Generative AI Use Policies for NZ Employers

Alex Solo
byAlex Solo11 min read

Generative AI tools are already showing up at work, often before management has decided what is allowed. A team member pastes customer data into a chatbot, a manager uses AI to draft a warning letter, or a contractor uploads internal documents to a public tool without thinking through ownership or privacy. Those are common mistakes, and they can create real employment, confidentiality and privacy problems for New Zealand businesses.

A generative AI use policy helps set the rules before those issues turn into disputes. It tells staff what tools they can use, what information they must never enter, how AI output should be checked, and what happens if the policy is ignored. If you are an employer in New Zealand, this guide explains what a workable policy should cover, the legal issues to think about before you sign or roll one out, and where businesses often get caught.

Overview

A generative AI use policy is an internal workplace policy that sets boundaries for how employees, contractors and managers may use AI tools in the course of work. For New Zealand employers, the main legal pressure points are usually privacy, confidentiality, intellectual property, employment process, and making sure staff understand the rules clearly enough for them to be enforced fairly.

  • which AI tools are approved, banned, or require prior approval
  • what business, customer, employee, and commercially sensitive information must never be entered into public AI systems
  • whether AI can be used for recruitment, performance management, disciplinary documents, customer communications, coding, or marketing content
  • who owns prompts, outputs, and AI-assisted work created in employment
  • what human review is required before AI output is used or sent externally
  • how the policy fits with employment agreements, privacy processes, confidentiality terms, and IT policies
  • what training, monitoring, and consequences apply if staff breach the policy

What Generative AI Use Policy Means For New Zealand Businesses

A generative AI use policy gives your business a clear internal rulebook for AI use at work. It is not just an IT document, it sits across employment, privacy, confidential information, and risk management.

For many founders and managers, the issue is not whether staff are using AI. The issue is that they are already using it informally. Without a policy, people tend to make their own judgement calls about what data can be uploaded, whether AI-written content can be sent straight to clients, and whether AI output is accurate enough for HR or operational decisions.

That creates inconsistency, and inconsistency is where businesses often get caught. If one manager allows AI use and another treats it as misconduct, you may end up with unfairness arguments. If one employee enters payroll information or customer complaints into a public chatbot, the privacy and confidentiality consequences can be serious.

Why employers are adopting AI use policies

Most businesses are adopting a generative AI use policy for one reason, they want the efficiency benefits without losing control of legal and operational risk.

A well-drafted policy can help you:

  • set acceptable use boundaries before staff rely on a verbal promise or informal team practice
  • reduce the chance of confidential information being disclosed to third party AI providers
  • support compliance with New Zealand privacy obligations when personal information is involved
  • avoid poor employment decision-making based on unchecked AI summaries or recommendations
  • clarify when human review is mandatory
  • show staff and contractors that AI is a business tool, not a free-for-all

What the policy usually covers

The right policy for your business depends on how your team uses AI. A software company using coding assistants will need something different from a professional services firm using AI for drafting, or a retail business using AI for customer communications.

Most NZ employer policies deal with the following:

  • approved platforms and account rules, including whether staff can use personal accounts for work tasks
  • prohibited inputs, such as customer data, health information, employee records, financial data, legal advice, source code, pricing models, and confidential contracts
  • approved use cases, such as brainstorming, internal first drafts, summarising non-sensitive material, or administrative support
  • restricted use cases, such as recruitment decisions, disciplinary letters, termination documentation, financial advice, or public statements without review
  • accuracy checks and fact verification requirements
  • requirements to label or disclose AI-assisted work internally where needed
  • record-keeping and approval workflows for higher-risk uses
  • consequences for misuse

Policy or contract, what is the difference?

A workplace AI policy is usually not the same thing as an employment agreement, but the two should work together. The policy sets operational rules, while the employment agreement deals with binding employment terms such as duties, confidentiality, intellectual property, and disciplinary frameworks.

That distinction matters before you sign or issue anything. If you want certain AI restrictions to be clearly enforceable, you may need more than a standalone policy. You may also need employment agreement clauses, contractor agreement terms, confidentiality wording, and IT acceptable use rules that support the policy.

Who should the policy apply to?

The safest approach is to think beyond employees. If contractors, consultants, agency workers, interns, or offshore support providers can access your systems or information, they should be covered by clear AI use rules too.

That often means using a mix of documents:

  • an internal AI use policy for workers
  • employment agreement wording for employees
  • contractor agreement provisions for non-employees
  • confidentiality and intellectual property clauses
  • privacy and data handling procedures

The main legal question is whether your AI policy actually matches the way your business handles data, employment decisions, and ownership of work product. A generic overseas template often misses New Zealand legal context and your real workplace risks.

Privacy and personal information

If staff enter personal information into a generative AI tool, privacy issues arise quickly. In New Zealand, businesses need to handle personal information in line with privacy obligations, and that includes being clear about collection, use, storage, access and disclosure.

Before you accept the provider's standard terms or approve a tool for work use, check:

  • what information the tool collects and stores
  • whether prompts and outputs are used to train the provider's systems
  • where data is stored and whether overseas disclosure is involved
  • whether the tool allows business settings that reduce training or retention risks
  • whether your privacy notice, privacy documentation, and internal processes need updating

This matters even more if your team handles HR records, health details, complaint information, customer profiles, or financial data. A policy should say plainly what staff must never input into public or unapproved systems.

Confidential information and trade secrets

The main risk is accidental disclosure. Staff often treat a chatbot like a private drafting assistant when, legally and commercially, that assumption may be unsafe.

If employees upload internal strategies, source code, pricing models, supplier terms, customer lists, or unpublished product plans, your business may lose control of valuable confidential information. Your policy should identify these categories clearly and ban or tightly restrict their use in AI tools unless a vetted enterprise system is approved for that purpose.

Intellectual property and ownership

Your policy should state who owns AI-assisted work created in the course of employment and what limits apply. Otherwise, ownership can become murky, especially where staff use personal accounts, external plug-ins, or mixed personal and business prompts.

Key points to deal with include:

  • whether prompts, outputs, edits and final deliverables created for work belong to the employer
  • whether staff may use AI-generated content from earlier roles or outside projects in your business
  • whether the tool's terms claim broad rights over uploaded content
  • whether copyright risks arise if AI output closely resembles third party material

For creative, software, marketing and product teams, this is not just a technical point. It affects what your business can safely reuse, commercialise, or claim as its own.

Employment process and fair treatment

Employers should not outsource judgement to AI in employment matters. AI can assist with drafting or summarising, but disciplinary decisions, performance concerns, recruitment assessments and termination processes still need human judgement and fair process.

This is where founders often get caught. A manager asks AI to draft a warning letter based on incomplete notes, copies it into an email, and sends it without checking for accuracy or tone. Another manager uses AI to score CVs without understanding how the tool reaches its recommendations. Those shortcuts can create legal and people risks at the same time.

Your policy should address whether AI can be used in:

  • recruitment and candidate screening
  • performance reviews
  • disciplinary investigations
  • warnings and termination letters
  • employee monitoring or productivity scoring

For many businesses, the safest position is to restrict or require senior approval for these higher-risk uses.

Contract and supplier terms

Before you sign with an AI provider, check the contract terms carefully. Standard terms may give the provider broad rights over inputs and outputs, wide limitations of liability, or weak commitments on data handling and service quality.

Review points often include:

  • data use and training rights
  • confidentiality commitments
  • security standards
  • subcontracting and offshore processing
  • service levels and outage risk
  • indemnities and liability caps
  • termination rights and data deletion on exit

If your customers or clients require strict confidentiality, you may also need to check your own outgoing contracts. Some agreements effectively prevent the use of public AI tools for that work unless the client consents.

Monitoring and policy enforcement

A policy is easier to enforce when staff have been told clearly what is expected and trained on how the rules apply. If you intend to monitor system use, prompts, downloads, or access logs, that should also be addressed lawfully and transparently through your wider workplace documentation and practices.

Disciplinary consequences should be proportionate and tied to existing workplace processes. Avoid vague statements that every breach is serious misconduct. That may be true for some conduct, such as deliberate disclosure of sensitive data, but not for every accidental or low-risk misuse.

Common Mistakes With Generative AI Use Policy

The biggest mistake is treating AI as a minor tech issue instead of a business-wide legal and operational issue. A short policy copied from overseas often leaves the real risks untouched.

Using a generic template without matching it to your workplace

Different teams use AI differently. Sales, marketing, HR, engineering, finance and customer support do not carry the same level of risk. A template that simply says staff must use AI responsibly will not help much if no one knows what that means in practice.

A better approach is to tailor the policy to the actual tasks your workers perform. If your team drafts client documents, writes code, handles employee records, or uses AI to create public content, the policy should say what is allowed for each area.

Banning everything, then ignoring reality

Some employers respond by imposing a total ban on AI use. That can be appropriate in narrow contexts, but many businesses find staff keep using tools quietly anyway, often through personal accounts. That creates a shadow system with less visibility and more risk.

If you want the policy to work, it needs to be practical. Staff should know:

  • which tools are approved
  • which tasks are acceptable
  • when approval is required
  • what information is off limits
  • what review steps must happen before output is used

Forgetting contractors and external workers

Many businesses focus only on employees. Then a contractor, freelancer or consultant uses AI in a way that exposes confidential material or creates ownership uncertainty.

If non-employees do meaningful work for your business, your contractor agreements should align with the same core rules on confidentiality, data handling, ownership, and permitted AI use.

Allowing AI in HR decisions without safeguards

This is a high-risk area. AI-generated interview questions, CV ranking, misconduct summaries, and warning letters can all look efficient, but they can also be inaccurate, biased, or poorly reasoned.

Human oversight should be built into the policy. If the tool is used in people management, someone with authority and context needs to review the output carefully before any action is taken.

Ignoring training and rollout

A policy sitting in a folder is not much use. Staff need practical examples, not just a one-line instruction to comply.

Training should cover situations such as:

  • what to do if a client asks whether AI was used
  • how to remove or avoid personal information in prompts
  • when AI output needs fact checking
  • when legal or management approval is required
  • what happens if a mistake has already been made

Managers also need guidance. If supervisors use AI carelessly in recruitment or discipline, the policy will not be taken seriously by the rest of the team.

An AI policy should not sit alone. If your current employment agreements, contractor terms, confidentiality clauses, privacy wording, and IT policies say nothing about AI or data use, the policy may have gaps.

Before you roll it out, review whether related documents need to be updated so they all point in the same direction, including any staff handbook or workplace policy set.

FAQs

Do NZ employers legally need a generative AI use policy?

No specific law says every employer must have one, but many businesses now need one in practice. If your staff use AI at work, a written policy helps manage privacy, confidentiality, ownership and employment process risks.

Can employees use public AI tools for work?

Sometimes, but only if your business allows it and the task is appropriate. Public tools should not be used for sensitive information unless you have carefully assessed the provider, the data handling terms, and the use case.

Should a generative AI use policy be part of the employment agreement?

Usually, the policy sits alongside the employment agreement rather than replacing it. Important supporting issues, such as confidentiality, intellectual property, acceptable use and disciplinary consequences, are often strengthened by written terms in the contract.

Can we use AI for recruitment or disciplinary documents?

You can allow limited assistance, but high-risk HR uses need caution. AI should not replace human judgement, fair process, or proper review, especially for candidate assessment, warnings, investigations or termination communications.

What should we do if staff are already using AI without approval?

Act quickly and calmly. Identify what tools are being used, what data has been entered, whether any privacy or confidentiality issue needs to be managed, and then put a clear interim rule in place while you finalise a formal policy and related contract updates.

Key Takeaways

  • A generative AI use policy helps New Zealand employers control how staff and contractors use AI at work.
  • The most common legal issues are privacy, confidential information, intellectual property, provider contract terms, and fair employment processes.
  • Your policy should clearly state approved tools, banned inputs, acceptable use cases, required human review, and consequences for misuse.
  • Higher-risk uses, especially recruitment, performance management and disciplinary processes, need tighter safeguards or restrictions.
  • The policy should align with employment agreements, contractor terms, confidentiality clauses, privacy processes and IT rules.
  • Training and practical rollout matter just as much as the written document.

If you want help with employment agreement updates, contractor terms, privacy risk issues, and supplier contract reviews, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get employment right

When should you get employment help?

Employment topics can become risky quickly when documentation, consultation, termination or contractor status is involved.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get employment right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.