Almost every business in Pakistan is now using AI tools, whether or not it has decided to. Staff use them for drafting, coding, translation, customer replies and analysis, usually on personal accounts, usually without telling anyone.
Pakistan has no comprehensive AI statute. That does not mean there is no legal exposure — it means the exposure arrives through the law you already have: contract, confidentiality, data protection, copyright, negligence and employment.
The immediate risk: what your staff are pasting in
The most common and most serious problem is not exotic. It is an employee putting a client's contract, a patient's records, a customer database or unreleased financials into a consumer AI tool.
That single act can breach:
- Confidentiality obligations to a client or counterparty, including an NDA you signed
- Customer data commitments and privacy expectations
- Sector rules — patient confidentiality, banking secrecy, legal privilege
- Buyer and vendor contracts restricting where data may be processed
Whether the tool trains on the input, who can see it, and where it is stored depend entirely on the plan and the terms — and consumer tiers are usually the worst on all three.
The fix is not to ban AI, which does not work. It is to provide an approved tool with appropriate terms, and to say clearly what may and may not be put into it.
See data protection and privacy for Pakistani businesses and the contracts every business should have.
Who is liable when the output is wrong
The question clients ask most. The short answer: you are.
AI vendors disclaim liability for output comprehensively. If you give a customer advice, a price, a diagnosis, a design or a document generated by AI, the customer's claim lies against you, on ordinary principles — contract, and negligence where a duty of care exists.
Three practical consequences.
Human review is a control, not a formality. For anything that goes to a customer, affects safety, or is relied on financially, a qualified person must check it and be able to say they did.
Professionals cannot delegate judgement. Doctors, engineers, accountants, architects and lawyers remain accountable for their own advice. See professional negligence claims and medical negligence claims.
Your customer contract should address it. Limitation of liability, exclusion of indirect loss, and — where AI materially assists a deliverable — a clear statement of what the customer is getting and what they must verify.
Copyright and ownership of output
Two separate questions, both live.
What you put in. Feeding third-party copyrighted material into a tool, and producing something substantially similar, is an infringement risk that does not disappear because a machine was involved.
What comes out. Pakistani copyright law, like most, is built around human authorship. Material generated without meaningful human authorship sits on uncertain ground, which matters if that output is a core asset — a logo, a character, a codebase, a marketing library.
Practical positions:
- For anything you need to own and enforce, ensure meaningful human authorship and keep records of the creative process
- Register what you can — trade marks in particular, which do not depend on authorship. See trade mark registration and copyright for creators and content businesses
- Check the vendor's terms on who owns output and whether commercial use is permitted on your plan
- Keep AI-generated material out of anything you will license to others as warranted original work, unless you have checked the position
Contracting with AI vendors and AI-enabled suppliers
Read for:
- Data use — is your input used for training? Can that be switched off, and is it off by default on your plan?
- Data location and transfer, and whether that conflicts with commitments you have made to your own customers
- Confidentiality and security, and breach notification obligations
- Output ownership and permitted use
- IP indemnity — some vendors indemnify against infringement claims arising from output, on conditions. This is worth having and worth reading
- Liability caps, which are usually very low relative to the risk
- Availability, and what happens if the service changes or is withdrawn
- Sub-processors, and your right to know who they are
Where a supplier uses AI in delivering services to you — an agency, a BPO, a software house — say so expressly in the contract: whether it is permitted, on what data, with what review, and who bears the consequences.
Employment and HR
Using AI in hiring — screening CVs, ranking candidates — carries a discrimination and fairness risk, and an inability to explain a decision is itself a problem. Keep a human decision-maker.
Monitoring staff with AI tools engages privacy expectations and should be disclosed, proportionate, and documented in policy.
Staff use of AI should be addressed in the contract and handbook — approved tools, prohibited data, and the disciplinary consequences of pasting confidential material into a personal account. See employment contracts.
Deepfakes, impersonation and fraud
Two exposures worth naming.
Against you. AI-generated voice and video are already being used in Pakistan for impersonation — a "director" on a call authorising a transfer, a cloned voice in a family emergency scam, or fabricated content targeting an individual. The remedies run through PECA and platform takedown. See online blackmail, fake accounts and takedowns, card and account fraud and investment scams.
Controls. Payment authorisation should never rest on a voice or a video call alone. Require a second channel and a second person for any transfer above a threshold — this single control defeats most of these frauds.
By you. Generating content depicting a real person without consent, or making false factual claims about someone, engages PECA and defamation. See what is actionable as defamation.
A workable internal AI policy
One page is enough, and it should say:
- Approved tools, and that work must be done on company accounts
- Never input: client confidential information, personal data of customers or staff, credentials, unpublished financials, or anything covered by an NDA
- Human review required before any output goes to a customer or is relied on
- Disclosure — when clients must be told AI was used, particularly where a contract requires it
- No AI decisions on hiring, discipline, credit or anything materially affecting a person, without a human decision-maker
- Record-keeping for outputs used in deliverables
- Who to ask when something is unclear
Where regulation is heading
Sectoral regulators — in banking, telecom, health and securities — are the most likely near-term source of AI-specific requirements in Pakistan, alongside data protection legislation. Businesses in regulated sectors should assume that explainability, record-keeping and human oversight will be expected, and build those habits now rather than retrofitting them.
If you export services or handle data from the EU or UK, you are already exposed to their frameworks through your customer contracts, which is usually where the real obligations arrive first. See freelancers and IT exporters and ESG and buyer compliance requirements.
How the firm can help
We prepare AI use policies and staff terms, review AI vendor and AI-enabled supplier agreements, advise on ownership and protection of AI-assisted work product, allocate liability properly in customer contracts, and act where AI-generated content is used to impersonate or defraud a client.
See corporate and commercial or regulatory and compliance, or contact the firm.
