Third-Party Risk15 min read

The Sovereign AI Label Is a Third-Party Risk. Here Is the Register for It.

By Adrian Dunkley·Aug 8, 2026
TLDR
  • Caribbean institutions are buying AI products described as sovereign, local or regionally hosted, where inference is performed by a foreign foundation model operated by a third party the buyer has never contracted with and often cannot name.
  • The architecture is not the failure. Renting a frontier model through a competent integrator is frequently the correct purchase. The failure is a board record, a regulatory return or a data protection file that describes an arrangement the organisation cannot evidence.
  • CAIRMC classifies this as a third-party and model-provenance risk under the Caribbean AI Risk Taxonomy, and treats it as AI Risk Tier 2 or Tier 3 depending on the sensitivity of the data reaching the undisclosed endpoint.
  • Every exposure it creates is computable from figures an institution already holds: annual inference spend, records per prompt, cost per hour of the dependent process, and the notification cost per record under the applicable data protection statute.
  • The eight-line register below carries a quantification method for each risk, a primary control mapped to ISO/IEC 42001:2023 and the NIST AI Risk Management Framework, and a named accountable function.
  • One control does most of the work and is the one most often waived: an egress-blocked demonstration before signature, evidenced and retained.

A Caribbean audit committee reviewing an AI deployment usually asks three questions: is it accurate, is it secure, and who is accountable when it is wrong. Those are the right questions. They are also insufficient, because each of them assumes the committee knows what the system is. In a growing share of the engagements the Caribbean AI Risk Management Council has reviewed over the past year, the committee did not, and neither did the executive that signed the contract.

The pattern is consistent. A product is procured on the strength of terms like sovereign, local, or regionally hosted. Somewhere in the technical architecture, every prompt is transmitted to a foundation-model provider in North America or Europe, operated by a company with which the buying institution has no contract, no service level, and no route of recourse. The vendor has not necessarily lied. In most cases nobody in the room asked the question in a form that required a written answer.

This article is not an argument against foreign models. It is a risk register, the quantification method that fills it in, and the control set that closes it.

Definition, Stated Once

Sovereignty over an AI system is the capacity to determine, on your own terms, whether it continues to operate and who observes what passes through it. In procurement terms that resolves into three conditions that must hold together rather than separately.

First, the contracting party owns the model or licenses the weights on terms it controls, so that it can continue to serve the client if the original supplier withdraws. Second, inference executes on infrastructure the vendor or the buyer operates. Third, the location of that infrastructure is recorded in the agreement, because a supervisor asking where regulated data is processed is requesting a document.

Two arrangements are commonly mistaken for sovereignty and are not. A locally built interface over a foreign model is a product decision. Fine-tuning a hosted foreign model on institutional data moves the organisation further from sovereignty rather than closer to it, because the training corpus has now also been transferred and the resulting weights reside with the provider.

The three procurement categories

Attribute Sovereign AI Self-hosted open weights Foreign model, local interface
Execution location Vendor or buyer infrastructure, named in contract Institution's own servers or cloud tenancy Provider data centres outside the region
Termination authority The vendor, under your contract The institution The provider, and the government regulating it
Residency evidence available to a supervisor Contractual and auditable Verifiable by inspection Determined by provider terms, not vendor assurance
Cost basis Compute, capacity or licence Hardware and operations Per token or per credit, with margin applied
Primary failure mode Vendor insolvency or default Institutional operations Provider outage, policy change, export restriction, repricing

Under the Caribbean AI Risk Taxonomy, misclassification between these columns falls under third-party and model-provenance risk. CAIRMC assesses it as AI Risk Tier 2 where the data reaching the undisclosed endpoint is internal and non-personal, and Tier 3 where it includes personal data, financial account information, health data, or material non-public information. A Tier 3 classification requires board-level reporting under the CAIRMC AI Governance Maturity Model from Level 3 upward.

The Register

Eight lines. Each carries a quantification method rather than a benchmark figure, because the exposure is institution-specific and every input below is a number the organisation already holds. An audit committee that fills this in with its own figures will produce a defensible number in an afternoon; one that waits for an industry benchmark will produce nothing.

ID Risk Tier Quantification method Primary control Accountable
SA-01 Undisclosed cross-border transfer of personal data through prompts 3 Data subjects per prompt × prompts per year × per-record notification and remediation cost under the applicable data protection statute Named inference location in contract; sub-processor schedule with change notice Data Protection Officer
SA-02 Inability to produce a data flow diagram on supervisory request 3 Cost of a remediation programme under supervisory direction, plus internal hours to reconstruct the flow after the fact, which is materially higher than documenting it before signature Pre-signature architecture attestation retained in the outsourcing file Chief Risk Officer
SA-03 Board or regulatory record states a residency position the institution cannot evidence 3 Not directly monetisable. Track as a control failure with a named owner and a correction deadline, and escalate as a governance finding rather than a financial one Evidence standard for AI claims in board papers Company Secretary
SA-04 Service interruption originating at a foundation-model provider outside the contract 2 Cost per hour of the dependent process × annual downtime hours drawn from the provider's own published incident history, not the vendor's SLA Documented manual fallback with a named invoking officer; dependency recorded in the BCP Head of Operations
SA-05 Unilateral upstream repricing passed through mid-contract 2 Annual inference spend × the largest upstream list-price movement observed in the last 24 months × remaining contract years Pass-through cap, or termination right when upstream pricing moves beyond an agreed band Chief Financial Officer
SA-06 Model substituted beneath the product without notice, changing output behaviour 3 Decisions per year affected by the model × the cost of reworking or reversing a wrong decision in that process, applied over the period between substitution and detection Model change notification clause; periodic output regression testing against a held-out set Model Risk function
SA-07 Switching cost concentration after integration into core processes 2 Re-integration effort in person-days × blended day rate, plus retraining hours and the cost of a parallel-run period Exit clause covering export of data, prompts, embeddings and fine-tuned artefacts in a usable format Head of Procurement
SA-08 Unregistered AI tools accumulating outside the assessed relationship 3 Count discovered tools during inventory, classify each by data sensitivity, then apply SA-01 to every tool touching personal data Mandatory AI inventory with named owners; procurement gate for any tool processing institutional data Chief Information Officer

Working the Numbers

Three of these lines deserve expansion, because they are the ones most often left as narrative when they could be arithmetic.

SA-04, continuity

Institutions routinely record this risk as unquantifiable. It is not. OpenAI, Anthropic and Google Cloud publish incident histories at status.openai.com, status.anthropic.com and status.cloud.google.com. Take twelve months of that history, take the cost per hour of the process the AI system sits inside, multiply, and the result is a defensible annual expected loss with a public source behind it. A vendor's service level agreement is the wrong input, because it covers the vendor's own availability and correctly excludes an upstream provider failure the vendor cannot control.

SA-05, repricing

An institution on a per-token contract holds an unpriced option written against it. The exposure is the annual inference spend multiplied by the largest upstream list-price movement in the recent past, extended over the remaining contract term. The most useful diagnostic here is simply asking the vendor to fix a price at three times current volume. A vendor whose own costs scale with tokens cannot, and the explanation of why will characterise the architecture more precisely than any technical review.

SA-01, transfer exposure

The inputs are the number of identifiable data subjects appearing in a typical prompt, the annual prompt volume, and the per-record cost of notification and remediation under the applicable statute. Jamaica's Data Protection Act 2020, Barbados' Data Protection Act 2019 and the Trinidad and Tobago Data Protection Act 2011, which remains largely unproclaimed, set materially different baselines, and an institution operating across CARICOM should compute the line separately for each jurisdiction rather than applying the strictest as a proxy. Where the institution processes data of EU residents, Regulation (EU) 2024/1689 and the General Data Protection Regulation add statutory ceilings of €35 million or 7% of worldwide annual turnover for prohibited practices and €20 million or 4% respectively. Those ceilings are rarely the operative exposure for a Caribbean institution. The operative exposure is a supervisory finding that governance over a material third party was undocumented, which is far cheaper to trigger and considerably harder to explain.

Control Mapping

The controls in the register are not new instruments. Each maps to a clause an institution pursuing certification is already implementing.

  • ISO/IEC 42001:2023. Supplier and third-party controls, AI system impact assessment, and the requirement to document the AI system lifecycle. An organisation that cannot identify the model performing inference cannot complete an impact assessment to the standard's evidential requirement.
  • NIST AI Risk Management Framework. The MAP function requires that AI system context, including third-party components, be established and documented. An undisclosed foundation-model dependency is an unmapped component, which means MEASURE and MANAGE are operating on an incomplete system boundary.
  • COSO Enterprise Risk Management. Risk appetite is meaningless when applied to an exposure the institution has not identified. Where an AI dependency sits inside a core process, it belongs in the risk profile reported to the board rather than in a technology register reviewed at management level.
  • ISO/IEC 27001. Supplier relationship security and information transfer controls apply directly to prompt content leaving the organisation, and the sub-processor schedule is the natural evidence artefact.

CAIRMC's Caribbean AI Risk Assessment methodology treats model provenance as a scored dimension rather than a narrative field, precisely because narrative fields absorb assurances and scored dimensions require evidence.

The Verification Set

Seven checks establish which of the three categories an institution is buying. They vary considerably in evidential weight, and treating them as equivalent produces false comfort.

Interrogating the model directly yields strong evidence when the model names a foundation-model provider, and close to none when it denies one, because a system prompt can instruct denial and because models misidentify themselves. CAIRMC has observed a self-hosted open-weight deployment assert that it was built by OpenAI, an incorrect answer that would have wrongly condemned a compliant vendor.

Network inspection during a query is conclusive on a positive and worthless on a negative, because any competent product calls the provider from its own backend. What the trace still yields is endpoint resolution and round-trip latency, and a time to first token consistent with a North American round trip measured from Kingston or Bridgetown is a matter for written follow-up.

Asking which weights are loaded and under what licence carries high evidential weight and is difficult to fabricate in front of a technically competent reviewer, which is the argument for having one present at evaluation rather than at post-incident review.

The sub-processor schedule is the strongest of the documentary checks, because misrepresentation in a signed data processing agreement is a contractual breach with consequences rather than a marketing exaggeration. The absence of a schedule, or a clause permitting substitution at the vendor's discretion without notice, is itself a finding.

Outage correlation against the provider status pages gives good evidence on a match and weak evidence on a non-match, since a multi-provider failover design survives any single provider outage. That design is genuinely more resilient and is not sovereign, and it introduces its own data protection question, because prompts may reach whichever provider the router selected.

Invoice structure gives moderate evidence, readily obscured by credit bundles and seat pricing.

The egress-blocked demonstration settles the question. The product is run on a network where outbound access to the major foreign model providers is blocked, or deployed into infrastructure the institution controls. A locally executed model continues to answer. A rebranded product returns an error or a canned fallback. This control costs a firewall rule and an afternoon, and in CAIRMC's review work it is the control most frequently proposed, most frequently agreed in principle, and most frequently dropped from the evaluation timetable under commercial pressure.

Where This Framework Fails

Publishing a verification set degrades it. Any vendor reading this document can prepare for the interrogation check and rehearse a fluent answer to the weights question. CAIRMC judges the trade acceptable, because the institutions that need the framework do not currently have one and the vendors capable of defeating it were already ahead of those institutions. What survives preparation is what costs money to fake, which is the demonstration and the signed schedule.

The more serious limitation is structural. This register treats provenance as a property of a single vendor relationship, when the material exposure in most Caribbean institutions is accumulation. An organisation may hold one properly assessed core system alongside an unlogged transcription tool that joins meetings, a browser extension installed by three staff in finance, and a customer service assistant from a fourth supplier. That organisation has one good contract and an unmapped surface, and SA-08 is the only line in the register that reaches it. In CAIRMC's engagement work across the region this year, a complete AI inventory has generally not existed prior to the engagement, and its eventual length has been the first material finding rather than the last.

A second limitation is worth stating plainly, because the register can be misread as an argument against foreign models. It is not. For internal drafting, translation, summarisation of public documents and marketing production, renting a frontier model through a competent local integrator is frequently the most defensible purchase available to a Caribbean institution, and the integrator earns its margin in workflow, support and accountability. Nothing in this register argues otherwise. The register applies to the description, and to the governance record built on it.

Reporting Line

Where an AI system processes personal data, financial account information or health data, the provenance position belongs in the risk report the board receives, expressed in one line: the model performing inference, the jurisdiction of execution, the date on which that position was last verified, and the method used to verify it. A position verified by an egress-blocked demonstration is evidence. A position verified by a vendor's assurance is a representation, and the report should say which of the two it is.

Institutions pursuing the Qualified AI Risk Professional designation cover this diagnostic within the third-party risk module, and CAIRMC has made the register above available for use as a working template rather than as an illustration.

Frequently Asked Questions

What does sovereign AI mean for procurement purposes?

An AI system where the contracting party controls the model and the hardware performing inference, and can name and evidence the jurisdiction of execution. Three conditions must hold together: ownership or controlled licensing of the weights, execution on infrastructure the vendor or buyer operates, and the location recorded in the agreement rather than described in a meeting.

How does CAIRMC classify a mislabelled AI product?

As third-party and model-provenance risk under the Caribbean AI Risk Taxonomy. AI Risk Tier 2 where the data reaching the undisclosed endpoint is internal and non-personal, and Tier 3 where it includes personal data, financial account information, health data or material non-public information. Tier 3 requires board-level reporting from Level 3 of the CAIRMC AI Governance Maturity Model upward.

How is continuity risk quantified when the outage originates upstream?

Multiply the cost per hour of the process the AI system sits inside by the annual downtime hours drawn from the foundation-model provider's own published incident history. The vendor's service level agreement is the wrong input, because it covers the vendor's availability and correctly excludes an upstream failure the vendor does not control.

Which single control gives the most assurance?

The egress-blocked demonstration. Run the product on a network where outbound access to the major foreign model providers is blocked, or deploy it into infrastructure the institution controls. A locally executed model continues to answer; a rebranded product stops. Evidence the result and retain it in the outsourcing file.

Does fine-tuning on Caribbean data change the classification?

No, where the fine-tuning is performed on a hosted foreign model. The training corpus has then also been transferred and the resulting weights reside with the provider, leaving residency, continuity and pricing exposure unchanged. Fine-tuning open weights the institution can download and re-host is a different arrangement, and the distinguishing question is whether the fine-tuned artefact is exportable on termination.

What does the EU AI Act add for a Caribbean institution?

Regulation (EU) 2024/1689 reaches institutions serving EU residents or supplying clients who do, with ceilings of €35 million or 7% of worldwide annual turnover for prohibited practices and €15 million or 3% for other breaches. For most Caribbean institutions the operative exposure is not the ceiling. It is a domestic supervisory finding that governance over a material third party was undocumented, which is cheaper to trigger and harder to remediate.

Is a foreign-model product an unacceptable purchase?

No. For internal drafting, translation, summarisation of public documents and marketing production, renting a frontier model through a competent integrator is frequently the most defensible option available. The register applies to the description of the arrangement and to the governance record built on it, not to the architecture.

Where should an institution start?

With the inventory rather than the diagnostic. List every AI product in use, including those procured outside the technology function, and assign a named owner to each. Then issue a single written request to every vendor on that list for the current sub-processor schedule and a written statement of the inference location. The responses, and the non-responses, will triage the list before any technical work begins.