As AI becomes embedded in day-to-day business operations, organisations need clear frameworks for managing risk, accountability and oversight.

In this three-part series, we explore the practical questions boards, executives and organisations are grappling with, from emerging risks to governance frameworks and AI policies. We begin by examining why AI should be treated as an enterprise risk and what that means for organisations.

Foreign interference, espionage, insider threats and AI-enabled influence campaigns may sound like the plot of a spy thriller. According to the New Zealand Security Intelligence Service’s (NZSIS) 2026 threat assessment, they are increasingly risks that New Zealand organisations need to understand and manage.

Key takeaways

  • National security is no longer solely a government concern. Many of the controls needed to manage these risks must sit within organisations themselves.

  • Foreign interference, espionage and insider threats can arise through seemingly ordinary commercial, research and community relationships.

  • AI is increasing the sophistication and scale of information and influence risks.

  • Due diligence, governance and staff awareness are becoming increasingly important risk controls.

  • Boards and executives should understand where their most sensitive information, assets and relationships sit, and consider whether current controls remain fit for purpose.

When legitimate business relationships mask broader risks

The NZSIS assessed that New Zealand’s public and private sectors are being targeted by foreign states and their proxies seeking access to critical assets. These assets may include intellectual property and innovative technology, commercially sensitive or personal information, access credentials and valuable relationship networks. The access can occur through cyber intrusion, recruitment of people with inside access, academic or commercial relationships, fake cover companies or direct theft.

For businesses, universities, research institutions and government agencies, this means that relationship and information-security risk need to be assessed together. A legitimate-looking joint venture, research collaboration, investment approach, procurement opportunity or overseas intermediary may still carry national security, sanctions, export-control or reputational risk if the true end user, beneficial owner or strategic purpose is obscured.

The report’s examples involve front companies, supply-chain intermediaries, and naivety about how technology could be used. They demonstrate that organisations should understand not only who they are dealing with, but why the relationship is being sought, how the relevant goods, services, information or data could be used, and who may ultimately benefit.

The threat inside the perimeter

Insider risk is another key theme.

The NZSIS identifies deliberate, influenced and unwitting insider activity, ranging from unauthorised disclosure and misuse of assets to theft, process corruption and sabotage.

This risk is not limited to malicious employees. It can also arise where a person is under pressure, targeted by an external actor, careless about due diligence, attracted by financial incentives or unaware of how their access or knowledge could be exploited.

Organisations should therefore treat insider risk as a people, culture and governance issue, not simply an IT-security issue. Effective controls may include clear rules on secondary employment and conflicts of interest, appropriate access controls, monitoring of privileged access, trusted reporting channels, travel-security guidance, exit processes, and training for people who hold sensitive roles or information. Organisations should also understand the warning signs of when a person may become an insider risk.

Foreign interference beyond government

For government agencies, local authorities, universities, community-facing organisations and businesses with public-sector or international relationships, foreign interference risk is relevant to all engagement activities (donations and sponsorships, gifts and hospitality, foreign delegations, events, media narratives, community consultation and relationships with intermediaries). Decision makers need to understand the risk indicators and have a clear pathway for raising concerns.

The risk is not limited to overt attempts to influence decisions. It may also arise through ordinary-looking relationships that are used to shape access, narratives, community trust or institutional positions over time.

AI and the new information battlefield

Rapid advances in technology, including generative AI, are changing the threat environment. AI-enabled tools can make it easier to create persuasive and targeted narratives, produce convincing deepfakes, amplify polarising content, obscure the source of information and lower barriers to misuse of other technologies. These risks intersect with cyber security, public communications, employee awareness, crisis response and information-integrity controls.

For organisations, the practical question is whether existing policies and controls keep pace with the way technology is being used. That may require reviewing acceptable-use policies, cyber incident response plans, social media and communications protocols, staff training, data handling processes, and arrangements for monitoring and responding to disinformation or threatening content.

Terrorism and violent extremism: preparing for the unlikely

A terrorist attack in New Zealand is assessed as possible, with the most plausible scenario involving a lone actor targeting people in a crowded place using readily accessible weapons. While many organisations will not be directly involved in counter-terrorism work, those responsible for public spaces, events, transport hubs, offices, education facilities, community venues or essential services should consider whether their emergency management and staff training arrangements are current.

Preparedness should be proportionate to the organisation’s role, footprint and risk profile. It may include reviewing physical security, crowded-places planning, incident response, escalation pathways, welfare support and communication protocols.

Five actions leaders should take now

Boards and senior leaders can respond by focusing on a short set of practical actions:

  1. Identify the organisation’s most sensitive information, assets, technology, relationships and people.

  2. Assess which assets or relationships may be attractive to foreign states, proxies or other threat actors.

  3. Clarify senior ownership of national security, geopolitical, sanctions, foreign interference and insider-risk issues.

  4. Apply risk-based due diligence to higher-risk investors, counterparties, suppliers, intermediaries, delegations, end users and beneficial owners.

  5. Strengthen key policies, access controls, staff training and escalation pathways for suspicious approaches or incidents.

How we can help

We can assist organisations to review governance frameworks, prepare enterprise risk assessments, develop due diligence frameworks, and advise on sanctions and export-control risk. We can also help strengthen policies and procedures, support board and executive briefings, assist with incident response, and deliver tailored training for teams with access to sensitive information or sensitive relationships.

In the current environment, resilience depends on understanding the threat, identifying what matters most, and putting proportionate controls around the people, information, assets and relationships that need protection. Organisations that do this well will be better placed to engage internationally and pursue opportunities, while protecting their own interests and New Zealand’s wider security.

Contacts

Related Articles