Local AI is not a magic shield
Local AI deserves far more attention in Māori technology discussions. It also deserves more careful discussion. Running a model locally can solve a very specific and important problem: information does not necessarily have to be transmitted to an external AI provider for processing. That is a substantial advantage, but it is not the same as solving Māori data sovereignty.
The distinction matters because Māori data sovereignty is not simply about geography. Keeping information in Aotearoa, on an iwi server or even on a disconnected laptop can strengthen control, but the deeper question remains who has authority over the information, who may use it, for what purpose, and with what consequences.
Local changes the risk
Imagine a laptop containing restricted whakapapa information. An employee installs a local AI model and indexes all of it. The laptop never connects to the internet. Nothing is uploaded to Microsoft, Google, OpenAI or another provider. From a conventional cloud-privacy perspective, this looks very strong.
Yet the fundamental question remains: did that person have authority to process that information in this way? If the answer is no, keeping everything offline has not solved the problem. It has merely changed its location.
This is why Te Mana Raraunga remains highly relevant to local AI. Its principles are concerned with control over collection, access, analysis, interpretation, management, use and reuse. That is a much richer concept than requiring a New Zealand server or turning off an internet connection.
When search changes access
AI can alter the practical sensitivity of information without changing who technically has file access. Consider an archive containing 50,000 documents. A staff member may already have permission to open each one, but finding a particular historical reference could take days or weeks.
Add an AI retrieval system and the situation changes. A person can ask for every reference to a whānau name, every document mentioning a particular site, or every report connected to a dispute. The underlying file permissions have not changed, but the practical accessibility of the information has changed enormously.
That should be treated as a governance event. AI can make obscure information discoverable, connect information that was previously separated across systems, and infer relationships that nobody explicitly recorded in one place. Those capabilities are precisely why the technology is useful. They are also why local deployment still needs good information governance.
Access needs context
Conventional enterprise security tends to ask whether a user has permission to open a file. Māori information may carry additional responsibilities that do not fit neatly into a simple read-or-deny model. Authority may depend on whakapapa, kaupapa, role, agreement, the circumstances under which information was provided, or expectations around future use.
A technically local system can still flatten those distinctions if every indexed document is made equally searchable to every authorised employee. One of the most important design tasks for Māori-controlled AI will therefore be deciding which collections can be searched together, which users can query which sources, what material should not be indexed at all, and whether some queries should require an additional level of authority.
This is not a reason to avoid local AI. It is a reason to build it with the same care that should apply to any system holding significant Māori information.
The problem of interpretation
Another limit of local AI is even more important. Installing an open model locally does not give the model cultural authority. A model may have encountered large quantities of Māori-related material during training. It may produce fluent explanations, recognise common terminology and generate sophisticated-looking analysis. None of those things establish whakapapa or authority.
A local model can help locate evidence, compare documents, identify patterns, suggest questions and assist with drafting where appropriate. It can help people process enormous quantities of written material. It cannot determine tikanga merely because it is running on iwi-owned hardware, and it cannot decide that one historical account is authoritative because its language sounds confident.
The safest and most useful design principle is to use AI to help people reach evidence rather than allowing it to replace the people who hold authority over that evidence. Where a question depends on whakapapa, local history, tikanga or knowledge held by particular people, the output should remain a prompt for checking, discussion and human judgement.
Training is another question
Local execution also does not erase questions about the model’s original development. An open-weight model may run entirely offline while still having been trained on data gathered under terms that are unclear, contested or culturally inappropriate. That is a model-provenance issue rather than a data-flow issue, but it remains relevant.
This distinction is useful because it prevents one concern from being used to obscure another. Running a model locally can genuinely prevent new organisational documents from being transmitted to the model provider. That benefit should be recognised. At the same time, organisations can still evaluate where the model came from, what licence applies, how it performs on Māori language and contexts, and whether its outputs reproduce harmful assumptions.
The positive case
None of these limitations weaken the case for local AI. They strengthen it by making the value more precise. Local AI allows an organisation to separate two questions that cloud platforms often combine. The first is whether an overseas service should receive the information. The second is whether AI should be used on the information at all.
With cloud AI, answering no to the first question may effectively prevent experimentation. With local AI, an organisation can instead decide that material will not be sent away but that carefully governed local analysis may still be worthwhile. That creates more choices, and choice is a practical part of rangatiratanga.
Start with low-risk material
Māori organisations do not need to begin with the most sensitive information they hold. A much better approach is to experiment with public and low-risk material first. Use published reports, public iwi management plans, government planning documents, GIS metadata, training datasets and material created specifically for testing.
Then deliberately stress the system. Ask difficult questions. Check every answer against the sources. Test Māori names and macrons. Test similarly named places. Test poor scans and OCR errors. Ask for page references. Ask the model to distinguish evidence from inference. See whether it invents citations. Try the same task with different models and compare the results.
This creates technical knowledge before sensitive information enters the environment. It also gives governance discussions something concrete to work with. Rather than debating hypothetical AI risk, people can examine a real system, a real dataset and a documented set of strengths and failures.
Design for kaitiakitanga
A useful local AI system should make provenance visible. It should show which source documents supported an answer, preserve original wording where that matters, and make it easy for a person to return to the source. It should also log enough activity to understand how the system is being used without turning the system into another unnecessary store of sensitive information.
Access controls should be designed around the information rather than added as an afterthought. Backups, embeddings, indexes and temporary files need the same attention as the original documents because derived data can also reveal information. A vector database that makes a restricted collection searchable is part of the information environment, not merely a technical cache.
A practical recommendation
Treat local AI as a significant reduction in one category of risk, not as a universal safety label. If the system is genuinely local, organisations can remove or materially reduce many concerns about routine transmission to external AI providers. Then governance can focus more clearly on the issues that remain: authority, access, appropriate use, provenance, cultural interpretation, security, model quality and consequence.
That is a positive change. It means some risks can be engineered away rather than endlessly managed through policy. The stronger the local technical capability becomes, the more choices Māori organisations have about where their information is processed and under whose rules.
Next in the series: Beyond Copilot: building broader Māori AI capability.