An AI usage policy doesn't need to be long. For most businesses one or two pages is enough. What matters is that it names the tools people may use, says what must never go into them, and puts a person in charge.
The gap is real. In a July 2026 survey, 83% of EMA member businesses surveyed use AI, and 13% have a policy for it (EMA, July 2026). EMA's members are employers who belong to an association, so they skew larger than the average NZ business. But the pattern will be familiar: people started using ChatGPT, Copilot or Gemini on their own, and nobody wrote anything down.
Do you need one?
If anyone in your business uses an AI chat tool, an AI notetaker, or an AI feature inside software you already pay for, then yes. You don't need one because a law says so. New Zealand has no AI-specific law. You need one because the laws you already work under, especially the Privacy Act 2020, still apply when the work goes through an AI tool.
The Privacy Commissioner has published what it expects from organisations using generative AI. MBIE has published voluntary Responsible AI Guidance for Businesses (July 2025), which says usage policies are "a good way to communicate the organisation's stance on AI and rules for its use". A short written policy is the simplest way to show you've thought about both.
What to put in it: ten sections
Each section below notes where the idea comes from, so you can read the source yourself.
1. Purpose and scope
Who the policy covers (staff, contractors, anyone with a work login) and what counts as an AI tool. Keep the definition broad: chat tools, notetakers, writing assistants, image tools, and AI features built into your existing software. MBIE's guidance starts with being clear about why you're using AI at all, which is a good opening line for the policy too.
2. The approved tools list
Name the tools people may use for work, and which version: the business or team tier, with model training turned off where the tool offers that. Anything not on the list needs approval first. MBIE's guidance suggests business usage policies tell staff "what tools are endorsed, and how they can be used". This list does most of the work in a business, because it's easy to follow and easy to check.
3. What never goes in
Spell out the information that must not be pasted or uploaded unless the tool is approved for it: personal information about customers or staff, health information, client confidential material, financial account details, and passwords. The Privacy Commissioner expects organisations to make sure personal or confidential information "is not retained or disclosed by the generative AI tool". If you can't confirm that for a tool, keep that information out of it.
4. A person checks before anything goes out
Any AI output that reaches a customer, or that drives a decision about a person, gets checked by a person first. This is one of the Privacy Commissioner's expectations: human review before acting on AI output. In practice it means AI drafts and a person sends.
5. Check facts, figures, laws and dates
AI tools can state wrong things with total confidence. MBIE's guidance describes this "hallucination" risk and notes that a tool may "fabricate information as truth". Your policy should say plainly that staff check any fact, number, legal point or date before using it.
6. Telling people when AI is used
Say when you tell customers that AI is involved. For example: when an AI notetaker is recording a meeting, or when a chat assistant on your website answers questions. The Privacy Commissioner expects organisations to be transparent about how, when and why they use generative AI tools.
7. Privacy checks before a new tool
Before a new tool goes on the approved list, someone answers a few questions. Where does it store data? Does the vendor keep it or train on it? Does it pull in information about people from other sources? The Privacy Commissioner expects a privacy impact assessment before you start. For a business that can be a one-page checklist. Our IPP3A guide has a six-question version.
8. Confidentiality and copyright in what you produce
Remind staff that client confidentiality still applies, and that AI output isn't automatically yours to use however you like. Don't feed in other people's copyright work without permission, and don't pass off AI output as original work where that matters, such as in a tender or a client report. MBIE's guidance flags intellectual property and confidentiality as things to consider before entering prompts and data.
9. Who owns it, and what to do when something goes wrong
Name one person who owns the policy and approves new tools. Say how staff ask for a new tool, and how they report a mistake, such as customer data pasted into the wrong tool. If personal information is involved, the owner checks whether it's a notifiable privacy breach under the Privacy Act. Write down who makes that call.
10. A review date
AI tools change their features and terms often. Set a review date, every six to twelve months, and when you add a new tool. MBIE's guidance builds in ongoing monitoring and improvement, and the Privacy Commissioner expects privacy assessments to be kept up to date.
A one-page staff version
Most people won't read two pages. Give them one table they can pin up.
| Do | Don't | Ask first |
|---|---|---|
| Use the approved tools, on your work login | Use a personal account for work | Trying a tool that isn't on the list |
| Draft, summarise and tidy with AI | Paste in customer, staff or health details | Using AI with client or customer information |
| Check every fact, figure and date | Send AI output without reading it | Using AI to help decide something about a person |
| Tell people when an AI notetaker is on | Enter passwords or bank details | Publishing AI-made images or text under our name |
| Report mistakes straight away | Hide a slip because it's awkward | Anything you're unsure about |
Add-ons for some industries
- Accountants and bookkeepers. Your professional confidentiality obligations apply to client data in AI tools. Check your professional body's current guidance on technology and confidentiality.
- Clinics. Health information is covered by the Health Information Privacy Code 2020. The Dental Council's guidance says to explain what AI will be used for and get consent before using it in patient care. Check whether your own board has guidance.
- Property managers. Only collect tenant information you actually need, and keep AI out of choosing between applicants.
Common mistakes
- A ban nobody follows. In our experience a flat ban pushes AI use onto personal accounts, where you can't see it. An approved list is easier to enforce. That's our opinion, not a rule.
- An overseas template. A policy that talks about GDPR or US state laws tells staff nothing about the Privacy Act.
- No approved list. Rules about "appropriate use" without naming tools leave every decision to the individual.
- No owner. If nobody approves tools or reviews the policy, it's out of date within months.
What a policy is not
A policy doesn't make your AI use lawful by itself, and this guide isn't legal advice. It's a written record of sensible rules, based on the Privacy Commissioner's expectations and MBIE's voluntary guidance. If you handle sensitive information or make decisions about people with AI, get advice for your situation.
Sources
Checked on 8 October 2026. Laws and guidance change, so check the source before relying on it.
- EMA: AI adoption surges among SMEs (9 July 2026)
- Privacy Commissioner: expectations for generative AI (15 June 2023)
- Privacy Commissioner: AI and the Information Privacy Principles (September 2023)
- MBIE: Responsible AI Guidance for Businesses (July 2025)
- Dental Council: Responsible use of AI in oral health practice (updated July 2026, PDF)