Sequence matters: the right way to scale AI in government #AI


The New Zealand government’s announcement that it will cut around 8,700 public service jobs by mid-2029 has focused attention squarely on AI and digital technology as tools of reform. Finance Minister Nicola Willis was clear. Reducing duplication, consolidating back-office functions, and accelerating the uptake of AI are central to delivering $2.4 billion in savings over four years. The Prime Minister pointed to Singapore and Southeast Asia as examples of what a technology-enabled public service can look like.

While AI tools can streamline public services by automating routine, repetitive administration, deploying them too quickly poses a major risk. To prevent AI from becoming a new category of liability, agencies must first establish two critical foundational safeguards: properly classifying and governing sensitive data and ensuring that existing human access permissions are properly aligned.

Data without classification is data without protection

AI operates on data. The promise of AI agents doing the work of multiple people rests entirely on those agents (and their owners) being able to access the right information, accurately and within the bounds of what is permitted. But in most government agencies today, data is poorly classified, spread across legacy systems, and largely ungoverned. Much of it sits in documents, policy papers, spreadsheets, and shared drives. In other words, the kind of unstructured data that is hardest to classify and most commonly left without meaningful governance at all.

Without sufficient data classification, there are no meaningful controls on who or what can access sensitive or regulated information. This essential data sensitivity context becomes even more critical as AI agents are introduced into organisations and start accessing data based on inherited permissions. If the underlying data has never been categorised as sensitive, restricted, or public, the guardrails simply do not exist.

For New Zealand agencies, this introduces a new compliance issue. Under the Privacy Act 2020, exposing personal citizen data to unauthorised AI models or third-party platforms without adequate safeguards is a breach. Furthermore, properly classifying data is essential to respecting Māori Data Sovereignty principles. Without that classification work done first, a tool designed to streamline government services becomes a liability capable of exposing sensitive data at scale.

Ungoverned access is AI’s biggest blind spot

According to SailPoint research, 96% of technology leaders agree that AI agents represent a growing security threat, yet fewer than half have policies in place to manage them. Governing those agents is a challenge I will address in the next article in this series. But that work cannot begin without first getting the human access layer right, and that is the second foundational gap agencies have consistently deferred.

Most agencies carry years of accumulated access permissions that no one has reviewed. People move between departments and roles, while their previous access lingers. Contractors retain credentials well beyond their engagement. Service accounts accrue entitlements that sit unexamined. This is an identity governance problem.

When AI agents enter the picture, they typically work on behalf of a person or system, inheriting or mirroring those access permissions. If a public servant has accumulated excessive access through years of role changes, the AI agent picks that up too. Suddenly, an agent tasked with answering routine queries can reach across systems and data its human owner may have retained access to inadvertently. The governance gap that was manageable as a human problem becomes an amplified risk at machine speed and scale.

Getting access controls right is the foundation without which AI cannot be deployed safely. It is not a preliminary step that can be skipped in the rush to modernise.

The efficiency case is real, but sequence matters

None of this is an argument against AI in the public service. The case for modernisation is strong, and agencies that approach it thoughtfully will be better placed to deliver more with a leaner workforce. But thoughtfully means in the right sequence.

Classify the data. Clean up access. Govern every identity, human and non-human alike. Agencies that invest in that foundational work now will have a platform capable of supporting genuine AI-driven efficiency. Those that skip it risk watching the productivity gains disappear under the weight of security and compliance costs that follow.

To learn more, visit us here.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW