⚡ Quick Summary
Published by the Ministry of Business, Innovation and Employment (MBIE), this guidance is a voluntary resource for businesses, including sole traders, non-profits and individual professionals, that use or develop AI systems. It is directed primarily at New Zealand AI users and deployers, while also addressing developers. Its purpose is to help organisations realise AI’s benefits in a trustworthy way, using a proportionate, risk-based approach that considers the likelihood, magnitude and context of potential harms.
The guidance draws on the OECD AI Principles, covering beneficial outcomes, human rights and democratic values, transparency, robustness, security, safety, accountability and systematic risk management across the AI lifecycle. It is organised into three layers: understanding the organisation’s purpose for AI; establishing business foundations; and addressing AI-system-specific considerations. It provides practical considerations, mitigation tips, hypothetical scenarios and checklist resources covering procurement, transparency and recordkeeping. The intended result is that businesses can identify relevant legal, technical, operational, ethical and stakeholder risks, select context-appropriate mitigations, and retain responsibility for decisions made with AI support.
🧩 What’s Covered
The guidance moves from organisational purpose and foundations to lifecycle-specific controls and supporting resources.
- Purpose and scope: Defines AI and generative AI using OECD concepts, explains the voluntary nature of the resource, and sets expectations for lawful, trustworthy use. It identifies risks involving cybersecurity, privacy, human rights, workplace culture, environmental effects, intellectual property, creators and physical safety.
- Understanding the ‘why’: Advises organisations to define AI objectives, values and guiding principles; assess inefficiencies and lawful data assets; draw on stakeholder insights; conduct cost-benefit analysis; and use isolated AI sandboxes for safe experimentation.
- Governance, law and risk: Sets out cross-functional responsibilities spanning leadership, security, data governance, technology, legal, privacy, HR and communications. It recommends cataloguing applicable legal obligations, maintaining a risk inventory, documenting mitigations, monitoring emerging risks and planning for continuity and system exit.
- Supporting capabilities: Covers AI procurement, cybersecurity, privacy and staff capability. It recommends supplier due diligence, trials isolated from technical systems, security risk assessment, incident response planning, privacy-by-design, role-based training and organisational policies for GenAI use.
- Stakeholder interactions: Explains stakeholder impact assessments, engagement plans, transparency and complaint channels. It calls for attention to affected and underrepresented communities, including Māori and Pacific peoples, and recommends disclosing AI use, risks, monitoring and routes for feedback or review.
- Data and modelling: Addresses fit-for-purpose training data, data quality, bias, provenance, privacy, licensing and intellectual property. It includes specific considerations for Māori data and mātauranga, and recommends model metrics, testing, red teaming, audits, model cards and monitoring for data drift.
- Use, outputs and appendices: Covers GenAI prompts, output errors and hallucinations, deepfakes, copyright risks, watermarking, human-in-the-loop decision-making and automation bias. Appendices provide a glossary, procurement, transparency and recordkeeping checklists, options for ethically sourcing datasets, and further resources.
💡 Why it matters?
The resource helps businesses treat AI adoption as a governance and operational responsibility rather than solely a technology purchase. Its risk-management cycle of identifying, assessing, managing, recording and reviewing risks can be applied across use cases, while the procurement and recordkeeping material supports evidence of decisions, system limits, controls and supplier arrangements.
It is particularly relevant where AI affects personal information, customers, employment, intellectual property or high-impact decisions. The guidance connects responsible practice to New Zealand legal obligations and directs businesses operating internationally to keep up with applicable local requirements. Its emphasis on human review, verification and feedback channels addresses overreliance on AI outputs and enables concerns to be identified and handled early.
❓ What’s Missing
The document states that it is not an exhaustive list of considerations and does not replace relevant New Zealand legislation, regulations or professional legal advice. It offers considerations and checklists rather than binding requirements, detailed implementation procedures or a formal assessment score. Sector-specific obligations are referenced only at a high level, with businesses directed to industry bodies, suppliers, peers and external guidance where relevant. The hypothetical scenarios illustrate possible risks and responses, but are not evidence of real incidents. Several cited resources, standards and tools sit outside the document, so readers seeking detailed technical testing methods, legal interpretation or sector-specific controls must consult those materials separately. The guidance also says that it may be expanded through future supplementary resources, case studies and toolkits.
👥 Best For
Business leaders, compliance and privacy staff, procurement teams, security practitioners and AI project owners in New Zealand organisations. It is especially suited to teams adopting third-party AI or GenAI tools, developing models, establishing cross-functional oversight, assessing suppliers, documenting AI systems, or designing human review and stakeholder-feedback arrangements.
📄 Source Details
Responsible AI Guidance for Businesses was produced by the Ministry of Business, Innovation and Employment (MBIE) in July 2025. The complete supplied PDF is 43 pages and is in English. It lists Print ISBN 978-1-99-106955-9 and Online ISBN 978-1-99-106999-3. No individual authors or edition number are stated.