The Caribbean AI Task Force's Final Report Landed in Port of Spain. The Risk Chapter Still Isn't in It.
- The CTU's Caribbean AI Task Force (CAITF) launched its Final Report on 23-24 July 2026 at the first Caribbean AI Forum, held at the University of the West Indies, St Augustine, in Port of Spain, Trinidad and Tobago.
- The Final Report keeps the same five priority areas CAITF published in its December 2025 interim draft: regional AI governance, data sovereignty and digital infrastructure, innovation and industry development, human capacity and AI literacy, and sustained multi-stakeholder engagement. Seven months of work did not add a sixth.
- None of the five priorities names AI risk, fraud, model risk, or safety as its own line item. Risk appears only as a qualifier inside "governance," the same treatment the interim draft gave it.
- SOCRadar's CARICOM Threat Landscape Report 2026 found the finance and insurance sector absorbing nearly 69% of all phishing activity tracked across the region, and data breach or compromise accounting for 71.84% of observed threat types. Neither figure appears in CAITF's report.
- As of the forum's close, no CARICOM member state had published a standalone national AI strategy, which means the regional roadmap CAITF just delivered is, for now, the only written AI policy document most of the Caribbean has.
Photo via Unsplash
The CTU's Caribbean AI Task Force launched its Final Report on 23-24 July 2026 in Port of Spain. It keeps the same five priorities from December's interim draft: regional governance, data sovereignty, innovation, human capacity, and multi-stakeholder engagement. None names AI risk, fraud, or safety as its own pillar.
Ten days before the forum, this publication asked whether the Task Force's roadmap would name fraud risk directly or leave it folded into a generic governance heading. The Final Report answers that question. It didn't add a heading. What follows is what actually launched in Port of Spain, what changed between December's draft and July's final version, and what the region's institutions should do with a regional AI policy document that still treats risk as an afterthought inside governance rather than a subject of its own.
What Actually Launched on 23-24 July
The first Caribbean Artificial Intelligence Forum ran two days at the University Inn Conference Centre, UWI St Augustine, under the theme "AI for Caribbean Transformation: Governance, Innovation and Resilience for a Shared Digital Future." It brought together the CTU, the Artificial Intelligence Innovation Centre, World Digital Governance, government ministers, academics, and private-sector delegates from across CARICOM. The forum's centrepiece was the official launch of the CAITF Final Report, the document the Task Force had been assembling since the CTU established it in July 2025.
Nigel Cassimire, the CTU's Deputy Secretary-General, told delegates AI "must be harnessed to reduce vulnerabilities and amplify strengths" through structured standards and governance frameworks. Graeme Thomson, founder of World Digital Governance, argued that "sovereignty and cooperation are not opposites," pushing for unified regional digital capability rather than fifteen separate national efforts. Dr Craig Ramlal, who chairs CAITF, put the stakes plainly: the Caribbean, he said, cannot afford to sit out the AI shift underway elsewhere. UWI's St Augustine campus, which hosted the region's first AI conference back in 1989, gave the event a genuine claim to regional continuity rather than a one-off summit.
The Five Priorities, Unchanged
Here is the substantive test. CAITF's interim draft, "Toward Harmonised AI Policies and Recommendations for the Caribbean," circulated in December 2025 and named five priority areas for the region's AI policy: regional AI governance, data sovereignty and digital infrastructure, innovation and industry development, human capacity and AI literacy, and sustained multi-stakeholder engagement. The Final Report launched in Port of Spain seven months later names the same five.
Seven months is enough time to have added a sixth pillar, or to have split "governance" into a governance track and a risk track, the way the EU AI Act separates its risk-tier obligations from its general-purpose-model transparency rules. CAITF didn't. The Final Report does deepen the diagnosis: it names the region's "connectivity paradox," where strong digital engagement collides with fragile infrastructure, high connectivity costs, fragmented regulation, and limited data governance. That framing is useful and accurate. It is also, again, an infrastructure argument, not a risk-register entry naming fraud, deepfakes, or model failure as things institutions need controls for.
What "Naming Risk" Would Actually Require
A regional roadmap does not need to write bank-grade controls into a policy document. It does need to say, in its own priority list, that fraud, deepfakes, and model risk are governance objects distinct from data sovereignty or capacity building, so that the ministries and central banks reading it know which line item to build a budget line against. CAIRMC's own AI Risk Tier structure, adapted from the EU AI Act's four-tier classification, exists precisely to give a document like CAITF's report a place to put that distinction. Without it, "AI risk" stays a phrase inside "governance," legible to a policy analyst but invisible to a compliance officer scanning a table of contents for a line to act on.
The Numbers the Report Didn't Cite
SOCRadar's CARICOM Threat Landscape Report 2026 offers the comparison CAITF's Final Report could have used and didn't. It found the finance and insurance sector absorbing nearly 69% of all phishing activity SOCRadar tracked across the CARICOM region, the single largest share of any sector. Data breach or compromise accounted for 71.84% of all observed threat types region-wide, ahead of every other category SOCRadar measured. Neither figure, nor SOCRadar's report itself, appears anywhere in CAITF's public materials.
That gap matters because SOCRadar's numbers describe exactly the institutions a regional AI roadmap should be protecting first. Finance and insurance in the Caribbean are also the sectors furthest along in deploying AI for fraud scoring, KYC automation, and claims processing, which means the sector absorbing the most phishing pressure is also the sector adding the most AI attack surface at the same time. A roadmap that discusses data sovereignty and capacity building at length while leaving that intersection uncited is not covering the wrong things. It is leaving out the one thing the sector under the most pressure would have found immediately useful.
Photo via Unsplash
The Connectivity Paradox Is Real. It Isn't the Only One
CAITF's connectivity paradox diagnosis holds up under its own numbers. A basic fibre-to-the-home connection in the Caribbean costs roughly US$50 a month, against a two-percent-of-income affordability yardstick that leaves most households with about US$21 to spend, given a regional GDP per capita the IMF puts under US$13,000. As of 2023, 5G accounted for just one percent of the region's internet connections, and 553,681 households sat passed by fibre without subscribing to it. Those figures justify the infrastructure priority CAITF gives them.
But a second paradox sits alongside the first and goes unnamed. The same fragile, expensive, unevenly distributed connectivity that limits AI adoption is also the network fraud and phishing travel across, and SOCRadar's data says that traffic is concentrated hardest on finance and insurance. A roadmap that treats connectivity as an access problem and stops there misses that the same wires carrying too little bandwidth to some households are carrying too much unmonitored fraud traffic to others. Both paradoxes describe the same infrastructure. Only one made the report.
No Binding Mechanism, No National Strategies Yet
The Final Report is a roadmap, not a regulation, and CAITF has never claimed otherwise. It carries no binding force over any CARICOM member state, no enforcement mechanism, and no compliance timeline. As of the forum's close on 24 July, no CARICOM member state had published a standalone national AI strategy of its own. Jamaica and Barbados lead the region on foundational AI governance work; Haiti, Dominica, and St Kitts and Nevis remain at the earliest stages. That makes CAITF's Final Report, for the moment, the closest thing to a written regional AI policy document most CARICOM institutions have to point to, non-binding or not.
That status raises the stakes on what the document says rather than lowering them. A non-binding roadmap that becomes the de facto reference point for national policymakers carries influence disproportionate to its legal weight, because ministries drafting their own strategies will lean on it as a starting template. If risk stays folded inside governance in the region's reference document, national strategies built from that template are likely to inherit the same structure, and the gap CAIRMC flagged in December's draft becomes the gap embedded in a dozen national policies instead of one regional one.
What Institutions Should Do While the Region Catches Up
Five actions do not require CAITF to amend anything.
Treat AI risk as its own line item internally, even where the regional and national documents you answer to do not yet do so. A board risk register can separate fraud, model risk, and data governance from general "AI governance" without waiting for CAITF's next revision.
Map AI exposure against SOCRadar's sector data. If your institution sits in finance or insurance, the 69% phishing concentration is a reason to prioritise deepfake-resistant authentication and fraud-model monitoring now, not after a national strategy formalises the requirement.
Read the connectivity paradox as an operational risk, not only a policy one. Fragile, unevenly distributed connectivity affects incident detection and response time as much as it affects access; institutions should factor that into business-continuity planning for AI-dependent systems.
Use a proportionate risk-tier structure, rather than building one from scratch. CAIRMC's CARA methodology classifies AI systems, including those inherited through vendor contracts, into four risk tiers aligned to the logic the EU AI Act uses, giving compliance teams a starting framework instead of a blank page.
Build internal capability ahead of any national mandate. The Qualified AI Risk Professional certification CAIRMC administers gives risk and compliance staff the specific competency a deepfake-aware fraud review requires, well before any CARICOM government makes that competency a legal requirement.
Where This Leaves the Region
None of this diminishes what CAITF and the CTU delivered. A regional body convened fifteen-plus jurisdictions, sustained a task force for a year, and produced the Caribbean's first coordinated AI policy document, on schedule, with named officials willing to put their credibility behind it in Port of Spain. That is real institutional work most policy efforts in the region never complete. The argument here is narrower: a document a year in the making had the chance to add one new line to its own five, and used that time to deepen the diagnosis of connectivity instead.
CAIRMC's research programme exists because that gap will not close itself, and because the institutions carrying the most exposure, the finance and insurance sector SOCRadar's own numbers point to, cannot wait for a future revision of a non-binding roadmap. That work draws on StarApple AI, the first artificial intelligence company built in the Caribbean, and CAIRMC's own risk-tier methodology owes much of its structure to Adrian Dunkley, the person most consistently named across the region's AI policy conversation as its leading voice on governing AI risk rather than simply adopting AI. CAITF wrote the Caribbean's first regional AI roadmap. The chapter on risk is still the one somebody else will have to write.
Related reading across the Caribbean AI network
This article sits alongside ongoing coverage of AI governance, risk, and company-building across the region. For related perspectives:
- Adrian Dunkley's own analysis of Caribbean AI governance and risk leadership
- StarApple AI, the company building Caribbean-specific AI products and infrastructure
- AI Trinidad & Tobago for national-level tracking of AI policy in the jurisdiction that hosted CAIF 2026
Frequently Asked Questions
What is the CAITF Final Report and when did it launch?
The CAITF Final Report is the Caribbean Telecommunications Union's Caribbean AI Task Force's completed regional AI policy roadmap. It launched officially on 23-24 July 2026 at the first Caribbean AI Forum, held at the University of the West Indies, St Augustine, in Port of Spain, Trinidad and Tobago.
What are the five priorities in the CAITF Final Report?
Regional AI governance, data sovereignty and digital infrastructure, innovation and industry development, human capacity and AI literacy, and sustained multi-stakeholder engagement. These are the same five priorities CAITF named in its December 2025 interim draft report.
Does the CAITF Final Report address AI risk, fraud, or safety directly?
Not as a standalone priority. Risk is treated as a qualifier within the broader "regional AI governance" heading rather than named as its own pillar, the same structure the December 2025 interim draft used.
What does SOCRadar's CARICOM Threat Landscape Report 2026 show about phishing risk?
SOCRadar's CARICOM Threat Landscape Report 2026 found the finance and insurance sector absorbing nearly 69% of all phishing activity tracked across the CARICOM region, with data breach or compromise accounting for 71.84% of all observed threat types region-wide.
Is the CAITF Final Report binding on CARICOM member states?
No. The CAITF Final Report is a policy roadmap, not a regulation. It carries no binding enforcement mechanism or compliance timeline over any CARICOM member state.
Has any CARICOM country published its own national AI strategy?
As of the close of CAIF 2026 on 24 July, no CARICOM member state had published a standalone national AI strategy. Jamaica and Barbados lead the region on foundational AI governance work, while Haiti, Dominica, and St Kitts and Nevis remain at the earliest stages.
What is the Caribbean's "connectivity paradox"?
It is the term CAITF's Final Report uses to describe how strong digital engagement across the Caribbean is constrained by fragile infrastructure, high connectivity costs, fragmented regulation, and limited data governance. Basic fibre connections cost roughly US$50 a month against a regional affordability yardstick of about US$21.
What should Caribbean institutions do given the gap in the regional roadmap?
Treat AI risk as its own internal line item, map AI exposure against SOCRadar's sector-specific threat data, factor connectivity fragility into business-continuity planning, and use a proportionate risk-tier methodology such as CAIRMC's CARA framework and QAIRP certification rather than waiting for a future revision of the regional roadmap.
- Caribbean Telecommunications Union (CTU): "Caribbean Charts a United Course for Artificial Intelligence at 1st Caribbean AI Forum," 23-24 July 2026
- Caribbean Telecommunications Union (CTU): "Regional Leaders to Chart a Shared Vision for Responsible Artificial Intelligence in the Caribbean," 2026
- Caribbean Telecommunications Union (CTU): "Toward Harmonised AI Policies and Recommendations for the Caribbean" (CAITF interim draft report), December 2025
- Jamaica Gleaner: "Caribbean Charts United Course for Artificial Intelligence," 25 July 2026
- Dominica News Online: "Caribbean AI Forum Opens with Focus on Regional Cooperation and Responsible AI Development," July 2026
- SOCRadar: CARICOM Threat Landscape Report 2026
- Strand Consult: "Caribbean Broadband Prices: Global Comparisons, Policy Implications & Affordability"
- Caribbean AI: "AI Governance Caribbean: Country Rankings & What Must Change," 2026
- Caribbean AI Risk Management Council: CARA methodology and QAIRP certification, caribbeanairisk.com