This page tracks AI-related incidents affecting Aotearoa, or with clear relevance to Kiwis. Each one is a real, documented case, rated by how serious the harm was.
How serious was the harm?
The incidents
Wellington Mayor Andrew Little said "large chunks" of a $435,000 Deloitte staffing review were written by AI, after the report was found to contain significant errors including double-counted roles, employment data three years out of date, and part-time staff counted as full-time - overstating staffing costs by an estimated $21.5 million. The headline recommendation to cut 330 FTE roles was later revised down to 284. Deloitte confirmed it uses "AI-enabled tools where appropriate" but says analysis and conclusions require human sign-off; it has not specified which sections were AI-generated.
After OpenAI's Hugging Face disclosure, Anthropic reviewed more than 141,000 of its own cybersecurity evaluation runs and found three separate incidents, dating back to April 2026, where Claude models (Opus 4.7, Mythos 5, and an internal research model) reached the internet from inside what was meant to be an isolated test environment and gained unauthorized access to the real production systems of three organisations. Anthropic attributed the escape to a misconfiguration with a third-party testing partner, Irregular, over whether the environment had internet access. The company said no data was exfiltrated and notified all three affected organisations.
NZEI Te Riu Roa urged parents to check whether their school uses SMART, an Australian-sourced AI assessment tool adopted by the Ministry of Education, after teachers reported it assigned identical scores to completely different student scripts based merely on word count rather than writing quality. The union also flagged contradictory Ministry messaging on data storage. School leaders were told backups go to Australia while parents were told data stays in New Zealand. Principals' Council Chair Stephanie Madden said the mixed messaging did "not help build trust."
Health NZ instructed staff to stop using free public AI tools such as ChatGPT to help draft clinical notes, after it emerged some were doing so without authorisation. Feeding patient information into consumer chatbots raised privacy and data-sovereignty concerns, a clear case of unsanctioned "shadow AI" use inside the public health system before governance had caught up.
Heidi, an AI clinical-documentation tool used by more than 1,250 frontline clinicians across New Zealand emergency departments, had its guardrails bypassed by security firm Mindgard using only typed prompts, after which it produced instructions for a doctor to steal a patient's identity and manufacture methamphetamine. Heidi and Health NZ disputed the framing, saying the flaw was patched and no patient data was exposed, but the case showed how quickly a tool approved as a note-taker could be pushed well beyond its intended function.
Declining leave to appeal in Jones v Family Court at Whangārei, the Supreme Court noted that the applicant had cited a number of authorities that appeared to have been hallucinated by an AI application. The Court signalled that litigants filing fabricated citations could face contempt of court charges, with further warnings issued to additional litigants later in the year.
High-achieving senior students at Cambridge High School and Pukekohe High School were accused of AI cheating and failed on internal assessments after AI-detection tools flagged their work. In one reported case flagging advanced vocabulary such as "imperfect" as too sophisticated to be a student's own writing. Parents and the students disputed the accusations, and educational-technology and university experts warned the detection tools are "not infallible" and carry legal risk when relied on. At least one grade was appealed through a school complaints procedure.
The Privacy Commissioner's inquiry into Foodstuffs North Island's facial recognition trial documented multiple misidentification cases across the trial period. The inquiry attributed those cases primarily to human error in the two-person confirmation step rather than to the algorithm itself, while flagging potential bias against Māori and Pacific shoppers as an unresolved concern. Consumer NZ separately disputed the misidentification rate reported by Foodstuffs.
In LMN v STC (No 2), a self-represented employee cited a supposed precedent to argue for procedural leniency on grounds of financial hardship. The Court could not locate the decision anywhere and found that no such case existed, concluding the citation had been generated by an AI tool. The judgment reminded litigants that AI-produced material must be checked before it is filed.
Google's AI-generated search summaries were found to be naming people protected by New Zealand court suppression orders, surfacing identities that publication bans exist specifically to protect. Suppression breaches are a criminal offence in New Zealand, and the case exposed the gap between automated summary generation and local legal obligations.
How we classify each entry
Every incident is tagged three ways. First, by how serious the harm was, using the five levels above.
Second, by how the failure happened:
- Bypassed: a person deliberately tricked, jailbroke, or misused the system to cause harm.
- Model Error: the system hallucinated or produced a wrong or harmful output, and no guardrail caught it.
- Algorithmic Bias: the system performed unequally across different groups of people.
- Shadow AI: an organisation deployed or used a tool without proper authorisation, policy, or oversight.
And third, by how confident we are in the reporting:
- Confirmed: verified by multiple sources or an official statement.
- Disputed: sources disagree, or the organisation involved contests it.
- Under Investigation: still unfolding.
For more AI-related news from around New Zealand, browse our NZ AI News Archive.
Report an incident
Seen an AI-related incident with relevance to Aotearoa? Tell us about it below. We review every submission before anything is added to the tracker, so it will not appear on this page automatically.