Artificial Intelligence in New Zealand

Regulatory guidance / voluntary codes in New Zealand

Guidance from the Office of the Privacy Commissioner

The OPC issued the Artificial intelligence and the Information Privacy Principles in September 2023 (OPC AI Guidance) which provides non-binding guidance on compliance with the Information Privacy Principles (the key obligations under the Privacy Act) when adopting AI-enabled solutions. The OPC AI Guidance builds on the OPC’s Generative Artificial Intelligence guidance dated June 2023 (OPC Gen AI Guidance).

At a high-level, the OPC AI Guidance:

  • recommends undertaking a Privacy Impact Assessment before deploying AI;
  • emphasises the importance of good governance, which requires involvement of senior leadership;
  • highlights the importance of transparency and explainability, accuracy, robustness and security, accountability, and human values and fairness. Also consistent with international regulation is the OPC's call for a 'privacy-by-design' approach to implementing AI;
  • identifies a need to consider te ao Māori perspectives on privacy (broadly, te ao Māori is the Māori worldview including tikanga Māori - Māori customs and protocols). Specific concerns identified in the OPC AI Guidance include:
    • bias from systems developed overseas that do not work accurately for Māori;
    • collection of Māori information without work to build relationships of trust, leading to inaccurate representation of Māori taonga that fail to uphold tapu and tikanga; and
    • exclusion from processes and decisions of building and adopting AI tools that affect Māori whānau, hapĹŤ, and iwi, including use of these tools by the public sector; and
  • identifies some use cases for AI as higher-risk, requiring more care, for example, the use of AI tools for automated decision-making.

The OPC continues to monitor risks raised by AI use, including calling for Privacy Act modernisation to address automated decision-making in its 2025 Annual Report, and joining international statements on trustworthy AI data governance and AI generated imagery.

For more information on the OPC AI Guidance, see DLA Piper's update here: New Zealand's Privacy Commissioner follows global trends with latest guidance on AI | DLA Piper.

New Zealand Government Cabinet Paper

The then Minister of Science, Innovation and Technology – Hon Judith Collins KC published the Approach to work on Artificial Intelligence Cabinet paper in July 2024, seeking agreement from Cabinet’s Economic Policy Committee on a strategic approach for New Zealand’s use of AI. The Minister proposed a ‘light-touch, proportionate and risk-based approach to AI regulation’. The approach would leverage existing laws as guardrails and only introduce new regulation to ‘unlock innovation or address acute risks’. Cabinet has focused on the following five key domains:

  • setting a strategic approach to AI;
  • enabling safe AI innovation in the public service;
  • harnessing AI in the New Zealand economy (with the Ministry of Business, Innovation and Employment (MBIE) instructed to formulate OPC AI guidance for firms to utilise);
  • prioritising engagement on international rules and norms; and
  • coordinating with work on national security.

OECD AI Principles

The New Zealand Government has adopted the Organisation for Economic Co-operation and Development (OECD) AI Principles adopted in 2019 and updated in 2024 (OECD AI Principles) to guide the development of trustworthy, innovative, and democratic AI in New Zealand, aligning with other OECD member states.

National AI Strategy

In July 2025, the New Zealand Government released New Zealand’s Strategy for Artificial Intelligence: Investing with confidence (AI Strategy) aiming to accelerate private sector AI adoption and innovation. The AI Strategy commits to stable and enabling policy for AI, involving a light-touch and principles-based approach that relies on existing legislation and the OECD AI Principles. In the AI Strategy, the Government outlines that it will reduce barriers to adoption, provide clear regulatory guidance, build necessary capabilities, and ensure that adoption occurs responsibly. The AI Strategy emphasises the opportunities in AI adoption and application rather than foundational AI development.

MBIE published a Responsible AI Guidance for Businesses (AI Guidance for Business) alongside the AI Strategy to assist with its practical application. The AI Guidance for Business is a non-binding guide of good practices and actions that can support businesses to adopt AI. It identifies and discusses various types of considerations for businesses using or developing AI systems, including risks to cybersecurity, privacy, human rights, workplace culture, the environment, intellectual property and creators, and physical safety.

For more information on the AI Strategy and AI Guidance for Business, see DLA Piper's update here: Quick on the uptake? New Zealand’s new strategic approach to Artificial Intelligence.

AI guidance for regulators

The New Zealand Government has released Responsible AI in Action guidance for senior leaders and management teams in regulatory organisations (Regulatory AI Guidance). It focuses specifically on best practice for AI use in the regulatory context, where decisions affect rights, obligations, and public confidence. The Regulatory AI Guidance emphasises that AI should facilitate, but not replace, careful judgement, legal interpretation, and discretion when making decisions that affect people's rights and public trust.

The core advice for regulators in the Regulatory AI Guidance is to:

  • treat AI as a regulatory capability, not an IT project;
  • scale governance and oversight to reflect risks;
  • use AI to support human judgement, not replace it; and
  • ensure AI use meets high ethical standards that reflect the rights, safety and livelihoods impacted by regulatory decisions.

Public Service AI Framework

The New Zealand Government has introduced the Public Service AI Framework (Framework) to guide the responsible use of AI across the public sector. As with the Regulatory AI Guidance, while not legally binding, the Framework sets out best practice principles for AI adoption. Its vision is the responsible adoption of AI ‘to modernise public services and deliver better outcomes for all New Zealanders.’

The Framework is guided by five AI principles:

  • Inclusive, sustainable development â€“ Public Service AI systems should contribute to inclusive growth, sustainable development and the reduction of economic, social, gender and other inequalities, including by reference to access to technology.
  • Human-centred values â€“ Public Service AI should respect the rule of law, democratic values, human and labour rights, including personal data protection and privacy, ensuring ethical and appropriate use.
  • Transparency and explainability â€“ Those using, or interacting with, Public Service AI should be aware of, and understand, how the Public Service is using that AI. Public Service agencies should therefore disclose when AI is used, how those systems were developed and how they affect outcomes.
  • Security and safety â€“ The security of customers and staff is a core business requirement. Public Service AI should apply a robust risk management approach and ensure the traceability of data.
  • Accountability – Public Service AI should be subject to oversight. Capability should therefore keep up with technological changes, including to relevant regulatory and governance frameworks.

The Framework's principles are informed by the OECD AI Principles, as well as the UK's Generative AI Framework for HMG dated January 2024 (but since withdrawn), the Algorithm Charter for Aotearoa New Zealand dated July 2020, and the AI Forum AI Principles dated March 2020.

The Government Chief Digital Officer is leading a Public Service AI work programme to support the implementation of the Framework’s vision while working closely with MBIE to compile a cross-portfolio policy work programme. The programme is guided by six pillars:

  • Governance â€“ supporting transparency and human accountability in Public Service AI use.
  • Guardrails â€“ enabling safe and responsible Public Service AI use.
  • Capability â€“ building internal and external AI knowledge and skills.
  • Innovation â€“ providing pathways that enable safe AI testing and innovation.
  • Social licence â€“ ensuring New Zealanders have trust and confidence in Public Service AI use.
  • Global voice â€“ ensuring international counterparts see New Zealand as a trusted AI partner.

Public Service Generative AI Guidance

The New Zealand Government published the Responsible AI Guidance for the Public Service: GenAI dated February 2025 (GenAI Guidelines) to support the New Zealand Public Service to explore generative AI systems in ways that are safe, transparent and responsible. The GenAI Guidelines outline foundational aspects of supporting public sector agencies in the utilisation and adoption of generative AI and give examples of how each aspect can be implemented.

Key considerations are also highlighted about generative AI systems which affect customer experience with the New Zealand Government and include transparency, accessibility, ethical considerations to address bias, Māori and indigenous data considerations, and privacy. Public Service agencies are expected to ensure transparency and accountability in their use of generative AI, enhance employee skills and capabilities, and follow best practices in procurement to align generative AI solutions with business needs and regulatory compliance.

AI Forum publications

The Artificial Intelligence Forum of New Zealand - Te Kāhui Atamai Iahiko o Aotearoa (AI Forum) released its AI Blueprint for Aotearoa: a refreshed vision to 2030 dated May 2026, designed as a practical roadmap for how Aotearoa can become a global leader in innovative, responsible and inclusive AI, and is globally recognised for harnessing the power of AI for the benefit of all. It proposes a focus on education, social licence and trust, and infrastructure. The AI Forum also released its Trustworthy AI in Aotearoa AI Principles dated March 2020 (AI Forum AI Principles). The AI Forum AI Principles are organised under five subheadings, namely: fairness and justice; reliability, security and privacy; transparency; human oversight and accountability; and wellbeing.

Other Regulatory and Sectoral Guidance

Various other regulators have published sector guidance on AI, including:

  • The Financial Markets Authority (FMA) has published sector research on AI in financial services dated September 2024, an opinion piece on good governance for AI dated February 2025, guidance on cyber-resilience and digital advice services, and issued public warnings regarding AI-enabled deepfake investment scams dated April 2026;
  • The Ministry of Justice published guidelines for the use of generative AI in Courts and Tribunals, dated December 2023. Similarly, the New Zealand Law Society published Generative AI guidance for lawyers and a report on Strengthening the rule of law in Aotearoa New Zealand. When utilising automated decision-making systems in dispute resolution and the delivery of justice, the latter report recommends stronger safeguards to reduce the unintended consequences and protect trust and confidence in the rule of law in New Zealand;
  • Parliament’s Economic Development, Science and Innovation Committee reported to Parliament in April 2026 on the public service's adoption of AI, AI guidance for businesses, the ‘light-touch’ approach to legislating AI, and the ethics of using AI in New Zealand. This included a key recommendation that Parliament stay alert to the novel challenges of AI, particularly in the context of legislative development; and
  • The Government Communications Security Bureau issued a joint statement with Five Eyes partners calling for a whole-of-organisation and whole-of-society response to the evolving cyber risk landscape driven by frontier AI, dated June 2026. New Zealand is a member of the Five Eyes security partnership alongside Australia, Canada, the United Kingdom, and the United States.

Biometric Processing Privacy Code 2025

The Biometric Processing Privacy Code 2025 (Biometrics Code) is a binding code of practice under the Privacy Act that came into force on 3 November 2025 (with a compliance transition period for agencies already using biometrics until 3 August 2026). The Biometrics Code regulates the collection, storage and use of biometric information for automated biometric processing (for example, verification, identification, and categorisation). Key features include requirements for effectiveness and proportionality assessments, safeguards to reduce privacy risk, transparency obligations, safe limits on highly intrusive uses (including health, emotion or attention prediction), and a prohibition on discriminatory biometric categorisation except in limited circumstances. The Biometrics Code is enforceable by the OPC under the Privacy Act’s complaints and compliance mechanisms.

Reserve Bank of New Zealand reports

The RBNZ issued its Financial Stability Report dated May 2026 (Report), which included a special topic "Rise of the machines – How could artificial intelligence impact financial stability?" (Special Topic).

The Report outlines that the adoption of AI could amplify risks in the financial sector and states that regulated entities are expected to maintain cyber-security strategies and frameworks that adequately address cyber threats.

The Special Topic outlines the use of AI within the financial sector, explores its potential benefits and challenges, provides an overview of the evolving regulatory landscape, and identifies AI-driven risks to financial stability, including errors, data privacy concerns, market distortions, and increased exposure to cyber attacks, all of which could amplify existing systemic risks.

Additionally, the Special Topic flags current and upcoming legislation and binding standards that are or will be relevant to mitigating AI-driven risks. These include:

  • the proposed Risk Management Standard and Operational Resilience Standards for deposit takers, slated to take effect in 2028; and
  • the Financial Markets (Conduct of Institutions) Amendment Act 2022 (commonly known as CoFI), which came into effect in full in March 2025 and aims to ensure that financial institutions treat consumers fairly. The RBNZ considers that this serves as an important framework for regulating the conduct risk associated with AI.

Continue reading

  • no results

Previous topic
Back to top