ISLAMABAD: The National Cyber Emergency Response Team (National CERT) has issued an advisory on the secure use of generative artificial intelligence (AI), warning that unauthorized use of AI chatbots and third-party services could expose sensitive information and organizational data to cybersecurity threats.

According to the advisory, the use of “Shadow AI” — unauthorized AI tools and services used within organizations — could lead to the leakage of sensitive information, source code and credentials.

The National CERT warned that prompt injection attacks, insecure AI-generated code and vulnerabilities in AI models and third-party services could further increase cybersecurity risks for organizations.

The advisory called on organizations to establish and strictly enforce an acceptable-use policy for generative AI. It recommended that government and other sensitive information should not be entered into public or unapproved AI platforms.

The National CERT also recommended mandatory human review of AI-generated code and critical AI-generated outputs before they are used in organizational systems or decision-making processes.

Organizations have been advised to implement data loss prevention and monitoring controls on AI platforms and maintain a list of approved AI tools, models and platforms.

The advisory further recommended aligning AI governance frameworks with internationally recognized standards, including those developed by the National Institute of Standards and Technology (NIST) and the Open Worldwide Application Security Project (OWASP).

The National CERT directed organizations to immediately contain AI-related security incidents and preserve relevant evidence for investigation.

It said incidents involving sensitive data leakage, prompt injection attacks and AI supply-chain attacks should be reported to the National CERT.

According to the advisory, AI-related cybersecurity incidents can be reported through the National CERT’s designated portal, email or Universal Access Number (UAN).

The National CERT urged organizations to adopt a proactive approach to AI security as the use of generative AI tools continues to expand across workplaces and institutions.