policy · Effective Jan 1, 2025
NZ regulates AI through New Zealand’s Strategy for Artificial Intelligence: Investing with Confidence.
New Zealand’s Strategy for Artificial Intelligence: Investing with Confidence · effective 2025
Updated 60 days ago · 3 sources · confidence: medium
Overview
New Zealand’s approach to artificial intelligence (AI) regulation is characterized by a philosophy of 'proportionate, risk-based' intervention designed to foster innovation while safeguarding fundamental rights and public trust. Unlike the European Union’s prescriptive, omnibus legislative model, New Zealand has deliberately chosen a decentralized path. This strategy is anchored in the belief that existing technology-neutral laws—such as the Privacy Act 2020, the Fair Trading Act 1986, and the Human Rights Act 1993—are sufficiently robust to address the majority of AI-related risks. The government’s role is primarily seen as a 'steward' and 'enabler,' providing clear guidance and removing regulatory barriers to encourage private sector investment, particularly among small and medium-sized enterprises (SMEs). The overarching goal is to position New Zealand as a 'fast follower' that can adapt to international trends while maintaining a unique local context, particularly regarding indigenous data rights. The regulatory maturity of the country has evolved rapidly since 2020, moving from high-level ethical principles to practical, operational frameworks. The publication of 'New Zealand’s Strategy for Artificial Intelligence: Investing with Confidence' in July 2025 marked a definitive policy shift toward active adoption. This strategy positions New Zealand as a pragmatic adopter that leverages AI to drive productivity in core sectors like agriculture, healthcare, and education. While the private sector operates under voluntary 'Responsible AI' guidance, the public service is held to higher standards of transparency and accountability, governed by the Government Chief Digital Officer (GCDO) and the 'Algorithm Charter for Aotearoa New Zealand,' which emphasizes the unique constitutional obligations under Te Tiriti o Waitangi (the Treaty of Waitangi). This dual-track system ensures that the state leads by example in ethical AI use while the broader economy remains flexible and competitive.
Regulatory approach
New Zealand utilizes a hybrid regulatory model that combines horizontal, technology-neutral legislation with sectoral 'soft law' and specific binding frameworks for high-trust digital services. The horizontal layer is dominated by the Privacy Act 2020, which governs how AI systems collect and process personal data. This is supplemented by the 'Algorithm Charter,' a voluntary but influential commitment for government agencies to ensure transparency and human oversight in algorithmic decision-making. The overall approach is 'light-touch,' meaning the government avoids imposing heavy compliance burdens that could stifle the burgeoning tech sector, instead opting for 'guidance-first' interventions that clarify how existing laws apply to emerging AI technologies. This approach is designed to be agile, allowing regulators to issue new guidance as technology evolves without the need for lengthy legislative cycles. A distinctive feature of New Zealand’s approach is the distinction between public and private sector expectations. Public service agencies are subject to the 'Public Service AI Framework' (2025), which mandates rigorous risk assessments, human-in-the-loop requirements for high-stakes decisions, and proactive disclosure of AI use. In contrast, the private sector is encouraged to follow the 'Responsible AI Guidance for Businesses' (2025), which maps to OECD principles but remains non-binding. However, where AI intersects with critical digital infrastructure—such as digital identity—the government has introduced binding legislation like the Digital Identity Services Trust Framework Act 2023. This creates a regulated ecosystem for accredited providers, ensuring that AI-driven identity verification meets strict security and privacy standards. This 'targeted regulation' model focuses on specific high-risk applications rather than the underlying technology itself. Governance of AI in New Zealand is distributed across several key agencies, with the Ministry of Business, Innovation & Employment (MBIE) leading the overarching national strategy and private-sector coordination. MBIE’s mandate is to ensure that AI policy supports economic growth and productivity while maintaining international interoperability. Within the public sector, the Government Chief Digital Officer (GCDO), situated within the Department of Internal Affairs (DIA), acts as the primary steward for AI standards, issuing the frameworks and guidance that govern how state services deploy automated systems. The GCDO also leads the cross-agency work programme on AI guardrails, capability, and innovation, ensuring a consistent approach across the public service. Enforcement is handled by existing regulators within their respective domains. The Office of the Privacy Commissioner (OPC) is the most active regulator in the AI space, possessing the power to investigate privacy breaches, issue compliance notices, and monitor how AI systems handle personal data. For digital identity, the Trust Framework Authority (within the DIA) oversees the accreditation and compliance of service providers. Additionally, the Commerce Commission monitors AI use in the context of consumer protection and competition law, ensuring that AI-driven pricing or marketing does not violate the Fair Trading Act. This multi-regulator model ensures that AI is not regulated in a vacuum but is integrated into the broader legal oversight of New Zealand’s digital economy, preventing the need for a new, centralized AI regulator.
Enforcement & penalties
Because New Zealand lacks a standalone AI Act, there are no 'AI-specific' statutory penalties. Instead, enforcement actions and financial sanctions are triggered through breaches of existing legislation. Under the Privacy Act 2020, the Privacy Commissioner can issue compliance notices to organizations failing to meet their obligations. While the Commissioner cannot currently levy large administrative fines for general privacy breaches, failure to notify the Commissioner of a 'notifiable privacy breach' (one likely to cause serious harm) is a criminal offense punishable by a fine of up to NZD 10,000. More significant financial consequences arise from proceedings in the Human Rights Review Tribunal, which can award damages for interference with privacy, including emotional distress and financial loss caused by biased or inaccurate AI decisions. In the realm of digital identity, the Digital Identity Services Trust Framework Act 2023 provides for more direct enforcement. The Trust Framework Authority can suspend or cancel the accreditation of providers who fail to meet the required standards. The Act also creates offenses for misrepresenting accreditation status or providing false information, with fines reaching up to NZD 50,000 for individuals and NZD 100,000 for bodies corporate. For private sector AI use that misleads consumers, the Commerce Commission can seek penalties under the Fair Trading Act, where companies can face fines of up to NZD 600,000 per offense for misleading or deceptive conduct. This ensures that while the regulatory approach is 'light-touch,' there are significant deterrents for the misuse of AI that causes tangible harm to individuals or the market.
Data protection
The data protection framework for AI in New Zealand is defined by the Privacy Act 2020, which is considered 'essentially equivalent' to international standards like the GDPR in many respects. The Act is built around 13 Information Privacy Principles (IPPs) that govern the entire data lifecycle. For AI developers and users, IPP 1 (Purpose of collection), IPP 3 (Collection from individual), and IPP 10 (Limits on use) are particularly critical, as they require agencies to have a clear, lawful purpose for data collection and to ensure that data used to train or prompt AI models is handled transparently. The Office of the Privacy Commissioner has issued specific guidance clarifying that these principles apply to AI, including generative models, and that 'personal information' includes technical metadata and even deepfakes if an individual is identifiable. A unique aspect of New Zealand’s data framework is the emphasis on Māori Data Sovereignty. The government recognizes that data is a 'taonga' (treasure) under the Treaty of Waitangi, and the Privacy Commissioner, along with the GCDO, expects agencies to engage with Māori when AI systems involve indigenous data. This includes respecting tikanga (customary practices) and ensuring that AI does not perpetuate historical biases or inequities against Māori communities. Furthermore, IPP 12 restricts the disclosure of personal information outside of New Zealand unless the receiving jurisdiction has comparable privacy safeguards, a vital consideration for organizations using cloud-based AI models hosted in foreign data centers. This ensures that New Zealanders' data remains protected even when processed by global AI platforms.
Sector-specific rules
While New Zealand avoids a general AI law, several sectors have developed specific rules and expectations. In the public sector, the 'Algorithm Charter' and the 'Public Service AI Framework' function as quasi-regulations, setting mandatory-in-practice standards for transparency and risk management. Agencies are required to perform Algorithmic Impact Assessments (AIAs) for high-risk systems, particularly those used in social welfare, policing, or border control. The GCDO’s 2025 guidance on Generative AI further restricts the use of public-facing GenAI tools for handling sensitive government data without enterprise-grade security controls and senior leadership approval. This ensures that the high bar for government accountability is maintained as new technologies are integrated into state services. In the financial and health sectors, AI use is governed by sector-specific codes and regulators. The 'Health Information Privacy Code 2020' sets stricter rules for the handling of medical data by AI systems, emphasizing patient confidentiality and the accuracy of AI-assisted diagnoses. In the financial sector, the Financial Markets Authority (FMA) and the Reserve Bank of New Zealand (RBNZ) monitor the use of algorithmic trading and AI in credit scoring to ensure market integrity and financial stability. These regulators expect boards to maintain active oversight of AI risks, treating them as part of an institution’s overall operational and cyber-risk profile. This decentralized oversight allows for rules that are tailored to the specific risks and technical requirements of each industry, rather than a one-size-fits-all approach.
International alignment
New Zealand’s AI policy is deeply rooted in international cooperation, particularly with the OECD. The government formally endorsed the OECD AI Principles in 2024, and the 2025 National AI Strategy explicitly aligns New Zealand’s 'Responsible AI' definitions with the OECD’s framework. This alignment is intended to ensure that New Zealand businesses can operate seamlessly across borders and that the country remains an attractive destination for international tech investment. New Zealand also participates in the 'Global Partnership on Artificial Intelligence' (GPAI) and coordinates closely with 'Five Eyes' partners on the security implications of AI, specifically through the National Cyber Security Centre (NCSC) and the Government Communications Security Bureau (GCSB). Regarding the European Union’s AI Act, New Zealand has adopted a 'watch and learn' posture. While New Zealand has not adopted the EU’s classification-based legislative structure, the GCDO’s public service guidance incorporates similar concepts, such as identifying 'high-risk' use cases that require more intensive human oversight and documentation. The government’s priority is to maintain 'regulatory interoperability,' ensuring that New Zealand’s light-touch regime does not conflict with the requirements of major trading partners like the EU, USA, and Australia. This allows New Zealand AI exports to meet international safety and ethical standards without redundant local compliance hurdles, facilitating the growth of the domestic tech sector in a globalized market.
What's next
The next 24 months are expected to see a refinement of New Zealand’s 'guidance-based' model rather than the introduction of new primary legislation. MBIE has signaled that it will conduct a review of existing statutes to identify 'unintended barriers' to AI adoption—such as outdated record-keeping requirements or liability rules that do not account for autonomous systems—and propose targeted legislative 'fixes' through a Regulatory Systems Amendment Bill. There is also ongoing discussion regarding the potential for a 'Public Service AI Assurance Regime,' which would formalize the oversight of government AI projects through an Expert Advisory Panel and more standardized auditing processes to ensure compliance with the Algorithm Charter. Additionally, the Office of the Privacy Commissioner is expected to continue updating its AI guidance, potentially introducing new 'Codes of Practice' for specific high-risk technologies like facial recognition or biometric processing in public spaces. As the Digital Identity Services Trust Framework becomes fully operational, the government will monitor its effectiveness as a template for other high-trust AI applications, such as automated credentialing or secure data sharing. Finally, New Zealand will likely increase its focus on 'Social Licence,' with planned public engagement initiatives to ensure that the rapid rollout of AI in public services maintains the trust of the diverse communities of Aotearoa, particularly in relation to data ethics, the prevention of algorithmic bias, and the protection of indigenous knowledge.
policy · Effective Jan 1, 2025
guideline · Effective Jan 1, 2025
guideline · Effective Jan 1, 2025
guideline · Effective Jan 1, 2025
guideline · Effective Oct 27, 2024
regulation · Effective Jan 1, 2024
regulation · Effective Jan 1, 2024
act · Effective Jan 1, 2023
act · Effective Jan 1, 2020
Sources:
act · Effective Jan 1, 2020
Sources:
guideline · Effective Jan 1, 2020
policy · Effective n/a
policy · Effective n/a
policy · Effective n/a
Member's bill that amends both the Crimes Act 1961 and the Harmful Digital Communications Act 2015 to expand the definition of an "intimate visual recording" to explicitly include images created, synthesised, or altered to show a person's likeness produced without consent. This extension will mean that (1) provisions relating to intimate visual images (Crimes Act sections 216H to 216N) will apply to created images; and (2) the offence in section 22A of the Harmful Digital Communications Act will apply to created images.
strategy · Effective Jan 1, 2025
Sources:
data_protection
Protects individual privacy and enforces the Privacy Act 2020 across all sectors.
central_coordinator
Leads digital transformation and AI standards across the New Zealand Public Service.
central_coordinator
Responsible for national AI strategy, economic policy, and consumer protection.
enforcement
Regulates and accredits digital identity service providers under the 2023 Act.
enforcement
Enforces competition, fair trading, and consumer protection laws.
Apr 30, 2026 · international_agreement
US, Australia, Canada, New Zealand and UK release joint guidance on careful adoption of agentic AI services
Open source →Mar 4, 2026 · news
US, Japan, New Zealand, South Korea, Singapore, UK and Canada join Australia's guidance on supply chain risks and mitigations for AI
Open source →Feb 22, 2026 · international_agreement
Data Protection Authorities adopt joint statement on AI generated imagery raising concerns on defamatory content and harm to vulnerable groups
Open source →Sep 16, 2025 · guideline_issued
Data protection authorities adopted joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protecting AI
Open source →Aug 3, 2025 · news
2025 APEC Digital and AI Ministerial Statement
Open source →Jul 7, 2025 · news
New Zealand releases AI strategy and business guidance
Open source →May 22, 2025 · international_agreement
US, UK, Australia and New Zealand jointly release guidance on AI data security
Open source →Feb 6, 2025 · news
NZ MPs get behind-the-scenes DeepSeek warning
Open source →Feb 2, 2025 · news
New Zealand releases guidance for safe use of AI in the public sector
Open source →Dec 17, 2024 · news
New Zealand Privacy Commissioner releases Biometrics Code for public consultation
Open source →Oct 27, 2024 · news
Global data protection authorities issue statement on data scraping, covering AI
Open source →Oct 22, 2024 · international_agreement
New Zealand government adopts Bletchley Declaration
Open source →Oct 15, 2024 · law_amended
APAC and other regional tech ministers discuss AI regulation
Open source →Jul 24, 2024 · news
MBIE releases cabinet paper on AI, indicating a light-touch risk-based approach to regulating AI
Open source →Apr 2, 2024 · law_amended
NZ Privacy Commissioner wants privacy laws tightened to cover biometrics and AI
Open source →Jan 28, 2024 · law_amended
New Zealand government looking to get up to speed on AI regulation
Open source →