Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
Many New Zealand businesses are already using AI tools for customer support, marketing, recruitment, analytics, document drafting and software development. The problem is that plenty of founders adopt these tools before they set any internal rules. Common mistakes include feeding personal information into public AI systems without checking the privacy impact, relying on AI outputs without human review, and buying AI-enabled software under contracts that say very little about data use, liability or security.
An AI governance policy helps fix that. It sets the rules for how your business chooses, uses, monitors and reviews AI systems. That matters in New Zealand because AI use can trigger privacy, consumer law, employment, contractual and governance issues long before there is any AI-specific statute aimed at your business. The right policy will not stop all risk, but it gives your team a practical framework for using AI lawfully and sensibly. Here’s what business owners need to know, what to include in an AI governance policy, and where companies often get caught before they sign a vendor contract or roll out AI across the business.
Overview
An AI governance policy is an internal set of rules for how your business approves, uses and checks AI tools. In New Zealand, the legal questions usually start with privacy, transparency, accuracy, contractual risk and accountability, rather than a single stand-alone AI law.
A useful policy should help your business make consistent decisions before you buy software, before staff use AI on customer data, and before you rely on AI-generated outputs externally.
- Identify which AI tools are allowed, restricted or banned
- Set rules for personal information, confidential information and commercially sensitive data
- Decide when human review is required before an AI output is used
- Assign responsibility for approvals, monitoring and incident reporting
- Check supplier contracts for data use, security, ownership and liability terms
- Address customer-facing disclosures, marketing claims and accuracy risks
- Review employment contracts, contractor terms and internal IT policies so they match the AI rules
What AI Governance Policy Means For New Zealand Businesses
An AI governance policy gives your business a practical operating rulebook for AI, not just a statement of good intentions. It should tell staff what they can use, what they cannot use, when they need approval and who is accountable if something goes wrong.
For many SMEs, AI enters the business quietly. A staff member starts using a generative AI tool to draft emails. A sales team plugs customer notes into an assistant. A founder buys an AI feature built into CRM or HR software. Each decision may feel small, but together they can create a real compliance problem.
Why businesses need a formal policy
The main risk is inconsistency. Without a clear policy, one team may treat AI as a harmless productivity tool while another uses it to make decisions that affect customers, job applicants or staff. That is where privacy issues, inaccurate outputs and unfair or misleading statements can start to build.
A formal policy also helps directors and business owners show they have thought about governance. Even where no law says you must have a document called an AI policy, regulators, customers, investors and commercial partners may still expect evidence that your business has a sensible process around data and automated tools.
How AI issues fit into existing New Zealand law
New Zealand does not currently regulate all business AI use under one dedicated law. That does not mean AI is unregulated. Existing legal duties still apply to the way your business collects information, markets services, enters contracts and manages risk.
The Privacy Act 2020 is often the first issue. If your AI tool collects, stores, analyses or generates outputs from personal information, your business still needs to comply with privacy obligations. That can include being transparent about collection and use, keeping information secure, limiting use to appropriate purposes, and making sure overseas disclosure risks are properly considered where relevant.
The Fair Trading Act 1986 can also matter. If your business uses AI to create website copy, ads, pricing messages or product claims, you remain responsible for misleading or deceptive conduct. “The AI wrote it” is not a defence if the statement is false or creates the wrong impression.
Contract law matters as well. A software subscription, services agreement, procurement contract or customer terms may not say much about AI, but that gap can create risk. If an AI vendor uses your data to train models, limits responsibility for errors, or provides weak security commitments, your business may be carrying more risk than expected.
Employment issues can arise where AI is used in recruitment, performance review, rostering, monitoring or internal decision-making. If staff are unsure what tools they can use, or if AI is used in a way that affects workplace rights or fairness, the business can quickly run into trouble.
What an AI governance policy usually covers
A workable policy should match the size and risk profile of your business. A small online retailer using AI only for draft product descriptions will not need the same level of internal controls as a health-tech company processing sensitive data.
Still, most businesses should cover a core set of issues, including:
- approved business uses of AI
- prohibited uses, such as entering sensitive personal information into unauthorised public tools
- approval processes for new AI systems
- privacy and confidentiality rules
- human oversight requirements
- record-keeping and version control
- staff training and awareness
- incident response and escalation
- contract review standards for AI suppliers
- review dates and responsibility for updating the policy
The point is not to write a perfect academic framework. The point is to give your team a clear, usable set of business rules that work in real situations.
When This Issue Comes Up
AI governance becomes urgent when AI moves from informal experimentation to real business use. For most founders, that happens earlier than expected.
This issue commonly comes up at moments such as:
- before you sign a software contract that includes AI features
- before you let staff use generative AI with customer or employee data
- before you launch a chatbot, recommendation engine or automated support tool
- before you use AI in recruitment, screening or performance processes
- before you spend money on setup for an AI-enabled platform
- before you make public claims about what your AI product can do
- before a customer, investor or enterprise client asks for your governance position
When buying AI-enabled software
Many businesses do not realise they are adopting AI because the tool is packaged as an ordinary software upgrade. A CRM, marketing platform, HR system or finance tool may include AI assistants, predictive features or automated decision support as part of the subscription.
This is where founders often get caught. They focus on price and functionality, but not on what happens to data, whether outputs can be trusted, or whether the vendor can reuse information. Before you sign, check the contract terms and make sure your internal policy actually matches the software’s capabilities.
When using personal information
If your business handles customer records, employee data, candidate information or user profiles, privacy should be front of mind. The issue is not just whether the AI tool is useful. The issue is whether the information can lawfully be used in that way, whether the use is transparent, and whether the provider gives acceptable protections.
Businesses in health, education, finance, property, e-commerce and professional services often face a higher level of concern because the information involved may be sensitive, commercially confidential or difficult to correct once processed.
When selling AI products or AI-powered services
If your business offers AI products to customers, your governance policy should not just cover internal use. It should also shape product claims, customer terms, service descriptions, complaint handling and risk allocation.
For example, a SaaS business that markets an AI tool as accurate, automated or decision-ready needs to think carefully about the representations it makes. If users rely on those claims and the system performs differently, consumer and contractual risk can follow.
When staff are already using AI without approval
This is extremely common in startups and SMEs. Staff often use AI first because it saves time, then mention it later, if at all. That can expose the business to data leakage, ownership disputes and inconsistent work quality.
If that is already happening, the answer is not necessarily to ban every tool immediately. A better first step is to map what tools are being used, what data is going in, who is relying on the outputs and where the highest risk sits. Your policy can then separate low-risk uses from uses that need tighter control.
Practical Steps And Common Mistakes
The best AI governance policy is specific, usable and tied to actual business decisions. A short policy that staff can follow is usually better than a dense document no one reads.
1. Map your current AI use
Start with a simple internal review. You need to know what AI tools are already in play before you can govern them properly.
Your review should identify:
- which tools staff or contractors are using
- what business functions they support
- what data goes into them
- whether outputs are used internally or given to customers
- whether any tools influence decisions about people
- which tools are built into existing software subscriptions
Without this step, policies tend to be too generic and miss the real risk areas.
2. Classify uses by risk
Not every AI use case carries the same legal risk. Drafting internal brainstorming notes is very different from processing customer data or screening job applicants.
A practical policy often groups uses into categories such as:
- low-risk permitted uses, such as drafting generic internal content without sensitive data
- restricted uses that require manager or privacy approval
- prohibited uses, such as uploading confidential client files to unauthorised public tools
This makes the policy easier for staff to apply in day-to-day work.
3. Set clear privacy and confidentiality rules
If your team does not know what data can be entered into AI systems, your privacy risk increases quickly. Your policy should be explicit about what is off limits and what requires extra approval.
Common rules include:
- do not enter personal information unless the tool has been approved for that use
- do not enter sensitive business information, trade secrets or legally privileged material into public AI tools
- check whether information is stored overseas or used for model training
- use de-identified or synthetic data where possible for testing
- follow any existing privacy policy, information security policy and confidentiality obligations
If your business has customer-facing privacy documentation, review whether it accurately reflects your AI-related data practices.
4. Require human review where it matters
AI outputs can sound confident and still be wrong. Human review should be mandatory where errors could affect customers, staff, legal obligations, pricing, safety or key commercial decisions.
Your policy should say when AI can assist and when it cannot decide. For example, staff may use AI to generate a first draft, but a person should still verify accuracy before publication, customer communication, hiring decisions or contract review.
5. Review supplier contracts properly
An AI governance policy is only part of the picture. The supplier contract often determines where the legal risk really sits.
Before you sign, check terms dealing with:
- how the provider can use your data
- whether customer data is used for training or service improvement
- security standards and incident notification
- sub-processors and overseas hosting
- intellectual property in inputs and outputs
- service levels, suspension rights and support
- warranties, exclusions and liability caps
- rights to audit, export or delete data on exit
If an enterprise customer asks about your AI governance, your own upstream supplier contracts may be the first place they expect you to have done the work.
6. Train staff and update related policies
A stand-alone AI policy rarely works if it conflicts with the rest of your documents. It should line up with your employment contracts, contractor terms, IT rules, privacy processes, confidentiality obligations and incident reporting procedures.
Staff training matters because most AI risk appears in ordinary decisions made under time pressure. A short, practical training session with examples is more useful than broad statements about innovation or ethics.
Common mistakes businesses make
Several patterns show up repeatedly in SMEs and growing startups:
- assuming low-cost or free AI tools are safe for business use
- copying an overseas AI ethics template that does not match New Zealand law or the business’s operations
- treating AI as an IT issue only, without input from legal, privacy or operational decision-makers
- failing to update customer terms, procurement contracts or internal policies
- using AI-generated content in marketing without checking accuracy
- making broad claims that the business is “AI compliant” or “fully governed” without clear evidence
- focusing on policy language while ignoring day-to-day behaviour inside the business
The strongest approach is practical rather than performative. Your policy should reflect what your business actually does and what your team can realistically follow.
What good governance looks like in practice
Good governance is visible in ordinary business decisions. Before you buy a new AI tool, someone checks the contract. Before a team uploads data, someone checks whether personal information is involved. Before AI-generated content goes live, someone verifies the claims.
That is what a useful AI governance policy should support. It should create a repeatable approval process, not just a document for the drawer.
FAQs
Does every New Zealand business need an AI governance policy?
Not every business is legally required to have a document with that exact title, but any business using AI should have clear internal rules. If staff use AI with customer data, employee information, confidential material or public-facing content, a written policy is a sensible baseline.
Is AI specifically regulated in New Zealand?
There is no single general AI law that covers all business use. Existing laws still apply, especially privacy, fair trading, contract, employment and sector-specific obligations.
Can we use public AI tools for customer information?
You should be very cautious. If personal information or confidential business information is involved, your business needs to check whether that use is permitted, secure and transparent, and whether the provider’s terms are acceptable.
Who should own AI governance inside a business?
Usually, one person or team should coordinate it, but the answer depends on the business. In smaller companies, that may be a founder, operations lead or privacy lead, with input from IT, HR and legal advisers where needed.
Do we need to tell customers when AI is being used?
Sometimes, yes. The need for disclosure depends on the context, including how the AI affects the service, what information is collected, and whether silence could mislead customers or create privacy concerns.
Key Takeaways
- An AI governance policy sets practical internal rules for how your business approves, uses and reviews AI tools.
- In New Zealand, AI use can raise privacy, fair trading, contract, employment and governance issues even without a single stand-alone AI statute.
- Your policy should address approved tools, data handling, human oversight, supplier contracts, staff training and incident response.
- The issue often becomes urgent before you sign a software contract, before staff use AI with personal information, or before you make customer-facing claims about AI outputs.
- Common mistakes include relying on public AI tools without controls, skipping contract review, and assuming the vendor carries all responsibility.
- A useful policy should match your actual operations and be supported by consistent contracts, privacy documents and internal processes.
If your business is dealing with AI governance policy and wants help with privacy compliance, supplier contract reviews, customer terms, and internal policy drafting, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
When should you formalise this?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.






