82% of New Zealand businesses are using AI. If you’re one of them, it’s worth pausing to consider: are you using it correctly or effectively? And is it giving you the correct answers? If you’re not confident, that’s the risk – trusting AI fully.
If you’re a business leader under pressure to adopt AI, but you’re uncertain where AI assistance should stop and human oversight should begin, we can help. Today, our Tribe are unpacking what’s actually at risk when AI touches sensitive decisions and data, and how to use AI safely and effectively.
Let’s get started.
Can I trust AI’s answers 100%?
Today NZ business leaders don’t trust AI 100%, and that’s a good thing – because AI works best with human oversight.
The issue is, 51% trust AI-generated insights enough to act on them but spend as much time checking AI outputs as they would have saved by using it. In this scenario AI reduces efficiency, and it’s partially because people are asking for information they don’t know themselves. This makes fact checking a necessity and erodes trust in tools – and without the right rules, readiness, and guidance, it could be a problem affecting your entire team.
This isn’t an IT issue either, it’s a governance problem.
Business leaders need to set precedence from the top down around what AI can be used for, and understand that AI is most helpful when it supports your work (not replaces you). The fix isn’t to avoid AI entirely or trust it blindly – it’s to build a structure and process that makes trust in AI decisions a deliberate, defensible choice.
What’s actually at risk?
Before you can start implementing AI governance in your business, it’s important to confirm what falls under the ‘sensitive data’ umbrella.
- Commercial and financial data: Forecasts, pricing models, board papers and strategic plans are exactly the kind of information leaders are now feeding into AI tools, often without knowing where that data goes or who else can see it.
- Customer’s personal information: Any AI tool that touches customer records needs to meet your obligations under the Privacy Act 2020 and the Information Privacy Principles, particularly around how personal information is collected, used and disclosed. This is where AI data security in local businesses tends to break down first, usually through informal, unsanctioned use rather than a deliberate decision.
- Third-party and vendor risk: Every AI tool your business uses sits on someone else’s infrastructure, with its own data handling practices. If you can’t answer basic questions about where an AI vendor stores your data, how long they keep it and whether they use it to train their own models, you don’t have a complete picture of your risk.
- Accountability gaps: This is the one most businesses underestimate. If an AI-assisted decision goes wrong, most businesses can’t currently produce a clear audit trail of who was involved, what data was used and why the outcome was accepted.
Should You Trust AI with High-Level Business Decisions?
The conversation goes beyond a simple yes or no answer. It’s a question of how to use AI in the decision making process.
AI excels in spotting patterns, speeding up processes, and surfacing opportunities busy business leaders might miss. It’s less reliable when it comes to judgement, context and weighing consequences that don’t show up clearly in the data. In practice, the split should look something like:
- AI supporting financial forecasting by modelling scenarios and flagging trends. A person still owns the final financial decision and what it means for the business.
- AI drafting customer communication in seconds. A person still approves it before it goes out, especially where it touches pricing, complaints, or anything sensitive.
- AI surfacing patterns in operational data that a team would take days to find manually. A person still decides what to do about them.
It isn’t about holding AI at arm’s length. It’s about making deliberate choices around the decisions AI can inform, and the ones it should never make without supervision.
How to build an AI decision framework you can actually stand behind
Now, let’s look at how you can change AI governance from a policy document nobody reads to a framework embedded into how your organisation actually operates. It should cover:
- Approved AI platforms: Your team knows which AI tools have been vetted and approved for use by the business and your IT team.
- Data governance and access controls: Know what data each AI tool can reach, and lock down access to anything commercially or personally sensitive by default rather than by exception.
- Clear rules on what AI can and can’t touch: Some decisions and some data categories should sit outside AI’s reach entirely, and this should be clearly communicated to and followed by everyone in the business.
- Human sign-off checkpoints: Build in a clear point where someone on your team reviews and approves AI-assisted outputs before they become a decision, customer communication or a financial commitment.
- Compliance alignment: Anchor your approach to the Privacy Act 2020 and the Ministry of Business, Innovation & Employment’s Responsible AI Guidance for Businesses. Getting AI compliance right isn’t about waiting for new legislation, it’s about applying existing laws and guidance to how your business handles data and decisions.
- Vendor and third-party due diligence: Before any AI tool touches sensitive data, you should understand how the vendor handles it, stores it, and secures it. Basically, you need to know whether the AI vendor is handling sensitive data responsibly.
Our CEO, Rohan Bowyer, puts it plainly:
“AI isn’t the hard part anymore. Almost every business we talk to is already experimenting with AI tools, agents, automations and integrations. The technology has never been more accessible and building something useful is no longer the barrier, the challenge is what happens next. As AI adoption accelerates, many businesses are creating a growing gap between what they’re trying to achieve and how their people and technology are operating day to day. Ownership lines are blurring, decisions are inconsistent, security controls are falling behind. Leaders often don’t have a clear view of what AI is doing across their business, what data it’s accessing, or how it’s influencing outcomes.
That’s why I believe governance and business control are becoming the real innovation advantage. Adopting AI quickly isn’t what will separate successful businesses from everyone else, most organisations can do that today. The differentiator will be how effectively they align, govern and manage AI alongside their people. Here’s a simple test – if you gathered your entire company in a room and explained what you’re trying to achieve this year, would your people and your AI walk out aligned? Would they be working towards the same goals? Operating within the same guardrails? Being held to the same standards of accountability? Most businesses couldn’t honestly answer yes, and that’s where the real opportunity lies. The businesses that win over the next decade won’t be the ones using the most AI. They’ll be the ones who never lost track of who, or what, was actually running the show.”
This is exactly where our Tribe helps with a practical approach. We bring the knowledge, experience, and processes to help transform AI uncertainty into a governed, strategic, and trusted tool that’s at the core of how you do business. It starts with an assessment of where you stand today, a roadmap that closes gaps with clear priorities, and a governance baseline you can build on as AI use grows.
How Tribe Makes Smarter, Safer AI Adoption Possible for New Zealand Businesses
AI usage and capabilities are advancing quickly, and the businesses that get the most from their tools won’t be the ones who rushed to adopt it quickly. It’ll be the businesses that took the time to build the governance, security, and human oversight that allowed them to adopt AI safely for meaningful decisions.
If you’re already using AI for parts of your business and want to know where the gaps in your governance sit, or you’re still deciding how far to let AI into high-level decisions, we can help you find out. With 50+ experts across New Zealand and offices in Hawke’s Bay, Auckland and Christchurch, we’re the trusted, steady technology partner of local businesses looking to understand AI opportunities and manage risk. Book a free governance and security conversation with us today, and you’ll get a clear picture of governance gaps, priorities, and clear next steps that make sense for your business and goals.
FAQs
Should you trust AI with sensitive business decisions?
Within limits. AI is reliable for speed, pattern-spotting, and surfacing options, but a person should still own final judgement on anything with real financial, legal, or reputational consequences. The safest approach treats AI as an input to sensitive decisions, not the decision-maker.
Is it legal to use AI with customer data in New Zealand?
It can be, provided your use complies with the Privacy Act 2020 and the Information Privacy Principles, particularly around collection, use, and disclosure of personal information. This is one of the clearest tests of whether AI is safe for sensitive data in your business: if you can’t explain how a tool handles personal information, you’re not ready to use it on customer data.
Who is liable if an AI-assisted business decision causes harm?
Ultimately, your business is. AI tools don’t carry legal or commercial accountability, directors and leadership do. That’s why an auditable decision trail, showing what data was used and who signed off, matters as much as the decision itself.
Does a small business need a formal AI governance policy?
Yes, and it doesn’t need to be complicated to start. A short policy covering who can use AI, which tools are approved, what AI output needs human sign-off, and what information should never be entered into an AI tool covers most of the risk for a small or mid-sized business.
How do you know if an AI vendor is handling your data responsibly?
Ask directly: where is data stored, how long is it retained, is it used to train the vendor’s models, and what security certifications does the vendor hold. If a vendor can’t answer clearly, treat that as your answer.
What’s the first step to using AI safely for high-level decisions?
Start with an assessment of what AI tools are already in use across your business, what data they can access, and where your current gaps sit against the Privacy Act. We also recommend working with a trusted technology partner, like our Tribe, who have helped to guide other local businesses through this process.