The moment the rulebook started drifting
New Zealand chose the light-touch path on artificial intelligence, and it chose it recently. The country published its first National AI Strategy in July 2025, the last OECD member to do so, and made a deliberate call to lean on existing laws rather than write standalone AI legislation. A companion Responsible AI Guidance for Businesses landed at the same time, entirely voluntary, with no enforcement teeth. For a business owner keen to get on with adoption, that was a reasonable starting position.
That position is now under formal challenge. On 7 August 2026 the Human Rights Commission released a report calling for Māori data sovereignty and Te Tiriti o Waitangi to sit at the heart of how AI is governed. This is not a think-tank opinion piece. It is a statutory Crown entity telling the government its strategy is insufficient, and Minister Paul Goldsmith is obliged to table a response in parliament.
What the Commission actually wants
The framework rests on several pillars: transparency, so people can understand how a system that makes decisions about them works; accountability, with clear lines of responsibility and accessible remedies when it goes wrong; meaningful Māori participation rather than box-ticking consultation; and a broader digital infrastructure strategy that looks beyond the public sector.
Senior Human Rights Advisor Sophie Bradwell-Pollack put the principle bluntly: “Human rights and Te Tiriti obligations apply. They apply whether you’re writing on paper or whether you’re using a computer.” She was equally direct about the government’s framing, noting that “innovation and efficiency is only really a small part of what needs to be considered.” The Commission conceded the obvious limit, that because most AI is built overseas and imported, New Zealand cannot control how it is made, but it can decide how it is used and governed here.
The compliance load is already heavier than most firms think
Here is the part businesses tend to miss. Even with zero new regulation, the obligations are already substantial. The MBIE guidance lists a stack of existing law that applies to AI use, including the Commerce Act 1986, Consumer Guarantees Act 1993, Privacy Act 2020, Human Rights Act 1993 and Bill of Rights Act 1990. The Privacy Commissioner’s guidance expects organisations to run privacy impact assessments before deploying AI, secure senior leadership sign-off, and keep a human in the loop before acting on AI outputs.
That caution has history behind it. In August 2025, Privacy Commissioner Michael Webster flagged significant risks in the strategy, pointing to Australia’s RoboDebt debacle and the UK’s Horizon scandal as cases where thousands were harmed by AI rolled out without proper thought. In July 2025, Dr Andrew Lensen of Victoria University warned that “having ‘Principles’ is not nearly sufficient” without legislation and enforcement, while Dr Karaitiana Taiuru noted the strategy did not mention the Treaty “not even once.” The HRC report is those warnings turning into a formal recommendation the Crown must answer.
The stakes cut both ways
Nobody serious wants to strangle this. Generative AI could add $76 billion to the economy by 2038, over 15% of GDP, and free up 275 hours per worker a year. Adoption is climbing among larger firms, 67% of which now use some form of AI, up from 48% in 2023.
But smaller firms are stuck. While 94% of SMEs are aware of at least one AI tool, 68% have no plans to evaluate or invest. Awareness is not the barrier, and some of that hesitation is almost certainly uncertainty about the rules. A 2025 Victoria University analysis placed New Zealand among the most permissive jurisdictions globally, alongside Japan and Singapore, while the EU pressed ahead with hard, enforceable law. For any Kiwi firm with EU market exposure, those obligations already apply regardless of what Wellington does.
Where this leaves business
A clear, proportionate framework could actually help. It would give the hesitant 68% something firm to plan against and reduce the guesswork that currently freezes SME investment. The genuine risk is the opposite outcome, that what emerges is not clarity but a process-heavy layer larger firms can absorb and smaller ones cannot, on top of obligations most businesses have not yet mapped.
The honest read is that the architecture is no longer settled. A statutory body has put a structured framework on the table, the minister must respond, and the direction of travel now points toward more codification, not less. Businesses using AI in hiring, customer decisions, health or anything touching personal data would be wise to get their privacy impact assessments and human-review processes in order now, before the rulebook they had no say in writing becomes the one they have to live under.
Join the discussion
Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.