Notes from the Asia-Pacific Region: Organizations navigate New Zealand's AI governance gaps

New Zealand organizations and privacy professionals are left to define responsible AI governance amid limited regulatory direction.

Contributors:
Daimhin Warner
CIPP/E
Country Leader, New Zealand, IAPP; Partner
Simply Privacy
Editor's note
Sitting in Singapore this week at the IAPP Asia Forum 2026, it has become clear that the conversation in this region has moved well beyond whether organizations should be governing artificial intelligence. The focus is now on how to operationalize governance, demonstrate assurance and build public trust as AI systems become embedded in business and government.
In her opening keynote, Singapore's Personal Data Protection Commissioner Denise Wong commented that "clarity in rules equals confidence in use." Singapore has become a regional leader in this space, developing not only high-level principles but also practical governance frameworks, AI testing methodologies and technical assurance tools.
By contrast, New Zealand's approach remains comparatively fragmented. There is no standalone AI law, no dedicated AI regulator and limited AI-relevant legislation. Instead, the government has produced a dispersed body of strategies and guidance, much of it voluntary. This leaves organizations with considerable discretion in determining what responsible AI governance looks like. To return to Commissioner Wong's statement, we do not have "clarity in rules," and so "confidence in use" is less likely to follow.
The government's position is broadly to encourage AI adoption while managing risk through existing laws and practical guidance rather than new legislation. This differs markedly from many overseas approaches. While the New Zealand approach offers flexibility, it also places significant responsibility on organizations to interpret how existing legal obligations apply to rapidly evolving technologies.
The centerpiece is the Ministry of Business, Innovation and Employment's 2025 New Zealand Strategy for AI: Investing with Confidence, supported by Responsible AI Guidance for Businesses. The emphasis is on increasing AI adoption while encouraging organizations to establish governance, assess risk and operate transparently. However, the guidance creates no new legal obligations and offers limited clarity about what constitutes adequate governance in practice.
The Government Chief Digital Officer's Public Service AI Framework and accompanying generative AI guidance encourage agencies to implement governance measures, retain meaningful human oversight and remain accountable for AI-assisted decisions. They provide useful direction, but they are nonbinding and their effectiveness depends on consistent implementation across agencies.
The Ministry for Regulation has adopted a similar position in its Responsible AI in Action, encouraging regulators to use AI to support functions such as analyzing large volumes of information while ensuring that responsibility for regulatory decisions remains with humans. Sensible though this is, retaining a human in the process will not necessarily prevent automation bias or over-reliance on AI-generated outputs.
The absence of AI-specific legislation should not be mistaken for a total absence of regulation. The Privacy Act 2020, Human Rights Act 1993, consumer protection law and sector-specific obligations all apply to the use of AI. However, these frameworks were not designed with modern AI systems in mind. While existing privacy law can address matters such as excessive data collection, inadequate transparency, poor security and inaccurate personal information, it does not adequately address broader concerns such as model opacity, inference, bias and accountability.
New Zealand's approach remains deliberately light touch. That may encourage innovation, but it also risks governance developing unevenly and largely in response to harm after it occurs. It is hard to say how long voluntary guidance and general legislation can provide credible protection as AI systems become more capable, pervasive and influential. For now, privacy professionals face the challenge of encouraging employers or clients to implement best practice responsible AI controls despite a lack of concrete legal obligations, or even agreement on what these controls are. For now, we will need to fall back on the old levers of trust and reputation and hope these can compete with the allure of new AI tools and the competitive pressure to embrace them.
This article originally appeared in the Asia-Pacific Dashboard Digest, a free weekly IAPP newsletter. Subscriptions to this and other IAPP newsletters can be found here.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Daimhin Warner
CIPP/E
Country Leader, New Zealand, IAPP; Partner
Simply Privacy
Tags:



