Guide · Governance · 8 min read

How to write an AI policy for a New Zealand business, and the seven sections it needs

A good AI policy is two pages long, names the tools people may use and the information they may not share, tells them AI output is a draft until checked, and says who to ask. Everything longer than that is usually a legal document nobody reads. Here are the seven sections, in the order to write them, with the decisions each one forces you to make.

Why the policy comes before the tools

Most businesses arrive at an AI policy after something has already happened: a customer asks whether their information went into a chatbot, an insurer’s renewal form has a new question, or a manager finds out that half the team has been using a tool for a year. The policy written in that moment is defensive and long. The policy written before the tools are switched on is short, because it is making decisions rather than apologising for them.

It also unlocks value. Staff who know what they may do use AI in the open; staff who suspect they are not allowed to use it in secret. The policy is the difference between AI you can see and AI you cannot.

Section 1: purpose and scope

Two paragraphs. Why the business is writing this (to let people use AI safely, not to stop them), who it applies to (everyone, including contractors and anyone with a login), and what counts as AI for the purpose of the policy (any tool that generates, summarises, classifies or decides, whether it is a standalone app or a feature inside software you already use). The last point matters because most AI use in a business now happens inside tools nobody thinks of as AI.

Section 2: approved tools and how to get them

List the tools the business has assessed, the account type people must use, and how to request access. State plainly that personal and free accounts are not approved for work involving company information. Keep the list current; a policy that names tools nobody uses any more tells staff it is not maintained. If a tool people want is not on the list, give them a route to ask, and answer within a week.

Section 3: information that must not be shared

The five categories: personal information about anyone, client-confidential and contractually protected material, non-public financials, credentials, and the business’s own intellectual property. Say that these may go only into approved tools on business accounts, and never into a public one. This is the section most staff will actually remember, so make it a list, not a paragraph.

Section 4: human review and accountability

AI output is a draft. The person who uses it is responsible for it, exactly as they would be for a template or a colleague’s suggestion. Anything that leaves the business, commits money, affects a customer or a staff member, or ends up in a record is checked by a person first. Name the kinds of decision that AI may never make alone in your business: hiring, credit, medical, disciplinary, whatever applies.

Section 5: privacy, records and disclosure

The Privacy Act 2020 applies to personal information whether a person or a model processes it. Say that AI use must stay within the purpose the information was collected for, that customers will be told when they are dealing with an automated system, and that records of automated actions are kept. If the business is in health, finance or another regulated sector, name the code or rule that applies and say the policy sits under it.

Section 6: ownership, incidents and questions

Name the person who owns the policy and the tool list. Say what to do when something has gone wrong: information shared that should not have been, an AI output that reached a customer with an error, a tool behaving unexpectedly. The instruction is “tell the owner the same day; nobody is in trouble for reporting”, because a policy that punishes reporting gets no reports.

Section 7: review

The policy is reviewed every six months, or when a new tool is approved, or after an incident. Date it. Sign it, at director level, because a signed two-page policy carries more weight with staff, insurers and customers than an unsigned twenty-page one.

Rolling it out

  • Send it with the approved tools already available, so the first thing people do with the policy is log in, not wait.
  • Run a thirty-minute session, live or recorded, that walks through the five categories and the review rule. That is the whole training; anything longer is not attended.
  • Add it to inductions and to the contractor onboarding pack.
  • Keep a record of who has read it. When a customer or insurer asks, that record is the answer.

Mistakes that get policies ignored

Every one of these is avoidable, and the fix for all of them is the same: write it short, name the tools, give the examples, sign it, and talk about it twice a year.

  • Length. Anything past two pages is read once, by the person who wrote it.
  • A ban with no alternative. Staff do not stop using AI; they stop telling you.
  • Written by legal alone, so it protects the business and helps nobody do their job.
  • No named owner, so questions go unanswered and the tool list goes stale.
  • No examples. “Confidential information” means nothing; “a supplier statement with bank details” means something.
  • Never mentioned again after the email that announced it.

A note on contractors and suppliers

Your contractors use AI tools too, on your information, and your suppliers increasingly run AI on the data you send them. The policy should say that contractors follow it as a condition of engagement, and your supplier questionnaires should ask the same questions you ask yourself: which tools, which accounts, is our data used for training, where is it stored, how long is it kept. A short clause in the engagement letter does most of the work.

Where to go from here

The AI Governance service on this site writes this policy for your business, with the tool assessments, the training and the record-keeping, aligned to ISO/IEC 42001 and the NIST AI Risk Management Framework, and hands it to you signed-off in a fortnight. The AI Opportunity Score below will tell you in five minutes whether the policy or the permissions is the more urgent gap.

Published 12 September 2026 · Be AI

Read enough? Find out where your business actually stands.

Twelve questions, five minutes, and a score you can put in front of your leadership team.