New Zealand - Public Service AI Framework (RAI-NZ-NA-PUBSEAI-2025)

Public Service AI Framework

New Zealand

RAI-NZ-NA-PUBSEAI-2025
Effective: January 29, 2025
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

The Public Service AI Framework (GCDO) is non‑binding guidance that sets a vision, five principles and a six‑pillar work programme to support responsible AI adoption across New Zealand public service agencies. It encourages a risk‑based, human‑centred and transparency‑focused approach aligned with existing New Zealand law and international AI principles.

Summary

The Public Service AI Framework, published by the Government Chief Digital Officer (GCDO) in January 2025, provides structured, non‑binding guidance for New Zealand public service agencies on the responsible adoption, deployment and governance of artificial intelligence (AI). It articulates a clear vision — “Adopt AI responsibly to modernise public services and deliver better outcomes for all New Zealanders” — and defines five core principles (inclusive sustainable development, human‑centred values, transparency and explainability, safety and security, and accountability). The Framework situates AI guidance within New Zealand’s broader legal and constitutional context (including the Treaty of Waitangi and domestic statutes such as the Privacy Act 2020, Official Information Act 1982, Public Service Act 2020 and relevant human‑rights instruments) and promotes a light‑touch, proportionate, risk‑based approach to regulation, consistent with Cabinet direction and MBIE advice.

Operationally, the Framework sets out a GCDO‑led work programme structured around six pillars: Governance, Guardrails, Capability, Innovation, Social licence and Global voice. This programme is intended to help agencies implement governance and assurance arrangements, apply safety‑by‑design and security‑by‑design approaches, build workforce capability, enable safe testing and innovation, and engage the public to build trust. The Framework applies broadly to “all forms of AI used in New Zealand public services,” referencing OECD definitions of AI systems and encouraging agencies to document AI uses, disclose when AI assists decision‑making, and enable affected individuals to understand outcomes.

The Framework is explicit that it is guidance rather than binding regulation: agencies are encouraged to align to its principles and the GCDO will support implementation through practical guidance (including a PDF one‑page A3 summary and a suite of follow‑on materials such as Responsible AI Guidance for the Public Service: GenAI released in February 2025). It emphasises alignment with existing law and mechanisms rather than creating a standalone AI Act, consistent with the MBIE Cabinet paper (June–July 2024) which recommended a proportionate, risk‑based policy approach.

Key operational expectations include: human accountability and oversight across AI lifecycles; proportionate risk assessment and assurance; transparency and public disclosure where appropriate; robust data governance and traceability; security and safety measures; procurement and supplier management; auditability and documentation; workforce capability building; and engagement with Māori and communities to uphold Treaty obligations and support equitable outcomes. While the Framework itself does not set new statutory penalties, failure to meet legal obligations (e.g., privacy law or public records requirements) may trigger enforcement under those existing regimes. The GCDO, supported by agencies such as MBIE, the Privacy Commissioner and the Public Service Commission, will steward implementation, monitoring and ongoing updates to guidance.

Full article

Read full text ↗

Overview

The Public Service AI Framework is a GCDO (Government Chief Digital Officer) issued guidance document designed to support responsible AI adoption across New Zealand’s Public Service. It sets a concise vision — "Adopt AI responsibly to modernise public services and deliver better outcomes for all New Zealanders" — and defines five guiding principles that draw on the OECD AI principles. The Framework is presented as non‑binding, risk‑based and proportionate, and sits within New Zealand’s wider AI policy architecture alongside the MBIE work programme and the National AI Strategy. The one‑page A3 summary is available from the GCDO site as a PDF and agencies are encouraged to reference it when creating governance or procurement artifacts. For the official Framework text and the A3 summary see Public Service AI Framework (digital.govt.nz) and the downloadable Public Service Artificial Intelligence Framework (PDF).

Definitions

The Framework adopts a practical working definition of an AI system aligned to the OECD: a machine‑based system that infers from input how to generate outputs (predictions, content, recommendations, decisions) that influence environments. It distinguishes AI by capability (from simple automation to adaptive systems) and covers generative AI as a subset addressed by follow‑on guidance. The Framework also uses standard governance terms such as "human oversight", "assurance", "guardrails", "risk assessment", and "traceability". It instructs agencies to interpret these definitions in light of the agency’s statutory obligations, including privacy, public information and human rights duties. Additional operational definitions and GenAI‑specific considerations are expanded in the companion Responsible AI Guidance for the Public Service: GenAI available at Responsible AI Guidance: GenAI (digital.govt.nz).

Governance and Institutional Framework

The Framework establishes expectations for governance arrangements within agencies and system stewardship by the GCDO. Agencies are expected to implement human accountability at all lifecycle stages, embed risk‑based assurance and reporting, and maintain documentation and audit trails to enable oversight. The GCDO will lead a cross‑agency work programme (Governance, Guardrails, Capability, Innovation, Social licence, Global voice) and coordinate with MBIE, the Public Service Commission, the Office of the Privacy Commissioner and other central agencies. MBIE’s Cabinet paper "Approach to work on Artificial Intelligence" frames the strategic, cross‑portfolio approach and recommends leveraging existing regulatory instruments rather than creating a stand‑alone AI Act; that paper and supporting materials are available at Approach to work on Artificial Intelligence (MBIE PDF). Institutional expectations include escalation mechanisms for high‑risk uses, procurement and supplier assurance processes, and integration of Treaty of Waitangi considerations into governance practices.

Key Focus Areas

The Framework sets out five principles and highlights six pillars that shape the public service’s focus. Principles cover inclusive development, human‑centred values, transparency and explainability, safety and security, and accountability. The pillars (Governance, Guardrails, Capability, Innovation, Social licence, Global voice) direct operational activity: Governance requires clear roles and responsibilities and oversight; Guardrails require risk assessment frameworks, model validation and testing; Capability calls for workforce training and secondments; Innovation supports safe testing and sandboxes for experimentation; Social licence emphasises public engagement, Māori partnership and addressing inequities; Global voice covers international coordination and exportable practices. The Framework also highlights procurement, data ethics, recordkeeping and incident response as recurrent cross‑cutting concerns. For GenAI specific operational measures see the companion guidance and the GCDO pages cited above.

Implementation Framework

The GCDO proposes a work programme and practical tools to help agencies implement the Framework: an assurance model, risk assessment templates, procurement checklists, documentation templates, and capability building resources. Agencies are asked to perform proportionate risk assessments prior to significant AI deployments, to embed security‑by‑design and privacy‑by‑design controls during procurement and development, and to maintain traceable data lineage and documentation to enable audit and redress. Implementation guidance encourages iterative pilots followed by scaled roll‑out when assurance outcomes are acceptable. The Framework deliberately avoids prescriptive thresholds; instead it instructs agencies to size assurance to risk and statutory obligations, using existing legal enforcement channels when breaches occur.

Monitoring and Evaluation

The Framework calls for continuous monitoring, periodic review and reporting to support oversight and public confidence. The GCDO will monitor uptake, maintain a repository of lessons learned and coordinate cross‑agency evaluation. Agencies are expected to maintain documentation sufficient for internal audit, ministerial inquiry and independent review where required. Measurement approaches recommended include post‑deployment performance monitoring, bias and fairness testing, security penetration testing, and user experience assessment. The GCDO will publish updates, and related guidance (e.g., GenAI guidance) supplements monitoring expectations with concrete checklists and reporting templates.

Penalties, Liability, and Appeals

As a non‑binding framework, the document itself does not create statutory penalties. Instead it clarifies that legal liability and enforcement arise under existing laws (Privacy Act 2020, Human Rights Act 1993, Official Information Act 1982, Public Records Act 2005, and civil liabilities) when agencies fail to meet statutory obligations. The Framework emphasises internal accountability, audit, and ministerial oversight as primary levers, while noting that privacy breaches, discriminatory outcomes or unlawful recordkeeping may result in regulatory action, complaints to the Privacy Commissioner, judicial review, or civil liability. Agencies are expected to maintain accessible appeal and review channels for individuals affected by AI‑assisted decisions consistent with administrative law norms.

Relationship to Other Instruments

The Framework is explicitly positioned within New Zealand’s existing legal and policy ecosystem. It references and aligns to the Treaty of Waitangi obligations and domestic statutes (Privacy Act 2020, Public Service Act 2020, Official Information Act 1982, Human Rights Act 1993, Public Records Act 2005). It also references international instruments and best practice, notably the OECD AI Principles. The Framework should be read alongside MBIE’s strategic guidance and the GCDO’s GenAI guidance, and agencies are encouraged to harmonise agency‑level AI policies with the Framework to ensure consistent application across government. See the GCDO page for cross‑references: Artificial intelligence (digital.govt.nz).

International Alignment

The Framework promotes alignment with international norms to support interoperability, trust and New Zealand’s reputation as a trusted AI partner. It endorses OECD values‑based principles, draws lessons from the UK Generative AI work and other international frameworks, and commits to engagement in international fora through MFAT and other agencies. The Global voice pillar directs activity to ensure New Zealand contributes to, and adopts where appropriate, international standards and norms. Links and references include the OECD AI Principles and comparative frameworks referenced on the GCDO page and MBIE materials. The Framework signals a preference for aligning domestic guidance with established international instruments rather than pursuing isolated regulatory regimes.

Implementation Timeline

MilestoneDate
Cabinet strategic direction endorsing OECD principles2024-06-26
Public Service AI Framework published (GCDO A3 summary & page)2025-01-29
Responsible AI Guidance for the Public Service: GenAI published2025-02-03
National AI Strategy launch (linked system strategy)2025-07-01
Ongoing GCDO work programme updates and guidance releases2025-ongoing

Sources and References

SourceType
Public Service AI Framework (digital.govt.nz)Primary Source
Public Service Artificial Intelligence Framework (PDF)Primary Source
Responsible AI Guidance for the Public Service: GenAI (digital.govt.nz)Primary Source
Approach to work on Artificial Intelligence (MBIE Cabinet paper)Primary Source
Guidance for safe use of AI in the public sector (Beehive press release)Primary Source

Requirements for a company

What an organisation has to do under New Zealand - Public Service AI Framework (RAI-NZ-NA-PUBSEAI-2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

11
  • Comply with all statutory obligations, including privacy, public information, and human rights duties.New Zealand public service agencies
  • Embed security-by-design and privacy-by-design controls during AI procurement and development.New Zealand public service agencies
  • Conduct proportionate risk and impact assessments before significant AI deployments.New Zealand public service agencies
  • Assign accountable owner(s), a governance forum, and escalation pathways for AI systems.New Zealand public service agencies
  • Maintain audit trails, model documentation, and testing records for AI systems.New Zealand public service agencies
  • Document Treaty of Waitangi considerations and stakeholder engagement in AI governance.New Zealand public service agencies
  • +5 more in the table below

Must not do

0

Nothing in this category.

Should do

2
  • Map agency AI uses to the five Framework principles and document alignment.New Zealand public service agencies
  • Conduct post-deployment performance monitoring, bias testing, security testing, and user experience assessment.New Zealand public service agencies

Should not do

0

Nothing in this category.

Who must do what

The obligations under New Zealand - Public Service AI Framework (RAI-NZ-NA-PUBSEAI-2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1New Zealand public service agenciesComply with all statutory obligations, including privacy, public information, and human rights duties.
It instructs agencies to interpret definitions in light of statutory obligations, including privacy, public information and human rights duties.
DefinitionsCritical
2New Zealand public service agenciesEmbed security-by-design and privacy-by-design controls during AI procurement and development.
embed security‑by‑design and privacy‑by‑design controls during procurement and development
During procurement and developmentImplementation FrameworkCritical
3New Zealand public service agenciesConduct proportionate risk and impact assessments before significant AI deployments.
Agencies are asked to perform proportionate risk assessments prior to significant AI deployments
Before significant AI deploymentsImplementation FrameworkImportant
4New Zealand public service agenciesAssign accountable owner(s), a governance forum, and escalation pathways for AI systems.
Assign accountable owner(s), governance forum and escalation pathways
Governance and Institutional FrameworkImportant
5New Zealand public service agenciesMaintain audit trails, model documentation, and testing records for AI systems.
Maintain audit trails, model documentation and testing records
Monitoring and EvaluationImportant
6New Zealand public service agenciesDocument Treaty of Waitangi considerations and stakeholder engagement in AI governance.
Document Treaty of Waitangi considerations and stakeholder engagement
Governance and Institutional FrameworkImportant
7New Zealand public service agenciesPublish where AI is used and provide accessible explanations for affected individuals.
Publish where AI is used, and provide accessible explanations for affected individuals
Key Focus AreasImportant
8New Zealand public service agenciesImplement human accountability at all AI system lifecycle stages.
Agencies are expected to implement human accountability at all lifecycle stages
Governance and Institutional FrameworkImportant
9New Zealand public service agenciesImplement procurement and supplier assurance processes for AI systems.
procurement and supplier assurance processes
Governance and Institutional FrameworkImportant
10New Zealand public service agenciesMaintain traceable data lineage and documentation to enable audit and redress.
maintain traceable data lineage and documentation to enable audit and redress
Implementation FrameworkImportant
11New Zealand public service agenciesMaintain accessible appeal and review channels for individuals affected by AI-assisted decisions.
Agencies are expected to maintain accessible appeal and review channels for individuals affected by AI‑assisted decisions.
Penalties, Liability, and AppealsImportant
12New Zealand public service agenciesMap agency AI uses to the five Framework principles and document alignment.
Map agency AI uses to the five Framework principles and document alignment
Compliance ChecklistRecommended
13New Zealand public service agenciesConduct post-deployment performance monitoring, bias testing, security testing, and user experience assessment.
Measurement approaches recommended include post‑deployment performance monitoring, bias and fairness testing, security penetration testing.
Post-deploymentMonitoring and EvaluationRecommended

© Regulations.AI · updated on 13-Jun-2026