IMAGINE someone in Pakistan is standing at a counter this morning. She is being told that the system will not accept her name as it appears on her degree. Her name on the degree is spelled differently, and the database will only accept the name in the format already stored against her identity record. The clerk is not difficult; the field on the digital form will not take it. There is no form for objection and no hearing at which she can explain that both names belong to the same person.
In this hypothetical scenario, a decision about her legal identity has just been made by a database. When a state moves from paper to software, a lot more changes than just the speed at which things are done.
For most of our history, law lived in a medium we understood: the register, the file, the stamped deed, the court record. A lawyerβs authority came from mastering that medium: what the text said, what a court had made it mean, and how to work out the space between the two. On paper, a rule takes effect through interpretation. An official reads it; someone contests it; a judge decides.
In a system, the rule is executed. The database either lets that department see your record, or it does not. Nobody necessarily weighs your circumstances at the moment of decision unless somebody deliberately built that pause into the design.
Pakistanβs digital state needs a new kind of lawyer β one who stops treating the system as somebody elseβs department.
Pakistan is now building at pace. The Digital Nation Pakistan Act, 2025, created the Pakistan Digital Authority, with a mandate covering digital governance, data, artificial intelligence and digital public infrastructure. The draft National Data Governance Policy, 2026, declares government data a strategic national asset and proposes rules on data sovereignty, and cross-border transfers. In April, the National Judicial (PolicyΒmaking) Committee issued guidelines positioning AI as an assistive tool for judicial institutions.
Meanwhile, the Personal Data Protection Bill remains a draft, years after the 2018 version was published.
So, the architecture is arriving ahead of the supposed governing law. Therefore, it is safe to assume that for now governance will largely come from policy documents, procurement contracts and default settings. This means lawyers will increasingly need to be involved not just when something goes wrong, but when these systems are being designed and built in the first place.
Consider interoperability, which is the quiet centre of all of this. A service links records, so a citizen no longer submits information the state already holds. That makes life easier, but it also creates important legal questions. Who may open that record, and for what purpose? How long does an incorrect entry follow someone, and who is answerable for it? What is left of consent when refusing to share means losing a service you need? Those are legal questions with technical answers, and technical questions with legal consequences.
Legal practice is forming around them. Data governance is the most visible piece: someone has to negotiate the terms on which institutions share, secure and delete individualsβ data, and that work happens before a system is built, not afterwards.
Artificial intelligence adds another layer. The National AI Policy, 2025, and the Islamabad AI Declaration both put accountability alongside adoption. This sounds unobjectionable until you have to demonstrate it. A lawyer in this space needs to know how a model was tested, where it fails, and what record would satisfy a regulator two years later. Much of the work is about evidence rather than doctrine.
Then there is the lawyer who sits with the people building the thing. The old sequence was linear: a team builds, legal clears. What is emerging moves counsel upstream, into the design conversation. Suppose a rule says an AI system must be auditable. Somebody has to decide what gets logged, who may inspect it, and what triggers review. An engineer cannot decide that alone, because the obligation is legal. A lawyer cannot decide it alone either, because the answer is a specification.
That shift also changes where legal judgement enters the process. It is no longer enough to ask whether a policy is lawful on paper. The important question is whether the institution has translated that policy into workflows that behave lawfully when nobody is watching. That means understanding exceptions, escalation paths, audit trails, access controls, and people who are affected when the system gets something wrong. It is a different kind of legal practice, but it is legal practice.
If I had to name one skill for the next generation, it would be that act of translation. A regulator can declare that an automated decision must be accountable. A policymaker can create a right to human review. A right nobody has built into a system is, in practice, a right that does not exist. Carrying a principle down into a requirement, a control, and a record somebody can check is now part of what it means to make the law work.
None of this threatens traditional practice. We will always need formidable litigators and lawyers who can draft contracts. But the surrounding literacy is shifting. How data moves through an institution, what an interface actually does, how digital identity works, where security risk collects. Lawyers do not need to write code. Lawyers do need to stop treating the system as somebody elseβs department.
The question worth asking is not whether technology will replace lawyers. It is whether lawyers will be in the room when these systems are designed.
Pakistan is laying the foundations of a digital state. Its rules are being written now, some in statutes, and a great many in software.
The writer is a technology lawyer specialising in data protection.
Published in Dawn, September 2nd, 2026
No comments yet. Be the first to comment!