A boat moored on calm water in Bridgetown, Barbados, near the harbour district that anchors the island's financial and government offices
Photo: Unsplash

TL;DR: The Central Bank of Barbados and the Financial Services Commission's 2024 Financial Stability Report, released in July 2025, put cyber and AI risk on the same short list as global economic uncertainty and climate risk, the three threats regulators judge most likely to shake the island's financial system. A companion post on the Bank's own website spells out why: AI now sits inside insurance claims, lending decisions, and investment management, and the "algorithmic bias and opaque reasoning" built into those models can produce costly errors if nobody is watching. None of this is theoretical committee talk. A Technology and Cyber Risk Management Guideline has been in force since May 2023, licensees must classify a cyber incident within 24 hours and report a major one within four, and a Cybercrime Bill is moving through Parliament to give prosecutors sharper teeth. The International Monetary Fund's own May 2026 assessment backs up the urgency, warning that AI is letting attackers find and exploit weaknesses faster than defenders can patch them. For a small, interconnected financial system like Barbados', that speed gap is the whole ballgame.

Three Risks, Not Two

For years, the Central Bank of Barbados and the Financial Services Commission's annual Financial Stability Report read the way most central bank documents read: interest rates, credit growth, capital buffers, the usual ledger of a small open economy watching its exposure to the rest of the world. The 2024 edition, published jointly by the two regulators in July 2025, kept that ledger but added a line that would not have appeared a decade ago. Global economic uncertainty. Climate risk. And, standing beside them as a named, structural threat, cyber and AI risk.

Naming something in a financial stability report is a regulator's way of saying it now belongs in the same conversation as inflation and hurricane exposure: modelled, stress tested, reported on publicly, rather than filed under "something the IT department handles." The report itself is measured about it. Scenario-based assessments suggest limited capital impact for now, and commercial banks remain resilient. But it also does something it had never done before, running a first-time quantitative estimate of potential losses under a simulated attack on the payment system, the kind of exercise that only gets built once a risk has stopped being hypothetical.

The timing tracks with what has changed on the ground. More Barbadians bank, pay bills, and move money electronically than at any point in the island's history, a shift the Central Bank's own move toward a fully paperless operation by the end of 2026 and the rollout of the instant payment system BiMPay both accelerate. Every one of those conveniences also widens the surface area a bad actor can probe. The report puts it plainly: increased electronic transactions and interlinked payment systems have heightened exposure to cyberattacks, raising the risk of service disruptions, liquidity stress, and reputational damage.

What "AI Risk" Actually Means Inside a Bank

It would be easy to read "AI risk" as shorthand for "hackers using AI," and that is part of the picture, but the Central Bank's own explainer separates two worries, and the second gets less attention outside regulatory circles even though it may matter more day to day.

The first is AI as a weapon: ransomware, phishing, and malware campaigns that AI tools make cheaper and faster to run, aimed at banks, credit unions, and insurance companies, with attacks on core payment rails like the RTGS or ACH systems flagged as the scenario that could do the most damage, since a serious outage there risks denting public confidence enough to trigger a bank run.

The second is AI as a decision-maker, and here the Central Bank's language gets notably specific. AI now sits inside insurance claims processing, lending decisions, and investment management, and the regulators worry that "algorithmic bias and opaque reasoning" in those models could produce poor decisions and costly errors, not from bad intent, but because a model trained on skewed or incomplete data quietly produces skewed outcomes, and nobody notices until the losses show up. Put the two together and the picture is less about one dramatic breach and more about two separate ways an institution loses control of a decision it thought a computer had made safely: once because someone broke in, once because nobody was checking the model's homework.

Smaller institutions carry the sharper end of both risks. A large regional bank can afford a dedicated cybersecurity team and a model risk committee; a small credit union serving a handful of parishes often cannot, which is why the Financial Services Commission has been running technology and cyber risk questionnaires among credit unions specifically, with similar tools now being built for insurance and securities-regulated entities.

The Rules Already on the Books

None of this sits in the abstract. Barbados already has a working regulatory scaffold, built well before AI risk made it into a headline report.

The Technology and Cyber Risk Management Guideline, known inside the sector as the TCRM, has been in force since May 2023. It sets out the Central Bank's expectations for how a licensed financial institution manages cyber risk day to day and, crucially, how it reports and classifies an incident once one happens. The guideline emerged out of the pandemic years, when digital banking adoption accelerated faster than the regulatory rulebook.

  • Classification within 24 hours: A licensee must assess and classify the severity of a cyber incident within a day of detecting it.
  • Initial report within four hours: Once classified as major, the institution has four hours to file its first report with regulators, a genuinely tight window built for speed.
  • Intermediate report at five working days: If still not contained after five working days, a further report is required.
  • Final report on containment: A closing report is due once the incident is fully resolved.

The most commonly reported threats under this framework, according to the FSC, are phishing, ransomware, and BIN attacks, the kind of fraud that targets stolen card number ranges rather than a single account. None of those three needs a headline-grabbing breach of a major bank to do real damage; they chip away at smaller institutions and individual customers constantly, and the reporting rules exist to give regulators a real-time picture of how often that is happening.

Sitting alongside the TCRM is the Cybercrime Bill, passed by the House of Assembly in February 2024 to replace the older Computer Misuse Act with a broader framework for prosecuting computer-related crime and supporting international cooperation across borders. The Bill has not had a smooth passage: it was referred to a Joint Select Committee after civil society groups raised free speech concerns over provisions that penalise online communication causing "annoyance" or "embarrassment." That fight deserves its own scrutiny, but should not obscure the Bill's core financial-sector purpose, giving Barbados sharper legal teeth against the fraud and AI-assisted scams the TCRM's reporting rules are built to surface.

"Not If, But When": The People Building the Guardrails

The clearest window into how seriously Barbados' regulators take this came not from a report but from a room. In April 2024, the Central Bank and the Financial Services Commission co-hosted an online discussion titled, without much room for interpretation, "Not If, But When: Managing Cyber Risk in Barbados' Financial Sector." The panel brought together Tamara Hurley, the Bank's Deputy Director of Bank Supervision, Shonté Chandler and Curtis Lowe from the FSC's credit union division, Anthony Harris, President of the Information Systems Security Association's Barbados chapter, Ryan Greaves, Chief Technology Officer at COB Credit Union, and Greg Vanier, a crisis and risk specialist with Edelman Canada brought in for an outside view on breach communication.

The title was not marketing. "Cyber-attacks are now so prevalent that the consensus among cybersecurity experts is that it is not a matter of if, but rather when organisations will be targeted," was the framing the regulators opened with, and the discussion spent more time on response and containment than on prevention alone, on the theory that a sector planning only to stop every attack is planning for a world that no longer exists.

Chandler used the session to lay out the FSC's reporting expectations in plain terms, telling attendees that "the severity of the incident should be classified within 24 hours of its detection," the same rule now written into the formal guideline. Hurley's framing was similarly direct: the guideline, she said, "details the standard that we expect for cyber risk management," a line that reads like ordinary regulatory language until you notice how much specificity sits underneath it, four-hour clocks, five-day checkpoints, named survey instruments for credit unions.

Governance Is the Product, Not the Paperwork

A four-hour reporting clock and a bias check on a lending model are the same instinct wearing two different hats: know what your systems are doing before a regulator, a customer, or an attacker finds out for you. Bajan institutions that treat AI governance as a real operating discipline, not a policy binder, will be the ones still standing when the "when" in that panel title arrives at their door.

Get AI Governance Support for Your Business

The View From Washington: AI Speeds Up the Attacker's Side

Barbados is not reading this problem in isolation, and it should not have to. The International Monetary Fund published its own assessment in May 2026, warning bluntly that "advanced AI models can dramatically reduce the time and cost needed to identify and exploit vulnerabilities." The practical effect is a widening speed gap between attacker and defender: a human security team patches on a schedule measured in days or weeks, while an AI-assisted attacker can probe thousands of systems for the same weakness far faster.

The IMF's deeper worry matches the one running through Barbados' own Financial Stability Report: interconnection. Modern finance runs on shared cloud infrastructure and common software libraries, so a single vulnerability, once found, does not threaten one institution. It threatens every institution using the same underlying service, simultaneously. The Fund's language on the worst case is stark: extreme cyber-incident losses could "trigger funding strains, raise solvency concerns, and disrupt broader markets," a description that could sit comfortably inside the Barbadian report's own payment-system attack scenario.

Its prescription is also one Barbadian regulators would recognise: "when attackers operate at machine speed, defenders must do the same," meaning institutions need their own AI tools for threat detection and incident response, paired with real governance and human oversight rather than a second black box nobody fully understands. The Fund notes, with obvious relevance to a small island economy, that emerging economies face disproportionate exposure to attackers who deliberately target regions with weaker defences, precisely the gap Barbados' TCRM guideline and credit union questionnaires are trying to close before it widens.

Why a Small System Cannot Just Copy and Paste

Barbados is not Toronto or London, and the reason this matters is scale, not sophistication. A handful of commercial banks and credit unions carry the deposits of nearly the entire population, so a serious incident at even one mid-sized institution touches a meaningfully large share of Bajan households directly. That concentration cuts both ways: it makes a bad day worse, but it also makes coordinated defence more achievable, since a shared guideline and a joint panel discussion can cover ground that would take years of fragmented effort in a larger market. The TCRM and the "Not If, But When" session are, in that sense, the right-sized response to an island-sized system.

Where Barbados still has real work to do is on the AI governance side, the algorithmic bias and opaque reasoning half of the risk, newer terrain than cyber incident reporting and less thoroughly mapped by existing guidelines. A bank that has drilled its four-hour incident response clock for years may still have no formal process for auditing whether an AI-assisted loan scoring model is quietly disadvantaging applicants from a particular parish. That gap is where the next Financial Stability Report is likely to spend more ink, and where Bajan institutions have the clearest opportunity to get ahead of the regulator rather than wait to be told.

What This Means for Bajan Businesses and Depositors

For the average depositor, the reassuring part is real: the Central Bank's own scenario testing suggests limited capital impact from cyber risk today, and commercial banks remain resilient by the regulator's own assessment. Nobody should read this and expect a savings account to vanish tomorrow.

For a small or mid-sized Bajan business, the useful takeaway is procedural. If a company processes payments, holds customer data, or uses any AI tool to screen applicants, price a product, or flag a claim, three things follow. Know which reporting rules apply if a breach happens, because the four-hour clock does not pause while someone looks up the guideline for the first time. Treat any AI model making decisions about customers as something that needs documented logic and a human who can explain and re-check its reasoning, not a vendor's black box accepted on faith. And engage regulators early rather than reactively; the TCRM, the credit union surveys, and the April 2024 panel all show the Central Bank and FSC would rather work with licensees on preparedness than discover gaps after an incident.

None of this requires a Bajan credit union or insurer to build its own artificial intelligence lab. Regional partners including StarApple AI, the Caribbean's first AI company, work with Caribbean financial institutions on this exact groundwork: AI readiness assessments, bias auditing, and staff training that turns a compliance requirement into a genuine operating advantage. The broader regional picture, tracked by the Caribbean AI Risk Management Council, shows Barbados is far from alone in working out how to govern AI inside a small financial system, and the answers taking shape in Bridgetown boardrooms this year are likely to become the template other island regulators reach for next.

Frequently Asked Questions

Why does Barbados' Central Bank now list AI as a financial stability risk?

The Central Bank of Barbados and the Financial Services Commission's 2024 Financial Stability Report, released in July 2025, names cyber and AI risk as one of three key threats to the island's financial system, alongside global economic uncertainty and climate risk. The report points to growing use of AI in insurance claims, lending decisions, and investment management, and warns that algorithmic bias and opaque reasoning built into those models could lead to poor decisions and costly errors if left unchecked.

What is the Technology and Cyber Risk Management Guideline (TCRM)?

The TCRM is a guideline the Central Bank of Barbados issued in May 2023, setting out its regulatory expectations for how licensed financial institutions manage cyber risk and report and classify cyber incidents. It was developed as electronic and digitised financial transactions accelerated, raising the sector's exposure to cyberattacks.

How quickly must a Barbadian bank or credit union report a cyber incident?

Under the reporting framework the Central Bank and the Financial Services Commission have put in place, a licensee must classify the severity of an incident within 24 hours of detection, submit an initial report within four hours of that classification if it is deemed major, follow up with an intermediate report if the incident is not contained within five working days, and file a final report once it is fully contained.

How is AI actually being used to attack financial institutions?

According to the International Monetary Fund's May 2026 analysis, advanced AI models dramatically cut the time and cost needed to find and exploit software vulnerabilities, letting attackers operate faster than defenders can patch systems. Because banks share cloud services and payment infrastructure, a single AI-discovered weakness can potentially compromise several institutions at once, which is why the IMF and the Central Bank of Barbados both treat AI-enabled cyberattacks as a systemic risk rather than an isolated one.

Does the Cybercrime Bill 2024 cover AI-related offences?

The Cybercrime Bill, passed by the House of Assembly in February 2024 and referred to a Joint Select Committee after free speech concerns were raised, is designed to replace the older Computer Misuse Act with a broader legal framework for prosecuting cybercrime and supporting international cooperation on computer-related offences. It gives Barbados a stronger legal basis to pursue AI-assisted fraud and hacking, though its scope has also drawn criticism from civil society groups over provisions unrelated to financial crime.

What should Bajan businesses and depositors take from this?

The Central Bank's own assessment is that commercial banks remain resilient and scenario-based capital impact from cyber risk looks limited for now. The bigger practical takeaway for businesses is that regulators expect real cyber governance, not just a policy on paper, and that AI tools used in lending or claims decisions need human oversight, documented logic, and regular bias checks rather than being treated as a black box.

About AI Barbados

AI Barbados is the island's main source for artificial intelligence news and education. Powered by StarApple AI, the Caribbean's first AI company, we help Barbadian banks, credit unions, insurers, and regulators understand what responsible AI governance looks like in practice, not just on paper.

From cyber incident readiness to bias audits on lending and claims models, we bring practical AI governance support to the institutions holding Barbados' financial system together.

Sign Up for AI Training & Services