Why NZ businesses need AI rules before they need more tools
Many small businesses already use AI informally. The bigger risk is that no one has decided which mistakes matter, who checks them, and what information should never leave the business environment. If staff are already using tools outside approved rules, use the Shadow AI Policy NZ Business Guide to find and govern that hidden use before expanding access.
Staff may already be using AI informally
A team member might use AI to rewrite an email, summarise a customer conversation, outline a proposal, draft a social post, or turn notes into tasks. Those uses can help, but they should not depend on private judgment about safety.
Privacy, customer trust, and business information risks
Official New Zealand guidance encourages safe AI use, privacy, cybersecurity, transparency, and sound data handling. Business.govt.nz's safe and smart AI guidance and MBIE's responsible AI guidance are useful, but each business still needs daily operating rules.
A practical policy should make sensitive data visible: customer records, staff information, financial details, passwords, commercial strategy, unpublished IP, and confidential supplier or client material. If AI is already touching those areas, maintain an AI risk register for NZ businesses using AI agents alongside the policy so each workflow has an owner and approval point.
Why “do not use AI” is usually not a practical policy
A blanket ban may feel safe, but it often drives AI use into private accounts and unlogged workarounds. A better starting point is controlled permission: approved tools, acceptable tasks, restricted information, and outputs needing review.