First Published: 09 October, 2026
Even someone who, like me, is a self-confessed passionate supporter of self-regulation has to seriously question the lack of positive action from the bureaucratic advisors to the New Zealand Government.
The regulators are getting nervous
The Human Rights Commission has called for deliberate, accountable, and equitable governance for the use of artificial intelligence. In its report to government dated 7 August 2026, it calls for a human rights-centred approach to AI and digital technologies.
The Privacy Commissioner doesn't go quite as far to prod the government into action but in his August 2026 newsletter he says “we are nervous about AI. “New Zealanders have earned a reputation around the globe for having a “she'll be right” attitude. We say that when we're confident, but also when we're nervous. And we are nervous about AI.
And the technology giants are losing control of their own creations
We have every right to be nervous if recent reports from Stuff journalist Finn Hogan are on the mark. He writes, “It's what science fiction has warned us about for decades, but sadly, it's actually here now: multiple powerful AI models are going rogue in ways which baffle their human minders.
Two separate frontier AI labs, OpenAI and Anthropic (makers, respectively, of ChatGPT and Claude), have admitted their models either broke out of containment or hacked into external servers unprompted. In OpenAI's case, it's believed to be the first time an AI agent conducted an autonomous cyber-attack.”
But the reason for alarm is that as AIs are given more ability to act in the world, they are also acting in increasingly unpredictable and potentially harmful ways.
And now we have OpenAI, one of the most powerful companies on Earth, breaching a government website to access non-public Medicare statistics. The Guardian reports, “Its AI agents were let loose with a pretty mundane task: to gather information on public health systems around the world. When those agents couldn’t immediately get what they wanted from public websites in Australia, they did not stop. They broke in, hacking into a secure database to get the information they were told to find. To be clear: hacking is unlawful. Human hackers face serious consequences, and so must AI companies.”
Compounding its illegal actions, OpenAI then took far too long to notify the federal government of this breach.
“There is this whole code of ethics and morals and social norms that these AI tools haven't been given,” says Auckland University honorary Research Fellow Andrew Chen. “We actually need to give it more of these constraints to help it understand what our expectations are.”
So, whilst our major concerns might be about AI users like you and me - marketers, technologists, analysts, industrialists, et al. We might need to be even more concerned about the technology giants’ apparent lack of control over their own brainchild.
New Zealand's light touch
The New Zealand Government has taken a light-touch, proportionate, and risk-based approach to artificial intelligence regulation, preferring to use existing laws instead of creating a standalone AI Act.
To quote...' NZ is following the OECD principles, which recommend that governments should promote an 'agile policy environment that supports transitioning from the research and development stage to the deployment and operation stage for trustworthy AI systems. Governments should review and adapt, as appropriate, their policy and regulatory frameworks and assessment mechanisms as they apply to AI systems to encourage innovation and competition for trustworthy AI.'
(Words, words, words, words!! and note Trustworthy is mentioned twice in their document)
Trustworthy systems? Haven't we just read that even OpenAI and Anthropic aren't to be trusted...not because they're dishonest, but because they might have given their systems too much freedom. It's been said many times that AI might communicate like a human, but it relies on math and computer code instead of real-life physical experiences, feelings, and self-awareness.
Europe took the opposite road
The EU, on the other hand, has taken an entirely different approach. The EU AI Act's Article 5 bans eight AI practices outright.
And ... because of the European AI legislation ... big-tech AI companies will now have to 'watermark' AI-generated or edited content so that your audience can identify that you've used it. AI watermarking is the process of hiding a subtle, machine-readable signal or pattern inside AI-generated content, such as text, images, audio, or video. It is completely invisible to humans, but specialised detection software can spot the mark to identify that the content was made or processed by an AI model.
It doesn't matter that you aren't doing business in Europe either, because the major generative AI models like Anthropic and OpenAI have advised their users worldwide that their output is being watermarked as AI-generated.
So why does New Zealand take the soft option?
If Europe is confident enough to believe it can legislate to govern the use of AI, why does the NZ government take the soft option?
Well, maybe they're not wrong!
Maybe they're not just too timid to introduce further restrictive legislation. To quote the website of Science.com “the soft option balances the mitigation of public harm with the preservation of technological innovation.” AI is a rapidly evolving global technology, so traditional static legal frameworks struggle to govern it effectively without becoming overly restrictive.
Legislation is, by its very nature, precise, restrictive, costly, and cumbersome. Strict rules can stifle business innovation and impose heavy administrative costs on smaller companies. Laws take a long time to pass and cannot easily change to match fast-moving industries or new technologies. And then there's the spectra of 'unintended consequences', those unforeseen or unexpected outcomes that happen all too often and are contrary to the original goals of the legislation.
Self-regulation on the other hand, allows businesses and industries to set their own operational and ethical standards. It allows industries to update rules in real time to match fast-moving technology or evolving social standards. Businesses tend to respond better to self-regulation because it offers speed, flexibility, and expertise that rigid government legislation cannot easily match.
So, the New Zealand Marketing Association is taking Action!
AI is in widespread use in the world of marketing communications and in New Zealand, the Marketing Association has decided not to wait for legislation and is launching a new Code of Practice for Marketing Communications, which includes a complete section on responsible use of AI.
The code includes a requirement that marketers remain personally responsible for marketing communications and consumer-facing outcomes produced, informed or delivered using AI. The code also commits marketers ensure that marketing communications created or materially altered using AI should meet the same standards of truthfulness, accuracy and substantiation as any other marketing communication.
Cultural or ethnic sensitivities will also require marketers to use extra care to ensure that its use is respectful, transparent and culturally appropriate when using AI to assist in marketing to audiences of different ethnicity, national origin or culture.
Marketers will be committed to regular reviews of AI-assisted communications to ensure that they continue to operate as intended and remain accurate, fair, lawful and consistent with best practice.
The code works on the principle that responsible organisations don't need more laws to make them honest – they just need education and guidance. Irresponsible and dishonest bad actors ignore the law anyway!
Author: Keith Norris, Compliance Consultant at NZ Marketing Association, 9th October 2026
Note: Keith acts as compliance advisor to the NZ Marketing Association. On 20 Oct 2026, the MA released a Code of Practice for Marketing Communications, which includes a complete section on responsible use of AI.
This is an edited version of a guest blog written for Data Insight Ltd https://www.datainsight.co.nz/
Category
Contact us if you have any suggestions on resources you would like to see more of, or if you have something you think would benefit our members.
Get in TouchSign up to receive updates on events, training and more from the MA.