Health and Safety at Work Amendment Act 2026
Since we published the Winter 2026 edition of Commercial eSpeaking, the Health and Safety at Work Amendment Act 2026 has received Royal Assent and will come into force on 1 April 2027.
The Act introduces ‘critical risk’ as a defined concept – being risks associated with hazards under Schedule 1A or risks likely to result in death, notifiable injury, illness, incident or occupational disease, and requires businesses to prioritise managing these risks above others.
If you employ fewer than 20 people, your health and safety duties will narrow specifically to critical risks, rather than covering every possible workplace risk. You’ll still need to meet baseline obligations, including providing adequate employee facilities (for example: toilets, drinking water and hand-washing facilities) but this change is intended to reduce the compliance burden for smaller businesses.
The Act also clarifies the duty owed by a Person Conducting a Business or Undertaking (PCBU) where its workplace includes outdoor space used for recreation. In specified circumstances, the PCBU will not owe the usual section 37 duty to people entering and using that space for recreational purposes, unless:
- The recreational use is part of a PCBU’s business or undertaking, or
- Other work connected to a business or undertaking conducted by the PCBU is being carried out at the time in the outdoor space near where the entry and use are taking place.
If your business already complies with industry-specific legislation, the Act confirms this will satisfy your obligations under the Act too, without needing to separately comply with the Act.
Businesses should begin reviewing their health and safety processes and policies now, ahead of the 1 April 2027 commencement date.
AI in the workplace
AI tools are becoming a standard part of many workplaces, used for everything from drafting documents to customer service and research. Used safely, AI may increase efficiency, but it is important to manage the associated risks and put the right safeguards in place.
Some key risks in practice include, without limitation:
- Confidentiality: Trade secrets or confidential information entered into an AI tool could be disclosed, retained or used to train the tool
- Privacy: Entering personal information into an AI tool may amount to a disclosure under the Privacy Act 2020
- Intellectual property: AI-generated content isn’t automatically free of copyright issues, and outputs may infringe someone else’s protected work, and
- Human oversight and transparency: AI output should be reviewed before it’s relied on, to guard against errors, bias or hallucinated content.
Some practical controls may include, without limitation:
- Paid subscriptions: Paid subscriptions to AI tools generally offer stronger safeguards than free versions, but your business will need to check the specific terms that apply
- Data audit: To take stock of what data the business holds, who can access it and whether use of an AI tool would give people wider access than they’re meant to have, and
- AI policy: To set clear expectations around which AI tools are approved for use, what types of information staff can and cannot put into them and the process for reviewing and signing off on AI-generated output before it’s relied on.
There is more guidance in the Ministry of Business, Innovation and Employment’s publication Responsible AI Guidance for Businesses. Click here to read it.
AI in the boardroom
A recent Federal Court of Australia decision has offered a timely warning on AI’s growing role in the boardroom.[1] The court also commented on AI use, warning that AI-generated summaries are not a substitute for directors actually reading and engaging with board materials themselves.
While the decision is not binding in New Zealand, directors here are subject to their own duty of care under the Companies Act 1993 that requires directors to exercise the care, diligence and skill of a reasonable director.
This duty applies regardless of whether AI is involved in a director’s decision-making process. If a director relies heavily on an AI-generated summary without checking it against the underlying material, they may struggle to demonstrate that they exercised the care, diligence and skill required by the Act.
As AI becomes more prominent in board processes and decision-making, this is a useful reminder that directors must properly engage with information and exercise independent judgement rather than relying solely on AI-generated material.
Reporting, liability and disclosure changes for consumer credit providers
On 1 July 2026, the Financial Markets Authority (FMA) took over responsibility for regulating the Credit Contracts and Consumer Finance Act 2003 (CCCFA) from the Commerce Commission. As part of this change, consumer credit providers including banks, credit unions and other lenders are now licensed under the Financial Markets Conduct Act 2013 (FMCA).
Reporting
Section 412 of the FMCA requires licensees to inform the FMA as soon as they believe they’ve breached, or are likely to breach, a licence obligation or if there has been, or is likely to be, a material change in circumstances, or where certain particulars are false or misleading.
While other types of FMCA licensees have been subject to this for years, this is new for consumer credit providers who have not had to comply with this until now. The obligation to report arises as soon as the licensee believes a breach may have happened or may be about to happen. Getting this timing wrong, or failing to report at all, can result in a penalty of up to $600,000.
Director and senior manager liability
Directors and senior managers of consumer credit providers no longer have a personal due diligence obligation under the CCCFA. Personal liability arises instead under the existing FMCA regime and requires involvement in a breach.
Disclosure
Under the CCCFA, courts may order a debtor not liable for borrowing costs where appropriate disclosures have not been made by consumer credit providers. This is triggered by way of application from a debtor or the FMA, where courts may consider factors including, without limitation, the provider’s compliance programmes and prejudice caused to the debtor.
For more detailed information about these changes, click here.
[1] ASIC v Bekier (Liability Judgment) [2026] FCA 196.