AI governance for infrastructure asset management
If you’re using (or procuring) AI for renewals prioritisation, predictive maintenance, demand forecasting, or automated inspections, you’re no longer just “doing analytics”. You’re making governance choices that affect public trust, service equity, and Te Tiriti obligations.
Three recent research contributions help translate “responsible AI” into practical operating models—and they map cleanly onto NZ’s existing expectations and settings.
Layered governance and lifecycle checkpoints
Joshi et al. (2025) highlight that GenAI governance must be layered (strategic, tactical, operational) and embedded across the full lifecycle—from ideation and data preparation through to deployment, monitoring, and retirement. They emphasise risk-based governance, continuous monitoring, cross-functional councils, and explicit management of vendor/third‑party and shadow AI risks. They also point to operational tools like sandboxing, TEVV (testing/evaluation/verification/validation), and practical playbooks (their “Principles in Action” and ResAI guide) to make governance executable rather than aspirational.
Bias, fairness, and “guardrails in production” as governance, not an afterthought
Abhishek et al. (2025) focus on data + AI governance for LLMs with a lifecycle approach: evaluate bias pre‑deployment, then apply real-time monitoring and guardrails in production. They report (via their BEATS framework) that 37.65% of outputs they assessed from leading LLMs contained some form of bias, with 33.7% rated as medium/high severity or impact—reinforcing the need for governance to include measurable evaluation and ongoing controls, not one-off assurance.
A process map for GenAI governance you can audit against
Luna et al. (2024) present a harmonised framework (H‑GenAIGF) that breaks GenAI governance into four constituents (data, model, content generation, ethics) with defined processes and sub-processes, mapped to principles such as transparency, auditability, privacy, fairness, and accountability. Their cross-regional comparison highlights inconsistent global coverage—useful for NZ organisations that need to evidence “we’ve covered the basics” even when regulation is evolving.
How this lands in the New Zealand governance reality
NZ already has strong “building blocks” for AI governance—especially for public agencies and local government:
Algorithm Charter for Aotearoa New Zealand (transparency, partnership, people focus, data fit-for-purpose and bias management, privacy/ethics/human rights, and human oversight) plus the Algorithm Impact Assessment (AIA) user guide as an implementation tool.
Privacy Act 2020 (information privacy principles governing collection, use, transparency, access/correction, etc.).
Public Service Act 2020 principles (including open government and stewardship), which shape expectations for explainability and accountability in public decision-making.
For councils: LGOIMA means models, inputs, and decision pathways can become subject to official information requests—so documentation and explainability are not optional extras.
Te Tiriti-aligned data governance expectations are increasingly explicit through Māori data sovereignty and governance thought leadership (e.g., Te Mana Raraunga principles and public-service-oriented Māori Data Governance models).
Central guidance is also maturing via the Government Chief Digital Officer’s AI guidance and public service AI framework ecosystem (2025).
What “good” can look like for NZ infrastructure asset managers
A practical governance pattern to adopt now
Treat AI use cases like regulated decisions: create an AI register, classify impact, define human accountability, and document decision pathways (especially for capital prioritisation and service level trade-offs).
Embed lifecycle assurance: align Joshi et al.’s lifecycle stages (ideation → retirement) with NZ’s AIA expectations—so risk assessment isn’t a one-time gate, but a living control set.
Measure bias and service equity explicitly: adopt Abhishek et al.’s mindset—pre‑deployment evaluation plus production guardrails—so sparse data (often rural/remote communities) doesn’t become “invisible demand.”
Procurement-ready governance: require vendor transparency on training data provenance, model limitations, monitoring hooks, audit logs, and incident response—because vendor opacity is a governance risk, not just a technical inconvenience.
Te Tiriti by design: treat partnership, engagement, and Māori data governance as design inputs (not consultation after the model is built), consistent with the Charter’s intent.
Credits and references
Joshi, H., Hassani, S., Gandhi, D., & Hartman, L. Approaches to Responsible Governance of GenAI in Organizations (IEEE ISTAS 2025 accepted; Vector Institute). Project: https://res-ai.ca/
Abhishek, A., Erickson, L., & Bandopadhyay, T. (2025). Data and AI governance: Promoting equity, ethics, and fairness in large language models (MIT Science Policy Review).
Luna, J., Tan, we., Xie, X., & Jiang, L. (2024). Navigating Governance Paradigms: A Cross-Regional Comparative Study of Generative AI Governance Processes & Principles (AIES 2024 accepted).
NZ public-sector anchors: Algorithm Charter + AIA guide; Privacy Act 2020, New Zealand Legislation; Public Service Act 2020; LGOIMA, New Zealand Legislation; Māori Data Sovereignty principles; Māori Data Governance model resourceskahuiraraunga.io; GCDO AI guidance (2025).
For asset managers in New Zealand, the practical question is no longer whether to adopt AI, but how far along the assurance chain the organisation has moved: pilot experimentation, operational deployment, or AI-informed capital governance. The weakest link in that chain is where governance work should start.
BLETCHLEY LABS