AI Risk and Compliance13 min read

FATF Named AI Deepfakes a Money-Laundering Risk. Trinidad Had Already Logged Six Cases.

By Dr S Budall·Aug 26, 2026
TLDR
  • FATF, the global AML/CFT standard-setter, published its Horizon Scan on AI and Deepfakes on 22 December 2025, naming deepfake-enabled fraud, synthetic identity creation and autonomous AI-driven laundering as active risks to customer due diligence and onboarding controls.
  • Trinidad and Tobago's securities regulator, TTSEC, issued six public investor alerts between October 2025 and June 2026 over AI-generated deepfakes impersonating the Finance Minister, a former President, a former bank chairman and a former Prime Minister to sell fake investment schemes.
  • Sumsub's Identity Fraud Report 2025-2026 recorded a 13.3% year-on-year rise in identity fraud across Latin America and the Caribbean, with deepfakes now sitting among the top five first-party fraud schemes globally at 11% of all recorded cases.
  • CFATF, the 25-member body that runs Caribbean mutual evaluations against FATF's standards, is chaired for the December 2025 to November 2026 term by Barbados; FATF's new guidance sets the bar the next round of evaluations is likely to measure member states against.
  • The fix is not a fraud-team problem alone. FATF frames this as a customer due diligence and suspicious activity reporting gap, which means it belongs on the desk of the compliance officer, not only the security team.
Illuminated circuit board schematic on a light table, representing the digital identity verification systems that AI-generated deepfakes are built to defeat

On 22 December 2025, FATF told its 200-plus member jurisdictions, in writing, that AI-generated deepfakes are now a live tool for money laundering, terrorist financing and sanctions evasion, not a hypothetical one. Six months earlier, Trinidad and Tobago's securities regulator had already opened a file on exactly that. Between October 2025 and June 2026, the Trinidad and Tobago Securities and Exchange Commission issued six separate public alerts warning that fraudsters were using AI to fabricate video and text of the country's Finance Minister, a former President, a former bank chairman and a former Prime Minister, each one lending fake credibility to a bogus investment scheme. FATF wrote the global diagnosis. Trinidad supplied the case file before the diagnosis was even published.

That sequencing matters for anyone running an AML programme in the Caribbean. FATF's Horizon Scan is not a fraud advisory aimed at consumers. It is guidance aimed at the institutions FATF's own standards bind: banks, insurers, money services businesses and the supervisors that examine them. When a standard-setter this size names a specific technique as an active threat to customer due diligence, that technique becomes something a compliance programme is expected to have a documented answer for at the next mutual evaluation. This article sets out what FATF actually said, what Trinidad's six cases show about how the threat plays out on the ground, and what a Caribbean bank, insurer or money services business should be doing differently because of it.

What FATF's Horizon Scan Actually Says

FATF built the Horizon Scan as a forward-looking assessment of how AI is changing the risk landscape for anti-money laundering, counter-terrorist financing and counter-proliferation financing work, rather than as a rules document. Its central claim is direct: AI can be, and is being, weaponised by money launderers, terrorist financiers and sanctions evaders to get past the controls institutions already have in place.

Four risk areas carry the weight of the report. The first is deepfake-facilitated fraud: synthetic audio, video and images convincing enough to impersonate a real individual and defeat know-your-customer checks, remote onboarding, biometric verification and liveness detection at the point where an account gets opened or a large transaction gets authorised. The second is the creation of synthetic identities, built to subvert customer due diligence entirely rather than to impersonate someone who already exists. The third is automated, high-volume laundering, where AI systems pattern transactions in ways rules-based monitoring was never built to catch, with FATF flagging that autonomous AI agents may eventually run these flows without a human directing each step. The fourth is a structural one: global digital onboarding and remote verification are creating cross-border gaps that make supervision and enforcement harder for any single jurisdiction acting alone, a description that fits a region built from more than a dozen separate regulatory perimeters better than it fits most single-country markets.

None of the four risk areas names a jurisdiction, and none was written with the Caribbean specifically in mind. That is exactly why Trinidad's experience is worth reading against it. A global standard-setter describing a category of risk in the abstract, and a single CARICOM member state already logging real cases of it, is the fastest way to see what compliance the abstract description actually demands.

Trinidad's Six Alerts, in Order

TTSEC's warnings did not arrive as a single incident. They built over eight months, each one naming a new impersonation the regulator had traced back to the same pattern: AI-generated video or fabricated text, dressed up to look like it came from someone the public already trusts. The first wave, in October 2025, centred on deepfake video of former President Anthony Carmona and former Republic Bank chairman Dr Ronald Ramkissoon, both used to lend credibility to fake trading platforms promising unrealistic returns. Later alerts extended the pattern to Trinidad and Tobago's sitting Finance Minister. The sixth and most recent alert, issued 26 June 2026, covered a fabricated online article purporting to be an interview with former Prime Minister Dr Keith Rowley, published under a forged byline attributed to Guardian Media editor Kejan Haynes, with the article laid out to mimic a real newspaper page. Guardian Media confirmed publicly that no such interview took place.

Read across all six alerts, a working pattern emerges. The fraudsters are not building elaborate new infrastructure. They are cloning the credibility of institutions the public already trusts: a government ministry, a courthouse, a bank boardroom, a national newspaper, and routing that borrowed trust straight into a fake trading platform that collects deposits and personal data before disappearing. TTSEC's own advice to the public tracks the FATF diagnosis closely: verify a claimed investment offer directly with the regulator, treat pressure to deposit quickly as a red flag, and check registration before sending money. That is sound consumer guidance. It is not, on its own, an AML control. A bank or payment processor sitting downstream of one of these schemes, receiving the deposits, still has to answer a separate question: could its own onboarding and monitoring have caught this before TTSEC had to say anything in public at all.

The Numbers Behind the Pattern

Trinidad's six alerts are not an isolated regional anomaly. Sumsub's Identity Fraud Report 2025-2026, drawn from analysis of more than four million fraud attempts, found identity fraud cases across Latin America and the Caribbean rising 13.3% year on year, with deepfakes now ranking among the top five first-party fraud schemes worldwide, at 11% of all recorded cases. The same report found multi-step, sophisticated fraud schemes, the kind that combine a fabricated identity with a staged deposit and a staged withdrawal, up 180% year on year, with complex attacks growing from 10% to 28% of all identity fraud cases the firm tracked. An earlier Sumsub regional study had already flagged Latin America and the Caribbean as the fastest-growing market for deepfake incidents specifically, up 255% between 2023 and 2024.

Put the two data sets beside each other and the direction is consistent even where the exact methodologies differ: deepfake and synthetic-identity fraud is growing faster in this region than the broader identity-fraud trend it sits inside, and it is growing from a smaller regulatory base of experience dealing with it. That combination, fast growth against thin institutional memory, is precisely the condition FATF's Horizon Scan was written to flag, and precisely the condition a CARICOM member state's next mutual evaluation is likely to test for.

Where CFATF Fits

The Caribbean Financial Action Task Force is the body that actually checks whether Caribbean institutions meet FATF's standards in practice. CFATF groups twenty-five states across the Caribbean Basin and runs the mutual evaluation process that scores each member's AML/CFT regime against FATF's recommendations, findings that feed directly into a country's standing with correspondent banks, reinsurers and international payment networks. For the December 2025 to November 2026 term, CFATF's chairmanship sits with Barbados, represented by Attorney General Wilfred Abrahams.

FATF's Horizon Scan was published squarely within that evaluation cycle. Mutual evaluations move slowly and methodically, but they do not ignore a standard-setter's own published risk assessment once it exists. An institution that treats AI-enabled deepfake fraud as a fraud-team problem today, rather than a customer due diligence and suspicious activity reporting gap with a paper trail behind it, is choosing to discover the difference at examination time rather than before it. That is an avoidable position, and it is the specific position this article is written to help a compliance officer get ahead of.

What This Means for Banks, and Separately, for Insurers

Banks and payment institutions are the most obvious exposure, and the one FATF's language addresses most directly: remote account opening, video-call identity verification and biometric liveness checks are the exact controls deepfakes are built to beat. A voice clone convincing enough to authorise a wire transfer over the phone, or a synthetic video convincing enough to pass a liveness check during onboarding, defeats the specific control most institutions currently rely on as their strongest line of defence, precisely because that control was designed for a threat model that assumed a real human on the other end of the call.

Insurers carry a related but distinct version of the same exposure, one that gets less attention in most Caribbean risk conversations, including Caribbean insurance coverage specifically. Claims fraud built on fabricated voice or video, a staged call reporting a loss, a doctored image supporting a claim, a synthetic voice authorising a beneficiary change on a policy, sits inside the same technique FATF just named, applied to a different transaction type. An insurer's claims desk asking whether a caller's voice sounds right is running the same failing test a bank's onboarding desk runs when it asks whether a video call looks right. Both need a documented, tested alternative, not a trained ear.

Building the Response Into an Existing Programme

The institutions best placed to respond are not the ones buying new deepfake-detection software first. They are the ones that already know where deepfake risk sits inside a programme they have built for other reasons. Under CAIRMC's Caribbean AI Risk Taxonomy, an AI system used for identity verification, transaction monitoring or claims triage sits at Risk Tier 3 or 4, the tiers that carry the heaviest documentation and human-oversight expectations under our own methodology, and under the EU AI Act's own high-risk category for institutions with EU-linked business. That classification is not new guidance created by FATF's report. It is confirmation that a control category most Caribbean institutions had already flagged as high-risk for other regulatory reasons has now acquired a second, independent reason to stay there.

ISO/IEC 42001:2023 gives the practical structure for the fix, through its requirement that an organisation determine and document the competence of the people running its AI-adjacent processes, which for a compliance function means retraining customer due diligence staff specifically on deepfake red flags rather than assuming existing fraud training already covers it. The NIST AI Risk Management Framework's GOVERN function makes the same point from a different angle: training has to match the policies staff are actually expected to follow, and a policy written before December 2025 was written before this specific risk existed in FATF's own documented scope. Three changes carry most of the practical weight: procuring liveness detection built to catch AI-generated video rather than only a static photograph, adding deepfake-specific indicators to the red-flag list that triggers a suspicious activity report, and giving the compliance function, not only the fraud or security team, formal ownership of the response. An institution that has done all three has a real answer ready the next time a CFATF examiner asks for one, rather than a promise to build one.

Caribbean AI Network

CAIRMC's work on AI risk governance sits alongside a wider network of Caribbean AI organisations building capacity across the region:

Frequently Asked Questions

What did FATF's Horizon Scan on AI and Deepfakes actually find?

Published 22 December 2025, FATF's Horizon Scan names AI-generated deepfakes as an active tool for money laundering, terrorist financing and sanctions evasion. It flags four risk areas: deepfake-facilitated fraud that defeats know-your-customer checks, remote onboarding and biometric liveness detection; synthetic identity creation built to subvert customer due diligence; automated, high-volume laundering that AI can pattern past rules-based monitoring; and cross-border supervision gaps created by global remote onboarding.

How many investor alerts has TTSEC issued over AI deepfake scams, and who has been impersonated?

Trinidad and Tobago's Securities and Exchange Commission issued six public alerts between October 2025 and June 2026. The impersonations included the Finance Minister, former President Anthony Carmona, former Republic Bank chairman Dr Ronald Ramkissoon, and a fabricated interview with former Prime Minister Dr Keith Rowley published under a forged Guardian Media byline.

What is CFATF, and does it examine AI-related risk in Caribbean banks?

CFATF, the Caribbean Financial Action Task Force, is the 25-member body that runs mutual evaluations of AML/CFT regimes across the Caribbean Basin against FATF's standards. It is chaired for the December 2025 to November 2026 term by Barbados, represented by Attorney General Wilfred Abrahams. CFATF does not publish AI-specific rules itself, but its evaluations measure member states against FATF's own standards, which now include the Horizon Scan's findings.

How do deepfakes defeat standard know-your-customer and biometric checks?

Synthetic audio and video convincing enough to imitate a real person can pass a remote video identity check or a liveness detection step, controls most institutions built assuming a genuine human was present on the call. A cloned voice can also be convincing enough to authorise a transaction or a policy change over the phone without triggering suspicion from staff trained to listen for inconsistency rather than to verify against a technical standard.

What should a Caribbean bank or insurer do about this now?

Three changes carry most of the weight: procure liveness detection built specifically to catch AI-generated video rather than only a still photograph, add deepfake-specific indicators to the red-flag list that triggers a suspicious activity report, and give the compliance function, not only fraud or security teams, formal ownership of the response so it is documented ahead of the next CFATF examination.

Are Caribbean insurers exposed to this risk, or only banks?

Insurers carry a distinct version of the same exposure. A fabricated voice or video used to report a loss, support a claim, or authorise a beneficiary change runs on the same technique FATF flagged for banking onboarding, applied to claims handling instead. A claims desk relying on whether a caller sounds credible is running the same test that fails at a bank's video-verification desk, and needs the same kind of documented, tested alternative.

CAIRMC works alongside the Caribbean AI Association and StarApple AI, the Caribbean's first AI company, in building AI risk governance capacity across the region.

Sources and References
  • FATF: Horizon Scan, AI and Deepfakes, Impacts on Money Laundering, Terrorist Financing and Proliferation Financing, published 22 December 2025
  • Trinidad and Tobago Securities and Exchange Commission: public investor alerts on AI-generated deepfake investment scams, October 2025 to June 2026
  • Trinidad Guardian: "TTSEC warns of rising investment scams and fake AI endorsements," coverage of TTSEC's sixth alert, June 2026
  • Sumsub: Identity Fraud Report 2025-2026
  • Caribbean Financial Action Task Force (CFATF): membership and 2025-2026 chairmanship information, cfatf-gafic.org
  • ISO: ISO/IEC 42001:2023, Artificial Intelligence Management Systems
  • NIST: AI Risk Management Framework (AI RMF 1.0), GOVERN function
  • Caribbean AI Risk Management Council: Caribbean AI Risk Taxonomy and CARA methodology, caribbeanairisk.com