It is a peculiar phase in the lifecycle of new technology when organisations begin writing rules for something they do not yet fully understand. AI is one such example.
Employers are being told they need AI strategies, AI policies, AI governance frameworks, responsible-use principles, registers, committees, training programmes, and increasingly elaborate statements about what artificial intelligence may or may not do. Some of that will eventually be necessary. But a more basic question comes first, and most organisations are stepping straight past it.
What is actually happening inside your organisation now?
It is surprisingly difficult to govern something when you do not know where it is being used.
AI adoption rarely waits for the policy
The conventional picture of workplace AI adoption is orderly. Management selects a tool. Risks are assessed. Rules are written. Employees are trained. The technology is deployed.
Reality is messier, and quieter. Someone in HR pastes the bones of a disciplinary letter into an AI assistant to sharpen the wording. A manager asks the same tool to summarise three months of performance notes before a difficult conversation. A recruiter uses a screening feature that came bundled with software the organisation already pays for, and never thinks of it as “using AI” at all. An employee, frustrated with a clause in their agreement, drops the paragraph into a public chatbot to see how it might be rewritten. In a meeting nobody flagged as sensitive, the transcription tool hums away in the background, generating a summary that will be forwarded, saved, and quietly relied upon.
None of this requires an organisation-wide AI project. It requires a browser and a few spare minutes.
By the time an employer decides it needs an AI policy, the technology is already woven through ordinary work. That changes the problem. The first task is not to decide what AI should look like in three years. It is to find out what it looks like on Tuesday morning.
A policy cannot govern an unknown system
There is nothing inherently wrong with beginning with an AI policy. A good one can establish real boundaries around approved tools, confidentiality, privacy, intellectual property, human oversight, and employment decisions. But a policy written without any understanding of existing practice risks becoming governance by assumption.
Suppose the policy states that confidential employee information must not be entered into unapproved AI systems. Reasonable enough. But which systems are staff already using, and which of those are approved? Has anyone checked whether managers have already fed employee information into them? What AI functionality sits buried inside the software the organisation licenses today, unnoticed because nobody thinks of it as AI? And what happens when the output of one of those systems finds its way into a decision about recruitment, performance, discipline, restructuring, or dismissal?
The policy may tell people what should happen from tomorrow. It tells you very little about the risk that already exists today.
Many employers are starting a step too far down the road.
Before strategy comes visibility. Before policy comes understanding. Before governance comes a baseline.
The employment relationship makes this different
There is a temptation to treat workplace AI governance as another information-technology problem. It isn’t. The moment AI begins influencing decisions about people, familiar employment-law obligations walk into the room.
An employer may ultimately have to explain why a decision was made. That explanation becomes considerably harder when part of the reasoning came from a system nobody recorded using, nobody independently checked, and nobody can now reconstruct.
Picture a manager wrestling with a performance problem that has dragged on for months. One evening they gather up everything they have, supervision notes, a run of emails, a couple of file memos, and paste the lot into an AI system with a simple instruction: find the pattern. The summary that comes back is clear, confident, and unsettlingly persuasive. Some of its conclusions the manager adopts outright. Others do quieter work, colouring how the manager now reads the employee, hardening a picture that was still forming. Six weeks later, the employment relationship is over.
By the time it ends, the useful summary is no longer the point. The question that matters is this: what part did the machine play in the decision? Who checked its work? What was fed into it, and was any of it accurate? Did the employee ever get a fair chance to answer the substance of the concerns, or only the version the system had already shaped? Could the manager, honestly, separate their own reasoning from the analysis handed to them on a screen? And if the whole thing were questioned a year later in mediation or the Authority, could the employer reconstruct how the decision was actually made?
Those are not futuristic questions. They are ordinary questions of process, evidence, accountability, and judgement. AI simply makes them harder to answer when nobody has designed the system around answering them.
Start with the employment lifecycle
A useful AI baseline should therefore look beyond whether an organisation has purchased an AI product. It should ask where AI is already touching the employment relationship. For most employers, that means looking across areas such as:
Recruitment and selection. Is AI drafting advertisements, screening applications, comparing candidates, summarising interviews, or influencing who gets shortlisted?
Performance management. Are managers using AI to analyse records, draft feedback, identify patterns, or assess performance information?
Disciplinary processes. Is AI being used to frame allegations, analyse explanations, prepare correspondence, or assist with decisions?
Workplace investigations. Are transcripts, witness material, credibility questions, or documentary evidence being processed through AI systems?
Monitoring and surveillance. Are automated systems assessing productivity, behaviour, communications, attendance, or other employee activity?
Employment documentation. Are agreements, policies, letters, restructuring documents, or other employment materials being generated or substantially reworked using AI?
Personal grievances and disputes. Is AI being used to analyse claims, prepare responses, assess evidence, or develop settlement positions?
Restructuring and redundancy. Is AI shaping selection criteria, role comparisons, the business case, consultation material, or the decision itself?
Not every use carries the same risk. That is precisely the point. The employer needs to know which uses are mundane productivity tools and which are beginning to influence decisions capable of materially affecting someone’s employment.
Governance should follow risk
Once the baseline exists, the next steps become much easier.
An organisation using AI mainly for low-risk administrative tasks does not need an elaborate governance apparatus. It needs clear rules, approved tools, sensible privacy and confidentiality controls, some training, and defined boundaries around employment decisions.
Another organisation opens the same drawer and finds something more serious. Managers already leaning on AI to weigh up employee performance. Recruitment software with automated screening features nobody has examined closely. Sensitive personal information moving through systems that were never assessed for it. AI-generated text sliding into disciplinary and investigation files without ever being labelled as such.
Those findings justify a different response. The governance should follow the actual risk, which is a good deal wiser than beginning with a generic policy and hoping reality fits inside it.
The missing question: who owns the judgement?
There is another reason to establish a baseline.
AI governance discussions tend to concentrate on the technology. Which model? Which provider? Where is the data stored? What security controls are in place? Those questions matter. But in employment practice another question matters more, and it rarely gets asked: who owns the judgement?
If AI assists with an employment decision, there must still be an identifiable human being who understands the evidence, tests the output, makes the decision, and can explain why. “AI recommended it” is not reasoning. Neither is “the system identified a pattern.” The practitioner, manager, investigator, or decision-maker has to remain capable of standing behind the conclusion.
That takes more than dropping the words human oversight into a policy. It takes an operating practice in which human responsibility is visible.
From baseline to governance
This is the thinking behind the Lex Praxis AI Governance Foundation. It deliberately begins before the policy.
The first tier is the AI Risk Baseline, a structured review of AI use and exposure across eight domains of the employment lifecycle. Its purpose is not to produce an impressive AI maturity score. It is to establish what is actually happening, where the meaningful risks sit, and what needs attention.
For organisations without serious exposures, the next step is straightforward: set the rules. The AI Governance Policy Framework then draws practical boundaries around approved tools, AI-assisted employment decisions, confidentiality and privacy, intellectual property, responsibility, and review.
Where the Baseline surfaces something more serious, the answer is not to bury it inside a general policy and hope it holds. It is to look properly, which is the point at which a full AI Employment Risk Audit becomes the right instrument.
The sequence is deliberate. Understand what is actually happening, set the rules that fit it, and investigate more deeply only where the facts demand it.
The point is not to slow AI down
Good governance is often presented as the thing standing between an organisation and innovation. I think that gets the relationship backwards.
Employers use AI more confidently when they know the boundaries. Managers experiment more sensibly when they understand where experimentation has to stop. And organisations are far better placed to benefit from these tools when they can tell useful assistance apart from decisions that demand considerably greater care.
The objective is not an AI-free workplace. Nor is it a workplace where every brush with an AI system triggers a committee meeting.
It is something much quieter than that. It is knowing where the technology has taken root in the organisation, which of those uses genuinely bear on decisions about people, and who stays answerable when one of those decisions is made. It is making sure that when an employment decision is questioned later, and sooner or later one will be, a real person can still sit across the table and explain, in plain terms, how the decision was reached and why.
That is not an AI strategy. It is the foundation that should come before one.
Lex Praxis advises New Zealand employers on employment law and AI governance. This article is general commentary and does not constitute legal advice. For advice specific to your circumstances, contact us directly.