AI is building a better Fraud

The Policy Desk · Fraud

A scammer needs about three seconds of your voice. Three seconds. The length of a WhatsApp ‘yeah man, soon reach.’ INTERPOL says financial fraud swallowed US$442 billion globally last year; one study found people could tell real voices from synthetic ones only 37.5 per cent of the time. Trinidad and Tobago has started treating this like a government problem. The rest of the region mostly has a roadmap that says ‘cybersecurity’ and keeps moving.

By the Caribbean AI Newsletter19 August 202610 min read

The dangerous part is not that AI can sound like your mother. It is that Caribbean life already trains us to believe the call: cousin overseas, money needed now, WhatsApp voice note, please don’t tell anybody yet. The best defence is embarrassingly low-tech: a family word the scammer has never heard.

INTERPOL's Global Financial Fraud Threat Assessment, published in March 2026, estimated global financial fraud losses at US$442 billion for 2025 and rated the overall risk as high, with significant escalation projected over the next three to five years.

In the United States, the FBI's Internet Crime Complaint Center annual report released on 6 April 2026 recorded US$20.9 billion in cybercrime losses, a 26 per cent single-year increase. For the first time in the report's 26-year history, the FBI broke out AI-related complaints as a separate crime category, logging more than 22,000 of them.

Neither INTERPOL nor the FBI publishes a Caribbean line, and no CARICOM member state publishes one of its own.

Exhibit 1 · What is counted, and what is not
Two institutions publish a number. The Caribbean publishes none.
INTERPOL covers global financial fraud. The FBI figure covers United States cybercrime across all categories. No CARICOM member state publishes an equivalent series.
$460bn$310bn$155bn0 $442bn$20.9bnnotcounted Global fraudUS cybercrimeCaribbean INTERPOL, 2025FBI IC3, 2025no series exists A crime with no measured cost cannot be ranked against crimes that have one

Sources: INTERPOL Global Financial Fraud Threat Assessment, March 2026; FBI Internet Crime Complaint Center Annual Report, 6 April 2026.

Why this scam fits the Caribbean a little too well

The technology is imported. The social engineering fits us locally.

Start with the diaspora. In plenty of Caribbean families, ‘I’m abroad and I need you to send money’ is not a red flag. It is Tuesday. A scam script that sounds absurd in a household with nobody overseas can sound completely ordinary in ours.

Then there is WhatsApp, the Caribbean’s unofficial operating system. We have spent years donating clean voice samples to family groups, work groups, school groups and the group somebody made for one funeral in 2019 that is somehow still active. One voice note is more audio than a modern clone needs.

And we are small. A fraud wave that gets a dedicated unit in a large country can become three people’s additional duties here. The scam scales like software. The regulator does not.

Trinidad and Tobago is the only country behaving like this is already here

Trinidad and Tobago established the Caribbean's first cabinet-level AI ministry, the Ministry of Public Administration and Artificial Intelligence under Minister Dominic Smith. On 11 September 2025 Cabinet approved an Inter-Ministerial Steering Committee on Cyber Security and AI, tasked with coordinating national policy and reporting quarterly on threats.

The Trinidad and Tobago Securities and Exchange Commission has issued six public investor alerts about investment scams and fake AI endorsements, the most recent on 26 June 2026. Deepfake content impersonating the country's finance minister circulated in 2025 and prompted an official investigation.

None of this is glamorous. That is the point. A ministry, a committee that has to report back, and a regulator that keeps warning people is what boring competence looks like.

Unfortunately, WhatsApp has no immigration desk at Piarco

A deepfake of a Trinidadian public figure reaches Jamaica, Barbados, Guyana or Antigua by WhatsApp in minutes, and none of those four has an equivalent cabinet-level AI ministry to respond with.

CARICOM's Council for Trade and Economic Development endorsed the UNESCO-supported Caribbean AI Policy Roadmap on 7 July 2026, which is a genuine step and gives the region an agreed framework. None of its language names deepfake fraud, investment scams or AI-enabled financial crime as a distinct item, and it does not create a binding cross-border enforcement mechanism for them.

So we have managed the very Caribbean trick of agreeing on the framework before agreeing on what happens when somebody clones your son’s voice and asks for $4,000 by Friday.

Exhibit 2 · What the numbers say
The measured global picture, and the Caribbean line that does not exist
MeasureFigureSource
Global financial fraud losses, 2025US$442 billionINTERPOL Global Financial Fraud Threat Assessment, March 2026
United States cybercrime losses, 2025US$20.9 billion, up 26%FBI IC3 Annual Report, 6 April 2026
AI-related complaints, first year reportedMore than 22,000FBI IC3, first separate category in 26 years
Audio needed to clone a voiceAbout three secondsPublished 2026 technical reporting on zero-shot voice models
Human accuracy distinguishing real from cloned voices37.5%Academic study of voice-cloning detection
TTSEC public investor alerts issuedSix, latest 26 June 2026Trinidad and Tobago Securities and Exchange Commission
Caribbean AI fraud lossesNot publishedNo regional series exists

The final row is the operative one. Without a regional loss series, no CARICOM government can size this against its other crime priorities, and no regional insurer can price it.

Forget the deepfake detector. Pick a family word.

The useful defences are almost offensively simple. No app. No dashboard. No ‘AI-powered fraud shield.’ Just habits that force the caller to prove something a stolen voice cannot prove.

Protection
Six things to put in place this week

Agree a family verification word

Pick a word or phrase that is not guessable from social media, share it in person or by a channel you already trust, and use it before any transfer requested by voice. This is the single most effective defence available and it costs nothing. A cloned voice cannot produce a word it has never heard.

Hang up and call back on a known number

Not the number that called, and not a number given during the call. A caller who resists this is telling you something. This one habit defeats most voice fraud regardless of how good the clone is.

Treat urgency and secrecy as the signal

The technology is new and the manipulation is old: pressure to act immediately, instruction not to tell anyone else, a narrow window. Every AI voice scam reported to date has relied on at least two of those three, because a victim who slows down verifies.

For businesses, require two-channel authorization

No payment above a set threshold moves on a voice instruction alone. Confirmation must arrive through a second channel initiated by your staff. Corporate deepfake losses reported internationally have run into millions on single incidents, and the failure is always process rather than technology.

Brief the people who handle money, not just IT

Finance officers, bursars, church treasurers and credit union clerks are the targets. Security awareness training that reaches only technical staff misses everyone who can actually move funds.

Report it even when the money is gone

Caribbean fraud statistics are thin partly because reporting is thin. Every unreported incident keeps the regional number at zero and keeps the problem off the policy agenda. Report to your national police cybercrime unit and to your financial regulator.

Three boring things the regional roadmap should add

The regional AI roadmap is useful. It also has a hole exactly where ordinary people are most likely to meet AI: getting robbed with it. That is fixable without another summit.

Name AI-enabled financial crime as a distinct category with its own measures, rather than leaving it inside general cybersecurity language. Establish a shared cross-border alert mechanism so a TTSEC warning reaches Jamaican and Guyanese consumers within hours rather than through news coverage. And require a regional loss series, because a crime nobody counts cannot be prioritized against the crimes that are counted.

The pipeline
How a cloned call is built, and the one thing that stops it
Every stage above is cheap and fast. The defence on the lower row costs nothing and does not depend on detecting anything.
HOW THE CALL GETS MADE Your voice note posted to a group 3 sec is enough Cloning model Call WHERE IT STOPS Your agreed family word never posted anywhere, asked before any transfer A clone cannot produce a word it has never heard

Illustration by the Caribbean AI Newsletter. Three-second sampling follows published 2026 reporting on zero-shot voice models.

Frequently asked questions

About three seconds of publicly available audio, on 2026 technical reporting. That can come from a social media clip, a podcast appearance, a voicemail greeting or a WhatsApp voice note. Modern zero-shot models are trained on thousands of speakers in advance and skip per-person fine-tuning entirely, which is why the sample requirement has fallen so far so quickly.
Probably not, and you should plan on that basis. In one academic study, participants correctly identified whether voices were real or synthetic only 37.5 per cent of the time, meaning most AI voices were taken for human. This is why the effective defences are procedural rather than perceptual: a pre-agreed verification word, and hanging up to call back on a number you already have.
A verification word agreed in advance, shared in person or through a channel you already trust, and not guessable from anyone's social media. Use it before sending money in response to any urgent voice request. A cloned voice can reproduce how a relative sounds; it cannot produce a word it has never encountered. Pair that with a rule that you always hang up and call back on a known number.
Trinidad and Tobago has gone furthest. It established the region's first cabinet-level AI ministry under Minister Dominic Smith, Cabinet approved an Inter-Ministerial Steering Committee on Cyber Security and AI on 11 September 2025 with quarterly threat reporting, and the TTSEC has issued six public investor alerts, most recently on 26 June 2026. CARICOM endorsed the UNESCO-supported Caribbean AI Policy Roadmap on 7 July 2026, though its language does not name deepfake fraud or AI-enabled financial crime as a distinct item.
Nobody knows, because no regional loss series exists. INTERPOL put global financial fraud losses at US$442 billion for 2025 and the FBI recorded US$20.9 billion in United States cybercrime losses, but neither publishes a Caribbean figure. This matters practically: a crime with no measured cost cannot be ranked against the crimes that have one, which is how it stays off budget lines and out of policy documents.
Require two-channel authorization for any payment above a threshold you set, where the second confirmation is initiated by your own staff rather than by the caller. Brief the people who can actually move money, which means finance officers, bursars and clerks rather than only IT staff. International corporate deepfake losses have run into millions on single incidents, and in reported cases the failure has consistently been an absent process rather than a technical one.
Because an unexpected call about an urgent money transfer is a normal event in a household with relatives abroad rather than an obviously suspicious one. The emergency-relative script depends on the target finding the premise plausible, and across much of this region it is not merely plausible but routine. The same structure that supports Caribbean households through remittances is what makes the script land.
INTERPOL has a number. The FBI has a number. The Caribbean has vibes. That is how a crime can be everywhere in people’s WhatsApp groups and nowhere in a budget document.
Caribbean AI Newsletter · The Policy Desk, 19 August 2026
🌴
About the Caribbean AI Newsletter

The Caribbean AI Newsletter is the leading daily source for artificial intelligence news, analysis, and practical insight for the Caribbean. The newsletter covers policy, workforce, education, cybersecurity, climate resilience, governance, language and cultural data, and the founders building the region's AI sector.

JamaicaTrinidad and TobagoBarbadosGuyanaThe BahamasSaint LuciaGrenadaSaint Vincent and the GrenadinesAntigua and BarbudaDominicaBelizeSurinameHaitiDominican RepublicCuracaoAruba
Visit the Directory
Previous
Previous

AI cheating in schools is real; did we have to kill the SBA?

Next
Next

Is AI Diluting Patois and Creole?