Pakistan’s National CERT sets eight security measures for using generative AI: policy, an approved-tools registry, DLP and audit logs
EditorialBy TrustList Editorial
Pakistan’s National CERT published Advisory 18 on 1 October 2026: eight measures for safe use of generative AI, including an acceptable-use policy, no sensitive data in public AI tools, a registry of approved tools, human review of AI code and DLP.
- Pakistan
- Islamabad, Pakistan
- Cybersecurity
- Artificial Intelligence - AI
- +2 more
About Pakistan’s National CERT sets eight security measures for using generative AI: policy, an approved-tools registry, DLP and audit logs
Pakistan’s National CERT sets eight security measures for using generative AI: policy, an approved-tools registry, DLP and audit logs
2 October 2026 — Pakistan's National Computer Emergency Response Team (PKCERT) published Advisory No. 18, "Safe and Secure Use of Generative Artificial Intelligence (GenAI) Tools and Platforms", on 1 October 2026. It lists eight measures it calls mandatory for organisations, and asks for incidents involving AI tools to be reported to the National CERT.
Not yet independently verified. This rests on PKCERT’s own advisory; its date comes from the document’s code and the file’s publication time, not a printed date line. The advisory states no compliance deadline, and no independent report was found. We will update this when it can be confirmed, and remove this note.
The eight measures
- An enforced acceptable-use policy for generative AI.
- No classified, personal, credential or source-code data entered into public AI tools.
- A vetted registry of approved AI tools, models, plug-ins and APIs.
- Human review of AI-generated code before it is used.
- Data-loss prevention and monitoring extended to AI interfaces.
- Alignment with recognised frameworks: the NIST AI Risk Management Framework and the OWASP Top 10 for LLM applications.
- Regular staff training on AI risks.
- Audit trails of AI use.
Incidents such as data exposure through AI tools, prompt injection or a compromised AI supply chain are to be reported to the National CERT.
Why it matters
"Shadow AI", staff pasting customer data, contracts or source code into public chatbots, is now one of the most common ways company data leaves an organisation. An official national baseline gives security teams in Pakistan a reference to point to, and gives buyers a checklist for AI tools they are asked to approve. It also matters to foreign vendors selling AI products to Pakistani banks, telecoms operators and government bodies, which tend to follow National CERT advisories closely.
What to do
- Map your current controls against the eight measures and note the gaps.
- Publish an approved-tools list and block or monitor unapproved AI services at the proxy or browser level.
- Extend DLP rules to AI chat interfaces and APIs, especially for source code and personal data.
- Ask AI vendors where prompts and outputs are stored, whether they are used for training, and what logs you can export for your audit trail.
Sources
Categories & features
- Pakistan
- Islamabad, Pakistan
- Cybersecurity
- Artificial Intelligence - AI
- Data Security
- Regulatory Compliance
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More PakistanThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.