AI Insights · AI Governance & Compliance · 5 min read

How to Write an AI Use Policy for Your Organisation (NZ Guide)

Last updated 17 July 2026

An AI use policy tells your staff what AI tools they can use, what data they can put into them, and what stays off-limits. For a New Zealand organisation the essentials are: approved tools, clear rules on personal and confidential data (aligned with the Privacy Act), a requirement for human review of important output, and named accountability. A short, clear policy that people actually read beats a long one nobody follows.

Why do you need an AI use policy?

Because staff are already using AI, with or without permission. Without a policy, sensitive data ends up in personal accounts ("shadow AI"), and no one owns the risk. A clear policy turns unmanaged, invisible AI use into governed, visible use — and it's a basic expectation if you handle personal data under the Privacy Act.

What should an AI use policy include?

  • Approved tools — which AI tools are sanctioned, and which are not to be used for work.
  • Data rules — what data can and cannot be entered, especially personal or confidential information.
  • Privacy alignment — how the policy meets your obligations under the NZ Privacy Act.
  • Human oversight — a requirement to review AI output before it is used for anything consequential.
  • Accountability — who owns AI decisions, and who to ask when unsure.
  • Transparency — when and how AI use should be disclosed.

What does a simple AI use policy structure look like?

Keep it to a single page where possible: purpose and scope; approved tools; what data is allowed and prohibited; the human-review requirement; accountability and who to contact; and a short review date so it stays current. Start proportionate and tighten as your AI use grows — a policy people understand and follow is worth far more than an exhaustive document that sits unread.

How do you get staff to actually follow the policy?

A policy only reduces risk if people read and follow it, which is a communication problem as much as a drafting one. Keep the language plain and the document short, launch it with a few minutes of practical training rather than an email nobody opens, and — most importantly — pair it with a genuinely good sanctioned tool. Staff bypass rules when the approved option is worse than the free one they already use; they follow them when the safe path is also the easy path. Frame the policy as "here is how to use AI well", not "here is a list of bans", and adoption improves markedly.

How often should the policy be reviewed?

AI tools and your own use of them change fast, so a policy written once and filed away goes stale quickly. Build in a review date — every six to twelve months is a sensible cadence for most New Zealand organisations — and revisit it sooner whenever you adopt a new tool, change what data it may touch, or your obligations shift. A short policy that is kept current is far more useful than a comprehensive one that describes tools you no longer use and ignores the ones staff actually rely on.

Frequently asked questions

Yes. Even a small team using a public AI tool should have a clear rule on what customer or personal data can be entered. The Privacy Act applies regardless of size.

The policy is one part of governance. Governance also covers accountability, risk assessment and monitoring — but a clear use policy is usually the fastest, highest-value first step.

No — this is general guidance. For your specific obligations, consult the Office of the Privacy Commissioner’s guidance and your own legal advisors.

Ready to talk it through?

Book a free discovery call. No preparation required — just tell us what you’re trying to solve.