The warning behind the slogan
Data sovereignty gets treated as a cultural courtesy in a lot of boardrooms, a box ticked somewhere near the end of an AI project. Dan Te Whenua Walker thinks that framing is about to cost businesses real contracts.
Walker, founder and chief executive of kaupapa Māori consultancy Toitū AI and a former leader at Microsoft, told 1News on 10 August 2026 that New Zealand is not keeping pace on embedding Māori data sovereignty into AI. Asked directly whether the country was keeping up, he said “No, no. And I think the Government knows that. I think we all feel it as well. It’s all moving so quickly.”
His specific point is one every technology buyer should sit up for. Māori need to be involved at the design and development stage of AI systems, not consulted after they are built. “If we’re going to use it, it should have our values and our mātauranga, our understandings built into it as well,” he said. That is not a values statement. It is an architecture statement, and architecture is very hard to retrofit.
Why this is a compliance question, not a courtesy
The regulator has already spelled out the stakes. MBIE’s responsible AI guidance for businesses, last updated in August 2025, states that improper data collection and processing in AI systems can result in privacy breaches, confidentiality violations, intellectual property violations and data sovereignty impacts. The consequences it names are not soft. They include reputational damage, financial penalties, compliance orders, cease and desist orders and asset freezing.
That is the current posture of the agency that also runs government procurement, the same system any firm selling AI-enabled services into the public sector has to navigate. MBIE’s own AI strategy, released in July 2025, acknowledged that AI carried risks including misappropriation and the loss of data sovereignty, particularly where cultural knowledge was used to train AI without consent.
Here is the trap. The strategy is deliberately light-touch, with no AI-specific law and reliance on existing privacy and consumer protection rules. Light-touch is not the same as low-risk. It means obligations are diffuse and the compliance picture is ambiguous, which leaves the risk sitting with the firm building the product.
The frameworks are a competitive asset, not a burden
Walker’s argument is not just defensive. He is making a competitive claim that New Zealand owns something no frontier lab can replicate. “We could never compete with the big frontier labs or the big hyperscalers. But what we can totally own is when you come to Aotearoa, we have amazing Māori data sovereignty frameworks,” he said.
Those frameworks are not theoretical. Te Mana Raraunga, the Māori Data Sovereignty Network, holds that Māori data should sit under Māori governance. Iwi leaders through Te Kāhui Raraunga have built an AI safeguards framework calling for bias monitoring, transparent algorithm use and a public register of algorithms. This is infrastructure a vendor can point to in a tender.
What the Microsoft deal actually proved
The reference point most people cite is the August 2024 arrangement in which Te Tumu Paeroa, the Office of Māori Trustee, struck a deal with Microsoft to move Māori data from offshore cloud centres to servers in Aotearoa, with encryption keys held by the data owners rather than the vendor. The full transfer was expected to take 12 to 24 months.
But the 2024 analysis is instructive about the limits. Privacy expert Gehan Gunasekara of the University of Auckland cautioned in 2024 that localising storage does not guarantee better protection, and that without stronger legal frameworks New Zealand risks losing the ability to dictate how data is managed. In other words, where the servers sit is the easy part. Who governs the data, and from what stage, is the part that matters.
The design-stage bill comes due
If a firm is training an AI system on New Zealand health data, education records, iwi-linked datasets or community information and has not addressed governance at the architecture stage, it is not facing a future compliance question. It is potentially building a product it cannot sell into public-sector contracts, or to clients with their own Treaty obligations.
The upside runs the same direction. Indigenous data rights are becoming a due-diligence question in procurement internationally, in markets like Canada, Australia and the EU. A vendor who embedded Māori data governance from the design stage holds a credential that competitors racing to bolt it on afterwards cannot manufacture. Walker’s timing warning is really a market-timing warning. The firms that treat this as procurement risk now will be selling into contracts the box-tickers get locked out of.
Join the discussion
Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.