AI usage policy for NZ businesses: what to put in it

Your team is probably using AI already. A policy just writes down what's OK, what isn't, and who to ask. Here's what an NZ business should put in one, and where each part comes from.

By Miro · A 9-minute read · for owners and managers of NZ businesses · Last checked: 8 October 2026

An AI usage policy doesn't need to be long. For most businesses one or two pages is enough. What matters is that it names the tools people may use, says what must never go into them, and puts a person in charge.

The gap is real. In a July 2026 survey, 83% of EMA member businesses surveyed use AI, and 13% have a policy for it (EMA, July 2026). EMA's members are employers who belong to an association, so they skew larger than the average NZ business. But the pattern will be familiar: people started using ChatGPT, Copilot or Gemini on their own, and nobody wrote anything down.

Do you need one?

If anyone in your business uses an AI chat tool, an AI notetaker, or an AI feature inside software you already pay for, then yes. You don't need one because a law says so. New Zealand has no AI-specific law. You need one because the laws you already work under, especially the Privacy Act 2020, still apply when the work goes through an AI tool.

The Privacy Commissioner has published what it expects from organisations using generative AI. MBIE has published voluntary Responsible AI Guidance for Businesses (July 2025), which says usage policies are "a good way to communicate the organisation's stance on AI and rules for its use". A short written policy is the simplest way to show you've thought about both.

What to put in it: ten sections

Each section below notes where the idea comes from, so you can read the source yourself.

1. Purpose and scope

Who the policy covers (staff, contractors, anyone with a work login) and what counts as an AI tool. Keep the definition broad: chat tools, notetakers, writing assistants, image tools, and AI features built into your existing software. MBIE's guidance starts with being clear about why you're using AI at all, which is a good opening line for the policy too.

2. The approved tools list

Name the tools people may use for work, and which version: the business or team tier, with model training turned off where the tool offers that. Anything not on the list needs approval first. MBIE's guidance suggests business usage policies tell staff "what tools are endorsed, and how they can be used". This list does most of the work in a business, because it's easy to follow and easy to check.

3. What never goes in

Spell out the information that must not be pasted or uploaded unless the tool is approved for it: personal information about customers or staff, health information, client confidential material, financial account details, and passwords. The Privacy Commissioner expects organisations to make sure personal or confidential information "is not retained or disclosed by the generative AI tool". If you can't confirm that for a tool, keep that information out of it.

4. A person checks before anything goes out

Any AI output that reaches a customer, or that drives a decision about a person, gets checked by a person first. This is one of the Privacy Commissioner's expectations: human review before acting on AI output. In practice it means AI drafts and a person sends.

5. Check facts, figures, laws and dates

AI tools can state wrong things with total confidence. MBIE's guidance describes this "hallucination" risk and notes that a tool may "fabricate information as truth". Your policy should say plainly that staff check any fact, number, legal point or date before using it.

6. Telling people when AI is used

Say when you tell customers that AI is involved. For example: when an AI notetaker is recording a meeting, or when a chat assistant on your website answers questions. The Privacy Commissioner expects organisations to be transparent about how, when and why they use generative AI tools.

7. Privacy checks before a new tool

Before a new tool goes on the approved list, someone answers a few questions. Where does it store data? Does the vendor keep it or train on it? Does it pull in information about people from other sources? The Privacy Commissioner expects a privacy impact assessment before you start. For a business that can be a one-page checklist. Our IPP3A guide has a six-question version.

8. Confidentiality and copyright in what you produce

Remind staff that client confidentiality still applies, and that AI output isn't automatically yours to use however you like. Don't feed in other people's copyright work without permission, and don't pass off AI output as original work where that matters, such as in a tender or a client report. MBIE's guidance flags intellectual property and confidentiality as things to consider before entering prompts and data.

9. Who owns it, and what to do when something goes wrong

Name one person who owns the policy and approves new tools. Say how staff ask for a new tool, and how they report a mistake, such as customer data pasted into the wrong tool. If personal information is involved, the owner checks whether it's a notifiable privacy breach under the Privacy Act. Write down who makes that call.

10. A review date

AI tools change their features and terms often. Set a review date, every six to twelve months, and when you add a new tool. MBIE's guidance builds in ongoing monitoring and improvement, and the Privacy Commissioner expects privacy assessments to be kept up to date.

A one-page staff version

Most people won't read two pages. Give them one table they can pin up.

DoDon'tAsk first
Use the approved tools, on your work loginUse a personal account for workTrying a tool that isn't on the list
Draft, summarise and tidy with AIPaste in customer, staff or health detailsUsing AI with client or customer information
Check every fact, figure and dateSend AI output without reading itUsing AI to help decide something about a person
Tell people when an AI notetaker is onEnter passwords or bank detailsPublishing AI-made images or text under our name
Report mistakes straight awayHide a slip because it's awkwardAnything you're unsure about

Add-ons for some industries

  • Accountants and bookkeepers. Your professional confidentiality obligations apply to client data in AI tools. Check your professional body's current guidance on technology and confidentiality.
  • Clinics. Health information is covered by the Health Information Privacy Code 2020. The Dental Council's guidance says to explain what AI will be used for and get consent before using it in patient care. Check whether your own board has guidance.
  • Property managers. Only collect tenant information you actually need, and keep AI out of choosing between applicants.

Common mistakes

  • A ban nobody follows. In our experience a flat ban pushes AI use onto personal accounts, where you can't see it. An approved list is easier to enforce. That's our opinion, not a rule.
  • An overseas template. A policy that talks about GDPR or US state laws tells staff nothing about the Privacy Act.
  • No approved list. Rules about "appropriate use" without naming tools leave every decision to the individual.
  • No owner. If nobody approves tools or reviews the policy, it's out of date within months.

What a policy is not

A policy doesn't make your AI use lawful by itself, and this guide isn't legal advice. It's a written record of sensible rules, based on the Privacy Commissioner's expectations and MBIE's voluntary guidance. If you handle sensitive information or make decisions about people with AI, get advice for your situation.

Sources

Checked on 8 October 2026. Laws and guidance change, so check the source before relying on it.

Written by Miro at Even Odds · Not legal advice · Last checked: 8 October 2026

AI policy questions

Is an AI policy a legal requirement in NZ?

No law requires one, and New Zealand has no AI-specific law. The Privacy Act 2020 still applies when you use AI with personal information, and the Privacy Commissioner has set out what it expects. A written policy is the simplest way to show you've thought it through.

Should we just ban ChatGPT?

You can, but in our experience bans push use onto personal accounts where you can't see it. An approved list, with business-tier tools and clear rules on what never goes in, is easier to enforce. That's our opinion; some businesses with very sensitive data do choose a ban.

How long should our AI policy be?

One or two pages for most businesses, plus a one-page staff summary. Long policies tend not to get read.

Does it need to cover Māori data?

The Privacy Commissioner expects organisations to engage with Māori about the potential impacts of generative AI tools. Scale this to your business. If you hold information about Māori customers or communities, think about how AI use affects them and say so in the policy.

Will a policy make us compliant?

No document does that on its own. A policy is a record of sensible rules. What protects you is people following it, choosing tools carefully and checking output. This guide isn't legal advice.

Want it written for you?

Use this outline yourself, or get the AI Usage Policy: a written policy for your business, a one-page staff summary, an approved-tools list and a 30-minute staff session. Delivered within 5 working days of the intake call.

The AI Usage Policy is $295 + GST, fixed. It is not legal advice.