
Why Continuous AI Oversight Is Becoming Essential
Executive Summary
On 27 July 2026, the European Union did something that surprised a great many people who had spent two years preparing for the opposite. Six days before its most consequential artificial intelligence obligations were due to take effect, it postponed them — pushing the deadline for high-risk AI systems from August 2026 out to December 2027, and for AI embedded in regulated products to August 2028.
It would be easy to read that as a reprieve. It is not. The transparency obligations still took effect on schedule. The prohibitions have applied since early 2025. And the reason for the deferral was not that the risk had receded — it was that the standards, the technical guidance and the national supervisory authorities were not ready in time.
That distinction matters enormously for Caribbean organizations, and for a reason that has nothing to do with Europe. The gap between how fast businesses are adopting AI and how fast anyone — regulator, standard-setter or board — can build the machinery to oversee it is now the defining feature of this subject. Organizations are not waiting for permission to use artificial intelligence. They are already using it, frequently without knowing where, and almost always without being able to demonstrate that it is controlled.
This article explains what AI governance is, why it has become a board matter rather than a technology matter, what can go wrong, and what a practical governance programme looks like for an organization that is not going to build a specialist internal function.
What AI governance actually means

Some definitions first, because this subject is unusually rich in terms that are used loosely.
An AI system is software that generates outputs — predictions, recommendations, classifications, text, decisions — from data, in ways that are not fully specified in advance by a human programmer. This is broader than most people assume. It includes the obvious generative tools, but also the fraud-scoring engine inside a core banking platform, the CV-ranking feature in a recruitment system, and the “suggested reply” function in an email client.
Generative AI is the subset that produces new content — text, images, code, audio — in response to a prompt. It is what most people mean when they say “AI,” and it is the category that has spread fastest through organizations because it requires no procurement decision, no integration project and no technical skill to start using.
Agentic AI describes systems that do not merely produce an output for a human to act on, but take actions themselves: sending the email, updating the record, approving the transaction. This is where the governance question sharpens considerably, because the human review step that most organizations quietly rely on may no longer exist.
Shadow AI is artificial intelligence in use inside an organization without its knowledge, approval or control. It is the AI equivalent of the unauthorised spreadsheet that half the finance department depends on.
AI governance, then, is the set of structures, policies, controls and reporting arrangements through which an organization decides where AI may be used, who is accountable for it, what safeguards apply, and how it can demonstrate to others that those safeguards actually operate. It is not a technology discipline. It is a governance discipline that happens to concern technology — which is precisely why it keeps landing on boards that did not expect it.
Why this matters now

Three developments have converged, and none of them is European.
The regulatory position has become harder to read, not easier. The EU’s deferral was accompanied by no reduction in the underlying obligations — transparency duties, including requirements around labelling AI-generated content, remain on their original schedule, and the machine-readable marking requirement lands in December 2026. Organizations that concluded from the headline that AI regulation had been paused have misread it. Meanwhile, no CARICOM state has a comprehensive AI regulatory regime, and Jamaica has issued no specific guidance on the use of personal data in AI systems. The absence of AI-specific law is routinely mistaken for the absence of legal exposure. It is not the same thing.
Existing law already applies, and is becoming enforceable. Jamaica’s Data Protection Act has been in full operation since December 2023, administered by the Office of the Information Commissioner, with mandatory breach notification within 72 hours and a registration obligation for data controllers. Through 2026 the Government has signalled that the enforcement provisions will be fully activated and that the OIC is being built into an enforcement-ready authority. An organization whose employees paste customer information into a public AI tool does not need an AI statute to have a problem. It has a data protection problem today.
Buyers and partners have started asking. ISO/IEC 42001, published at the end of 2023, is the first international management system standard for AI against which an organization can be independently certified. It has moved quickly from novelty to procurement question, particularly for organizations selling into regulated markets. Regionally, the Caribbean Telecommunications Union established a Caribbean AI Task Force in 2025 to work towards harmonised policy across member states. The direction of travel is clear even where the destination is not.
How AI enters an organization — and how governance works

The central practical problem is not that AI is dangerous. It is that AI arrives through many doors at once, and most organizations are watching only one of them.
It arrives through enterprise software, when a vendor adds AI features to a product already in use. Through generative platforms adopted by individual employees. Through customer service applications. Through productivity suites. Through third-party vendors who use AI to deliver services under contract. Through cloud platforms, analytics tools and embedded functionality nobody was told about. And through applications employees acquire independently, on personal accounts, to make their own work easier.
None of these routes involves a procurement decision that a governance function would ordinarily see. Which is why an AI inventory almost always surprises the management team that commissioned it.
Governance that works is therefore built as a cycle rather than a policy document. Dawgen structures it in five stages.
Assess establishes the facts: what AI is in use, who is using it, what data it touches, which use cases carry material consequences, and how mature the existing governance arrangements really are.
Design builds the architecture: a governance framework, an acceptable-use policy, clear accountability across the board, management, technology, risk, compliance, legal, internal audit and the business units — and a risk classification that distinguishes an administrative productivity tool from a system influencing credit, employment or healthcare decisions.
Implement converts that into operating controls: approval workflows, inventory registers, vendor due diligence, data-access restrictions, human review requirements, output validation, incident reporting, escalation thresholds and staff training.
Monitor keeps it current, because AI systems, vendors, models, data, regulation and business use cases all change continuously. Annual review is not a cadence that matches this subject.
Assure prepares the evidence — control documentation, audit trails, approval records, testing results — so that when the question comes, the answer is demonstrable rather than asserted.
The risks that actually materialise

Discussions of AI risk tend toward the speculative. The exposures that turn up in practice are more mundane and more immediate.
Confidential information leaving the organization. An employee pastes a draft contract, a patient record or a customer list into a public AI tool to summarise it. Depending on the tool and the account type, that data may be retained, used for training, or accessible to the vendor. This is the single most common finding in an initial AI review, and it is almost always accidental.
Outputs that are wrong in ways that look right. Generative systems produce fluent, confident, plausible text regardless of whether the underlying content is accurate. They invent citations, misstate figures and fabricate details with the same tone they use for correct answers. Where output goes to a customer, a regulator or a court without review, fluency becomes a liability rather than an asset.
Decisions that cannot be explained. If an applicant is declined credit or a candidate is filtered out of a recruitment process, the organization must be able to say why. “The system recommended it” is not an answer that survives a complaint, a regulatory query or litigation.
Bias that reproduces at scale. A human decision-maker with a bias affects the cases they touch. A biased system affects every case, consistently, and generates a documentary record of having done so.
Third-party dependency. Increasingly the AI risk an organization carries is not in software it chose, but in software its vendors chose. Few contracts written before 2023 say anything useful about AI, and the due diligence questionnaires in most organizations still do not ask.
Cybersecurity exposure. AI tools introduce new attack surfaces, new credentials, new data flows and new categories of misuse — including AI-assisted social engineering that is substantially more convincing than what preceded it.
Silent model change. The model behind a tool can be updated by its vendor without notice. A control that was validated against last quarter’s behaviour may not hold against this quarter’s. This is unlike almost any other control environment, and it is the strongest single argument for continuous rather than periodic oversight.
Absence of records. Many organizations cannot reconstruct which AI tool produced a given output, on what date, using which inputs, reviewed by whom. When an incident occurs, that gap is the problem.
Governance, financial and regulatory implications

For directors, the analysis is more familiar than it first appears. Boards are not expected to understand model architecture, any more than they are expected to understand the cryptography behind the payment system. They are expected to satisfy themselves that material risks are identified, that accountability is assigned, that controls exist, and that they receive information sufficient to exercise oversight. AI does not create a new duty. It creates a new domain in which an existing duty applies — and one where most boards currently receive no information at all.
The accountability question is the one that reliably exposes the gap. Ask who approves a new AI use case, who decides which decisions require human review, who assesses an AI vendor, and who would be told first if an AI-related incident occurred. In organizations without a governance framework, these questions have no owner. They have not been allocated to anyone, which means in practice they have been allocated to whoever acts last.
Financially, three effects are emerging. AI spend is fragmenting across departments in a way that resembles early cloud adoption, with limited visibility into aggregate cost or realised benefit. Procurement cycles are lengthening as buyers begin requiring evidence of AI governance from suppliers — which means a firm’s own governance maturity is becoming a commercial asset or a commercial obstacle. And insurers, auditors and lenders are beginning to ask questions in this area that they did not ask two years ago.
Regulatorily, the practical position for a Caribbean organization is this. There is no AI statute to comply with. There is data protection law that is in force and moving toward active enforcement. There is sectoral regulation — financial services, insurance, employment, consumer protection — that applies to outcomes regardless of the tool that produced them. And there is a reasonable expectation that AI-specific requirements will arrive, with an implementation window shorter than the one Europe granted itself. Organizations that build governance now will be adapting an existing framework. Organizations that wait will be building from nothing under time pressure.
What organizations should actually do

A workable sequence, in order of dependency.
Build the inventory first. Everything else depends on knowing what exists. Cover enterprise software with AI features, standalone tools, embedded vendor functionality and employee-acquired applications. Expect the result to be larger than management predicts.
Classify by consequence, not by technology. A tool that drafts internal meeting notes and a tool that scores credit applications require entirely different treatment. Sort use cases by the significance of what happens when the output is wrong.
Issue an acceptable-use policy that is specific enough to follow. State which tools are approved, what categories of information must never be entered into them, and what happens when someone needs an exception. A policy that says “use AI responsibly” gives an employee nothing to act on.
Define the human control points explicitly. For each material use case, state whether a human must review before the output is used, who that human is, and what they are reviewing for. This single step prevents a disproportionate share of what goes wrong.
Bring AI into vendor due diligence. Ask suppliers whether AI is used in delivering the service, what data it processes, whether prompts and outputs are retained, and whether the model may change without notice.
Establish an approval route for new use cases. Without one, adoption continues through the side door and the inventory is stale within a month.
Train people on the failure modes. Most AI incidents involve well-intentioned employees who did not know that pasting a document into a tool constituted disclosing it.
Set reporting to the governance calendar. A short, standing item covering the AI portfolio, risk distribution, control status, vendor exposure, incidents, regulatory developments and open remediation. One page, every quarter, with every figure dated.
Keep the evidence as you go. Assembling documentation retrospectively, under scrutiny, is far more expensive than capturing it contemporaneously.
A composite Caribbean case study

A Caribbean financial services organization — a composite drawn from patterns seen across the region, not a specific client — had experienced rapid employee adoption of generative AI. Management’s working assumption was that use was limited to a handful of staff drafting internal documents.
An initial inventory found otherwise. AI was in use across research, customer communication, document preparation and data analysis. Several third-party applications already in the environment contained embedded AI functions that had never been assessed. A number of employee-led use cases had never been through any approval process, because no approval process existed.
The questions that emerged were not technical. Were employees entering confidential information into public tools? Were AI-generated customer communications independently reviewed before sending? Which vendors retained prompts and outputs? Who approved new applications? How would an AI-related incident be reported, and to whom? What should the board be told?
The programme that followed introduced an enterprise AI inventory, use-case classification, an acceptable-use policy, vendor assessment requirements, human-review controls, approval workflows, staff training, incident reporting and quarterly governance reporting.
The most valuable outcome was not the documentation. It was that management regained visibility and accountability over a technology environment that had developed considerably faster than the governance processes meant to control it. The organization did not use less AI afterwards. It used more of it, with a clearer view of where the consequential decisions sat.
The Dawgen Global perspective

Our view is that AI governance is being framed too often as a compliance exercise, and that this framing produces poor outcomes. Organizations that approach it defensively tend to write restrictive policies that employees route around, which leaves the organization with the appearance of control and none of the substance.
The more useful framing is capability. An organization that knows what AI it operates, has classified it by consequence, has defined its human control points and can evidence that those controls work is an organization that can adopt AI faster and more confidently than one that cannot. Governance is what makes scale possible. It is not the brake.
We also take the view that this is not work most mid-market organizations should build a specialist internal function to perform. The subject moves too quickly, the required expertise spans too many disciplines, and the workload is uneven — heavy at establishment, then steady and modest. That profile suits a continuing advisory relationship better than a permanent hire.
Dawgen TRUST360™ is built on that reasoning: an initial diagnostic, an implementation phase, and then continuing governance support — monitoring, control testing, regulatory watch and board reporting — at a cadence matched to how quickly this subject actually changes.
Conclusion

The European deferral bought organizations time, but it bought it for a reason that should give nobody comfort: the machinery of oversight could not be built fast enough. That is precisely the problem inside individual organizations too, and no one is going to grant them an extension.
The starting point is not a policy. It is visibility. An organization cannot govern AI it does not know exists, and almost every organization that conducts an honest inventory discovers more than it expected.
Request the Dawgen AI Governance Maturity Diagnostic. It examines AI strategy, governance, accountability, risk management, data, privacy, cybersecurity, third parties, human oversight, policies, controls, employee practices, monitoring, reporting and assurance readiness — and produces a prioritized roadmap for strengthening your position.
Download the Dawgen TRUST360™ brochure · dawgen.global/contact-us · [email protected]
At Dawgen Global, we help you make Smarter and More Effective Decisions.
Sources and further reading
- Regulation (EU) 2026/1744 (the “Digital Omnibus on AI”), published in the Official Journal 24 July 2026, in force 27 July 2026, amending Regulation (EU) 2024/1689 (the EU AI Act)
- European Commission AI Act Service Desk — implementation timeline
- ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system; and ISO/IEC 42006:2025 on requirements for certification bodies
- NIST AI Risk Management Framework (AI RMF 1.0) and its Generative AI Profile
- Jamaica Data Protection Act 2020; Office of the Information Commissioner
- Jamaica Information Service — Ministerial statement on activation of Data Protection Act enforcement provisions, 2026/27 Sectoral Debate
- Caribbean Telecommunications Union — Caribbean AI Task Force
- UNESCO Caribbean Artificial Intelligence Policy Roadmap
Regulatory positions stated in this article reflect the position as at August 2026 and should be verified before being relied upon. This article is general commentary and does not constitute legal, regulatory or assurance advice.
About Dawgen Global
Dawgen Global is an independent, integrated multidisciplinary professional services firm headquartered at 47 Trinidad Terrace, New Kingston, Jamaica, serving more than 15 territories across the Caribbean. Founded and led by Dr. Dawkins Brown, Executive Chairman, the firm is independent and not affiliated with any international network. It delivers a full suite of professional services under one roof: audit and assurance; tax advisory; IT and digital transformation; risk management; cybersecurity; actuarial and insurance regulatory advisory; HR advisory; mergers and acquisitions; corporate recovery; business advisory and strategy; accounting BPO and virtual CFO services; and legal process outsourcing.
The proposition is simple: big-firm capability without the big-firm price. Dawgen Global’s integrated approach is built for the specific complexities and opportunities of the Caribbean market, helping organizations make sharper, better-informed decisions that drive measurable progress.
To explore a partnership, reach out:
- Website: dawgen.global
- Email: [email protected]
- WhatsApp (Global): +1 555-795-9071
- Caribbean offices: +1 876-665-5926 | +1 876-929-3670 | +1 876-926-5210

