Chapter 06 · Section II · 15 min read
What Nepal could realistically do
The honest near-term agenda is not a sovereign frontier model or a blanket ban on foreign AI — it is procurement standards, sectoral rules, a small oversight unit, impact assessments for high-risk deployments, and a data-protection law that actually has teeth.
Most Nepali commentary on AI policy oscillates between two unhelpful poles. On one side: a maximalist fantasy in which Nepal builds a sovereign large language model, declares digital independence, and joins the frontier-lab club. On the other: a defeated shrug that says the country is too small to do anything, so we should wait for the EU and India to figure it out and then port whatever they pass. Both are wrong, and they are wrong in the same way — they ignore what the existing administration in Singha Durbar can actually do this fiscal year with the staff it already has. The realistic agenda is smaller, less photogenic, and considerably more powerful. It consists of five moves, none of which require new statutes, all of which fit inside the existing institutional map.
1. Procurement standards for government AI use
The single highest-leverage move available to Nepal in 2026 is the one that requires the least legislation: write a procurement standard for any AI system the government buys, and apply it across ministries. The US example earlier in this chapter showed that procurement, when the buyer is large and consistent, becomes de facto regulation. Nepal’s government is not a large buyer on the global scale, but it is by far the largest buyer of enterprise software inside Nepal — and the vendors who win those contracts are the same vendors who then sell to banks, cooperatives, and large NGOs. A serious procurement standard would require, at minimum: data residency clauses (where do citizen data go, and under what jurisdiction); audit rights (can a Nepali regulator inspect logs, model documentation, and training-data summaries); exit clauses (what happens to the data and the model on contract termination); explainability requirements (can the vendor articulate, in plain Nepali, how the system makes decisions that affect citizens); and disclosure of subcontractors and sub-processors.
None of this is novel. Templates exist — the EU’s procurement guidance, India’s MeitY model contract clauses, the US GSA’s AI procurement playbook — and could be adapted to Nepali realities in a few months by a competent legal team. The instrument is a circular from the Public Procurement Monitoring Office, not an act of parliament.
2. Sectoral rules under the regulators that already exist
The second move is to extend, deliberately, each existing sectoral regulator’s mandate to cover AI deployments inside its domain. This is the Indian pattern and it fits Nepal because the regulators already exist and already have the substantive expertise the rules will require.
Nepal Rastra Bank is already moving here. The directives on digital lending and KYC automation that have been issued in the last two years are, in substance, AI directives — they govern credit-scoring models, anti-fraud systems, and automated identity verification. The work to do is to make this visible: a consolidated NRB circular on “AI in regulated financial services” that pulls the existing scattered guidance into one document, adds explainability and exit-clause requirements, and is published for industry consultation.
MoCIT owns the content and intermediary space. The next round of platform rules — for TikTok, Meta, the major Nepali platforms — will inevitably touch synthetic content, recommendation systems, and AI-generated political material. A modest rule, requiring provenance labelling on AI-generated content and disclosure of recommendation logic on platforms above a user threshold, is well within MoCIT’s existing authority.
The Election Commission has the narrowest but the most time-sensitive job. Federal elections are not far off. A rule on AI-generated political advertising — requiring disclosure on the ad itself, holding the political party legally liable for synthetic content it commissions or amplifies — does not need a new statute. The Commission’s existing rule-making authority over election conduct is sufficient.
The Ministry of Health is the most under-developed regulator on this list, and the most consequential. Diagnostic AI is arriving in tertiary hospitals via imaging vendors. Without a sectoral rule, the country is one mis-diagnosis away from a scandal that sets back medical AI by a decade. A minimum-viable rule — vendor disclosure of validation cohorts, mandatory clinician-in-the-loop for any AI-assisted diagnosis that triggers treatment, post-market reporting of adverse events — is overdue.
3. A small AI oversight unit inside MoCIT/NITC
The third move is the one most likely to be over-built if it is built at all. The temptation will be to propose a Nepal AI Authority — a new statutory body with a chair, commissioners, regional offices, and a logo. Resist this. What the country needs, on the evidence, is a small interdisciplinary unit — five to ten people, lodged inside MoCIT or NITC, reporting to the Secretary — whose job is to publish guidance, coordinate across the sectoral regulators, intervene on egregious deployments, and be the institutional memory for what other countries are doing. Staffed with a mix of lawyers, technologists, and a few former civil servants who know how directives actually move, such a unit could shape more policy in a year than a new authority could shape in five, because it would not have to spend its first three years setting up its own administrative apparatus.
The unit would not regulate directly. It would advise the regulators who do, draft the model clauses they reuse, run the cross-sector workshops, and maintain the public registry of consequential government AI deployments. It would, in effect, be the country’s AI policy memory and translation layer.
4. Impact assessments for high-risk deployments
The fourth move is to require — by directive, not statute — that any new government AI deployment touching a defined set of high-risk domains undergo a written impact assessment before procurement closes. The high-risk list should be short and specific: CCTV with facial recognition; automated benefits adjudication; predictive policing or any pre-crime scoring; AI-assisted medical diagnosis; AI-assisted educational assessment that determines pass-fail or placement; and any system that produces a score or risk band attached to a citizen’s national ID. The assessment itself need not be elaborate — ten to fifteen pages — but it must answer specific questions: what data the system was trained on, what its known failure modes are on Nepali populations, what human review process exists, and what the appeal mechanism is for a citizen who believes they have been wrongly classified.
5. Data-protection legislation that actually has teeth
The fifth move is the one piece that does need legislation: pass the Data Protection Bill, and pass it with a regulator that has real audit authority and real penalty powers. The previous chapter on privacy made the point in detail. What matters here is that the other four moves degrade into theatre without the baseline. Procurement clauses on “data residency” mean little if no regulator can inspect whether the vendor actually complied. Sectoral rules on “explainability” mean little if a citizen who challenges a decision has no statutory right to demand the explanation. The impact assessments are paper exercises if no one is empowered to read them and act on what they find. The Bill is the keystone. Without it, the other four moves are masonry waiting on an arch.
What is not on this list, and why
A working agenda is defined as much by what it refuses as by what it includes. Three large items belong on the refused list. A sovereign Nepali frontier model. Training a frontier model costs hundreds of millions of dollars and access to an order of magnitude more GPUs than Nepal will sensibly own this decade. The opportunity cost — talent, capital, political attention — is enormous, and the result, if it ever shipped, would be a worse version of something already free at the API. A blanket ban on foreign AI products. This protects domestic incumbents, harms citizens who lose access to genuinely useful tools, and creates rent-seeking opportunities for whoever gets the import licence. A National AI Strategy as a glossy document. Several drafts of this exist already. None has moved a single line of regulation. The strategy document is the displacement activity that lets the country feel it is acting on AI without acting on AI.
The unflattering truth is that good AI policy in Nepal will look small. It will be a circular, a directive, a procurement template, a five-person unit, a passed bill. It will not be a press conference. It will be more powerful than the press conference.
Check your understanding
Quick check
—A senior MoCIT official asks for the single most realistic and high-leverage AI policy move Nepal could make in the next twenty-four months, given existing administrative capacity. Which answer best fits?
What comes next
Policy is one half of the story. The other half — the half most readers can actually act on tomorrow morning — is personal. The closing section of the course asks what a thoughtful Nepali student, professional, parent, or citizen can hold themselves to in the day-to-day use of these tools, while the policy machinery grinds slowly in Singha Durbar.