New Zealand - Public Service AI Framework (RAI-NZ-NA-PUBSEAI-2025)
Public Service AI Framework
New Zealand
RAI-NZ-NA-PUBSEAI-2025The Public Service AI Framework (GCDO) is non‑binding guidance that sets a vision, five principles and a six‑pillar work programme to support responsible AI adoption across New Zealand public service agencies. It encourages a risk‑based, human‑centred and transparency‑focused approach aligned with existing New Zealand law and international AI principles.
Summary
The Public Service AI Framework, published by the Government Chief Digital Officer (GCDO) in January 2025, provides structured, non‑binding guidance for New Zealand public service agencies on the responsible adoption, deployment and governance of artificial intelligence (AI). It articulates a clear vision — “Adopt AI responsibly to modernise public services and deliver better outcomes for all New Zealanders” — and defines five core principles (inclusive sustainable development, human‑centred values, transparency and explainability, safety and security, and accountability). The Framework situates AI guidance within New Zealand’s broader legal and constitutional context (including the Treaty of Waitangi and domestic statutes such as the Privacy Act 2020, Official Information Act 1982, Public Service Act 2020 and relevant human‑rights instruments) and promotes a light‑touch, proportionate, risk‑based approach to regulation, consistent with Cabinet direction and MBIE advice.
Operationally, the Framework sets out a GCDO‑led work programme structured around six pillars: Governance, Guardrails, Capability, Innovation, Social licence and Global voice. This programme is intended to help agencies implement governance and assurance arrangements, apply safety‑by‑design and security‑by‑design approaches, build workforce capability, enable safe testing and innovation, and engage the public to build trust. The Framework applies broadly to “all forms of AI used in New Zealand public services,” referencing OECD definitions of AI systems and encouraging agencies to document AI uses, disclose when AI assists decision‑making, and enable affected individuals to understand outcomes.
The Framework is explicit that it is guidance rather than binding regulation: agencies are encouraged to align to its principles and the GCDO will support implementation through practical guidance (including a PDF one‑page A3 summary and a suite of follow‑on materials such as Responsible AI Guidance for the Public Service: GenAI released in February 2025). It emphasises alignment with existing law and mechanisms rather than creating a standalone AI Act, consistent with the MBIE Cabinet paper (June–July 2024) which recommended a proportionate, risk‑based policy approach.
Key operational expectations include: human accountability and oversight across AI lifecycles; proportionate risk assessment and assurance; transparency and public disclosure where appropriate; robust data governance and traceability; security and safety measures; procurement and supplier management; auditability and documentation; workforce capability building; and engagement with Māori and communities to uphold Treaty obligations and support equitable outcomes. While the Framework itself does not set new statutory penalties, failure to meet legal obligations (e.g., privacy law or public records requirements) may trigger enforcement under those existing regimes. The GCDO, supported by agencies such as MBIE, the Privacy Commissioner and the Public Service Commission, will steward implementation, monitoring and ongoing updates to guidance.
Full article
Read full text ↗Overview
The Public Service AI Framework is a GCDO (Government Chief Digital Officer) issued guidance document designed to support responsible AI adoption across New Zealand’s Public Service. It sets a concise vision — "Adopt AI responsibly to modernise public services and deliver better outcomes for all New Zealanders" — and defines five guiding principles that draw on the OECD AI principles. The Framework is presented as non‑binding, risk‑based and proportionate, and sits within New Zealand’s wider AI policy architecture alongside the MBIE work programme and the National AI Strategy. The one‑page A3 summary is available from the GCDO site as a PDF and agencies are encouraged to reference it when creating governance or procurement artifacts. For the official Framework text and the A3 summary see Public Service AI Framework (digital.govt.nz) and the downloadable Public Service Artificial Intelligence Framework (PDF).
Definitions
The Framework adopts a practical working definition of an AI system aligned to the OECD: a machine‑based system that infers from input how to generate outputs (predictions, content, recommendations, decisions) that influence environments. It distinguishes AI by capability (from simple automation to adaptive systems) and covers generative AI as a subset addressed by follow‑on guidance. The Framework also uses standard governance terms such as "human oversight", "assurance", "guardrails", "risk assessment", and "traceability". It instructs agencies to interpret these definitions in light of the agency’s statutory obligations, including privacy, public information and human rights duties. Additional operational definitions and GenAI‑specific considerations are expanded in the companion Responsible AI Guidance for the Public Service: GenAI available at Responsible AI Guidance: GenAI (digital.govt.nz).
Governance and Institutional Framework
The Framework establishes expectations for governance arrangements within agencies and system stewardship by the GCDO. Agencies are expected to implement human accountability at all lifecycle stages, embed risk‑based assurance and reporting, and maintain documentation and audit trails to enable oversight. The GCDO will lead a cross‑agency work programme (Governance, Guardrails, Capability, Innovation, Social licence, Global voice) and coordinate with MBIE, the Public Service Commission, the Office of the Privacy Commissioner and other central agencies. MBIE’s Cabinet paper "Approach to work on Artificial Intelligence" frames the strategic, cross‑portfolio approach and recommends leveraging existing regulatory instruments rather than creating a stand‑alone AI Act; that paper and supporting materials are available at Approach to work on Artificial Intelligence (MBIE PDF). Institutional expectations include escalation mechanisms for high‑risk uses, procurement and supplier assurance processes, and integration of Treaty of Waitangi considerations into governance practices.
Key Focus Areas
The Framework sets out five principles and highlights six pillars that shape the public service’s focus. Principles cover inclusive development, human‑centred values, transparency and explainability, safety and security, and accountability. The pillars (Governance, Guardrails, Capability, Innovation, Social licence, Global voice) direct operational activity: Governance requires clear roles and responsibilities and oversight; Guardrails require risk assessment frameworks, model validation and testing; Capability calls for workforce training and secondments; Innovation supports safe testing and sandboxes for experimentation; Social licence emphasises public engagement, Māori partnership and addressing inequities; Global voice covers international coordination and exportable practices. The Framework also highlights procurement, data ethics, recordkeeping and incident response as recurrent cross‑cutting concerns. For GenAI specific operational measures see the companion guidance and the GCDO pages cited above.
Implementation Framework
The GCDO proposes a work programme and practical tools to help agencies implement the Framework: an assurance model, risk assessment templates, procurement checklists, documentation templates, and capability building resources. Agencies are asked to perform proportionate risk assessments prior to significant AI deployments, to embed security‑by‑design and privacy‑by‑design controls during procurement and development, and to maintain traceable data lineage and documentation to enable audit and redress. Implementation guidance encourages iterative pilots followed by scaled roll‑out when assurance outcomes are acceptable. The Framework deliberately avoids prescriptive thresholds; instead it instructs agencies to size assurance to risk and statutory obligations, using existing legal enforcement channels when breaches occur.
Monitoring and Evaluation
The Framework calls for continuous monitoring, periodic review and reporting to support oversight and public confidence. The GCDO will monitor uptake, maintain a repository of lessons learned and coordinate cross‑agency evaluation. Agencies are expected to maintain documentation sufficient for internal audit, ministerial inquiry and independent review where required. Measurement approaches recommended include post‑deployment performance monitoring, bias and fairness testing, security penetration testing, and user experience assessment. The GCDO will publish updates, and related guidance (e.g., GenAI guidance) supplements monitoring expectations with concrete checklists and reporting templates.
Penalties, Liability, and Appeals
As a non‑binding framework, the document itself does not create statutory penalties. Instead it clarifies that legal liability and enforcement arise under existing laws (Privacy Act 2020, Human Rights Act 1993, Official Information Act 1982, Public Records Act 2005, and civil liabilities) when agencies fail to meet statutory obligations. The Framework emphasises internal accountability, audit, and ministerial oversight as primary levers, while noting that privacy breaches, discriminatory outcomes or unlawful recordkeeping may result in regulatory action, complaints to the Privacy Commissioner, judicial review, or civil liability. Agencies are expected to maintain accessible appeal and review channels for individuals affected by AI‑assisted decisions consistent with administrative law norms.
Relationship to Other Instruments
The Framework is explicitly positioned within New Zealand’s existing legal and policy ecosystem. It references and aligns to the Treaty of Waitangi obligations and domestic statutes (Privacy Act 2020, Public Service Act 2020, Official Information Act 1982, Human Rights Act 1993, Public Records Act 2005). It also references international instruments and best practice, notably the OECD AI Principles. The Framework should be read alongside MBIE’s strategic guidance and the GCDO’s GenAI guidance, and agencies are encouraged to harmonise agency‑level AI policies with the Framework to ensure consistent application across government. See the GCDO page for cross‑references: Artificial intelligence (digital.govt.nz).
International Alignment
The Framework promotes alignment with international norms to support interoperability, trust and New Zealand’s reputation as a trusted AI partner. It endorses OECD values‑based principles, draws lessons from the UK Generative AI work and other international frameworks, and commits to engagement in international fora through MFAT and other agencies. The Global voice pillar directs activity to ensure New Zealand contributes to, and adopts where appropriate, international standards and norms. Links and references include the OECD AI Principles and comparative frameworks referenced on the GCDO page and MBIE materials. The Framework signals a preference for aligning domestic guidance with established international instruments rather than pursuing isolated regulatory regimes.
Implementation Timeline
| Milestone | Date |
|---|---|
| Cabinet strategic direction endorsing OECD principles | 2024-06-26 |
| Public Service AI Framework published (GCDO A3 summary & page) | 2025-01-29 |
| Responsible AI Guidance for the Public Service: GenAI published | 2025-02-03 |
| National AI Strategy launch (linked system strategy) | 2025-07-01 |
| Ongoing GCDO work programme updates and guidance releases | 2025-ongoing |
Sources and References
| Source | Type |
|---|---|
| Public Service AI Framework (digital.govt.nz) | Primary Source |
| Public Service Artificial Intelligence Framework (PDF) | Primary Source |
| Responsible AI Guidance for the Public Service: GenAI (digital.govt.nz) | Primary Source |
| Approach to work on Artificial Intelligence (MBIE Cabinet paper) | Primary Source |
| Guidance for safe use of AI in the public sector (Beehive press release) | Primary Source |
Requirements for a company
What an organisation has to do under New Zealand - Public Service AI Framework (RAI-NZ-NA-PUBSEAI-2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
11- Comply with all statutory obligations, including privacy, public information, and human rights duties.New Zealand public service agencies
- Embed security-by-design and privacy-by-design controls during AI procurement and development.New Zealand public service agencies
- Conduct proportionate risk and impact assessments before significant AI deployments.New Zealand public service agencies
- Assign accountable owner(s), a governance forum, and escalation pathways for AI systems.New Zealand public service agencies
- Maintain audit trails, model documentation, and testing records for AI systems.New Zealand public service agencies
- Document Treaty of Waitangi considerations and stakeholder engagement in AI governance.New Zealand public service agencies
- +5 more in the table below
Must not do
0Nothing in this category.
Should do
2- Map agency AI uses to the five Framework principles and document alignment.New Zealand public service agencies
- Conduct post-deployment performance monitoring, bias testing, security testing, and user experience assessment.New Zealand public service agencies
Should not do
0Nothing in this category.
Who must do what
The obligations under New Zealand - Public Service AI Framework (RAI-NZ-NA-PUBSEAI-2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | New Zealand public service agencies | Comply with all statutory obligations, including privacy, public information, and human rights duties. “It instructs agencies to interpret definitions in light of statutory obligations, including privacy, public information and human rights duties.” | — | Definitions | Critical |
| 2 | New Zealand public service agencies | Embed security-by-design and privacy-by-design controls during AI procurement and development. “embed security‑by‑design and privacy‑by‑design controls during procurement and development” | During procurement and development | Implementation Framework | Critical |
| 3 | New Zealand public service agencies | Conduct proportionate risk and impact assessments before significant AI deployments. “Agencies are asked to perform proportionate risk assessments prior to significant AI deployments” | Before significant AI deployments | Implementation Framework | Important |
| 4 | New Zealand public service agencies | Assign accountable owner(s), a governance forum, and escalation pathways for AI systems. “Assign accountable owner(s), governance forum and escalation pathways” | — | Governance and Institutional Framework | Important |
| 5 | New Zealand public service agencies | Maintain audit trails, model documentation, and testing records for AI systems. “Maintain audit trails, model documentation and testing records” | — | Monitoring and Evaluation | Important |
| 6 | New Zealand public service agencies | Document Treaty of Waitangi considerations and stakeholder engagement in AI governance. “Document Treaty of Waitangi considerations and stakeholder engagement” | — | Governance and Institutional Framework | Important |
| 7 | New Zealand public service agencies | Publish where AI is used and provide accessible explanations for affected individuals. “Publish where AI is used, and provide accessible explanations for affected individuals” | — | Key Focus Areas | Important |
| 8 | New Zealand public service agencies | Implement human accountability at all AI system lifecycle stages. “Agencies are expected to implement human accountability at all lifecycle stages” | — | Governance and Institutional Framework | Important |
| 9 | New Zealand public service agencies | Implement procurement and supplier assurance processes for AI systems. “procurement and supplier assurance processes” | — | Governance and Institutional Framework | Important |
| 10 | New Zealand public service agencies | Maintain traceable data lineage and documentation to enable audit and redress. “maintain traceable data lineage and documentation to enable audit and redress” | — | Implementation Framework | Important |
| 11 | New Zealand public service agencies | Maintain accessible appeal and review channels for individuals affected by AI-assisted decisions. “Agencies are expected to maintain accessible appeal and review channels for individuals affected by AI‑assisted decisions.” | — | Penalties, Liability, and Appeals | Important |
| 12 | New Zealand public service agencies | Map agency AI uses to the five Framework principles and document alignment. “Map agency AI uses to the five Framework principles and document alignment” | — | Compliance Checklist | Recommended |
| 13 | New Zealand public service agencies | Conduct post-deployment performance monitoring, bias testing, security testing, and user experience assessment. “Measurement approaches recommended include post‑deployment performance monitoring, bias and fairness testing, security penetration testing.” | Post-deployment | Monitoring and Evaluation | Recommended |
Related Regulations
Responsible AI Guidance for the Public Service: GenAI
New Zealand96% similar
Responsible Artificial Intelligence guidance for businesses
New Zealand94% similar
New Zealand’s Strategy for Artificial Intelligence: Investing with Confidence
New Zealand93% similar
Algorithm Charter for Aotearoa New Zealand
New Zealand93% similar
New Zealand AI Regulation Overview
New Zealand92% similar
© Regulations.AI · updated on 13-Jun-2026