Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Common Mistakes With Employee AI Use Policy
- Using a policy copied from an overseas template
- Banning AI completely, then looking the other way
- Failing to define confidential information clearly
- Ignoring contractors and temporary workers
- Assuming AI output is fine if a person pressed send
- Forgetting training and rollout
- Not reviewing provider terms before use
- Leaving the policy untouched after the first draft
- Key Takeaways
Many New Zealand businesses are already using AI tools at work, often before anyone has written down the rules. That creates obvious problems. Staff may paste confidential client material into public tools, rely on AI output without checking it, or use personal accounts that the business cannot monitor or control. Another common mistake is treating AI as a pure IT issue, when it also affects employment obligations, privacy, intellectual property, confidentiality, and internal accountability.
An employee AI use policy helps you set clear boundaries before a small shortcut becomes a bigger legal or commercial issue. It tells your team what tools they can use, what information they must never upload, when human review is required, and what happens if the policy is ignored. For founders and managers, the real question is not whether staff will use AI. It is whether your business has sensible rules in place before you rely on speed and convenience over control.
Overview
An employee AI use policy is an internal workplace policy that explains how workers may and may not use AI systems in their role. For New Zealand businesses, it should sit alongside employment agreements, privacy practices, confidentiality obligations, IT policies, and any sector specific requirements that apply to your business.
- Define which AI tools are approved, restricted, or banned.
- Set rules for confidential information, personal information, and client data.
- Require human review before staff rely on AI generated content, advice, code, or decisions.
- Explain ownership of work product and how intellectual property is handled.
- Deal with monitoring, security, training, and reporting obligations.
- Make sure the policy lines up with employment agreements and disciplinary processes.
What Employee AI Use Policy Means For New Zealand Businesses
An employee AI use policy gives your business a practical framework for using AI at work without leaving major decisions to guesswork. It is less about banning technology and more about setting business rules that match your legal obligations and risk tolerance.
For many SMEs, AI enters the workplace informally. A staff member uses a chatbot to draft client emails. A sales manager uses AI to prepare proposals. A developer uses an AI coding assistant. A recruiter uses AI to screen CVs. None of that is automatically unlawful, but each use case raises different legal and operational risks.
In New Zealand, the policy should reflect the fact that employer obligations do not disappear because a tool is automated. If an employee mishandles personal information, discloses confidential material, or sends misleading content created by AI, the business still carries the risk. The same applies if an AI generated result is discriminatory, inaccurate, or contrary to your contractual commitments to customers.
Why businesses are adopting AI policies now
The immediate reason is control. Business owners want to know what staff are doing, what tools are being used, and what data is leaving the business.
The legal reason is consistency. When expectations are unclear, managers respond differently to the same behaviour. One team may allow AI generated reports with no review, while another bans them entirely. That inconsistency creates avoidable employment issues, especially if a disciplinary issue later arises.
The commercial reason is quality. AI can speed up drafting and routine tasks, but it can also invent facts, repeat bias, or produce material that sounds right while being wrong. If your business delivers advice, customer communications, software, creative content, or regulated services, this matters quickly.
What a policy usually covers
A good employee AI use policy should answer the day to day questions staff actually have. It should not read like a generic technology statement copied from overseas.
Most businesses will want the policy to cover:
- which roles may use AI tools and for what purposes
- whether staff can use free public tools or only approved enterprise tools
- whether personal accounts are prohibited for business use
- what information must never be uploaded, including customer data, health information, payroll records, source code, financial forecasts, and confidential contracts
- when AI output must be reviewed by a manager or subject matter expert
- how AI use should be disclosed internally or to customers, if relevant
- how records are kept for prompts, outputs, and decisions where traceability matters
- what happens if someone breaches the policy
How this fits with employment documents
The policy should not sit in isolation. This is where founders often get caught. They draft a policy, circulate it by email, and assume that is enough.
Your employment agreements should already include clauses dealing with confidentiality, intellectual property, lawful and reasonable directions, workplace policies, and use of business systems. The AI policy should work with those clauses, not contradict them. Before you hire your first worker, or before you roll out AI tools to an existing team, it is worth checking that your contracts support the policy you want to enforce.
Where contractors also access your systems, a separate contractor agreement or services agreement may need similar restrictions. Do not assume employees and contractors can be treated the same way. Before you classify someone as a contractor, make sure the underlying arrangement is correct and that any AI related obligations are reflected in the contract.
Privacy and data handling are usually the first pressure point
If staff use AI tools with personal information, your Privacy Act obligations remain front and centre. The practical issue is simple. Once data is pasted into a third party tool, your business may lose visibility over how that information is stored, used, or retained.
Your policy should deal clearly with:
- whether personal information can be used in AI prompts at all
- whether de-identification is required before using data
- whether customer consent or internal approval is needed for certain use cases
- whether offshore processing or storage is permitted
- how staff should respond if they accidentally disclose personal information through an AI tool
This matters even more if your business handles sensitive data, such as health information, employee records, children’s data, or customer financial details.
AI policies are also a governance tool
For startups and growing SMEs, an employee AI use policy helps management set a position before bad habits become normal. It gives team leaders a reference point when approving tools, training staff, or dealing with mistakes.
If your business later enters a client contract that asks about security, privacy, confidentiality, or use of subcontractors and automated tools, having a clear internal policy can also support your responses. It will not solve every due diligence question, but it shows that your business has thought about how AI is actually used.
Legal Issues To Check Before You Sign
Before you sign off on an employee AI use policy, make sure it can actually be enforced and that it matches the way your business works. The main risk is adopting a policy that looks sensible on paper but clashes with your contracts, privacy position, or internal systems.
Employment law and workplace policy enforceability
In New Zealand, employers can usually issue lawful and reasonable workplace policies, but the details matter. A policy that is vague, inconsistent, or introduced without proper communication can be harder to rely on later.
Before you sign, check:
- whether your employment agreements clearly require compliance with workplace policies
- whether the AI policy is expressed as guidance, a mandatory rule, or a mix of both
- whether managers understand how to apply it consistently
- whether disciplinary consequences are realistic and proportionate
- whether staff should be consulted before major changes are introduced, especially where monitoring or job design may be affected
If the policy is likely to affect how employees perform their role, how their work is monitored, or whether certain tasks are automated, a broader employment process may be needed. This is particularly relevant before you rely on AI as part of performance management, recruitment filtering, or internal decision making.
Confidentiality and client obligations
If your business has promised customers, suppliers, or commercial partners that their information will be kept secure, AI use can create a contract problem as well as an internal one. A staff member may breach those obligations simply by uploading material to a tool that is not approved.
Review your customer and supplier contracts before you accept the provider's standard terms for a new AI tool. Some agreements restrict offshore disclosure, subcontracting, data processing methods, or use of third party platforms. Your internal policy should not permit conduct that your external contracts prohibit.
Privacy Act compliance
A policy that allows broad AI use without privacy controls is asking for trouble. If staff use personal information in AI systems, your business should have a clear basis for doing so and clear limits around that use.
You may need to think about:
- what categories of personal information employees handle
- whether the tool provider stores prompts and outputs
- whether data is used to train the provider’s models
- whether information is transferred outside New Zealand
- whether your privacy notice, disclosures, and internal procedures need updating
- whether a privacy impact assessment is sensible for higher risk use cases
The policy should also tell staff what to do if they suspect an AI related privacy breach. Speed matters when personal information is exposed.
Intellectual property and ownership of outputs
Your business should decide in advance who owns AI assisted work product and what staff are allowed to create with third party tools. This is not just a drafting point. It affects client deliverables, internal product development, branding, software, and marketing content.
Before you sign, look at:
- your employment agreement intellectual property clauses
- the provider’s terms on ownership, reuse, and training
- whether staff can input proprietary code, designs, or unpublished materials
- how AI generated content is checked for copyright, originality, and infringement risks
If your team creates branded content, product copy, design assets, or software, human review is especially important. AI output can look original while still creating infringement or ownership uncertainty.
Accuracy, bias, and decision making
If employees use AI to support decisions about candidates, staff, customers, pricing, or risk, your policy should not assume the tool is neutral. Human review needs to be built into the process.
This matters where AI tools influence:
- recruitment screening
- performance reviews
- customer communications
- credit, pricing, or service decisions
- legal, financial, or technical advice prepared for clients
Where a wrong output could cause real harm, the policy should clearly say that AI is an assistant, not the final decision maker.
Monitoring and staff expectations
If your business plans to monitor AI use, prompt histories, or employee activity on approved tools, be upfront about it. Hidden monitoring creates trust issues and can trigger employment disputes.
Your policy should explain what monitoring occurs, why it occurs, and how the information may be used. It should also align with any broader technology, surveillance, or acceptable use policies already in place.
Common Mistakes With Employee AI Use Policy
The most common mistake is treating an employee AI use policy as a generic document problem rather than a practical workplace rule. A policy only works if staff understand it, managers apply it, and the business has systems that support it.
Using a policy copied from an overseas template
Many AI policies are written for large overseas companies with different privacy rules, different employment frameworks, and different technology stacks. A New Zealand business needs something more grounded.
If your policy refers to approval processes, legal standards, or monitoring practices that do not fit your business, staff will ignore it. That creates a false sense of protection.
Banning AI completely, then looking the other way
Some businesses respond by prohibiting all AI use. In practice, staff still use it quietly on personal devices or unapproved accounts because the tools save time.
A blanket ban can be appropriate for some high risk tasks, but many businesses need a more realistic model. Approved tools, approved use cases, and clear red lines usually work better than pretending the technology is not there.
Failing to define confidential information clearly
If the policy says “do not upload confidential information” but never explains what that means, the rule is too loose. Staff may not realise that draft contracts, pricing models, board papers, customer complaints, code repositories, or internal HR issues all fall into that category.
Concrete examples matter. This is especially true for smaller teams where people wear multiple hats and move quickly.
Ignoring contractors and temporary workers
Founders often focus on employees and forget the marketing freelancer, software contractor, or virtual assistant with access to business systems. If those people are using AI tools on your information, they create similar risks.
Use contract terms that reflect your AI position. Confidentiality, data handling, intellectual property, and approved tool requirements should not stop at the payroll line.
Assuming AI output is fine if a person pressed send
Human involvement alone does not solve the problem. If the review is rushed or purely cosmetic, the business still wears the consequences of inaccurate or misleading content.
Your policy should say what meaningful review looks like for different tasks. A blog draft, a customer support reply, a software update, and a hiring recommendation do not all need the same level of checking, but none should be left entirely to automation without thought.
Forgetting training and rollout
A policy sent as a PDF with no discussion is often ineffective. Staff need examples, scenarios, and a place to ask questions.
Managers also need guidance. If one manager informally encourages AI use for speed while another threatens disciplinary action for the same behaviour, the policy will quickly lose credibility.
Not reviewing provider terms before use
The provider’s standard terms can shape how data is stored, whether inputs are retained, what rights the provider claims, and what security commitments exist. Internal rules alone do not override those terms.
Before you rely on a verbal promise from a sales representative, review the written terms and make sure they match what your policy permits staff to do.
Leaving the policy untouched after the first draft
AI use changes quickly. New tools are introduced, teams adopt new workflows, and customer expectations shift. A policy that made sense six months ago may already be out of date.
Set a review point and update the document when business practices change, especially if you move into more sensitive data handling or more automated decision making.
FAQs
Do all New Zealand businesses need an employee AI use policy?
Not every business is legally required to have one, but if your staff use AI for work, a written policy is usually a sensible step. It helps with privacy, confidentiality, quality control, and employment management.
Can we just add one line to our IT policy instead?
Sometimes a short addition is enough for very limited AI use, but many businesses need more detail. If staff are using AI for client work, recruitment, coding, internal documents, or customer communications, a dedicated policy is often better.
Can employees use public AI tools with work information?
That depends on your rules and the tool involved. Many businesses prohibit staff from entering confidential or personal information into public tools, especially where the business cannot control storage, retention, or training use.
Should contractors be covered too?
Yes, if contractors access your systems, data, or deliverables. Usually this is handled through a contractor agreement or services agreement rather than an employee policy alone.
What should happen if someone breaches the policy?
The policy should set out reporting steps, investigation expectations, and possible consequences. Outcomes should be proportionate and consistent with employment law, existing agreements, and the seriousness of the breach.
Key Takeaways
- An employee AI use policy helps New Zealand businesses control how staff use AI tools at work.
- The policy should cover approved tools, banned uses, confidentiality, privacy, data handling, human review, monitoring, and breach reporting.
- It should align with employment agreements, contractor arrangements, and customer or supplier contracts.
- Privacy Act issues are often the first major risk, especially where staff may input personal information into third party tools.
- AI output should not be treated as reliable without review, particularly for client advice, recruitment, software, or sensitive business decisions.
- A policy works best when it is tailored to your business, supported by training, and reviewed as your use of AI changes.
If you want help with employment agreement updates, privacy and confidentiality controls, contractor terms, or internal workplace policies, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get employment right
When should you get employment help?
Employment topics can become risky quickly when documentation, consultation, termination or contractor status is involved.







