Turks and Caicos Islands

Turks and Caicos Islands

Law Over Borders Comparative Guide: Artificial Intelligence Law Guide

29 Sep 2026
Artificial Intelligence Law Guide Artificial Intelligence Law Guide

The Turks and Caicos Islands is a small, common law, British Overseas Territory jurisdiction. Artificial intelligence (AI) adoption is still at an early but active stage. The most visible use is in professional services, court preparation, financial services, hospitality, marketing, education, government administration, real estate support, translation, document review and customer service. There is no large domestic AI development industry. The market is mainly an adopter market, not a model-builder market.

Local businesses are using general-purpose AI tools for drafting, research, workflow, summaries and client engagement. Law firms, accounting firms, tourism operators and small businesses are testing AI to improve speed and reduce cost. The key practical risks are familiar: confidentiality, accuracy, hallucinated legal authorities, intellectual property, data transfers, cyber risk, bias and over-reliance by non-specialists.

The Turks and Caicos Islands (TCI) does not yet have a standalone AI Act. However, currently its most important AI-specific instrument is Practice Direction No. 1 of 2025, A Guide to the Use of Generative AI in Court Proceedings. It was issued by the Chief Justice under section 17 of the Supreme Court Act and section 3 of the Chief Justice (Responsibilities) Act. It commenced on 4 August 2025 and applies to all proceedings in all courts in TCI. It is the clearest statement of TCI public policy on AI: AI may be used, but the human user remains accountable.

The wider legal framework is built from existing law: the Constitution, confidentiality law, professional obligations, intellectual property law, electronic transactions law, consumer protection, sectoral regulation and common law duties. The likely next stage is not a single broad AI statute immediately. The more likely path is targeted regulation in courts, public administration, privacy, financial services, procurement, education and cybersecurity.

AI in TCI is assessed first through constitutional values: fairness, equality, privacy, protection of law, lawful administrative action and freedom of expression. These rights are technology-neutral. They apply whether a decision is made manually, with software, or with AI assistance.

The Turks and Caicos Islands Constitution Order 2011, as amended, is the starting point. It protects fundamental rights and freedoms, including protection of law, equality before the law, privacy of home and correspondence, freedom of expression, protection from discrimination, peaceful enjoyment of property, protection of the environment and lawful administrative action.

Practical implications for AI are:

  • Government bodies using AI should keep a human decision-maker responsible for the decision.
  • AI-supported decisions should be explainable enough for the affected person to understand the case against them.
  • Public bodies should avoid secret scoring systems that affect rights, permits, benefits, education or enforcement without procedural safeguards.
  • AI should not be used in a way that produces discriminatory outcomes or prevents effective appeal or review.

Practice Direction No. 1 of 2025 reflects these constitutional values in the court context. It states that courts will ensure AI use does not undermine the right to a fair hearing before an impartial tribunal, verify AI-generated outputs, and disclose AI use in decision-making.

There is currently no locally reported legal case that specifically addresses AI and human rights. However, in AI and related matters, TCI courts are likely to draw on the Constitution, common law fairness principles, local human rights legislation and persuasive Commonwealth and European human rights jurisprudence where relevant. The most relevant themes are likely to be fair trial rights, privacy, freedom of expression, non-discrimination, lawful administrative action and effective remedies.

In practice, an AI system used by a public authority should be tested against five questions:

  • Is there lawful authority for using it?
  • Is the affected person told, where fairness requires it?
  • Can the decision be explained?
  • Has discriminatory impact been assessed?
  • Is there a meaningful human review or appeal route?

TCI has no AI-specific intellectual property legislation. Existing intellectual property principles apply. The most important practical issues are ownership of AI-assisted outputs, use of copyright works for training, confidentiality of prompts, and trade mark misuse in AI-generated marketing.

TCI patent law is based on the Patents Act. There is no known TCI rule recognising an AI system as an inventor. The prudent position is that an inventor should be a natural person, and any applicant should identify the human contribution to the inventive concept.

For AI-assisted inventions, clients should keep records showing:

  • the human problem identified;
  • the prompts or technical method used;
  • the human evaluation of outputs;
  • the final inventive step selected by a human; and
  • any assignment from the individual inventor to the company.

No TCI case has yet tested whether an invention generated substantially by AI is patentable.

Copyright protection in TCI is derived from UK copyright law as extended to the territory. There is no AI-specific statutory rule on whether purely machine-generated output is protected, who owns it, or whether training on copyright works is permitted.

Practical guidance:

  • Treat AI outputs as potentially unprotected unless there is meaningful human authorship.
  • Do not assume that paying for an AI tool gives ownership of the output.
  • Check the tool terms carefully.
  • Do not input third-party copyright material for training or adaptation unless the client has rights to do so.
  • Keep records of human editing and selection, especially for commercial creative work.

For legal work, the Practice Direction also warns that generative AI (GenAI) outputs may be in breach of copyright. That is a direct local warning to lawyers and court users.

Confidentiality is a major AI risk in TCI. The Confidential Relationships Act is central. It protects confidential information and creates criminal exposure for unauthorised disclosure by persons who possess confidential information in circumstances where another person is not entitled to receive it.

The common law of breach of confidence and professional duties also remain important. For lawyers, the duty of confidentiality is not reduced because a tool is convenient or widely used.

The court Practice Direction gives the clearest practical rule: court users shall not input privileged or sensitive information into unsecured AI platforms. It states that sensitive material and information to which professional privilege may attach may not be inputted by court users in a public chatbot. It encourages enterprise-grade platforms offering secure data environments.

Best practice in TCI is:

  • use enterprise or closed environments where possible;
  • disable training on client data where available;
  • avoid public chatbots for privileged information;
  • redact personal and confidential information before using AI; and
  • include AI confidentiality provisions in client engagement terms, vendor contracts and staff policies.

Currently, there does not appear to be any reported TCI cases on AI and patents, copyright, trade secrets or database rights. The likely first disputes will be commercial rather than constitutional: unauthorised use of photographs, resort marketing content, architectural images, music, brand assets, confidential business plans or legal documents in AI tools.

In the absence of local AI cases, TCI courts are likely to look to English and Commonwealth authority, adapted to local statutes and common law.

TCI does not currently have a comprehensive, GDPR-style data protection regime in force. Data protection issues are therefore managed through constitutional privacy rights, confidentiality law, sector-specific secrecy obligations, contract and common law duties. This is a gap for AI deployment.

TCI does not currently have a single domestic data protection law governing all personal data processing. The Constitution protects private and family life, home and correspondence. The Confidential Relationships Act protects confidential information. The Electronic Transactions Act allows regulations to be made on personal data processing in connection with electronic transactions, but comprehensive regulations have not been implemented.

For AI training, this means there is no local statutory text that expressly permits or prohibits training on personal data. The practical answer is risk-based:

  • obtain consent or contractual authority where possible;
  • avoid training on sensitive personal data unless clearly justified and protected;
  • anonymise or aggregate data before use;
  • do not upload confidential client or employee data to public tools; and
  • check whether foreign privacy laws apply, especially GDPR, UK GDPR, US state privacy law or sector rules where the data subjects, vendors or servers are overseas.

TCI has no local GDPR-style regime, no general data protection authority, no general data protection officer (DPO) appointment obligation, no general DPIA obligation and no general statutory breach-notification regime. That does not mean there is no risk.

Organisations still face:

  • constitutional privacy duties in public-sector contexts;
  • confidentiality duties under the Confidential Relationships Act;
  • sectoral confidentiality duties in financial services, health, telecoms and public bodies;
  • contract liability;
  • negligence and breach of confidence claims; and
  • overseas privacy law exposure where operations are cross-border.

The absence of a comprehensive statute is one reason AI governance policies should be written contractually, operationally and ethically, rather than waiting for a regulator.

TCI has no broad open data statute. Public information is made available through government websites, the Gazette, court resources, legislation databases and public registries, but access is fragmented.

For AI projects using public-sector data, the key checks are:

  • Is the data truly public, or only accessible for a limited purpose?
  • Are there licence terms or copyright restrictions?
  • Does the dataset contain personal or confidential information?
  • Could combining datasets re-identify individuals?
  • Is the use consistent with the purpose for which the information was collected?

Public authorities should use written data-sharing agreements for AI projects. Those agreements should address purpose, retention, security, audit rights, vendor access, cross-border transfer, publication and deletion at the end of the project.

TCI has no biometric-specific AI law. Voice data, facial images, facial templates and other biometric identifiers should be treated as high-risk personal information, particularly when used for identification, surveillance, security, employment, education, immigration, policing or access control.

Recommended safeguards:

  • use clear notices and consent where appropriate;
  • perform a privacy and human rights impact assessment;
  • limit retention;
  • secure templates separately from ordinary files;
  • prohibit secondary use without approval;
  • maintain human review for adverse decisions; and
  • test for demographic bias.

For law enforcement or border use, lawful authority, necessity, proportionality and auditability are essential.

Bias is primarily managed through constitutional equality and non-discrimination principles, employment law, human rights oversight and common law fairness. There is no AI-specific anti-bias statute.

The Constitution protects equality before the law and protection from discrimination. It prohibits discrimination on grounds including race, national or social origin, political or other opinion, colour, religion, language, creed, association with a national minority, property, sex, sexual orientation, birth or other status.

AI systems can create discrimination even when no one intends it. Examples include biased recruitment screening, credit scoring, customer segmentation, policing tools, education allocation or immigration triage.

Practical TCI compliance steps:

  • identify protected characteristics that may be affected;
  • test outputs before deployment;
  • keep human review for adverse outcomes;
  • document the reason for using the AI system;
  • avoid black-box systems for rights-sensitive decisions; and
  • create a complaint and correction process.

Where a public authority uses AI, lawful administrative action and constitutional equality will be central to any challenge.

AI increases cyber risk. It can assist phishing, impersonation, malware development, fraud and data exfiltration. It can also improve monitoring, anomaly detection and incident response. TCI regulation is still sector-led rather than AI-led.

TCI does not have a general AI infrastructure statute. Cybersecurity obligations arise from sectoral regulation, contracts, confidentiality duties, public-sector controls, financial services expectations and general criminal law. The Cyber (Sanctions) (Overseas Territories) regime also extends cyber sanctions measures to British Overseas Territories, including TCI.

For critical or regulated AI systems, organisations should adopt minimum controls:

  • access control and multi-factor authentication;
  • encryption in transit and at rest;
  • logging of AI inputs and outputs;
  • vendor security due diligence;
  • incident response plans;
  • employee training on deepfakes and phishing;
  • backup and business continuity planning; and
  • prohibition on uploading credentials, client secrets or government data into public AI tools.

For legal practice, the Practice Direction expressly warns that public GenAI systems may lack confidentiality safeguards.

There is no general AI competition statute in TCI. Competition concerns are most developed in telecommunications and consumer protection. General common law restraint of trade principles may also be relevant.

There are no TCI AI cases on algorithmic collusion, dark patterns or platform self-preferencing. However, the risks are real, particularly in tourism, transport, real estate, hospitality, telecoms and online services.

Examples that could become relevant:

  • competitors using common pricing software that produces coordinated prices;
  • AI systems monitoring rivals and automatically matching prices;
  • dark patterns that mislead consumers online;
  • AI-generated false reviews;
  • discriminatory pricing that is not disclosed; or
  • exclusionary access to key digital infrastructure or data.

The safest practical approach is to treat AI pricing tools as competition sensitive. Businesses should not share non-public pricing, occupancy, customer or bidding data with competitors through a common AI vendor unless carefully reviewed.

TCI does not have a broad economy-wide competition act equivalent to the UK Competition Act. There are, however, sectoral and consumer-facing controls.

Telecommunications is the clearest sector. The Telecommunications Commission has issued Telecommunications Competition Guidelines and has powers under telecommunications legislation and licences to address dominance, interconnection, retail pricing and anti-competitive conduct by licensees.

Consumer-facing AI may also fall under the Consumer Protection Act 2016, as amended in 2019. The Government describes that Act as covering consumer safety, duties of providers, misleading and deceptive conduct, false representation, unfair business practices, enforcement mechanisms and the Consumer Protection Appeal Tribunal.

For AI systems used in consumer sales, the practical rule is simple: do not use AI to mislead customers, conceal material terms, fabricate reviews or create unfair pressure.

Agentic AI is not separately regulated in TCI. Existing agency, contract, tort, professional responsibility and sectoral rules apply. The key point is that AI has no legal personality.

TCI law does not recognise an AI agent as a legal person. An AI system cannot own property, sue, be sued, hold office, be admitted to practise law, give evidence as a witness, or enter contracts in its own right.

An AI tool may act as software used by a human, company or public body. Legal responsibility remains with the person or entity deploying it. If an AI bot negotiates or accepts terms online, the legal question will be whether the human or company authorised that process under ordinary contract and agency principles.

Practical drafting points:

  • state whether automated acceptance is binding;
  • set transaction limits;
  • require human approval for high-value or unusual transactions;
  • log instructions and outputs;
  • allocate risk for AI error in contracts; and
  • disclose chatbot use where customers may think they are dealing with a human.

There are no TCI sector-specific rules aimed only at autonomous AI agents in financial services, healthcare, transport or defence. Existing sector laws and licences still apply.

Examples:

  • Financial services firms should treat agentic AI as an outsourced or technology risk, with governance, records, supervision and confidentiality controls.
  • Healthcare providers should not allow AI to replace professional clinical judgment.
  • Legal professionals cannot delegate professional responsibility to AI. The Practice Direction states: “AI use does not absolve the author of ethical or professional obligations.”
  • Transportation, aviation and maritime users should consider licensing, safety and insurance obligations before deploying autonomous systems.

At present, no TCI regulator has issued a comprehensive agentic AI rulebook.

There is no AI-specific product liability regime. Existing consumer, contract, negligence, sale of goods, unfair contract terms and professional negligence principles apply. The practical issue is whether the AI is supplied as a product, service, software tool or professional advice component.

AI can be treated differently depending on how it is supplied. A physical device with embedded AI, such as a security camera, vehicle feature or medical device, is likely to be analysed as goods plus software. A chatbot or document review platform is more likely to be analysed as a service or software subscription.

Relevant TCI principles may include:

  • contractual warranties and exclusions;
  • implied terms under sale of goods principles;
  • consumer protection rules against misleading or unfair practices;
  • negligence where a duty of care exists;
  • professional negligence where AI is used in professional services; and
  • confidentiality and privacy claims if data is mishandled.

Vendors should be clear about intended use, limitations, required human oversight, update obligations and prohibited uses.

TCI has no AI-specific strict liability regime. Strict liability may arise only under existing legal categories, for example particular statutory duties, inherently dangerous activities, or established common law rules. Most AI harms will be assessed through contract, negligence, misrepresentation, consumer protection or professional duty.

The absence of strict liability does not mean low risk. A court may find negligence where a supplier or user deploys a high-risk AI system without testing, warnings, monitoring, human oversight or a reasonable incident response process.

There is no AI-specific recall regime. For AI-enabled goods or consumer services, recall and safety obligations should be considered under consumer protection, contract, sector-specific licensing and general duties to avoid foreseeable harm.

Practical steps when a defect or risk is discovered:

  • suspend the affected function where necessary;
  • notify affected customers or users;
  • issue patches or updates;
  • preserve logs and evidence;
  • notify insurers and regulators where required;
  • provide a workaround or refund where appropriate; and
  • review whether the defect created data breach, safety or discrimination issues.

For court documents, the Practice Direction provides specific sanctions for misuse: the court may strike out submissions, refuse improperly verified or undisclosed documents, and impose costs for non-compliance.

There do not appear to be any leading reported TCI AI product liability cases. The likely first claims will involve:

  • hallucinated legal or professional advice;
  • negligent use of AI by professionals;
  • data leakage through public AI tools;
  • AI-generated defamatory or misleading content;
  • unfair consumer practices using automated sales tools; and
  • discrimination in employment, lending or access to services.

TCI courts are likely to be influenced by English and Commonwealth decisions, particularly where local statutes are similar or where the issue is common law negligence, confidence, contract or professional discipline.

The main domestic AI development is judicial, not legislative. Practice Direction No. 1 of 2025 is a significant first step because it regulates AI in all TCI courts and sets standards of accountability, verification, disclosure, confidentiality and sanctions.

TCI has not enacted a standalone AI Act. The enacted AI-specific instrument is Practice Direction No. 1 of 2025, A Guide to the Use of Generative AI in Court Proceedings. It was issued on 14 July 2025 and commenced on 4 August 2025.

Key features:

  • applies to all proceedings in all courts in TCI;
  • applies to closed-source and open-source GenAI models;
  • defines GenAI, hallucination, LLMs and enterprise-grade AI;
  • permits AI for drafting, summaries, procedural documents, legal research and skeleton arguments, subject to disclosure and verification;
  • prohibits GenAI in affidavits, witness statements and evidentiary material produced from personal recollection;
  • requires leave for AI use in annexures to affidavits or witness statements and expert reports;
  • requires disclosure where GenAI is used in documents;
  • requires verification of legal authorities from official sources such as TCILII, court websites or recognised legal databases; and
  • provides sanctions for non-disclosure or failure to verify.

The core local standard is captured by three short rules: disclose, verify and remain accountable.

There is no published whole-of-government AI strategy for TCI comparable to national AI strategies in larger jurisdictions. AI policy is emerging through sector practice, court guidance, public-sector digitalisation and professional adoption.

Likely next steps for TCI should include:

  • a public-sector AI use policy;
  • procurement rules for AI vendors;
  • a data protection statute;
  • cybersecurity minimum standards;
  • AI guidance for schools and public officers;
  • guidance for high-risk decisions in immigration, policing, benefits, education and health; and
  • professional training for lawyers, judges, regulators and public administrators.

TCI should avoid over-regulating low-risk use. It should focus first on high-impact AI that affects rights, money, liberty, public services, children, health, employment, immigration or access to justice.

1. Can we use ChatGPT or another AI tool for business work in TCI?

Yes, but do not use it casually for confidential, privileged or sensitive information. Use enterprise-grade tools where possible. Check the vendor terms. Train staff. Keep human review. Do not let AI produce final legal, financial, medical or public-facing content without verification.

2. Can lawyers use AI for court work?

Yes. Practice Direction No. 1 of 2025 permits GenAI for tasks such as drafting documents, summarising information, legal research and skeleton arguments. But use must be disclosed where required, legal authorities must be verified, and the lawyer remains responsible. GenAI must not be used for affidavits, witness statements or evidentiary material based on personal recollection. Expert report use requires prior leave.

3. Can we put client information into a public AI chatbot?

Usually no. The safer answer is no unless the information is anonymised, non-sensitive and authorised. The Practice Direction says court users shall not input privileged or sensitive information into unsecured AI platforms and that privileged information may not be inputted into a public chatbot.

4. Can an AI agent bind my company to a contract?

The AI agent has no legal personality. But your company may still be bound if it authorised the automated process. Use clear limits. Require human approval for high-value transactions. Keep logs. Tell customers when they are dealing with a bot. Put AI allocation clauses in customer and vendor contracts.

5. Who is liable if AI gives a wrong answer or causes loss?

Usually the human user, company, professional adviser or vendor, depending on the facts and contract. TCI has no AI-specific liability statute. Liability will be assessed through contract, negligence, consumer protection, confidentiality, professional discipline or sector rules. The best protection is governance: approved tools, human review, testing, warnings, logs, incident response and insurance.