The Pakistani regulatory stack for AI
پاکستان میں AI کا ضابطہ جاتی ڈھانچہ
40 min read
Three ways to see it
PDPA 2023 (draft form, repeatedly revised) defines personal data, sensitive personal data, lawful bases for processing, data subject rights including access and correction, data protection officer obligations for large processors, cross-border transfer rules, and a National Commission for Personal Data Protection. Read against any AI deployment in Pakistan, PDPA is the data feedstock law. No AI runs without data; no data is touched legally without PDPA compliance once it passes.
Way one to read the stack: by domain. PECA covers crime: defamation, doxxing, unauthorised access, electronic fraud. PDPA covers data: collection, processing, retention, transfer. The draft AI Policy covers governance, capacity, ecosystem, and sectoral pilots. SBP covers banking, SECP covers capital markets and insurance, NEPRA covers energy, PEMRA covers broadcasting, PTA covers telecoms. Any Pakistani AI deployment of meaningful scale touches at least three of these. Mapping early prevents trouble.
Way two: by enforcement reality. PECA is enforced, with thousands of FIRs, sometimes controversially. PDPA, once passed, will create a new enforcement authority. The AI Policy is policy, not law, but ties to government procurement. Sectoral circulars are enforced by the relevant regulator with the usual bank inspection or licence renewal teeth. A Pakistani AI vendor cannot read just the bedtime story version of the regulations; they have to ask, for each rule, what real-world enforcement attaches.
Quick check
Quick check: what makes modern AI different from a rule-based program?
The why-tree
Why-tree level one: why a stack, not a single law? Because Pakistan never passes horizontal technology laws. Telecoms, banking, broadcasting all evolved as separate regulators. AI is being layered on top in the same pattern.
Try this with Claude
AI-edge prompt to try: 'You are a Pakistani technology lawyer. Read my one-paragraph AI project description and produce a regulatory map covering PECA 2016, draft PDPA 2023, draft AI Policy 2025, and any sectoral SBP, SECP, NEPRA, PEMRA, PTA touchpoints. Flag the three biggest risks I am most likely overlooking.' Treat the output as a structured starting point for a real legal review.
Sources
Sources and further reading. Prevention of Electronic Crimes Act (PECA) 2016 and 2022 amendments. Draft Personal Data Protection Act 2023, Ministry of IT and Telecommunication. Draft National AI Policy 2025, MoITT. State Bank of Pakistan, prudential regulations and risk management guidelines. SECP, guidelines on use of technology in capital markets. PTA, regulatory updates on AI and OTT. UNESCO Pakistan country profile. Asian Development Bank, Digital Pakistan reports.