AI Risk Management14 min read

Your Face Is Not Neutral: The Biometric AI Risk Caribbean Banks and Border Agencies Cannot Defer

By Nicholas Dunkley·Jun 26, 2026
TLDR
  • NIST's 2019 FRVT benchmark tested 189 facial recognition algorithms; most produced false positive rates 10–100× higher for Black African and East Asian faces than for white faces from the same vendor's system.
  • MIT Media Lab found commercial facial recognition misidentified darker-skinned women at rates up to 34.7%, compared with under 1% for lighter-skinned men.
  • Jamaica, Barbados, and Trinidad and Tobago are all expanding national digital identity and biometric verification programmes in 2026.
  • Caribbean banks using biometric KYC tools from foreign vendors have almost universally not requested demographic performance breakdowns for Caribbean populations.
  • No CARICOM country has published a biometric AI governance standard for banking or border control as of mid-2026.
  • The EU AI Act classifies biometric identification systems as high-risk, carrying documentation requirements that now flow back to Caribbean institutions through vendor contracts.
Digital biometric scan abstract representing facial recognition AI risk assessment in Caribbean banking

Every major Caribbean bank now uses some form of digital identity verification. Several use facial recognition. Caribbean airports at Kingston, Bridgetown, Port of Spain, and Georgetown operate biometric gates or biometric scanning during passenger processing. Immigration departments across CARICOM are digitising ID systems with biometric components, supported by international development finance.

None of that is surprising. Biometric AI is fast, scales without additional staff, and reduces certain types of identity fraud. The case for deployment is straightforward. What is less straightforward, and what Caribbean institutions almost never discuss, is what these systems do when they are wrong, and specifically, who they are most likely to be wrong about.

The answer to that question has been on public record since 2019. It sits uncomfortably with the demographics of every CARICOM member state.

What the Evidence Actually Says

The National Institute of Standards and Technology (NIST) published its Face Recognition Vendor Test in 2019, the largest independent evaluation of commercial facial recognition algorithms ever conducted. It tested 189 algorithms from 99 developers, running each against a database of millions of photographs.

The headline finding was not that facial recognition does not work. It is that facial recognition does not work equally. For one-to-one matching, which is the use case in banking KYC and e-passport gates, the most common failure mode was false negatives: the system fails to match a genuine identity. For most algorithms in the NIST study, false negative rates for Black African, East Asian, and American Indian faces were 10 to 100 times higher than for white faces. The variation was not marginal. It was structural, present across the majority of the 189 systems tested, and attributable to underrepresentation of non-white faces in the training data used to build those systems.

MIT Media Lab researcher Joy Buolamwini published complementary findings in the same period. Her Gender Shades study evaluated commercial facial analysis systems from Microsoft, IBM, and Face++. Error rates for darker-skinned women reached 34.7%. For lighter-skinned men, the same systems' error rate was below 1%. A 34-percentage-point gap is not a calibration issue. It reflects whose faces were and were not included when those systems were built.

These findings are from 2019. The algorithmic lineage of the systems Caribbean banks and government agencies are using in 2026 descends from training pipelines built well before 2019, and in most cases has not been comprehensively re-validated on representative Caribbean population samples since deployment.

What This Means for Caribbean Banking KYC

Know-your-customer processes in Caribbean banking now routinely include digital identity verification. A customer applies for an account, uploads a photograph of their identity document, and the system compares it against a selfie or live video. If the system matches them, they proceed. If it does not, they face a rejection or a manual review queue.

For customers in Jamaica, Barbados, Trinidad, or Guyana, whose skin tones sit in the demographic range where the NIST study found the highest error rates, the probability of a false rejection is materially higher than for a lighter-skinned applicant making the same correct submission with the same genuine identity documents.

This is not a hypothetical inequity. It is a documented statistical outcome of using systems built on unrepresentative training data. The Caribbean customer who is incorrectly rejected faces three costs: time lost to manual review, potential exclusion from digital-only application pathways with no manual alternative, and the reputational harm of having a legitimate identity questioned by a system that should not have doubted it.

For the bank, the risks are different but also real. Under Jamaica's Data Protection Act 2020 and Barbados's Data Protection Act 2019, automated individual decision-making that materially affects a person requires proper disclosure and, in some cases, a right to human review. A biometric KYC rejection is an automated individual decision. If the bank cannot demonstrate that its system was validated to perform equitably across its actual customer population, it carries a compliance gap under existing data protection law, before any AI-specific regulation arrives.

Caribbean Border Control: The Accountability Gap

The banking KYC context at least involves an institution with a defined regulator, a data protection law, and a commercial incentive to fix problems when they are identified. Border control is more complex.

Jamaica's Airports Authority, the GAIA airport authority in Barbados, and the Airports Authority of Trinidad and Tobago have all expanded biometric processing at their major international terminals in 2024 and 2025. The Immigration, Customs, Excise and Contraband Division and its counterparts across CARICOM increasingly process passengers using systems with biometric components. Regional governments are pursuing national digital ID programmes with biometric registration as a core element: Jamaica's National Identification System (NIDS) relaunch, Barbados's national digital identity programme, Trinidad and Tobago's e-ID initiative, and similar efforts in Guyana and across the OECS.

These are public systems, operated by government agencies, affecting citizens in the exercise of rights of entry, movement, and access to public services. When they produce a false rejection at a border gate, the affected person does not have a bank's customer service team to escalate to. They have a queue, a uniformed officer with discretion, and limited options to contest an automated result on the spot.

No CARICOM immigration ministry has published demographic performance data for its biometric border systems. No regional standards body has published a biometric AI accuracy standard that Caribbean government procurement must meet. The IDB and World Bank programmes that finance national ID systems include data protection requirements, but none currently mandate demographic performance benchmarking against Caribbean population samples as a condition of contract.

Caribbean governments are deploying AI systems that make consequential identity decisions about Caribbean citizens, using systems whose accuracy for darker-skinned faces is documented to be lower, without the performance disclosure requirements that would allow oversight bodies to assess the actual error rate being accepted.

The EU AI Act Has Already Classified This as High-Risk

The EU AI Act is unambiguous on biometric identification: systems that perform remote biometric identification, real-time or otherwise, are classified as high-risk under Annex III. High-risk systems require conformity assessments, technical documentation including demographic performance data, ongoing monitoring, and registration in the EU's AI systems database.

Caribbean institutions deploying biometric systems sourced from EU-based vendors are encountering AI Act requirements through their vendor contracts. Several of the major KYC and identity verification vendors supplying Caribbean banks are EU-based or have EU-regulated subsidiaries. Their standard contracts for 2025 and 2026 deployments include AI Act conformity representations. Caribbean procurement teams signing these contracts are acquiring systems that are EU AI Act-conformant in their EU deployments, but that may not have had Caribbean-market performance independently validated to the same standard.

This creates a compliance asymmetry. The EU customer of the same biometric system has documented demographic performance data available to their regulator. The Caribbean customer of the same system does not, because no Caribbean regulator has required it.

Five Questions Every Caribbean Institution Must Ask

Whether the institution is a commercial bank procuring a digital KYC platform, a government agency deploying a biometric e-gate, or a fintech building identity verification into a mobile product, these five questions define the minimum due diligence standard for biometric AI in 2026.

What is the training dataset's demographic composition? This is the foundational question. If the vendor cannot provide a clear answer, or if the answer does not include meaningful representation of Afro-Caribbean, Indo-Caribbean, and mixed-heritage populations, the performance gap documented in the NIST study applies by default until proven otherwise.

Has the system been independently benchmarked on a Caribbean population sample? Vendor-provided accuracy statistics are typically measured on the vendor's own test dataset. That dataset may not reflect Caribbean demographic composition. An independent benchmark on a representative Caribbean sample provides the only reliable performance estimate for Caribbean deployments.

What is the false rejection rate across demographic groups for the Caribbean deployment context? This requires the vendor to disaggregate performance data. Aggregated accuracy statistics can mask large group-level disparities. A system that is 97% accurate overall may be 99% accurate for one demographic group and 89% accurate for another. Caribbean institutions need the disaggregated figures.

What is the human review pathway when the system rejects a genuine identity? This is both an operational question and a data protection compliance question. Under Caribbean data protection laws, individuals subjected to automated decisions have rights. The institution needs a documented, accessible human review process, not a theoretical one.

What monitoring is in place to detect performance drift for Caribbean users over time? Model performance degrades as deployment conditions change. A biometric system that performs adequately at deployment may perform less well two years later if the model has not been updated. The institution needs a monitoring programme that catches drift before it accumulates into a material adverse outcome.

CAIRMC's Position on Biometric AI Governance

The Caribbean AI Risk Management Council's AI Risk Audit Framework addresses biometric AI as a category of high-risk automated decision-making. The framework's regional representativeness dimension requires that any AI system making decisions about Caribbean individuals be validated on Caribbean population data. The human oversight dimension requires documented review pathways for automated rejections. The monitoring and drift detection dimension requires ongoing performance tracking disaggregated by demographic group where technically feasible.

CAIRMC has called on the CARICOM secretariat, individual CARICOM central banks, and regional technology regulators to adopt a minimum biometric AI performance standard as part of any public procurement framework for digital identity systems. The standard CAIRMC proposes mirrors EU AI Act high-risk system requirements, calibrated for Caribbean institutional capacity: demographic performance benchmarking against a representative Caribbean sample, published disaggregated error rates, documented human review pathways, and annual performance audits.

Two things are knowable about the current situation. First, Caribbean institutions are deploying biometric AI systems whose accuracy for darker-skinned faces is documented to be lower, without the testing protocols that would quantify the regional exposure. Second, regulatory requirements in this area are arriving. The IDB and international development partners are incorporating AI governance conditions into digital public infrastructure financing. Caribbean governments that have not established biometric AI standards before their next digital ID procurement cycle will face those requirements as external conditions rather than domestically-set ones.

Acting ahead of compulsion is better procurement. Caribbean institutions that require demographic performance data from vendors before signing will receive it, because vendors have it for their EU deployments and can produce it for other markets when required to. The requirement just has to be made.

CAIRMC offers a biometric AI procurement checklist as part of its AI Risk Audit Framework. Caribbean institutions beginning a biometric AI deployment or reviewing an existing one can access it at caribbeanairisk.com/resources.

Frequently Asked Questions

Why does facial recognition AI perform less accurately for darker-skinned people?

Facial recognition systems learn from training datasets. Most commercial systems were built and validated predominantly on North American and European datasets, which are majority white. The systems therefore have less training signal for features associated with darker-skinned faces. NIST's 2019 FRVT study found false positive rates 10–100× higher for Black African faces than white faces across 189 commercial algorithms. This is a data representation problem, not an inherent technical ceiling, but fixing it requires deliberate retraining on demographically representative data.

What biometric AI applications are Caribbean banks using?

Caribbean banks primarily use biometric AI for digital KYC during account opening, document verification, and liveness detection. These systems compare a selfie or live video against a passport or national ID photograph. Several also use voice recognition for telephone banking and biometric login for mobile apps. The highest-risk applications are those that gate access to financial services, where a false rejection denies a legitimate customer access to their account or application.

Does the EU AI Act apply to biometric systems used in the Caribbean?

Directly, the EU AI Act governs EU-based institutions. In practice, Caribbean institutions feel its reach through vendor contracts. The Act classifies biometric identification as high-risk under Annex III, requiring technical documentation including demographic performance data. Caribbean banks procuring biometric KYC tools from EU-based vendors now receive systems sold with AI Act conformity representations. Those representations cover EU-context performance; Caribbean institutions should request equivalent documentation for their Caribbean deployment population.

What are Caribbean banks legally required to do about biometric AI accuracy?

Under Jamaica's Data Protection Act 2020 and Barbados's Data Protection Act 2019, automated individual decisions that materially affect a person require disclosure and a right to human review. A biometric KYC rejection is an automated individual decision. Banks that cannot show their system was validated for equitable performance across their actual customer population carry a compliance gap under existing data protection law, independent of any AI-specific regulation.

What should Caribbean governments require when procuring biometric border systems?

CAIRMC recommends Caribbean government procurement require five elements: demographic performance benchmarking against a representative Caribbean population sample; published disaggregated false rejection and acceptance rates by demographic group; documented human review pathways for system rejections; annual performance audits; and vendor disclosure of training dataset demographic composition. These mirror EU AI Act high-risk system standards, calibrated for Caribbean institutional capacity.

What is CAIRMC's guidance on biometric AI?

CAIRMC's AI Risk Audit Framework addresses biometric AI as high-risk automated decision-making. It requires biometric systems used in Caribbean institutions to be validated on Caribbean population data, have demographic performance disaggregation, include accessible human review pathways for rejections, and undergo ongoing monitoring for performance drift. CAIRMC has also called on CARICOM central banks to adopt a minimum biometric AI procurement standard. Resources are available at caribbeanairisk.com/resources.

Sources and References
  • NIST: Face Recognition Vendor Test (FRVT) Part 3: Demographic Effects, NISTIR 8280, September 2019
  • Joy Buolamwini and Timnit Gebru: Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification, MIT Media Lab, 2018
  • EU AI Act (Regulation 2024/1689): Annex III high-risk classification, biometric identification systems
  • Jamaica Data Protection Act, 2020
  • Barbados Data Protection Act, 2019
  • Inter-American Development Bank (IDB): Digital Identity in Latin America and the Caribbean, 2024
  • World Bank: Global ID Coverage, Barriers, and Use by the Numbers: An In-Depth Look at the 2017 ID4D-Findex Survey
  • CARICOM: Caribbean Community Digital Agenda 2025–2030
  • Caribbean AI Risk Management Council: AI Risk Audit Framework, caribbeanairisk.com/resources
  • Related reading: StarApple AI | AI Jamaica | AI Trinidad and Tobago | AI Barbados | AI Guyana | Saint Lucia AI | Caribbean AI Association