A.I Policy

STATEMENT OF PURPOSE

This policy sets out the principles and expectations for the ethical, responsible, and effective use of Artificial Intelligence (AI) technologies across the business and its systems. It ensures AI is deployed in ways that uphold the company's core values, maintain the trust of our Directors, shareholders, customers, and suppliers, comply with all applicable laws and regulations, and supports innovation, operational excellence, and sustainable growth.

 

SCOPE

This policy applies to:

▪ All company employees, contractors, and third-party service providers

▪ All AI systems and tools used within the business, including generative AI, machine learning models,

recommendation engines, customer service bots, and analytics tools.

▪ All company-wide platforms, systems, and digital channels.

 

PRINCIPLES FOR AI USE

The company is committed to the following guiding principles:

▪ Transparency:

o Users must be informed when interacting with AI systems (e.g. virtual assistants, agents or

chatbots)

o AI-generated content or decisions affecting staff, stores or suppliers must be clearly explained.

 

▪ Accountability

o Human oversight must remain in all AI-related decisions that impact employment, pricing,

customer service, or critical business functions.

o Responsibility for AI outcomes lies with designated company personal, not the AI system.

▪ Privacy & Data Protection

o All AI tools must comply with the Privacy Act 2020(NZ) and the company's internal data governance

policies.

o AI must not be used to infer or process sensitive personal data without appropriate consent.

 

▪ Fairness & Non-Discrimination

o AI systems must be regularly reviewed to ensure they do not reinforce bias or lead to unfair

treatment.

o Training data for AI must be relevant, representative, and sourced responsibly.

 

▪ Security

o Only approved AI tools can be used within the business.

o AI tools must include appropriate security controls to protect company systems and data.

o Access to AI platforms must be restricted based on user roles and regularly reviewed.

 

USE OF AI TOOLS

To ensure responsible and secure use of AI tools within the company, the following rules apply:

▪ Only approved AI tools (i.e. Paid versions of Microsoft Copilot, ChatGPT Teams) may be used for work-related tasks,

including content creation, report writing, data analysis, meeting recording, transcription, or

summarisation.

 

▪ Staff must:

o Follow all privacy, security, and confidentiality requirements.

o Not enter confidential, personal, or sensitive information into AI tools unless explicitly authorised.

o Not rely solely on AI tools for legal, financial, or security-related decisions without expert

validation.

o Review and validate all AI-generated content before use, publication, or distribution.

 

▪ Meeting recordings:

o Recording meetings without notifying participants is strictly prohibited. This includes the use of

tools such as Read.AI, Otter.ai, Fireflies and Fathom.

o Meeting hosts must clearly inform all attendees when a meeting is being recorded and obtain

their consent.

▪ Misuse of AI tools will be considered a breach of policy and may result in disciplinary action.

 

ACCEPTABLE USE OF AI WITHIN THE COMPANY

Examples include:

• Customer support chatbots for frequently asked questions.

• AI-driven forecasting or trend analysis, with human review.

• Generative AI for internal content creation (e.g., marketing copy), with human review.

• Recording and transcribing meetings with participant consent.

 

PROHIBITED USE OF AI WITHIN THE COMPANY

AI must not be used to:

• Create misleading or deceptive content (e.g., fabricated testimonials, deepfakes).

• Transmit customer, supplier or company data to third-party AI services without proper authorisation.

• Make automated decisions with significant business or employment impact without human oversight.

 

APPROVAL & MONITORING

▪ All AI tools must be approved by a Director before deployment or use

▪ Usage and system outputs will be reviewed routinely to ensure compliance and performance.

▪ An internal AI Register will be maintained in the company's Software and Services Register to track all AI systems

in use across the company.

 

TRAINING & AWARENESS

All company staff using AI tools will be provided with:

▪ Training on ethical and effective use of AI.

▪ Guidance on interpreting AI outputs, crafting responsible prompts, and ensuring content accuracy.

 

INCIDENT REPORTING

Any suspected:

▪ AI misbehaviour or inaccuracies,

▪ Privacy breaches,

▪ Security incidents,

Must be reported immediately to a company director

 

REVIEW CYCLE

This policy will be reviewed annually internally or earlier if there are significant changes in AI technology, regulation, or company-wide business practices.