Why Your AI Architecture Must Understand Māori Data Sovereignty
Previous: [Chapter 13 — The Agentic Asset Register: Building Your Inventory Before the Auditors Do]Next: [Chapter 15 — Technical Implementation of Data Sovereignty Controls (Thursday, 21 May 2026)]
On 1 May 2026, five governments co-signed the most thorough agentic AI security guidance published to date. NCSC NZ is a named co-author. The "Careful Adoption of Agentic AI Services" document, released jointly by the Five Country Council, identifies five distinct risk categories, 23 individual risks, and more than 100 best practices for organisations deploying AI agents across critical infrastructure. It is technically sound, well-targeted, and directly relevant to the architecture this book has been building across its first thirteen chapters.
It says nothing about tikanga.
That absence is not a flaw in the document. The Five Country Council guidance addresses the security architecture of agentic systems. It is scoped for five jurisdictions simultaneously. What makes New Zealand's agentic architecture obligations different from the other four countries' does not appear in joint publications. It appears here.
Your Zero Trust framework probably does not mention tikanga. In New Zealand, that is a problem.
Part Two of this book built the technical and regulatory foundations: NZISM v3.9, MCSS reporting, the agent identity architecture from Chapter 12, and the agentic asset register from Chapter 13. Those foundations are necessary. They are not sufficient. Part Three begins with a question that none of them answers: when an AI agent processes data that belongs to Māori, in a sovereignty sense rather than a records-management sense, what governance obligations apply, and what architecture enforces them?
The answer is not in NZISM. It is not in the EU AI Act. It is not in the NIST Zero Trust Architecture standard. It is in Te Mana Raraunga's Charter of 2018, in six principles that constitute Māori Data Sovereignty governance, and it requires an architectural response, not a checkbox.
Section A: What Māori Data Sovereignty Actually Means
The first thing to get right is the distinction between data about Māori and data of Māori. They are not the same. Conflating them is the most common architectural error organisations make when they begin engaging with Māori Data Sovereignty.
Data about Māori is data that describes, records, or analyses Māori people, communities, or land. Census figures on iwi population. Health statistics disaggregated by ethnicity. Geographic boundaries of rohe. This data is collected and held by organisations, agencies, and institutions. It is subject to the Privacy Act 2020, NZISM v3.9 classification requirements, and standard data governance obligations. It describes Māori; it does not belong to Māori in the governance sense that Māori Data Sovereignty addresses.
Data of Māori is different in kind, not only in sensitivity. Whakapapa records. Mātauranga Māori — the traditional knowledge systems of specific iwi and hapū. Oral histories encoded in digital form. Environmental monitoring data over taonga species. Imagery of culturally significant sites. This data does not merely describe Māori communities; it expresses relationships, carries obligations, and holds cultural significance that no data classification schema captures. It is, in the language Te Mana Raraunga uses, taonga: treasure that requires guardianship, not just governance.
The distinction matters architecturally because it changes the question. For data about Māori, the question is: who can access it, under what conditions, and with what protections? The Privacy Act 2020 and NZISM v3.9 address that question, at least in part. For data of Māori, the question is different: who holds governance authority over it, and under what principles may any access occur? That question is not answered by classification standards. It requires engaging with the governance traditions and institutions that hold the authority.
Te Mana Raraunga was established in 2015 and formalised its foundational governance document, the Charter, in 2018. The Charter is the authoritative statement of Māori Data Sovereignty principles in Aotearoa. Te Mana Raraunga is not a government body; it is a Māori-led initiative that asserts and operationalises Māori communities' rights to exercise authority over Māori data. Te Kahui Raraunga, the Iwi Data Network established subsequently, operationalises those principles at the iwi level, providing the institutional structure through which iwi-specific data governance arrangements are built and maintained. [1][2] The two bodies work in complementary roles: Te Mana Raraunga sets the principles; Te Kahui Raraunga implements them within iwi-specific contexts.
The Office of the Privacy Commissioner published Māori Data Guidance in 2023, setting out the OPC's position on the Privacy Act 2020's interoperation with Māori Data Sovereignty principles. [3] The guidance is clear: the Privacy Act provides a baseline but does not displace iwi or hapū data governance arrangements. The two frameworks apply simultaneously. The OPC's guidance is the authoritative interpretive source for the Privacy Act intersection; it is not a substitute for direct engagement with Te Mana Raraunga and Te Kahui Raraunga. Separately, the Biometric Processing Privacy Code 2025 (August 2025) reinforces the position: organisations collecting biometric data from Māori are expected to consider tikanga Māori and Māori Data Sovereignty principles as part of their proportionality assessment.
This is the structural gap that Part Three addresses. No international Zero Trust framework, no agentic AI architecture guide, and no current security standard captures the co-existence of a statutory privacy regime and a parallel governance system grounded in Te Tiriti o Waitangi. New Zealand architects must hold both simultaneously. Part Three gives them the architecture to do so.
Section B: Why International Frameworks Miss This
The NIST Zero Trust Architecture, Special Publication 800-207, defines seven tenets and addresses identity, devices, networks, applications, and data. Data classification is the product of an organisational policy process: define sensitivity levels, classify accordingly, control access by classification. The model is technically sound and internationally applicable. It does not account for data whose governance authority rests with a group of people whose rights predate the organisation that holds the data.
The EU AI Act establishes risk categories for AI systems, mandates conformity assessment for high-risk applications, and imposes transparency requirements. It does not have a mechanism for recognising indigenous data governance as a constraint on model training or inference.
The CSA Agentic Trust Framework, which Chapter 12 drew on for its three-tier agent classification model, provides a useful architecture for agent governance. Its scope is security governance: authentication, authorisation, and audit. Cultural governance is outside its scope by design; frameworks built for cross-jurisdictional applicability cannot incorporate cultural specificity without losing generality.
NZISM v3.9 is the closest domestic parallel. It is the canonical New Zealand Government information security baseline and the most technically demanding domestic standard an organisation operating under NZISM must meet. NZISM v3.9 does not currently codify cultural security obligations specific to Māori data. That is a statement of the standard's scope, not a deficiency. The gap between NZISM's scope and the full scope of an organisation's obligations toward Māori data is what the Cultural Security Envelope concept addresses. The Cultural Security Envelope, introduced here as an architectural pattern across Part Three, extends NZISM-style baseline thinking to incorporate cultural security obligations that NZISM does not currently codify. Both the NZISM baseline and the Cultural Security Envelope apply; neither replaces the other.
Privacy Act 2020 amendments, including the notification obligations for indirect collection that commenced 1 May 2026, represent a significant expansion of organisational obligations toward Māori data. AI agents that derive Māori data through inference, aggregation, or secondary processing now trigger notification requirements. The mechanism is timely and technically significant. Those obligations address when organisations must notify data subjects; they do not address who holds governance authority over collectively significant data. Both the Privacy Act's notification framework and tikanga governance apply; neither substitutes for the other.
The absence of cultural governance in international frameworks will not be filled by the next standard revision. It is a structural condition of those frameworks: universal applicability requires abstraction away from cultural specificity. New Zealand's obligations toward Māori data are not abstract. They require a local supplement to every international framework the organisation applies.
Section C: Tikanga as a Governance Architecture
The word "tikanga" is sometimes translated as "custom" or "protocol." That translation understates what tikanga is. Tikanga is a governance system: a set of principles, obligations, and relational commitments that structure how decisions are made and how responsibilities are held. Applied to data, tikanga does not ask "is this access permitted under our policy?" It asks "does this access honour the relationships and obligations this data carries?"
Te Mana Raraunga's Charter 2018 establishes six principles. Read architecturally, they function as a governance specification. The mapping below is an interpretive exercise, not an authoritative one. These are the architectural readings that the principles support, based on Andreas Hamberger's analysis of their governance implications for AI systems. They do not represent a statement of what Te Mana Raraunga has mandated for IT infrastructure.
Rangatiratanga is the principle of authority and self-determination. Māori have the right to govern Māori data. Read architecturally: governance authority over taonga data originates with iwi and hapū; it is not delegated to them by organisations that hold the data. The organisation operates as a custodian under that authority, and the data governance structure must reflect that relationship. An organisation that consults Māori communities about data governance decisions while retaining final authority has not implemented rangatiratanga. An organisation that establishes iwi governance structures with binding authority — not advisory roles — has begun to do so.
Whakapapa is the principle of relational connection and genealogy. Data exists within relationships. A health record is not an isolated datum; it connects a person to whānau, to land, to cultural context. Whakapapa in the data architecture context means contextual integrity must be maintained: data cannot be processed in isolation from the relationships it expresses. Aggregating Māori health records and inferring patterns without engagement with the relational context in which those records were generated breaks the whakapapa connection. Architecturally, this imposes obligations on data lineage tracking, on how records are combined, and on the scope of inference permitted from collected data.
Whanaungatanga is the principle of relational obligation. Relationships carry responsibilities; access to data creates an obligation that persists beyond the transaction. An AI agent that reads a whakapapa record does not merely consume data. It incurs an obligation to the people whose relationships that data expresses. Architecturally, this means audit trails are not merely compliance artefacts. They are records of obligations incurred. An agent access log, in a whanaungatanga governance framework, is a record of responsibility assumed, not only activity tracked.
Kotahitanga is the principle of collective benefit and unity. Māori data governance must benefit Māori communities collectively, not merely the individuals whose records are held. A health record from a single individual may also be a record about their whānau, their hapū, their iwi. Individual consent mechanisms do not address the collective governance dimension. Organisational architectures that rely exclusively on individual consent for Māori data are, from a kotahitanga perspective, incomplete. Iwi and hapū governance structures must participate in access decisions that carry collective significance.
Manaakitanga is the principle of care, generosity, and reciprocity. Governance must express affirmative care and respect toward those whose data is held, not merely compliance with minimum standards. Architecturally, the target is not breach avoidance. It is stewardship: data handling that actively demonstrates care for the communities whose data is held. This is the difference between a governance framework designed to avoid breach and a framework designed to demonstrate ongoing responsibility.
Kaitiakitanga is the principle of guardianship across generations. The stewardship obligation is not discharged at the point of collection. It persists for as long as the data exists. Data retention policies, disposition schedules, and archival decisions are all kaitiakitanga questions. An organisation that collects Māori data, uses it, and disposes of it without iwi engagement in the disposition decision has not fulfilled its kaitiakitanga obligations, even if it has met every other governance requirement.
| Principle | Governance Meaning | Architecture Decision |
|---|---|---|
| Rangatiratanga | Governance authority held by iwi and hapū; not delegated to them | Custodian model: iwi governance structures hold binding authority; organisational policy operates within those constraints |
| Whakapapa | Data exists within relational context; cannot be processed in isolation | Contextual integrity controls; data lineage tracking; scope-of-inference limits |
| Whanaungatanga | Access creates obligations that persist beyond the transaction | Audit trails as obligation records; access logs linked to iwi governance accountability |
| Kotahitanga | Collective benefit required; individual consent insufficient for collectively significant data | Iwi and hapū governance participation in access decisions |
| Manaakitanga | Affirmative stewardship, not minimum compliance | Governance framework designed to demonstrate care; positive stewardship standard |
| Kaitiakitanga | Generational obligation; persists across full data lifecycle | Iwi input required for retention, archival, and disposition decisions |
Section D: The Agent Identity Connection
Chapter 12 introduced the Agent Registry: every AI agent receives a declared identity before any access to governed resources is permitted. The OPA policy in that chapter included a cultural classification field; cultural_classification returns taonga_whakapapa, taonga_general, or standard. Chapter 13 extended that classification discipline into the agentic asset register, giving the organisation a full inventory of agents, their declared purposes, and their data access scope.
Both chapters introduced the mechanism. This chapter provides the governance specification that gives the mechanism meaning.
A cultural classification of taonga_general is not a label. It is a governance commitment. An agent carrying that classification should be operating under governance arrangements that give effect to all six Te Mana Raraunga principles: rangatiratanga obligations in the authority structure that granted access; whakapapa obligations in the contextual integrity controls that govern what the agent may infer; whanaungatanga obligations in the audit trail that records what the agent did; kotahitanga obligations in the consent architecture; manaakitanga obligations in the stewardship standard; kaitiakitanga obligations in the data lifecycle governance.
Without the foundations this chapter provides, the cultural classification field in the agent registry is syntax without semantics. A label applied and potentially ignored. The tikanga-derived governance framework is what the field must point to.
The Privacy Act 2020 notification obligations for indirect collection, which commenced 1 May 2026, connect directly to this architecture. The agent identity layer established in Chapter 12 makes it possible to attribute those obligations to a specific agent, against a specific data asset, at a specific time. That attribution is what the audit trail captures. Whanaungatanga requires that the audit trail be read not merely as a compliance artefact but as a record of an obligation incurred. The architecture makes both readings simultaneously possible.
The alignment between the Privacy Act's notification framework and Te Mana Raraunga principles is real. It is not equivalence. An organisation that meets its Privacy Act notification obligations but has not established iwi governance structures with binding authority over taonga data has satisfied one framework while remaining outside the scope of the other. Both apply. Both must be addressed.
Te Mana Raraunga Alignment Checklist for Architects
This checklist is a practitioner starting point, not a compliance instrument. No regulatory body has published these questions as a formal standard requirement. They are intended to help architects and governance leads assess whether the six Charter principles have been given meaningful effect in the organisation's data architecture and governance arrangements. The framing below is Andreas Hamberger's interpretive synthesis of the Charter's governance implications for AI systems.
| # | Principle | Assessment Question |
|---|---|---|
| 1 | Rangatiratanga | Have you identified which data assets are taonga, and do iwi governance structures hold binding (not advisory) authority over access decisions affecting those assets? |
| 2 | Whakapapa | Does the data architecture track relational context, and are there controls that prevent processing Māori data in isolation from the relationships it expresses? |
| 3 | Whanaungatanga | Does the audit architecture capture not only which agent accessed which data, but the obligations that access incurred, and are those records accessible to iwi governance structures? |
| 4 | Kotahitanga | For data with collective cultural significance, does the consent architecture go beyond individual consent to engage iwi and hapū governance in access decisions? |
| 5 | Manaakitanga | Is the governance framework designed to demonstrate affirmative stewardship, or is it designed to meet minimum standards only? |
| 6 | Kaitiakitanga | Do retention, archival, and disposition policies incorporate iwi input, and is the governance obligation attached to data across its full lifecycle? |
| 7 | Agent Identity | Does the agent registry include a cultural classification field, and does that classification connect to a defined governance framework rather than functioning as an unverified label? |
| 8 | Notification | Is the organisation prepared to attribute indirect collection notification obligations to specific agents, and does the agent audit trail support that attribution with sufficient specificity? |
The Architecture That Part Two Made Possible
Microsoft Agent 365 reached general availability on 1 May 2026. Per-agent Entra IDs are now commercially available at enterprise scale, with governance flowing through Purview, Defender, and Intune, at USD 15 per user per month standalone or USD 99 per user per month in the Microsoft 365 E7 Frontier Suite. [6] Each AI agent gets an identity. The architecture is technically capable. What it does not include is a cultural classification tier connected to a tikanga-derived governance framework. That is not a criticism of Microsoft's architecture; it is a statement of scope. Microsoft's governance framework is not designed for Aotearoa's obligations. Closing that gap is the architect's responsibility.
The agentic systems that New Zealand organisations are deploying now, and will deploy at increasing scale, will process Māori data. Some of that processing will involve taonga. The identity layer is in place. The classification field exists. The agentic asset register can carry the governance commitment. What was absent was the governance specification that gives those fields meaning. This chapter is that specification.
Chapter 15 will provide the technical implementation: how cultural classification flows through agent identity, how iwi governance integrates with access control policy, and what enforcement looks like when kaitiakitanga is expressed as policy-as-code. The present chapter establishes the foundation. The foundation is not optional. An implementation built without it may pass every technical review and still operate outside the governance framework that New Zealand's obligations require.
When an AI agent in your organisation processes Māori data this week, does your architecture know? And if it knows, what has it committed to in return?
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. Zero Trust Architecture for the Agentic Enterprise is the first book in The Hamberger Report series, providing practitioners with deployable patterns and configurations for securing AI-driven systems.
I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.
[1] Te Mana Raraunga. "Charter of Te Mana Raraunga." 2018. https://www.temanararaunga.maori.nz
[2] Te Kahui Raraunga. Publications 2019-2024. URL: https://www.kahui.raraunga.maori.nz (URL verification pending; organisation confirmed).
[3] Office of the Privacy Commissioner. "Māori Data Guidance." 2023. https://www.privacy.org.nz
[4] Office of the Privacy Commissioner. Privacy Act 2020, Information Privacy Principle 3A. Commenced 1 May 2026. https://www.privacy.org.nz
[5] NCSC NZ; CISA; ASD ACSC; Canadian Centre for Cyber Security; NSA; NCSC UK. "Careful Adoption of Agentic AI Services." 1 May 2026. https://www.ncsc.govt.nz/protect-your-organisation/careful-adoption-of-agentic-ai-services/
[6] Microsoft. "Microsoft Agent 365 General Availability." Microsoft Security Blog. 1 May 2026. https://www.microsoft.com/security
[7] NCSC NZ. "New Zealand Information Security Manual v3.9." https://www.nzism.gcsb.govt.nz
[8] National Institute of Standards and Technology. "Zero Trust Architecture." Special Publication 800-207. 2020. https://doi.org/10.6028/NIST.SP.800-207
[9] Cloud Security Alliance. "Agentic AI Trust Framework." 2026. https://cloudsecurityalliance.org
[10] Office of the Privacy Commissioner. "Biometric Processing Privacy Code 2025." August 2025. https://www.privacy.org.nz

