maestro ai labs × caribbean artificial intelligence association

The Caribbean AI Risk Index

The Caribbean AI Risk Index (CARI) is a composite measure of each nation’s exposure to artificial-intelligence-driven disruption and of the institutional capacity in place to absorb it. It covers the sixteen sovereign Caribbean states and fifteen territories, is constructed from public data under the OECD–JRC composite-indicator methodology, and is published with its full method so that any score can be independently recomputed.

AI Risk Index
Territory (dashed = estimate)
Scores are relative within the Caribbean sample. Small islands carry circular markers. Dashed outlines are territories, scored as estimates outside the sovereign ranking.

Reading the index. CARI is a composite indicator built under the OECD–JRC methodology: exposure and fragility are estimated separately from normalised indicator sets and combined by geometric aggregation on a regional 20–88 scale. Every profile carries its rank interval from the sensitivity analysis, a simulated score interval from 1,000 Monte Carlo draws, and a data-coverage grade; gaps are disclosed, never interpolated. Territories carry dashed outlines and estimated scores outside the 16-country ranking, coded from the law in force in each jurisdiction.

CARI Me

What this means for you

The national pillars, translated into personal terms and ranked for the selected country. Modelled from the index inputs.

Cost-of-living pressure is read through the economic resilience gap, the channel through which AI-driven electricity and hardware costs pass into small import-dependent economies. Voice-clone exposure combines remittance dependence with social-media saturation.

Key figures

Regional overview

Country ranking

The full ranking

#CountryCARITier JobsCyberGovernance InfoEconomyPsychosocial Confidence

Pillar scores 0–100, higher = greater relative risk. Confidence: A ≥85% indicator coverage · B 65–84% · C <65%.

Territories

Territory estimates

TerritoryGoverned underCARI est.Tier JobsCyberGovernance InfoEconomy

Territories are scored on the same scale, shown with dashed outlines, and sit outside the sovereign ranking; their governance inputs, including data-protection and cybercrime legislation, are coded from the law in force in each jurisdiction. Estimates falling outside the sovereign anchor range are clipped to a 5–95 display band, so several territories with no legal framework share the ceiling value.

The five pillars

What the index measures

Methodology

How the index is built

Summary

The Caribbean AI Risk Index is estimated as a two-dimensional composite. The exposure dimension aggregates three pillars: labour-market exposure, in which sectoral GDP shares are weighted by occupational AI-exposure coefficients drawn from the ILO and Felten task-based literatures and combined with outsourcing intensity; the cyber and AI-agent threat surface; and the information environment. The fragility dimension aggregates two pillars measuring governance capacity and economic resilience. The governance pillar scores each state's readiness index position, data-protection enforcement, cybercrime legislation, national AI strategy status, and public AI-literacy provision; the resilience pillar scores sectoral concentration, measured both as top-sector share and as a Herfindahl–Hirschman diversification index, together with remittance dependence, income, unemployment, the domestic expertise base, and verified public investment in digital and AI capability. Measured cyber incidence enters the threat pillar as ransomware leak-site listings per million population. Indicators are normalised to a common 0–100 scale against documented goalposts, or against winsorised within-sample ranges where no external scale exists, and pillar scores are combined within each dimension by weighted arithmetic mean. The composite is the geometric mean of the two dimensions, a specification adopted on the recommendation of the methodological review because it is non-compensatory: high readiness cannot offset high exposure, and low exposure cannot conceal weak institutions. A non-compensatory classification rule assigns a latent-risk flag to any state whose fragility score reaches 80, irrespective of its composite value. All inputs, coding decisions and sources are published on this page.

Foundations

CARI's risk domains map onto the MIT AI Risk Repository (Slattery et al., 2024) taxonomy; its risk framing follows the NIST AI Risk Management Framework; its construction follows the OECD/JRC Handbook on Composite Indicators; its readiness logic inverts the IMF AI Preparedness Index and Oxford Insights Government AI Readiness Index; and its labour-exposure coefficients derive from the ILO's occupational GenAI-exposure research (Gmyrek et al., WP96/WP140). Input data are drawn from the ITU, UN DESA, the World Bank, Oxford Insights, the ILO, the WTTC, DataReportal, the IMF, INSEE, national legislation records, and the peer-reviewed psychology literature; the full source register with document-level citations is held in the project archive and is available on request.

Calculation
  • Formula: CARI = 100·√((E′/100)·(F′/100)), where E = mean of the three exposure pillars, F = mean of the two fragility pillars, and p′ = 1 + 0.99p. The composite is then stretched so the regional minimum and maximum sit at 20 and 88. The stretch changes nothing about ranks or tiers; it makes the differences between countries visible. Integer scores only, since decimals would be false precision at this sample size.
  • Tiers are set at quintiles of the observed score distribution and labelled in explicitly relative language. There is deliberately no “Severe” tier.
  • Missing data is never silently imputed: pillar weights are redistributed, the redistribution is disclosed, and each country carries a data-coverage percentage, a confidence grade (A≥85%, B 65–84%, C<65%), and a provisional flag where an anchor indicator is absent.
  • Sensitivity: exposure/fragility weight tilts of ±25% and an alternative arithmetic aggregation are re-run, and each country's resulting rank range is published in its profile.
  • Simulation: 1,000 Monte Carlo draws perturb every continuous input by a uniform ±10% and move every ordinal coding one step with probability 0.25, then recompute the full pipeline, normalisations included. The 10th–90th percentile of the simulated score distribution is published in each profile as the simulated score interval; a narrow interval indicates a score robust to measurement error, a wide one indicates sensitivity to the underlying codings.
  • Scored with coverage flags: ransomware leak-site listings, normalised per million population, enter the threat pillar. Where regional monitoring explicitly obtained no data for a state, the input is recorded as missing rather than zero and the pillar weight is redistributed.
  • Deliberately unscored: broader cyber incident narratives (they track disclosure rather than safety), election-cycle AI incidents (calendar effects), and psychosocial impacts (no Caribbean-level evidence yet). All three appear as documented context instead.
Expert review

The draft methodology and preliminary scores were reviewed from seven perspectives before publication: composite-index methodology, frontier-AI capabilities, labour economics, social psychology, AI policy, cybersecurity, and Caribbean regional development. Every blocking finding was adopted. The principal changes were the removal of tourism from the labour-exposure pillar, since in-person tourism occupations rank near the bottom of every published AI-exposure gradient; the reclassification of incident counts as unscored context; the treatment of state information control as a scored risk; the decision to document rather than score the psychosocial domain pending Caribbean evidence; and the restructuring of the index into non-compensating Exposure and Fragility axes, so that low measured exposure cannot conceal extreme institutional fragility.

Independence disclosure: Maestro AI Labs provides commercial AI services in the region; the Caribbean Artificial Intelligence Association is a membership advocacy body. No government paid for, reviewed, or influenced any score. The full method and data are published so any score can be independently recomputed. Corrections are welcome and will be logged publicly.

Limitations
  • Scores are relative within the Caribbean. “Comparatively Lower” does not mean low risk in absolute terms, and “Very High” is a regional comparison rather than a condemnation.
  • Small-state statistics gaps are real: several microstates lack ILO labour estimates, and regional cyber monitoring explicitly obtained no data for five countries. Coverage grades disclose this; they cannot cure it.
  • Composite indices cannot capture everything. Haiti's crisis dynamics and Cuba's state-controlled information environment both exceed what public indicators measure, and both carry explicit caveats.
  • Tourism figures mix WTTC reference years (2022–2024); Guyana's income statistics are oil-distorted; both are flagged where used.
  • Version 2.0 added cybercrime-legislation status, AI-literacy provision, verified public investment, the domestic expertise base, Herfindahl–Hirschman diversification, per-capita ransomware incidence, and the Monte Carlo simulation. The remaining roadmap covers government-domain email-security (DMARC/DNSSEC) scans, FIRST CSIRT membership, financial-fraud readiness (CFATF), Creole-language AI exclusion, data-sovereignty indicators, and a Caribbean youth psychosocial study, which is CAIA's standing research call.
  • Montserrat is a full CARICOM member but a UK overseas territory, so it is not scored as a sovereign state; territories (Puerto Rico, USVI, Cayman, Aruba, Curaçao, Martinique, Guadeloupe and others) are governed under US/EU/UK/Dutch AI and data frameworks and are outside a sovereign-policy index.
Maestro AI Labs × CAIA

About this project

The Caribbean AI Risk Index is a collaboration between Maestro AI Labs and the Caribbean Artificial Intelligence Association, led by Adrian Dunkley, President of the Association. Its purpose is to give Caribbean governments, businesses and citizens a shared, evidence-based picture of where AI-driven risk is concentrating and where preparation is advancing. The full method and data sources are published on this page; every score can be independently recomputed, and corrections and national data submissions are welcome.

Contribute national data

National statistical offices, CERTs and researchers holding data superior to the public sources used here are invited to submit it; verified submissions will be incorporated in the next edition with attribution.

Contact the team