A first framework, narrowly scoped
On June 26, 2026, Pakistan's Ministry of Information Technology and Telecommunication released the draft National Data Governance Policy 2026 for public consultation, opening a window for feedback that closed on July 10 (Dawn). It is the country's first attempt to write a unified rulebook for how the state itself builds, deploys and audits AI systems — not a general AI law for the private sector, but a policy scoped to federal ministries, regulators, statutory corporations and other public bodies (Digital Pakistan). The Pakistan Digital Authority (PDA), created under the Digital Nation Pakistan Act 2025, will administer it, and once notified, agencies get twelve months to align their systems and contracts with it (Digital Pakistan).
The substance is familiar to anyone who has read the EU AI Act or Canada's directive on automated decision-making. Agencies deploying AI for "legally significant decisions" must ensure transparency, explainability and meaningful human oversight; citizens gain a right to demand human review of automated decisions; the PDA will maintain a public registry of automated decision systems; and compliance is checked through annual audits and a National Data Maturity Index that scores institutions on governance and openness (Digital Pakistan). The draft also sets specific guardrails on government use of generative AI — controls against factual inaccuracy, IP infringement and data leakage (Arab News).
The steelman: this is proportionate, not precautionary overreach
The case for these rules is genuinely strong, and it deserves to be stated plainly before it's contested. Generative models hallucinate, and when a government agency uses one to help draft a benefits determination, a procurement decision or a regulatory finding, the citizen on the receiving end has a legitimate claim to know a machine was involved and to contest the outcome. Requiring human sign-off on legally significant automated decisions, publishing a registry of what systems exist, and auditing agencies against a maturity index are not exotic asks — they are close to what OECD governments and the EU AI Act's public-sector provisions already require. Crucially, the policy's scope discipline is itself the right design choice: it regulates the government's own procurement and use of AI, not the private developer ecosystem or the open-weight models circulating outside the state. That is a narrower, more defensible starting point than economy-wide AI statutes that try to regulate model-builders before anyone has identified concrete harms.
Where the friction actually bites
The complication is that this narrowly-scoped policy does not exist in isolation — it sits directly downstream of Pakistan's National AI Policy, approved and shared with the public in August 2025, which commits the state to building "sovereign" AI capacity through a $1 billion investment program, a National AI Fund permanently financed by 30% of the R&D fund managed by Ignite, and a network of AI Centers of Excellence (Arab News). The Islamabad AI Declaration, adopted February 20, 2026, reaffirmed that sovereign, capability-driven posture and directed the PDA to build out a national AI Supervisory Framework — the same PDA now administering the Data Governance Policy (GlobeNewswire).
The problem is compute, not ambition. Pakistan's entire AI-optimized infrastructure currently runs on roughly 3,000 GPUs in a single Karachi data center, with about 2,000 megawatts of power allocated for future expansion — nowhere near the scale required to train frontier models domestically (Tech Policy Press). That is precisely why serious analysts of the sovereignty push argue Pakistan's realistic path is not training trillion-parameter models from scratch but distilling and locally hosting open-weight systems — compressing existing open models into smaller, cheaper deployments that keep sensitive data inside the country without needing hyperscale compute (Tech Policy Press). Those are exactly the systems government agencies will reach for first, because they are the only AI Pakistan can currently afford to run domestically — and they are exactly what the new registration, explainability and audit regime will apply to.
Where the government should draw the line
None of this makes the Data Governance Policy wrong. It makes implementation the place where the policy will either stay proportionate or start undermining the very sovereignty project it serves. The risk is not the registry or the human-review requirement in principle — it's how broadly "legally significant decision" and "high-risk system" get defined once the PDA writes the supporting instruments the draft promises. A distilled open-weight model doing back-office triage or document summarization is not the same risk category as one adjudicating a benefits claim, and a maturity-index audit regime built for the latter will simply slow adoption of the former if the tiers aren't kept distinct. Given that Islamabad is already resource-constrained on compute, adding compliance friction to the cheapest, fastest path to functioning government AI — open, distilled models — would tax the strategy it's meant to legitimize.
The fix is not to weaken oversight of decisions that actually affect citizens' legal interests. It's for the PDA, when it finalizes standards under this policy, to write an explicit risk tier that exempts low-stakes automation from the full registration-and-audit track, reserving explainability and human-review mandates for systems that make or materially inform decisions with legal effect. Pakistan has a rare chance to get sequencing right: build the sovereign AI base first with open models moving fast, then tighten oversight as deployment scales into consequential government functions. Flip that order, and the compliance regime becomes the bottleneck the National AI Policy was designed to route around.