NADRA and AI How Facial Recognition Technology Works in Pakistan
NADRA facial recognition now verifies identities for pensions, passports and more. Here is how the AI works, where it's used, and the risks involved.

NADRA Facial Recognition: 7 Essential Facts, Benefits and Hidden Risks for Pakistanis
NADRA facial recognition has gone from a behind-the-scenes experiment to something millions of Pakistanis may use in their daily lives. If you’ve renewed your CNIC through the Pak ID app, applied for a passport online, or helped an elderly parent whose fingerprints wouldn’t scan at the bank, you’ve likely come across it already.
The reason is simple. Fingerprint verification has failed a lot of people. Labourers with worn-down fingertips, farmers, older citizens and people with skin conditions have been turned away from banks, SIM franchises and property offices because a machine couldn’t read their thumbs. Facial recognition offers another way to prove who you are, and in January 2026, NADRA started issuing official facial recognition certificates for exactly this situation.
But this technology deserves a careful look, not just applause. NADRA holds sensitive data on almost every Pakistani, and its track record isn’t spotless. An official investigation found that personal data of 2.7 million citizens was stolen between 2019 and 2023, and some of it surfaced abroad. Criminal gangs have used thousands of fake silicone fingerprints to fool biometric systems and activate illegal SIMs. Now faces are becoming part of the same system, at a time when AI can fake faces better than ever.
This article explains how facial recognition technology in Pakistan actually works, where NADRA uses it today, what past illegal activities teach us, and what citizens should know to protect themselves.
What Is NADRA Facial Recognition?
NADRA facial recognition is a biometric verification method that confirms your identity by comparing a fresh image of your face with the photo already stored in NADRA’s database, usually the one on your CNIC record.
It’s not a completely new idea. NADRA has captured facial photographs for identity cards for years. What’s changed is the use of AI to match faces automatically and reliably enough to accept them as legal proof of identity.
The legal foundation is now in place. Pakistan’s rules were amended to formally recognise facial and iris scans as biometric identities, and NADRA says facial recognition remains an approved biometric method, particularly when fingerprint verification isn’t possible.
How NADRA Facial Recognition Works: Step by Step
Most people use the system without knowing what’s happening behind the screen. Here’s a simplified explanation of how AI-based face verification generally works.
Step 1: Capturing Your Face
The process begins when a camera captures your face. This could be a camera at a NADRA registration centre, a device at a bank or service outlet, or your phone’s camera through the Pak ID app. At registration centres, if fingerprint verification fails elsewhere, the citizen has a fresh photograph taken, which is then matched with the image already in NADRA’s records.
Step 2: Liveness Detection
Before matching, a good system checks that it’s looking at a real, live person and not a printed photo, a screen, a mask or a video. This is called liveness detection. Apps often ask you to blink, turn your head or move closer to the camera. Users of the Pak ID app will recognise these prompts, and some have complained online about the camera not responding properly during capture.
Liveness checks are one of the most important security layers, because without them, anyone with your photo could try to pass as you.
Step 3: Creating a Face Template
The AI doesn’t compare photos the way a human would. Instead, it measures features of your face, such as the distance between your eyes, the shape of your jaw and the contours of your nose, and converts them into a mathematical code, often called a face template or embedding. This code is what gets compared, not the image itself.
Step 4: Matching Against the Database
There are two types of matching, and the difference matters a lot for privacy:
- 1:1 verification: The system compares your face against one specific record, the one linked to the CNIC number you’ve provided. It answers the question, “Is this person who they claim to be?” This is what NADRA’s certificate and Pak ID services mainly use.
- 1:N identification: The system compares a face against many records to find out who someone is. This is what surveillance cameras linked to criminal databases do. It answers, “Who is this person?”
1:1 verification is generally lower risk because you’re choosing to prove your identity. 1:N identification raises much bigger questions, because people can be identified without their knowledge.
Step 5: The Decision
The system produces a similarity score. If it’s above a set threshold, the match is accepted. If it’s below, verification fails. Setting that threshold is a balancing act: too strict and genuine people get rejected, too loose and impostors might slip through.
7 Essential Facts About NADRA Facial Recognition in 2026
Here’s where the technology stands today in Pakistan.
1. It’s Now Legally Recognised as Biometric Identity
As mentioned above, the rules have been amended so facial and iris scans legally count as biometric identities. This matters because institutions like banks and telecom companies previously relied almost entirely on fingerprints, and many refused alternatives.
2. Facial Recognition Certificates Launched in January 2026
From January 20, 2026, NADRA began issuing facial recognition-based verification certificates at all its registration centres for citizens whose fingerprints can’t be verified. The certificate costs a nominal Rs20.
The certificate includes the purpose of verification, your recent photo next to your photo on record, your CNIC number, name, father’s name, a unique tracking ID and a QR code. You can then present it to banks, SIM franchises, housing societies or property offices that require biometric verification.
One practical note: users have raised questions online about why the certificate is only valid for seven days, so plan to use it quickly after getting it.
3. The Pak ID App Already Uses It for Several Services
Face verification isn’t limited to certificates. NADRA says the system is already used for transferring Islamabad-registered vehicles and for online passport applications. The Pak ID app also uses AI-powered biometric capture, including facial recognition and fingerprints, for CNIC services.
4. Pensioners Can Verify From Home
One of the most practical uses is for elderly pensioners. In June 2026, the finance minister announced that pensioners can complete their mandatory “proof of life” verification from home using facial recognition on the Pak ID app. For older citizens who previously had to travel to banks repeatedly, this is a real improvement.
5. SIM Verification Is Still Disputed
This is where things get complicated. In 2025, NADRA proposed using the Pak ID app for facial verification when issuing SIMs, and mobile operators completed a proof of concept. But in August 2026, NADRA withdrew the plan and asked operators to deploy dedicated hardware at their own locations, following NADRA’s new rules for access to its National Data Warehouse published on July 28, 2026.
NADRA said the disagreement isn’t about whether facial recognition works, and that operators can integrate facial verification into their own franchises, service centres and apps. For citizens, this means SIM verification with facial recognition depends on whether your operator has installed the required equipment.
6. Banks and Other Institutions Are Moving Toward It
NADRA’s plans also allow banks and telecom operators to carry out facial or iris verification directly at their outlets once they install suitable equipment. As more institutions adopt it, fingerprint failures should stop being a dead end for ordinary citizens.
7. Safe City Cameras Use Facial Recognition Too
Beyond identity verification, facial recognition is part of Pakistan’s Safe City projects. Islamabad’s Safe City system includes facial recognition software alongside 1,950 surveillance cameras. According to officials, face recognition cameras are installed at the city’s entry and exit points to identify suspicious individuals.
Punjab’s Safe City initiative uses an AI-powered facial recognition system to help police identify and trace suspects. In Karachi, the first phase of the Smart Safe City project planned 1,300 cameras with facial and number plate recognition in the red zone and airport corridor. Sindh’s chief minister has also directed integration of criminal records, vehicle registrations and NADRA data for smart policing.
This is the 1:N identification use described earlier, and it’s the one that raises the most serious privacy questions.
Why Pakistan Needs Alternatives to Fingerprints
It’s worth understanding why NADRA biometric verification is shifting toward faces in the first place.
Fingerprints Fail Many Ordinary People
Many citizens struggle with fingerprint scanners. Those most affected include:
- Labourers, farmers and construction workers with worn fingerprints
- Elderly people whose fingerprints fade with age
- People with skin conditions, injuries or amputations
- Women doing heavy household work with abrasive materials
When fingerprint verification fails, these citizens face serious trouble at banks, SIM franchises, housing societies and property transfers. Facial recognition gives them an alternative that doesn’t depend on their hands.
Fingerprints Have Also Been Faked on a Massive Scale
The second reason is fraud, which brings us to the illegal activities that shaped this technology.
Past Illegal Activities: What NADRA’s History Teaches Us
Any honest look at facial recognition technology in Pakistan has to include the failures of the biometric system that came before it.
The Silicone Fingerprint Racket
In 2021, the FIA uncovered a large operation using fake fingerprints. Authorities recovered more than 6,000 silicone fingerprints, 7,000 illegally activated SIM cards, 19 biometric devices, phones and printers. The FIA found that the fraud was carried out through a compromise of NADRA’s biometric verification system.
The damage spread widely. Investigators reported that 13,000 SIMs were seized in Faisalabad, and thousands of cybercrime complaints traced back to people, many elderly or women, whose data was being misused. Half a million SIMs were blocked and two mobile operators were fined.
The lesson: biometric systems are only as strong as the process around them. Fake fingers fooled scanners because liveness checks were weak and criminals had access to people’s fingerprint data.
The 2.7 Million Citizen Data Leak
The biggest scandal came to light in 2024. A Joint Investigation Team found that the personal data of 2.7 million Pakistanis had been compromised between 2019 and 2023. The JIT said NADRA offices in Karachi, Multan and Peshawar were allegedly involved, and found evidence of NADRA data surfacing in Argentina and Romania. The data reportedly moved from Multan to Peshawar, then to Dubai, before being sold abroad.
NADRA later clarified that the biometric system used for SIM verification, among other things, had been compromised, not the entire data record. Still, the consequences were serious. NADRA terminated a Grade 19 officer and five other employees, though concerns about internal accountability remained.
Insiders Selling Citizen Data
The problem hasn’t only been hackers. In June 2025, two NADRA employees in Hyderabad were caught selling citizens’ data. Insider abuse is one of the hardest risks to prevent, because the people involved have legitimate access to the system.
Why These Cases Matter for Facial Recognition
These incidents show three things clearly:
- Biometric data can be stolen and misused. Unlike a password, you can’t change your face or fingerprints once they’re leaked.
- The weakest link is often human. Corrupt insiders and poorly secured offices have caused more damage than sophisticated technology failures.
- Criminals adapt quickly. If fingerprints were faked with silicone, faces can be targeted with photos, masks, videos and deepfakes.
Can AI Fool NADRA Facial Recognition?
This is a fair question in 2026. AI can now create realistic fake faces and videos, and criminals worldwide are experimenting with ways to trick face verification systems. Common attack methods include:
- Presentation attacks: Holding up a printed photo, a screen, or a 3D mask to the camera.
- Deepfake videos: Using AI-generated video of a real person’s face that blinks and moves.
- Injection attacks: Feeding a fake video stream directly into an app, bypassing the phone’s real camera.
Strong liveness detection is designed to stop these, and systems that capture faces at supervised NADRA centres or on dedicated hardware are much harder to fool than a phone app. That may be one reason NADRA has pushed operators to use dedicated equipment for SIM issuance rather than relying on the app.
There’s also an important link to the 2.7 million data leak. If stolen records include photos, criminals may have exactly the raw material they need to try deepfake attacks. That’s why security has to cover both the matching technology and the database itself.
Privacy and Ethical Concerns Around Facial Recognition in Pakistan
NADRA facial recognition brings real benefits, but also serious ethical questions.
Surveillance Without Consent
When you choose to verify your identity at a bank, you’ve consented to the check. When a Safe City camera scans your face on the street and matches it against a database, you haven’t. Mass 1:N identification can be used to track people’s movements, including journalists, activists, protesters or simply ordinary citizens, if strong legal limits aren’t in place.
Function Creep
Systems built for one purpose often get used for others. A database created to issue identity cards may gradually be connected to policing, tax, travel and other systems. Each new connection increases both usefulness and risk.
Data Protection Gaps
Pakistan has been working on dedicated personal data protection legislation for years. Strong, independently enforced rules about who can access biometric data, how long it’s kept, and what happens when it’s misused are essential, especially given NADRA’s past breaches.
Accuracy and Bias
Facial recognition systems don’t perform equally for everyone. International testing has shown that accuracy can vary by age, gender and skin tone, and older faces can be harder to match against old ID photos. A system that works well for young urban men but struggles with elderly rural women would repeat the same exclusion problem fingerprints created.
Global Warnings
Other countries offer useful lessons. Some European regulators have fined companies for collecting facial images without consent, and several cities have restricted police use of facial recognition. These debates show that the technology’s legal and ethical limits are still being worked out worldwide.
How to Protect Yourself as a Pakistani Citizen
You can’t control NADRA’s security, but you can reduce your personal risk:
- Use only official channels. Download the Pak ID app only from official app stores and use NADRA’s official web portal. Fake apps and websites can steal your photos and data.
- Never share OTPs or verification codes with anyone claiming to be from NADRA, a bank or a telecom company.
- Check SIMs registered in your name regularly through PTA’s official service, and block any you don’t recognise. Some reports note the Pak ID system can alert you if someone tries to register a SIM using your ID.
- Limit copies of your CNIC. Don’t hand out photocopies or photos of your ID card casually, and write the purpose on any copy you must give.
- Be careful with face photos online. Clear, front-facing photos of you and your family, especially children, can be misused.
- Help elderly relatives. Older citizens are often the main users of facial verification and the main targets of fraud. Walk them through the process and warn them about fake calls.
- Report misuse quickly to NADRA, PTA or the NCCIA if you suspect your identity has been used fraudulently.
What Good Governance Should Look Like
For NADRA facial recognition to earn public trust, a few safeguards are essential:
- Clear legal limits on when faces can be matched against the database, especially for surveillance.
- Independent oversight of how Safe City facial recognition is used by police.
- Strong liveness detection and certified hardware for high-risk services like SIM issuance and banking.
- Strict insider controls, including audit logs of who accessed which records and real penalties for misuse.
- Transparency reports on breaches, error rates and how many people are wrongly rejected.
- Accessible alternatives so no citizen is locked out of services because a machine can’t recognise them.
For further reading, Dawn’s report on the rule change recognising facial and iris scans as biometric identities explains the certificate system in detail, and ProPakistani covers the NADRA and PTA dispute over Pak ID facial verification for SIMs. On security risks, Dawn’s coverage of the JIT finding that 2.7 million citizens’ data was compromised and Biometric Update’s report on the fake silicone fingerprint racket are essential background.
Conclusion
NADRA facial recognition has become a legally recognised way to prove identity in Pakistan, working by capturing a live image, checking for liveness, converting facial features into a digital template and matching it against your NADRA record, and it now powers facial verification certificates launched in January 2026, Pak ID services such as passport applications, vehicle transfers and pensioners’ proof of life, a still-disputed plan for SIM verification, and Safe City cameras in Islamabad, Punjab and Karachi. For citizens whose fingerprints fail, especially labourers and the elderly, it’s a genuine improvement. But NADRA’s history, including the silicone fingerprint racket that activated thousands of illegal SIMs, the leak of 2.7 million citizens’ data that surfaced abroad, and insiders caught selling records, shows that biometric systems are only as trustworthy as the security and accountability around them, and the rise of deepfakes and mass surveillance raises the stakes further. The technology can serve Pakistanis well if it comes with strong liveness checks, strict insider controls, clear legal limits on surveillance and real data protection, and until then, citizens should use only official channels, guard their personal data and report misuse quickly.
Keywords:











