Regulation & Compliance18 min read

The AI Compliance Countdown: What Every Caribbean Business Must Do Before 2027

By Adrian Dunkley, President·Jun 15, 2026
TLDR
  • The bulk of the EU AI Act applies from August 2026, with the obligations for many high-risk AI systems phased to December 2027. Caribbean companies that serve European clients, process European data, or use EU-origin AI vendors are directly in scope. Penalties reach 35 million EUR or 7% of global annual turnover for prohibited practices, and 15 million EUR or 3% for high-risk system violations.
  • CARICOM-EU trade runs to several billion euros a year. That commercial footprint means many Caribbean businesses already have EU exposure, and therefore EU AI Act obligations, whether they know it or not.
  • Bank of Jamaica supervisory expectations on technology and model risk, CARICOM's emerging AI governance work, and the regional financial regulators' fintech and model-risk guidance together create a layered compliance environment. Caribbean businesses must meet all of it at once.
  • The Caribbean faces an acute shortage of qualified AI compliance professionals. That scarcity makes a structured, prioritised approach essential: there is no capacity to treat everything as urgent.
  • Five specific actions follow that Caribbean businesses must complete before 2027 to reach baseline compliance across both the EU regulatory perimeter and the emerging Caribbean domestic frameworks.
Caribbean coastline and blue water representing the region's business environment

The compliance window that Caribbean businesses thought they had is narrowing fast. The bulk of the EU AI Act's obligations became applicable in August 2026, and the obligations specific to many stand-alone high-risk AI systems (Annex III) have been phased to December 2027 under the EU's Digital Omnibus agreement. As those obligations bite, any organisation placing a high-risk AI system in service in the European market, or deploying such a system that affects EU persons, faces the full weight of the regulation: mandatory conformity assessments, technical documentation requirements, human oversight obligations, and, under Article 99, penalties of up to 15 million EUR or 3 percent of global annual turnover for high-risk system violations (rising to 35 million EUR or 7 percent for prohibited practices), whichever is higher.

Many Caribbean executives read that sentence and conclude it does not apply to them. They are wrong. The EU AI Act's jurisdictional reach follows the data and the market, not the geography of the deploying company. A Jamaican financial institution using an AI credit scoring model sourced from a European vendor, and processing loan applications from EU-resident Jamaicans, is a deployer under the Act. A Barbadian insurance company using EU-origin AI underwriting software to price policies for European tourists is in scope. A Trinidadian fintech serving the diaspora in the United Kingdom, which remains broadly aligned with EU AI Act standards in its own AI regulation, faces equivalent obligations. For Caribbean businesses the live question is no longer whether the Act applies, but how much of their AI exposure it covers and what they need to do about it.

The EU AI Act Has Arrived: Caribbean Companies Are in Scope

CARICOM and the wider CARIFORUM bloc trade billions of euros' worth of goods and services with the European Union each year under the EU-CARIFORUM Economic Partnership Agreement. That figure represents the formal trade relationship. The AI exposure is broader. It includes Caribbean financial services firms serving EU-resident customers through digital channels, Caribbean technology companies providing services to European clients, and Caribbean organisations using AI systems built and maintained by EU-based vendors. Any organisation in one of those categories that uses AI classified as high-risk under the Act, including AI in credit scoring, employment decisions, educational access, and critical infrastructure management, is a covered entity.

The high-risk classification is broad. The Act lists eight categories of high-risk AI in Annex III, covering biometric identification, critical infrastructure management, education and vocational training, employment decisions, essential private and public services (including credit scoring and life insurance underwriting), law enforcement, migration and border control, and administration of justice. A Caribbean bank using AI credit decisioning is deploying Annex III high-risk AI. A Caribbean insurer using AI for life insurance underwriting is doing the same. The compliance obligations that apply are substantial: mandatory conformity assessment, technical documentation, logging and audit trail requirements, human oversight provisions, and registration in the EU AI Act database for certain systems.

The penalties are equally substantial. Article 99 sets the maximum fine for violations related to high-risk AI systems at 15 million EUR or 3 percent of global annual turnover, and the maximum for prohibited AI practices at 35 million EUR or 7 percent of global annual turnover. For a Caribbean financial institution with a regional balance sheet, a penalty at the lower end of that range would be existential. The risk is not theoretical: the European AI Office, established to coordinate enforcement, has been active since its inception, and EU member state regulators have signalled that cross-border enforcement, including against non-EU entities serving the European market, is a priority.

Five Compliance Actions for Caribbean Businesses

The compliance challenge Caribbean businesses face in 2026 and 2027 is manageable with the right structure. The five actions below are sequenced by urgency and logical dependency, each building on the one before. An organisation that completes all five will have achieved baseline compliance with the EU AI Act's obligations as they apply to Caribbean deployers, and will simultaneously have laid the groundwork for meeting the emerging Caribbean domestic frameworks described in the sections that follow.

Action 1: Map Your AI Exposure. Before any compliance work can be scoped, an organisation must know what AI it uses, where that AI came from, and whether any of it touches EU data or EU clients. This is an AI inventory exercise, and it routinely reveals AI deployments that senior management and the board were not aware of. Marketing teams deploy AI tools for customer segmentation. HR departments use AI screening tools for recruitment. Finance teams use AI for expense analysis and forecasting. Each of these may be out-of-scope for EU AI Act purposes, or each may be high-risk depending on the specific use case and the population affected.

The inventory should capture: the name and vendor of each AI system in use; the category of decision it supports or automates; whether it processes data from EU-resident individuals; the vendor's jurisdiction and the governing law of the supply contract; and the risk classification the vendor has assigned or that the organisation has independently assessed. This inventory is the foundation of every subsequent compliance step, and it is the first document a regulator will request in an enforcement inquiry.

Action 2: Assess Which Systems Are High-Risk. Once the inventory is complete, each AI system must be assessed against the Annex III categories. This is a legal and technical exercise, not solely a technology one: the risk classification depends on the specific use case, not just the type of AI. A machine learning model used for internal research is not the same as the same model used to make or substantially influence a credit decision. A classification error, either over-classifying low-risk systems and triggering unnecessary compliance costs, or under-classifying high-risk systems and missing the obligation, is expensive. Most Caribbean organisations will need external legal or compliance support for this step, given the complexity of the Act and the shortage of Caribbean professionals with direct EU AI Act expertise.

For systems that are classified as high-risk, the deployer (the Caribbean organisation using the system, even if a European vendor built it) must ensure that the technical documentation required under Article 11 exists and is current. If the vendor has not provided this documentation, the organisation must request it. Vendors who cannot produce conformant Article 11 documentation are a material compliance risk, and the supply contract should include explicit provisions requiring it.

Action 3: Establish Human Oversight for High-Risk AI. Article 14 of the EU AI Act requires that high-risk AI systems be designed and deployed to allow effective human oversight. For Caribbean deployers, this means that wherever a high-risk AI system generates an output that affects a material decision, a qualified human must be in a position to understand what the system is doing, identify failures or biases, and override the system's output when appropriate. The human oversight provision is not satisfied by nominally having a human in the loop who has no practical ability to understand or override the AI. Regulators have been explicit on this point.

In practice, for Caribbean financial institutions using AI credit scoring: loan officers who approve or decline applications based on AI scores must have access to sufficient information about how the score was generated to make a meaningful independent judgment. They must be trained to identify when a score may be anomalous. They must have authority to deviate from the AI recommendation with documented rationale. These are not just compliance requirements. They are sound risk management practices that Caribbean financial regulators have independently converged on through their own frameworks.

Action 4: Build the Documentation and Audit Trail. The EU AI Act requires deployers to maintain logs of high-risk AI system operation to the extent this is within their control under Article 12, and to retain these logs for at least six months (with sector-specific extensions in regulated industries). For Caribbean financial institutions, where financial records retention requirements already extend to five to seven years in most jurisdictions, the AI log retention obligation should be integrated into existing records management frameworks rather than treated as a separate system.

Documentation requirements extend beyond logs. Deployers must maintain records of the conformity assessment for each high-risk system, the technical documentation provided by the developer, the results of any testing conducted before deployment, and records of incidents or near-misses involving the AI system. This documentation package is what an enforcement authority will examine. Caribbean organisations that cannot produce it face not only the substantive penalties for compliance failures but the procedural penalties for documentation failures, which can be imposed independently.

Action 5: Integrate AI Compliance into the Risk Governance Framework. The first four actions are operational: they produce an inventory, a classification, a human oversight structure, and a documentation set. Action 5 is structural: it ensures that AI compliance is owned, resourced, and maintained within the organisation's risk governance framework rather than existing as a one-time exercise that degrades over time.

This means designating a named individual as responsible for AI compliance (not just technology compliance generally). It means including AI risk in the organisation's risk appetite statement and risk register. It means ensuring that new AI system deployments go through a compliance assessment before go-live, not after. It means building AI compliance into vendor management processes so that EU AI Act requirements flow through to AI vendor contracts. And it means establishing a process for monitoring regulatory developments across the EU AI Act implementation cycle, the Caribbean domestic frameworks, and the sector-specific guidance that financial regulators in Jamaica, Trinidad and Tobago, and Barbados continue to develop.

Bank of Jamaica Supervisory Expectations on Technology and Model Risk

Financial services building representing Caribbean banking regulation

The Bank of Jamaica, as the supervisor of Jamaica's deposit-taking institutions, issues supervisory guidance and reporting requirements that set its expectations for technology and model risk. Such supervisory guidance does not always have the same binding force as a prudential rule, but in Jamaica it typically functions as the direct precursor to formal regulatory requirements, and examination teams use it as the benchmark against which supervised institutions are assessed. The practices below reflect the direction of that supervisory expectation, consistent with model-risk-management norms that prudential regulators internationally have converged on.

The first expectation is that supervised institutions maintain an inventory of the AI and analytical models in use, with documentation of each model's purpose, its training data, its validation approach, and its ongoing performance monitoring. This maps directly onto Action 1 and Action 4 in the five-step framework above: organisations that have built an EU AI Act-compliant inventory and documentation set will find that much of this expectation is already met.

The second is that AI models used in credit, risk, and compliance functions be subject to independent validation before deployment and on a recurring basis thereafter. Independent validation means validation by a party who did not build or configure the model. For Caribbean banks relying entirely on vendor-provided AI, this means commissioning independent technical assessments of the vendor's models, or requiring the vendor to provide third-party validation reports. This is a materially higher bar than most Caribbean banks currently meet, and it is an area where the regional shortage of qualified AI and model-risk professionals creates a practical execution risk.

The third concerns model risk management more broadly: that supervised institutions have a model risk management policy, assign model risk ownership, and report material model failures to the Board Risk Committee. This aligns with Action 5 in the framework: integrating AI compliance into the broader risk governance structure is not only an EU AI Act requirement but a sound prudential expectation.

CARICOM's AI Governance Framework: What Is Coming

CARICOM's draft AI Governance Framework, circulated for regional consultation in early 2026, represents the largest piece of Caribbean-specific AI regulatory infrastructure to emerge from the regional integration process. It is not yet binding: it is a framework for member states to implement through domestic legislation, and the pace of implementation will vary across the 15 CARICOM member states. But the framework's provisions signal where Caribbean domestic AI regulation is heading, and organisations that have built compliance structures for the EU AI Act and the Bank of Jamaica circular will be well-positioned to meet the emerging CARICOM requirements.

The CARICOM framework's core provisions align closely with international standards: risk-based classification of AI systems, transparency obligations for AI-assisted decision-making that affects individuals, requirements for human oversight in high-stakes decisions, and accountability mechanisms that assign clear responsibility for AI outcomes. The framework places particular emphasis on two issues that reflect Caribbean-specific concerns: first, the risk that AI systems trained predominantly on non-Caribbean data will perform poorly or discriminately for Caribbean populations; and second, the dependence of Caribbean AI deployments on infrastructure, models, and expertise located outside the region.

On the data representation issue, the framework recommends that Caribbean organisations deploying AI for decisions affecting Caribbean individuals document the training data composition of any AI system and assess whether the data is sufficiently representative of the Caribbean population the system will serve. This is not a requirement that Caribbean organisations will find easy to meet for vendor-provided systems: most AI credit scoring models, fraud detection systems, and underwriting tools used in the region were trained on US, European, or Latin American data with limited Caribbean representation. The gap between the framework's aspiration and current vendor practice is substantial, and it represents both a compliance risk and a genuine model performance risk.

Caribbean Financial Services: The Highest-Risk Sector

The Caribbean fintech sector is estimated to be worth on the order of US$1 billion to US$1.5 billion as of 2025 and is growing rapidly. The broader financial services sector, including banks, insurance companies, credit unions, and payment service providers, is the largest organised deployer of AI in the Caribbean economy. It is also the sector most exposed to the convergence of EU AI Act requirements, Bank of Jamaica circular expectations, and CARICOM framework provisions.

Caribbean financial institutions face a specific compliance complexity that non-financial sector organisations do not. Financial services AI systems are disproportionately concentrated in the high-risk categories under the EU AI Act: credit scoring, insurance underwriting, fraud detection, and AML transaction monitoring are all Annex III use cases. Every major Caribbean bank and insurer is therefore a high-risk AI deployer under the EU framework, regardless of their EU market exposure. The compliance obligations are not optional for these institutions: they are triggered by what the AI does, not solely by where the clients are.

The AML use case deserves particular attention. Caribbean financial institutions operate under intense correspondent banking pressure, with major US and European banks requiring evidence of strong AML controls as a condition of maintaining correspondent relationships. AI-based transaction monitoring is increasingly the technology infrastructure through which Caribbean banks demonstrate that their AML programmes meet correspondent bank standards. When that AI is a high-risk system under the EU AI Act, and the correspondent banks that demand AML evidence are themselves subject to EU regulation, the compliance chain reaches from the EU through the correspondent bank directly to the Caribbean institution's AI system. A Caribbean bank whose AI transaction monitoring tool cannot be shown to meet EU AI Act standards may face questions from its correspondent banks that go beyond regulatory compliance to operational continuity.

How the Caribbean AI Risk Management Council Can Help

The Caribbean AI Risk Management Council, established by Adrian Dunkley of StarApple AI as the Caribbean's first dedicated AI governance institution, developed the first Caribbean AI risk governance framework in 2024. That framework anticipated the regulatory convergence now arriving from three directions: the EU AI Act, the Bank of Jamaica circular, and the CARICOM draft framework. Caribbean organisations that have engaged with CAIRMC's published frameworks are not starting from zero on any of these requirements.

The CAIRMC AI compliance programme offers Caribbean businesses a structured path through the five-step roadmap described in this article. The programme includes an AI inventory methodology calibrated to the Caribbean business environment, a risk classification protocol that maps Caribbean AI use cases to EU AI Act categories, human oversight design guidance tailored to the staffing and system constraints Caribbean institutions actually face, and a documentation framework that satisfies both EU requirements and Bank of Jamaica circular expectations in a single set of records.

The shortage of qualified AI compliance and model-risk professionals across the region means that many Caribbean organisations cannot build internal AI compliance capacity at the pace the regulatory timeline requires. CAIRMC's practitioner network, which spans the wider Caribbean AI community including the Caribbean AI Association, AI Jamaica, AI T&T, 14West AI, and the advisory network of Adrian Dunkley, provides access to practitioners with direct experience in Caribbean AI risk, EU AI Act compliance, and the specific regulatory environments of Jamaica, Trinidad and Tobago, Barbados, and the wider CARICOM region.

The five-step framework is not a long-term project. For most Caribbean businesses, the inventory and classification steps can be completed within six to eight weeks with appropriate external support. The human oversight and documentation structures can be built in parallel over the following two to three months. The governance integration step, the structural piece that makes compliance self-sustaining, requires leadership commitment rather than technical expertise, and it is the step where CAIRMC's board-level frameworks provide the most direct support.

The 2027 deadline is now under eighteen months away, and the EU AI Act's August 2026 application date means Caribbean organisations with EU exposure are already inside the enforcement window. The choice is between acting now on Caribbean terms with a structured approach, or acting later under regulatory pressure, which costs more and gives the organisation far less control. The five steps and the support to follow them are in place. What is missing in most organisations is the decision to begin.

Frequently Asked Questions

Does the EU AI Act apply to Caribbean businesses?

Yes. The EU AI Act's jurisdiction follows data and markets, not the geography of the deploying company. Any Caribbean business that serves EU-resident clients, processes data from EU persons, or uses EU-origin AI systems for decisions affecting EU individuals is in scope as a deployer. CARICOM and the wider CARIFORUM bloc trade billions of euros with the EU each year, a large commercial footprint that brings many Caribbean companies within the Act's reach. For most, the live question is how much of their AI exposure the Act covers, not whether it applies.

What are the EU AI Act penalties for non-compliance?

Under Article 99 of the EU AI Act, violations related to high-risk AI systems carry penalties of up to 15 million EUR or 3 percent of global annual turnover, whichever is higher. Violations involving prohibited AI practices carry penalties of up to 35 million EUR or 7 percent of global annual turnover. These penalties apply to deployers, including non-EU organisations that deploy covered AI systems affecting EU persons. For a Caribbean financial institution, a penalty even at the lower range of the scale would be operationally severe.

What does the Bank of Jamaica expect for AI and model risk?

Bank of Jamaica supervisory expectations on technology and model risk point supervised institutions toward maintaining an AI and analytical model inventory covering each model's purpose, training data, validation approach, and performance monitoring; independently validating AI models used in credit, risk, and compliance functions before deployment and on a recurring basis; and maintaining a model risk management policy with designated ownership of model risk and board-level reporting of material model failures. These expectations closely parallel EU AI Act obligations and can largely be met through the same compliance infrastructure.

What are the five compliance steps Caribbean businesses must take before 2027?

The five steps are: (1) Map your AI exposure by building a complete inventory of all AI systems in use, their vendors, their use cases, and their EU data or client exposure. (2) Assess which systems qualify as high-risk under EU AI Act Annex III. (3) Establish documented human oversight structures for each high-risk system meeting the Article 14 standard. (4) Build the technical documentation and audit trail required under Articles 11 and 12. (5) Integrate AI compliance into the organisation's formal risk governance framework with named ownership and ongoing monitoring processes.

What is CARICOM's draft AI Governance Framework?

CARICOM's draft AI Governance Framework, circulated for regional consultation in early 2026, provides a risk-based classification system for AI systems, transparency obligations for AI-assisted decisions affecting individuals, human oversight requirements, and accountability mechanisms assigning clear responsibility for AI outcomes. It emphasises two Caribbean-specific concerns: the risk that AI trained predominantly on non-Caribbean data will perform poorly or discriminately for Caribbean populations, and the region's dependence on AI infrastructure, models, and expertise located outside the Caribbean. Member states are expected to implement the framework through domestic legislation at varying speeds.

Why is Caribbean financial services the highest-risk sector for AI compliance?

Caribbean financial services is the highest-risk sector because its core AI use cases, including credit scoring, insurance underwriting, fraud detection, and AML transaction monitoring, are disproportionately concentrated in the EU AI Act's Annex III high-risk categories. Every major Caribbean bank and insurer is therefore a high-risk AI deployer regardless of their EU market exposure. The AML context adds a further dimension: Caribbean banks must demonstrate AI compliance to maintain correspondent banking relationships with European and US institutions that are themselves subject to AI regulation, creating a compliance chain that reaches directly into Caribbean AI systems.