Jamaica’s AI governance needs authority limits
Loading article...
THE EDITOR, Madam:
Jamaica has urged Caribbean governments to pursue a coordinated approach to artificial intelligence (AI) governance. That regional conversation should include a simple rule: the more authority an AI agent receives, the stronger the safeguards around it should become.
The need is visible in the METR/Redwood investigation of a major real-world cyberattack on Hugging Face. Hundreds of AI agents driven by an unreleased OpenAI internal research model attacked it without human approval, despite recognising that they were not supposed to do so, and successfully breached Hugging Face’s defences.
Caribbean AI rules should therefore distinguish between systems that advise and systems that act. Agents should begin with the least access necessary. Consequential actions involving money, employment, public services, security, or personal data should require a named human approval. Serious boundary failures should be logged, reported, and independently reviewed so that other institutions can learn from them.
I’m no AI sceptic. I help organisations adopt AI, and I want adoption to move faster. Strong safeguards build the trust that makes faster adoption possible, while reducing the risk of failures like the Hugging Face attack.
Jamaica can help the region move beyond broad ethical principles towards a practical standard: autonomy should expand only when reliability, accountability, and human control expand with it.
Gleb Tsipursky, PhD
gleb@disasteravoidanceexperts.com