How this was made. The version number counts drafts of the text. It does not measure the inquiry behind it, which has run over days and across several AI systems, with argument between those systems and within them, directed, refused and repeatedly redirected by the author. The source material was AI-generated, and then adversarially and iteratively refined across a range of tools — systems built by different companies in different jurisdictions, set against each other and against the author. No one of them produced this text, and no one of them reviewed it alone. The plurality is deliberate rather than incidental. A single model carries a single set of priors about which sources are authoritative, and this series argues that an evidence base narrowed in exactly that way is how a contested question comes to look settled. Using one model to investigate that claim would have been the claim refuting itself. To name a single model on it would credit that model with work that was neither its own nor done in a single pass. The plurality was also necessary, and the record should say why. In drafting, the assisting model repeatedly led with United States institutional sources — a national laboratory, an industry association, a market study nineteen years old — and presented conclusions drawn from them as the state of knowledge. On one occasion European measured data contradicting those conclusions was present in the same research return and was placed below them. Framings were proposed that would have argued against this series’ own position using that evidence base, and offered as rigour. Each was refused by the author and the material rebuilt. That is the mechanism these documents describe, occurring in their own making, and it is recorded because a series arguing that evidence bases narrow without anyone deciding to narrow them cannot credibly claim its own production was exempt. The framing, the corrections and the judgements are the author’s, and so are the errors. How this site is written sets out what is declared on every piece, who checks it, and where the per-piece record lives.
What this publication does not claim, and what is outstanding against it in the register.
Nothing outstanding in the register. Every claim in this publication has its evidence recorded, and no question against it is parked. That is a statement about this publication on the date shown above, generated from the register rather than asserted, and it will change when the register does.
What this publication rests on, and how solid each part of it is. What you can actually require is an essay, and this page describes it as one.
This publication cites outside sources, and they are listed below — each with what it supports, and with what it does not support. That second column is the one that matters: the common failure is not a fabricated source, it is a real source stretched past its finding.
framework
Supports. Quoted: “Agencies are encouraged to align with the direction set by this Framework, however it’s not binding,” and its fifth principle: “AI use within the Public Service should be subject to oversight by accountable humans with appropriate authority” — shows almost nothing is mandatory in NZ AI governance.
Does not support. States its own non-binding status; “should” is “the operative word” — guidance, not enforceable requirement.
framework
Supports. Quoted: “a commitment by government agencies,” applying could/should/must by the agency’s own risk rating, including “providing a channel for challenging or appealing of decisions informed by algorithms.”
Does not support. Quoted stating its own limit: “it cannot fully address important considerations, such as Māori Data Sovereignty.”
⚠️ Retrieval. ⚠️ “Whether it remains operative in 2026 could not be established this session and should be confirmed before anyone relies on it.”
framework
Supports. Quoted: “Simply having a ‘human in the loop’ may not be enough to uphold the accuracy principle, given the well-known problem of automation blindness,” and expects “senior leadership approval based on full consideration of risks and mitigations” before deployment.
Does not support. Described as “guidance, but they rest on binding principles” — the expectations document itself is not binding, though the underlying Privacy Act principles are.
regulation
Supports. Cited as an example of something “binding, and narrow” in NZ — a code of practice under the Privacy Act, commenced November 2025.
Does not support. Only cited for existing/commencing; its substantive requirements are not detailed and it is not claimed to address agentic AI generally.
statute
Supports. Searched: “‘automated’ appears zero times” and “‘algorithm’ once, inside the information-matching provisions” — used to establish no right to human intervention, no oversight threshold, and no equivalent to GDPR Article 22.
Does not support. A word-search finding about the current consolidated text; does not examine case law or other statutes/common-law duties.
evidence
Supports. Quoted: “We also need stronger protections for the significant privacy risks that arise from automated decision-making” — confirmation from the regulator that NZ currently lacks such protections.
Does not support. A call for reform, not itself a change in law.
standard
Supports. Paraphrased: “uniquely identify and authenticate organisation-defined system services and applications before establishing communications with devices, users, or other services” — presented as “almost exactly, the first of the twelve requirements below,” proof the requirement “It was written. And it appears in no baseline … An organisation bound by those baselines is not required to select it and will not select it by default.”
Does not support. “It appears in no baseline: not Low, not Moderate, not High, not the privacy overlay, not the operational-technology overlay.”
specification
Supports. Cited: “specifies a workload identifier containing no notion of ownership or accountability” — further evidence the standards landscape does not require accountable agent identity.
Does not support. Describes SPIFFE’s scope on this one point only.
standard
Supports. Cited: “states its scope as the identity of users” — used with SPIFFE to show identity standards do not cover accountable agent/workload identity.
Does not support. Scope statement only; not a critique of adequacy for its stated purpose.
standard
Supports. Cited: names single-agent and multi-agent use cases and states the overlays “will assume that certain controls are already in place” — including identification and authentication.
Does not support. “The overlays for agents had not been published at the time of this search” — substantive content could not be checked.
⚠️ Retrieval. ⚠️ Post-cutoff; overlay text not yet published/available to check.
framework
Supports. Described (via the sibling piece “Our own machines”) as offering “seven commitments and a three-phase pathway for AI under New Zealand authority,” first commitment “Authority stays here…”; quoted proposing MBIE amend the Government Procurement Rules “to insert the cross-party test pair: jurisdiction of inference… and data residency” — used as an independently reached convergence with this piece’s procurement-lever argument.
Does not support. “This piece has not examined the proposal independently, and a reader relying on its contents should go to that framework and to the proposal itself rather than to this summary.”
⚠️ Retrieval. Sourced at second hand via the sibling document “Our own machines,” not independently examined by this piece.
framework
Supports. Cited as existing in “a full version aligned to the AI Act and a lighter version for systems outside it” — “voluntary templates, but templates that make the requirements concrete and quotable.”
Does not support. Voluntary, not binding; no claim about adoption rates or enforceability.
regulation
Supports. Quoted: binding requirement to remove “pre-commercial, commercial, technical, contractual and organisational obstacles” to switching/porting, “including to on-premises infrastructure,” with functional equivalence — described as requirements eleven and twelve, “in force, for cloud services in Europe.”
Does not support. Applies to cloud services in Europe specifically; not a general AI-agent regulation.
regulation
Supports. Used across the twelve-requirement table: Art.26(6) partially supports requirement 9 (audit logs, “at least six months, high-risk only, applying from 2027”); Art.14(4)/26(2) for requirement 10 (human step-up approval, high-risk only); Art.14(4)(e) for requirement 11 (system stop); Art.26(5) for requirement 12 (suspension on risk).
Does not support. Each requirement is marked only “Partly” met; for requirement 11 specifically: “Art. 14(4)(e) requires a stop for the system, not revocation of a credential” — narrower than the requirement as stated. All apply to high-risk systems only.
regulation
Supports. Cited as partial support for requirement 10 (human step-up approval) — “for high-impact federal AI.”
Does not support. Applies to US federal high-impact AI only; not examined further.
regulation
Supports. Described as “the closest existing thing to a tiered mandatory regime, with four impact levels” — partial support for requirements 10 and 12 (approval and contingency planning “at higher impact levels”).
Does not support. “Its Appendix C could not be retrieved this session — the department’s site refused automated access — so nothing from it is quoted here and its requirements are described only in outline from the department’s own summary pages.”
⚠️ Retrieval. ⚠️ Not retrieved — Appendix C; described only from department summary pages.
framework
Supports. Cited as requiring “a public record of algorithmic tools” — partial support for requirement 4 (default-deny tools with signed inventory), though “an inventory rather than a deny-list.”
Does not support. An inventory/transparency requirement only, not an approval or default-deny control.
framework
Supports. Cited as advising caution against autonomous self-update of agents/models/plugins — partial support for requirement 8.
Does not support. “The UK Playbook advises caution; nothing requires it” — advisory only, not mandatory.
Supports. Quoted: “AI systems must not be implemented in Aotearoa without fully realising Māori authority over Māori data” — sets requirements “from a body with the standing to set them,” including that decommissioning is a partnership decision. Its requirements are scored in the schedule’s table alongside those of states and standards bodies.
Does not support. “It does not address Māori data sovereignty, which is not a subsection of this schedule and should not be written as though it were… An institution adopting these twelve has not discharged that obligation and should not tell itself otherwise.”
Supports. “Reported to require a verifiable identity per agent” — raised as a possible counterexample to the claim no jurisdiction requires agent identity.
Does not support. “That could not be confirmed from the framework text, and if it does, it is the first and this piece must say so” — explicitly unconfirmed.
⚠️ Retrieval. ⚠️ Unconfirmed — the framework’s body text could not be retrieved/opened this session.
regulation
Supports. Cited as a candidate vehicle: “If they do not [contain any AI provision], that is the shortest path from this piece to something enforceable — a schedule appended to the rules binds every agency that buys.”
Does not support. “Whether they contain any AI provision could not be established this session; the rule text was not retrievable.”
⚠️ Retrieval. ⚠️ Not retrieved — rule text unavailable this session.
standard
Supports. Listed among instruments relevant to this schedule’s subject matter (AI management systems).
Does not support. Its operative text “could not be opened”; nothing from it is quoted or its requirements described.
⚠️ Retrieval. ⚠️ Not retrieved — “ISO/IEC 42001’s operative text… could not be opened. Each is marked below and none is quoted.”
standard
Supports. Listed among instruments relevant to this schedule’s subject matter.
Does not support. Could not be opened; nothing from it is quoted or described.
⚠️ Retrieval. ⚠️ Not retrieved.
Foundational documents. These are positions this project has taken, not findings.
| Record | What it is | Status |
|---|---|---|
CON-13 |
Claims carry evidence | draft v0.1 |
None. This publication references no evidence record. That is the correct description of what it is rather than a gap: it is an essay, reasoning from the foundational documents above rather than reporting a measurement. Where it states a number, that number is marked in the text as what it is.
| Record | What it is | Status |
|---|---|---|
CON-12 |
Exceptions are disclosed first | draft v0.1 |
CON-22 |
Institutional judgement is written down | draft v0.1 |
FIG-30 |
Twelve requirements, and where each is already mandatory | drawn for this publication · figures/FIG-30.svg |
Generated from the corpus, not written by hand: this page cannot claim a source the corpus does not hold, and it changes when the records do.
Alongside: the publication · questions and answers