BletchleyLabz owl emblem BLETCHLEY LABS
← All Lab Notes

Governing autonomy at the asset face: a New Zealand perspective on agentic AI in government and highly regulated asset management

Agentic AIAI GovernanceAsset ManagementCritical InfrastructureNew Zealand

Conference paper, 2026.

Abstract

Agentic AI—systems that plan, decide, and act on behalf of humans rather than merely generating content—is arriving in the asset-intensive sectors that keep a country running: water, electricity, transport, defence. For New Zealand, where public infrastructure is managed by councils, council-controlled organisations, and Crown agencies under a deliberately light-touch regulatory regime, the governance question is sharp. How do you let an agent act on a water network when the foundations for safe autonomy—trustworthy data, retained expertise, mature oversight—are, by the profession’s own admission, largely absent? This paper synthesises industry research from Australia and New Zealand and the United Kingdom with governance frameworks from Singapore, the European Union, and international standards bodies, and reads them through New Zealand’s actual instruments: the Algorithm Charter for Aotearoa New Zealand, the Public Service Artificial Intelligence Framework, the Privacy Act 2020, and ISO 55000-aligned asset management practice. We argue that agentic AI cannot be governed with generative-AI playbooks, and that New Zealand’s existing, voluntary, risk-based architecture is a workable starting point only if it is extended to cover the one thing agents do that chatbots do not: take consequential action in the physical world.

Keywords: agentic AI, asset management, AI governance, critical infrastructure, New Zealand, responsible AI

1. Introduction

New Zealand has chosen its lane on artificial intelligence. In June 2024 Cabinet agreed to promote the OECD AI Principles as the country’s direction of travel, and the resulting posture is deliberately light-touch, principles-based, and technology-neutral—the Government has signalled that existing frameworks such as privacy, consumer protection, and human rights law will be updated as needed rather than replaced by AI-specific legislation (Ministry of Business, Innovation and Employment [MBIE], 2025a). The public-sector instrument that gives this posture operational shape is the Public Service Artificial Intelligence Framework, issued by the Government Chief Digital Officer within the Department of Internal Affairs (Department of Internal Affairs [DIA], 2025). It sets a vision—“Adopt AI responsibly to modernise public services and deliver better outcomes for all New Zealanders”—and defines five principles: inclusive, sustainable development; human-centred values; transparency and explainability; safety and security; and accountability (DIA, 2025). There is no New Zealand AI Act.

That architecture was designed for a world of analytical and generative AI. Agentic AI breaks the mould. Where generative AI produces text or images for a human to review, an agent can take actions, adapt to new information, and interact with other systems to complete tasks on behalf of humans (AI Verify Foundation & Infocomm Media Development Authority [IMDA], 2026). An agent does not draft a recommendation that a pump be throttled; given the tools, it throttles the pump. The governance distance between recommending and acting is the entire subject of this paper.

The stakes are highest in asset management for government and regulated sectors. In New Zealand, formal adoption of the international asset management standard ISO 55001 is led by the regulated electricity distribution sector and now extends to water and wastewater, transport, and defence, with thirteen certified organisations as of early 2026 and the regulated electricity distributors furthest advanced—networks managed under ISO 55001 certification grew from zero in 2016 to 30 per cent in 2026 (Gatland, 2026). This infrastructure is the physical substrate of public life. When an asset-management AI errs, the consequence is not a poorly worded sentence. The European Union makes this concrete: AI used as a safety component in the management and operation of critical infrastructure, including the supply of water, gas, heating, and electricity, is classified high-risk precisely because its failure or malfunctioning “may put at risk the life and health of persons at large scale” (Regulation (EU) 2024/1689, recital 55). New Zealand has no equivalent binding rule, which makes the voluntary architecture’s adequacy a live question—particularly as the national infrastructure body itself observes that “new technologies such as artificial intelligence could fundamentally change how people use infrastructure” (New Zealand Infrastructure Commission Te Waihanga, 2026).

This paper asks: how should New Zealand government and public organisations responsibly adopt agentic AI for asset management in government and highly regulated environments, given both the country’s distinctive governance settings and the uncomfortable state of the sector’s foundations?

2. The foundations are not ready

It is tempting to treat the readiness problem as someone else’s. The evidence does not allow it, and in New Zealand the evidence is pointed: the New Zealand Infrastructure Commission Te Waihanga reports that the country ranks “fourth to last in the OECD for asset management,” with visible symptoms of weak practice including sewage leaks in hospitals, leaky classrooms, and mouldy army barracks (New Zealand Infrastructure Commission Te Waihanga, 2026). The problem, the Commission stresses, is not solely one of investment quantum; the sector also has a maturity problem (Gatland, 2026). Three findings from the wider industry research show what that immaturity looks like in practice.

Data is abundant and untrusted. Across the 2026 Australia–New Zealand asset management research—twelve roundtables with 153 senior practitioners and a survey of 715 professionals—36 per cent of organisations collect more maintenance and reliability data than they can effectively analyse, and professionals spend an average of 14.6 hours per week, some 38 per cent of their working time, searching for, validating, or reconciling data across multiple systems (MAINSTREAM & KPMG, 2026). The deeper issue is conviction: organisations have invested in dashboards only to find decision-makers do not trust the data enough to act (MAINSTREAM & KPMG, 2026). One power distribution utility had integrated 100 per cent of its finance data but only 30 per cent of its work data—exactly the data an asset-optimising agent would consume (MAINSTREAM & KPMG, 2026). This matters because data integrity sits at the centre of responsible-AI scholarship: models built on incomplete or biased data inherit and amplify those flaws, with one bias-evaluation study finding that 37.65 per cent of outputs from industry-leading large language models contained some form of bias (Abhishek et al., 2025).

Expertise is leaving. Engineers Australia estimates 25,000 engineers will retire within five years, and mean time to repair has already climbed from 49 to 81 minutes through skills gaps (MAINSTREAM & KPMG, 2026). The knowledge most at risk is contextual judgement—the engineer who knows a bearing sounds wrong below twelve degrees—and it cannot be written into a manual (MAINSTREAM & KPMG, 2026). The pattern repeats in the UK, where organisations lose roughly £240,000 in productivity per retiring specialist yet only 22 per cent run formal knowledge-capture programmes (MAINSTREAM, 2025).

Pilots stall. Around 45 per cent of ANZ organisations are still exploring or have not started with AI; only about 11 per cent have genuinely scaled it; and 76 per cent of those who explored AI failed to achieve expected returns (MAINSTREAM & KPMG, 2026). In the UK, 58 per cent of asset-intensive organisations have abandoned at least one AI-related maintenance project in the past three years, taking an average of 22 months to move from pilot to production—nearly twice the global average (MAINSTREAM, 2025). Tellingly, the single highest-rated practitioner concern in the ANZ research—85 per cent expressed at least some worry—was younger engineers over-relying on AI outputs, captured in the line that “AI doesn’t know when it doesn’t know” (MAINSTREAM & KPMG, 2026). When such a system is handed the power to act, that blind spot becomes operational risk.

3. Why agentic AI is a different governance problem

An agent built on a language model carries components a simple application lacks: planning and reasoning, tools for acting on external systems, and protocols such as the Model Context Protocol for communicating with tools and other agents (AI Verify Foundation & IMDA, 2026). Each component is a fresh source of risk. An agent can hallucinate a faulty plan, call the wrong tool with the wrong input, or be steered by a prompt injection into exfiltrating or corrupting the data its tools can reach (AI Verify Foundation & IMDA, 2026). These are not entirely novel risks so much as familiar software and LLM vulnerabilities—such as injection attacks, hallucination, and data leakage—manifesting through new surfaces (AI Verify Foundation & IMDA, 2026).

Two design properties determine how much harm an agent can do: its action-space (what tools and systems it can reach, and whether it can write as well as read) and its autonomy (whether it follows a defined procedure or exercises its own judgement at each step) (AI Verify Foundation & IMDA, 2026). The consequential failure modes for asset management are concrete—erroneous actions, unauthorised actions taken without required escalation, data breaches, and disruption to connected systems—and because agents pass outputs to one another, a single hallucinated figure, such as an inventory count, can cascade downstream into excessive or insufficient stock orders (AI Verify Foundation & IMDA, 2026).

This is the gap in New Zealand’s current settings. The Algorithm Charter for Aotearoa New Zealand commits signatories to manage algorithms that carry a high risk of unintended consequences, using a likelihood-and-impact risk matrix to determine when the Charter’s commitments apply (Stats NZ, 2020). Its commitments are real and relevant—transparency, partnership reflecting Te Ao Māori and the Treaty of Waitangi, a focus on people, fitness of data, privacy and human rights, and human oversight (Stats NZ, 2020). But the Charter’s human-oversight commitment is framed around “clearly explaining the role of humans in decisions informed by algorithms” and providing a channel for challenging those decisions (Stats NZ, 2020). That framing assumes a human at the decision point. Agentic AI, by design, removes the human from many decision points—which is precisely why the Charter, valuable as it is, was not written for software that acts autonomously.

4. A governance approach, adapted for New Zealand

The constructive path is to extend, not abandon, what exists. We organise the extension around the four areas of the Model AI Governance Framework for Agentic AI (AI Verify Foundation & IMDA, 2026), mapping each onto New Zealand instruments and asset-management reality.

4.1 Assess and bound the risk before deployment

Risk is a function of likelihood and impact, and both can be bounded by design (AI Verify Foundation & IMDA, 2026). This aligns naturally with the Charter’s likelihood-impact risk matrix and the OECD-derived, risk-based posture of the Public Service AI Framework (DIA, 2025; Stats NZ, 2020). The translation for agents is to choose use cases honestly: an agent summarising shutdown lessons is low-impact; an agent issuing set-point changes to a water-pressure monitoring system is the precise high-risk safety component the EU AI Act names (Regulation (EU) 2024/1689, recital 55).

The most effective controls are unglamorous. Least-privilege access—granting an agent only the minimum tools and data it needs—directly limits the blast radius of failure, and constraining an agent to a defined standard operating procedure rather than free improvisation reduces unpredictability (AI Verify Foundation & IMDA, 2026). Running high-risk operations such as code execution in self-contained, network-limited sandboxes is consistent with the sandbox testing long recommended in responsible-AI practice (AI Verify Foundation & IMDA, 2026; Joshi et al., 2025). For structured risk identification, organisations can draw on catalogues such as the MIT AI Risk Repository, which documents more than 1,600 AI risks across causal and domain taxonomies (Joshi et al., 2025), and certify their management systems against ISO/IEC 42001 (Joshi et al., 2025). Crucially, this is where the data problem returns: an agent reasoning over the 30 per cent of work data one utility had integrated will act confidently on gaps, so data governance—data owners, standards such as ISO 14224, discipline at the point of entry—is a precondition, not a parallel task (MAINSTREAM & KPMG, 2026).

4.2 Make humans meaningfully accountable

Deployers remain accountable, but autonomy complicates a responsibility model built for static workflows, and multiple actors across the agent lifecycle diffuse it further (AI Verify Foundation & IMDA, 2026). The framework’s answer—defining significant checkpoints requiring human approval for high-stakes, irreversible, or outlier actions—maps onto the older Singapore taxonomy of human-in-the-loop, human-over-the-loop, and human-out-of-the-loop decision models, which tied the required level of human control to a probability-severity-of-harm matrix and insisted that safety-critical systems allow a person to assume control or safely shut down (IMDA & Personal Data Protection Commission [PDPC], 2020). For a New Zealand water or lines company, severity should pull the human firmly into the loop.

The subtle threat is automation bias—over-trusting a system that has performed well before—which is the same fear practitioners voiced about junior engineers (AI Verify Foundation & IMDA, 2026; MAINSTREAM & KPMG, 2026). A human who reflexively approves an agent’s actions is not oversight. The framework therefore urges training humans to recognise failure modes and auditing the effectiveness of approvals over time, which aligns with both the Charter’s commitment to regularly peer-review algorithms for unintended consequences and the Public Service AI Framework’s accountability principle of governance, regulatory frameworks, and auditing with human oversight (AI Verify Foundation & IMDA, 2026; DIA, 2025; Stats NZ, 2020). New Zealand carries an additional, distinctive obligation: both the Charter and the Framework require that AI use reflect the Treaty of Waitangi and Māori views on ethics, bias, and data, meaning accountability structures for agentic systems affecting public services must consider impacts on Māori rather than treat fairness as a generic technical metric (DIA, 2025; Stats NZ, 2020). Accountability also runs along the value chain—contracts with third-party agent providers should secure features such as scoped API keys, per-agent identity tokens, and logging of tool calls, addressing the vendor and third-party risk that responsible-AI scholarship flags as persistently under-managed (AI Verify Foundation & IMDA, 2026; Joshi et al., 2025).

4.3 Implement technical controls across the lifecycle

Responsible deployment is a lifecycle discipline. During development, controls should target the new agentic components—prompting an agent to reflect on whether its plan adheres to instructions, logging its reasoning for verification, enforcing strict tool input formats, and withholding write access to sensitive databases unless strictly required (AI Verify Foundation & IMDA, 2026). Before deployment, testing must extend beyond output accuracy to overall task execution, policy compliance, and correct tool use; after deployment, agents should be rolled out gradually—to trained users and lower-risk internal systems first—and continuously monitored, because their adaptive autonomy means not all risks can be foreseen (AI Verify Foundation & IMDA, 2026). This lifecycle stance is consistent with the NIST AI Risk Management Framework, whose four core functions—Govern, Map, Measure, and Manage—structure ongoing risk assessment across the AI lifecycle (National Institute of Standards and Technology [NIST], 2023), and with the responsible-AI literature’s framing of governance as continuous from ideation to model retirement (Joshi et al., 2025).

4.4 Enable end-user responsibility without eroding tradecraft

Trustworthy deployment rests on the people who use agents. Users must be told an agent’s range of actions, its data access, and whom to escalate to on malfunction (AI Verify Foundation & IMDA, 2026). But the framework names a longer risk: as agents absorb the entry-level tasks that have always been the training ground for new staff, basic operational knowledge erodes (AI Verify Foundation & IMDA, 2026). For a New Zealand profession already facing a knowledge exodus, this is the most consequential warning. Automating away the routine work through which a young inspector once learned the network risks automating away the apprenticeship that produces the contextual judgement no agent can replicate (MAINSTREAM & KPMG, 2026). Organisations should identify each role’s core capabilities and deliberately preserve the work exposure that keeps them alive (AI Verify Foundation & IMDA, 2026).

5. The regulatory backdrop and New Zealand’s choice

New Zealand’s voluntary, risk-based model runs on two complementary tracks. MBIE leads the national strategy, New Zealand’s Strategy for Artificial Intelligence: Investing with Confidence (2025), an adoption-focused roadmap explicitly aimed at accelerating private-sector AI uptake under the Government’s “Going for Growth” agenda, accompanied by its companion Responsible AI Guidance for Businesses (MBIE, 2025a, 2025b). In parallel, public-sector AI adoption is driven separately—the strategy itself notes that it “complements the work being undertaken by” the Minister for Digitising Government—and given operational form by the Department of Internal Affairs’ Public Service AI Framework, which governs how public-service agencies, the bodies that manage New Zealand’s public assets, use AI in their own operations (DIA, 2025; MBIE, 2025a). Both tracks are anchored to the OECD AI Principles, whose five values-based principles—inclusive growth and well-being; human rights and democratic values; transparency and explainability; robustness, security and safety; and accountability—were adopted in 2019 and revised in 2024 to reflect developments including generative AI (Organisation for Economic Co-operation and Development [OECD], 2024). New Zealand’s adoption of these principles, the strategy states, “does not require additional regulatory overlay beyond existing law” (MBIE, 2025a).

That choice has real virtues, including interoperability with the 42 countries party to the OECD principles (MBIE, 2025a). Comparative work shows, however, that risk-based approaches such as the EU’s achieve the broadest coverage of governance processes, and that across six jurisdictions only one governance process aligned across all approaches studied—evidence of how little consistent, executable provision yet exists globally (Luna et al., 2024). For a public asset operator, the open question is whether voluntary guidance suffices when an agent can act on a water or electricity network. The EU’s answer is mandatory lifecycle obligations—risk management, data governance, and human oversight—for high-risk critical-infrastructure systems, backed by a definition of severe incidents that expressly includes “a serious and irreversible disruption of the management or operation of critical infrastructure” (Regulation (EU) 2024/1689, Article 3, recitals 55 and 65–66). New Zealand need not import an AI Act to close the gap. It already has, in the electricity distribution sector, a regulator-driven maturity mechanism—the Commerce Commission’s Asset Management Maturity Assessment Tool, the primary formal driver of asset-management system development in that sector (Gatland, 2026)—which shows that sector-specific, assessment-based oversight is achievable within existing arrangements. The same logic can extend the Algorithm Charter and Public Service AI Framework with agent-specific guidance: explicit treatment of action-space and autonomy, mandatory human checkpoints for irreversible physical actions, and identity management that establishes, in the agentic framework’s words, “who holds accountability for each agent” (AI Verify Foundation & IMDA, 2026).

6. Conclusion

The difference between an AI that recommends and an AI that acts is a difference in kind, and in New Zealand’s regulated asset sectors—where a wrong autonomous action can interrupt water supply or destabilise a network—that difference is decisive. The encouraging finding is that the country already holds most of the governance scaffolding it needs: a risk-based posture, an Algorithm Charter, a Public Service AI Framework, Treaty obligations that force a richer view of fairness, and a maturing ISO 55001 tradition concentrated, tellingly, in its most regulated sectors. What is missing is the agentic extension—bounding action-space, keeping humans meaningfully in the loop where harm is severe, testing and monitoring across the lifecycle, and protecting the human expertise agents would quietly erode. Above all, the sector cannot let autonomy run ahead of its foundations. A country already ranked fourth to last in the OECD for asset management cannot assume the data and maturity that safe autonomy demands (New Zealand Infrastructure Commission Te Waihanga, 2026); an agent reasoning over untrusted data and unintegrated systems will act on those weaknesses with a confidence no human would (MAINSTREAM & KPMG, 2026). The organisations that deploy agentic AI safely will be the ones already doing the patient work of data governance, knowledge capture, and workforce development—the work New Zealand’s asset managers know they must do regardless. Agentic AI does not let them skip it. It raises the price of having done so.

References

  • Abhishek, A., Erickson, L., & Bandopadhyay, T. (2025). Data and AI governance: Promoting equity, ethics, and fairness in large language models (arXiv:2508.03970v1). arXiv.
  • AI Verify Foundation & Infocomm Media Development Authority. (2026). Model AI governance framework for agentic AI (Version 1.0).
  • Department of Internal Affairs. (2025). Public Service Artificial Intelligence Framework. New Zealand Government.
  • Gatland, A. (2026). Who’s using the ISO 55000 standards in New Zealand? An update for 2026. Asset Dynamics.
  • Infocomm Media Development Authority & Personal Data Protection Commission. (2020). Model artificial intelligence governance framework (1st ed.).
  • Joshi, H., Hassani, S., Gandhi, D., & Hartman, L. (2025). Approaches to responsible governance of GenAI in organizations. In 2025 IEEE International Symposium on Technology and Society (ISTAS) (arXiv:2504.17044v2).
  • Luna, J., Tan, I., Xie, X., & Jiang, L. (2024). Navigating governance paradigms: A cross-regional comparative study of generative AI governance processes and principles. In Proceedings of the 2024 AAAI/ACM Conference on AI, Ethics, and Society (AIES).
  • MAINSTREAM. (2025). The state of maintenance and reliability in the UK.
  • MAINSTREAM & KPMG. (2026). The state of asset management in Australia & New Zealand (30th ed.).
  • Ministry of Business, Innovation and Employment. (2025a). New Zealand’s strategy for artificial intelligence: Investing with confidence — Accelerating private sector AI adoption and innovation. New Zealand Government.
  • Ministry of Business, Innovation and Employment. (2025b). Responsible AI guidance for businesses. New Zealand Government.
  • National Institute of Standards and Technology. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). U.S. Department of Commerce. https://doi.org/10.6028/NIST.AI.100-1
  • New Zealand Infrastructure Commission Te Waihanga. (2026). 2026 national infrastructure plan / Mahere Tūāhanga ā-Motu.
  • Organisation for Economic Co-operation and Development. (2024). Recommendation of the Council on artificial intelligence (OECD/LEGAL/0449).
  • Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L 2024/1689.
  • Stats NZ. (2020). Algorithm charter for Aotearoa New Zealand.