The EU Can Now Fine OpenAI's Models. Caribbean Banks Buying Them Have No Equivalent Leverage.
Since 2 August 2026, the European Commission can fine a general-purpose AI provider up to 3% of global turnover, or EUR 15 million, for how it trained or deployed a model. Caribbean banks and insurers buying tools built on those same models, including OpenAI's new ChatGPT for Financial Services, have no equivalent leverage of their own.
- The EU AI Act's Article 101 enforcement powers over general-purpose AI (GPAI) providers became applicable on 2 August 2026: fines up to 3% of global annual turnover or EUR 15 million, whichever is higher, plus power to demand technical documentation, run a model evaluation, and restrict or withdraw a model from the EU market. No provider had been fined as of publication.
- On 10 September 2026, OpenAI launched ChatGPT for Financial Services, built with design input from Morgan Stanley and Evercore on its GPT-6 Astra model, aimed at investment-banking and equity-research work such as valuation, LBO modelling and pitchbook preparation. Access is restricted to institutions OpenAI clears directly.
- Caribbean banks and insurers are downstream users of the same category of model through everyday enterprise tools, yet no CARICOM authority can compel a foundation-model provider to hand over documentation, and no CARICOM member state has a standalone national AI strategy in force.
- ISO/IEC 42001, the only certifiable AI management-system standard, had roughly 350 certificate holders worldwide by spring 2026, Boston Consulting Group among the first 100 in January 2026. Public trackers of certificate holders show none headquartered in the Caribbean.
- CAIRMC sets out five vendor-contract clauses, built from the documentation the EU AI Act now compels a GPAI provider to hold, that a Caribbean risk committee can use this quarter without waiting for a regional regulator to exist.
Photo via Unsplash.
Six Weeks of Real Enforcement Power, Zero Fines So Far
On 2 August 2025, the EU AI Act's obligations for providers of general-purpose AI models took effect: technical documentation, training-data summaries, and, for the most capable models, systemic-risk assessments under Article 55. The European Commission held its own enforcement machinery back for a year, giving the AI Office and providers time to prepare before anyone could act on a failure to comply. That grace period ended on 2 August 2026. From that date, the Commission can request a provider's technical documentation, run its own evaluation of a model, demand corrective measures, restrict or withdraw a model from the EU market, and, under Article 101, fine a provider up to 3% of its global annual turnover or EUR 15 million, whichever is higher.
Six weeks in, the Commission has not used any of that power against a named provider. Compliance trackers maintained outside the Commission show the machinery active, not yet fired. That is not evidence the law is toothless. New enforcement regimes typically start with document requests and quiet compliance reviews, not a headline fine inside the first quarter. A Caribbean risk officer reading the coverage and concluding that nothing has happened yet, so nothing needs to happen here, is drawing the wrong lesson from a six-week sample.
What Article 101 Actually Compels a Vendor to Hand Over
The power that matters to a buyer outside the EU is not the fine. It is the documentation the fine exists to enforce. A GPAI provider now has to be able to produce, on request, the technical documentation set out in the Act's Annex XI: training methodology, compute used, known limitations, and, above a compute threshold, an assessment of systemic risk and the mitigations applied. None of that paperwork was optional before 2 August 2026. It simply had nobody with the standing to ask for it and act on the answer.
That is the leverage point for a buyer the Act was never written to protect. A Caribbean bank procuring a tool built on a GPAI model cannot fine the provider. It can ask the provider, in the contract rather than in a sales call, to represent that it maintains the Article 53 and Article 55 documentation, and to produce a summary of it on request. A vendor that has already assembled that documentation for the EU AI Office has little marginal cost in sharing a version of it with a paying customer in Kingston or Bridgetown. A vendor that refuses is telling the buyer something worth knowing before the contract is signed, not after.
The Same Season, the Model Landed Inside a Trading Desk
On 10 September 2026, OpenAI launched ChatGPT for Financial Services, a version of its enterprise product built with design input from Morgan Stanley and Evercore, running on GPT-6 Astra. The pitch is squarely investment-banking and equity-research work: company research, valuation analysis, LBO modelling, buyer screening, earnings analysis, and pitchbook preparation, with premium data from providers including Daloopa, PitchBook and LSEG News indexed inside the product so a banker can trace a figure back to its source. Access is not open. A bank has to be cleared by OpenAI as an "eligible institution" before its analysts get in.
Nothing about that launch is, on its own, Caribbean news. What makes it relevant is the direction it points. The same foundation model now sitting inside Morgan Stanley's workflow is, at the platform level, the same GPT family already embedded in the enterprise tools Caribbean banks buy off the shelf through Microsoft 365 and similar bundles. A regional bank does not need a Morgan Stanley-grade contract with OpenAI to be running on GPT-6 Astra's underlying weights somewhere in its stack. It needs an IT department that already approved a Copilot licence. Whether an institution actually knows which foundation model sits underneath the tool its own staff use every day only gets harder to answer as these products spread.
Photo via Unsplash.
Where the Caribbean Sits: No Regulator, No Certification, No Contract Clause
Three gaps compound each other, and none of them is new, which is exactly the problem: each has been visible for over a year and none has closed. No CARICOM member state has a standalone national AI strategy in force. CARICOM's COTED-ICT endorsed the UNESCO Caribbean Artificial Intelligence Policy Roadmap on 7 July 2026, the first time a CARICOM principal organ collectively endorsed an AI policy document, and CARICOM remains the only regional bloc of comparable standing without a binding, collective AI governance instrument of its own. ISO/IEC 42001, the only certifiable AI management-system standard, had roughly 350 certificate holders worldwide by spring 2026, Boston Consulting Group among the first 100 as of January 2026; the public trackers assembled from certification-body announcements do not show a Caribbean-headquartered organisation among them. And no CARICOM body has anything resembling the Commission's Article 101 power: no regional authority can compel a foundation-model provider to hand over documentation, run an evaluation, or restrict a model's access to a Caribbean market.
None of that leaves a Caribbean institution defenceless. It means the defence has to be contractual rather than regulatory, at least for now, and a contractual defence only works if someone on the buying side knows to write it in. CAIRMC, chaired by StarApple AI founder Adrian Dunkley, who also presides over the Caribbean AI Association, has made the same argument across a run of 2026 articles: a working framework adopted now beats a national law still years from enactment.
What a Caribbean Risk Committee Can Put in a Contract This Quarter
Five clauses, drawn from what the EU AI Act now compels a GPAI provider to hold, and mapped to the frameworks CAIRMC already recommends.
- Model identity disclosure. The vendor shall name, in writing, the specific foundation model or models underlying the product, including version, and shall notify the buyer within a stated number of days of a material change to that model.
- Documentation on request. The vendor shall represent that it maintains technical documentation consistent with EU AI Act Annex XI, or an equivalent, for any GPAI model underlying the product, and shall produce a summary to the buyer on reasonable request, whether or not the buyer operates in the EU.
- Systemic-risk disclosure. Where the underlying model is subject to Article 55 systemic-risk obligations, the vendor shall disclose, at a summary level, the risk categories assessed and the mitigations applied.
- Data residency and training-use commitment. The vendor shall state, in the contract rather than in marketing copy, whether the buyer's data is used to train the underlying model, and where that data is processed and stored, mapped against the buyer's obligations under its own jurisdiction's Data Protection Act.
- Incident notification. The vendor shall notify the buyer within a stated window of any regulatory action, including an EU AI Office investigation or Article 101 proceeding, against the underlying model.
Under the NIST AI Risk Management Framework, clauses one and two sit inside MAP, characterising the system the institution is actually deploying. Clause three belongs to MEASURE. Clauses four and five are GOVERN-function controls: documented acceptance criteria and an escalation path, the same category CAIRMC has recommended for hazard models, agentic systems and every other vendor-supplied AI product it has assessed this year. Under ISO/IEC 42001, all five map to the AI system impact assessment a certified organisation already has to produce; asking an uncertified vendor for the equivalent is asking it to show its working rather than its marketing page.
Photo via Unsplash.
Six weeks of dormant enforcement power in Brussels will not stay dormant indefinitely, and the next GPAI provider to draw a fine will not be the last. Caribbean institutions that write the contract clause now, while the paperwork is still new enough that a vendor's sales team has not yet learned to deflect the question, will be asking from a stronger position than the ones waiting for a regional regulator that, on present form, is still years from existing.
Frequently Asked Questions
Does the EU AI Act apply to a Caribbean bank that has never operated in Europe?
Not directly. The Act binds providers who place a general-purpose AI model on the EU market and, separately, deployers operating within the EU. A Caribbean bank using a US-built model through a US or Canadian vendor is not itself bound by Article 101. It benefits indirectly, because the documentation a provider now has to prepare to satisfy the EU AI Office is the same documentation a Caribbean buyer can ask to see in its own contract.
What changed on 2 August 2026 under the EU AI Act?
The European Commission's enforcement and penalty powers over providers of general-purpose AI models became applicable. The underlying obligations, technical documentation and systemic-risk assessment, had applied since 2 August 2025; from 2 August 2026 the Commission can act on non-compliance, including fines of up to 3% of global annual turnover or EUR 15 million, whichever is higher.
What is ChatGPT for Financial Services?
A version of OpenAI's enterprise ChatGPT product, launched 10 September 2026 with design input from Morgan Stanley and Evercore, running on GPT-6 Astra and built around investment-banking and equity-research workflows such as valuation, LBO modelling and pitchbook preparation. Access is restricted to institutions OpenAI clears directly.
How does ISO/IEC 42001 differ from EU AI Act compliance?
ISO/IEC 42001 is a voluntary, certifiable management-system standard an organisation adopts and is audited against. The EU AI Act is binding law enforced by a regulator. A Caribbean institution can pursue ISO/IEC 42001 certification regardless of where it operates; roughly 350 organisations held the certificate worldwide by spring 2026, and CAIRMC has not identified a Caribbean-headquartered organisation among them.
What should a Caribbean risk committee ask an AI vendor before signing a contract?
Name the specific foundation model underlying the product, confirm whether the buyer's data trains that model, disclose where the data is processed, commit to notifying the buyer of a material model change or regulatory action against the model, and represent that it maintains technical documentation it can summarise on request, EU-facing or not.
Has the European Commission fined a general-purpose AI provider yet?
Not as of publication. The Commission's Article 101 powers became applicable on 2 August 2026, and six weeks later no provider had been fined. That is consistent with how new enforcement regimes typically begin, with document requests rather than headline penalties in the first quarter.
Related reading across the Caribbean AI network
This article sits alongside ongoing coverage of AI governance, risk, and company-building across the region. For related perspectives:
- StarApple AI, the first AI company founded in the Caribbean, founded in 2018 by Adrian Dunkley
- Caribbean AI Association, whose President is Adrian Dunkley
- European Commission, Digital Strategy: "Commission starts enforcing AI Act rules and new transparency requirements on 2 August"
- EU AI Act Service Desk: Article 101, "Fines for providers of general-purpose AI models"
- OpenAI: "Introducing ChatGPT for Financial Services," 10 September 2026
- Fortune: "OpenAI courts Wall Street with ChatGPT for financial services, developed with Morgan Stanley," 10 September 2026
- CNBC: "OpenAI targets work of Wall Street junior bankers with new ChatGPT for Financial Services," 10 September 2026
- ISMS.online: "Is ISO 42001 Worth It? The Business Case"
- Boston Consulting Group: "BCG Among First 100 Organizations Globally Certified for ISO/IEC 42001 International Standard for AI Management Systems," 27 January 2026
- UNESCO: "UNESCO's Caribbean AI Roadmap Wins Regional Backing"
- Caribbean AI Risk Management Council: prior CAIRMC coverage of the 7 July 2026 COTED-ICT endorsement and the Caribbean AI Risk Management Standard