New Zealand PS AI baseline: who stops the agent before it sends?

Governance Watch | Published | HaltState

Watch New Zealand PS AI baseline: who stops the agent before it sends? on YouTube

New Zealand's Public Service AI Framework asks for human accountability, not just good intentions. It is a non-binding framework for Public Service AI practitioners and decision-makers — not a new law, and not a rule imposed on every private business. This is a baseline explainer, reviewed against the official pages on 21 September 2026. General information and technical commentary, not legal advice.

Five principles, one uncomfortable question

The framework sets five principles: inclusive, sustainable development; human-centred values; transparency and explainability; safety and security; and accountability. The accountability principle says AI use within the Public Service should be subject to oversight by accountable humans with appropriate authority and capability at every stage. The transparency section says agencies should publicly disclose when AI systems are used, how they were developed and how they affect outcomes, as relevant and appropriate to the use case. The Government Chief Digital Officer leads safe and trustworthy AI adoption and use in the public service.

Our operational question: if an assistant is about to send something it should not, who has the authority and the means to stop it?

Read the date carefully

The framework page displays "Last updated 29 January 2025" and also says it sits within the National AI Strategy launched in July 2025. A displayed update date is not evidence that the page has remained unchanged since January, and it does not establish a legal commencement date. Check the official page for the current state before relying on any detail here.

Non-binding does not mean law-free

The framework page separately says agencies need to use AI in line with the existing laws, regulations, conventions, policies and guidance that apply to public service AI use. Its examples include the Privacy Act 2020 and Public Records Act 2005. The page recommends using the framework to inform organisational policies and evaluate AI initiatives; it does not make the framework binding. Treat it as a starting point for an agency's questions, not proof of a mandatory vendor test or a prediction about future tenders. This article does not determine whether any particular use complies with those laws.

An illustrative scenario: the wrong information leaves the inbox

Hypothetical, not a reported incident: imagine a public-service assistant drafting a citizen response and then attempting to send third-party personal information. A proposed control would check the permitted recipients, information scope and required human approval before allowing a sending action. This NZ correspondence scenario has not been executed or tested, and no observed HaltState decision is claimed for it.

A separate isolated test, retained from the Australian episode

In a retained Australian demonstration record, synthetic purchase_order.change proposals were evaluated by the HaltState policy engine against authored in-memory fixtures at source commit 73dfe7ed. A proposal without an approved task mandate returned DENY; a second carrying user access and an approved task mandate returned APPROVAL_REQUIRED. Neither action was executed, no human approval was completed, and the evidence is hash-only and unsigned, with a verified content digest (e92e7342…). The record retains the action, policy version, decision and content digest.

That example illustrates a configured decision boundary; it does not validate the NZ scenario or certify conformity with the framework.

What stays with the agency

The agency and its advisers still need to assess applicable obligations, decide how to disclose AI use, design and implement controls, and manage records and incidents. HaltState's retained test shows the policy decisions above, not that any agency is legally compliant.

One practical next step

Read the official framework, choose one automated action, and identify who can authorise it, who can stop it and what record the decision leaves. Before a real release, check scope, ownership and the actual controls your systems enforce. Explore HaltState.

Inspect the isolated test record and limitations.

Actual isolated test record

Retained Australian demonstration record; authored in-memory policy evaluation against an immutable source commit. Unsigned hash-only evidence, not certification.

Action
purchase_order.change
Scenario A (no task mandate)
DENY — au_ism_po_change_no_task_mandate_deny_v1
Scenario B (dual authority)
APPROVAL_REQUIRED — au_ism_po_change_dual_authority_approval_v1
Policy version
881e5fd2005182a915d84e67ee1475c63af2c983f84a83021e87d41951bbe613
Frozen source
73dfe7ed098c55493adb1d4a32542aefcded6fad
Content digest
e92e73421967f979ef1ee9f6fcae946fe99da10669c001d32b30eef1682bf97f

Nothing was executed. No human approval was completed. No production connectors, persistent tenant configuration or signing were exercised. Hash-only evidence is not legal clearance or government acceptance.