The World's Financial Regulators Just Agreed on 12 AI Rules. No Caribbean Regulator Has Adopted a Single One.
- On 10 June 2026 the Financial Stability Board published a consultation report setting out 12 sound practices for AI adoption in finance, covering governance, lifecycle risk management, and cyber and third-party risk. Comments are due 22 July 2026 and a final version is expected in October 2026.
- Grant Thornton's 2026 AI Impact Survey of 950 business leaders found only 18% of banking executives were fully confident they could pass an independent review of their AI controls within 90 days, and half cited governance gaps as already limiting AI performance.
- Bank of England Deputy Governor Sarah Breeden told the European Central Bank's June 2026 Sintra forum that existing regulatory frameworks were not built for autonomous agents, and that relying on a human in the loop for every agent action is unlikely to be realistic.
- No CARICOM member state has a binding AI-specific supervisory framework for financial institutions, and no Caribbean central bank or regulator has published guidance mapped to the FSB's 12 practices.
- The FSB has no legal authority over Caribbean regulators, but its standards tend to become the reference point examiners, correspondent banks, and rating agencies measure against regardless, the way Basel capital rules did. Caribbean banks and insurers gain nothing by waiting for a domestic law to force the same conversation.
On 10 June 2026, the Financial Stability Board put out a document that most Caribbean risk officers have not read. It is not a law. The FSB cannot fine anyone or revoke a banking licence. What it published is a consultation report called "Sound Practices for Responsible Adoption of Artificial Intelligence (AI)," and it is the closest thing the global financial system has to a shared answer on what a bank, insurer, or credit union should be doing about AI governance right now.
Twelve practices, grouped into three areas, open for comment until 22 July 2026, with a final version due in October. Nothing in that timeline requires a single CARICOM institution to do anything. That is precisely why it matters. Standards with no enforcement mechanism attached to them are the ones that quietly become the benchmark, because everyone downstream, examiners, correspondent banks, reinsurers, credit rating agencies, starts asking whether an institution's practices line up with them anyway.
What the FSB Actually Published
The Financial Stability Board exists to coordinate financial oversight across the G20 economies, a role it has held since the 2009 reforms that followed the global financial crisis. Its June 2026 consultation report groups its 12 sound practices into three pillars. The first four practices cover organisation-wide AI governance: board-level accountability, a documented risk appetite for AI use, clear ownership of AI decisions, and policies that apply across the whole institution rather than one department's pilot project. Practices five through ten address the AI lifecycle itself, from model development and validation through deployment and ongoing monitoring, the same discipline banks already apply to traditional credit models, extended to cover generative and agentic systems. The final two practices, eleven and twelve, deal with AI-related cyber, IT, and third-party risk, the exposure created when a bank's AI capability actually runs on a foreign cloud platform or a vendor's foundation model rather than anything built in-house.
The report is candid about its own limits. It states plainly that the sound practices were not developed to address the risks specific to frontier AI models, the largest and newest systems. That is a deliberate scope decision, not an oversight, and it tells Caribbean readers something useful: even the body writing the global reference standard is treating frontier-model risk as a separate, harder problem it has not yet solved. Institutions in the region deploying vendor-supplied frontier models should not assume the FSB's forthcoming standard will settle that question for them either.
Why a Non-Binding Report Still Sets the Bar
Caribbean banking supervision has been here before. Basel's capital and liquidity standards were never automatically binding across the region the day the Basel Committee published them. The Bank of Jamaica, the Central Bank of Trinidad and Tobago, the Eastern Caribbean Central Bank, and the Central Bank of Barbados each built their own supervisory guidance around Basel principles over years, not because a regional law forced them to on day one, but because correspondent banks, IMF Article IV missions, and international rating agencies expected it. A Caribbean bank that could not demonstrate Basel-aligned capital adequacy found its correspondent relationships and its funding costs affected long before any domestic statute caught up.
AI governance is following the same track, faster. CARICOM's Committee of Central Bank Governors has already flagged AI as a priority for central banking operations at its recent bi-annual meetings, alongside fintech adoption and cybersecurity. That is a useful signal of intent. It is not a supervisory framework, and nothing public indicates any CARICOM member state has begun mapping its own guidance, formal or informal, to the FSB's 12 practices. The gap between "AI is on the agenda" and "we have a documented framework an examiner could test against" is exactly the gap Caribbean institutions cannot afford to leave open while waiting for a regional law that has no drafting timeline yet.
The Agentic AI Warning Sitting Underneath the Framework
The FSB's consultation report is about adoption practices generally, but the sharper warning came from a different regulator the same month. Speaking at the European Central Bank's June 2026 forum on central banking in Sintra, Bank of England Deputy Governor Sarah Breeden said the existing regulatory architecture was not built to contemplate autonomous agents, and that relying on a human in the loop for every agent action is unlikely to be realistic going forward. She raised the possibility of circuit-breaker or kill-switch style controls, the kind used to halt runaway trading, as a model for containing AI agents that misbehave at speed and at scale.
That warning lands directly on a trend CAIRMC has tracked across Caribbean banking and brokerage operations: institutions deploying AI agents to execute trades, process claims, or approve transactions with progressively less human review at each step. Breeden's point is not that agents are inherently unsafe. It is that the accountability structures built for a world where a person approves each material action do not automatically transfer to a world where the agent approves its own next ten actions in the time it takes a compliance officer to open the ticket. A Caribbean brokerage or payments platform running agentic AI without a documented escalation and override protocol is operating exactly the gap Breeden described, just without the balance sheet to absorb the consequences if it goes wrong.
The Proof Gap: Confidence Does Not Equal Control
Grant Thornton's 2026 AI Impact Survey, which polled 950 business leaders between 23 February and 18 March 2026, found that only 18% of banking executives were fully confident they could pass an independent review of their AI controls within 90 days. Half said governance and compliance gaps were already limiting how well their AI systems performed. Banks, the survey found, were more likely than any other sector to describe their own AI controls as untested.
These are institutions with dedicated model risk teams, internal audit functions built for exactly this kind of review, and compliance budgets most Caribbean banks and insurers do not have. If 82% of them lack confidence they could survive a 90-day audit of their own AI controls, a Caribbean credit union or regional insurer without a standalone model risk function faces a considerably larger version of the same gap, with fewer people assigned to close it. The Caribbean AI Association has documented how unevenly AI adoption is spreading across the region's financial sector, with agentic tools and generative AI features arriving in customer-facing products well ahead of any published governance document sitting behind them. The FSB's practices, and the proof gap Grant Thornton measured, both describe institutions with far more resources than most of their Caribbean counterparts.
What Caribbean Financial Institutions Should Do Before October
Four things follow from the timeline as it now stands. First, map current AI use, including any agentic tools and third-party AI vendors, against the FSB's three pillars now, rather than waiting for the October final version. The practices are unlikely to change in substance between the consultation draft and the finalised report, and starting the mapping exercise early means gaps surface on the institution's own schedule instead of an examiner's.
Second, treat the FSB's third pillar, cyber, IT, and third-party risk, as the priority, not an afterthought. Most Caribbean financial institutions run AI capability through a foreign cloud provider or a vendor's model rather than anything built internally, which is precisely the concentration risk the FSB's practices eleven and twelve target directly.
Third, address the agentic AI question Breeden raised specifically. Any institution running AI agents in trading, claims processing, or payments should be able to document what happens when the agent's next action falls outside its normal range, and who has the authority to stop it before it executes. If that documentation does not exist yet, it is the single highest-priority gap to close.
Fourth, use the certification and framework infrastructure that already exists in the region rather than starting from a blank page. CAIRMC's AI Risk Audit Framework and its AI Risk Management Practitioner certification were built to give Caribbean institutions a working answer to exactly this kind of international standard before a domestic law arrives to force one. Adrian Dunkley, who chairs CAIRMC and founded StarApple AI, the Caribbean's first dedicated AI company, has argued that regional institutions gain nothing by timing their governance work to a foreign regulator's publication calendar. His analysis of how international standards move from consultation to de facto benchmark, available through adriandunkley.net, treats the FSB's October deadline the same way CAIRMC treated the EU AI Act's compliance dates: as a preview of what enforcement eventually looks like, not a schedule the region can safely wait out. StarApple AI's own work building Caribbean-specific AI products, documented at starapple.ai, runs on the same premise, that the region should build its own governance capacity rather than import it after the fact.
Where This Leaves the Region
The FSB will publish its final sound practices in October 2026. Between now and then, Caribbean financial institutions have a choice that has nothing to do with legal obligation. They can spend the next four months mapping their own AI governance against a framework that is very likely to become the reference point their auditors, correspondent banks, and regional supervisors eventually adopt anyway. Or they can wait for October, read the finished document for the first time, and start the same mapping exercise several months behind institutions that started reading in June.
No Caribbean regulator has to adopt the FSB's 12 practices for them to matter. Basel standards were never adopted by CARICOM statute on day one either, and Caribbean banks still spent years closing the gap once correspondent banks started asking questions their old capital ratios could not answer. The AI version of that question is being drafted right now, and it will be finished in October whether or not a single Caribbean institution has looked at it by then.
Frequently Asked Questions
What did the Financial Stability Board publish in June 2026?
On 10 June 2026 the FSB published a consultation report titled "Sound Practices for Responsible Adoption of Artificial Intelligence (AI)," setting out 12 sound practices for financial institutions grouped into three areas: organisation-wide AI governance, risk management across the AI lifecycle, and AI-related cyber, IT, and third-party risk. The comment period closes 22 July 2026, and a final version is expected in October 2026.
Are the FSB's AI sound practices legally binding on Caribbean financial institutions?
No. The FSB has no direct legal authority over CARICOM regulators or Caribbean financial institutions. However, its standards have historically become de facto benchmarks that correspondent banks, credit rating agencies, and IMF reviews measure institutions against, the way Basel capital and liquidity standards did before any Caribbean statute formally adopted them.
Does any CARICOM country have a binding AI supervisory framework for banks?
No CARICOM member state currently has a binding AI-specific supervisory framework for financial institutions. CARICOM's Committee of Central Bank Governors has flagged AI as a priority for central banking operations at recent bi-annual meetings, but no Caribbean regulator has published guidance mapped to the FSB's 12 sound practices.
What did the Bank of England say about agentic AI risk?
Speaking at the European Central Bank's June 2026 Sintra forum, Bank of England Deputy Governor Sarah Breeden said existing regulatory frameworks were not built to contemplate autonomous AI agents, and that relying on a human in the loop for every agent action is unlikely to be realistic. She suggested circuit-breaker or kill-switch style controls could be needed to contain agentic AI systems that misfire in trading or other financial functions.
How confident are banks that their AI controls would pass an independent review?
Grant Thornton's 2026 AI Impact Survey of 950 business leaders, conducted between 23 February and 18 March 2026, found only 18% of banking executives were fully confident they could pass an independent review of their AI controls within 90 days. Half of banking executives said governance and compliance gaps were already limiting their AI performance, and banks were more likely than any other sector surveyed to describe their AI controls as untested.
What should Caribbean financial institutions do before the FSB finalises its standard in October 2026?
Map current AI use, including agentic tools and third-party AI vendors, against the FSB's three pillars now rather than waiting for the final report. Prioritise cyber, IT, and third-party risk given how much regional AI capability runs on foreign cloud platforms and vendor models. Document escalation and override protocols for any AI agents already in production. Use existing regional infrastructure, such as CAIRMC's AI Risk Audit Framework and Practitioner certification, rather than starting the governance work from a blank page.
- Financial Stability Board: "Sound Practices for Responsible Adoption of Artificial Intelligence (AI)," consultation report, 10 June 2026
- Financial Stability Board: "FSB consults on sound practices for the responsible adoption of artificial intelligence (AI)," press release, 10 June 2026
- Bank of England: "Agents of change," speech by Deputy Governor Sarah Breeden at the European Central Bank Forum on Central Banking, June 2026
- Grant Thornton: 2026 AI Impact Survey Report, banking insights, surveying 950 business leaders, 23 February to 18 March 2026
- Financial Conduct Authority: Mills Review findings, launch event, 6 July 2026
- CARICOM Committee of Central Bank Governors: Bi-Annual Meeting press releases, 2025-2026
- Caribbean AI Risk Management Council: AI Risk Audit Framework and sector guidance, caribbeanairisk.com
- StarApple AI: Product and company information, starapple.ai