Skip links
Keynote speech by Judith Collins KC, President Law Commission, New Zealand at TechLaw.Fest 2026

Keynote speech by Hon Judith Collins KC at TechLaw.Fest 2026

TechLaw.Fest 2026
Keynote Speech
Wednesday, 10 September 2026
Hon Judith Collins KC
President of the New Zealand Law Commission


Opening: trust is the foundation

Good morning. It is a pleasure to be here in Singapore for TechLaw Fest, in a room of people who understand that the future is not something that simply happens to us. It is something we shape — through law, through institutions, through technology, and through the trust we ask citizens to place in us.

I come to this subject not as a technologist, but as someone who has had to make decisions about public power in the real world. In New Zealand, I am the President of the Law Commission, an independent Crown entity whose role is to review the law and recommend reform where the law is outdated, unclear, inefficient, or no longer serving New Zealand well. The Commission does not make policy for the government and it does not pass legislation. Its task is more careful and deliberately independent: to examine an area of law, identify the problem, consult widely with those affected, test options against legal principle and practical reality, and then provide evidence-based recommendations to the Minister and, ultimately, to Parliament. That process matters because good law reform is not simply about changing words on a page. It is about understanding how law works in people’s lives, how institutions apply it, and how reform can improve fairness, clarity, accessibility, and public confidence.

Prior to this role, I have also served in 18 separate ministerial roles including as Minister responsible for Defence, for the intelligence and security agencies, for Science, Innovation & Technology, for digitising government services, and for the Public Service. I have also served as Attorney-General.

Those roles have taught me that government cannot separate innovation from legitimacy, security from liberty, or efficiency from accountability. In public office, the question is never simply whether a technology can be used. The question is whether it should be used, on what terms, under whose authority, with what safeguards, and in whose interests.

The question before us is not whether artificial intelligence will change government. It already is. The question is whether government will shape that change with confidence — not the confidence of haste, not the confidence of fashion, but the confidence that comes from legitimacy, competence, accountability, and public consent.

Singapore is a fitting place for that question. It is a country known for state capacity, digital ambition, and comparatively high public trust. The latest Edelman Trust Barometer places trust in government in Singapore at 76 percent, making government the most trusted institution in Singapore in that survey. That trust is a national asset. It enables long-term planning, disciplined execution, and the adoption of new systems before every citizen has seen every detail.

But trust is not evenly distributed around the world, and it is not guaranteed even where it is strong. In many societies, public institutions face suspicion, polarisation, misinformation, and a deepening sense among some citizens that government acts at a distance from their lives. In that environment, the words “automated”, “mandatory”, and “black box” can sound less like progress and more like exclusion. If AI is to strengthen government, rather than strain the bond between citizen and state, confidence must be earned before it is claimed.

The promise of AI in government

AI and automated decision-making can help governments do things they already need to do better. They can reduce waiting times, detect patterns that humans may miss, support frontline staff, improve accessibility, translate information, triage demand, identify risk, and personalise services. In the best cases, these tools can make public services faster, more consistent, and more responsive.

That is not a small prize. Citizens do not experience government as an abstract constitutional idea. They experience it when a permit is approved, a benefit is paid, a passport is renewed, a border process is completed, a hospital appointment is scheduled, a police report is handled, or a business regulation is applied. If AI can help deliver those services more accurately, more quickly, and more fairly, then government has a responsibility to consider it.

But the public sector is not the same as the private sector. A consumer can usually stop using a product. A citizen often cannot opt out of government. That asymmetry matters. When government uses AI, it does so with public power, public data, and public consequences. That means the standard is not merely whether the system works. The standard is whether it is lawful, fair, explainable, secure, accountable, and worthy of public confidence.

This point is not abstract. The United Kingdom’s recent experience with digital identity is a reminder that even a proposal presented as modern, efficient, and administratively sensible can encounter deep public resistance if it is perceived as compulsory, centralising, or insufficiently protective of civil liberties. After plans were announced for digital ID to become mandatory for right-to-work checks, thousands of protesters marched in London, and subsequent reporting indicated the government moved away from making the digital identity document mandatory for workers. That sequence matters because it shows how quickly the politics of trust can overtake the logic of efficiency.

Other countries have taken a different route: building digital identity as a service people choose because it is useful, secure, and convenient, while preserving alternatives for those who cannot or do not wish to use it. Voluntary or opt-out models are not perfect; in practice, convenience can still become pressure. But they begin from a different democratic instinct. They say to the citizen: we will make the digital path good enough that you want to use it, not so compulsory that you must.

Trust is not sentiment; it is earned through systems

One lesson from Singapore’s own public sector thinking is that trust is not simply a warm feeling toward government. It is built through competence, integrity, fairness, and respect for process. People may accept a difficult decision if they believe the process was fair. They are less likely to accept even a favourable outcome if they believe the process was arbitrary, hidden, or not genuinely accountable.

The evidence on public trust is remarkably consistent. People trust government when they believe it is competent, honest, fair, and acting in the public interest. Competence matters because citizens judge government by whether it can deliver services well, especially in moments of crisis. Integrity matters because perceived corruption, favouritism, or double standards can quickly corrode legitimacy. Fairness matters because people are more likely to accept even an adverse decision if they believe the process was lawful, even-handed, and open to review.

Transparency, responsiveness, and accountability matter too. People need to understand what government is doing and why; they need to feel that consultation is genuine rather than performative; and they need to see errors acknowledged and corrected when things go wrong. Trust is therefore not created by asking people to have confidence. It is created when institutions demonstrate competence, integrity, fairness, transparency, responsiveness, reliability, and accountability — especially when decisions affect a person’s rights, livelihood, data, or dignity.

This is especially important in the age of AI. Trust in AI cannot rely on mystique. It cannot rest on saying, “the computer says no,” or even “the computer says yes.” Public confidence requires a clear answer to six questions: Who authorised this system? What is it for? What data does it use? Who is accountable for the outcome? How can we be sure it is accurate, reliable and fair? And, finally, how can a person challenge or correct it?

Those questions are not obstacles to innovation. They are the conditions for durable innovation. If government cannot answer them, public trust will eventually move from confidence to suspicion. If government can answer them clearly, AI can become not a threat to trust but a tool for renewing it.

The risks: when automation fails, it can fail at scale

The risks are not theoretical. Around the world, governments and public bodies have seen automated systems produce serious harm when design, oversight, and accountability failed. Australia’s Robodebt scheme became a warning about what happens when automated debt assumptions are pursued without adequate legality, empathy, human review, or practical routes for citizens to contest outcomes. The Netherlands’ SyRI case showed the dangers of welfare fraud risk profiling without sufficient transparency and rights protection. The United Kingdom’s Post Office Horizon scandal reminds us that when institutions defer too readily to technical systems, people can be wrongly accused, disbelieved, and damaged for years.

These examples differ in law, technology, and context, but they carry a common lesson: automation can magnify administrative power. That can be a benefit when the system is accurate and fair. It can be devastating when the system is wrong, biased, poorly explained, or treated as beyond question.

AI also creates particular forms of risk. There is the risk of error: a model may be trained on incomplete, outdated, or poor-quality data. There is the risk of bias: a system may reproduce patterns of disadvantage that already exist in society. There is the risk of automation bias: a human decision-maker may defer to the machine because it appears objective. There is the risk of opacity: people may not know AI was used, or may not understand how it affected them. There is the risk of security failure: automated systems can become attractive targets for cyberattack, data theft, manipulation, and hostile interference.

And there is a democratic risk: if important decisions feel unchallengeable, people may begin to conclude that government is not listening. That is how efficiency can become alienation. That is how a tool meant to improve service delivery can erode confidence in the institution using it.

A framework for confident AI governance

So what does it mean to govern with confidence? I suggest it requires seven disciplines — seven habits of government that make innovation worthy of trust.

First, define the public purpose. Government should be clear about the problem AI is meant to solve. A system should not be adopted because it is fashionable, or because the tool exists, or because efficiency is attractive in the abstract. It should be adopted because it improves a public service, supports lawful decision-making, or helps public servants deliver better outcomes.

Second, test before scaling. AI systems should be piloted carefully, evaluated rigorously, and monitored continuously. The larger the possible impact on rights, entitlements, liberty, livelihood, or dignity, the higher the burden of testing should be. Governments should resist the temptation to scale before they have evidence that a system performs safely across different communities and circumstances.

Third, preserve human accountability. “Human in the loop” should not be a slogan. It should mean a human with real authority, sufficient information, and enough time to question the system. Human review must not become a rubber stamp. The public servant remains responsible for the decision, and the institution remains responsible for the system.

Fourth, make transparency meaningful. People should know when AI or automated decision-making is being used in decisions that affect them. They should be able to understand, in practical terms, what role it played. Transparency does not require publishing every line of code or exposing systems to gaming. It does require clear communication, public registers where appropriate, plain-language explanations, and reasons that can be understood and challenged.

Fifth, build contestability and choice into the design. A person affected by an automated outcome should know where to go, who can help, and how a decision can be reviewed by a human. Where digital identity, automated decision-making, or AI-enabled services become gateways to essential rights or services, governments should be especially cautious about compulsion. Alternatives, opt-outs, and human review are not signs of weakness. They are signs that government understands the difference between convenience and consent.

Sixth, protect privacy, security, and sovereignty. Public sector AI depends on data. Data must be collected lawfully, held securely, used proportionately, and protected from misuse. Governments need strong cyber security, procurement discipline, assurance over third-party systems, and clarity about where data is stored, who can access it, and how models are trained. For New Zealand, this also includes the important question of Māori data sovereignty and the need to honour Te Tiriti o Waitangi in digital governance.

Seventh, consult early and genuinely. People who will be significantly affected by a government’s use of AI systems should have a voice in their design and deployment. The Digital Council for Aotearoa New Zealand’s work on automated decision-making found that people wanted systems built for and with the communities affected by them. That is not merely good process. It is better design.

Why Singapore’s trust advantage matters

Singapore begins from a position many governments would envy. In the 2026 Edelman Trust Barometer, conducted in late 2025, government trust in Singapore was reported at 76 percent — a striking trust advantage when many countries are dealing with scepticism, polarisation, and distrust of public institutions. High institutional trust gives government the ability to move quickly, coordinate policy, invest in infrastructure, and ask citizens to accept innovation before every detail is familiar. That is a strategic advantage in the age of AI.

What is especially striking is that Singapore’s trust in government did not collapse after the COVID pandemic. On Edelman’s figures, it rose from about 70 percent before COVID-19 to the mid-to-high 70s during and after the pandemic, remaining around 76 to 77 percent in recent surveys. That suggests not simply inherited trust, but trust reinforced through performance — and therefore trust that must continue to be protected as government moves into AI-enabled public services.

The contrast with comparable countries is important. Across many democracies, the pandemic period produced a short-lived rally in trust, followed by frustration with cost-of-living pressures, polarisation, misinformation, and doubts about competence, with the OECD and Edelman reporting point to lower or more fragile trust settings across the United Kingdom, the United States, Australia, New Zealand, and Canada than in Singapore. Australia’s trust in government was reported at about 45 percent in 2023, down from 2022; Canada sat around neutral at about 51 percent; the United States was lower again at about 42 percent; and New Zealand’s public sector trust, while stronger than some, rose sharply during the pandemic and then settled back closer to 60 percent. In the United Kingdom, official survey work has also found that people tend to trust institutions such as the courts, police, and civil service more than national government, Parliament, or political parties.

But trust should not be treated as a blank cheque.  It is not a right. It is better understood as capital: built slowly, spent carefully, and replenished through performance and accountability. A high-trust government may be able to move faster, but precisely because it can move faster, it must also show the discipline to move wisely.

For Singapore, the question is not whether government can deploy AI or digital systems. Clearly it can. The question is how to use that capability in a way that deepens public confidence rather than simply consuming it. That means being transparent before controversy arises, building challenge rights before mistakes occur, and designing systems for those who may be less digitally confident, less powerful, or less trusting. It also means remembering the lesson from digital identity debates elsewhere: people are more likely to trust a system they can understand, question, and, where appropriate, choose.

High-trust societies can sometimes face a subtle danger: because people tend to accept institutions, problems may be noticed later. A high-trust environment therefore needs not fewer safeguards but excellent safeguards, because the public may reasonably expect the government to have done the hard work in advance.

New Zealand perspectives

From New Zealand’s perspective, we are still mapping the full extent of automated decision-making across government. Some legislation expressly authorises automated electronic systems, but that is not the case for all uses. This means visibility matters. If government itself cannot easily explain where and how automated systems are being used, it will struggle to explain that to the public.

We also have legal and constitutional features that shape our approach. The Official Information Act and the Privacy Act have helped promote public trust by creating expectations of openness, access, correction, and lawful handling of personal information. New Zealand’s Treaty of Waitangi adds a distinctive dimension: Māori rights, interests, participation, and data sovereignty must be considered in the design and governance of digital systems.

Recent New Zealand research shows a public that is digitally engaged but cautious. Many people see the internet positively, but there is scepticism about online information, concern about privacy and security, and uncertainty about whether AI can be effectively regulated. Those concerns should not be dismissed as fear of technology. They are signals about what government must do to make innovation legitimate.

Australia’s Long-term Insights Briefing on AI and public service delivery is also useful. It identifies integrity, competence, empathy, and improved service performance as central to trustworthiness. That word “empathy” is important. Public services are not merely transactions. They often arrive at moments of vulnerability, stress, need, or uncertainty. AI may assist the public servant, but it must not extinguish the human quality of public service.

Law, courts, and accountability

Law has a vital role to play, but we should not pretend that courts alone can solve this problem. Judicial review, privacy law, human rights law, information law, contract, procurement rules, and administrative law principles all have something to contribute. But legal remedies are often slow, retrospective, and dependent on people knowing enough to complain.

Cases overseas illustrate the range of issues. Pintarich in Australia raised questions about computer-generated tax correspondence. Bridges in the United Kingdom considered live automated facial recognition by police. Johnson involved automated welfare payments. Haghshenas in Canada concerned visa decision-making supported by an Excel-based tool. Loomis in the United States involved a risk assessment tool in sentencing. The SyRI case in the Netherlands concerned welfare fraud risk profiling. Each arose in a different legal system, but collectively they show courts grappling with the same underlying challenge: how to ensure that automated systems remain subject to law.

In New Zealand, there is limited direct case law on the legality of automated decision-making. But the Court of Appeal has recognised, in the context of automatically produced criminal history reports, that computerised systems may still involve exercises of executive power that are amenable to review. That is an important principle. Government cannot avoid accountability by placing a machine between the citizen and the state.

In New Zealand, D’Arcy-Smith v Chief Executive of the Ministry of Social Development [2024] NZHC 1550,  the High Court confirmed the Ministry of Social Development had breached one of the information privacy principles in the Privacy Act 2020 when an automated system erroneously issued two automatic debt collection letters based on incorrect information. (Although it was found not to be an interference with privacy in the circumstances, because it had not had a significant impact on the recipient.)

This case (although earlier and in a lower court) is another example of the courts recognising that government agencies remain accountable for actions taken by automated systems.

Cyber security: the unseen foundation of trust

AI governance must also be cyber security governance. In the digital state, cyber security is not a technical back-office function. It is one of the foundations of public trust. Public sector systems hold information that is valuable, sensitive, and sometimes deeply personal. They also support services on which people depend: identity, borders, taxation, welfare, health, justice, education, and infrastructure. If those systems are compromised, the harm is not limited to privacy breaches. It may include manipulated decisions, denial of services, operational disruption, strategic vulnerability, and a loss of confidence in the ability of government to protect its citizens.

Governments around the world need to be fully alive to this danger. A cyber failure in government is not just an IT incident. It can become a constitutional and political event. When citizens are told to trust digital identity systems, automated eligibility assessments, AI-supported policing, online health portals, or digital tax platforms, they are being asked to trust that the state can keep those systems safe. If that trust is broken, the damage can last long after the system is restored.

The threat comes from more than one direction. Criminal hackers may seek money, data, disruption, or leverage. Ransomware attacks can close services, expose personal information, and force governments into urgent decisions under pressure. Fraudsters can use AI to impersonate officials, deceive citizens, or exploit public systems at scale. At the same time, foreign governments and state-backed actors may seek strategic advantage: intelligence collection, interference, coercion, sabotage, or the quiet erosion of confidence in public institutions.

That is why cyber security in the age of AI is also a question of sovereignty. It asks whether government understands who has access to public data, where systems are hosted, how vendors are assured, how models are protected, and how quickly the state can detect, respond to, and recover from compromise. It asks whether the public sector is prepared not only for failure, but for adversaries who will deliberately exploit failure to weaken trust.

Governments therefore need resilience by design. That includes secure architecture, independent assurance, supply-chain scrutiny, incident response plans, audit logs, identity and access controls, procurement standards, red-teaming, and clear accountability when third-party systems are used. It also includes the ability to operate safely when a system fails. If government cannot pause, override, isolate, or fall back from an AI-enabled system, it has not governed the risk.

Sovereignty is another part of resilience. Countries will make different choices about data localisation, cloud services, model development, international standards, procurement, and strategic dependency. But every government should be able to answer a basic question: when we use AI in public services, who ultimately controls the data, the model, the decision pathway, the security response, and the accountability?

Governing with confidence: a practical agenda

If I were to reduce the challenge to a practical agenda, I would put it this way.

  • Create a clear inventory of public sector AI and automated decision-making systems, beginning with higher-impact uses.
  • Classify systems by risk, with stronger obligations where decisions affect rights, benefits, liberty, enforcement, or access to essential services.
  • Require impact assessments before deployment, including privacy, human rights, bias, security, accessibility, and affected-community perspectives.
  • Maintain human accountability for significant decisions, with genuine human review and the ability to override or bypass the system.
  • Ensure public notice, plain-language explanations, and meaningful reasons when AI materially contributes to a decision.
  • Build accessible challenge pathways so people can correct errors and seek review without needing technical expertise.
  • Audit systems after deployment, publish appropriate assurance information, and remove or redesign systems that do not perform as promised.
  • Invest in public service capability so officials understand the systems they procure, deploy, monitor, and explain.
  • Consult affected communities early, including indigenous peoples and groups likely to face disproportionate impact.
  • Treat cyber security, procurement, and sovereignty as core governance issues, not technical afterthoughts.

This agenda is not anti-innovation. It is pro-confidence. It recognises that government can move fastest when people believe it is moving carefully, honestly, and in the public interest. The lesson for the age of AI is simple: the strongest systems are not those that make people powerless before the machine; they are those that give people confidence that the machine remains subject to law, to judgment, and to human dignity.

Conclusion: confidence must be earned again and again

Let me end where I began: with trust. In Singapore, trust in government is a strength — a hard-won national advantage. In many parts of the world, trust is thinner, more contested, and more easily lost. But in every country, trust is the currency of legitimate government. It is what allows public power to be exercised not merely with authority, but with consent.

AI will test that trust. It will ask whether governments can innovate without overreaching, automate without dehumanising, and move quickly without leaving citizens behind. It will ask whether the state can use tools of extraordinary power while still remaining recognisably human in judgment, accountable in action, and humble in the face of error.

The wrong lesson would be to step back from AI altogether. The equally wrong lesson would be to rush forward on the assumption that efficiency will be enough. Efficiency without legitimacy will not endure. Innovation without accountability will not persuade. And digital systems that people cannot understand, challenge, or, where appropriate, choose, will not strengthen democratic confidence.

So the task before us is clear. We must build AI governance that is worthy of public trust before public trust is asked to carry it. We must keep law close to power, people close to decisions, and accountability close to every system that acts in the name of the state. If we do that, AI can help government become not colder, but more capable; not more remote, but more responsive; not less accountable, but more deserving of confidence. That is what it means to govern with trust and confidence in the age of AI.