The Missing Middle: Why Caribbean Companies Are Compliant on Paper but Exposed in Practice
Written By: Owen Duckie, CIPM, MSc. (Distinction)
Ask a compliance officer at a regional bank, telco, or insurer whether their company is "data protection compliant," and most will say yes. Ask the same person whether their company is "AI governance compliant," and the answer is usually a pause — followed by some version of "there's nothing to comply with yet."
That pause is the story of the Caribbean's current regulatory moment. Data privacy law in the region is maturing quickly. AI governance is, almost everywhere, still a blank page. Companies operating in the gap between those two realities are the ones carrying the most risk — often without realizing it.
Two Regions, Two Very Different Maturity Curves
Two things jump out.
First, data protection has become the regional default. Thirteen of fifteen CARICOM member states now have a data protection law either in force or passed and waiting on a commencement order. Even where enforcement is uneven, the legal architecture (data subject rights, breach notification, a designated regulator) largely exists.
Second, AI governance does not. Of all the jurisdictions surveyed, only two, Jamaica and the Dominican Republic, have produced any national-level AI document at all, and both are policy recommendations or strategies rather than enforceable law. Everywhere else, there is nothing. Not a light-touch code of practice, not a voluntary standard, not even a task force. Just silence.
That asymmetry is the "missing journey" companies are now living through.
Caribbean AI Governance and Data Protection Snapshot
The Journey Nobody Mapped
Most compliance programs in the region were built to a familiar checklist: register with the regulator, appoint a data protection officer, write a privacy policy, run breach-notification drills, get comfortable with subject access requests. That checklist is real, it's necessary, and for many companies it's genuinely done or nearly done.
But AI has quietly changed what "compliant" needs to mean, and the checklist hasn't caught up. A bank using a machine-learning model to score loan applicants, an insurer using an algorithm to flag fraudulent claims, a telco using AI to route customer complaints, a hotel group using AI to set dynamic pricing: all of these are already operating in a space that data protection law only partially covers, and that no AI-specific law covers at all.
The journey these companies actually need to take has several stages that are currently missing or incomplete across most of the region:
Stage 1: Knowing what you have
Most organizations don't have an inventory of where AI or automated decision-making is actually being used inside the business, often because it arrived bundled inside a vendor's software rather than as a deliberate internal build. You can't govern what you haven't mapped.
Stage 2: Extending existing rights to automated decisions
Several of the region's data protection acts, Jamaica's and Barbados' among them, already give individuals the right to contest automated decisions and, in Jamaica's case, require processing impact assessments. Very few companies have operationalized what that actually means when the "decision" comes from a model rather than a person. Right now, this is one of the only real legal levers available anywhere in the Caribbean for someone harmed by an algorithmic decision, and it's underused.
Stage 3: Bias, explainability, and accountability testing
This is the layer that dedicated AI laws normally provide, and that's almost entirely absent regionally. Without external requirements, whether an AI system gets tested for bias or explainability is currently left to each company's internal judgment and, often, the standards baked into whatever third-party AI tool they've bought.
Stage 4: Cross-border data flows for AI training and inference
Many AI systems used regionally run on infrastructure or models hosted abroad. Data protection acts generally require "adequate protection" for cross-border transfers, but applying that standard to, say, a cloud-hosted large language model processing customer data is a much newer and murkier question than applying it to a simple data-sharing agreement between two companies.
Stage 5: Institutional oversight
Jamaica's proposed National AI Oversight and Implementation Council is the only concrete regional example of what dedicated AI oversight might look like. Nowhere else in the Caribbean does an equivalent body exist yet, even in draft form.
Most companies are somewhere between stage 1 and stage 2. Very few have reached stage 3, and almost none have institutional support at stage 5, because that institution doesn't yet exist in their jurisdiction.
Why an AI Governance Framework Fills the Gap
This is exactly the kind of gap that an AI governance framework, even a voluntary or internally adopted one, is built to close, and it can do so well before any government finishes drafting binding legislation.
It gives companies a map even when the law doesn't. A structured framework (drawing on something like the OECD AI Principles or UNESCO's Recommendation on the Ethics of AI) lays out the same territory a future Caribbean AI law will likely cover: fairness, transparency, human oversight, accountability, safety. Adopting these voluntarily now means a company isn't starting from zero once binding rules do arrive; it's converting existing practice into compliance rather than building compliance from scratch under deadline pressure.
It turns existing data protection rights into working AI safeguards. Because most of the region already has data protection law with rights around automated decision-making, a governance framework can operationalize those rights specifically for AI systems: impact assessments before deployment, documented human review checkpoints, clear channels for a customer to contest an automated decision. This uses law that already exists rather than waiting for law that doesn't.
It gives regulators and the public confidence the law hasn't yet had to earn. In a region where regulatory enforcement capacity is still developing (many regulators are new, under-resourced, or, as with several commencement-order-pending laws, not yet operational at all), a company's own governance framework becomes the primary evidence that it's acting responsibly. That matters commercially: customers, investors, and cross-border partners increasingly ask about AI governance posture before signing contracts, regardless of whether local law requires it.
It positions companies ahead of the region's own trajectory. Jamaica's UNESCO Readiness Assessment and policy drafting process, and the Dominican Republic's national AI strategy, both signal where the rest of CARICOM is likely headed next. Companies that adopt governance frameworks now are effectively front-running a wave of legislation that history suggests is coming; data protection law went from five countries a decade ago to thirteen-plus today, and AI law is very likely to follow a similar curve, just starting later.
It manages a real cross-border complexity problem. Because the region's laws don't mirror each other and its AI landscape is even more fragmented, any company operating across multiple Caribbean markets faces a genuinely inconsistent patchwork. A single internal AI governance framework, applied consistently across markets and calibrated to the strictest applicable local law, is often more practical than trying to track twenty different partial and evolving regimes separately.
The Bottom Line
Caribbean companies aren't non-compliant out of negligence. In most cases, they're compliant with everything that currently exists to be compliant with. The problem is that "everything that currently exists" stops well short of where the actual risk now sits. Data protection law addresses the collection and use of personal data. It was not written with algorithmic decision-making, model bias, or explainability in mind, because it mostly predates the current wave of AI adoption.
Until the region's governments close that gap, and Jamaica's policy drafting process suggests some of them are trying, the companies best protected won't be the ones that wait for the law. They'll be the ones that build an AI governance framework now, using the data protection rights, ethical principles, and institutional models already on the table regionally, and treat the coming legislation as confirmation of practice rather than the starting gun for it.