Most boards in the Islands have approved an AI policy. Far fewer have seen an AI inventory. The gap between them is where the risk sits, because AI arrives through three doors at once: tools staff adopt themselves, features switched on by default in software you licence, and AI deployed by outsourced providers whose regulatory risk still rests with you.
The local regulatory position has moved decisively in twelve months.
The direction of travel is identical in each: No separate AI rulebook, existing obligations applied to AI and an expectation that you can evidence how. Groups with UK or Cayman entities will see the same pattern.
The exposure here is rarely an exotic model behaving unpredictably. It is ordinary people using ordinary tools with no control around them.
You own the output. In Ayinde v London Borough of Haringey [2025] EWHC 1383 (Admin), fictitious authorities were put before the High Court and those responsible referred to their regulators; dozens of similar UK cases have followed. Substitute “regulatory filing” or “trustee minute” for “court submission” and it lands on a Jersey trust company.
Confidentiality is lost at ‘the moment of paste’. In [2026] UKUT 81 (IAC), the Upper Tribunal held that uploading confidential documents into a public AI tool placed that information in the public domain, breaching confidentiality and waiving privilege and noted the risk is not confined to lawyers. For businesses built on fiduciary duty, there is no remedy after the fact.
AI is used against you, too. In 2024 the consultancy Arup confirmed a loss of around US$25.6m after an employee made 15 transfers following a video call on which every other participant was a deepfake. Voice cloning now bears directly on client verification and payment authorisation.
You cannot govern what you have not counted.
Shadow AI, default-on vendor features and AI inside outsourced processes are where a first inventory produces the biggest surprises.
Underneath all four sits one gap. Almost every organisation can produce a policy. Very few can produce the inventory, risk assessments, approvals, human-oversight records, testing results and monitoring evidence a supervisor or a client’s auditor will ask to see.
There is more than one credible route, and the choice is a board decision, not a technical one.

Four things make ISO/IEC 42001 the right answer for most organisations here.


ISO/IEC 42001 is not a harmonised standard under the EU AI Act and confers no presumption of conformity.
Certification evidences that a management system works. It does not certify the output of any model. Treat it as assurance, not immunity.
Only a few hundred organisations worldwide are thought to have held certificates by spring 2026. In jurisdictions competing on trust and regulatory credibility, that is a real differentiator and a short-lived one.
ISO/IEC 42001 is a ‘plan–do–check–act’ management system for AI: scope, accountability, risk and impact assessment, controls, competence, lifecycle operation, monitoring, internal audit and continual improvement. A typical route runs six to twelve months:
AI adoption will keep accelerating, and the Islands are right to encourage it. But the organisations that benefit most will be those that can show their work to a regulator, to a client running due diligence and to their own audit committee.
A focused readiness assessment is the sensible first step: What AI you run, what is material, where the gaps are and a proportionate roadmap.

Most boards start with a readiness assessment: What AI you’re running, what’s material, and where the gaps are. From there we support AI inventories and materiality models; policy and committee terms of reference, impact assessments, vendor AI risk reviews, control design and assurance mapping' board reporting, ISO/IEC 42001 readiness and board training.

Arthur Mainja