TL;DR
  • Your staff are already using AI in real decisions, approved or not. The board's first job is to find out where.
  • AI governance is the next chapter of data governance, not a separate one. A model is only as trustworthy as the data it learned from and the process that deployed it.
  • Three risks matter most: shadow AI you cannot see, model drift you cannot feel, and decisions no one can explain or is accountable for.
  • Govern by risk tier. A marketing draft and a credit decision should not sit under the same rules. Be light on the low-stakes majority, firm on the few that carry real consequence.
  • The EU AI Act is becoming the reference standard the way GDPR did. Adopting its core ideas early is cheaper than retrofitting them.

Somewhere in your organisation, a decision was shaped by AI this week that never crossed a governance line, because there was no line to cross. A staff member drafted a customer response with a public chatbot, or built a pricing rule in a spreadsheet on top of a model they found online, or pasted a client list into a tool to summarise it. None of this was malicious. All of it is the organisation now deciding, and possibly leaking data, through systems the board does not know exist. That is the starting condition for AI governance in most Caribbean firms in 2026: not a blank page, but a set of uses already running in the dark.

The instinct is to treat this as a new and specialist problem. It is mostly an old one wearing new clothes. AI governance is data governance carried one step further, into the models that now sit between the data and the decision. A firm that cannot say who owns its customer data certainly cannot say what a model trained on that data is allowed to decide, which is why the governance foundations from the rest of this series are the ground this stands on.

Three Risks A Board Can Actually Name

Strip away the jargon and the risks that matter to a board come down to three, each of which a director can hold without a technical briefing.

The first is shadow AI: use the organisation cannot see. You cannot govern, secure or audit a tool you do not know is in use, and the only fix is unglamorous, an inventory of where AI is already touching decisions. The second is model drift: a model's gradual loss of accuracy as the world moves away from the data it learned on. A credit model built before a downturn, or a demand model built before a storm reshaped spending, keeps giving confident answers that are steadily more wrong, and because it never flags its own decay, drift bites hardest exactly when conditions change most. The third is accountability: when a model declines a loan or misprices a policy, a named human has to own that decision, be able to explain it, and be able to overturn it. A model cannot be accountable, so if no person is, the organisation has handed a real decision to something that cannot answer for it.

Govern By Risk, Not By Blanket Rule

The failure mode is a single heavy AI policy applied to everything, which either strangles harmless uses or, more often, gets ignored. Tier instead. Sort AI uses by the consequence of getting them wrong, and match the control to the tier. This is the core logic of the EU AI Act, and it is sound wherever you operate.

Risk tierExample useGovernance to apply
LowDrafting copy, summarising notes, brainstormingLight. Basic data-handling rules, no client data in public tools.
MediumSegmenting customers, forecasting demand, ranking leadsNamed owner, documented data source, periodic accuracy check.
HighCredit decisions, pricing, hiring, anything affecting a person's rights or moneyHuman in the loop, explainability, drift monitoring, audit trail, board sight.

The point of tiering is speed as much as safety. A business that governs its low-risk AI lightly can let people use it freely and move faster, while spending its real oversight on the handful of decisions where a wrong model output costs someone money or a right. Govern everything equally and you get the worst of both: friction on the trivial and false comfort on the serious.

1
Inventory of where AI touches decisions
3
Risk tiers, each with its own controls
1
Named owner per model in use
Ongoing drift monitoring, not a launch check

Bring Your AI Use Into The Light

We help Caribbean boards inventory their AI use, tier it by risk, set human-oversight and accountability rules, and monitor models for drift, all built on the data governance the models depend on. Fast on the low-risk majority, firm where it counts.

Explore Our Data Science Service ↗

The Cheapest Way To Get It Wrong

A recurring StarApple theme is worth restating here, because AI makes it sharper. A model pointed at ungoverned data does not fail loudly. It produces fast, fluent, confident answers that carry the authority of a machine, and some meaningful share of them are wrong in ways no one checks. That is more dangerous than a slow human error, because the wrong answer arrives polished and on time and invites a signature. Governance is what keeps the confidence of the output tied to the quality of what went into it, and without it a business simply automates its mistakes at scale.

There is regulatory weather coming too, and it is cheaper to dress for it now. A Caribbean firm serving European customers can already fall within the reach of the EU AI Act, and even where it does not, the Act is hardening into the reference standard the way the GDPR did for privacy. Regional bodies such as the Caribbean AI Risk Management Council are building on the same foundations. None of this requires a compliance department tomorrow. It requires a board that has done the inventory, tiered its uses, and can say who owns each model, which is exactly the work that also makes the AI safer to use.

One honest limit worth stating. Governance can make AI accountable and auditable; it cannot make a bad model good, and it cannot fully explain some models even when you require it to. Where a decision genuinely affects a person's money or rights and the model cannot be explained, the right governance answer is sometimes not to use that model for that decision at all. Knowing where that line sits is part of the job, not a failure of it.

Frequently Asked Questions

What is AI governance and how does it relate to data governance?

AI governance is the rules and accountabilities for how models are built, approved, used and monitored. It is the next chapter of data governance, because a model is only as trustworthy as the data it learned from and the process that deployed it. A firm with no data governance cannot have real AI governance.

What is shadow AI and why is it a board-level risk?

Shadow AI is staff using AI to make or shape decisions without the organisation's knowledge or approval. It is a board risk because the firm is now deciding, and possibly leaking data, through systems it cannot see or audit. The first step is to find where AI is already used.

What is model drift?

The quiet decay of a model's accuracy as the world moves away from its training data. A credit model built before a downturn keeps giving confident, steadily-less-right answers. Because it never announces the decay, drift bites hardest when conditions change most. Monitor accuracy over time, not just at launch.

Who is accountable when an AI model makes a wrong decision?

The organisation, and inside it a named person. A model cannot be accountable, so a human must own its use and be able to explain and overturn a decision. Governance that leaves accountability with the algorithm is not governance.

Does a Caribbean company need to care about the EU AI Act?

Often yes, indirectly. A firm serving European customers can fall within its reach, and it is becoming a de facto reference standard the way GDPR did. Its core ideas, risk-tiering, documentation and human oversight, are sound governance anywhere, and cheaper to adopt early.

How should a board start governing AI without slowing the business down?

Inventory where AI is used, tier the uses by risk, put human oversight on the high-stakes ones, assign an owner to each model, and monitor accuracy over time. Light on the low-risk majority, firm on the few decisions that carry real consequence.

About StarApple Analytics

StarApple Analytics is Jamaica's leading data science, business intelligence and market research company, a subsidiary of StarApple AI, the first AI company in the Caribbean, established by Adrian Dunkley in Kingston in 2023. We help boards govern AI and model risk through our data science service, and run training with certificates for leadership teams. Contact us at insights@starapple.ai.

Related reading across the Caribbean AI network

Adrian Dunkley, the AI Boss StarApple AI Who Owns The Number?