AI Ethics in Pakistan: Who Is Responsible When AI Gets It Wrong?
AI Ethics in Pakistan explored: who carries the blame when algorithms fail, and what accountability actually looks like today.

AI ethics in Pakistan is no longer an academic debate confined to university seminars. It is a live question every time a hospital uses an algorithm to triage patients, a bank runs a credit-scoring model, or a government office automates a decision that used to sit with a human clerk. When these systems make mistakes, and they do, the country still lacks a clear, tested answer to a simple question: who pays for it?
This gap matters more in Pakistan than in many other places. The country is racing to build an AI ecosystem, train a workforce, and attract investment, all while the basic legal scaffolding for AI accountability in Pakistan is still being drafted. A developer in Lahore, a hospital administrator in Karachi, and a government official in Islamabad can all be using the same AI tool, and none of them may know, with any certainty, who is legally on the hook if that tool causes harm.
This article walks through where responsibility currently sits, what the National AI Policy actually says about it, where the legal system falls short, and what a workable accountability structure could look like. The goal is not to scare anyone off AI. It is to lay out, plainly, what protections exist right now, what doesn’t, and what people building or using these systems in Pakistan should be watching for.
Why AI Ethics in Pakistan Has Become Urgent
AI adoption in Pakistan has moved faster than most people realize. Government departments are experimenting with automated service delivery. Fintech companies use machine learning for lending decisions. Hospitals are piloting diagnostic tools. Universities are testing AI in admissions and grading support. None of this is hypothetical anymore.
The problem is that algorithmic accountability has not kept pace with adoption. As one legal review of Pakistan’s regulatory gaps put it, the country faces real challenges around accountability, data privacy, and ethical dilemmas <cite index=”5-1″>largely because it lacks a comprehensive legal framework to govern artificial intelligence</cite>. That is not a minor technical gap. It means that when an AI system denies someone a loan unfairly, misdiagnoses a patient, or flags an innocent person through facial recognition, there is often no clear legal path to hold anyone responsible.
A few factors have pushed this from “someday” to “right now”:
- Government digitization is expanding automated decision-making into taxation, procurement, and public service delivery, which directly affects how citizens access basic entitlements.
- Private sector adoption in banking, insurance, and e-commerce means AI is already influencing decisions about money, employment, and access to services.
- Facial recognition and surveillance tools are being deployed by law enforcement in some cities, raising direct questions about privacy and due process.
- Generative AI tools are now widely used by students, journalists, and businesses, creating new categories of harm like deepfakes and misinformation that didn’t exist in this form a few years ago.
None of these use cases are inherently wrong. The problem is deploying them without a clear answer to what happens when they fail.
What the National AI Policy Says About Responsibility
Pakistan’s federal cabinet approved the National AI Policy in July 2025, and it remains the country’s most significant attempt to define how AI should be governed. <cite index=”1-1″>The policy leans on transparency, fairness, and accountability as guiding principles, and it lays groundwork for future AI impact assessments and algorithmic-audit requirements</cite>. On paper, that sounds like a solid foundation.
In practice, the policy is a framework of intentions rather than a rulebook with teeth. <cite index=”1-1″>It takes a risk-based approach to AI governance, but it hasn’t yet spelled out a detailed risk classification system with the level of specificity found in something like the EU AI Act, even though it does separate lower-risk applications from those touching fundamental rights, public safety, or critical infrastructure</cite>. That distinction matters, but without granular rules attached to it, it’s more of a signpost than a working system.
The New AI Directorate
One concrete structural step is the creation of an oversight body. <cite index=”1-1″>The policy sets up a formal government framework covering risk classification, sovereign-cloud preferences, governance structures, and sectoral oversight, run through a new AI Directorate housed under the Ministry of Information Technology and Telecommunication</cite>. This directorate is meant to be the body that eventually issues the implementing rules startups, banks, and public agencies will need to follow.
For now, though, companies and public bodies deploying AI are largely operating ahead of the rulebook. <cite index=”1-1″>Startups and other organizations building or deploying AI systems are already expected to map their data flows, screen products for risk level, and prepare for possible impact assessments, even as the regulatory window is expected to tighten as detailed rules get drafted</cite>.
A Proposed AI Commission
Beyond the current policy, there has been a legislative push to create a dedicated regulator. <cite index=”6-1″>A draft law, referred to as the Regulation of Artificial Intelligence Act, proposes establishing a National Artificial Intelligence Commission focused on data protection, accountability, and ethical standards, with the power to oversee AI use and penalize violations</cite>. This commission, if it becomes law, would be the closest thing Pakistan has to a single body citizens could complain to when an AI system causes harm. As of now, it remains a proposal, not an operating institution.
Who Is Actually Liable When AI Fails?
This is the question that matters most in practice, and it’s the one with the least clarity. When an AI-driven decision hurts someone, in theory the responsibility could fall on:
- The developer who built the model and trained it on a particular dataset.
- The deploying organization (a bank, hospital, or government agency) that decided to use the tool for a real-world decision.
- The individual official or employee who accepted the AI’s output without independent review.
- The data provider, if flawed or biased training data caused the failure.
Right now, Pakistani law doesn’t clearly assign this responsibility to any one of these parties by default. Legal scholars examining the issue have pointed out that AI raises hard questions around intellectual property, data privacy, and algorithmic discrimination that <cite index=”6-1″>the country’s legal system is not well equipped to answer, since there is little existing guidance on how liability and accountability should actually be assigned</cite>.
Human Rights Add a Legal Backstop, But Not a Complete One
Pakistan’s existing international obligations do offer some protection, even without a dedicated AI law. Because Pakistan is a signatory to core human rights treaties, any AI system operated by the state has to respect certain baseline protections. <cite index=”7-1″>Pakistan’s status as a party to the ICCPR and the UDHR means it has committed to guaranteeing privacy and freedom of expression, and any AI regulation the country adopts cannot erode those existing freedoms</cite>. This gives citizens a theoretical basis to challenge government AI decisions, but treaty obligations are a slow and indirect route compared to a functioning domestic complaints process.
What Meaningful Accountability Would Require
Legal commentators tracking Pakistan’s AI regulatory path have proposed a fairly concrete set of building blocks for real accountability, rather than aspirational language. These include:
- A public registry of AI tools used by government agencies, so citizens know when they’re interacting with an automated system.
- Regulatory sandboxes that let new AI tools get tested under supervision before wide deployment.
- Independent audits, run either by a regulator or vetted third parties, for any AI system classified as high-impact.
- A clear right to challenge any AI-driven decision that affects someone’s rights or access to services.
<cite index=”7-1″>Developers and deployers of high-impact AI systems should be expected to document their systems clearly, and citizens should have a defined right to challenge any AI-driven decision that restricts their speech or other freedoms</cite>. Without these pieces in place, “accountability” remains a word in a policy document rather than something a harmed person can actually invoke.
Ethical Governance vs. Legal Enforcement
There’s an important distinction that keeps getting blurred in Pakistan’s AI conversation: ethical guidelines and enforceable law are not the same thing. A company can publish an AI ethics charter and still cause real harm if nothing legally compels it to follow that charter, or penalizes it for ignoring it.
Some governance proposals for Pakistan explicitly call this out. <cite index=”9-1″>AI needs to be aligned with human-centered values, and the argument is that ethical guidelines for AI should be made legally enforceable rather than left as voluntary commitments</cite>. This is the crux of the responsibility problem: voluntary ethics codes rely on companies and agencies policing themselves, which tends to break down exactly in the cases where accountability matters most.
International Models Pakistan Is Watching
Pakistan isn’t building its approach in a vacuum. Policymakers and legal scholars have been comparing international frameworks to figure out what might translate locally.
- The European Union’s AI Act sorts AI systems into risk tiers, ranging from unacceptable to high-risk to low-risk, and attaches specific legal obligations to each tier.
- The United States has generally taken a sector-by-sector approach, relying on executive orders and softer guidance focused on algorithmic accountability and transparency rather than one overarching law.
- China’s model is heavily state-directed, showing how AI regulation can be tightly bound to national security priorities rather than individual rights.
<cite index=”9-1″>These differing approaches, from the EU’s risk-tiered system to the sectoral US model to China’s state-controlled approach, all illustrate how AI regulation internationally has become a genuine policy priority, even though each country is solving for different goals</cite>. Pakistan’s challenge is picking pieces that fit its own institutional capacity, rather than importing a model wholesale that assumes resources or infrastructure the country doesn’t yet have.
The Practical Gap: Policy on Paper vs. Reality on the Ground
Even a well-written AI policy runs into trouble if the underlying systems it assumes are in place simply aren’t there yet. Analysts reviewing Pakistan’s National AI Policy have flagged this directly. <cite index=”4-1″>The policy’s success ultimately depends on closing a real gap between its stated vision and conditions on the ground, since it assumes foundational systems like reliable electricity, widespread internet access, solid data governance, digital literacy, and a functioning regulatory ecosystem are already in place</cite>. In many parts of the country, they aren’t.
This gap has direct consequences for accountability. It’s hard to demand rigorous algorithmic audits from a regulator that doesn’t yet have the technical staff to perform them. It’s hard to guarantee citizens a meaningful right to challenge an automated decision if digital literacy is uneven and legal aid is scarce. Responsible AI governance in Pakistan isn’t just a legislative drafting problem, it’s an institutional capacity problem.
Where International Bodies Are Filling Gaps
International organizations have stepped in to help close some of this distance, particularly around technical review and capacity building. UNESCO has been directly involved in reviewing Pakistan’s draft AI policy. <cite index=”3-1″>UNESCO has contributed to the technical review of Pakistan’s draft National AI Policy, working to align the country’s strategy with international ethical standards while still accommodating Pakistan’s own development priorities</cite>. UNESCO has also pushed its own diagnostic tool as part of this effort. <cite index=”3-1″>The organization has promoted its AI Readiness Assessment Methodology, already used in more than 50 countries, as a way for governments to spot regulatory gaps, improve institutional coordination, and build safeguards against discrimination and algorithmic bias</cite>.
This kind of external technical support is useful, but it’s supplementary. It can help Pakistan write better rules faster. It cannot, by itself, build the domestic enforcement muscle needed to make those rules mean something when a specific person is harmed by a specific AI decision.
Sector-by-Sector: Where Responsibility Gaps Hit Hardest
Not every AI use case carries the same risk, and Pakistan’s accountability gap shows up differently depending on the sector.
Healthcare
AI diagnostic and triage tools promise real benefits in a country with a shortage of specialists relative to population size. But a misdiagnosis carries life-or-death consequences, and there is currently no dedicated medical-AI liability framework distinguishing between a doctor’s error and a flawed algorithm’s recommendation.
Financial Services
Banks and fintech lenders increasingly use AI-driven credit scoring. If that scoring system systematically disadvantages certain neighborhoods, professions, or demographic groups, there’s currently no dedicated algorithmic fairness requirement forcing lenders to disclose or correct that bias, beyond general consumer protection law that wasn’t written with AI in mind.
Public Sector and Law Enforcement
This is arguably the highest-stakes category, since it directly touches due process and civil liberties. Facial recognition and predictive tools used by law enforcement carry a real risk of misidentification, and without a public registry of these tools or an independent audit requirement, citizens often don’t even know when an algorithm played a role in a decision affecting them.
Education
AI is increasingly used in grading support and admissions screening. Errors here affect a student’s academic future, yet there’s little established process for a student to formally contest an AI-assisted decision the way they might contest a human grader’s mistake.
What Individuals and Organizations Can Do Now
Waiting for perfect legislation isn’t a realistic strategy for anyone deploying or affected by AI in Pakistan today. A few practical steps make sense regardless of how the regulatory picture evolves:
- Document decision-making processes. Organizations using AI for consequential decisions should keep clear records of how the system was trained, tested, and validated, since this becomes the evidence base if something goes wrong later.
- Build in human review for high-stakes decisions rather than letting AI outputs go straight into action unchecked.
- Push for contractual clarity. When a company buys or licenses an AI tool from a vendor, the contract should specify who bears liability if the tool causes harm.
- Know your rights under existing law. Even without a dedicated AI statute, general consumer protection, data protection, and constitutional privacy provisions may still apply.
- Watch the AI Directorate’s rulemaking. As the Ministry of IT and Telecommunication’s AI Directorate issues implementing rules, staying current on these updates will matter more than reading the original policy document once and moving on.
Frequently Asked Questions
Does Pakistan have a dedicated AI law right now? Not yet. The National AI Policy, approved in July 2025, sets direction and principles, but a dedicated AI statute with binding liability rules, such as the proposed Regulation of Artificial Intelligence Act, has not been finalized into law.
Who regulates AI in Pakistan today? The AI Directorate under the Ministry of Information Technology and Telecommunication is the primary body currently shaping implementation, though a separate National Artificial Intelligence Commission has been proposed as a dedicated regulator.
Can someone sue over an AI-driven decision in Pakistan? There’s no dedicated AI liability statute yet, but general legal protections around privacy, consumer rights, and constitutional freedoms may still provide a basis for a claim, depending on the facts.
Conclusion
AI ethics in Pakistan sits at an uncomfortable midpoint: the country has a stated policy commitment to fairness, transparency, and accountability, but the legal and institutional machinery needed to enforce that commitment is still under construction. The National AI Policy and its new AI Directorate are real steps forward, and international support from bodies like UNESCO is helping close technical gaps, but until Pakistan has a functioning liability framework, an active oversight commission, and enforceable rights for citizens to challenge.
AI-driven decisions, the honest answer to “who is responsible when AI gets it wrong” remains: it depends, and often, no one. Closing that gap should be treated as urgent, not aspirational, given how quickly AI is already being woven into healthcare, banking, law enforcement, and public services across the country.











