AI Governance
46 Million Attacks, Yet Only 30% AI Awareness: Why Jamaica's Leadership Risk Is Growing Faster Than Its Laws
Jamaica's rising cyberattack volume, limited public AI awareness, and accelerating regulatory enforcement are creating a leadership-level governance risk for organizations handling sensitive information.

The risk is already inside the organization.
Jamaica recorded approximately 46 million cyberattack attempts during 2025, while research conducted by The University of the West Indies found that only 30 per cent of Jamaicans can identify AI-generated misinformation and deepfakes. Individually, these figures are alarming. Together, they expose a growing leadership problem that extends far beyond technology departments.
Artificial intelligence is entering workplaces, cyber threats continue to increase, and organisations are collecting larger volumes of sensitive information, yet governance, oversight, and accountability continue to lag.
During the 2026 Sectoral Debate, Minister with responsibility for Science, Technology and Special Projects, Dr. Andrew Wheatley, acknowledged that government entities have already begun using artificial intelligence tools without a coordinated policy framework. His warning was not directed solely at government. It reflects a challenge facing banks, healthcare providers, business process outsourcing firms, professional services companies, and every organization handling sensitive information.
"The problem is that AI use is outpacing understanding. It is outpacing oversight, it is outpacing accountability. And in the context of government where public servants handle sensitive personal data, confidential State information, and records that belong to the Jamaican people, that gap is a risk we cannot afford to ignore."
Jamaica is now moving toward full enforcement of the Data Protection Act, shifting the Office of the Information Commissioner from public education toward investigation and enforcement. For executive leadership, this changes data protection from a compliance exercise into a measurable financial risk.
Under the Data Protection Act, organisations that fail to comply with their obligations may face penalties of up to J$4 million per offence, while certain offences may also result in imprisonment. However, regulatory penalties represent only a small portion of the financial exposure.
A serious data incident often triggers external forensic investigations, legal representation, customer notification programmes, public relations support, technology remediation projects, compliance reviews, and independent security assessments. For medium and large organizations, these costs can easily exceed tens of millions of dollars. The Jamaica Stock Exchange and National Health Fund incidents have demonstrated that the financial consequences of a breach extend well beyond the technical recovery itself.
The cost of rebuilding trust can be even greater. Customers may hesitate to share information, investors may question governance practices, and international partners may reassess their relationships. For Jamaica's financial services, BPO, healthcare, and professional services sectors, reputation is an economic asset. Once damaged, it is often far more expensive to restore than it was to protect.
Many executives continue to view upcoming legislation as the beginning of their obligations. In reality, the risks already exist. Employees are using AI tools to draft reports, summarize meetings, analyze documents, and process information. Sensitive data is increasingly moving through systems that organizations may not fully understand, while cyber threats continue to increase and public awareness remains limited.
The most important question facing leadership is not whether new laws will arrive. Jamaica's regulatory environment is clearly moving toward stronger enforcement, greater accountability, and increased oversight. The real question is whether organizations currently possess the visibility necessary to identify their own risks before regulators, customers, or the public identify them first.
Reference source
https://jis.gov.jm/