Artificial Intelligence in New Zealand
Regulatory guidance / voluntary codes in New Zealand
Law / proposed law in New Zealand
Laws specifically addressing AI have not been introduced in New Zealand, and, based on the current Government's recent policy decisions in respect of AI, New Zealand is unlikely to see any economy-wide specific AI legislative reforms in the foreseeable future. Instead, AI is regulated through existing technology-neutral laws, such as the Privacy Act 2020 (Privacy Act), consumer protection laws, and New Zealand's intellectual property and human rights legislation.
Regulatory guidance / voluntary codes in New Zealand
Guidance from the Office of the Privacy Commissioner
The OPC issued the Artificial intelligence and the Information Privacy Principles in September 2023 (OPC AI Guidance) which provides non-binding guidance on compliance with the Information Privacy Principles (the key obligations under the Privacy Act) when adopting AI-enabled solutions. The OPC AI Guidance builds on the OPCâs Generative Artificial Intelligence guidance dated June 2023 (OPC Gen AI Guidance).
At a high-level, the OPC AI Guidance:
- recommends undertaking a Privacy Impact Assessment before deploying AI;
- emphasises the importance of good governance, which requires involvement of senior leadership;
- highlights the importance of transparency and explainability, accuracy, robustness and security, accountability, and human values and fairness. Also consistent with international regulation is the OPC's call for a 'privacy-by-design' approach to implementing AI;
- identifies a need to consider te ao MÄori perspectives on privacy (broadly, te ao MÄori is the MÄori worldview including tikanga MÄori - MÄori customs and protocols). Specific concerns identified in the OPC AI Guidance include:
- bias from systems developed overseas that do not work accurately for MÄori;
- collection of MÄori information without work to build relationships of trust, leading to inaccurate representation of MÄori taonga that fail to uphold tapu and tikanga; and
- exclusion from processes and decisions of building and adopting AI tools that affect MÄori whÄnau, hapĹŤ, and iwi, including use of these tools by the public sector; and
- identifies some use cases for AI as higher-risk, requiring more care, for example, the use of AI tools for automated decision-making.
The OPC continues to monitor risks raised by AI use, including calling for Privacy Act modernisation to address automated decision-making in its 2025 Annual Report, and joining international statements on trustworthy AI data governance and AI generated imagery.
For more information on the OPC AI Guidance, see DLA Piper's update here: New Zealand's Privacy Commissioner follows global trends with latest guidance on AI | DLA Piper.
New Zealand Government Cabinet Paper
The then Minister of Science, Innovation and Technology â Hon Judith Collins KC published the Approach to work on Artificial Intelligence Cabinet paper in July 2024, seeking agreement from Cabinetâs Economic Policy Committee on a strategic approach for New Zealandâs use of AI. The Minister proposed a âlight-touch, proportionate and risk-based approach to AI regulationâ. The approach would leverage existing laws as guardrails and only introduce new regulation to âunlock innovation or address acute risksâ. Cabinet has focused on the following five key domains:
- setting a strategic approach to AI;
- enabling safe AI innovation in the public service;
- harnessing AI in the New Zealand economy (with the Ministry of Business, Innovation and Employment (MBIE) instructed to formulate OPC AI guidance for firms to utilise);
- prioritising engagement on international rules and norms; and
- coordinating with work on national security.
OECD AI Principles
The New Zealand Government has adopted the Organisation for Economic Co-operation and Development (OECD) AI Principles adopted in 2019 and updated in 2024 (OECD AI Principles) to guide the development of trustworthy, innovative, and democratic AI in New Zealand, aligning with other OECD member states.
National AI Strategy
In July 2025, the New Zealand Government released New Zealandâs Strategy for Artificial Intelligence: Investing with confidence (AI Strategy) aiming to accelerate private sector AI adoption and innovation. The AI Strategy commits to stable and enabling policy for AI, involving a light-touch and principles-based approach that relies on existing legislation and the OECD AI Principles. In the AI Strategy, the Government outlines that it will reduce barriers to adoption, provide clear regulatory guidance, build necessary capabilities, and ensure that adoption occurs responsibly. The AI Strategy emphasises the opportunities in AI adoption and application rather than foundational AI development.
MBIE published a Responsible AI Guidance for Businesses (AI Guidance for Business) alongside the AI Strategy to assist with its practical application. The AI Guidance for Business is a non-binding guide of good practices and actions that can support businesses to adopt AI. It identifies and discusses various types of considerations for businesses using or developing AI systems, including risks to cybersecurity, privacy, human rights, workplace culture, the environment, intellectual property and creators, and physical safety.
For more information on the AI Strategy and AI Guidance for Business, see DLA Piper's update here: Quick on the uptake? New Zealandâs new strategic approach to Artificial Intelligence.
AI guidance for regulators
The New Zealand Government has released Responsible AI in Action guidance for senior leaders and management teams in regulatory organisations (Regulatory AI Guidance). It focuses specifically on best practice for AI use in the regulatory context, where decisions affect rights, obligations, and public confidence. The Regulatory AI Guidance emphasises that AI should facilitate, but not replace, careful judgement, legal interpretation, and discretion when making decisions that affect people's rights and public trust.
The core advice for regulators in the Regulatory AI Guidance is to:
- treat AI as a regulatory capability, not an IT project;
- scale governance and oversight to reflect risks;
- use AI to support human judgement, not replace it; and
- ensure AI use meets high ethical standards that reflect the rights, safety and livelihoods impacted by regulatory decisions.
Public Service AI Framework
The New Zealand Government has introduced the Public Service AI Framework (Framework) to guide the responsible use of AI across the public sector. As with the Regulatory AI Guidance, while not legally binding, the Framework sets out best practice principles for AI adoption. Its vision is the responsible adoption of AI âto modernise public services and deliver better outcomes for all New Zealanders.â
The Framework is guided by five AI principles:
- Inclusive, sustainable development â Public Service AI systems should contribute to inclusive growth, sustainable development and the reduction of economic, social, gender and other inequalities, including by reference to access to technology.
- Human-centred values â Public Service AI should respect the rule of law, democratic values, human and labour rights, including personal data protection and privacy, ensuring ethical and appropriate use.
- Transparency and explainability â Those using, or interacting with, Public Service AI should be aware of, and understand, how the Public Service is using that AI. Public Service agencies should therefore disclose when AI is used, how those systems were developed and how they affect outcomes.
- Security and safety â The security of customers and staff is a core business requirement. Public Service AI should apply a robust risk management approach and ensure the traceability of data.
- Accountability â Public Service AI should be subject to oversight. Capability should therefore keep up with technological changes, including to relevant regulatory and governance frameworks.
The Framework's principles are informed by the OECD AI Principles, as well as the UK's Generative AI Framework for HMG dated January 2024 (but since withdrawn), the Algorithm Charter for Aotearoa New Zealand dated July 2020, and the AI Forum AI Principles dated March 2020.
The Government Chief Digital Officer is leading a Public Service AI work programme to support the implementation of the Frameworkâs vision while working closely with MBIE to compile a cross-portfolio policy work programme. The programme is guided by six pillars:
- Governance â supporting transparency and human accountability in Public Service AI use.
- Guardrails â enabling safe and responsible Public Service AI use.
- Capability â building internal and external AI knowledge and skills.
- Innovation â providing pathways that enable safe AI testing and innovation.
- Social licence â ensuring New Zealanders have trust and confidence in Public Service AI use.
- Global voice â ensuring international counterparts see New Zealand as a trusted AI partner.
Public Service Generative AI Guidance
The New Zealand Government published the Responsible AI Guidance for the Public Service: GenAI dated February 2025 (GenAI Guidelines) to support the New Zealand Public Service to explore generative AI systems in ways that are safe, transparent and responsible. The GenAI Guidelines outline foundational aspects of supporting public sector agencies in the utilisation and adoption of generative AI and give examples of how each aspect can be implemented.
Key considerations are also highlighted about generative AI systems which affect customer experience with the New Zealand Government and include transparency, accessibility, ethical considerations to address bias, MÄori and indigenous data considerations, and privacy. Public Service agencies are expected to ensure transparency and accountability in their use of generative AI, enhance employee skills and capabilities, and follow best practices in procurement to align generative AI solutions with business needs and regulatory compliance.
AI Forum publications
The Artificial Intelligence Forum of New Zealand - Te KÄhui Atamai Iahiko o Aotearoa (AI Forum) released its AI Blueprint for Aotearoa: a refreshed vision to 2030 dated May 2026, designed as a practical roadmap for how Aotearoa can become a global leader in innovative, responsible and inclusive AI, and is globally recognised for harnessing the power of AI for the benefit of all. It proposes a focus on education, social licence and trust, and infrastructure. The AI Forum also released its Trustworthy AI in Aotearoa AI Principles dated March 2020 (AI Forum AI Principles). The AI Forum AI Principles are organised under five subheadings, namely: fairness and justice; reliability, security and privacy; transparency; human oversight and accountability; and wellbeing.
Other Regulatory and Sectoral Guidance
Various other regulators have published sector guidance on AI, including:
- The Financial Markets Authority (FMA) has published sector research on AI in financial services dated September 2024, an opinion piece on good governance for AI dated February 2025, guidance on cyber-resilience and digital advice services, and issued public warnings regarding AI-enabled deepfake investment scams dated April 2026;
- The Ministry of Justice published guidelines for the use of generative AI in Courts and Tribunals, dated December 2023. Similarly, the New Zealand Law Society published Generative AI guidance for lawyers and a report on Strengthening the rule of law in Aotearoa New Zealand. When utilising automated decision-making systems in dispute resolution and the delivery of justice, the latter report recommends stronger safeguards to reduce the unintended consequences and protect trust and confidence in the rule of law in New Zealand;
- Parliamentâs Economic Development, Science and Innovation Committee reported to Parliament in April 2026 on the public service's adoption of AI, AI guidance for businesses, the âlight-touchâ approach to legislating AI, and the ethics of using AI in New Zealand. This included a key recommendation that Parliament stay alert to the novel challenges of AI, particularly in the context of legislative development; and
- The Government Communications Security Bureau issued a joint statement with Five Eyes partners calling for a whole-of-organisation and whole-of-society response to the evolving cyber risk landscape driven by frontier AI, dated June 2026. New Zealand is a member of the Five Eyes security partnership alongside Australia, Canada, the United Kingdom, and the United States.
Biometric Processing Privacy Code 2025
The Biometric Processing Privacy Code 2025 (Biometrics Code) is a binding code of practice under the Privacy Act that came into force on 3 November 2025 (with a compliance transition period for agencies already using biometrics until 3 August 2026). The Biometrics Code regulates the collection, storage and use of biometric information for automated biometric processing (for example, verification, identification, and categorisation). Key features include requirements for effectiveness and proportionality assessments, safeguards to reduce privacy risk, transparency obligations, safe limits on highly intrusive uses (including health, emotion or attention prediction), and a prohibition on discriminatory biometric categorisation except in limited circumstances. The Biometrics Code is enforceable by the OPC under the Privacy Actâs complaints and compliance mechanisms.
Reserve Bank of New Zealand reports
The RBNZ issued its Financial Stability Report dated May 2026 (Report), which included a special topic "Rise of the machines â How could artificial intelligence impact financial stability?" (Special Topic).
The Report outlines that the adoption of AI could amplify risks in the financial sector and states that regulated entities are expected to maintain cyber-security strategies and frameworks that adequately address cyber threats.
The Special Topic outlines the use of AI within the financial sector, explores its potential benefits and challenges, provides an overview of the evolving regulatory landscape, and identifies AI-driven risks to financial stability, including errors, data privacy concerns, market distortions, and increased exposure to cyber attacks, all of which could amplify existing systemic risks.
Additionally, the Special Topic flags current and upcoming legislation and binding standards that are or will be relevant to mitigating AI-driven risks. These include:
- the proposed Risk Management Standard and Operational Resilience Standards for deposit takers, slated to take effect in 2028; and
- the Financial Markets (Conduct of Institutions) Amendment Act 2022 (commonly known as CoFI), which came into effect in full in March 2025 and aims to ensure that financial institutions treat consumers fairly. The RBNZ considers that this serves as an important framework for regulating the conduct risk associated with AI.
Appointed supervisory authority in New Zealand
New Zealand does not have a dedicated AI regulator. Oversight of AI-related matters is distributed across existing sectoral regulators where their mandate interacts with AI, including the Office of the Privacy Commissioner (OPC) (privacy and personal information), the Financial Markets Authority (financial services), and the Commerce Commission (consumer protection). Other bodies with relevant sectoral mandates include the Human Rights Commission, and the Reserve Bank of New Zealand (RBNZ) (prudential oversight), as well as industry governance bodies with profession-specific oversight, such as the New Zealand Law Society.
In the public service, the Government Chief Digital Officer coordinates AI policy. Recently, Te Aka Matua o te Ture (the New Zealand Law Commission) has been instructed by the Minister of Justice to review the legal issues related to the use of automated decision-making by government. This is a significant instruction as Te Aka Matua o te Ture is an independent, statutory body established to advise on and review legislation.
More generally, New Zealandâs regulatory approach remains principles-based and light-touch, with no immediate plans for a dedicated AI regulator. The July 2024 Cabinet Paper and July 2025 AI Strategy (each discussed in the Regulatory Guidance / Voluntary Codes section) confirmed the Governmentâs preference for leveraging existing regulatory frameworks rather than introducing economy-wide AI-specific legislation.
Definitions in New Zealand
As there is no AI-specific legislation in New Zealand, there are no relevant statutory definitions. As New Zealand is an adherent to the OECD AI Principles, the definition of âAI systemâ in those principles is relevant â namely
<blockquoteâAn AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment.â
This is the definition used in the AI Strategy, the Framework, the AI Guidance for Business, and the GenAI Guidelines.
The OPC AI Guidance broadly defines AI as computer systems where one or more of the following applies:
- machine learning systems developed or refined by processing training data;
- classifier systems used to put information into categories (e.g., captioning images);
- interpreter systems that turn noisy input data into standardised outputs (e.g., deciding what words are present in speech or handwriting);
- generative systems used to create text, images, computer code, or something else; and/or
- automation where computers take on tasks that people have done up until recently.
Prohibited activities in New Zealand
Laws specifically addressing AI have not been introduced in New Zealand yet. However, the Biometrics Code prohibits certain biometric processing activities by placing âsafe limitsâ on highly intrusive uses of biometrics, including predicting health, emotion or attention, or categorising into categories protected by the Human Rights Act 1993 (e.g., sex, race, age, disability). Although the Biometrics Code is not AI-specific, it imposes strict requirements around the deployment of AI-powered biometric systems.
Separately, the Crimes Act 1961 and Harmful Digital Communications Act 2015 create criminal offences for causing harm by posting digital communications and posting intimate visual recordings without consent, which is relevant to AI-generated harmful content. However, âdeepfakeâ images do not clearly fall within this definition. The Deepfake Digital Harm and Exploitation Bill is progressing through Parliament and proposes to expand these provisions to cover created or synthesised intimate images.
High-risk AI in New Zealand
As mentioned in the Prohibited Activities section, laws specifically addressing AI have not been introduced in New Zealand yet, so no AI uses are expressly classified as high-risk by statute. However, several frameworks identify higher-risk use cases. The non-binding OPC AI Guidance identifies the use of AI tools for automated decision-making as being higher-risk, given the potential for the use to have direct impacts on outcomes for individuals. The Biometrics Code effectively treats certain biometric uses as high-risk by imposing âsafe limitsâ on highly intrusive practices, as discussed in the Prohibited Activities section. The OPCâs 2025 Annual Report called for Privacy Act modernisation to introduce stronger protections for automated decision-making, including addressing inaccuracy, discrimination and explainability, though no amendments have been proposed by legislators. Finally, the use of AI in the public sector is receiving increasing attention, particularly in automated decision-making in regulatory contexts.
Controls on generative AI in New Zealand
Laws specifically addressing AI have not been introduced in New Zealand yet, so there are no statutory controls on the use of generative AI.
The GenAI Guidelines (summarised in the Regulatory Guidance / Voluntary Codes section) are relevant for the New Zealand public sector's use of generative AI tools.
Additionally, the OPC Gen AI Guidance summarises privacy risks arising from the use of generative AI, which organisations subject to the Privacy Act are expected to appropriately mitigate. The risks identified are:
- privacy risks associated with the training data used by generative AI (e.g., how it was collected and whether it was collected with sufficient transparency);
- confidentiality of information entered into generative AI tools;
- accuracy of personal information created by generative AI; and
- individuals' ability to exercise their data subject rights to access and correction of their personal information held in or processed by generative AI tools.
Enforcement / fines in New Zealand
Laws specifically addressing AI have not been introduced in New Zealand yet, so there are no AI-specific enforcement regimes or fines. However, enforcement and fines under existing legislation could be applied in the AI context. Under the Privacy Act, the Privacy Commissioner may issue compliance notices and issue fines up to NZD 10,000 for certain breaches (for example, for a failure to notify a notifiable privacy breach to the Privacy Commissioner) and refer matters to the Human Rights Review Tribunal. The Biometrics Code is enforceable under the Privacy Actâs complaints and compliance mechanisms. The Human Rights Act 1993 provides for complaints to the Human Rights Commission and proceedings before the Human Rights Review Tribunal, and the Tribunal can award damages for privacy breaches. The Fair Trading Act 1986 and Commerce Act 1986 provide for pecuniary penalties, injunctions, and compensation orders. The FMA has enforcement powers under the Financial Markets Conduct Act 2013. The Harmful Digital Communications Act 2015 creates criminal offences with penalties including imprisonment of up to two years and fines of up to NZD 50,000 for individuals or NZD 200,000 for bodies corporate.
User transparency in New Zealand
Laws specifically addressing AI have not been introduced in New Zealand yet, so there are no specific AI transparency requirements. However, the OPC AI Guidance highlights the importance of transparency when using AI tools in order to mitigate the risk of breaching Information Privacy Principle 3 of the Privacy Act. The AI Guidance for Business provides a transparency checklist for businesses to disclose their AI use. Additionally, the Privacy Amendment Act 2025 introduced Information Privacy Principle 3A (IPP 3A), which came into effect on 1 May 2026 and requires agencies that collect personal information indirectly (i.e., from a source other than the individual concerned) to inform the individual of that collection, unless an exception applies. While not AI-specific, IPP 3A enhances transparency obligations relevant to AI systems that collect or process personal information from third-party sources.
Fairness / unlawful bias in New Zealand
Laws specifically addressing AI have not been introduced in New Zealand yet, so there are no AI-specific fairness or unlawful bias requirements. Fairness and unlawful bias requirements under existing legislation could be applied in the AI context, such as the Human Rights Act 1993 (Human Rights Act). While it does not specifically regulate AI, the Human Rights Act is to be read as applying as widely as possible to protect human rights. Therefore, if an AI decision is ultimately attributable to a company or public body, the Human Rights Act would apply to that decision and create an obligation to ensure that decision is not discriminatory. The Biometrics Code reinforces this by prohibiting the use of biometric systems to categorise individuals into classes corresponding to the prohibited discrimination grounds in section 21(1) of the Human Rights Act, except in limited circumstances. Additionally, the OPC AI Guidance and AI Guidance for Business both emphasise fairness and bias mitigation as key considerations for responsible AI deployment.
Human oversight in New Zealand
Laws specifically addressing AI have not been introduced in New Zealand yet, so there are no statutory human oversight requirements. However, the OPC AI Guidance states the importance of developing processes for the human review of AI decisions, and to empower and adequately resource the people conducting these reviews. Both the OPC AI Guidance and the AI Guidance for Business highlight the importance of human oversight where automated decision-making has direct impacts on the outcomes of people. Both also warn that having a âhuman in the loopâ may not be sufficient to uphold the accuracy principle due to the risk of automation blindness. On this topic, the AI Guidance for Business concludes with a reminder that businesses are responsible for their decisions, regardless of the supporting technology used.
Guidance from the Office of the Privacy Commissioner
The OPC issued the Artificial intelligence and the Information Privacy Principles in September 2023 (OPC AI Guidance) which provides non-binding guidance on compliance with the Information Privacy Principles (the key obligations under the Privacy Act) when adopting AI-enabled solutions. The OPC AI Guidance builds on the OPCâs Generative Artificial Intelligence guidance dated June 2023 (OPC Gen AI Guidance).
At a high-level, the OPC AI Guidance:
- recommends undertaking a Privacy Impact Assessment before deploying AI;
- emphasises the importance of good governance, which requires involvement of senior leadership;
- highlights the importance of transparency and explainability, accuracy, robustness and security, accountability, and human values and fairness. Also consistent with international regulation is the OPC's call for a 'privacy-by-design' approach to implementing AI;
- identifies a need to consider te ao MÄori perspectives on privacy (broadly, te ao MÄori is the MÄori worldview including tikanga MÄori - MÄori customs and protocols). Specific concerns identified in the OPC AI Guidance include:
- bias from systems developed overseas that do not work accurately for MÄori;
- collection of MÄori information without work to build relationships of trust, leading to inaccurate representation of MÄori taonga that fail to uphold tapu and tikanga; and
- exclusion from processes and decisions of building and adopting AI tools that affect MÄori whÄnau, hapĹŤ, and iwi, including use of these tools by the public sector; and
- identifies some use cases for AI as higher-risk, requiring more care, for example, the use of AI tools for automated decision-making.
The OPC continues to monitor risks raised by AI use, including calling for Privacy Act modernisation to address automated decision-making in its 2025 Annual Report, and joining international statements on trustworthy AI data governance and AI generated imagery.
For more information on the OPC AI Guidance, see DLA Piper's update here: New Zealand's Privacy Commissioner follows global trends with latest guidance on AI | DLA Piper.
New Zealand Government Cabinet Paper
The then Minister of Science, Innovation and Technology â Hon Judith Collins KC published the Approach to work on Artificial Intelligence Cabinet paper in July 2024, seeking agreement from Cabinetâs Economic Policy Committee on a strategic approach for New Zealandâs use of AI. The Minister proposed a âlight-touch, proportionate and risk-based approach to AI regulationâ. The approach would leverage existing laws as guardrails and only introduce new regulation to âunlock innovation or address acute risksâ. Cabinet has focused on the following five key domains:
- setting a strategic approach to AI;
- enabling safe AI innovation in the public service;
- harnessing AI in the New Zealand economy (with the Ministry of Business, Innovation and Employment (MBIE) instructed to formulate OPC AI guidance for firms to utilise);
- prioritising engagement on international rules and norms; and
- coordinating with work on national security.
OECD AI Principles
The New Zealand Government has adopted the Organisation for Economic Co-operation and Development (OECD) AI Principles adopted in 2019 and updated in 2024 (OECD AI Principles) to guide the development of trustworthy, innovative, and democratic AI in New Zealand, aligning with other OECD member states.
National AI Strategy
In July 2025, the New Zealand Government released New Zealandâs Strategy for Artificial Intelligence: Investing with confidence (AI Strategy) aiming to accelerate private sector AI adoption and innovation. The AI Strategy commits to stable and enabling policy for AI, involving a light-touch and principles-based approach that relies on existing legislation and the OECD AI Principles. In the AI Strategy, the Government outlines that it will reduce barriers to adoption, provide clear regulatory guidance, build necessary capabilities, and ensure that adoption occurs responsibly. The AI Strategy emphasises the opportunities in AI adoption and application rather than foundational AI development.
MBIE published a Responsible AI Guidance for Businesses (AI Guidance for Business) alongside the AI Strategy to assist with its practical application. The AI Guidance for Business is a non-binding guide of good practices and actions that can support businesses to adopt AI. It identifies and discusses various types of considerations for businesses using or developing AI systems, including risks to cybersecurity, privacy, human rights, workplace culture, the environment, intellectual property and creators, and physical safety.
For more information on the AI Strategy and AI Guidance for Business, see DLA Piper's update here: Quick on the uptake? New Zealandâs new strategic approach to Artificial Intelligence.
AI guidance for regulators
The New Zealand Government has released Responsible AI in Action guidance for senior leaders and management teams in regulatory organisations (Regulatory AI Guidance). It focuses specifically on best practice for AI use in the regulatory context, where decisions affect rights, obligations, and public confidence. The Regulatory AI Guidance emphasises that AI should facilitate, but not replace, careful judgement, legal interpretation, and discretion when making decisions that affect people's rights and public trust.
The core advice for regulators in the Regulatory AI Guidance is to:
- treat AI as a regulatory capability, not an IT project;
- scale governance and oversight to reflect risks;
- use AI to support human judgement, not replace it; and
- ensure AI use meets high ethical standards that reflect the rights, safety and livelihoods impacted by regulatory decisions.
Public Service AI Framework
The New Zealand Government has introduced the Public Service AI Framework (Framework) to guide the responsible use of AI across the public sector. As with the Regulatory AI Guidance, while not legally binding, the Framework sets out best practice principles for AI adoption. Its vision is the responsible adoption of AI âto modernise public services and deliver better outcomes for all New Zealanders.â
The Framework is guided by five AI principles:
- Inclusive, sustainable development â Public Service AI systems should contribute to inclusive growth, sustainable development and the reduction of economic, social, gender and other inequalities, including by reference to access to technology.
- Human-centred values â Public Service AI should respect the rule of law, democratic values, human and labour rights, including personal data protection and privacy, ensuring ethical and appropriate use.
- Transparency and explainability â Those using, or interacting with, Public Service AI should be aware of, and understand, how the Public Service is using that AI. Public Service agencies should therefore disclose when AI is used, how those systems were developed and how they affect outcomes.
- Security and safety â The security of customers and staff is a core business requirement. Public Service AI should apply a robust risk management approach and ensure the traceability of data.
- Accountability â Public Service AI should be subject to oversight. Capability should therefore keep up with technological changes, including to relevant regulatory and governance frameworks.
The Framework's principles are informed by the OECD AI Principles, as well as the UK's Generative AI Framework for HMG dated January 2024 (but since withdrawn), the Algorithm Charter for Aotearoa New Zealand dated July 2020, and the AI Forum AI Principles dated March 2020.
The Government Chief Digital Officer is leading a Public Service AI work programme to support the implementation of the Frameworkâs vision while working closely with MBIE to compile a cross-portfolio policy work programme. The programme is guided by six pillars:
- Governance â supporting transparency and human accountability in Public Service AI use.
- Guardrails â enabling safe and responsible Public Service AI use.
- Capability â building internal and external AI knowledge and skills.
- Innovation â providing pathways that enable safe AI testing and innovation.
- Social licence â ensuring New Zealanders have trust and confidence in Public Service AI use.
- Global voice â ensuring international counterparts see New Zealand as a trusted AI partner.
Public Service Generative AI Guidance
The New Zealand Government published the Responsible AI Guidance for the Public Service: GenAI dated February 2025 (GenAI Guidelines) to support the New Zealand Public Service to explore generative AI systems in ways that are safe, transparent and responsible. The GenAI Guidelines outline foundational aspects of supporting public sector agencies in the utilisation and adoption of generative AI and give examples of how each aspect can be implemented.
Key considerations are also highlighted about generative AI systems which affect customer experience with the New Zealand Government and include transparency, accessibility, ethical considerations to address bias, MÄori and indigenous data considerations, and privacy. Public Service agencies are expected to ensure transparency and accountability in their use of generative AI, enhance employee skills and capabilities, and follow best practices in procurement to align generative AI solutions with business needs and regulatory compliance.
AI Forum publications
The Artificial Intelligence Forum of New Zealand - Te KÄhui Atamai Iahiko o Aotearoa (AI Forum) released its AI Blueprint for Aotearoa: a refreshed vision to 2030 dated May 2026, designed as a practical roadmap for how Aotearoa can become a global leader in innovative, responsible and inclusive AI, and is globally recognised for harnessing the power of AI for the benefit of all. It proposes a focus on education, social licence and trust, and infrastructure. The AI Forum also released its Trustworthy AI in Aotearoa AI Principles dated March 2020 (AI Forum AI Principles). The AI Forum AI Principles are organised under five subheadings, namely: fairness and justice; reliability, security and privacy; transparency; human oversight and accountability; and wellbeing.
Other Regulatory and Sectoral Guidance
Various other regulators have published sector guidance on AI, including:
- The Financial Markets Authority (FMA) has published sector research on AI in financial services dated September 2024, an opinion piece on good governance for AI dated February 2025, guidance on cyber-resilience and digital advice services, and issued public warnings regarding AI-enabled deepfake investment scams dated April 2026;
- The Ministry of Justice published guidelines for the use of generative AI in Courts and Tribunals, dated December 2023. Similarly, the New Zealand Law Society published Generative AI guidance for lawyers and a report on Strengthening the rule of law in Aotearoa New Zealand. When utilising automated decision-making systems in dispute resolution and the delivery of justice, the latter report recommends stronger safeguards to reduce the unintended consequences and protect trust and confidence in the rule of law in New Zealand;
- Parliamentâs Economic Development, Science and Innovation Committee reported to Parliament in April 2026 on the public service's adoption of AI, AI guidance for businesses, the âlight-touchâ approach to legislating AI, and the ethics of using AI in New Zealand. This included a key recommendation that Parliament stay alert to the novel challenges of AI, particularly in the context of legislative development; and
- The Government Communications Security Bureau issued a joint statement with Five Eyes partners calling for a whole-of-organisation and whole-of-society response to the evolving cyber risk landscape driven by frontier AI, dated June 2026. New Zealand is a member of the Five Eyes security partnership alongside Australia, Canada, the United Kingdom, and the United States.
Biometric Processing Privacy Code 2025
The Biometric Processing Privacy Code 2025 (Biometrics Code) is a binding code of practice under the Privacy Act that came into force on 3 November 2025 (with a compliance transition period for agencies already using biometrics until 3 August 2026). The Biometrics Code regulates the collection, storage and use of biometric information for automated biometric processing (for example, verification, identification, and categorisation). Key features include requirements for effectiveness and proportionality assessments, safeguards to reduce privacy risk, transparency obligations, safe limits on highly intrusive uses (including health, emotion or attention prediction), and a prohibition on discriminatory biometric categorisation except in limited circumstances. The Biometrics Code is enforceable by the OPC under the Privacy Actâs complaints and compliance mechanisms.
Reserve Bank of New Zealand reports
The RBNZ issued its Financial Stability Report dated May 2026 (Report), which included a special topic "Rise of the machines â How could artificial intelligence impact financial stability?" (Special Topic).
The Report outlines that the adoption of AI could amplify risks in the financial sector and states that regulated entities are expected to maintain cyber-security strategies and frameworks that adequately address cyber threats.
The Special Topic outlines the use of AI within the financial sector, explores its potential benefits and challenges, provides an overview of the evolving regulatory landscape, and identifies AI-driven risks to financial stability, including errors, data privacy concerns, market distortions, and increased exposure to cyber attacks, all of which could amplify existing systemic risks.
Additionally, the Special Topic flags current and upcoming legislation and binding standards that are or will be relevant to mitigating AI-driven risks. These include:
- the proposed Risk Management Standard and Operational Resilience Standards for deposit takers, slated to take effect in 2028; and
- the Financial Markets (Conduct of Institutions) Amendment Act 2022 (commonly known as CoFI), which came into effect in full in March 2025 and aims to ensure that financial institutions treat consumers fairly. The RBNZ considers that this serves as an important framework for regulating the conduct risk associated with AI.