The country's cyber watchdog says it's testing New Zealand government owned software code to improve its security.
This follows a handful of cases worldwide of advanced AI models escaping test arenas in some cases to launch their own cyber attacks.
The latest is a Chinese model Kimi K3 reportedly escaping to the internet.
British testers also detected two models that created fake human profiles to try and trick people.
The National Cyber Security Agency said it aware of these reports from the UK AI Security Institute.
"We are also working with international partners to understand the opportunities and risks from this technology and are," the NCSC told RNZ on Monday.
Its focus is on testing the model Mythos, made by Anthropic, and "other tools" to strengthen government and commercial cyber defences, it said.
"This includes testing New Zealand government-owned code to improve its security."
The centre put out advice in June that said, "New Zealand Government entities do not need access to the most advanced frontier AI models to stay protected."
While it said at the time that using existing cyber security mitigations and practices properly was enough, in its statement on Monday it said it was working with a number of partners and AI companies on the application of "advanced AI tools to cyber security".
A top US government official told cybersecurity leaders at theBlack Hat summit in Las Vegas last week that the Trump administration remained hands-off as regulating would only strangle growth and be "obsolete [in] 48 hours".
At the same conference OpenAI revealed that AI agents themselves had created an internal message board to share vulnerabilities and exploits in the weeks before a hack attack on the firm Hugging Face.
Here, the NCSC said it was working directly with government agencies, businesses and other organisations to increase their understanding of advanced AI and their cyber-security in anticipation of the tools' deployment.
The BBC had also reported that Anthropic said it found three instances out of thousands where its model Claude had managed to gain access to the internet off its own bat, while Meta said its model hacked another company during tests.
In an article by Reuters, researchers warned that if one advanced model discovers a shortcut to escape test environments that till now were adequate, then other models with similar access would likely do the same.
Some are suggesting the 'sandboxes' for tests will have to be entirely physically separate from any internet-linked system.