An employer reads something that worries them about AI at work. They do the sensible thing. They sit down, they list the tools their people are using, and they ask a chatbot what the policy should say about each one.
The answer comes back good. Structured, plausible, better than most templates sold for money. And in the course of getting it, they have pasted a list of their internal systems, the teams using them, and a few examples drawn from real employee situations into a service that may keep the input, may train on it, and almost certainly holds it outside New Zealand.
The act of solving the problem created another instance of the problem.
We could stop there and call it ironic, but the irony is only a symptom. Underneath it sits a category error, and the error is worth seeing in a sober light, because employers who make it will do a great deal of work that protects them from nothing.
Two different kinds of problem
There is a species of problem that is solved by knowing things. What the information privacy principles require. What a reasonable acceptable-use clause looks like. How AI notetakers commonly fail. These are information problems. They have answers, the answers are largely public, and a competent model will retrieve and assemble them well. We use AI for this daily, and we would not pretend otherwise.
There is a second species, though, that knowing does not touch. It is solved by someone being answerable. Who decided this. On what material. What was weighed, and what was set aside. Whether they could explain it, under questioning, to someone who was not in the room.
The two look alike from outside, because both produce documents. They are not alike. The first is retrieval. The second is a question about a person, and it cannot be handed to a system that has no standing to answer it.
Employers keep treating their AI exposure as the first kind of problem. What gets tested is the second.
What gets tested
Section 103A of the Employment Relations Act 2000 asks whether the employer’s actions, and how the employer acted, were what a fair and reasonable employer could have done in all the circumstances at the time. It then names the process factors the Authority must consider: whether the concern was sufficiently investigated, whether it was raised with the employee, whether they had a reasonable opportunity to respond, and whether their explanation was genuinely considered. Since 21 February 2026 there is a fifth — whether the employer was obstructed by the employee.
Read that list again with a chatbot in the room.
Sufficiently investigated. If the investigation summary came out of a notetaker and nobody checked it against what was said, what exactly was sufficient? The summary is a compression, performed by a system with no stake in accuracy and a documented habit of smoothing ambiguity into confident prose. That is not a reason never to use one. It is a reason someone must own the gap between the recording and the summary, and be able to say what they did about it.
Genuinely considered. This is the one that should worry employers most. Genuine consideration is a state of mind, and it leaves traces — questions asked, positions changed, material weighed and rejected for stated reasons. A decision-maker who receives a well-drafted recommendation and signs it produces the same artefact as one who interrogated it. The documents are indistinguishable. The people are not, and cross-examination exists to find the difference.
Then there is s 4. Where an employer proposes a decision likely to adversely affect an employee’s continued employment, good faith requires giving that employee access to information relevant to the continuation of their employment, and a real opportunity to comment on it before the decision is made.
The full Court construed that obligation in Vice-Chancellor of Massey University v Wrigley and Kelly. Two things it held bear directly on this. The duty is not confined to restructuring — the Court said at the outset that the principles apply equally wherever employment is at risk, serious disciplinary cases included. And relevant information is not limited to what has been written down. It includes what is held only in people’s minds, because otherwise an employer could defeat the purpose of the provision by the simple expedient of not recording things. Information that was never recorded may be harder to retrieve and less certain once retrieved. Neither bears on whether it is relevant.
A note on currency, because it matters. Parliament narrowed part of that decision: s 4(1B) and (1C) were replaced in 2015, expressly to limit it, so that an employer need not hand over confidential information about another identifiable individual where doing so would unwarrantedly disclose their affairs. What Parliament did not touch was the construction of “relevant” in s 4(1A)(c). The gate was moved. What falls inside the fence was left where the Court put it.
Which is the practical bite. Material generated by an AI tool and relied on in forming a proposal is relevant information about the decision, and the fact that nobody saved it does not make it less so. On Wrigley’s reasoning that is precisely the argument the provision exists to defeat. An employer who ran part of the reasoning through a chat window it did not keep has relied on something it cannot produce, cannot summarise, and cannot invite comment on. The carve-outs are no help here: a carve-out is a reason to withhold something you have. It is not a cure for not having it.
We should be even-handed about the consequences. Section 103A(5), replaced in February 2026, now says the Authority must not find a dismissal unjustifiable solely because of process defects where those defects did not result in the employee being treated unfairly. The old threshold, which also required the defects to be minor, is gone. That is a real shelter, and it is wider than it used to be. But it protects defects that made no difference, and an employer who cannot say what informed the decision is in no position to argue that a gap made no difference. They cannot establish what was in the gap.
The Privacy Act 2020 adds its own version. An employee is entitled to access personal information held about them, and since 1 May 2026 a further notification obligation, IPP 3A, covers personal information collected other than from the individual concerned. An employer who does not know what went into which tool cannot answer an access request honestly. Not because they are concealing anything, but because they do not know. “We cannot tell you what we hold about you” is a poor sentence in any forum.
The half that will not delegate
Three things are missing from every AI-generated answer, and no improvement in the models supplies them.
The first is standing. An output is unsigned. No one can be asked to explain it, no one’s reputation is attached to it, and no one can be called. The Authority does not receive analysis. It receives evidence, from people. A document whose author cannot be examined has a hole where its authority should be.
The second is the particular workplace. A model can describe good practice. It cannot know that your operations manager runs disciplinary meetings hot, that your last three grievances all turned on inadequate notice, or that your process, under pressure, tacitly skips the response stage. That knowledge is local, it is where the risk actually lives, and it is not in the training data.
The third is the capacity to be wrong in a way that costs something. Accountability is not a document. It is an arrangement in which a person carries the consequence of a bad decision. That is the whole mechanism, and it is the one thing a tool cannot take part in. You can automate the drafting of a decision. You cannot automate being the person who made it.
The honest position
None of this argues for keeping AI out of the workplace, and we would not make that argument. It argues for knowing which half of the work is being handed over.
The information half can go freely. Let it draft, summarise, structure, and propose. Then treat what comes back the way you would treat a memo from a capable junior colleague who has never met the people involved: useful, probably right in outline, and not something to put your name to until it has been tested against what you know and they do not.
The rest is unglamorous. Know which tools are in use, including the ones nobody approved. Know what goes into them, and where that lands. Know which employment decisions they touch. And know, for each of those, the name of the person who owns the output before it reaches an employee — not as a formality, but because when the question is finally asked, a name is what the answer requires.
Most employers cannot produce that list today. Better to find that out now, while it is still a question you are asking yourself.
Technology evolves. Governance must keep pace.
- Employment Relations Act 2000, s 103A (test of justification), as amended by the Employment Relations Amendment Act 2026 (2026 No 4), s 19 — legislation.govt.nz
- Employment Relations Act 2000, s 4 (good faith), in particular s 4(1A)(c) and the confidentiality provisions in s 4(1B)–(1C) — legislation.govt.nz
- Vice-Chancellor of Massey University v Wrigley and Kelly [2011] NZEmpC 37, judgment of the full Court, 18 April 2011, at [2] and [62]–[63] — employmentcourt.govt.nz
- Commerce Commission v Fonterra Co-operative Group Ltd [2007] NZSC 36, [2007] 3 NZLR 767 at [22], and Air Nelson Ltd v New Zealand Amalgamated Engineering, Printing and Manufacturing Union Inc [2010] NZSC 53, [2010] 3 NZLR 433 at [19] — the Supreme Court authority applied by the full Court in Wrigley.
- Privacy Act 2020, and the information privacy principles including IPP 3A in force from 1 May 2026 — privacy.org.nz
This article provides general information and commentary. It is not legal advice.