Generative AI is moving quickly into the boardroom and across organisations — analysing board papers, drafting communications, supporting strategic research, detecting risk, and helping management execute. New Zealand boards are broadly optimistic but cautious, and the Institute of Directors (IoD) has made clear that adopting AI does not change a director’s fundamental duties. KiwiGen.AI helps boards and executive teams adopt generative AI safely, with governance frameworks that keep pace with the technology.
Understanding Artificial Intelligence in Corporate Governance Institute of Directors New Zealand
The IoD’s guidance examines how New Zealand organisations are adopting AI – the strategic benefits they are pursuing, and how boards are managing AI risk within existing frameworks. Oversight of automated decision-making has become a test of governance credibility, making it a clear priority for directors governing in an AI world.
AI in the boardroom and beyond Adoption is becoming mainstream. Organisations are using AI to improve operational efficiency, customer outcomes, risk management, and data analysis. The strongest business cases involve streamlining operations, but the focus is rapidly shifting to strategic growth and innovation.
Most organisations use AI to support rather than replace human decisions, and the level of risk depends on what the system does. An internal tool that summarises management reports is very different from an autonomous system that influences hiring, pricing, or strategic direction. The greater the potential impact on stakeholders, the stronger the testing, oversight, and accountability arrangements should be – and boards must be particularly alert to algorithmic bias, data privacy, and a lack of transparency in AI-supported decisions.
Mind the governance gap The main risk is letting adoption outpace governance. Across various sectors, organisations are expanding their AI use faster than they are updating risk controls – creating an “AI governance gap”. The risks extend well beyond cybersecurity to inaccurate or misleading outputs, bias, decisions that cannot be explained, and over-reliance on third-party platforms. A model should not be trusted simply because its results look consistent; the board must ensure management can adequately test, monitor, challenge, and explain it.
Existing New Zealand directors’ duties still apply. AI does not reduce the need to act in good faith, exercise care, diligence, and skill, and protect confidential corporate information. A board should not rely on AI-generated insights without ensuring management has checked the assumptions and accuracy. Accountability remains firmly with the directors and the organisation, not the software developer.
Practical steps for your board To keep governance ahead of adoption, boards should ask management to:
- Identify where AI is used – keep a register of approved tools, trials, embedded features, and informal staff use, noting what data each accesses and its potential impact on the organisation’s risk profile.
- Assess risk from a stakeholder perspective – apply stronger controls where AI influences pricing, communications, compliance, or human resources.
- Scrutinise third-party providers – understand data storage, retention, model-training policies, security, and how the provider handles incidents.
- Define meaningful human oversight – specify who reviews outputs and when results must be rejected or escalated; review must involve genuine professional judgement.
- Build a culture of AI literacy – ensure directors and staff undergo training on confidentiality, bias, hallucinations, and verification, maintaining a healthy professional scepticism.
Resources:
- Browse our Director Governance insight articles
- Governing AI (Institute of Directors)
- AI in the boardroom: A guide for directors (Institute of Directors)
- Frontier AI cyber threat considerations for boards of directors (Australian Cyber Security Centre)
