Generative AI Policies for New Zealand Workplaces: What Employers Should Cover

Alex Solo
byAlex Solo11 min read

Generative AI tools are already showing up in New Zealand workplaces, often before the employer has decided what is allowed. Staff use AI to draft emails, summarise meetings, write code, create marketing copy and review documents, sometimes on free public tools with no real thought about privacy, confidentiality or ownership.

The common mistakes are predictable: letting employees upload sensitive client data, assuming AI output automatically belongs to the business, and treating AI as an IT issue instead of an employment, privacy and risk issue.

A clear generative AI use policy helps employers set rules before problems become expensive. It tells workers what tools they can use, what information must never be entered into a model, how AI-generated work should be checked, and what happens if someone ignores the rules. If you employ staff in New Zealand, this guide explains what a practical workplace AI policy should cover, where the legal pressure points usually sit, and what founders should sort out before they rely on a provider's standard terms.

Overview

A workplace policy for generative AI should set clear boundaries around approved tools, banned uses, human review, privacy, intellectual property and staff accountability. The goal is not to ban useful technology, but to reduce the legal and operational risk that comes from casual or hidden use.

  • define what counts as generative AI and which tools are approved
  • set rules for confidential information, personal information and client data
  • state when human review is mandatory before output is used
  • deal with ownership, copyright risk and use of third party material
  • explain employment consequences for misuse or unauthorised use
  • check provider terms before you accept the provider's standard terms
  • train managers and staff so the policy works in practice

What Generative AI Use Policy Means For New Zealand Businesses

A generative AI use policy is an internal workplace document that tells your workers when and how they can use AI tools for business tasks. For most employers, it sits alongside existing policies on IT use, privacy, confidentiality, remote work, records management and disciplinary processes.

This matters because AI adoption usually starts informally. A team member tries a chatbot to draft a proposal. A manager uses an AI note taker in a meeting. A developer uses a coding assistant linked to external servers. If there is no policy, the business can lose control of data, create poor records, and expose itself to disputes about who approved what.

What the policy should do

A useful policy should answer practical questions employees actually have during the work day. If the document is vague, staff will fill the gaps themselves.

  • Which AI tools are approved for work use?
  • Can employees use free public AI tools on company devices?
  • What information is strictly prohibited from being uploaded?
  • When must a person check, edit or verify AI output?
  • Can AI be used for recruitment, performance management or disciplinary matters?
  • Who approves a new AI tool before the business starts using it?
  • What records need to be kept when AI is used for important decisions?

Why employers should not rely on informal instructions

Verbal warnings like “use common sense” are usually not enough. They do not tell staff what common sense means when they are under pressure to work quickly. This is where founders often get caught, especially before they hire their first worker or before they scale from a small team to multiple departments.

A written policy also helps if you later need to deal with misconduct, performance issues or a client complaint. If your expectations were never documented, enforcement becomes harder and the business may look inconsistent.

Where AI policies fit with New Zealand employment obligations

New Zealand employers still need to act fairly and reasonably when setting workplace rules and addressing employee conduct. A generative AI use policy should be introduced in a sensible way, communicated clearly, and applied consistently.

If the policy changes how employees do their jobs, monitor them more closely, or affects performance expectations, you may need to think carefully about consultation and implementation. The Fair Work style issues businesses worry about in other markets show up differently here, but the core lesson is the same: do not surprise your staff with unclear rules and then jump straight to punishment.

Privacy is another major issue. If employees enter personal information into an external AI tool, your business may create privacy risks even if the employee meant well. Under New Zealand privacy law, businesses need to think about what personal information they collect, how they use it, where it goes, who can access it, and whether people have been told enough about that use in a privacy notice.

Common workplace uses that need clear rules

Most businesses do not need one rule for all AI use. Different tasks create different risks.

  • marketing drafts and social media content, where false claims and brand issues can arise
  • customer support scripts, where inaccurate answers can create service and reputation problems
  • HR drafting, where personal information and bias concerns can be serious
  • software development, where code ownership, security and open source issues can appear
  • sales proposals and tenders, where confidential pricing and client information may be exposed
  • meeting summaries and note taking, where consent, privacy and record accuracy matter

That is why many employers create a core generative AI use policy, then add team-specific guidance where needed.

The main legal risks sit in the provider terms, your employment settings, and the data your team puts into the tool. Before you sign a contract, or before you accept the provider's standard terms through a click-through sign-up, you should check whether the tool actually fits your business and your legal obligations.

Privacy and personal information

If your staff will use AI tools with any personal information, privacy needs to be front and centre. Public tools may use prompts or uploaded material to train models, store data overseas, or give broad access rights to service providers.

Your policy should clearly state what data cannot be entered into an AI system without express approval.

  • employee records
  • customer contact details
  • health information
  • CVs, performance notes and disciplinary material
  • commercially sensitive client information
  • any information subject to confidentiality obligations

You should also look at whether the provider offers business settings that limit training on your data, allow account controls, and support deletion or retention settings. A free version of a tool may not be suitable for workplace use at all.

Confidentiality and trade secrets

Once confidential material is entered into the wrong system, the damage can be difficult to reverse. A policy should say plainly that confidential business information, client secrets, pricing models, source code, unreleased product plans and legal advice must not be uploaded unless the tool has been approved for that exact use.

This point matters before you sign customer contracts too. Some client agreements restrict subcontracting, offshore processing, or use of third party systems. An employee can accidentally put your business in breach by pasting client material into an AI prompt.

Intellectual property and ownership

Employers often assume that if an employee creates something with AI during work, the business automatically owns everything and can use it freely. That assumption is risky.

Your policy should explain that AI-assisted work may raise questions about:

  • whether output is original enough to attract copyright
  • whether the tool provider claims rights or licences over inputs and outputs
  • whether the output reproduces protected third party material
  • whether staff must disclose when content was generated or heavily assisted by AI

If your team creates important content, code, designs or training material, your employment agreements and contractor agreements should also align with the policy. Internal policy alone does not replace properly drafted IP clauses and written terms in contracts.

Accuracy, bias and human review

AI output can sound confident while being wrong. For employers, the legal issue is often not the tool itself but what someone did with its output.

Your policy should set mandatory human review rules for higher-risk uses, such as:

  • legal or compliance content
  • HR decisions
  • health and safety material
  • financial figures or modelling
  • public advertising claims
  • customer-facing advice

This is especially important under the Fair Trading Act, where misleading claims in marketing can create real exposure even if the false statement came from an AI tool. “The AI wrote it” is not much of a defence.

Employment process and disciplinary settings

A policy should also explain the consequences of misuse. That does not mean threatening dismissal for every mistake. It means drawing clear lines between accidental misuse, poor judgement, reckless conduct and deliberate misconduct.

The disciplinary section should work with your existing employment framework. If you later need to investigate unauthorised AI use, the process still needs to be fair. Policy wording should support reasonable employer action, not overreach in a way that becomes hard to enforce.

Procurement and vendor terms

Before you rely on a provider's standard terms, check the commercial points that usually get missed by busy founders and operations teams.

  • where the data is stored and processed
  • whether your data is used for model training
  • who owns inputs and outputs
  • what security commitments the provider gives
  • what happens on termination
  • whether there are meaningful warranties or the tool is supplied largely as-is
  • whether liability is capped at a very low amount

If a team is adopting AI for client work, this contract review matters before you spend money on setup or integrate the tool into your workflow.

Common Mistakes With Generative AI Use Policy

The biggest mistake is writing a policy that sounds sensible but gives employees no real direction. A short document with generic statements about responsible use will not do much when someone is deciding whether to upload a customer spreadsheet to a public chatbot.

Using a blanket ban that nobody follows

Some employers respond to uncertainty by banning AI completely. That can fail in practice because staff may keep using unapproved tools quietly, especially if clients expect fast turnarounds or competitors are using AI-assisted workflows.

A better approach is usually controlled permission. Approve certain tools, ban specific uses, and require sign-off for anything outside the approved list.

Ignoring existing employment documents

A policy should not sit alone. If your employment agreements, contractor agreements, confidentiality clauses and disciplinary policies do not line up, gaps appear quickly.

For example, you may want employees to disclose AI use in certain work product, but the employment contract says nothing about process changes, IP assignment or confidential information handling in external systems. This is where legal documents need to work together.

Treating AI output as final work product

Many businesses save time on drafting, but lose that time again when inaccurate output goes public. Problems often show up in client proposals, website copy, internal policies and recruitment materials.

Your policy should make clear that employees remain responsible for the final work. AI can assist, but it should not replace judgment, fact-checking or approval pathways.

Missing HR-specific risks

Using AI in people decisions creates higher risk than using it for a first draft of a blog post. Employers should be especially careful where AI is used in recruitment screening, performance reviews, disciplinary drafting or redundancy planning.

These uses can create problems around privacy, fairness, bias, record accuracy and over-reliance on automated suggestions. If AI will touch employment decisions, the policy should say so directly and often require senior approval.

Forgetting records and transparency

If an AI-assisted process leads to a complaint, a business may need to explain what happened. A policy should consider whether staff need to record:

  • which tool was used
  • what type of information was entered
  • whether personal or confidential information was involved
  • what checks were carried out before relying on the output
  • who approved the final result

You do not need burdensome paperwork for every low-risk use. But for important decisions, some audit trail can make a big difference.

Rolling out the policy without training

Even a well-drafted generative AI use policy can fail if managers and staff do not understand the reasons behind it. Training should be practical and role-based.

For example, sales staff need examples about tenders and customer promises. HR teams need examples about employee data and recruitment. Developers need examples about code repositories, security and third party rights.

Assuming one overseas template fits New Zealand law

Templates from overseas providers often reflect foreign employment rules, foreign privacy expectations and different business practices. They may also use language that is too broad, too technical or not aligned with New Zealand workplace documents.

A New Zealand employer should tailor the policy to its actual team structure, approved tools, customer obligations and employment arrangements. That is especially true if you engage both employees and contractors, or if you handle sensitive client information.

FAQs

Do New Zealand employers need a separate generative AI use policy?

Not always, but many do. If staff use AI tools for work, a separate policy or a well-drafted AI section in existing workplace policies can make expectations much clearer.

Can employees use free public AI tools for work?

Only if the employer allows it. Many businesses restrict or ban free public tools for work tasks because of privacy, confidentiality and ownership risks.

Should employees tell the business when they used AI?

Often yes, especially for higher-risk work such as client advice, recruitment, coding, legal content, or public marketing. Disclosure rules should be clear in the policy.

Does a workplace AI policy replace employment agreement clauses?

No. A policy helps set rules for day-to-day conduct, but employment agreements and contractor agreements still need suitable clauses for confidentiality, intellectual property, data handling and misconduct processes.

What if an employee breaches the policy?

The employer should follow a fair process and consider the seriousness of the conduct, the wording of the policy, the training given, and the surrounding facts. Not every breach justifies the same response.

Key Takeaways

  • A generative AI use policy helps New Zealand employers control how staff use AI tools at work, especially where privacy, confidentiality and work quality are at stake.
  • The policy should cover approved tools, banned uses, personal information, client data, human review, ownership issues and consequences for misuse.
  • Before you sign, or before you accept the provider's standard terms, check data use, security, ownership, liability and overseas processing terms carefully.
  • Your AI policy should match your employment agreements, contractor agreements, privacy practices and disciplinary processes.
  • Training and practical examples matter, because a policy that staff do not understand will not reduce risk.
  • Higher-risk uses such as HR decisions, customer-facing advice, marketing claims and confidential client work usually need stricter controls and clearer approval pathways.

If you want help with workplace policy drafting, employment contract updates, privacy risk settings, and provider contract review, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get employment right

When should you get employment help?

Employment topics can become risky quickly when documentation, consultation, termination or contractor status is involved.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get employment right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.