Why NZ Businesses Are Adopting AI Before They're Ready | NSP

NSP Marketing

16 August 2026

11 min

Read

Why Most NZ Businesses Are Adopting AI Before They're Ready For It

 

Eighty-three percent of New Zealand SMEs are already using AI in some capacity. Only thirteen percent have an AI policy in place.

That gap - published by the Employers and Manufacturers Association in July 2026, from a survey of more than 300 NZ member businesses - is the clearest single statistic in the NZ AI landscape right now. It tells you that AI adoption in New Zealand has moved well past the experimentation phase. And it tells you that governance has not kept pace.

This isn't a criticism of the businesses involved. It's a reflection of how AI arrived: quickly, cheaply, and through individual decisions rather than organisational ones. Staff found tools that made their work faster. They started using them. The tools spread. By the time leadership had a conversation about AI policy, AI was already embedded in how the business operated - just without any framework governing how.

Microsoft's 2026 workplace data found that 81% of NZ AI users are bringing their own AI tools to work - the shadow AI pattern we've documented across legal, accounting, healthcare, construction, real estate, and education. The tools are already in the building. Most businesses simply don't know where.

KPMG's NZ findings show why readiness still feels fragile even while adoption rises: only 36% of NZ workers believe they have the skills to use AI tools appropriately, and only 23% believe current safeguards are sufficient to make AI use safe.

Three-quarters of the workforce using AI. Less than a quarter confident the guardrails exist to make it safe.

That's the readiness problem. And it has specific, practical consequences for NZ businesses that are worth understanding clearly.

 

What "Ready" Actually Means

AI readiness isn't a technology question. It's an organisational question.

A business can have access to Microsoft Copilot, ChatGPT, and every other AI tool available in the market - and still not be ready to use them in a way that's safe, consistent, and genuinely valuable. Readiness isn't about having the tools. It's about having the conditions that make using the tools well possible.

Those conditions are:

Governance - Decisions - made deliberately, by the right people - about which AI tools are approved, what data they can access, what human oversight applies to AI outputs, and how new tools get assessed before they're used with client or sensitive information.

Data foundations - AI works with the data in your environment. If that data is poorly organised, inconsistently classified, over-shared, or sitting in systems that haven't been reviewed in years, AI will surface and act on information in ways that create risk rather than value.

Staff capability - Knowing which tools are available is not the same as knowing how to use them well. AI literacy - understanding what AI does reliably, where it makes mistakes, and how to check outputs before relying on them - is what separates a productive AI user from a liability risk.

Security posture - AI tools expand the attack surface of your environment. Shadow AI - tools adopted without IT visibility - creates data governance gaps that attackers find and exploit. The security layer that protects your business needs to account for AI, not just pre-AI threat patterns.

A structured programme - The businesses that get the most value from AI aren't the ones that adopted the most tools. They're the ones that approached adoption systematically - understanding the current state, building the foundations, then expanding capability deliberately.

New Zealand ranks 37th on the Government AI Readiness Index as of the May 2026 AI Blueprint, with national targets of top 30 and top 25 by 2030. At the business level, the picture is similar: adoption is ahead of readiness, and the gap between them is where risk accumulates.

 

The Three Ways Unready AI Adoption Creates Problems

Understanding the specific failure modes matters - because most NZ businesses in the gap between adoption and readiness aren't experiencing dramatic AI failures. They're experiencing quiet ones that compound over time.

1. Data Goes Where It Shouldn't

When staff use AI tools without governance, they make individual decisions about what information to put into those tools. Those decisions are usually reasonable in isolation. A lawyer summarising a contract. An accountant asking for help with a tax memo. A project manager drafting a client report. Each one is individually sensible.

Collectively, they represent client financial data, legal advice, commercially sensitive project information, and personal details about individuals flowing into AI systems operating under terms the business has never reviewed - and into training datasets the business has no visibility into.

81% of NZ AI users are bringing their own AI tools to work. For most NZ businesses, that means a significant proportion of AI activity is happening outside any governed environment - not because staff are being careless, but because no governed environment exists for them to work within.

The Privacy Act 2020 creates specific obligations around how personal information is handled. Those obligations apply regardless of whether the information was processed by a person or an AI tool. A business that doesn't know what AI tools its staff are using doesn't know what personal information has left its controlled environment - and that's not a position of compliance.

2. AI Outputs Are Relied On Without Appropriate Review

AI tools are confident even when they're wrong. This is a documented characteristic of large language models - they produce plausible, well-structured, authoritative-sounding output regardless of whether that output is accurate.

In low-stakes contexts, an AI error is an embarrassment. In a tax advice context, an AI hallucination about the bright-line rules is a professional liability claim. In a client communication context, an AI-generated error that goes undetected is a client relationship problem. In a legal context, an AI-generated clause that misrepresents the agreed position is a commercial dispute.

Only 36% of NZ workers believe they have the skills to use AI tools appropriately. The gap between that figure and the 83% already using AI represents a significant cohort of staff using tools they're not confident they understand - and making decisions about when to trust AI outputs without a clear organisational standard for when human review is required.

The standard isn't that AI can't be used for consequential work. It's that AI-generated output in a consequential context requires review by a person with the expertise to catch what AI gets wrong. That review step is what most businesses haven't systematised.

3. Security Posture Doesn't Account for AI

Every AI tool added to a business environment - whether formally adopted or brought in by staff without IT oversight - is a new connection, a new data flow, and a new potential entry point.

Shadow AI creates attack surface that IT doesn't know exists and therefore can't monitor or protect. A free AI tool connected to a staff member's Microsoft 365 account has OAuth permissions to access email, files, and calendar. When that tool is compromised, or when its terms change, that access extends to your business environment. And because IT doesn't know the tool exists, nothing is watching for it.

Only 23% of NZ workers believe current safeguards are sufficient to make AI use safe. That figure reflects a general population assessment, but it maps to what NSP sees in NZ business environments: security controls that were built for a pre-AI threat model, not extended to account for how AI has changed the attack surface.

The businesses that are genuinely ready for AI have addressed this by ensuring their security posture accounts for AI - their monitoring covers shadow AI exposure, their identity and access management controls what AI tools can access through staff accounts, and their governance framework means new AI tools are reviewed before they're adopted rather than discovered after.

 

What the Readiness Gap Looks Like in Practice

To make this concrete, here's what the gap between AI adoption and AI readiness typically looks like in a NZ SME:

What's happening: Staff across the business are using AI tools - ChatGPT for drafting, Copilot features embedded in Microsoft 365 that were activated through a recent update, AI-assisted tools in practice management software, AI transcription tools added to Teams, free AI tools that connected to work email accounts months ago.

What leadership knows about it: Some of it. Probably the tools that were formally adopted. Not the ones staff found independently. Not the features that were enabled through software updates. Not the full picture of what data has been processed through which systems.

What governance exists: In 83% of NZ SMEs, no formal AI policy. In most of the remaining 17%, a policy that hasn't been communicated broadly or reviewed since it was written. Very rarely: a policy that covers the specific tools and workflows in active use, with staff training that reflects current practice.

What security posture covers: Pre-AI threat patterns. Email security, endpoint protection, identity management - but typically not shadow AI monitoring, not AI tool access review, not the specific attack surface that AI adoption has created.

What the business thinks its exposure is: Lower than it is. The confidence-readiness gap is exactly what Datacom's 2026 research documented at the national level - most leaders believe they're more prepared than they are, because they don't yet have visibility into the full picture of AI activity in their environment.

 

The Businesses Getting This Right

The NZ businesses using AI most effectively in 2026 share a pattern that's worth understanding - because it's not about which tools they've adopted, it's about how they approached adoption.

They started by understanding the current state. Before building policy or deploying new tools, they found out what AI was already in use across their environment - which tools, by which staff, with what data, under which terms. That visibility exercise almost always surfaced more than leadership expected.

They built the foundations before expanding capability. Data governance - knowing where sensitive information lives and ensuring it's appropriately controlled before AI tools interact with it. Identity and access management - ensuring AI tools can only access the data they genuinely need, and that staff accounts are protected against the credential-based attacks that AI adoption has made more complex. A governance framework - not a lengthy policy document, but clear, practical decisions about which tools are approved, what oversight applies, and how new tools get reviewed.

They treated AI adoption as a programme, not a project. A one-time policy launch doesn't address an ongoing adoption pattern. The businesses that are genuinely ready have a rhythm - regular reviews of what's in use, updates to the approved tool list as tools evolve, ongoing staff training that reflects actual practice rather than generic AI literacy.

The AI Forum NZ found 91% of businesses report efficiency improvements from AI, 77% report lower operating costs, and 50% report positive financial impacts. Those outcomes are real. They're also more reliably achieved by businesses that pair adoption with governance - because ungoverned AI adoption creates costs and risks that erode the efficiency gains over time.

 

Where the NSP Secure AI Accelerator Fits

NSP's Secure AI Accelerator is a programme designed specifically for NZ businesses navigating the gap between adoption and readiness. It's not a technology deployment or a policy-writing exercise. It's a structured programme that moves a business from wherever it currently sits to a genuinely mature AI operating position - with documented evidence of that maturity that its board, its insurer, and its clients can see and rely on.

The programme works across three integrated pillars:

Enable - building the AI capability and workflows that let your team use AI effectively. Approved tools, training, Microsoft Copilot configuration, practical AI workflows designed for how your business actually operates.

Secure - ensuring the security layer accounts for AI. Shadow AI visibility, identity and access management that covers AI tool access, security monitoring that extends to the attack surface AI has created, and the governance framework that keeps it current.

Assure - producing the documented evidence of AI governance maturity. The AI policy, the training records, the approved tool list, the security posture documentation that matters at cyber insurance renewal, in client due diligence conversations, and at board level.

 

Frequently Asked Questions About AI Readiness for NZ Businesses

What does AI readiness actually mean for a small NZ business?

AI readiness means having the conditions in place to use AI safely and consistently - not just access to tools. That includes knowing what AI tools are in use across your business, having governance decisions made about how they can be used, ensuring staff know what oversight is required before acting on AI outputs, and having a security posture that accounts for AI. A business with access to every AI tool available but no governance around any of them is not AI-ready - it's AI-exposed.

How do I know if my business is AI-ready?

The quickest diagnostic is the policy question: do you have a documented AI policy that your staff have been trained on? If not, there's a governance gap. Beyond that: do you know what AI tools your staff are currently using, including tools they've found independently? Do you know what business or client data has been processed through those tools? Have your IT and security controls been updated to account for AI? If more than one of these is "no" or "I'm not sure," a formal AI readiness assessment is the most direct next step.

Is 83% of NZ SMEs using AI accurate - our business hasn't formally adopted any AI tools?

It's possible your business has more AI activity than you're aware of. The EMA's July 2026 survey of 300+ NZ businesses found 83% already using AI, but much of that use is informal and staff-initiated rather than formally adopted. AI features embedded in Microsoft 365, AI tools brought in by individual staff members, AI-assisted tools in practice management or accounting software - all of these count as AI use without requiring a formal adoption decision. The most common finding when NZ businesses do a proper inventory is that AI is more present than leadership knew.

What's the risk of not having an AI policy?

The practical risks are: client or sensitive data being processed through AI tools under incompatible data handling terms; AI-generated errors being relied upon without appropriate review; Privacy Act obligations being inadvertently breached; cyber insurance underwriters asking about AI governance at renewal and finding gaps; and competitive disadvantage relative to businesses that are using AI more effectively because they've built the governance that makes consistent, confident use possible.

What's the difference between an AI policy and AI governance?

An AI policy is a document. AI governance is the broader system that makes AI use safe and consistent - the policy, plus the approved tool list, plus the staff training, plus the security controls, plus the oversight processes, plus the regular review rhythm that keeps everything current. Most NZ businesses that have addressed AI governance have a policy. Far fewer have the full governance system. The policy is the starting point, not the destination.

How long does it take to go from current state to genuinely AI-ready?

Moving from informal AI usage to embedded capability typically takes around six months: a baseline assessment, ground rules and measurement in the first month, process redesign and training over months two to four, and a review rhythm from there. NSP's Secure AI Accelerator operates over 12 months - because genuine maturity, with documented evidence of governance and the board-ready reporting that comes with it, takes longer than the initial governance foundations. The first three months produce the most visible change; the full 12 months produce the evidenced, sustainable operating position.

 

Is Your Business Ready?

Most NZ businesses find out they weren't when something goes wrong - a data governance question from a client, an AI error that reaches a customer, a cyber insurance renewal that asks about AI policy, or a shadow AI tool that turns out to have been processing sensitive data for months.

The better position is understanding where you stand before that moment. NSP's AI Secure AI Accelerator

Book your Secure AI Accelerator Programme →

Or call us directly: 0508 010 101

 

Related Reading

Let’s stay in touch!

Enter your details below to stay up-to-date with the latest IT solutions and security measures.