AI policy

Read the Privacy Impact Assessment of our proposed use of Copilot

Purpose

This policy establishes the governance, risk, privacy, and ethical requirements for the safe, responsible, and transparent use of Artificial Intelligence (AI) systems within Aroturuki Tamariki
Children (plural) aged 0-13 yearsView the full glossary
. It ensures that AI use supports our monitoring functions while protecting tamariki, rangatahi
Young person aged 14 – 21 years of ageView the full glossary
, whānau
Whānau refers to people who are biologically linked or share whakapapa. For the Monitor’s monitoring purposes, whānau includes parents, whānau members living with tamariki at the point they have come into care View the full glossary
, kaimahi, and community partners. It also ensures alignment with the:

  • Public Service AI Framework (2025)
  • Protective Security Requirements (PSR)
  • NZISM (New Zealand Information Security Manual)
  • Privacy Act 2020
  • Aroturuki Tamariki Information Rules
  • Incident Response and Procurement Policies

Scope

This policy applies to:

  • All Aroturuki Tamariki kaimahi and board members engaging with AI tools or systems on behalf of Aroturuki Tamariki, and contractors and third-party partners who have agreed to its application.
  • All AI systems, including generative AI, machine learning, automation tools, and embedded AI features in software.
  • All organisational data processed, analysed, or interacted with by AI systems.
  • All procurement, deployment, and use of AI tools across the organisation.

Aroturuki Tamariki
Children (plural) aged 0-13 yearsView the full glossary
commits to the following principles, aligned with the Public Service AI Framework’s five principles (inclusive development, human-centred values, transparency, robustness, and accountability). 

Manaakitanga – Improvement and stewardship

  • AI use must support our role to improve outcomes for tamariki, rangatahi
    Young person aged 14 – 21 years of ageView the full glossary
    and their whānau
    Whānau refers to people who are biologically linked or share whakapapa. For the Monitor’s monitoring purposes, whānau includes parents, whānau members living with tamariki at the point they have come into care View the full glossary
    .
  • It should enhance the quality, accessibility, and equity of our work.
  • It must not compromise the trust people place in us.

Kaitiakitanga – Human oversight and accountability 

  • Content generated or guided by AI must be reviewed by kaimahi.
  • A named individual or team must be accountable for decisions or work that involve AI assistance.
  • Kaimahi are always accountable for work products, regardless of AI assistance. 

Tika, pono – Fairness, bias and equity

  • Proactively identify and mitigate potential biases in AI training data, design, and outputs, to the extent feasible, to ensure fairness and prevent discrimination in line with the Responsible AI
  • Guidance for the Public Service: GenAI.
  • Ensure AI does not reinforce bias or cause harm. 

Māramatanga – Transparency and explainability 

  • Be open about when and how AI is being used to support our reporting, analysis or decision-making processes.
  • Clearly label AI-generated content where lack of disclosure could be misleading.
  • Be mindful that use of AI (including inputs and generated outputs) may be subject to requests under the Official Information Act 1982. 

Whakamaru – Privacy, security and confidentiality 

  • AI use must adhere to the Privacy Act 2020, Public Records Act 2005, Public Service Act 2020, Oversight of Oranga Tamariki System Act 2022 and Information Rules under that Act, Public Sector AI Framework expectations, and Aroturuki Tamariki ICT use protocols.
  • Do not enter or upload sensitive, personal, confidential, or other classified information into any AI tool or platform that is not approved for that data type by ELT. This includes publicly available AI tools and third-party AI services not listed on the agency’s approved AI systems register. 

Kounga – Integrity and quality assurance

  • All AI-generated content must be checked to ensure it is accurate and appropriate for the task it is to be used for.
  • Take reasonable steps in the circumstances to ensure the use of AI respects copyright and other intellectual property rights.

Prohibited uses 

The following are strictly not allowed 

  • Using AI tools or platforms not approved by the AI Officer.
  • Using AI tools or platforms for purposes not approved by the AI Officer.
  • Using Aroturuki Tamariki
    Children (plural) aged 0-13 yearsView the full glossary
    data to train or fine-tune any AI model or allowing Aroturuki Tamariki data to be used for such purposes.
  • Entering or uploading personally identifiable or otherwise sensitive information into unapproved AI tools.
  • Using AI to collect personal information about individuals from third party sources.
  • Using AI to generate new personal information about individuals. This includes using AI tools to generate opinionative or evaluative information about individuals but, to avoid doubt, does not include using authorised transcription tools that utilise AI for processing.
  • Using AI to generate or manipulate quotes, evidence, or monitoring findings.
  • Using AI for automated decision-making. 

Approved uses 

AI tools and platforms approved for organisational use by ELT may be used for: 

  • drafting administrative content (e.g. emails, summaries, templates)
  • analysing non-sensitive, non-identifiable datasets
  • productivity support (e.g., scheduling, formatting, document structuring)
  • internal process automation where no sensitive personal information is involved. 

Consultation with stakeholders 

AI tools must not be implemented to assess the matters referred to in section 14 of the Oversight of Oranga Tamariki System Act 2022 without undertaking the consultation referred to in Rule 7 of the Information Rules. This means AI tools must not, without such consultation, be implemented to monitor the performance of the Oranga Tamariki system in the context of its interface with other systems, including: 

  • assessing compliance with the Oranga Tamariki Act 1989, national care standards regulations, and other regulations and standards made under that Act by the chief executive of Oranga Tamariki and approved providers
  • assessing the quality and impacts of service delivery, service mix, service resourcing, and practices on the experiences of children, young people, families, and whānau
    Whānau refers to people who are biologically linked or share whakapapa. For the Monitor’s monitoring purposes, whānau includes parents, whānau members living with tamariki at the point they have come into care View the full glossary
    , or 
  • assessing outcomes for children, young people, families, and whānau who receive services or support through the Oranga Tamariki system, and changes in outcomes over time, with particular regard to Māori children and young people and their whānau. 

AI Officer-guided deployment

  • The AI Officer is the central approval and advisory authority for AI use activities.
  • AI tools considered for deployment must be reviewed and signed off by the AI Officer and ELT.
  • The AI Officer will maintain a register of IT platforms, data and workspaces where AI use is permitted. This will be available on Te Mātāpuna. 

AI risk assessment 

The AI Officer must approve all medium and high-risk uses of AI. Before permitting staff to use an AI tool for organisational purposes, Aroturuki Tamariki must complete an AI Risk Assessment, covering the following. 

  • Privacy risks (including all applicable information privacy principles).
  • Security risks (PSR, NZISM).
  • Data sensitivity and classification.
  • Vendor compliance.
  • Bias and cultural safety.
  • Human oversight requirements.
  • Transparency and explainability. 

Vendor and procurement requirements 

All AI enabled tools procured by Aroturuki Tamariki or activated within existing services, software, or platforms, must: 

  • not use Aroturuki Tamariki data for model training or otherwise for the vendor’s own purposes
  • provide clear data retention and deletion controls
  • support auditability and transparency
  • meet applicable NZISM and PSR security requirements (subject to Aroturuki Tamariki’s
  • acceptance of residual risk through its certification and accreditation processes)
  • include privacy/security breach notification obligations
  • undergo contract review by the AI Officer. 

Data handling requirements 

  • No personal information about tamariki, rangatahi
    Young person aged 14 – 21 years of ageView the full glossary
    or whānau may be processed by AI systems unless expressly approved by the AI Officer and ELT. To avoid doubt, this includes using AI-enabled transcription services to process interviews with tamariki, rangatahi or whānau, unless expressly approved.
  • All AI outputs must be reviewed by a human before use.
  • AI-generated content must be clearly identified in internal workflows where lack of disclosure could be misleading. 

Incident response 

Any suspected misuse of AI, privacy breach, or security incident must be: 

  • reported immediately using the Incident Report Form
  • logged and escalated per the Incident Response Standard Operating Procedure
  • investigated by the AI Officer
  • reported to the Privacy Commissioner if required (s.114). 

Using an AI system in violation of this policy – particularly in relation to confidential or personal information – is a serious breach of protocol and may result in disciplinary action.

Role

Responsibility

Board Receive reports on significant AI deployments, associated risks, and any AI-related incidents involving the compromise of Aroturuki Tamariki
Children (plural) aged 0-13 yearsView the full glossary
confidential information or personal information of tamariki, rangatahi
Young person aged 14 – 21 years of ageView the full glossary
,whānau
Whānau refers to people who are biologically linked or share whakapapa. For the Monitor’s monitoring purposes, whānau includes parents, whānau members living with tamariki at the point they have come into care View the full glossary
, or kaimahi, or that could otherwise bring Aroturuki Tamariki into disrepute or weaken people's trust and confidence in Aroturuki Tamariki.
Chief Executive Owns AI Governance. Sets strategic direction and approves significant AI initiatives.
AI Officer The central governance role. Responsible for guiding the deployment process, maintaining the deployment register, approving checklists, conducting reviews, and providing expert advice on risk mitigation.
Privacy Officer Responsible for reviewing and approving Privacy Impact Assessments for any non-standard deployments involving personal data.
Managers Foster responsible use, ensure team compliance, and provide guidance.
All kaimahi Use AI responsibly, protect data, follow this policy. Must not attempt to bypass data restrictions or use non-approved tools for official work.
Vendor Must comply with contractual AI restrictions and privacy requirements

Documents associated with this policy

  • AI use guide
  • ICT user policy
  • Information rules

This policy will be reviewed

  • Annually
  • After any major AI related incident.
  • When PSR, NZISM, or Public Service AI Framework guidance changes.
  • When new AI risks emerge.

Version control

Version 1.0

30 January 2026