If your team uses ChatGPT, Microsoft Copilot, Gemini or any other AI tool at work, you need a short, clear AI use policy. Not because a regulator demands a specific document, but because without one, people guess. Some avoid useful tools altogether; others paste customer details into a free chatbot without a second thought.

This guide explains what New Zealand guidance expects, then gives you a template you can adapt in under an hour.

What New Zealand guidance says

New Zealand has no AI-specific law. The Government’s July 2025 AI strategy deliberately takes a light-touch, principles-based approach, which means existing law applies, especially the Privacy Act 2020.

The Office of the Privacy Commissioner is clear: “The Privacy Act applies to everyone using AI tools in New Zealand.” Its guidance also offers a simple rule of thumb: “If in doubt, we recommend you do not use AI tools to handle personal information.”

In June 2023 the Commissioner set out eight expectations for organisations considering generative AI:

  1. Have senior leadership approval.
  2. Review whether a generative AI tool is necessary and proportionate.
  3. Conduct a privacy impact assessment.
  4. Be transparent with the people affected.
  5. Engage with Māori about potential impacts.
  6. Develop procedures about accuracy and access by individuals.
  7. Ensure human review before acting on AI outputs.
  8. Ensure personal or confidential information is not retained or disclosed by the tool.

MBIE’s Responsible AI Guidance for Businesses (July 2025) adds practical advice for businesses of every size: understand why you’re using AI, keep personal and confidential information out of public tools that may reuse what you type, check outputs for errors and bias, keep a person in the loop for decisions, and train your staff. It also reminds businesses that having a privacy officer is a legal requirement.

One more recent change to know about: since 1 May 2026, information privacy principle 3A generally requires you to tell people when you collect their personal information from someone else. If an AI tool gathers information about people indirectly, factor that in.

The template

Copy this into a document, replace the bracketed text, and remove anything that doesn’t apply. Keep it to one or two pages; a policy nobody reads protects nobody.

[Business name] AI use policy

1. Purpose. This policy explains how we use artificial intelligence (AI) tools safely and effectively. It applies to everyone who works for or with [Business name], including contractors.

2. Approved tools. You may use these AI tools for work: [list tools and account types, for example Microsoft 365 Copilot with your work account]. Do not use other AI tools for work without approval from [role].

3. What you can and can’t put into AI tools.

  • Never enter personal information about customers, staff or anyone else (names, contact details, health, financial or identity information) into tools that are not on the approved list.
  • Never enter confidential business information, such as pricing, contracts, passwords or client documents, into tools that are not approved for it.
  • Approved tools may be used with [describe the information allowed, for example internal documents, but not customer health information].
  • If in doubt, leave it out, and ask [role].

4. Check everything. AI tools can be confidently wrong. You are responsible for checking the accuracy of anything AI helps you produce before it is used or sent. Never rely on AI alone for decisions about people, money, safety or legal matters.

5. Be open about AI. Tell customers when they are dealing with an AI system, such as a chatbot. Do not present AI-generated content as a person’s professional advice without review.

6. Privacy. Before using AI in a new way that involves personal information, talk to our privacy officer, [name], who will decide whether a privacy impact assessment is needed. We follow the Privacy Act 2020.

7. Security. Use your work account, never a personal account, for approved tools. Keep data and history settings as configured by [role]. Report any suspected data leak straight away.

8. Intellectual property. Respect copyright and licence terms. Do not upload third-party material you don’t have the right to use. Check AI-generated content before publishing it as our own.

9. Mistakes and incidents. If personal or confidential information is entered into an unapproved tool, or AI output causes a problem, tell [role] immediately. We will deal with it without blame, and learn from it.

10. Training. Everyone who uses AI tools for work will complete our AI training. Ask [role] if you would like more help.

11. Review. [Role] owns this policy and will review it at least every six months, or sooner if our tools or the law change.

Approved by [name, role] on [date].

How to roll it out

A policy only works if people understand it. We recommend:

  • Leadership sign-off first. It matches the Privacy Commissioner’s first expectation and signals that AI use is supported, not just tolerated.
  • A short team session. Walk through the policy with real examples from your work: what’s fine, what isn’t, and why.
  • Approve good tools. People turn to unapproved tools when the approved ones are missing or hard to use. Give your team a safe, capable option.
  • Name an owner. One person answers questions, approves new tools and keeps the policy current.
  • Review regularly. AI tools change fast. Put a six-monthly review in the calendar.

A policy is a starting point

Writing the policy usually surfaces bigger questions: which tools you should approve, where AI could save real time, and what your team needs to use it well. That’s where training makes the difference.

Our AI training for teams includes a tailored version of this policy, written with you, plus hands-on sessions using your team’s own work. If you’d rather start with a quick self-assessment, try our free AI readiness check.

This template is general guidance, not legal advice. For complex or high-risk uses of personal information, get professional advice.

Sources

  1. Artificial intelligence and the Information Privacy Principles, Office of the Privacy Commissioner, September 2023
  2. Generative artificial intelligence: the Commissioner’s expectations, Office of the Privacy Commissioner, 15 June 2023
  3. Responsible AI Guidance for Businesses, MBIE, July 2025
  4. IPP3A: notifying people when collecting personal information indirectly, Office of the Privacy Commissioner

Checked on 3 October 2026. Schemes, prices and rules change, so confirm details with the source before you act.