Yes, with conditions. A licensed adviser may use AI to draft, but pasting a client’s identifying details into a consumer tool that trains on your inputs is hard to reconcile with IPP 5 of the Privacy Act 2020 and clause 4 of the Code. Use no-training tools, and review everything.
Key facts
| Question | Short answer |
|---|---|
| Is AI drafting prohibited for licensed advisers? | No. Neither the Immigration Advisers Licensing Act 2007 nor the Code of Conduct 2014 mentions AI. |
| Which law bites first? | Privacy Act 2020: IPP 5 (storage and security), IPP 10 (limits on use), IPP 11 and IPP 12 (disclosure), and Part 6 (notifiable privacy breaches). |
| Which Code clauses are engaged? | cl 1 (due care), cl 4 (confidentiality), cl 26 (file management), cl 27(a) (documents held securely), cl 31(a) (no false or misleading documentation). |
| Is there regulator guidance? | The Privacy Commissioner published expectations for agencies using generative AI on 15 June 2023. We could find no AI-specific IAA guidance as at 10 August 2026. |
| Does the tool matter more than the brand? | Yes. The question is whether your tier’s terms permit the provider to use your inputs for its own purposes. |
| Who owns the output? | You do, professionally. Licences are issued to natural persons, not to firms or to software. |
Can a licensed immigration adviser use ChatGPT to draft immigration documents?
Yes. There is no prohibition anywhere in the licensing regime. The Code of Conduct 2014 predates generative AI and says nothing about it, and we could find no AI-specific guidance from the Immigration Advisers Authority as at 10 August 2026. That silence is not permission. It means the existing obligations apply unchanged: confidentiality, due care, secure handling, accurate records.
The Privacy Commissioner reaches the same place from the other direction. The Office’s position is that “the Privacy Act is technology-neutral and takes a principle-based approach, meaning the same privacy rights and protections apply to generative AI tools that apply to other activities that use personal information”, and that “our starting point is that the Privacy Act applies to everyone using AI tools in New Zealand.”
The real question is what you paste, into what, and what you do with what comes back.
What does the Privacy Act require when you paste client details into an AI tool?
Three principles engage at once, and all three turn on a single fact: whether the provider may use your input for its own purposes. IPP 5 requires reasonable security safeguards. IPP 10 limits use to the purpose of collection. IPP 11 and IPP 12 govern disclosure. Answer the retention and training question and the rest follows.
IPP 5(b) is the limb advisers usually miss. It requires that where information is given to a person “in connection with the provision of a service to the agency, everything reasonably within the power of the agency is done to prevent unauthorised use or unauthorised disclosure of the information.” Choosing a consumer account with training switched on, when a no-training tier was available to you at the same price or close to it, is a hard thing to describe as everything reasonably within your power.
IPP 10 is the training question stated precisely. The visa file you hold was obtained in connection with progressing an immigration matter. Improving somebody’s language model is a different purpose, and IPP 10 does not permit a new purpose unless one of its listed grounds applies. Authorisation by the individual is one of those grounds, which is why the AI position belongs in your written agreement rather than in your head.
One more principle is newly relevant. IPP 3A came into force on 1 May 2026, and where you collect personal information about someone from a source other than that person, it requires reasonable steps to make them aware of the collection, its purpose, and “the intended recipients of the information”. Immigration practices collect indirectly all the time, from employers, partners, sponsors and INZ. If an AI provider is genuinely a recipient rather than your processor, that is a fact those people may need to be told.
Is sending client information to an AI provider a disclosure, or is the provider your agent?
Often it is not a disclosure. Section 11 of the Privacy Act 2020 applies where one agency (A) holds information “for or on behalf of” another agency (B), including “for safe custody or processing on behalf of B”. The information is then treated as held by B and not A, not by both.
Section 11(5)(a) puts it beyond doubt: “the transfer of the information to A by B is not a use or disclosure of the information by B”.
That protection has one condition, and it is exactly the condition that fails on a consumer account. Section 11(3) says the information “is to be treated as being held by A as well as B if A uses or discloses the information for its own purposes.” Training a model is a use for the provider’s own purposes. Once that is happening you are no longer looking at processing by an agent, you are looking at a disclosure, and IPP 11 has to be satisfied.
If the recipient is offshore, IPP 12 adds a second gate. It permits disclosure only on one of six grounds, including informed authorisation from the individual, reasonable grounds to believe the recipient is subject to privacy laws providing comparable safeguards, or reasonable grounds to believe the recipient must protect the information comparably “pursuant to an agreement entered into between A and B”. Note the direction of travel: a contract is one of the ways you satisfy IPP 12, which is another reason the terms attached to your tier matter more than the badge on the login page. Where the agent analysis does hold, section 11(4) makes clear it does not matter that the provider is outside New Zealand.
Section 11 is genuinely arguable at the edges and is not a substitute for advice on your own arrangements. The safe working rule is the simple one: if the tool may use your inputs for its own purposes, treat it as a disclosure; if it contractually may not, the agent analysis is available to you.
What is the difference between a consumer AI tool and one with no-training terms?
Contract, retention and control. Not the interface, not the model, and not whether you are paying. A personal paid subscription and a business subscription can run the identical model and sit on opposite sides of this line. The only question that matters is what the terms permit the provider to do with your input.
| General consumer tool | Tool with contractual no-training terms | |
|---|---|---|
| Training on your inputs | Permitted unless you opt out | Excluded by the terms of the contract |
| Where the position lives | A settings toggle any staff member can change | An agreement you can produce on request |
| Retention | The provider’s policy, changeable at will | Defined, and zero-retention options exist |
| Data location | Wherever the provider operates | Sometimes specified, often still offshore |
| What you can show an inspector | Browser history | A contract, and a log on the client file |
OpenAI’s published policy states that “by default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Team, ChatGPT Enterprise, and the API”, while consumer ChatGPT may use conversations to improve models unless the user opts out. Two cautions. Product names drift: ChatGPT Team was renamed ChatGPT Business on 29 August 2025, so read the terms attached to your actual account. And the same consumer-versus-business split exists across the major providers under different names.
Retention deserves its own thought. In November 2025 a United States magistrate judge ordered OpenAI to produce roughly 20 million de-identified ChatGPT conversations to the plaintiffs in the New York Times copyright litigation, some months after an earlier blanket preservation order over output logs had been lifted. No privacy policy anticipates litigation of that kind. Keep identifying detail out of the pipe regardless, so that whatever is retained is not about your client.
Which Code of Conduct clauses does AI drafting engage?
Five, and none of them mention technology. Clause 1 requires an adviser to “be honest, professional, diligent and respectful and conduct themselves with due care and in a timely manner”. Clause 4 requires confidentiality, clause 26 requires a complete client file, clause 27(a) requires secure handling, and clause 31(a) prohibits misleading documentation.
Take confidentiality first. Clause 4(b) is the limb that travels: it requires you to “require that any employees or other persons engaged by the adviser also preserve the confidentiality of the client”. Clause 27(a) requires personal documents, “whether held physically or electronically”, to be held securely while in your possession.
Clause 31(a) is where a hallucination stops being an embarrassment and becomes a disciplinary matter. It prohibits an adviser from “deliberately or negligently” providing false or misleading documentation to the decision maker. The negligence limb is the operative word. The Privacy Commissioner’s guidance is blunt that generative AI tools “often produce very confident errors of fact or logic and can perpetuate bias and discrimination”. A submission containing an invented instruction, a misquoted policy or a fabricated date is misleading documentation, and the software having produced it is not one of the exceptions.
Clause 26 cuts both ways, and this is the part advisers underestimate. It requires a client file containing copies of all written communications including file notes of material oral communications, a well-managed filing system, and retention for no less than seven years. The IAA’s own toolkit describes a well-managed file as “a ‘useable trail’ of actions”. Work done in a chat window that never lands on the file is not a record of anything.
In [2026] NZIACDT 35 the Tribunal upheld breaches of clauses 1, 2(e), 18(c), 26(a), 26(b), 26(d) and 31(a) against an adviser whose client communications lived in a consumer messaging app. Her own explanation was that she “became too confident and lost her records when the phone was lost”, and she “admitted negligence in file keeping”. Substitute a chat history for a phone and the failure mode is identical.
What should never be pasted into a general consumer AI tool?
The test is not “is there a name in it”. It is whether the material, alone or in combination, identifies a real person. Immigration files identify people through combinations of attributes far more often than through names, which is why redaction is not anonymisation.
| Keep out of a general consumer tool | Why |
|---|---|
| Passport, visa and client numbers, addresses, dates of birth | Direct identifiers; IPP 5 and cl 27(a) |
| Medical certificates, x-ray results, health history | Sensitive information, and s 113(b) makes sensitivity a factor in whether a breach is notifiable |
| Relationship evidence, statutory declarations, private correspondence | Identity is carried by the narrative, not the name |
| Police certificates and character disclosures | High potential for serious harm if exposed |
| INZ correspondence including PPI letters, pasted in full | Carries the applicant’s identifiers and INZ’s own file references |
| Employer payroll, job check and accreditation material | Personal information about people who are not your client |
| Anything about a partner, dependent child, sponsor or referee | Collected indirectly, and they never chose your AI vendor |
A file note about a chef from a named country in a small town, with a partnership application declined in March, is identifiable with every name removed.
What happens if an AI tool causes a notifiable privacy breach?
Part 6 of the Privacy Act applies exactly as it would to a lost laptop. A privacy breach includes unauthorised or accidental access to, or disclosure of, personal information you hold. If it is reasonable to believe the breach has caused, or is likely to cause, serious harm to an affected individual, it is a notifiable privacy breach.
Section 114 then requires you to notify the Privacy Commissioner “as soon as practicable after becoming aware” of it, and section 115 requires you to notify the affected individual, subject to the stated exceptions. Section 113 lists the factors you must consider when assessing serious harm, including whether the information is sensitive and whether it was protected by a security measure. Failing to notify the Commissioner is an offence under section 118 carrying a fine of up to $10,000, and it is expressly not a defence that you have since taken steps to address the breach.
The practical consequence is unglamorous. If you cannot say what was pasted, by whom, on which account and about which client, you cannot run the section 113 assessment at all, so you cannot properly form the view that a breach is not notifiable. An unlogged workflow does not only create risk, it removes your ability to reason about it.
Who is responsible for the output, and what does a defensible workflow look like?
You are, personally. Section 10 of the Immigration Advisers Licensing Act 2007 permits a licence only where “the person is a natural person”. The licence is not held by your firm and it is certainly not held by a vendor. A defensible workflow is therefore one that keeps a person in the decision, and leaves a record of it.
The New Zealand Law Society’s generative AI guidance, which does not bind licensed advisers but is the closest professional-standards analogue, puts the point plainly: “a lawyer is not absolved from responsibility for legal advice or defects in an end-product (such as a contract) because it is derived from Gen AI.” The Courts of New Zealand issued guidelines for the use of generative AI in courts and tribunals on 7 December 2023, in separate versions for judicial officers, for lawyers and for people without a lawyer.
The Privacy Commissioner’s eight expectations for agencies adopting generative AI translate almost directly into a practice policy: senior leadership approval, a check that the tool is necessary and proportionate, a Privacy Impact Assessment, transparency, engagement with Māori, procedures about accuracy and access, human review prior to acting, and this, which is the operative rule:
“Do not input into a generative AI tool personal or confidential information, unless it has been explicitly confirmed that inputted information is not retained or disclosed by the tool provider.”
In practice that comes down to five habits. Decide at practice level which tools are approved and on which tier, and write it down. Put the AI position in the written agreement clause 18 already requires, including whether a client may decline AI assistance. Strip or tokenise identifiers before anything leaves your systems, and treat a failure of that step as a stop rather than a warning. Keep the prompt context, the draft and the final version on the client file, so clause 26 is satisfied by the work rather than by somebody’s memory. Read every output against the source material before it goes anywhere.
Practice systems can carry part of this. Clerq substitutes identifying details before any model call, refuses the request if that step is unavailable, and versions each draft onto the matter; our compliance page sets out which clauses the system touches and which it does not. That reduces the surface area. It does not discharge an obligation, and no software can. The review gate is still a person with a licence.
This article describes practice-management and privacy obligations. It is not legal advice and it is not immigration advice. Take advice on your own arrangements before you settle a policy.
Frequently asked questions
Is it a privacy breach to paste a client’s name into ChatGPT? Not automatically, but it can be. If the provider uses your input for its own purposes, section 11(3) of the Privacy Act 2020 treats the information as held by the provider as well as by you, and you then have to justify a disclosure under IPP 11 and IPP 12. On a consumer account with training left on, that justification is difficult.
Does the Immigration Advisers Authority ban the use of AI? No. As at 10 August 2026 we could find no AI-specific guidance published by the IAA, and the Licensed Immigration Advisers Code of Conduct 2014 does not mention AI. The existing clauses apply in full, particularly clause 1 (due care), clause 4 (confidentiality), clause 26 (file management) and clause 31(a) (no false or misleading documentation).
Does paying for ChatGPT mean my data is not used for training? Not by itself. OpenAI’s published position is that it does not train on inputs or outputs from its business products by default, while consumer ChatGPT may use conversations for training unless you opt out. A personal paid plan is not a business plan. Check the tier your account is actually on.
Do I have to tell clients that I use AI? The Privacy Commissioner’s published expectation is that if a generative AI tool is used in a way likely to impact clients and their personal information, they must be told how, when and why. Putting it in the written agreement required by clause 18 is the practical way to do that.
Can I use AI to draft a file note? Yes, as a draft. Clause 26(a)(iii) requires file notes recording material oral communications, and clause 26(c) requires you to confirm material discussions in writing to the client. A note you have read, corrected and adopted is a record. A generated note nobody checked is a liability.
Is AI output my work? Professionally, yes. Under section 10 of the Immigration Advisers Licensing Act 2007 only a natural person may be licensed, so responsibility sits with you personally. The Law Society’s guidance for lawyers puts the analogous point plainly: a lawyer is not absolved from responsibility for defects in an end product because it came from generative AI.
Sources
- Office of the Privacy Commissioner, Generative Artificial Intelligence (15 June 2023). Checked 10 August 2026.
- Office of the Privacy Commissioner, Artificial intelligence topic page. Checked 10 August 2026.
- Privacy Act 2020, s 11 (personal information treated as being held by another agency in certain circumstances). Checked 10 August 2026.
- Privacy Act 2020, s 22 (the information privacy principles, including IPP 3A, 5, 10, 11 and 12). IPP 3A was inserted on 1 May 2026 by s 4 of the Privacy Amendment Act 2025. Checked 10 August 2026.
- Privacy Act 2020, Part 6 (notifiable privacy breaches, ss 112 to 118). Checked 10 August 2026.
- Office of the Privacy Commissioner, IPP 5 (storage and security). Checked 10 August 2026.
- Office of the Privacy Commissioner, IPP 12 (disclosure outside New Zealand). Checked 10 August 2026.
- Immigration Advisers Licensing Act 2007, s 10 (who may be licensed as an immigration adviser). Checked 10 August 2026.
- Licensed Immigration Advisers Code of Conduct 2014 (PDF). Checked 10 August 2026.
- Immigration Advisers Authority, Code of Conduct toolkit: file management. Checked 10 August 2026.
- INZ (Kindl) v Zhou [2026] NZIACDT 35 (PDF). Checked 10 August 2026.
- New Zealand Law Society, Generative AI guidance for lawyers. Not binding on licensed immigration advisers; cited as the closest professional-standards analogue. Checked 10 August 2026.
- Courts of New Zealand, Guidelines for use of generative artificial intelligence in courts and tribunals (7 December 2023). Checked 10 August 2026.
- OpenAI, How your data is used to improve model performance. Checked 10 August 2026.
- OpenAI Help Centre, ChatGPT Business rename FAQ. Checked 10 August 2026.
- Bloomberg Law, OpenAI must turn over 20 million ChatGPT logs, judge affirms, with background in Engadget, OpenAI no longer has to preserve all of its ChatGPT data (11 October 2025). Checked 10 August 2026.
Published 10 August 2026. This is a plain-English guide for licensed advisers, not legal advice. Where it cites the Code of Conduct, the Immigration Act or the Privacy Act, read the source it links to rather than this summary of it.