Pakistan - AI Regulation (2024)

Regulation of Artificial Intelligence Bill, 2024

Pakistan

RAI-PK-NA-ARTIN20-2024
Proposed(Officially filed for action)
BillGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

The Regulation of Artificial Intelligence Bill, 2024 (introduced in the Senate by Senator Dr. Afnan Ullah Khan) proposes a national regulatory framework for the development, deployment and oversight of AI in Pakistan. Key measures include creation of an Artificial Intelligence Commission, registration and oversight duties, obligations on transparency, data governance alignment with data-protection initiatives, incident reporting, and significant administrative penalties for non-compliance.

Summary

The Regulation of Artificial Intelligence Bill, 2024 is a private members' bill introduced in the Senate of Pakistan in 2024 with the stated objective of creating a statutory framework to govern the development, deployment and use of artificial intelligence technologies in Pakistan. The bill proposes the establishment of an Artificial Intelligence Commission (AIC) as the primary regulator with authority to register AI systems and providers, set standards, maintain a complaints and enforcement regime, and manage a dedicated AI Regulation Fund to support the commission’s activities. The draft addresses transparency requirements for AI systems (including documentation of datasets, model provenance and human oversight measures), data-use restrictions, obligations for risk assessment and mitigation, reporting of security incidents and breaches, and special controls for systems deemed to be high-risk or sensitive.

Under the bill’s framework, developers and deployers would be required to conduct and document algorithmic impact assessments, implement human-in-the-loop controls where appropriate, comply with data protection obligations and ensure explainability and auditability of outputs in defined contexts. The bill also contemplates conformity assessment and possible certification for certain high-risk categories; it creates administrative powers for inspections and market surveillance and sets out an enforcement regime that includes very large fines (reported in draft summaries and media coverage) and potential sanctions up to suspension of services. In the draft discussed in committee sessions, appeals against commission decisions are to be available to courts including the High Court.

The bill recognizes interplay with existing and proposed national instruments such as Pakistan’s Personal Data Protection Bill (and the Ministry of IT & Telecom’s National AI Policy process) and instructs coordination with other sectoral regulators (e.g., telecom and financial regulators) for domain-specific AI risks. During committee review the Ministry of IT & Telecom advised a cautious approach, noting the need to develop an enabling ecosystem and national policy alongside or prior to creating a standalone regulator. Media reports from late 2024 and 2025 summarise committee deliberations, the proposed composition of the commission, and potential punitive measures. As of the time of retrieval, the bill remains pending with the Senate Standing Committee on Information Technology and Telecommunication for clause-by-clause consideration and stakeholder consultation.

Key regulatory themes in the bill include governance and oversight (creation of a regulator, inter-agency coordination), risk management (impact assessment and classification of high-risk systems), safety testing and conformity assessment (mandatory testing and documentation), transparency and disclosure (model cards, dataset provenance and human oversight), data protection and privacy alignment with national data law, protections for fundamental rights (prevention of discriminatory outcomes and manipulative uses), cybersecurity and model security requirements, accountability and documentation obligations (audit trails, recordkeeping), market surveillance and enforcement including heavy administrative fines, and mechanisms for international cooperation and alignment with global standards. The proposal is intentionally broad to capture public- and private-sector uses and aims to regulate systems that are developed, deployed or used within Pakistan or that materially affect Pakistani residents. The bill’s final scope, thresholds, detailed obligations and penalty structure remained subject to change through committee review and stakeholder consultation.

Full article

Read full text ↗

Overview

The Regulation of Artificial Intelligence Bill, 2024 was introduced in Pakistan’s Senate in September 2024. It seeks to create an institutional framework centred on an Artificial Intelligence Commission responsible for registration, oversight, monitoring and enforcement of AI-related activity in Pakistan. The Senate bill summary notes receipt of notice on 9 August 2024 and introduction and reference to committee on 9 September 2024. Discussion in the Senate Standing Committee on IT & Telecom and reporting by national press indicate the bill advances principles familiar from international AI governance approaches — risk classification, transparency obligations, human oversight and heavy administrative penalties for breaches. For the official summary, see the Senate Bill Summary (Regulation of Artificial Intelligence Bill, 2024) and for ministry-level policy context consult the Ministry of Information Technology & Telecommunication (MoITT) site.

Definitions

The bill defines foundational and operational terms to delimit coverage and obligations: "artificial intelligence" (broadly covering software systems using statistical, machine learning, or other algorithmic approaches to make or assist decisions), "AI system provider" (entities that develop, train, produce, distribute or market AI systems), "deployers" or "operators" (bodies that place systems into operation), "high-risk system" (systems whose failure or misuse could significantly harm individuals or public interest), "data controller/processor" (for alignment with data protection frameworks), and the "Artificial Intelligence Commission" (the proposed regulator). Definitions also address "automated decision-making", "model provenance", "dataset provenance" and "human oversight" to create enforceable duty constructs in the clauses that follow.

Governance and Institutional Framework

The legislative text proposes creation of an Artificial Intelligence Commission (AIC) with a chairperson and members (media accounts indicate a chair plus four members in early drafts) to: (a) register AI providers and relevant systems; (b) set technical standards and guidelines; (c) maintain an AI Regulation Fund to finance operations; (d) adjudicate complaints and initiate enforcement action; and (e) coordinate with sectoral regulators such as the Pakistan Telecommunication Authority and financial regulators. The commission is empowered to require conformity assessment, to order audits and inspections, and to issue administrative sanctions. Interim governance responsibilities are expected to involve the Ministry of IT & Telecom and other ministries for cross-cutting policy. See the Senate bill summary at Senate Bill Summary and MoITT policy materials at MoITT for related institutional developments.

Key Focus Areas

The bill’s substantive obligations cluster around: risk management and mandatory algorithmic impact assessments for systems that may materially affect rights or safety; transparency and documentation (including model cards, dataset documentation and public notices for automated decision-making); data protection alignment (mandating compliance with national data-protection law and data minimisation); human oversight and redress (mechanisms for human review of high-impact decisions and channels to lodge complaints with the commission); safety testing, conformity assessment and certification for high-risk systems; cybersecurity and model-security requirements (secure training data, access controls and incident response); sectoral coordination for healthcare, finance, telecommunications and public services to handle domain-specific risks; market surveillance and post-deployment monitoring; and enforcement measures including fines and remedial orders. These focus areas mirror global AI-regulatory trends while being tuned to Pakistan’s institutional landscape as reported by national press and Senate proceedings (Senate Bill Summary, ProPakistani summary).

Implementation Framework

Implementation envisages phased obligations: an initial registration roll-out, development of rules and standards by the AIC, creation of a certification/conformity pathway for high-risk systems (including third-party testing), and development of sectoral memoranda of understanding with other regulators. The bill describes an AI Regulation Fund to support commissioning of audits and technical capability building. Operational implementation depends on delegated rule-making powers, published compliance guidances and capacity-building by MoITT and the AIC. The Ministry’s parallel national AI policy consultation process is expected to support harmonised implementation across government and industry. See MoITT and media coverage of committee deliberations for implementation commentary.

Monitoring and Evaluation

The bill creates reporting obligations for deployers and a complaints mechanism allowing individuals to report harms to the AIC. Monitoring tools include required record-keeping, periodic compliance reports, and incident notifications for cybersecurity compromises or algorithmic harms. The Commission will have inspection and market-surveillance functions and is expected to publish periodic compliance reports and enforcement statistics to measure effectiveness. Independent evaluation is contemplated via mandated impact reviews and possible collaboration with academic and civil-society stakeholders to audit outcomes in sensitive domains.

Penalties, Liability, and Appeals

The draft contemplates administrative fines (media reports reference ranges up to PKR 1.5–2.5 billion for severe breaches in early summaries), suspension or blocking of non-compliant services, and referral for criminal investigation where offences involve classified or sensitive data misuse. The bill provides for administrative proceedings by the Commission with regulated parties’ right of appeal to the High Court or other judicial fora as specified. Penalty quantum, procedural safeguards, and appeal timelines remain subject to committee modification during clause-by-clause review (ProPakistani, Dawn reporting).

Relationship to Other Instruments

The bill is intended to operate alongside Pakistan’s emerging data-protection and digital-governance instruments, including the proposed Personal Data Protection Bill and the Ministry of IT & Telecom’s national AI policy. It mandates coordination with sectoral regulators (telecom, financial, health regulators) to avoid regulatory gaps and overlapping jurisdiction. The draft instructs alignment of confidentiality, national security and privacy safeguards with existing laws such as PECA and any enacted data-protection statute.

International Alignment

The draft bill draws on international regulatory practice (risk-based approaches, transparency obligations and certification regimes). It signals the government’s intent to align with emerging global standards while preserving national priorities — for example, data localisation for sensitive datasets and coordination with foreign regulators for cross-border AI supply chains. The bill’s architecture mirrors reforms in other jurisdictions prioritising human oversight, safety testing and conformity assessment for high-risk AI applications.

Implementation Timeline

MilestoneDateReference
Notice of Bill2024-08-09Senate Bill Summary
Introduction in Senate & reference to Committee2024-09-09Senate Bill Summary
Senate IT Committee deliberations (reported)2024-11-09The News
Public committee hearings / clause-by-clause review (expected)By 2024-12-31 (as reported)The Nation

Sources and References

SourceType
Regulation of Artificial Intelligence Bill, 2024 — Senate Bill SummaryPrimary Source
Senate Panel to Deliberate on Regulation of Artificial Intelligence Bill 2024 — ProPakistaniSecondary/Media
IT ministry faces grilling over ‘selective’ AI collaboration — DawnSecondary/Media
Ministry of Information Technology & Telecommunication — OfficialPrimary Source (policy context)

Requirements for a company

What an organisation has to do under Pakistan - AI Regulation (2024), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Proposed). These requirements apply once the instrument takes effect and may change before then.

Must do

10
  • Register AI systems and providers with the Artificial Intelligence Commission.AI system providers and deployers.
  • Conduct mandatory algorithmic impact assessments for systems that may materially affect rights or safety.Providers and deployers of high-risk AI systems.
  • Ensure AI systems comply with national data protection laws and data minimisation principles.All entities processing personal data with AI systems.
  • Implement human oversight mechanisms for high-impact AI decisions and provide redress channels.Deployers of high-impact AI systems.
  • Perform safety testing, conformity assessment, and certification for high-risk AI systems.Providers and deployers of high-risk AI systems.
  • Establish cybersecurity and model-security requirements, including secure training data and access controls.AI system providers and deployers.
  • +4 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Pakistan - AI Regulation (2024), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1AI system providers and deployers.Register AI systems and providers with the Artificial Intelligence Commission.
The legislative text proposes creation of an Artificial Intelligence Commission (AIC)... to: (a) register AI providers and relevant systems
Critical
2Providers and deployers of high-risk AI systems.Conduct mandatory algorithmic impact assessments for systems that may materially affect rights or safety.
risk management and mandatory algorithmic impact assessments for systems that may materially affect rights or safety
Before placing on marketCritical
3All entities processing personal data with AI systems.Ensure AI systems comply with national data protection laws and data minimisation principles.
data protection alignment (mandating compliance with national data-protection law and data minimisation)
Critical
4Deployers of high-impact AI systems.Implement human oversight mechanisms for high-impact AI decisions and provide redress channels.
human oversight and redress (mechanisms for human review of high-impact decisions and channels to lodge complaints with the commission)
Critical
5Providers and deployers of high-risk AI systems.Perform safety testing, conformity assessment, and certification for high-risk AI systems.
safety testing, conformity assessment and certification for high-risk systems
Before placing on marketCritical
6AI system providers and deployers.Establish cybersecurity and model-security requirements, including secure training data and access controls.
cybersecurity and model-security requirements (secure training data, access controls and incident response)
Critical
7AI system deployers.Notify the Artificial Intelligence Commission of cybersecurity compromises or algorithmic harms.
incident notifications for cybersecurity compromises or algorithmic harms
Critical
8AI system providers and deployers.Provide transparency documentation, including model cards, dataset provenance, and public notices for automated decisions.
transparency and documentation (including model cards, dataset documentation and public notices for automated decision-making)
Important
9AI system deployers.Maintain required records and submit periodic compliance reports to the Artificial Intelligence Commission.
Monitoring tools include required record-keeping, periodic compliance reports
Important
10All entities developing or deploying AI systems.Align confidentiality, national security, and privacy safeguards with existing laws and enacted data-protection statutes.
It instructs alignment of confidentiality, national security and privacy safeguards with existing laws
Important

© Regulations.AI · updated on 13-Jun-2026