@Oscar can most probably confirm / deny this
Nothing to confirm nor deny - the issue isn't compatibility with the protocol but with keys generated
link-17 is mix of Link-16 and Link-22. But message compatibility does not translate to whether the PAF has (whether by their own or OEM agreement) decided to keep the keys for the two pieces of the net apart.
There are benefits to that as well - Link-16 is shared - Link-17 is proprietary. Pakistan does not invent Link-16 crypto on its own and runs an approved key mgmt which then they fill through using AN/PYQ-10C systems.
Now this is assumption and I cannot say for certain - but there are mechanisms that could be part of wider PAF(or OEM) security concerns on isolating the two subnets within the wider PAF net(
or rather Link-16 is the subnet within Link-17 or its current successor).
Because of how sensitive Link-16 is as it is still primary used net even with additional links within NATO you likely signed agreements to:
1. Allow the U.S. to
observe and verify compliance with FMS. This means recurring
on-site inventories, physical security reviews, and key-control checks. We already know that this happens for US hardware(
and on a side note why no one in the US who isnt looking for a quick buck will every echo Indian claims on F-16s.. because the US audits them regularly 
)
2. Key generation and key usage within terminals as to be kept modernized(part of the recent upgrade package) to be relevant. Which means without support - loaded keys and fielded jets can keep working for a while until it starts hitting reliability and sustainment issues. So, you can still fly against enemies - just not effectively for too long.
3. If you digested Link-16 directly within Link-17 terminals - and if the key material is U.S.-releasable Link-16 COMSEC that Washington holds (lets say even if used during a coalition exercise) then basically that potentially opens your national network wide open. VERY UNLIKELY BUT I AM GIVING THIS HERE AS A REASON
4. Lets say if nodes (which theoretically can) run BOTH link-16 and 17, and basically copy paste information from one message to another for the lack of a better analogy you have another leak.
By using a gateway - you also add a separation layer - keep everything secure even if it adds a small(negligible in overall context) latency.
Considering the paranoia the military has about US access to the net - making it a primary "adversary" in red vs blue infosec scenarios - to my read what the competent could do - they have done - now it is up to adversaries of Pakistan to exploit what the incompetent left open or the dishonest can open.