What the policy shift means for you

The government agrees with us now

In July 2025, the federal cabinet approved Pakistan's first National AI Policy. In February 2026, following the Indus AI Summit in Islamabad, the government adopted the Islamabad AI Declaration on Sovereign, Responsible, and Capability Driven Artificial Intelligence, committing to one billion dollars in AI investment by 2030. A new AI Directorate was established inside the Ministry of Information Technology and Telecommunication to oversee how AI gets built and deployed across the country.

None of this was written with any single company in mind. Read closely, though, and it describes the exact argument this company was built on.

Sovereign is now a government word, not a vendor word

The policy names sovereign AI infrastructure as a national priority, with a stated preference for local data centres and local cloud environments over foreign ones. That is not marketing language borrowed for effect. It is federal policy, written because the government concluded that routing a nation's data and decisions through infrastructure it does not control is a risk worth spending a billion dollars to avoid.

Punjab has moved further and faster than any other province. The Chief Minister has approved the province's first AI Roadmap, aiming to make Punjab the most AI capable province in South Asia by 2029, with a dedicated AI Delivery Unit she personally chairs. The province has also given in principle approval to a GPU based government cloud project, built specifically so government workloads do not have to depend on a foreign cloud provider. In July 2026, the federal government introduced a National Data Governance Policy requiring that AI systems used in government decision making be explainable, auditable, and assessed for risk before deployment, with clear records of how they function.

What this means if you are deciding whether to adopt AI

If your organisation is a bank, a hospital, a government department, or a factory weighing an AI system, three things follow from where policy now stands.

First, a system that depends on sending your data to a cloud service outside Pakistan is moving against the direction the government has set, not with it. That does not make it unusable today. It does mean the direction of travel is toward more scrutiny of that exact arrangement, not less.

Second, if your organisation is a government body or works closely with one, a system that cannot explain how it reached a decision or account for what happened to the data behind it is now a harder thing to defend, not a formality to wave through. The National Data Governance Policy specifically asks for auditability and a documented risk assessment before deployment.

Third, Pakistan still has no comprehensive personal data protection law in force. A bill has existed in draft since 2023 and has not yet passed. That gap will close eventually, and the pattern already visible in the rules that do exist, the State Bank's requirements for banks, the telecom regulator's localisation rules for operators, points toward data staying inside the country by default once it does. An organisation whose data already stays home will not need to change anything when that law arrives. An organisation whose data does not will.

Where Manar sits in this

Manar trains AI systems on a client's own data and runs them on hardware the client owns, inside the client's own premises. Nothing about that arrangement was designed around this year's policy announcements. It was already the only way the company builds anything. The policy did not change what Manar does. It changed how much explaining everyone else now has to do.

Request a Site Read Security and Data