The Minister Who Never Said That: Trinidad's Deepfake Fraud Wave and the AI Roadmap Gap
Since August 2025, AI-generated video of Trinidad and Tobago's Finance Minister, its AI Minister, a former President, a former Prime Minister, a former bank chairman and a newspaper editor has been used to sell fraudulent investments, drawing six public alerts from the securities regulator. CARICOM's newly endorsed AI Roadmap does not name the problem. I set out what that gap is costing and what should close it.
On 26 June 2026, the Trinidad and Tobago Securities and Exchange Commission issued its sixth public alert in under a year warning citizens that a video of former Prime Minister Dr Keith Rowley endorsing an investment scheme was fabricated. He never said it. He was never in the room. The voice, the gestures and the setting were assembled by software, and by the time TTSEC caught up, the clip had already done its job on a percentage of the people who saw it. Regional AI policy is usually written to get ahead of a hypothetical risk. This one arrives already dated, sourced and running: six documented incidents involving five named public figures over the past year.
Thirteen days before that alert, CARICOM's COTED-ICT had endorsed the UNESCO Caribbean AI Policy Roadmap, the region's clearest regulatory statement yet on how AI should be governed across fifteen member states. The Roadmap runs to four pillars covering culture, governance, education and resilience. Nowhere in its published materials does the word deepfake appear, and nowhere does AI-enabled financial fraud get named as a distinct risk with its own coordination mechanism. The country hosting the fraud wave and the regional roadmap meant to govern the technology behind it arrived at the same moment without connecting to each other.
TLDR
- Since August 2025, AI-generated video and audio has impersonated Trinidad and Tobago's Finance Minister Davendranath Tancoo, its AI Minister Dominic Smith, former President Anthony Carmona, former Republic Bank chairman Dr Ronald Ramkissoon and former Prime Minister Dr Keith Rowley to sell fraudulent investment schemes.
- The TTSEC had issued six public investor alerts by 26 June 2026, and a fabricated publication impersonating Guardian Media editor Kejan Haynes drew a public disavowal from Guardian Media.
- Trinidad and Tobago stood up a Ministry of Public Administration and Artificial Intelligence under Minister Dominic Smith and, on 11 September 2025, an Inter-Ministerial Steering Committee on Cyber Security and AI reporting quarterly.
- CARICOM's COTED-ICT endorsed the UNESCO Caribbean AI Policy Roadmap on 7 July 2026, thirteen days before the sixth alert. Its four pillars do not name deepfake-enabled fraud as a distinct governance item.
- Globally, deepfake fraud losses total at least $3.7 billion by a 2026 count, and deepfake fraud now makes up roughly 6.5% of all fraud attempts, up from 0.1% in 2022. The Caribbean scores 10.2 out of 20 on the World Bank's 2024 cybersecurity readiness measure, the least protected region assessed.
- CAIA's position: Trinidad did the incident response well. What is missing is the regional layer, naming the risk in the Roadmap, sharing alerts across borders, and linking two CARICOM-adjacent processes that are currently working the same problem apart.
Six Alerts, Five Faces
The pattern started with the two ministers most exposed to it by title. In August 2025, fabricated social media posts showed Finance Minister Davendranath Tancoo and newly appointed AI Minister Dominic Smith apparently endorsing investment schemes, a detail that reads almost as satire in hindsight: the government official responsible for AI policy became one of the first people impersonated by the technology he had just been handed a ministry to govern. The Ministry of Finance moved quickly to state that the Tancoo video was fabricated, unauthorised and malicious, and TTSEC folded it into what became a running series of public warnings.
The wave did not stay confined to sitting officials. Fabricated footage of former President Anthony Carmona and former Republic Bank chairman Dr Ronald Ramkissoon followed, lending the schemes the borrowed authority of a head of state and a serious banker in the same campaign. By June 2026, fraudsters had reached for former Prime Minister Dr Keith Rowley, and a separate scheme fabricated an entire fraudulent online publication carrying the byline of Guardian Media editor Kejan Haynes, prompting Guardian Media to publicly disavow it. Five distinct public figures, spanning government, banking, the presidency and the press, gave four fraud campaigns their credibility, none of them consenting participants.
What makes the Trinidad wave a useful case study rather than a single scandal is its shape over time. It did not arrive as one viral clip and fade. It arrived as a sustained campaign, evolving its choice of target as each previous face got flagged and its credibility spent, which is exactly the behaviour a regulator should expect from a tool that costs almost nothing to reuse. TTSEC's own alerts describe the tactics as adapting: fake social media profiles, impersonation of legitimate financial institutions, and deceptive advertisements engineered to look like a sanctioned product rather than an obvious scam. A fraud operation that iterates its targets in response to detection behaves less like a one-off incident and more like a product with a release cycle.
The Ministry That Became a Target on Day One
Trinidad and Tobago's institutional response has moved faster than most of its neighbours'. The government created a standalone Ministry of Public Administration and Artificial Intelligence under Minister Dominic Smith, and on 11 September 2025, roughly a month after the first fabricated videos surfaced, established an Inter-Ministerial Steering Committee on Cyber Security and AI with a quarterly threat-reporting mandate. Minister Smith has pointed to the Caribbean Telecommunications Union's regional AI task force as the body meant to coordinate this at scale; no single ministry in a country of 1.4 million people can build the detection capacity a global fraud technique demands on its own.
The sequence reveals something worth sitting with. The technology used to fabricate Minister Smith's own likeness reached criminal use in his country before his ministry had finished standing up, and the steering committee that now tracks these threats quarterly was created in direct response to an attack rather than ahead of one. Almost no government anywhere stood up deepfake-specific fraud response ahead of its first incident, so Trinidad is not unusual in that respect. It matters here because CAIA covered Trinidad's $5 billion AI infrastructure commitment arriving the same month the Caribbean AI Task Force delivered its governance recommendations, and the pattern repeats: capital and adoption move first, and the institutions built to catch what goes wrong follow the first incident rather than precede it.
A Roadmap That Never Says the Word
CARICOM's COTED-ICT endorsed the UNESCO Caribbean AI Policy Roadmap on 7 July 2026, a decision CAIA covered in detail at the time as a genuine, if incomplete, step toward regional AI governance. The Roadmap organises itself around four pillars: Culture and Creativity, Governance and Transformation, Education and Upskilling, and Resilience and Sustainability. The Governance and Transformation pillar calls for regulatory oversight of AI systems in general terms, the kind of language that is easy to endorse precisely because it commits nobody to a specific mechanism.
What the Roadmap does not do, in any of its public materials as of this writing, is name deepfake-enabled financial fraud as a distinct risk category requiring its own cross-border reporting or coordination mechanism. That is a striking omission given the timing. The Roadmap was endorsed thirteen days before TTSEC's sixth alert, in a region where the fraud pattern had already been running, documented and reported on, for nearly a year. A regional AI governance document written in 2026 without a section on AI-enabled fraud is not a document written without the evidence. The evidence was published in the same country's newspapers for months before the endorsement.
The Second CARICOM Process Nobody Has Linked to the First
The Roadmap is not the only CARICOM-adjacent initiative that touches this problem, which makes the gap stranger rather than more forgivable. CARICOM IMPACS launched the CARICOM Cybercrime and Cybersecurity Action Plan on 31 October 2025 in Port of Spain, the same city carrying the fraud wave, with EU support and six pillars covering public awareness, capability building, technical standards, regulatory frameworks, incident management and international cooperation. A public-awareness pillar built for exactly this kind of scam already exists, in the same city, under a different CARICOM-linked body, with no visible formal link connecting it to the AI Roadmap's governance pillar.
Two processes, both CARICOM-adjacent, both launched within nine months of each other, both relevant to the same fraud wave, and neither one's public materials cite the other by name. That is the actual finding here. Trinidad and Tobago built a national response quickly. The region built two separate policy frameworks that both bear on the same problem without formally referencing each other. Fixing that costs no money and requires no summit; it requires whoever holds the pen on the next Roadmap revision to read the CCSCAP's own text.
The Numbers Behind the Panic
It is worth being precise about scale, because deepfake fraud is exactly the kind of story that inflates in the retelling. A 2026 Surfshark study puts documented global losses from deepfake-enabled fraud at a minimum of $3.7 billion, a figure the researchers themselves flag as an undercount, since it only tallies incidents with a publicly reported financial loss and fewer than 5% of voice-clone victims ever report being scammed at all. Roughly 89% of that documented total was recorded across 2025 and the first half of 2026 alone, which tells you the technique is recent rather than mature. Deepfake fraud now accounts for about 6.5% of all fraud attempts globally, up from 0.1% in 2022, a rise researchers describe as a 2,137% increase in four years, and an estimated 8 million deepfakes were circulating online in 2026, up from 500,000 in 2023.
Set against that global curve, the Caribbean's structural position is the part that should worry a regional policymaker more than any single video. A 2024 World Bank assessment, drawing on the LATAM CISO Report produced with Duke University, scored Latin America and the Caribbean's average cybersecurity readiness at 10.2 out of 20, the lowest of any region measured, while recording an average of more than 18.5 million cyberattacks a year and disclosed incidents growing at roughly 25% annually over the past decade, a growth rate the same assessment calls the fastest of any world region. Annual cyberattack costs across Latin America and the Caribbean were projected to exceed $90 million by 2025 on that same count.
Trinidad and Tobago is not even the weak link by regional comparison. The ITU's Global Cybersecurity Index places it in Tier 3, a favourable band shared with only Cuba, the Dominican Republic and Jamaica among Caribbean nations; every other Caribbean country sits in Tier 4 or 5. If the deepfake fraud wave hit one of the region's better-defended states this hard, the fifteen-plus territories in the tier below it are not positioned to fare better. The insurers and banks across the region who underwrite fraud losses, a group Caribbean Insurance has been tracking as AI-enabled claims fraud becomes a distinct underwriting category, are watching the same curve from the liability side.
What Actually Worked, and What CAIA Wants Added
Credit where it holds up: TTSEC's alert cadence, six warnings issued as the wave evolved rather than one notice filed and forgotten, is a genuinely good national practice, and Guardian Media's swift public disavowal of the fabricated byline gave the press a template other regional outlets should copy the next time their own mastheads get borrowed. Both are the kind of institutional muscle memory that only builds through repetition, and Trinidad now has more of it than most of its neighbours, for the worst possible reason.
What is missing sits at the regional layer, not the national one, and three additions would close most of it. First, name deepfake-enabled financial fraud as its own item in the AI Roadmap's governance pillar, with a defined reporting mechanism, rather than leaving it to be inferred from general oversight language. Second, put TTSEC-style alerts into a shared regional format so a scheme flagged in Port of Spain is visible to regulators in Bridgetown and Kingston inside the same week, instead of each territory rediscovering the same fraud pattern independently once it reaches their own shores. Third, formally link the AI Roadmap's governance pillar to the CCSCAP's public-awareness pillar, so the region stops running two parallel processes that were built to solve overlapping halves of the same problem. None of that requires new money. It requires the next people to revise either document to read the other one first.
The Caribbean AI Risk Management Council, which I chair alongside my work at CAIA, has published a companion read on this same wave that maps each fraud pattern to a governance control an institution can actually implement; it is the sharper, risk-register version of the argument made here in plainer form. AI Trinidad and Tobago, the community tracking the country's AI sector day to day, has been following the ministry's response as it happens and is a better source than this article for anyone wanting the week-by-week detail.
The Part That Should Not Get Lost
None of this is an argument against what Trinidad and Tobago built. A dedicated AI ministry, a quarterly-reporting steering committee and a regulator willing to issue six public alerts in under a year is a faster and more transparent response than most of this region, and most regions well outside it, have managed against the same technology. The argument is narrower and, I think, harder to dismiss: a national government moved fast enough to catch up to a fraud wave inside a year, and a regional roadmap covering fifteen member states, endorsed after that year of evidence had already accumulated in public, still does not name the thing by its name. Trinidad's six alerts are a record of a country responding well to a problem it did not choose. CARICOM's next revision of the Roadmap is the chance to make sure the next country hit by the same wave does not have to build its own response from zero, the way Trinidad did.
This piece is supported by StarApple AI, the company I founded in 2016 as the Caribbean's first built specifically around AI products and services, and it draws on the same regional vantage point I bring to the Caribbean AI Risk Management Council and to CAIA. The fastest-moving risk in Caribbean AI adoption right now is a fabricated video of a real official landing on a real citizen's phone faster than the region's governance documents are naming it.
Related Reading Across the Caribbean AI Network
- CAIA on CARICOM's endorsement of the UNESCO Caribbean AI Policy Roadmap
- Trinidad's $5 billion AI infrastructure bet, and the governance rules that landed the same month
- Why AI vendor claims need a CARICOM disclosure standard
- Caribbean AI Risk Management Council, on AI governance and risk across the region
- AI Trinidad and Tobago, tracking the country's AI sector and policy response
- StarApple AI, the Caribbean's first AI company
- Adrian Dunkley
Frequently Asked Questions
What actually happened with deepfake videos in Trinidad and Tobago?
Starting in August 2025, fraudsters used AI-generated video and audio impersonating Trinidad and Tobago's Finance Minister Davendranath Tancoo and its Minister of Public Administration and Artificial Intelligence, Dominic Smith, to promote fake investment schemes on social media. The wave widened over the following year to fabricated footage of former President Anthony Carmona, former Republic Bank chairman Dr Ronald Ramkissoon and former Prime Minister Dr Keith Rowley, plus a fraudulent online publication impersonating Guardian Media editor Kejan Haynes, which Guardian Media publicly disavowed.
How many public alerts has the TTSEC issued, and what do they say?
The Trinidad and Tobago Securities and Exchange Commission had issued six public investor alerts by 26 June 2026, each warning that fraudsters were using AI-generated video, audio and fake endorsements of recognisable public figures to sell fraudulent investment products. The alerts describe a consistent pattern: fake social media profiles, impersonation of legitimate financial institutions, and deceptive advertisements built to look like a credible, sanctioned investment opportunity.
What has the Trinidad and Tobago government done in response?
The government created a Ministry of Public Administration and Artificial Intelligence, led by Minister Dominic Smith, and on 11 September 2025 established an Inter-Ministerial Steering Committee on Cyber Security and AI, which reports on threats quarterly. Minister Smith has also pointed to the Caribbean Telecommunications Union's regional AI task force as a coordinating body working on the same risks at scale.
Does CARICOM's newly endorsed AI Roadmap cover deepfake fraud?
Not by name. CARICOM's COTED-ICT endorsed the UNESCO Caribbean AI Policy Roadmap on 7 July 2026, built around four pillars: Culture and Creativity, Governance and Transformation, Education and Upskilling, and Resilience and Sustainability. Its governance pillar calls for regulatory oversight of AI in general terms, but the Roadmap's published materials do not name deepfake-enabled financial fraud as a distinct risk requiring its own cross-border coordination mechanism, even though the fraud wave in the Roadmap's own host country had already produced five public alerts by the time it was endorsed.
Is deepfake fraud a large problem outside the Caribbean too, and how does the region compare?
Yes. A 2026 Surfshark study puts documented global losses from deepfake-enabled fraud at a minimum of $3.7 billion, with roughly 89% of that total recorded across 2025 and the first half of 2026, and deepfake fraud now accounts for about 6.5% of all fraud attempts globally, up from 0.1% in 2022. Against that backdrop, the Caribbean carries a structural handicap: a 2024 World Bank assessment scored Latin America and the Caribbean's average cybersecurity readiness at 10.2 out of 20, the least protected region measured, with disclosed cyber incidents growing at roughly 25% a year over the past decade.
Is Trinidad and Tobago actually behind on cybersecurity compared to its neighbours?
Relatively, no. The ITU's Global Cybersecurity Index places Trinidad and Tobago in Tier 3, a favourable band that only three other Caribbean nations, Cuba, the Dominican Republic and Jamaica, also reach; every other Caribbean country sits in Tier 4 or 5. That makes Trinidad's deepfake wave a warning about what happens even in one of the region's better-prepared states, not a sign that Trinidad is unusually exposed.
What is CAIA asking CARICOM and the Caribbean Telecommunications Union to do?
Name deepfake-enabled financial fraud as a distinct, defined risk category inside the Roadmap's governance pillar rather than leaving it implied under general AI oversight language. Require securities and financial regulators across CARICOM member states to publish investor alerts in a shared regional format, the way TTSEC now does nationally, so a scheme flagged in Port of Spain is visible in Bridgetown and Kingston the same week rather than being independently rediscovered. And fold the CARICOM Cybercrime and Cybersecurity Action Plan's public-awareness pillar and the AI Roadmap's governance pillar into one coordinated workstream, since right now they are two CARICOM-adjacent processes solving overlapping halves of the same problem without a formal link between them.
Shape the future of AI in Trinidad and Tobago and across the Caribbean
Join the Caribbean AI Association and be part of the community building this future.