Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Map your real AI use cases
- 2. Set approval levels based on risk
- 3. Create clear data input rules
- 4. Deal with accuracy and human review
- 5. Align the policy with your privacy and contract documents
- 6. Train staff and keep records
- 7. Plan for incidents and complaints
- Common mistakes New Zealand businesses make
FAQs
- Do all New Zealand businesses need an AI governance policy?
- Is an AI governance policy a legal requirement in New Zealand?
- What is the difference between an AI governance policy and a privacy policy?
- Should startups have an AI governance policy, or is this only for larger companies?
- Can we just rely on the AI provider's terms and policies?
- Key Takeaways
Many New Zealand businesses are already using AI before they have any clear internal rules for it. That creates obvious problems. Teams paste confidential information into public tools, buy AI products without checking privacy terms, or rely on automated outputs in customer decisions without any human review. The result can be poor accuracy, privacy complaints, misleading claims, and messy accountability when something goes wrong.
An AI governance policy helps fix that. It gives your business a practical set of rules about where AI can be used, who approves it, what data can go into it, how outputs should be checked, and how risks are escalated. For startups and SMEs, the challenge is keeping that policy useful rather than turning it into a vague statement nobody follows.
This guide explains what an AI governance policy should cover in New Zealand, when businesses usually need one, and the practical mistakes to avoid before you sign with an AI vendor, launch AI features, or let staff use generative AI in day to day work.
Overview
An AI governance policy is an internal framework that sets the rules for how your business selects, uses, monitors, and reviews AI systems. In New Zealand, it usually sits alongside your privacy policy, customer terms, supplier contracts, information security practices, and internal approval processes.
A good policy does not just say your business will use AI responsibly. It tells staff what they can and cannot do, identifies who makes decisions, and creates an audit trail when AI affects customers, employees, or commercially sensitive information.
- Define what your business means by AI and which tools the policy covers
- Assign ownership, approvals, and escalation paths
- Set rules for personal information, confidential information, and sensitive business data
- Require testing, human review, and monitoring before high impact use cases go live
- Address fairness, bias, accuracy, and explainability risks
- Align the policy with your Privacy Act obligations, customer disclosures, and supplier contracts
- Create staff rules for generative AI, procurement, record keeping, and incident response
- Review the policy regularly as tools, use cases, and legal expectations change
What AI Governance Policy Means For New Zealand Businesses
An AI governance policy is the document that turns general concerns about AI into clear operational rules for your business.
For many founders, AI use starts informally. A staff member uses a chatbot to draft marketing copy. A sales team uploads call notes into an AI note taker. A developer plugs a third party model into your product. A manager uses automated scoring to shortlist applicants or assess customer risk. Those choices can affect privacy, contracts, advertising claims, intellectual property, and internal accountability.
In New Zealand, there is no single standalone AI Act that replaces your existing business obligations. Instead, AI use often intersects with current legal duties, especially around privacy, fair dealing, contracts, and governance. That means your policy should be built around the real legal and commercial risks your business already has.
Why a policy matters even if AI use seems low risk
The main risk is not only building your own AI product. It is ordinary business use without guardrails. Even simple uses can create legal exposure if staff enter personal information into external tools, generate inaccurate public statements, or make important decisions based on unchecked outputs.
A written policy also helps directors, founders, and managers show that AI use is being considered properly. That matters before you spend money on setup, before you promise AI features to customers, and before you sign a supplier agreement that shifts risk onto your business.
How this connects with New Zealand legal obligations
Your AI governance policy should fit with the legal framework your business already operates under. Depending on your use case, that may include:
- The Privacy Act 2020, especially where personal information is collected, used, stored, disclosed, or sent offshore through an AI provider
- The Information Privacy Principles, including transparency, purpose limits, security, access, and correction rights
- The Fair Trading Act 1986, if AI generated marketing, product claims, or customer communications could be misleading
- Your customer contracts and website terms, especially if you promise certain service levels, outputs, or decision making processes
- Your supplier and software agreements, including data use rights, security commitments, liability allocation, and intellectual property terms
- Employment obligations, if AI is used in recruitment, performance management, or workplace monitoring
- Sector specific expectations in regulated industries such as financial services, health, education, or insurance
The policy does not replace those obligations. It helps your team follow them consistently.
What a practical policy usually includes
A useful policy is tailored to your business model. A software startup offering AI features to customers will need different controls from a retail business using AI for internal admin. Still, most New Zealand SMEs should cover the same core areas.
- Scope, including which tools, systems, teams, and use cases are covered
- Risk classification, such as low risk internal drafting tools versus higher risk customer decision systems
- Data handling rules, including when personal information or confidential material must not be entered into an AI tool
- Approval rules for buying, building, or integrating AI systems
- Testing and validation requirements before deployment
- Human oversight requirements for high impact outputs
- Rules for customer transparency where AI materially affects service delivery or decisions
- Monitoring, incident reporting, and periodic review
- Training requirements for staff and contractors
- Record keeping so decisions can be explained later if needed
When This Issue Comes Up
Most businesses need an AI governance policy earlier than they think, usually at the point AI use stops being a one off experiment and starts affecting real data, real customers, or real decisions.
Founders often assume governance can wait until the business is larger. In practice, the issue usually appears during ordinary growth moments.
When staff start using generative AI tools at work
If your team is using public AI tools for drafting, coding, customer support, design, or summarising meetings, you already need clear internal rules. This is where founders often get caught. Staff may think they are saving time, but they can accidentally disclose client information, upload unreleased product plans, or create content that is inaccurate or copied too closely from other sources.
Your policy should say:
- Which tools are approved
- What information must never be entered into them
- When outputs must be checked by a human
- Who signs off on external facing content or important internal decisions
Before you launch an AI feature or AI enabled product
If your business sells software, online services, or digital products, governance becomes a product issue as well as an internal one. Before launch, you need to test whether the feature works as described, whether users are given accurate information about its limits, and whether your customer terms deal with responsibility for AI outputs.
This is especially relevant if your business is scaling fast, selling online, or pitching to enterprise customers. Larger customers often ask about data handling, human oversight, security, subcontractors, and incident response before they sign.
When you are buying AI from a vendor
Procurement is one of the most common trigger points. A vendor demo can look polished, but your business still needs to know what happens to the data, where it is stored, who can access it, whether it is used to train models, and what contractual protection you actually have if the tool fails.
Before you sign a contract, your policy should help the business check:
- Whether the vendor is handling personal information on your behalf
- Whether offshore disclosure is involved
- Whether the contract limits the vendor's liability too heavily
- Whether the vendor can reuse your data
- Whether there are meaningful service, security, and deletion commitments
When AI is used for decisions about people
Higher risk use cases need closer attention. That includes recruitment screening, customer eligibility decisions, fraud detection, credit style assessments, pricing, or workplace monitoring. Even if the AI is only one input, poor controls can create fairness concerns, privacy issues, or practical complaints that damage trust.
For these use cases, your policy should require more than a general approval. It should require documented testing, clear human review points, and a process for challenging outcomes.
When investors, customers, or partners ask governance questions
Governance often becomes visible during due diligence. Investors may ask whether your business owns its training data, whether outputs create IP risk, or whether privacy settings have been checked. Customers may ask how AI decisions are reviewed. Commercial partners may ask whether your business has any written policy at all.
If the answer is no, the discussion gets harder. A short, practical policy can make those conversations much easier.
Practical Steps And Common Mistakes
The best AI governance policy is one your team can actually use, backed by contracts, privacy settings, and approval processes that match what happens in the business.
1. Map your real AI use cases
Start with a simple internal audit. Do not write the policy in the abstract. Find out which tools are already being used across the business and what data goes into them.
That review should cover:
- Public generative AI tools used by staff
- Embedded AI features inside existing software
- Customer facing AI products or automations
- AI used in marketing, analytics, hiring, support, security, or finance operations
- Any third party providers processing personal information or confidential business information
Many businesses skip this step and write a policy that does not match reality. That makes the document hard to enforce and easy to ignore.
2. Set approval levels based on risk
Not every use of AI needs the same sign off. Internal brainstorming tools may need light controls. Tools that affect customers, pricing, eligibility, or personal information need stronger checks.
Your policy can divide use cases into categories such as:
- Permitted without further approval, subject to basic data rules
- Permitted with manager or legal approval
- Restricted or prohibited unless special conditions are met
This gives staff practical guidance and helps avoid bottlenecks.
3. Create clear data input rules
For most SMEs, privacy and confidentiality are the first issues to sort out. A policy should state in plain language what staff must not upload into AI tools unless a proper review has happened.
That often includes:
- Personal information, unless the tool and use case have been approved
- Customer lists, contact details, or behavioural data
- Health information or other sensitive information
- Confidential contracts, board papers, financial forecasts, or source code
- Information covered by non disclosure obligations
This point matters whether you are a startup deciding on business structure and internal controls, or an established SME updating systems before a new product launch. Good governance is not just about technology. It is about deciding what information is safe to use and under what conditions.
4. Deal with accuracy and human review
AI outputs can sound convincing while still being wrong. Your policy should say when human review is mandatory and who is accountable for the final decision or communication.
Common examples include:
- Marketing content that could create misleading claims
- Customer communications that affect rights, pricing, or service delivery
- Legal, HR, or compliance content used internally
- Code or technical outputs deployed into production systems
- Any decision with a material effect on a person or customer relationship
A common mistake is assuming the tool provider is responsible for bad outputs. Usually, your business remains responsible for how those outputs are used.
5. Align the policy with your privacy and contract documents
An AI governance policy should not sit on its own. It needs to line up with your privacy policy, internal privacy process, employee policies, and commercial agreements.
For example:
- If your website says you only use information for certain purposes, AI use should fit within that statement or the wording should be reviewed
- If customer contracts promise a human delivered service, adding AI may require clearer disclosure
- If your supplier agreement lets the vendor use your data broadly, your internal policy should not pretend the risk does not exist
- If contractors use AI in deliverables, your contracts should address confidentiality, quality control, and ownership issues
This is also where related business assets matter. If you are developing branded AI tools or products, think about trade mark protection for names and customer facing features. If you are building a new venture around AI, your company setup and core contracts should be reviewed before you spend money on setup.
6. Train staff and keep records
A policy no one reads does not do much. Staff need simple, role specific training. Sales teams need rules for claims and disclosures. Developers need procurement and testing rules. HR needs guidance on any people related use cases. Leadership needs escalation pathways.
Records also matter. Your business should keep enough documentation to show:
- Which AI tools are approved
- Who approved them
- What data was assessed
- What testing was done
- What incidents or concerns have arisen
- When the use case was last reviewed
7. Plan for incidents and complaints
Things will go wrong at some point. The policy should say what happens if confidential information is entered into the wrong tool, if a model produces a harmful or biased output, or if a customer asks how an AI assisted decision was made.
Your incident process should cover:
- Immediate containment steps
- Who must be notified internally
- Whether privacy response steps are needed
- How customer communications are handled
- Whether the tool should be suspended pending review
Common mistakes New Zealand businesses make
Most governance failures are not technical. They come from basic business gaps.
- Using a copied overseas policy that does not match New Zealand legal context or your actual operations
- Treating the policy as an ethics statement rather than a practical rulebook
- Ignoring vendor contracts and focusing only on internal staff conduct
- Allowing personal information to be entered into tools without a privacy review
- Assuming disclosure alone fixes all risk
- Failing to review marketing claims about what the AI can do
- Leaving high impact decisions to automation without meaningful human oversight
- Forgetting to update employment contracts, contractor terms, customer terms, or procurement processes
A shorter policy that people follow is usually better than a long one that sits in a folder untouched.
FAQs
Do all New Zealand businesses need an AI governance policy?
Not every business needs a long formal document, but any business using AI in a repeatable way should have written rules. If staff use AI tools at work, or if AI affects customers, data, hiring, or important decisions, a policy is usually sensible.
Is an AI governance policy a legal requirement in New Zealand?
There is no single general law that says every business must have one. The value of the policy is that it helps your business meet existing obligations, especially around privacy, fair trading, contracts, and governance.
What is the difference between an AI governance policy and a privacy policy?
A privacy policy explains to customers or users how your business handles personal information. An AI governance policy is mainly an internal document that sets rules for selecting, using, monitoring, and approving AI tools and AI related decisions.
Should startups have an AI governance policy, or is this only for larger companies?
Startups should think about it early, especially if they are selling online, building AI into products, or relying on third party AI providers. A startup does not need a complex enterprise framework, but it does need clear rules before investor diligence, enterprise sales, or product scale make the gaps harder to fix.
Can we just rely on the AI provider's terms and policies?
No. Provider terms are only part of the picture. Your business still needs its own rules for staff use, data handling, customer disclosures, approvals, and accountability. Vendor contracts also need to be reviewed carefully because they often limit the provider's responsibility.
Key Takeaways
- An AI governance policy helps New Zealand businesses set clear internal rules for how AI is approved, used, monitored, and reviewed.
- The policy should cover scope, roles, risk levels, data handling, testing, human oversight, incident response, and staff training.
- Privacy Act issues, Fair Trading Act risks, customer contracts, supplier terms, and employment processes can all be affected by AI use.
- Common trigger points include staff using generative AI tools, buying AI software, launching AI features, and using AI in decisions about people.
- The most effective policy is practical and tailored to your actual use cases, not copied from a generic overseas template.
- Your policy should align with your privacy documents, commercial contracts, procurement steps, and internal approval processes.
If your business is dealing with AI governance policy and wants help with privacy compliance, supplier contract reviews, customer terms, and internal AI use policies, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.







