< All insights & articles

AI at work: What New Zealand employers need to get right

Published on
Written by

Artificial intelligence tools such as ChatGPT and Microsoft Copilot are becoming part of everyday work. Employees may be using them to draft emails, summarise documents, prepare reports, review applications or create marketing content.

These tools can save time, but they also create risks around privacy, confidentiality, accuracy, employment decisions and copyright.

The key point for employers is that using AI does not remove their responsibility for the information entered into a tool, the work it produces or the decisions made with its assistance.

Know how AI is being used

A business does not need to have formally introduced AI for employees to be using it.

Before creating rules, employers should understand:

  • Which tools staff are using
  • What tasks they are using them for
  • Whether personal or confidential information is being entered
  • Whether AI-generated work is being checked
  • Whether AI is influencing recruitment or employment decisions

An open discussion with employees can help identify where AI is already being used and where clearer boundaries may be needed.

Protect confidential and personal information

One of the biggest risks is employees copying information into an AI tool without considering where it may be stored or how it may be used.

Employees should generally avoid entering:

  • Client or customer information
  • Employee or applicant information
  • Financial records
  • Health information
  • Passwords or login details
  • Contracts and legal documents
  • Trade secrets or sensitive business information

Employers should check the terms of any approved AI tools, including whether prompts are retained, used for training or transferred overseas.

Removing a person’s name may not always be enough if the remaining details could still identify them.

Check AI-generated work carefully

AI-generated content can sound convincing while still being inaccurate, incomplete or outdated.

This creates particular risk when it is used to prepare:

  • Legal or financial information
  • Employment correspondence
  • Customer terms
  • Health and safety documents
  • Reports or public statements
  • Advice provided to clients

AI output should be treated as a draft rather than a finished product.

The level of review should match the level of risk. A suggested social media caption may need a light check, while a disciplinary letter or client report requires careful review by someone with the right knowledge and authority.

Be careful with employment decisions

AI may be used to compare CVs, rank applicants, draft performance feedback or analyse employee information.

However, an employer should not rely on an AI system to make the final decision.

AI tools may reflect bias in their data or place too much weight on irrelevant information. Employers still need to ensure decisions are fair, based on accurate information and free from unlawful discrimination.

Where AI is used in recruitment or employee management, employers should understand:

  • What information the tool considered
  • Whether the criteria were relevant
  • Whether the information was accurate
  • Whether any group could be unfairly disadvantaged
  • Who reviewed and approved the final decision

AI can assist with administrative work, but meaningful human judgement must remain part of the process.

Consider copyright and ownership

Businesses should not assume that AI-generated writing, images or designs are automatically original or safe to use.

Before publishing or using AI-generated work commercially, consider:

  • How much human input was involved
  • Whether the output resembles an existing work
  • The provider’s terms concerning ownership
  • Whether commercial use is permitted
  • Whether confidential material was used in the prompt
  • Whether the business needs exclusive ownership of the final work

The law in this area is still developing, so caution is sensible where AI-generated material will be widely published or used for commercial purposes.

What should an AI policy cover?

A workplace AI policy should be clear and practical. It may include:

  • Which tools employees may use
  • Appropriate and prohibited uses
  • Information that must not be entered
  • When human review is required
  • Rules for recruitment and employment decisions
  • Accuracy and source-checking requirements
  • Copyright and ownership considerations
  • When AI use should be disclosed
  • What to do if information is entered by mistake
  • Training and review requirements

The policy should be easy to find, understood by employees and reviewed as new tools are introduced.

A sensible approach

AI can help employees work more efficiently, but it should not replace judgement, accountability or a fair process.

Employers who set clear expectations now will be better placed to use these tools productively while reducing the risk of privacy breaches, employment disputes and intellectual property issues.

How McVeagh Fleming can help

McVeagh Fleming can assist employers with workplace AI policies, privacy obligations, employment processes, confidentiality requirements and intellectual property concerns.

Getting the right framework in place can help employees use AI confidently while making it clear where human review and approval are still required.

No items found.
No items found.
© McVeagh Fleming 2026
This article is published for general information purposes only.  Legal content in this article is necessarily of a general nature and should not be relied upon as legal advice.  If you require specific legal advice in respect of any legal issue, you should always engage a lawyer to provide that advice.

View all Insights

AI at work: What New Zealand employers need to get right

AI at work: What New Zealand employers need to get right

Written by:

Artificial intelligence tools such as ChatGPT and Microsoft Copilot are becoming part of everyday work. Employees may be using them to draft emails, summarise documents, prepare reports, review applications or create marketing content.

These tools can save time, but they also create risks around privacy, confidentiality, accuracy, employment decisions and copyright.

The key point for employers is that using AI does not remove their responsibility for the information entered into a tool, the work it produces or the decisions made with its assistance.

Know how AI is being used

A business does not need to have formally introduced AI for employees to be using it.

Before creating rules, employers should understand:

  • Which tools staff are using
  • What tasks they are using them for
  • Whether personal or confidential information is being entered
  • Whether AI-generated work is being checked
  • Whether AI is influencing recruitment or employment decisions

An open discussion with employees can help identify where AI is already being used and where clearer boundaries may be needed.

Protect confidential and personal information

One of the biggest risks is employees copying information into an AI tool without considering where it may be stored or how it may be used.

Employees should generally avoid entering:

  • Client or customer information
  • Employee or applicant information
  • Financial records
  • Health information
  • Passwords or login details
  • Contracts and legal documents
  • Trade secrets or sensitive business information

Employers should check the terms of any approved AI tools, including whether prompts are retained, used for training or transferred overseas.

Removing a person’s name may not always be enough if the remaining details could still identify them.

Check AI-generated work carefully

AI-generated content can sound convincing while still being inaccurate, incomplete or outdated.

This creates particular risk when it is used to prepare:

  • Legal or financial information
  • Employment correspondence
  • Customer terms
  • Health and safety documents
  • Reports or public statements
  • Advice provided to clients

AI output should be treated as a draft rather than a finished product.

The level of review should match the level of risk. A suggested social media caption may need a light check, while a disciplinary letter or client report requires careful review by someone with the right knowledge and authority.

Be careful with employment decisions

AI may be used to compare CVs, rank applicants, draft performance feedback or analyse employee information.

However, an employer should not rely on an AI system to make the final decision.

AI tools may reflect bias in their data or place too much weight on irrelevant information. Employers still need to ensure decisions are fair, based on accurate information and free from unlawful discrimination.

Where AI is used in recruitment or employee management, employers should understand:

  • What information the tool considered
  • Whether the criteria were relevant
  • Whether the information was accurate
  • Whether any group could be unfairly disadvantaged
  • Who reviewed and approved the final decision

AI can assist with administrative work, but meaningful human judgement must remain part of the process.

Consider copyright and ownership

Businesses should not assume that AI-generated writing, images or designs are automatically original or safe to use.

Before publishing or using AI-generated work commercially, consider:

  • How much human input was involved
  • Whether the output resembles an existing work
  • The provider’s terms concerning ownership
  • Whether commercial use is permitted
  • Whether confidential material was used in the prompt
  • Whether the business needs exclusive ownership of the final work

The law in this area is still developing, so caution is sensible where AI-generated material will be widely published or used for commercial purposes.

What should an AI policy cover?

A workplace AI policy should be clear and practical. It may include:

  • Which tools employees may use
  • Appropriate and prohibited uses
  • Information that must not be entered
  • When human review is required
  • Rules for recruitment and employment decisions
  • Accuracy and source-checking requirements
  • Copyright and ownership considerations
  • When AI use should be disclosed
  • What to do if information is entered by mistake
  • Training and review requirements

The policy should be easy to find, understood by employees and reviewed as new tools are introduced.

A sensible approach

AI can help employees work more efficiently, but it should not replace judgement, accountability or a fair process.

Employers who set clear expectations now will be better placed to use these tools productively while reducing the risk of privacy breaches, employment disputes and intellectual property issues.

How McVeagh Fleming can help

McVeagh Fleming can assist employers with workplace AI policies, privacy obligations, employment processes, confidentiality requirements and intellectual property concerns.

Getting the right framework in place can help employees use AI confidently while making it clear where human review and approval are still required.

Subscribe to receive updates

I would like to receive updates for:
Thank you for subscribing. Your submission has been received!
Oops! Something went wrong while submitting the form. Please try again.