Key takeaways
- New Zealand government organisations reported 545 AI use cases in 2026, double the 272 reported in 2025, with nearly a third now operational rather than experimental.
- The governance challenge is changing from deciding whether AI can be used to maintaining visibility and control as AI spreads across teams, systems and business processes.
- Professional services firms should prepare for the same transition by introducing proportionate risk tiers, clear ownership, an AI inventory and ongoing review of systems already in production.
New Zealand’s public sector is moving quickly from experimenting with artificial intelligence to putting it into everyday use.
The Government Digital Delivery Agency’s 2026 cross-agency survey reports 545 AI use cases across 59 organisations, compared with 272 reported by 70 organisations last year. More than half of participating organisations reported six or more use cases, with an average of about nine per organisation.
The headline is rapid adoption. The more important governance question is what happens when an organisation no longer has a handful of AI pilots, but a growing portfolio of AI embedded across its operations.
AI is moving from pilots into operations
The survey recorded 167 AI use cases in operational phases, three times the number reported in 2025. Nearly one-third of all reported use cases are now operational, showing a clear shift from planning and proof-of-concept activity towards systems people are actually using.
AI is being used across administration, digital and technology functions, communications, policy, project management, corporate services and human resources. More than half of reported use cases directly or indirectly support public-facing services, while generative AI remains the most common technology followed by natural language processing, agentic AI and machine learning.
For organisations outside government, the pattern should look familiar. AI often begins with a controlled productivity experiment and then spreads into existing software, workflows and business processes as staff discover where it can save time or improve services.
Governance gets harder as adoption scales
Early AI governance can be relatively simple. An organisation can approve a few tools, establish rules about confidential information and require employees to check AI-generated work.
That becomes harder when there are dozens of use cases owned by different business units and supported by different vendors. The organisation then needs to know who owns each system, what information it accesses, what decisions it influences, what human review applies and whether the original approval still reflects how the technology is being used.
The problem is not necessarily that individual AI systems become more dangerous. It is that organisational visibility can deteriorate as the number of systems increases.
An AI policy therefore becomes only one part of the control environment. Organisations also need repeatable processes for identifying, assessing, approving, monitoring and eventually retiring AI use cases.
Not every use case needs the same controls
The growth shown in the government survey also reinforces the need for proportionate governance.
Using an approved generative AI tool to improve an internal email is materially different from using AI to analyse sensitive client information, screen employment candidates, recommend financial decisions or take actions through an agentic system. Treating every one of those activities identically would either create unnecessary bureaucracy around low-risk uses or insufficient scrutiny around higher-risk ones.
A practical governance model should therefore classify AI according to consequence. Data sensitivity, impact on people, level of autonomy, importance of the output and availability of meaningful human oversight are useful factors when determining how much review is required.
Low-risk use can then move quickly within clear boundaries, while higher-risk uses receive privacy, security, legal, procurement or executive scrutiny where appropriate.
The survey contains an important qualification
The reported number of AI use cases doubled, but the survey should not be interpreted as a precise measure showing that AI use across a fixed group of agencies increased by exactly 100 percent.
Seventy organisations participated in 2025 compared with 59 in 2026, and the survey relies on organisations reporting their own use cases. What the results clearly demonstrate is a substantial increase in reported use, a higher average number of use cases per participating organisation and a significant increase in systems reaching operational stages.
That distinction is worth making because governance decisions should be based on what the evidence shows rather than an exaggerated interpretation of the headline number.
The evidence is still significant. AI is becoming considerably more embedded in New Zealand’s public sector.
Some barriers are reducing
The survey also reports that several long-standing barriers to AI adoption have declined, including staff capability, security and privacy concerns, and lack of internal understanding or organisational support. Skills and capability, cost and funding, and security nevertheless remain among the most frequently reported barriers.
More difficult issues are also becoming visible as adoption matures, particularly public acceptance, AI reliability and data sovereignty. These cannot be resolved simply by buying a better AI product because they involve organisational decisions about trust, information, accountability and acceptable risk.
This is another sign of maturing adoption. The question is moving from whether an organisation has access to AI towards whether it can operate AI reliably and responsibly.
AI literacy becomes part of governance
The Government Digital Delivery Agency reinforced this point during the same week by releasing an AI Development Series with the Leadership Development Centre for public servants.
The programme covers introductory AI knowledge, safe and responsible use, practical application and emerging developments, with particular emphasis on informed decision-making, human judgement, responsibility and oversight.
There is a useful lesson for professional services firms here. Staff training should not be treated only as a way to encourage AI adoption; it is also a governance control.
A policy cannot anticipate every prompt, document or situation an employee will encounter. Staff therefore need enough AI literacy to recognise when information should not be entered into a system, when output requires verification and when a proposed use needs additional approval.
What this means for your organisation
Professional services firms should consider whether their AI governance is designed for the amount of AI they expect to be using next year rather than the amount they were using last year.
Maintain an AI inventory. Record material AI systems and use cases, their purpose, business owner, supplier, information accessed and current status. Include AI functions embedded inside existing software.
Introduce risk tiers. Separate routine productivity uses from systems handling sensitive information, influencing significant decisions or taking actions. Increase approval and assurance requirements as potential consequences increase.
Assign clear ownership. Every material AI use case should have a person responsible for its ongoing operation, not merely someone who approved its initial purchase.
Review operational AI. Reassess systems when their purpose, model, supplier, integrations, permissions or information access materially changes.
Build practical AI literacy. Train staff not only on permitted tools but on verification, confidentiality, privacy, limitations and when human judgement must take priority.
Prepare for increasing autonomy. Where agentic AI can access tools or take actions, establish explicit permissions, human approval points, logging and the ability to disable or reverse activity.
Governance needs to grow with adoption
The public sector survey provides a useful picture of what AI adoption looks like once experimentation begins turning into normal operations.
For professional services firms, the lesson is not simply to adopt more AI. It is to make sure governance can scale at approximately the same pace.
A firm with two approved AI tools can rely heavily on individual oversight. A firm with AI embedded throughout its software and workflows needs something more systematic: visibility, proportionate assessment, clear ownership and ongoing review.
Those controls become easier to establish while the AI portfolio is still manageable. Waiting until dozens of systems are already operating makes the governance problem considerably harder.
General information disclaimer
This article provides general information and commentary only. It is not legal, privacy, technology, governance or other professional advice. Organisations should obtain advice appropriate to their circumstances and intended use of AI.
Sources
- Government Digital Delivery Agency, Report: 2026 cross-agency survey of use cases for artificial intelligence, updated 19 August 2026
- Government Digital Delivery Agency, 2026 cross-agency AI survey: highlights
- Government Digital Delivery Agency, New training supports safe and practical use of AI across the public service, 18 August 2026

