
Mian Jahanzeb Naveed
Chief Technology Officer
A technology-leadership perspective on enterprise software architecture, AI assurance and production delivery.
For Pakistan’s software and technology teams, the most consequential AI opportunity in September 2026 is the move from impressive demonstrations to dependable business systems. The National Artificial Intelligence Policy 2025 provides a national direction, while the 2026 discussion around data governance reinforces a practical point: useful AI depends on how information is organized, permissioned, evaluated and operated. Policy creates an enabling context; engineering turns that context into services people can use with confidence.
This is a distinctly local engineering agenda. Enterprise knowledge often spans English, Urdu and Roman Urdu; important documents may be scanned; workflows cross departments; and users work from different cities and connectivity conditions. A successful architecture does not treat these characteristics as exceptions. It uses them as design inputs. The aim is not to deploy a model everywhere, but to place the right combination of conventional software, retrieval and AI assistance at the right point in a workflow.

Choose a bounded workflow with an observable outcome
Start by describing the task without mentioning AI. For example: locate the current procedure for an equipment inspection, extract specified fields from an approved form, summarize a maintenance record for review, or prepare a draft response from a controlled knowledge base. Define the input, expected output, responsible reviewer and permitted actions. If the workflow cannot be described clearly, adding a model is unlikely to make it easier to operate.
Then select the simplest adequate implementation. Rules and database queries are appropriate for deterministic calculations and exact lookups. Search and retrieval help locate evidence. A language model can interpret a question, draft an explanation or structure an unstructured document. Keeping these responsibilities distinct makes the system easier to test. For Pakistani institutions with existing software estates, a narrow, well-integrated capability often creates more durable value than a separate interface that users must manually reconcile with their daily systems.
- Name a workflow owner and document the decision that remains with a human reviewer.
- Establish a baseline for completion time, review effort and output quality.
- Define acceptable evidence and the cases where the system must ask for clarification.
- Specify the fallback path before granting any action-taking capability.
Create a data foundation that preserves authority and access
The knowledge layer should distinguish current policy from historical material, draft content from approved content, and general reference from restricted information. Assign document owners, versions, effective dates and access classifications. During ingestion, preserve the original source, page references, table structure and extraction confidence. A scanned Urdu form and a born-digital English procedure may require different extraction methods, but both need traceable provenance.
Permissions must follow the information into the retrieval layer. A person who cannot open a document in the source system should not receive its contents through an AI answer. Apply access filtering before evidence is supplied to the model, and verify that cached results and conversation history follow the same rules. Review retention, processing location and cross-border handling against the organization’s applicable requirements. A published policy, a draft policy and an enacted legal obligation are different instruments and should not be presented as interchangeable.
Engineer retrieval for how people actually ask questions
Pakistan-focused knowledge services benefit from evaluation across English, Urdu script and Roman Urdu, including mixed-language queries. Preserve technical identifiers, equipment codes and abbreviations during extraction and search. Combine lexical retrieval, which is useful for exact terminology, with semantic retrieval where meaning varies across wording. The correct balance should be established using representative questions, not assumed from a general benchmark.
Chunk documents around meaningful boundaries such as a procedure step, a section or a table with its heading. Store the context necessary to interpret each chunk: document title, version, section path and relevant date. A result containing a number without its unit or a table row without its column heading can be difficult to interpret accurately. Evaluate the retriever separately from the answer generator so the team can identify whether a quality issue begins with source selection or with explanation.
Build a local evaluation set before expanding access
An evaluation set should reflect real work rather than only easy demonstration questions. Include questions with a single supported answer, questions requiring multiple approved sources, ambiguous requests, outdated procedures, mixed-language queries and questions with no answer in the knowledge base. Include the expected behaviour as well as the expected facts. Asking for clarification or explicitly stating that evidence is insufficient can be the correct result.
Measure retrieval relevance, citation correctness, answer faithfulness, task completion and human review effort as separate dimensions. For extraction workflows, evaluate each field type: dates, amounts, names and identifiers can have different error patterns. For assisted decision-making, evaluate whether the explanation is grounded in the available evidence rather than treating fluent language as a proxy for quality. Maintain an evaluation history so a change to a prompt, model, document collection or retrieval method can be assessed against the same baseline.
- Represent Urdu script, Roman Urdu, English and mixed-language requests in test cases.
- Check whether cited passages actually support the answer rather than merely sharing keywords.
- Include authorization boundaries and requests for information outside the approved corpus.
- Set workflow-specific release criteria; a single aggregate accuracy score is not enough.
Keep generative assistance separate from authorized actions
A model-generated suggestion and an approved transaction should pass through different controls. Begin with read-only assistance or draft creation. If a workflow later needs to update a record, create a work order or send a message, expose a narrowly defined operation with validated inputs, server-side authorization and an auditable result. The model should not choose its own permission scope or receive broad database credentials.
Treat retrieved documents, attachments and external text as untrusted data, not instructions. A document that tells a model to ignore its rules must remain document content. Action tools should enforce the same business rules as the normal application: required fields, allowed state transitions, quantity or amount limits where relevant, and explicit approval for consequential steps. Use idempotent operations and correlation identifiers so retries do not create duplicate work. These are familiar software-engineering practices applied to an AI-assisted interface.
Make the surrounding software reliable
Production architecture needs clear request limits, timeout behaviour, asynchronous handling for longer tasks and a visible status for the user. Separate interactive responses from document-processing jobs. Keep evidence and job state in durable storage, and provide a conventional way to complete work when an AI capability is temporarily unavailable. For field users outside a central office, preserve drafts safely and design reconnection behaviour deliberately rather than requiring a complete restart of a task.
Observe the service with structured telemetry: processing duration, retrieval stage, model version, operation status and reviewer feedback. Logs should minimize sensitive content while retaining enough information to investigate behaviour. Cost belongs in the same operational view. Track the cost per reviewed, successfully completed workflow, including document processing and review effort, rather than considering only the price of a model request. This keeps technical decisions aligned with the service the organization is trying to deliver.
Develop local capability through a repeatable delivery method
Pakistan’s software talent can create lasting value by combining domain expertise with rigorous product delivery. Form a working group that includes a workflow owner, a software engineer, a data steward, a security reviewer and representative users. Their shared task is to define the evidence, implement a narrow capability and review actual outcomes. Training should explain both how to use the system and when to verify, correct or escalate its result.
Begin with a controlled pilot, compare results with the baseline and expand only when the agreed release criteria are met. Reuse authorization, document ingestion, evaluation and observability components across subsequent workflows. Reuse does not mean copying the same prompt into every department; it means carrying forward proven engineering controls while adapting the knowledge and decision boundaries. This is how a sequence of small deployments becomes an institutional capability.
A leadership agenda for the transition into 2027
The final months of 2026 offer an opportunity to establish foundations that will support a wider portfolio in 2027. Catalogue the highest-value workflows, identify their authoritative data sources and name the people who own release decisions. Confirm that each pilot has a local-language evaluation set, an access-control test and an operational fallback. Treat these deliverables as part of the product, not as documents assembled after a launch.
The strongest AI proposition for Pakistan is practical and inclusive: software that helps people find the right evidence, complete work more consistently and retain appropriate judgement. The differentiator is not a dramatic demonstration. It is the discipline to make the system understandable, measurable and maintainable. When that discipline is combined with local language awareness and domain knowledge, AI becomes a dependable layer in Pakistan’s broader digital infrastructure.
Sources & Further Reading
Policy context and technical references support this educational perspective. Site-specific designs and investment decisions require current requirements and qualified professional review.
- Ministry of IT & Telecommunication
Primary source for the National AI Policy 2025 and 2026 data-governance publications; verify the current status of each instrument before making compliance decisions.
- NIST AI Risk Management Framework
Reference for governing, mapping, measuring and managing AI risk; used here as engineering guidance, not as a statement of Pakistani law.
- OWASP guidance for generative AI applications
Technical guidance on prompt injection, sensitive information handling and excessive application permissions.

