Legal

Acceptable Use & Agentic AI

Effective Date: 25 September 2026

This Platform Acceptable Use & Agentic AI Safety Policy (”Policy”) sets out the standards that apply to the use of the Future Caribbean Platform and to the development, demonstration and use of agentic artificial-intelligence systems through Future Caribbean programmes.

It forms part of the Future Caribbean General Website & Platform Terms of Use and, where applicable, the Future Caribbean Buildathon Official Rules.

1. Our Approach

Future Caribbean supports responsible experimentation and innovation in artificial intelligence, including agentic AI systems.

We recognise that AI systems can provide significant benefits while also creating risks, particularly where systems can act autonomously, access external systems, make decisions, handle personal information or affect other people.

Our approach is therefore risk-based.

Participants are expected to consider the reasonably foreseeable consequences of their systems and to apply safeguards proportionate to those risks.

2. What Is an Agentic AI System?

For this Policy, an agentic AI system means an AI-enabled system capable of taking actions, making or recommending decisions, using tools, interacting with external systems or pursuing a defined objective with a degree of autonomy.

This may include systems that:

call APIs or other software tools;

access or modify data;

communicate with users or third parties;

execute transactions or workflows;

operate software or digital environments; or

take actions without requiring a human to approve every individual step.

The Policy applies whether the system is developed independently or uses third-party models, APIs or other AI services.

3. General Requirements

When developing or using an agentic AI system through Future Caribbean, you must:

comply with applicable law;

respect the rights and privacy of other people;

use data only where you have an appropriate right or lawful basis to do so;

take reasonable steps to secure credentials, APIs and connected systems;

test the system before demonstrating or deploying it;

consider foreseeable misuse and failure modes;

maintain appropriate human oversight;

avoid representing an AI system as a human where doing so would materially mislead another person; and

promptly address serious safety or security issues that you discover.

Participants remain responsible for their systems, including actions taken by an AI agent operating under their control.

4. Prohibited Uses

Future Caribbean does not permit the development or use of its Platform or programmes to knowingly facilitate:

Fraud and financial crime

Systems designed to commit or materially facilitate:

fraud;

theft;

money laundering;

sanctions evasion;

financial deception; or

unauthorised access to financial accounts.

Malware and cyber abuse

Systems designed to:

deploy malware;

steal credentials;

compromise systems without authorisation;

conduct unauthorised exploitation;

evade security controls for malicious purposes; or

disrupt or damage computer systems or networks.

Security research and testing may be permitted where the participant has appropriate authorisation and the activity is conducted within a controlled environment.

Weapons

Systems designed to facilitate the unlawful acquisition, construction, targeting or deployment of weapons.

Sexual exploitation

Systems involving:

sexual exploitation of children;

non-consensual sexual content;

sexual extortion; or

other unlawful sexual exploitation.

Unauthorised surveillance

Systems designed to conduct surveillance, tracking or monitoring of people without appropriate authorisation or lawful basis.

Impersonation and deception

Systems intended to materially deceive people by impersonating another person or organisation, particularly where the deception is intended to cause financial, legal or other significant harm.

This does not prohibit clearly identified fictional, entertainment or experimental systems.

Unlawful personal-data collection

Systems designed to collect, infer, scrape or process personal information in a manner that violates applicable law or another person’s reasonable privacy rights.

Circumvention

Systems designed to circumvent legal, technical or security restrictions for unlawful purposes.

5. High-Risk Systems

Some legitimate projects may present elevated risks because of the context in which they operate.

Examples include systems involving:

financial transactions or financial decision-making;

healthcare or medical decisions;

employment or recruitment decisions;

access to essential services;

critical infrastructure;

highly sensitive personal information;

biometric identification;

children or vulnerable persons;

legal or regulatory decisions; or

autonomous actions that could cause significant physical, financial or reputational harm.

These systems are not automatically prohibited.

However, participants should implement safeguards proportionate to the risks, which may include:

meaningful human review;

clear user disclosure;

restricted permissions;

transaction or action limits;

logging;

monitoring;

testing;

fallback procedures; and

the ability to stop or disable the system.

Future Caribbean may impose additional requirements on a particular Challenge where the nature of the project warrants them.

6. Human Oversight

Where an agentic system can take consequential actions, participants should ensure that an appropriately informed person can intervene, override or stop the system where reasonably practicable.

The degree of human oversight should reflect the potential consequences of an error.

Participants should not rely solely on the fact that an AI model has performed well in testing as evidence that human oversight is unnecessary.

7. Security and Credentials

Participants must take reasonable steps to protect:

API keys;

passwords;

authentication tokens;

private repositories;

personal information;

sponsor or partner systems; and

other credentials or sensitive information.

Credentials must not be published in public repositories, demonstrations or other publicly accessible materials.

Participants must not connect an AI agent to a third-party system unless they have the necessary permission to do so.

8. Data

Participants must have an appropriate legal basis or other permission to use personal information in their projects.

Participants should use the minimum information reasonably necessary for their project.

Where practical, participants should use:

synthetic data;

anonymised data; or

appropriately de-identified data

instead of identifiable personal information.

Participants must not upload confidential or personal information to a third-party AI service unless they are authorised to do so and have considered the service’s applicable privacy and data-use terms.

9. Transparency

Where an AI system interacts directly with people, participants should provide reasonable disclosure that the interaction involves an AI system where failing to do so could materially mislead the user.

Participants should not make false claims about:

the capabilities of their system;

the data it uses;

the level of human oversight;

its accuracy or reliability; or

its performance.

Demonstrations should accurately represent the system’s actual capabilities.

10. Testing and Evaluation

Participants should test agentic systems for reasonably foreseeable:

errors;

unintended actions;

security vulnerabilities;

prompt injection;

inappropriate outputs;

unauthorised tool use;

data leakage; and

failure of human safeguards.

The extent of testing should be proportionate to the system’s capabilities and potential consequences.

Participants should document material limitations where those limitations could affect how judges or users understand the system.

11. External Tools and Models

Participants may use third-party AI models, APIs, datasets, software and other tools subject to the applicable Challenge Rules and third-party terms.

Participants are responsible for complying with applicable licences and terms.

Where a third-party model or service materially affects the operation of a Submission, participants should disclose that use where required by the applicable Challenge Rules.

12. Autonomous Actions

An agent should have only the permissions reasonably necessary to perform its intended function.

Where an agent can:

send messages;

make purchases;

execute transactions;

modify files;

access external accounts;

publish content; or

otherwise take consequential action,

participants should consider appropriate limits, confirmations, monitoring or other safeguards.

A participant should not give an experimental agent unrestricted access to systems merely for convenience.

13. Build in Public

Future Caribbean encourages open collaboration and building in public.

However, participants are not required to disclose:

confidential information;

personal information;

security credentials;

proprietary information they are not authorised to disclose; or

information subject to an employer, client, sponsor or other contractual restriction.

Public-building requirements in a particular Challenge will be subject to the applicable Challenge Rules.

14. Incident Reporting

Participants should promptly notify Future Caribbean if they discover a material:

security vulnerability affecting Future Caribbean;

unauthorised disclosure of personal or confidential information;

compromise of Future Caribbean systems;

misuse of Future Caribbean credentials; or

safety issue that could materially affect other participants or the public.

Reports should be sent to us via email.

Where a matter concerns participant conduct rather than technical security, it may instead be reported under the Future Caribbean Code of Conduct and Complaints & Enforcement Procedure.

15. Monitoring and Enforcement

Future Caribbean may take reasonable steps to investigate suspected violations of this Policy.

Depending on the circumstances, action may include:

requesting information or clarification;

requiring additional safeguards;

restricting access to a Platform feature;

suspending an account or Submission;

removing content;

disqualifying a participant or Submission; or

terminating participation.

Where reasonably practicable, Future Caribbean will give the affected participant an opportunity to respond before taking final action.

Immediate action may be taken where reasonably necessary to address a serious safety, security or legal risk.

16. No Guarantee of Safety

AI systems can behave unpredictably and may produce inaccurate, biased, insecure or unintended results.

Future Caribbean does not guarantee that any AI system developed through its programmes will be safe, accurate, reliable or suitable for deployment.

Participants are responsible for evaluating whether and how their systems should be used outside the Buildathon or programme environment.

17. Challenge-Specific Requirements

A particular Challenge may impose additional AI safety, technical, security or compliance requirements.

Those requirements will be identified in the applicable Challenge-Specific Rules.

Where a Challenge requirement is stricter than this Policy, the Challenge requirement will apply to that Challenge.

18. Relationship with Other Policies

This Policy should be read together with:

the Future Caribbean General Website & Platform Terms of Use;

the Buildathon Official Rules;

applicable Challenge-Specific Rules;

the Future Caribbean Code of Conduct; and

the Future Caribbean Privacy Notice.

In the event of a conflict, the document hierarchy established in the applicable Official Rules or Terms will apply.

19. Changes to this Policy

We may update this Policy to reflect changes in technology, programme requirements, applicable law or safety practices.

Where a material change affects an ongoing Challenge, we will provide reasonable notice and will not apply the change retrospectively in a manner that materially disadvantages a participant except where permitted by the applicable Rules or required by law.

← Back to Future Caribbean