The Caribbean AI Task Force Wants a Regional Data-Sharing Deal by 2027. Its Own Chair Says the Region Still Confuses What Data Privacy Is For.
- At the Caribbean Development Bank's inaugural Caribbean Evaluation Space 2026 conference in Barbados, during the 2 September plenary "AI, Data, and Power," Craig Ramlal, chair of the CTU's Caribbean AI Task Force and executive director of UWI St Augustine's Artificial Intelligence Innovation Centre, said: "We confuse what data privacy is and what it should be used for."
- The Innovation Centre has pushed an open-data initiative since 2012. Fourteen years on it still has not been approved, even as the Task Force's own recommendations call for regional agreements covering data sharing, standardisation, and legal frameworks.
- Latin America and the Caribbean hold 6.6% of global GDP but capture just 1.12% of global AI investment, against a global AI market projected at US$3 trillion to US$4.8 trillion by 2033. A survey of 2,500 Caribbean businesses found 60% of those struggling with digital adoption cite a shortage of skilled IT workers as the top reason.
- The conference sat inside the CARICOM state with the region's most functional data protection regime. Barbados's Data Protection Act 2019 has had an operating Data Protection Commissioner since July 2021. Trinidad and Tobago, home to the Task Force chair's own university, has left most of its 2011 Data Protection Act unproclaimed for fifteen years.
- CAIRMC's read: a data-sharing agreement signed before the region settles what its own data protection law is for does not remove that risk. It moves the risk from individual unproclaimed statutes into a CARICOM-wide pool that inherits the same unresolved question at a larger scale.
Caribbean coastline. Photo via Unsplash.
Craig Ramlal has spent fourteen years trying to get one open-data initiative approved. He is not a junior researcher stuck in a slow committee. He chairs the Caribbean AI Task Force (CAITF), the body behind the region's first cross-border AI policy roadmap, and he directs the Artificial Intelligence Innovation Centre (AIIC) at the University of the West Indies, St Augustine. When the person running the region's flagship AI institution tells a room of evaluators and policymakers in Barbados that "we confuse what data privacy is and what it should be used for," that is not a complaint about paperwork. It is a description, from the person best placed to know, of the exact problem a regional data-sharing agreement is supposed to fix.
What Happened in Barbados
The Caribbean Development Bank ran its first Caribbean Evaluation Space conference in Barbados from 1 to 3 September 2026. On the second day, a plenary titled "AI, Data, and Power: Shaping the Future of Evaluation in the Caribbean" framed AI as a governance issue rather than a set of tools, and the discussion turned quickly to data. The region holds significant amounts of data, but as Jamaica Observer business reporter Codie-ann Barrett reported from the session, countries and organisations keep it inside their own borders and their own institutions rather than sharing it. Ramlal named the habit directly, then went further: "We confuse what data privacy is and what it should be used for."
Jos Vaessen, chief evaluation officer and senior adviser at the World Bank's Independent Evaluation Group, spoke alongside him on a related shortage. "Nowadays all of our evaluations in one way or another have some AI components," he said, arguing that governments need a deliberate programme to pull technology professionals into public service rather than losing them to better-paying private roles. That skills gap shows up in the numbers Barrett reported: a survey of 2,500 Caribbean businesses found that 60% of those struggling to implement new digital technology cite a lack of skilled IT workers as the primary obstacle, with brain drain compounding the shortfall. Set against a global AI market projected to reach US$3 trillion to US$4.8 trillion by 2033, Latin America and the Caribbean account for 6.6% of global GDP but capture only 1.12% of global AI investment. No separate figure isolates how much of that sliver the Caribbean itself receives.
CAITF's own six recommendations, drawn from its final report launched at the Caribbean AI Forum in July, already call for equitable access to AI resources, frameworks for managing AI-driven economic disruption, capacity development, research funding, support for AI-ready niche industries, and regional agreements covering data sharing, standardisation, and legal frameworks. Ramlal was blunt about what he wants next: "We are not a region of report writers and talkers; we want to be a region that actually does something." By his own timeline, 2023 marked the point the Caribbean started taking AI seriously, 2026 is meant to bring stronger policy, and 2027 is when implementation is supposed to begin.
The Confusion Ramlal Named
Data protection law, done properly, is not a wall against sharing. It is a set of conditions under which specific categories of data may move: consent, purpose limitation, data minimisation, and safeguards on where the data goes next. A statute that does those things well makes large-scale sharing defensible. Treating the statute itself as the obstacle, rather than the absence of a working version of one, is the confusion Ramlal is describing, and it explains why an open-data push with no functioning data protection scaffolding underneath it has taken fourteen years to go nowhere.
Jamaica's Data Protection Act 2020 does contain cross-border transfer provisions, the mechanism a regional data-sharing agreement would actually need to lean on. But the country only opens its first public consultation on a national AI policy by 11 September 2026, eighteen months after its underlying task force recommendations were published with no risk chapter attached. A region cannot build the "regional agreements covering data sharing" item on CAITF's own list on top of national laws that are unevenly written, unevenly proclaimed, and unevenly enforced, and expect the agreement to resolve a confusion the national laws never resolved first.
Port of Spain, Trinidad and Tobago. Photo via Unsplash.
Where the Region's Data Protection Law Actually Stands
The asymmetry is not abstract. Barbados's Data Protection Act 2019 came into force in March 2021, with a Data Protection Commissioner, Lisa Greaves, appointed that July and the power to fine violations up to BBD$500,000. It is one of the more functional regimes in CARICOM, and it happens to be the law of the country that hosted the 2 September plenary. Trinidad and Tobago, the jurisdiction where the AI Innovation Centre and CAITF are actually based, has left the bulk of its Data Protection Act 2011 unproclaimed for fifteen years, a gap the country's own securities regulator has had to work around while issuing six public alerts on AI-generated deepfake investment fraud since Cabinet formed an Inter-Ministerial Steering Committee on Cyber Security and AI in September 2025. Jamaica's Data Protection Act 2020 sits somewhere between the two, with its own controller registry paused for weeks earlier this year even as national AI strategy work continued around it.
A regional data-sharing agreement due for 2027 has to interoperate across all three states of readiness simultaneously: a functioning regime in Barbados, a mostly dormant one in Trinidad and Tobago, and a partially operational one in Jamaica, plus twelve other CARICOM member states at their own points on that same spectrum. The Caribbean AI Association has separately tracked how unevenly private-sector AI adoption itself is spreading across the region, a pattern that mirrors the legal unevenness rather than compensating for it.
What CAIRMC's Standard Says That the Task Force's Recommendations Do Not
CAIRMC's Caribbean AI Risk Assessment (CARA) methodology starts from a different premise than "get more data moving." It starts by classifying what the data actually is before deciding how, or whether, it moves. Aggregate, de-identified statistical data used to train a regional model carries a different risk tier than the informal-sector transaction records or biometric identifiers a bank or a border agency holds. CAIRMC's Caribbean AI Risk Management Standard, 82 articles across four risk tiers, treats cross-border and third-party data movement as its own control area, mapped to Clause 6.1 risk treatment requirements common to ISO management system standards and to the MAP function inside the NIST AI Risk Management Framework, the stage where an organisation is meant to document a dataset's provenance and intended use before a model ever touches it.
None of CAITF's six recommendations names that sequencing. "Regional agreements covering data sharing, standardisation and legal frameworks" reads as one line item alongside funding and capacity building, not as a project with its own dependency on national data protection law actually working first. A risk committee reading CAITF's recommendations next to CAIRMC's standard has an obvious question to raise before signing on to anything: does the proposed agreement specify what tier of data is being shared, on what legal basis, with what retention limit, and with what audit right if a partner institution misuses it? If the answer is not yet written down, the agreement is asking institutions to trust a process that its own chair says the region does not yet understand.
What Caribbean Boards and Regulators Should Do Now
Four steps do not require waiting for CAITF's 2027 implementation date. First, classify the categories of data an institution might realistically be asked to contribute to a future regional or sector dataset, using CAIRMC's tier structure or an equivalent, before any request arrives rather than after. Second, use the cross-border transfer and legitimate-interest provisions that already exist in a national Data Protection Act, Barbados's functioning one included, rather than treating the absence of a CARICOM-wide instrument as a reason to do nothing. Third, put purpose limitation, retention period, and audit rights into any data-sharing request from a regional body or AI vendor in writing before agreeing to it, rather than relying on a verbal assurance about how the data will be used. Fourth, submit comments now, while frameworks are still open: StarApple AI's Adrian Dunkley, who chairs CAIRMC, has argued institutions that engage with governance work as it is being drafted capture a shorter and cheaper adoption curve than institutions that wait for a finished document.
Ramlal is right that the region has produced more reports than results. A data-sharing agreement signed before the region agrees on what data privacy is protecting will not fix that. It will produce a different kind of document: an incident report, filed after the first cross-border transfer someone never consented to.
Frequently Asked Questions
What is the Caribbean's AI data-sharing problem?
The region holds significant amounts of data but keeps it siloed by country and by organisation. The Artificial Intelligence Innovation Centre's open-data initiative has been unapproved since 2012. Craig Ramlal, its executive director and chair of the CTU's Caribbean AI Task Force, told the Caribbean Development Bank's Caribbean Evaluation Space 2026 conference on 2 September 2026 that "we confuse what data privacy is and what it should be used for," pointing to conceptual confusion, not only missing infrastructure, as the core obstacle.
Does this affect an organisation that is not doing AI research itself?
Yes. Any Caribbean bank, insurer, ministry, or hospital holding customer, patient, or citizen data is a potential party to a future regional data-sharing agreement, whether it opts in directly or through a national dataset a government contributes on its behalf. The confusion Ramlal named, treating data protection law as a blanket restriction rather than a mechanism for governed sharing, shapes how any institution's compliance team currently reads its own obligations under Jamaica's DPA 2020, Trinidad and Tobago's 2011 Act, or Barbados's DPA 2019.
What should an institution do before a regional data-sharing agreement exists?
Classify the data it might be asked to contribute by sensitivity tier before any agreement is signed, use the cross-border transfer and legitimate-interest provisions already written into its own national Data Protection Act rather than waiting for a CARICOM-wide instrument, and require any AI vendor or regional body requesting data to put purpose limitation, retention period, and audit rights in writing.
What does the region's data-sharing gap cost, in investment terms?
Latin America and the Caribbean capture just 1.12% of global AI investment against 6.6% of global GDP, set against a global AI market projected at US$3 trillion to US$4.8 trillion by 2033. Separately, a survey of 2,500 Caribbean businesses found 60% of those struggling with digital technology adoption cited a shortage of skilled IT workers as the top reason, a related but distinct cost driven by capacity rather than data access alone.
How does an open-data push differ from a data protection framework, and can the two coexist?
They answer different questions. An open-data initiative is about volume and access, getting more data moving between institutions. A data protection framework sets the conditions under which specific categories of data may move: consent, purpose limitation, security, and cross-border safeguards. A functioning data protection law is what makes large-scale sharing defensible rather than reckless. The Innovation Centre's fourteen-year delay suggests the region has been treating the two as opposed rather than as one project, open data, that depends on the other, settled protection rules, being resolved first.
What is the risk if data-sharing moves ahead of data protection clarity?
Data that could not legally move under Trinidad and Tobago's largely unproclaimed Data Protection Act could enter a shared regional pool through a member state with a more permissive or better-enforced regime, then flow back through the same agreement. CAIRMC's Caribbean AI Risk Management Standard treats cross-border and third-party data movement as its own control area requiring a documented legal basis and audit rights, not a governance detail to settle after an agreement is already in force.
What is the current state of data protection law across the Caribbean relevant to this story?
Barbados's Data Protection Act 2019 came into force in March 2021, with a Data Protection Commissioner appointed that July and the power to fine violations up to BBD$500,000, and it is the law of the country that hosted the 2 September 2026 conference. Trinidad and Tobago's Data Protection Act 2011, the jurisdiction where the AI Innovation Centre and the Task Force are based, has left most of its enforcement sections unproclaimed for fifteen years. Jamaica's Data Protection Act 2020 sits in between, with its own registry paused for weeks in 2026. A regional data-sharing agreement has to interoperate across all three states of readiness at once.
What happens between now and 2027, when the Task Force envisions implementation beginning?
Ramlal has said 2023 marked when the Caribbean began taking AI seriously, with 2026 expected to bring stronger policy and 2027 the year implementation is meant to start. Jamaica opens its own national AI policy consultation by 11 September 2026, and CAIRMC's Caribbean AI Risk Management Standard remains open for public comment. Institutions that submit input to both processes now have a chance to get purpose limitation, consent, and cross-border transfer questions written into the frameworks before 2027, rather than raising them as objections after an agreement is already signed.
Related reading across the Caribbean AI network
This article sits alongside ongoing coverage of AI governance, risk, and company-building across the region. For related perspectives:
- StarApple AI, the first AI company founded in the Caribbean, founded in 2018 by Adrian Dunkley, who chairs CAIRMC
- Caribbean AI Association, which tracks private-sector AI adoption across the region
- Trinidad and Tobago AI, covering AI developments in the jurisdiction home to the Artificial Intelligence Innovation Centre and CAITF
- Barbados Artificial Intelligence, covering AI developments in the jurisdiction that hosted the Caribbean Evaluation Space 2026 conference
- Codie-ann Barrett, "Caribbean's AI ambitions face a data-sharing problem," Jamaica Observer, 4 September 2026
- Caribbean Development Bank: Caribbean Evaluation Space 2026 Conference programme, Barbados, 1-3 September 2026
- University of the West Indies, St Augustine: press materials on the Caribbean AI Task Force and "Toward Harmonized AI Policies and Recommendations for the Caribbean," July 2026
- Government of Barbados: Data Protection Commission, Ministry of Industry, Innovation, Science and Technology
- Caribbean AI Risk Management Council: "Jamaica's AI Consultation Opens September 11. The Draft Behind It Has No Risk Chapter," 31 August 2026
- Caribbean AI Risk Management Council: "CARICOM Endorsed a Caribbean AI Roadmap on July 7. Trinidad's Deepfake Fraud Wave Shows What Still Isn't in It," 29 July 2026
- Caribbean AI Risk Management Council: Caribbean AI Risk Management Standard, public consultation announcement
- ISO: ISO/IEC 42001:2023, Artificial Intelligence Management Systems
- NIST: AI Risk Management Framework (AI RMF 1.0)