By Allan Roper – DataPro Consulting
A Caribbean company no longer needs to be specifically targeted to be at risk.
An attacker using AI can scan exposed systems, test stolen credentials, generate convincing phishing emails, imitate business writing styles, and exploit a known vulnerability before the organization’s next internal meeting. That is the new reality of cyber risk.
Artificial intelligence is changing the threat landscape in ways that businesses and public bodies can no longer afford to treat as hypothetical. The danger is not simply that criminals now have access to smarter tools. The deeper issue is that AI makes attacks faster, easier, cheaper, and more scalable.
For Caribbean organizations, this matters because our economies are increasingly digital, cloud-based, identity-driven, and dependent on personal data. Banks, insurers, healthcare providers, law firms, BPOs, schools, retailers, utilities, and government agencies all rely on personal data as a core operating asset.
But in the AI-enabled threat era, personal data is not only something criminals steal after a breach. It is often the raw material used to begin one.
The new cyber threat is speed
The most important shift in cyber risk is not sophistication. It is speed.
Fortinet’s 2026 Global Threat Landscape Report describes a cybercrime ecosystem that no longer behaves like a series of isolated attacks. It operates more like an industrial system. In 2025, Fortinet telemetry recorded 640 billion reconnaissance events, 67.65 billion brute-force attempts, and 121.99 billion exploitation attempts globally. The report also found that time-to-exploit has collapsed to 24–48 hours in many cases, often outpacing traditional patching and remediation timelines.
That should concern every board, executive, compliance officer, IT leader, and Data Protection Officer in the region.
In the past, many organizations imagined cyberattacks as highly targeted, manual operations carried out by skilled hackers. That view is now outdated. Today, attackers can use AI-enabled tools to scan exposed systems, identify weaknesses, test credentials, generate phishing messages, automate attack paths, and exploit known vulnerabilities at scale.
The attacker does not need to be brilliant if the toolchain is fast, reusable, and widely available.
The report identifies AI-powered offensive tools such as FraudGPT, WormGPT, HexStrike AI, APEX AI, and BruteForceAI being advertised in underground forums. These tools are positioned to assist with phishing, fake business communications, malicious code generation, automated reconnaissance, credential abuse, and brute-force attacks.
AI does not need to invent a new kind of crime to be dangerous. It only needs to make existing crimes faster, cheaper, and easier to repeat.
What this means for Caribbean organizations
The risk is practical, not theoretical.
A fake supplier email can be generated using public information about a company’s staff, vendors, and payment processes. A compromised Microsoft 365 or Google Workspace account can expose customer records, legal files, HR data, or financial information. A phishing email can be personalized using details from LinkedIn, websites, procurement notices, or previous data breaches.
A small business may think it is too insignificant to be targeted. A public body may assume its existing policies are enough. A large company may believe its cybersecurity tools alone will protect it.
Those assumptions are becoming increasingly dangerous.
AI-enabled attackers do not always need to choose one victim carefully. They can automate discovery, scale their attempts, and move quickly when they find weakness. In that environment, slow governance becomes a vulnerability.
The question is no longer simply: “Do we have cybersecurity tools?”
The better question is: “Can our people, policies, systems, and decision-making move fast enough to respond?”
Agentic AI raises the stakes
The next stage of concern is agentic AI.
Agentic AI refers to systems that can plan, act, use tools, call APIs, retrieve information, execute workflows, and adapt toward a goal with less human intervention. In a business context, this can be useful. Agentic AI can support customer service, compliance monitoring, research, data processing, and workflow automation.
In the wrong hands, the same capabilities can support autonomous reconnaissance, phishing campaign management, vulnerability chaining, credential validation, and movement through compromised systems.
This changes the risk profile in four important ways.
First, agentic AI can gather intelligence at scale.
Second, it can make decisions based on stolen, leaked, or publicly available data.
Third, it can interact with systems through browsers, APIs, and connected tools.
Fourth, it can repeat workflows continuously without fatigue.
For defenders, this means the old control model is no longer enough. Annual audits, static policies, and slow manual review cannot adequately respond to threats that move at machine speed.
The risk is no longer limited to “what an AI model says.” It now includes what an AI-connected system can do.
Identity has become the control plane
One of the clearest messages from the Fortinet report is that identity now sits at the centre of cyber risk.
FortiRecon observed 4.62 billion stealer logs traded or shared on the darknet. The report describes credential theft as an upstream industry producing inventory at scale. In cloud environments, valid credentials may become the exploit, and APIs may become the execution engine.
This should trouble every Caribbean organization that relies on Microsoft 365, Google Workspace, cloud hosting, remote access systems, VPNs, online banking portals, HR platforms, CRMs, or customer databases.
Once credentials are stolen, attackers may not need malware. They may simply log in as legitimate users, move through trusted systems, and abuse normal business tools.
AI makes this worse.
Stolen credentials can be sorted, validated, enriched, and reused faster. Phishing messages can be personalized. Voice and writing styles can be imitated. Fake supplier messages can be made more convincing. Attackers can identify which compromised accounts are most valuable and use them to pivot into payroll systems, customer records, health data, legal files, or financial platforms.
This is where cybersecurity and data protection meet.
A weak password policy, poor access control, excessive privileges, unmanaged third-party accounts, or delayed account revocation is no longer just an IT weakness. It is a data protection risk.
Why this connects directly to the Data Protection Act
Jamaica’s Data Protection Act is not merely a privacy compliance statute. It is a governance framework for trust in the digital economy.
The Act requires data controllers to handle personal data responsibly, protect it against misuse and unauthorized access, comply with the data protection standards, and notify the Information Commissioner and affected data subjects where required.
The seventh data protection standard is especially relevant in the AI-enabled threat era. It requires appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage.
That obligation cannot be separated from cybersecurity.
If an organization has weak identity controls, poor monitoring, unmanaged AI tools, inadequate vendor oversight, or a breach response plan that exists only on paper, it may also have a data protection problem.
The Act also requires data controllers to report certain contraventions or security breaches affecting, or potentially affecting, personal data within 72 hours of becoming aware of them.
This creates a serious governance issue.
If AI-enabled attacks are moving in hours, governance cannot move in months.
A Data Protection Impact Assessment that does not consider AI-enabled phishing, credential theft, cloud misconfiguration, third-party AI tools, automated exploitation, and connected AI systems is incomplete.
A breach response plan that has not been tested is not a plan. It is a document.
The Caribbean governance gap
The Caribbean is not separate from the global AI and cybercrime ecosystem. It is part of it.
The region faces a difficult reality. Digital adoption is increasing, but infrastructure, regulatory maturity, resources, and institutional capacity vary widely. Many organizations are adopting cloud platforms, software-as-a-service tools, digital payment systems, AI assistants, and automated workflows faster than their governance frameworks are evolving.
That creates exposure.
The Caribbean Telecommunications Union’s work on regional AI governance has highlighted the need for a harmonized, human-centric, rights-based, and inclusive approach to AI. This is important because AI governance cannot be left to individual departments, informal experimentation, or vendor assurances alone.
The governance question is not whether Caribbean organizations should use AI. They should.
AI can improve productivity, expand access to services, support compliance, strengthen analytics, and help smaller organizations compete.
The real question is whether AI will be governed before it becomes embedded into critical business processes, customer interactions, public services, security decisions, and personal data environments.
What proper AI governance should require
AI governance must move beyond innovation theatre.
It must answer practical questions.
Who approved the AI system? What personal data does it process? Was a Data Protection Impact Assessment completed? Was the tool assessed for privacy, bias, security, and misuse risk? Are employees entering confidential or personal data into public AI tools? Are vendors using customer data to train models? Can the organization explain automated decisions? Can access be revoked quickly? Are logs retained? Who is accountable when an AI agent makes a harmful decision or exposes personal data?
These are not academic questions. They are the bridge between responsible AI and compliance with data protection law.
For Caribbean organizations, AI governance should include at least five practical pillars.
1. Know which AI tools are being used
Organizations need an AI inventory.
They should know which AI tools are being used, who is using them, what they are being used for, and whether personal or sensitive personal data is involved.
This includes approved tools, employee-driven tools, vendor-embedded AI features, chatbots, analytics platforms, productivity assistants, and AI systems connected to internal workflows.
An organization cannot govern what it cannot see.
2. Assess privacy risk before deployment
Privacy-by-design must apply to AI.
Any AI system that processes personal data, supports profiling, automates decisions, connects to customer databases, or assists with compliance, HR, finance, health, education, or law enforcement functions should be assessed before deployment.
That assessment should consider the purpose of processing, the categories of personal data involved, security controls, retention periods, transparency, accuracy, bias, human oversight, cross-border transfers, and the rights of data subjects.
A DPIA should not be treated as a formality. It should be used as a practical decision-making tool.
3. Strengthen identity and access controls
AI-enabled attacks increasingly exploit valid accounts.
That means identity governance must become a priority. Organizations should strengthen multi-factor authentication, least privilege, privileged access management, password hygiene, session revocation, and monitoring for unusual logins.
They should also review third-party accounts, dormant accounts, shared credentials, administrator privileges, and access to sensitive databases.
In an AI-enabled threat environment, the speed at which an organization can revoke compromised access may determine the scale of the breach.
4. Govern vendors and third parties
Many AI risks enter through vendors.
AI vendors, SaaS providers, cloud platforms, processors, consultants, and outsourced service providers should be assessed before they are allowed to process or access personal data.
Organizations should ask direct questions.
Will our data be used to train models? Where will the data be stored? Will it be transferred across borders? How long will it be retained? Can it be deleted? What security controls are in place? What audit rights exist? How quickly will the vendor notify us of a breach? Can the vendor explain how the AI system produces outputs or decisions?
Vendor governance is not procurement paperwork. It is part of data protection accountability.
5. Prepare for incidents at AI speed
A 72-hour breach notification obligation is meaningful only if the organization can detect, investigate, escalate, and communicate quickly enough.
Incident readiness should include tabletop exercises, evidence preservation, legal review, regulator notification workflows, data subject communication plans, and clear internal decision-making authority.
Organizations should test whether they can answer basic questions quickly.
What happened? What systems were affected? What personal data was involved? How many individuals may be affected? Has access been contained? Has the threat actor been removed? Is notification required? Who approves the notification? Who communicates with affected individuals?
If those questions cannot be answered under pressure, the organization is not ready.
The boardroom message
The most dangerous misconception is that AI risk belongs only to the IT department.
It does not.
AI-enabled cybercrime is a board-level governance issue because it affects legal compliance, customer trust, operational resilience, reputation, revenue, and regulatory exposure.
Boards and executives should treat defensive speed as a business risk indicator. That means measuring how quickly the organization can detect suspicious activity, contain an incident, revoke compromised credentials, communicate internally, preserve evidence, and meet legal notification obligations.
The board should be asking:
Do we know which AI tools are being used across the organization?
Do we understand what personal data those tools process?
Are our identity controls strong enough for the current threat environment?
Have we assessed AI-related privacy and security risks?
Can we revoke compromised access quickly?
Are vendors contractually restricted from misusing our data?
Have we tested our breach response plan?
Can we meet our legal obligations if an AI-enabled incident happens this week?
These are governance questions, not technical details.
For Caribbean organizations, the answers will determine more than cyber resilience. They will determine whether individuals can trust institutions with their personal data in an economy increasingly shaped by AI.
Conclusion: AI governance is data protection governance
AI will bring enormous opportunities to the Caribbean.
It can improve productivity, expand access to services, support compliance, strengthen analytics, and help organizations compete in larger markets. But without governance, the same technologies can accelerate fraud, identity theft, unauthorized processing, discrimination, data breaches, and loss of public trust.
The Data Protection Act already gives organizations the foundation: accountability, transparency, security, purpose limitation, data minimization, rights protection, and breach response.
AI governance must now build on that foundation.
The region does not need to choose between innovation and protection. Responsible innovation depends on protection.
In the age of agentic AI and industrialized cybercrime, privacy and cybersecurity are no longer separate disciplines. They are two sides of the same duty: to protect people, preserve trust, and ensure that technology serves the Caribbean rather than exposing it.
Every Caribbean organization should now ask three simple questions:
What AI tools are we using?
What personal data do they touch?
And can we detect, contain, and report an AI-enabled breach fast enough to meet our legal and operational obligations?
Those questions should not wait for the next incident. They should be answered now.
References
- Fortinet FortiGuard Labs. 2026 Global Threat Landscape Report: Insights from FortiGuard Labs. 2026.
- Office of the Information Commissioner Jamaica. Obligations of Data Controllers under the Data Protection Act.
- Office of the Information Commissioner Jamaica. What are the Obligations of Data Controllers?
- Parliament of Jamaica. The Data Protection Act, 2020.
- Caribbean Telecommunications Union. Caribbean Artificial Intelligence Task Force Draft Interim Report.
- OWASP Foundation. OWASP Top 10 for Large Language Model Applications / GenAI Security Project.
- UNESCO. Recommendation on the Ethics of Artificial Intelligence.
- OECD. OECD AI Principles.
- National Institute of Standards and Technology. AI Risk Management Framework.

