Technology Law Jul 23, 2026 · 16 min read

Artificial Intelligence and the Coming Constitutional Crisis of Pakistan

Autonomous systems can now publish, decide, and act without any person intending the result. Pakistani criminal law assumes a human offender with a guilty mind. This article raises the constitutional questions Parliament has not yet answered.

In January 2025, Pakistan amended the Prevention of Electronic Crimes Act and wrote a new offence into the statute book. Section 26A now punishes any person who intentionally spreads information online that the person knows, or has reason to believe, is false, with imprisonment that may reach three years and a fine that may reach two million rupees. Read that provision slowly. It turns on a human being who acts intentionally and who knows. Now set beside it a plain fact of the present decade. Autonomous software can already compose and publish content on its own, in the small hours of the morning, without any person writing it, reading it, or approving it. The statute assumes a guilty mind. The technology quietly removes one. That distance, between what our criminal law assumes and what artificial intelligence actually does, is the subject of this article.

A word of honesty at the outset. It would be false to say that the world has written no law for artificial intelligence. The opposite is true. The European Union has passed the most detailed statute any legislature has yet attempted, and its central obligations begin to apply from 2 August 2026. The Council of Europe opened the first binding international treaty on artificial intelligence for signature in September 2024. The United States governs through agency guidance and the risk framework published by its National Institute of Standards and Technology. China regulates recommendation algorithms and generative systems. UNESCO adopted a global recommendation on the ethics of artificial intelligence in 2021, and the OECD principles have shaped policy since 2019. Legislative activity has been extraordinary. And yet not one of these instruments answers the question this article poses. None of them explains how a criminal court should assign responsibility when a highly autonomous system produces an unlawful act that no human specifically intended.

So this is not another article that lists foreign statutes and urges Pakistan to copy one of them. It asks something more uncomfortable. It asks what happens to the oldest assumptions of our criminal law, and to the guarantees written into our Constitution, when the actor in the dock may be a machine that intended nothing at all. History suggests that constitutions are rarely tested by the questions their authors answered. They are tested by the questions their authors never imagined. Artificial intelligence is now producing exactly that kind of question, and Pakistan has barely begun to ask them.

Why this article asks questions rather than giving answers

Constitutional systems are tested the way engineers test a structure. You do not wait for the storm. You model the load that could break the design and you study the failure in advance. Lawyers call these hypotheticals. Engineers call them stress tests. The value of a stress test is not that it predicts the future. It is that it reveals, ahead of time, the exact point at which an existing rule stops making sense.

Every question that follows is built that way. Each one is plausible on the technology already in the market. Each one is anchored in a real provision of Pakistani law. And each one ends without a tidy answer, because the honest position is that no jurisdiction on earth holds a settled answer yet. A reader who finishes this article feeling slightly unsettled has understood it correctly. Law reform begins in discomfort, not in confidence.

The liability vacuum

Pakistani criminal law rests on two ideas so old that we rarely say them aloud. The first is that every crime has an identifiable actor. The second is that the actor carried a guilty mind, whether intention, knowledge, recklessness, or negligence, according to what the particular offence demands. The Pakistan Penal Code of 1860 was drafted on those ideas. So was the Code of Criminal Procedure of 1898. Both assume that an investigation ends, sooner or later, at a human being.

Now picture a media company that runs an autonomous publishing agent. The system writes and posts updates continuously, with little or no human review. In the small hours of one morning it composes and publishes material that appears to break Pakistani law. No employee read it first. No one instructed it to write those words. By the time the country wakes, the post has traveled across every platform, public anger has gathered, and a criminal case has opened.

The court must now find both the act and the mind behind it. Who performed the prohibited act when a statistical model assembled the sentence? Who held the guilty mind when no person formed any view about that sentence at all? Can the mere deployment of an unsupervised system amount to criminal negligence, and if so, on whose part? The developer who built the model, most likely abroad? The company that deployed it? The engineer who configured it? The manager who failed to watch it? The provider that hosted it? Or nobody. The Penal Code offers no provision written for this moment, because the moment did not exist when the Code was written, and did not exist even a decade ago.

The AI defence

Every new capability creates a new excuse. Section 26A of the amended cybercrime law, like most serious offences, turns on intention. The prosecution must prove that the accused acted intentionally and knew the material to be false. Imagine the accused answers in five words. My AI agent did it.

Pakistani procedure places on the prosecution the burden of proving the offence to the required standard. Electronic records may be examined under the Electronic Transactions Ordinance of 2002, and the Qanun e Shahadat Order of 1984 governs how facts are proved, including electronic evidence where it is admissible. Yet none of these was designed to separate four situations that now look identical from the outside. The person who used the machine deliberately and hides behind it. The person who deployed it carelessly. The person whose system genuinely failed in a way nobody could foresee. And the person who simply invented the entire story after the fact.

If the courts accept the excuse too readily, the autonomous agent becomes the most powerful shield in the history of criminal defence, available to anyone who wishes to publish, trade, transfer, or defraud, and then point at the software. If the courts reject it too quickly, they risk punishing people who took every reasonable precaution and were undone by a failure no diligence could have prevented. Where exactly should the line fall? Our law of evidence does not yet say, and pretending otherwise helps no one.

The collapse of the guilty mind

For as long as criminal law has existed it has asked one question above all others. What was the accused thinking? The doctrine of mens rea, the guilty mind, is the moral engine of the whole system. It is the reason we treat a deliberate wrong differently from a tragic accident, and it is why an innocent mistake is not a crime.

Artificial intelligence puts to that doctrine a question it was never built to survive. What if nobody was thinking at all? A modern model holds no beliefs and no desires. It holds weights, tokens, probabilities, and vast fields of numbers that shift as it computes. It produces language that looks purposeful without any purpose behind it. When such a system generates an unlawful sentence, there is conduct in the world, yet there may be no mind anywhere in the chain that intended that particular sentence to exist.

Can a body of law whose central question is the content of a human mind keep functioning when the immediate cause of the act has no mind to examine? That is not a technical curiosity for the seminar room. It is a question about whether the moral foundation of criminal responsibility can carry the weight the coming decade is about to place upon it.

The examination that cannot happen

Article 10A of the Constitution guarantees every citizen the right to a fair trial and to due process. A great deal of what we mean by a fair trial depends on the ability to test evidence. A witness can be questioned. A document can be challenged. A method can be probed until the court is satisfied it is sound. Testing is not a technicality. It is how truth is separated from assertion.

Now suppose a public authority refuses a benefit, or a court receives an opinion, on the strength of an advanced model, and the affected person asks the only question that matters. Why? Why did the system reach this conclusion about me? And the honest reply from the authority is that it cannot fully reconstruct the reasoning, because the model is of a kind whose inner workings resist complete explanation even by the people who built it.

The EU AI Act requires transparency and documentation for certain systems, and that is a real advance. Yet even that careful statute cannot promise that every advanced model will be fully interpretable, because many of them are not. So the constitutional question stands on its own two feet. Can meaningful review of a decision exist when the reasoning behind the decision cannot be fully shown? If the answer is no, then the right to a fair hearing may quietly shrink into a right to be told that no explanation is available.

The foreign intelligence problem

Suppose that within a few years most Pakistani lawyers prepare their opinions with a single foreign platform trained on Pakistani judgments, because it is faster and more thorough than any library a chamber could keep. Suppose judges begin to receive submissions shaped, in their very bones, by the same system. The judge still decides. But the frame of the argument, the choice of precedent, and the shape of the reasoning arrive already formed, from a product built and controlled in another country.

Then one ordinary morning the provider updates its model. It adjusts a safety setting, or a ranking rule, or the way it weighs one line of authority against another. Nothing in Pakistan has changed. No statute was amended. No judgment was overruled. And yet the legal analysis reaching thousands of Pakistani desks shifts overnight. Has the practical influence over how Pakistani law is read migrated, without anyone ever deciding that it should, to engineers who sit in another jurisdiction? And if it has, which provision of our own law even recognises that this has taken place?

Constitutional geography

Consider where a single disputed act actually lives. The servers sit in California. The company is incorporated in Ireland. The model was trained in Canada. Content review is performed from Singapore. The person who pressed deploy is in Lahore. The person harmed is in Karachi. The publication reaches readers in a hundred and ninety countries within minutes.

Whose constitution governs the intelligence that produced the act? This is more than the familiar business of private international law, which decides which country rules apply to a dispute that crosses borders. It is a question of constitutional geography, of where sovereign authority sits when the decisive actor is a distributed system that belongs, in any meaningful sense, to no single place at all. Pakistani law can assert jurisdiction over harm suffered inside Pakistan. Whether it can truly reach the intelligence that caused the harm is a very different question, and a far harder one.

The death of evidence

For a generation, digital evidence has meant something reassuringly solid. A phone. An email header. A recording from a camera. A log on a server. Courts learned to trust these things because forging them convincingly was difficult, and difficulty is a kind of guarantee.

That guarantee is ending. Systems now within ordinary reach can manufacture a human voice, a moving image, a signature, a contract, a photograph, a medical report, or a bank statement that a trained eye cannot tell apart from the genuine article. When any piece of digital material can be fabricated to a standard that defeats normal scrutiny, what is left of the idea of proof? What does the phrase proof beyond reasonable doubt mean in a courtroom where the most vivid evidence, the video that appears to settle everything, may be a total invention? The rules of evidence were built for a world in which seeing was, more often than not, believing. That world is closing behind us.

The constitutional black box

Bring the abstraction down to one citizen at one counter. A man asks why his visa was refused. The department answers that the system recommended refusal. He asks why the system recommended it. The department answers, truthfully, that it does not know.

Every part of that exchange may soon be ordinary. Governments across the world are adopting automated triage for taxation, immigration, land records, national identity, policing, admissions, and welfare. The efficiency is real. So is the hazard. Article 4 of the Constitution guarantees that every citizen shall be treated in accordance with law, and fair administrative action has long demanded that a decision affecting a person be capable of a reasoned explanation. Can constitutional accountability survive when the reasoning of the state itself becomes unknowable to the state? A government that cannot explain its own decisions has not grown more efficient. It has grown harder to hold to account, and that is a constitutional loss dressed as an administrative gain.

Seven questions our law has not answered

The scattered problems above share a single spine. Pakistani law knows how to deal with a human offender who acted with a guilty mind, and the world knows how to write governance rules about risk. Neither yet knows how to close the gap between them. The table below sets that gap out plainly.

The question What Pakistani law assumes What global AI rules do The gap that remains
Who is the offender when a system acts on its own? The Penal Code and the Criminal Procedure Code assume an identifiable human actor. Governance frameworks focus on risk and oversight, not criminal attribution. No accepted doctrine assigns criminal responsibility for a genuinely autonomous act.
Can a machine hold a guilty mind? Criminal law attributes mental states to persons according to statute. No jurisdiction recognises a machine as capable of criminal intent. Mens rea stays human, and the immediate actor may have none.
Can an automated system be tested like a witness? Fair trial assumes evidence that can be challenged in court. Transparency duties exist, but explainability has real technical limits. A system that cannot explain itself resists meaningful challenge.
Who is liable when an autonomous system publishes unlawful content? Liability follows established principles applied to persons and companies. No settled global model governs autonomous publication. Responsibility splits across many actors and none clearly fits.
Can the claim that the machine did it become a defence? No such defence exists in Pakistani law. No international standard defines one. Courts face a new and unresolved evidentiary dispute.
Who owns intelligence trained on public legal knowledge? Traditional rules protect works, inventions, and related rights. The global debate on training data and outputs continues. Governance of public knowledge inside private models is unsettled.
Which constitution governs a distributed act? Jurisdiction attaches to harm suffered within Pakistan. No framework resolves autonomous causation across borders. Sovereign authority over the intelligence itself is unclear.

One hundred questions before one constitutional amendment

There is a natural instinct, when a technology frightens a legislature, to reach quickly for a statute. Draft a law. Form a committee. Announce a framework. Pakistan has shown that it can move fast when it wishes, as the cybercrime amendment of 2025 made clear. But speed is not the same as wisdom, and the greater danger here is not that Pakistan legislates too slowly. The greater danger is that Pakistan legislates with complete confidence before it has understood what it is regulating.

A law written today will govern the systems of today. The constitutional crisis, if it arrives, will come with the systems of the next decade, and it will arrive quietly, with no coup and no amendment, through nothing more dramatic than a hundred million small automated suggestions gradually reshaping how a society reasons, remembers, and decides. Against a shift of that kind, a hastily drafted statute is not a shield. It is a reassurance that may turn out to be false.

So perhaps the first question for Parliament is not how artificial intelligence should be regulated. Perhaps the first question is whether we yet understand what artificial intelligence is becoming. If the honest answer is not yet, then every amendment, every licence, every committee, and every proposed safeguard risks governing the surface while the deeper change passes unnoticed underneath. This article offers no draft law and no ten point plan, and that restraint is deliberate. Before one constitutional amendment, there ought to come a hundred careful questions. These have been a few of them.

At Two Black Coats we work with founders, institutions, and public bodies on exactly these frontiers, where technology meets the Constitution and the criminal law. Our companion article on AI governance and intelligence sovereignty sets out the other half of the picture, the question of who should own and govern the intelligence a nation comes to depend upon. If your organisation is building or deploying artificial intelligence and needs advice that takes both the technology and the Constitution seriously, our technology and intellectual property team in Islamabad is ready to help. You can speak to our advocates here.

Frequently asked questions

Short answers to the questions readers ask us most about artificial intelligence, criminal responsibility, and constitutional law in Pakistan.

Back to all articles

FAQs

Frequently asked questions

Does Pakistan have a law that covers crimes committed by AI?

Not directly. Pakistan has criminal statutes such as the Pakistan Penal Code of 1860 and the Prevention of Electronic Crimes Act, amended in 2025, and these apply to people and companies. None of them was written for a situation in which an autonomous system produces an unlawful act that no person specifically intended. That gap between the assumptions of the law and the behaviour of the technology is the central problem this article examines.

Can artificial intelligence have criminal intent under Pakistani law?

No. Criminal responsibility in Pakistan depends on a guilty mind, meaning intention, knowledge, recklessness, or negligence held by a person or a legally responsible entity. A machine has no mind in that sense. The difficulty arises when the person closest to an unlawful output did not intend it and perhaps could not have foreseen it, which leaves the law searching for an actor who fits its own assumptions.

If my AI system publishes something unlawful, am I responsible?

It depends on the facts, and the law is still forming. A court will look at whether the system acted on its own or under instruction, who controlled its deployment, whether reasonable safeguards and monitoring were in place, and whether the output was intended, foreseeable, or the result of careless oversight. Keeping clear records of who authorised and configured a system, and what controls existed, will matter a great deal if a dispute arises.

What is the AI defence?

It is the claim, likely to appear more often, that an accused person did not commit an act because an autonomous system did it without instruction. The worry is that without reliable ways to test such a claim, it could shield genuine wrongdoing, while a rule that ignores it could punish people who truly took care. Pakistani evidence law does not yet provide a settled method for telling these situations apart.

How does the PECA Amendment 2025 fit into this?

The 2025 amendment added a new offence for the intentional spread of false information online and created a new authority to oversee digital content. Because that offence turns on intention and knowledge, it raises the very question this article poses. How should a court apply a standard built around a deliberate human act to content that an autonomous system produced on its own.

What should a business using AI in Pakistan do now?

Treat governance as a legal matter, not only a technical one. Record who deploys and configures each system, keep audit trails and human review for anything that can affect a person, and set clear contracts that state who is responsible for outputs. These steps do not answer the deeper constitutional questions, but they place a business in a far stronger position if an incident ever reaches a court.

Need advice on your matter?

Speak with an advocate at Two Black Coats for an honest first opinion.