Artificial intelligence is rapidly transforming how organisations operate, make decisions and interact with customers, employees and other stakeholders. As AI becomes embedded in everyday business activities, boards and senior leaders are increasingly expected to understand both the opportunities and risks it presents.
Our AI governance: A practical framework handbook provides practical guidance on the legal, regulatory and governance issues organisations should consider when adopting and using AI. Drawing on developments in New Zealand and overseas, it outlines the key questions boards should be asking to support responsible AI use and effective governance.
Key takeaways
What does good AI governance look like?
AI governance is becoming a core board responsibility. Directors and senior leaders should have sufficient AI literacy to oversee management, understand where AI is being used across the organisation and ensure appropriate governance frameworks, policies and reporting are in place. Effective governance should balance innovation and opportunity with responsible risk management.
How should organisations manage employees' use of AI?
AI tools are now widely accessible, and employees may use them with or without organisational oversight. Organisations should establish clear policies on approved tools, acceptable use and human verification of outputs, while ensuring employees understand the risks associated with entering confidential, personal or commercially sensitive information into AI systems.
How can organisations maintain trust when using AI?
Trust remains fundamental to successful AI adoption. Organisations should be transparent about how AI is being used, ensure appropriate human oversight of important decisions and regularly assess AI systems for inaccuracy, unfair bias or unintended consequences.
Who owns AI-generated content?
Ownership of AI-generated content remains uncertain under existing intellectual property frameworks. Organisations should carefully consider whether valuable outputs created using AI can be adequately protected and whether contractual, operational or other safeguards are needed to preserve competitive advantage.
Can using AI create legal and regulatory risk?
AI can raise issues across privacy, employment, consumer protection, competition and intellectual property law. Boards should understand how AI is used within the organisation and ensure governance processes are equipped to identify and manage legal and regulatory obligations as requirements continue to evolve.
Can using AI put confidential information or legal privilege at risk?
Entering confidential, commercially sensitive or privileged information into AI tools can create significant legal and commercial risks. Organisations should understand how AI providers use and retain data, implement appropriate controls and ensure employees know what information should never be entered into AI systems.
Is an organisation responsible for what its AI says or does?
Organisations remain accountable for the outputs and actions of AI systems they deploy, including customer-facing AI tools and emerging AI agents. Boards should ensure there are appropriate guardrails, testing, monitoring and escalation processes in place, so accountability remains with people, not technology.
What do boards need to know about AI transparency and overseas regulation?
AI regulation is developing rapidly both in New Zealand and internationally. Overseas frameworks, including the European Union AI Act and Australian transparency requirements, may affect New Zealand organisations. Boards should understand how these developments apply to their business and prepare for increasing expectations around AI governance, transparency and accountability.
How should boards balance AI opportunities with sustainability and cultural considerations?
AI systems can create cultural, ethical and environmental impacts alongside business opportunities. Boards should consider issues such as Māori data governance, algorithmic bias, fairness and AI's environmental footprint when assessing how AI is used within their organisation.
Key questions every board or senior business leader should be asking
The handbook concludes with practical questions directors can use to assess their organisation’s AI governance, including:
- Is AI governance a standing item on our board agenda?
- Does the board receive clear, regular reporting on where AI is used and what risks are emerging?
- Do we have a board-approved AI policy covering approved tools, prohibited uses and human oversight?
- Have we assigned clear responsibility for approving and monitoring AI tools?
- Are we transparent about where AI is used to make decisions affecting people?
- Have we identified decisions with material consequences that require meaningful human oversight?
- Do we test AI systems for accuracy, fairness and bias?
- Are employees entering confidential, proprietary or privileged information into unapproved AI tools?
- Where AI systems use Māori data or affect Māori communities, have we engaged appropriately and applied culturally appropriate safeguards?
- Are customer-facing AI systems subject to clear mandates, guardrails and pre-deployment testing?
- Do we verify important factual assertions, citations and figures in AI-assisted work?
- Do our AI supplier contracts contain appropriate assurances, audit rights and data-protection commitments?