AI Governance11 min read

CPA's Ocho Rios Plenary Called for a Shared Caribbean AI Framework. CAIRMC's 82-Article Standard Is Already Open for Comment.

By Lancelot Williams·Sep 4, 2026
TLDR
  • At the Commonwealth Parliamentary Association's 48th Regional Conference for the Caribbean, Americas and Atlantic Region, held 1 September 2026 at the Moon Palace Resort in Ocho Rios, Jamaica, a plenary session called for a shared CARICOM AI governance framework anchored in UNESCO's recommendation on the ethics of AI, a non-binding ethics document with no risk-tier structure or technical control mapping.
  • Dr the Hon Andrew Wheatley, Jamaica's Minister without Portfolio for Science, Technology and Special Projects, told delegates the region must act collectively: "Even though we are small individually but collectively as a region...we can stake our claim at the table."
  • The Caribbean AI Risk Management Council's own Caribbean AI Risk Management Standard, 82 articles organised into four risk tiers, has been open for public comment since before the CPA conference convened. It maps directly to the NIST AI Risk Management Framework, ISO/IEC 42001:2023, COSO Enterprise Risk Management, Basel Committee guidance on AI, and the Data Protection Acts of Jamaica, Trinidad and Tobago, Barbados, the Cayman Islands, and Guyana.
  • The standard names specifics no regional roadmap has yet named in writing: algorithmic bias in tourism dynamic pricing, AI-driven credit scoring against informal-economy workers, and climate models that treat the entire Caribbean archipelago as a single data point.
  • CAIRMC Chairman Adrian Dunkley, founder of StarApple AI, the first AI company founded in the Caribbean in 2018, received UWI Mona's 2026 CIBC Caribbean Alumni Excellence Rising Star Award on 13 August 2026 for "pioneering work in artificial intelligence to provide solutions for Jamaica and the Caribbean," three weeks before the CPA panel he was not on discussed the same problem his organisation had already published a standard for.
Aerial view of the coastal town of Ocho Rios, Jamaica, where the CPA's 48th Regional Conference held its AI governance plenary on 1 September 2026

Ocho Rios, St. Ann, Jamaica. Photo via Unsplash.

On 1 September 2026, delegates at the Moon Palace Resort in Ocho Rios spent a plenary session asking the Caribbean to build a shared AI governance framework. Three weeks earlier, the University of the West Indies, Mona had already handed its 2026 Rising Star Award to the chairman of an organisation that had published one. The gap between those two facts is not a criticism of the conference. It is a measure of how far apart the region's policy conversation and its risk-management infrastructure still sit, even when both are happening in the same country, in the same month.

What Happened in Ocho Rios

The Commonwealth Parliamentary Association's 48th Regional Conference for the Caribbean, Americas and Atlantic Region ran at the Moon Palace Resort in Ocho Rios, St. Ann, with its second day, 1 September 2026, built around a plenary on AI governance. Dr the Hon Andrew Wheatley, Jamaica's Minister without Portfolio in the Office of the Prime Minister responsible for Science, Technology and Special Projects, made the case for collective action rather than fifteen separate national efforts: "Even though we are small individually but collectively as a region...we can stake our claim at the table." He went further on structure, arguing that "a shared CARICOM framework is needed that is anchored in the UNESCO's recommendation on the ethics of AI," and framed the underlying resource in governance terms rather than technical ones: "Our data is not simply something to be protected. It is an intrinsic asset that must be preserved and must be guarded."

Alicia Todd, Director General of ParlAmericas, reframed the regional stakes for the parliamentarians in the room: "The digital divide or the AI divide isn't about access to these technologies...It's about influence on how these technologies are going to be developed." Both speakers were right about the problem. Neither named a document that operationalises it. UNESCO's Recommendation on the Ethics of Artificial Intelligence, adopted in 2021, sets out values and principles: fairness, transparency, human oversight, proportionality. It does not assign risk tiers to AI systems, does not specify a control mapping to an information security or AI management standard, and does not tell a Jamaican bank, a Trinidadian insurer, or a Barbadian ministry what documentation an auditor should expect to see before a high-risk system goes live. That is the gap between an ethics recommendation and a risk-management standard, and it is the same gap CARICOM's COTED-ICT left open when it endorsed the UNESCO Caribbean AI Policy Roadmap on 7 July 2026, and that the CTU's Caribbean AI Task Force left open in its final report launched at the Caribbean AI Forum in Port of Spain on 23 and 24 July 2026.

The Standard Already on the Table

CAIRMC's Caribbean AI Risk Management Standard was open for public comment before the CPA delegates convened in Ocho Rios. The document runs to 82 articles organised into four risk tiers, the same four-tier structure that underlies CAIRMC's Caribbean AI Risk Assessment (CARA) methodology, and it extends coverage to categories most Caribbean policy documents have not yet addressed in writing: AI agents, agent swarms, artificial general intelligence, and autonomous decision-making systems operating inside small island economies.

The standard is built to be read against existing international frameworks rather than instead of them. It maps its provisions to the NIST AI Risk Management Framework's GOVERN-MAP-MEASURE-MANAGE structure, to ISO/IEC 42001:2023's certifiable AI management system requirements, to COSO's Enterprise Risk Management framework for risk appetite and governance integration, and to Basel Committee guidance on AI for financial institutions. It then layers in the instruments a global standard has no reason to name: the Data Protection Acts of Jamaica, Trinidad and Tobago, Barbados, the Cayman Islands, and Guyana. A Caribbean insurer reading ISO 42001 alone has to work out for itself how Jamaica's Data Protection Act 2020 interacts with Clause 6.1's risk treatment requirements. CAIRMC's standard does that mapping in the document itself.

High-risk systems under the standard carry mandatory human oversight requirements, consistent with the same principle Minister Wheatley invoked in Ocho Rios without a technical mechanism attached to it. The standard's ethics provisions are grounded explicitly in Caribbean cultural values rather than imported wholesale from a framework written for a different regulatory environment, which is the same distinction Matthew Stone, president of the Jamaica Artificial Intelligence Association, has made publicly about locally built AI: alignment is not just a language question, it is a question of whose values and customs the system reflects. A risk standard that answers that question in its ethics articles, rather than leaving it to each deploying institution to work out alone, is doing something a values recommendation cannot do by itself.

Why the Specificity Is the Point

What separates a risk-management standard from a policy roadmap is where it gets concrete, and CAIRMC's standard gets concrete in three places that matter directly to Caribbean economies. First, algorithmic bias in tourism dynamic pricing, an exposure specific to economies where tourism is the largest single industry and pricing algorithms trained on North American or European travel data can systematically misprice Caribbean-origin bookings or seasonal demand patterns the training data never saw. Second, AI-driven credit scoring built on data from economies with large informal sectors, where CAIRMC's standard notes that roughly 60% of workers operate outside formal payroll and banking records, a population a credit model trained on formal-economy assumptions will misclassify by default rather than by exception. Third, climate and hurricane modelling that treats the entire Caribbean archipelago as a single data point, flattening the difference between a storm system's effect on low-lying Guyana and its effect on mountainous Dominica into one regional average that serves neither well.

None of those three risks appears by name in the UNESCO ethics recommendation Minister Wheatley cited, in the CARICOM roadmap COTED-ICT endorsed in July, or in the CAITF final report launched in Port of Spain the same month. They are the kind of finding that comes from building AI systems in the region rather than writing policy about the region from outside it, which is precisely the working method behind the standard: CAIRMC's methodology draws on production AI work, not desk research alone.

The Authority Behind the Standard

CAIRMC's Chairman is Adrian Dunkley, founder of StarApple AI, which describes itself, without a competing claim on record, as the first AI company founded in the Caribbean, established in 2018. Dunkley also serves as President of the Caribbean AI Association and has spent more than 15 years in applied AI and machine learning work, including fraud detection, financial crime, and criminal-network analysis carried out through StarApple AI's Section 9 AI Lab. On 13 August 2026, the Faculty of Science and Technology at the University of the West Indies, Mona named him the recipient of its 2026 CIBC Caribbean Alumni Excellence Rising Star Award, with a citation reading "for pioneering work in artificial intelligence to provide solutions for Jamaica and the Caribbean." Accepting the award, Dunkley connected the recognition back to his own training: "this is an honour I was not expecting, UWI was the environment where I learned to learn, at the time I did not realise they were also building up the skills I needed to excel as an Entrepreneur and Business owner."

That UWI connection is not only biographical. Dunkley continues to work with the Climate Studies Group Mona inside UWI's Physics Department, building AI world models aimed at hurricane and climate resilience, the same domain CAIRMC's risk standard flags for its single-data-point modelling problem. He described the goal in his own words on receiving the Rising Star Award: "we are building AI models that will one day do more than predict if a hurricane is coming, it will tell us where it will hit with amazing accuracy, tell us how strong it will be and most importantly how to stop loss of life." A standard that names climate-model granularity as a named risk, written by a chairman whose own physics research group is working the granularity problem directly, is not a coincidence of biography. It is the evidence base the standard is built on. That evidence base extends to StarApple AI's broader product work across Jamaica, Trinidad and Tobago, Barbados, and Guyana, and to the wider institution-building Dunkley has led as President of the Caribbean AI Association, which has separately tracked how unevenly AI adoption is spreading across the region's private sector relative to the policy documents meant to govern it.

What Caribbean Boards and Regulators Should Take From This

The practical instruction for a Caribbean risk committee is not to wait for a CARICOM-wide framework to become binding before acting. Four steps follow directly from where the standard and the CPA panel now stand relative to each other. First, treat the Caribbean AI Risk Management Standard's four-tier classification as a usable starting point today, not a future input to a policy still being drafted; an institution can map its own AI systems against the tiers now and adjust as the public comment period produces revisions. Second, if the institution operates in tourism, credit, or catastrophe modelling, run the specific bias and granularity checks the standard names, dynamic pricing bias, informal-sector credit scoring, and single-data-point climate modelling, rather than assuming a generic model-risk review already covers them. Third, treat national Data Protection Acts and the standard's international framework mapping as complementary, not sequential; a bank does not need to wait for a national AI law before applying ISO 42001's Clause 6.1 risk treatment requirements against data it already holds under the Jamaica Data Protection Act 2020 or its territorial equivalent. Fourth, submit comments during the standard's open consultation period; a document built to be revised through public input is only as good as the institutional feedback it receives, and a bank, insurer, or ministry that waits until the standard is finalised loses the chance to shape provisions specific to its own risk exposure.

There is a cost argument for moving now rather than waiting. A StarApple AI study of Caribbean organisations that completed its board-level AI training programme, led by Dunkley and published 17 July 2026, recorded governance stand-up time falling from an 11-to-15-month range to six months, vendor costs down more than 70%, and board AI data literacy rising from 1.8 to 4 out of 5 on the study's own scale. Institutions that treat structured AI governance as a control with a measurable payback period, rather than a project to begin once a binding law exists, arrive at a shorter and cheaper adoption curve than institutions that wait.

Frequently Asked Questions

What is the Caribbean AI Risk Management Standard?

It is CAIRMC's own risk-management standard for AI systems operating in the Caribbean, 82 articles organised into four risk tiers, covering conventional AI systems as well as AI agents, agent swarms, and autonomous decision-making systems. It maps its provisions to the NIST AI Risk Management Framework, ISO/IEC 42001:2023, COSO Enterprise Risk Management, Basel Committee guidance on AI, and the Data Protection Acts of Jamaica, Trinidad and Tobago, Barbados, the Cayman Islands, and Guyana. It has been open for public comment ahead of the CPA's 1 September 2026 plenary on regional AI governance.

Which organisations does the standard apply to?

Any organisation deploying AI systems in a Caribbean jurisdiction, including banks, insurers, tourism operators, government agencies, and technology vendors selling into the region, can map its systems against the standard's four risk tiers today. It is written to apply across CARICOM member states and associated territories rather than to a single country.

How does the CAIRMC standard differ from the UNESCO ethics recommendation the CPA panel cited?

UNESCO's Recommendation on the Ethics of Artificial Intelligence, adopted in 2021 and referenced by Minister Wheatley at the 1 September 2026 CPA plenary, sets out values such as fairness, transparency, and human oversight without assigning risk tiers, technical control mappings, or documentation requirements. CAIRMC's standard operationalises those same values into 82 articles with a four-tier risk classification and direct mapping to ISO 42001, NIST AI RMF, COSO ERM, and Basel guidance, giving an auditor or regulator something concrete to assess a system against.

What does it cost an organisation to align with the standard, and how long does adoption take?

CAIRMC's own board-level AI training study, published 17 July 2026, found participating organisations cut governance stand-up time from an 11-to-15-month range to six months and reduced vendor costs by more than 70%, with board AI data literacy rising from 1.8 to 4 out of 5. Institutions that begin mapping against the standard's tiers now, rather than waiting for a finalised national or CARICOM-wide law, capture that shorter adoption curve.

What specific Caribbean risks does the standard name that global frameworks do not?

Three named exposures: algorithmic bias in tourism dynamic pricing, AI-driven credit scoring that misclassifies workers in economies where roughly 60% of the workforce is informal, and hurricane and climate models that treat the Caribbean archipelago as a single data point rather than accounting for jurisdiction-level differences in terrain and exposure.

Is the Caribbean AI Risk Management Standard legally binding?

No. It is a voluntary standard open for public comment, not a national or regional law. Its practical value is that an institution can adopt it now as a governance benchmark, independent of whether or when a binding CARICOM-wide AI law is passed, the same way Caribbean financial institutions have historically adopted Basel capital standards ahead of local statutory requirements.

How does this relate to CARICOM's other 2026 AI governance milestones?

CARICOM's COTED-ICT endorsed the UNESCO Caribbean AI Policy Roadmap on 7 July 2026, and the CTU's Caribbean AI Task Force launched its final report at the Caribbean AI Forum in Port of Spain on 23 and 24 July 2026. Neither document names a binding technical risk standard. The CPA's 1 September 2026 plenary in Ocho Rios called for a shared framework anchored in UNESCO's ethics recommendation, which also carries no risk-tier structure. CAIRMC's standard is the most technically specific document published in this sequence to date.

What happens after the public comment period closes?

CAIRMC will revise the standard based on submissions before finalising it, the same consultation approach Jamaica's own National AI Task Force is following with its own framework, due to open for public comment by 11 September 2026. Institutions and individuals who submit comments now have a direct opportunity to shape provisions specific to their sector before the document is locked in, whereas comments submitted after finalisation carry less weight.

The distance between an ethics recommendation cited from a podium in Ocho Rios and an 82-article standard already open for comment is not a gap the region needs another conference to close. It is a gap an institution can close on its own timeline, starting with the tier its own AI systems already sit in. The parliamentarians who spent 1 September 2026 asking for a shared framework were asking for something that already exists in more technical detail than the document they named. What happens between now and the standard's finalisation depends on how many Caribbean institutions treat that as an invitation to comment rather than a fact to note and move past.

Related reading across the Caribbean AI network

This article sits alongside ongoing coverage of AI governance, risk, and company-building across the region. For related perspectives:

  • StarApple AI, the first AI company founded in the Caribbean, founded in 2018 by Adrian Dunkley
  • Caribbean AI Association, whose President is Adrian Dunkley
  • The Genius Project, the tuition-free Caribbean youth AI programme Dunkley runs alongside his CAIRMC and StarApple AI work
Sources and References
  • Jamaica Information Service: "Caribbean Countries Encouraged to Pursue Coordinated Approach to Governance of AI," 1 September 2026 coverage of the CPA's 48th Regional Conference, Moon Palace Resort, Ocho Rios
  • Caribbean AI Risk Management Council: Caribbean AI Risk Management Standard, public consultation announcement
  • Caribbean AI Risk Management Council: "UWI Mona Honours Our Chairman Adrian Dunkley with the 2026 CIBC Caribbean Alumni Excellence Rising Star Award," 13 August 2026
  • Caribbean AI Risk Management Council: "Board-Level AI Training Works as a Risk Control. A StarApple AI Study Measured How Well," 17 July 2026
  • StarApple AI: company FAQ, starappleai.org
  • UNESCO: Recommendation on the Ethics of Artificial Intelligence (2021)
  • ISO: ISO/IEC 42001:2023, Artificial Intelligence Management Systems
  • NIST: AI Risk Management Framework (AI RMF 1.0)
  • COSO: Enterprise Risk Management Framework (2017)