard with monitoring behind it, or as paperwork that sits unread. The threat it is designed to address — an employee copying a sensitive file into a public AI tool because it was faster than asking permission — is a human one, and the guidance is only as strong as the training and supervision that back it.
Sources & reporting notes
This is a synthesis of published material, not eyewitness reporting. Sources were reviewed on 19 September 2026.
- National Cyber Emergency Response Team — National Cybersecurity Handbook 2026-27 (PDF)Primary government document · Sets out the AI-tool prohibitions, the eight operational domains, the PISF 2026 framework basis and the CERT Rules 2023 incident-reporting requirements.
- The Express Tribune — Public servants told not to feed sensitive data into AI19 September 2026 · Independent report on the handbook's ban on classified documents, official emails, source code and citizens' personal information in public AI tools, and the approved-tools rule.
- Profit by Pakistan Today — Govt cybersecurity body warns officials against personal email, public AI tools18 September 2026 · Independent report on the handbook's email, device, cloud and AI guidance, the eight domains, the CERT Rules reporting requirement and the forensic-incident steps.
- Dawn — Guidelines issued for officials to prevent cyberattack18 September 2026 · Independent report on the National Cybersecurity Handbook 2026-27 and its warnings against personal email, unapproved devices, commercial cloud services and public AI tools for official information.


