top of page
town of newzealand

COMPLIANCE NEW ZEALAND

Enforced at runtime.

New Zealand takes a light-touch, principles-based approach: existing law applies to AI, guided by the national AI Strategy and the Privacy Commissioner's expectations. EVEDY makes that compliance demonstrable – at runtime.

FRAGMENTED AI REGULATION 

The regulatory landscape for AI in New Zealand

No AI-specific statute – but the Privacy Act, sector regulators and public-sector commitments set clear expectations that enterprises must be able to evidence. This is an incomplete excerpt of the current compliance.

REGULATION

WHAT IT REQUIRES 

HOW EVEDY ENFORCES IT

Privacy Act 2020

Information Privacy Principles; guidance from the Privacy Commissioner on AI

Lawful collection and use of personal information, security safeguards, transparency – with explicit regulator expectations for generative AI.

Automatic PII redaction in prompts and responses, access control via your IAM, complete logging of every AI interaction.

AI Strategy & Responsible AI Guidance

Light-touch national framework relying on existing law

Responsible adoption: risk assessment, transparency, human oversight and accountability across the AI lifecycle.

Policy enforcement per use case, human-oversight escalation, version testing and evaluation before production.

Algorithm Charter for Aotearoa

Public sector; relevant to suppliers to government

Transparency, partnership, and human oversight of algorithmic decision-making in and for public agencies.

Runtime controls and audit trails that let suppliers evidence Charter-aligned use of AI in government engagements.

Sector regulators & consumer law

FMA, Commerce Commission and the Fair Trading Act applied to AI

No misleading conduct, fair customer outcomes and sound governance of models used in regulated services.

Non-compliant outputs are detected, blocked or escalated in real time; evidence flows to your SIEM and audit systems.

ISO/IEC 42001 & internal policies

AI management standard and your own directives

A systematic AI management system: roles, processes, continuous improvement – plus your enterprise AI policies.

Enterprise policies are stored as machine-enforceable rules and applied automatically to every AI interaction – not just documented.

As of August 2026. This overview does not constitute legal advice.

THE DIFFERENCE

From written policy to runtime enforcement

Most enterprises have AI policies. Very few can prove they are followed. EVEDY closes exactly that gap.

1

Capture the rules

Legal requirements and internal policies are modelled as machine-readable policies – synchronised from your GRC platform if you wish.

2

Enforce at runtime

Every request to a model or agent passes through EVEDY. Violations are blocked, corrected or escalated – in real time, not after the fact.

3

Prove compliance

Audit trails per user, per agent and per regulation give internal audit, the board and regulators defensible evidence at any time.

bottom of page