“`html
body {
font-family: Arial, sans-serif;
line-height: 1.7;
color: #222;
background: #ffffff;
margin: 0;
padding: 0;
}
article {
max-width: 900px;
margin: 40px auto;
padding: 20px;
}
h1 {
color: #12355b;
font-size: 38px;
line-height: 1.2;
}
h2 {
color: #0b6b63;
margin-top: 35px;
}
h3 {
color: #12355b;
margin-top: 25px;
}
p {
font-size: 17px;
}
ul {
padding-left: 25px;
}
li {
margin-bottom: 10px;
}
.summary {
background: #f1f8f7;
border-left: 5px solid #0b6b63;
padding: 20px;
margin: 25px 0;
}
.highlight {
background: #f7f9fc;
padding: 18px;
border-radius: 8px;
margin: 15px 0;
}
table {
width: 100%;
border-collapse: collapse;
margin: 25px 0;
}
th, td {
border: 1px solid #ddd;
padding: 12px;
text-align: left;
vertical-align: top;
}
th {
background: #12355b;
color: white;
}
.cta {
background: #12355b;
color: white;
padding: 25px;
border-radius: 8px;
margin-top: 35px;
}
.cta a {
color: white;
font-weight: bold;
}
AI & Technology Law in Pakistan: Future Regulations & Risks
Pakistan’s AI and technology law is evolving through the
National AI Policy 2025, draft data-governance reforms,
PECA amendments and provincial initiatives. While there is
no comprehensive standalone AI Act yet, individuals and
businesses should prepare for stronger regulation of AI,
privacy, deepfakes, cybersecurity and automated decision-making.
Introduction
Artificial Intelligence (AI) and emerging technologies are rapidly
transforming business, governance, media, and daily life in Pakistan.
From AI-powered public services and deepfakes to data-driven
decision-making, the legal landscape is evolving quickly.
Pakistan does not yet have a comprehensive standalone AI Act.
However, the National AI Policy 2025, the draft National Data
Governance Policy 2026, PECA amendments and provincial initiatives
are helping shape the legal framework for emerging technologies.
This guide explains the current legal framework, future regulatory
directions, major risks and practical compliance steps for individuals,
businesses and institutions.
Current Legal Framework for AI and Technology
Pakistan currently relies on a combination of existing laws and
emerging policy instruments rather than one comprehensive AI statute.
-
Prevention of Electronic Crimes Act (PECA) 2016:
Covers various cyber offences, including certain forms of false
information, dignity offences, online impersonation and
deepfake-related harms. -
National AI Policy 2025:
Pakistan’s national roadmap for AI development, skills,
infrastructure, secure and trustworthy AI, innovation and
international cooperation. -
National Data Governance Policy 2026 (Draft):
Addresses government data, privacy, cross-border transfers,
AI use in public services and human oversight of significant
automated decisions. -
Provincial Initiatives:
Punjab has proposed legislation addressing protection of
performers’ voices, faces and likenesses from unauthorised
AI cloning and deepfakes. -
Other Relevant Laws:
Copyright Ordinance 1962, Electronic Transactions Ordinance 2002,
provincial consumer protection laws, contract principles and
tort law may also become relevant to AI-related disputes.
National AI Policy 2025
The National AI Policy 2025 establishes a roadmap for the development
and adoption of artificial intelligence in Pakistan. It focuses on
innovation, AI skills, infrastructure, secure and trustworthy AI,
regulatory sandboxes and institutional implementation structures.
Detailed binding regulations may develop as the policy moves toward
implementation.
Data Governance and Privacy
Data governance is becoming an important part of Pakistan’s emerging
technology framework. The draft National Data Governance Policy 2026
proposes stronger safeguards relating to privacy, consent, breach
notifications and human oversight.
Significant automated decisions affecting citizens may increasingly
require transparency and meaningful human involvement.
Deepfakes and Digital Identity Protection
AI-generated images, videos and cloned voices can create serious legal
problems involving privacy, dignity, harassment, misinformation and
identity misuse.
PECA provides legal tools against certain forms of harmful digital
content, while emerging provincial initiatives seek additional
protection for performers’ voices, faces and digital likenesses.
Judicial Guidelines on AI
Emerging national guidelines for the use of AI in judicial
institutions emphasise human oversight, transparency and ethical use.
AI may assist judicial institutions, but independent judicial
decision-making remains a human responsibility.
Major Legal and Practical Risks
| Risk Area | Description | Potential Consequences |
|---|---|---|
| Deepfakes & Synthetic Media | Unauthorised voice or face cloning, fake videos and AI-generated content. | PECA offences, defamation, harassment claims and emerging digital-identity penalties. |
| Data Privacy | Collection or use of personal data for AI systems without clear rules. | Potential future liability, reputational damage and contractual risks. |
| Automated Decision-Making | AI used in hiring, credit, benefits or policing without adequate human oversight. | Potential constitutional, equality and due-process concerns. |
| Intellectual Property | Uncertainty regarding AI-generated works and training data. | Copyright, ownership, authorship and licensing disputes. |
| AI Liability | AI systems causing financial or physical harm. | Possible contractual, negligence or consumer protection claims. |
| Cybersecurity & Misinformation | AI-powered scams, fake information and digital security threats. | PECA enforcement, regulatory action and civil claims. |
Practical Guidance for Individuals
- Be careful when sharing biometric information, voice samples and personal images.
- Report harmful deepfakes and AI-generated harassment through appropriate cybercrime channels.
- Keep informed about developing data protection and privacy rights.
Practical Guidance for Businesses and Developers
- Conduct risk assessments before deploying high-impact AI systems.
- Maintain meaningful human oversight over important decisions.
- Obtain appropriate consent and contractual permissions for voices and likenesses.
- Monitor developments under the National AI Policy and data-governance framework.
- Prepare for possible future AI registries, transparency requirements and impact assessments.
Looking Ahead
Pakistan is gradually moving from a largely reactive approach,
relying on PECA and general legal principles, toward more structured
AI and data governance.
Important areas to watch include the development of comprehensive
personal data protection legislation, binding AI regulations,
deepfake-specific protections and sector-specific standards for
areas such as finance, healthcare, elections and public services.
Frequently Asked Questions
Does Pakistan have a specific AI law?
Not yet. The National AI Policy 2025 provides a national roadmap,
while comprehensive binding AI legislation is still developing.
Existing laws such as PECA apply to many AI-related harms.
Are deepfakes illegal in Pakistan?
Certain deepfake-related conduct can attract legal consequences,
particularly where it involves dignity, harassment or false
information. Additional digital-identity protections are also
emerging.
Is there a comprehensive data protection law?
A comprehensive Personal Data Protection Act has not yet been fully
enacted. Data governance policies and proposed legislation continue
to develop.
Can AI be used in court decisions?
AI may assist judicial institutions, but final judicial decisions
must remain subject to independent human decision-making.
What should companies do before deploying AI?
Companies should assess risks, maintain human oversight, obtain
appropriate consent, document AI processes and monitor regulatory
developments.
Who deals with AI-related cyber offences?
The National Cyber Crime Investigation Agency (NCCIA) is identified
in the current framework as the primary agency for relevant
cybercrime enforcement under PECA, alongside relevant authorities
where applicable.
Will AI regulation become stricter in Pakistan?
Current developments indicate a move toward stronger rules concerning
data governance, high-risk AI, transparency, cybersecurity and
synthetic media.
Conclusion
AI and technology law in Pakistan is entering an important period of
development. Although comprehensive dedicated legislation is still
emerging, the National AI Policy 2025, data governance reforms,
PECA framework and provincial initiatives already have significant
implications for citizens and businesses.
Understanding these developments and preparing for stronger future
regulation can help individuals and organisations use AI responsibly
while reducing legal and compliance risks.
Need Legal Guidance?
Developing or deploying AI systems, facing deepfake-related
issues, or dealing with technology compliance and data risks
in Pakistan?
Contact the technology and cyber law team at
Justify.pk
for practical legal guidance.
“`



