Karsten Wenzlaff, Advisor
August 26th, 2025
Mar 26, 2026 | NCFA Insight | Artificial Intelligence And Data

On March 1, 2026, CodeWall, a security research firm focused on AI systems, privately reported security gaps to McKinsey. The firm said its agent found 22 unauthenticated endpoints, then chained a SQL injection issue and other weaknesses to gain read and write access across the production environment. CodeWall said the reachable data included 46.5 million chat messages, 728,000 files, 57,000 user accounts, 384,000 AI assistants, and 94,000 workspaces. It also said prompts, model configurations, and RAG related data were reachable.
On March 2, 2026, McKinsey acknowledged the findings and patched the unauthenticated endpoints the same day.
On March 9, 2026, CodeWall publicly shared research on vulnerabilities in McKinsey’s internal AI platform Lilli.
On March 11, McKinsey released this statement about the vulnerability and that a third party forensic review found no evidence that unauthorized parties accessed client data or client confidential information.
Public API documentation appears to have exposed a map of the system. Some endpoints reportedly required no authentication. One of them allegedly allowed database manipulation through JSON keys, which opened the door to SQL injection. From there, CodeWall said it could determine live production data and reach much deeper parts of the platform.
This incident doesn't point first to a model failure. It points to ordinary application security weaknesses around an AI system that had become deeply embedded in internal work.
McKinsey didn't confirm the full scale of the researcher claims. Instead, it focused on the response. The company said it fixed the issue quickly and found no evidence that unauthorized parties accessed client data or client confidential information.
Having said that, the reported scale of reachable internal material was large enough to raise questions about internal knowledge exposure, employee work patterns, and intellectual property concentration in one system.
CodeWall said prompt and configuration layers were reachable. If true, it means a bad actor could have potentially altered how the system retrieves information or generates answers. In an internal AI tool, that can create wrong outputs that look normal to staff.
That's where this type of incident becomes more useful for fintechs and financial firms. A publicly visible outage gets noticed whereas quietly altered outputs may not. In regulated environments, that can affect approvals, reviews, client treatment, policy interpretation, and internal decision support before anyone spots the pattern.
Banks, lenders, insurers, wealth firms, and fintechs are building similar internal AI layers right now. They connect those tools to policy documents, research, support logs, internal files, and customer related workflows because it saves time and helps staff move faster.
But that convenience comes with risk given that AI often pulls sensitive access into one place. If permissions are weak, endpoints are exposed, or prompt controls aren't protected, one internal tool can become a wider point of failure.
A key lesson founders and operators should take from this case, is to ask whether the application around it is locked down, whether prompts and retrieval rules are treated as sensitive assets, whether permissions are tight, and whether anyone has tested the system the way an attacker would.
Enterprise AI doesn't erase old security mistakes. It can magnify them by concentrating data, access, and trust inside a single interface.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Mar 25, 2026 | NCFA Insight | Regulation And Policy, Capital Markets And Market Infrastructure

Sports volume built the business. Now rules, surveillance, and product limits will decide who lasts. On March 23, 2026, a bipartisan Senate bill moved to ban sports and casino style contracts on CFTC registered prediction market venues. The Senate release said a March Madness winner contract had already passed $100M in trading volume and that Super Bowl prediction market volume topped $1B in 2026.
Those numbers explain why prediction markets are now under direct pressure from lawmakers. Prediction markets are no longer fringe. They now sit in a fight over who regulates them, which contracts stay allowed, and whether the business still works under tighter rules.
Sports helped prediction markets reach a wide audience fast, but that same growth put them in direct competition with state regulated sportsbooks and tribal gaming interests. The Prediction Market Senate bill to ban sports contracts is aimed straight at that overlap. It would prohibit any CFTC registered entity from listing contracts that closely resemble a sports bet or a casino style game. If it advances, sports contracts would be the first part of the business to take a hit. That in itself wouldn't kill prediction markets, but it would force a reset around contracts that look more like economic, financial, or commercial forecasting and less like entertainment wagering.
Sports contracts brought scale, attention, and league partnerships. NCFA looked at that earlier when the NHL partnered with Kalshi and Polymarket. Sports now look like the part of the business most likely to trigger a stronger federal and state response.
Polymarket and Kalshi tightened their controls on the same day. On March 23, Polymarket tightened its market integrity rules across both its DeFi venue and its CFTC regulated US exchange. The updated rules ban trading on stolen confidential information, illegal tips, and outcomes a trader can influence.
Kalshi added candidate and athlete trading bans covering political candidates, athletes, referees, coaches, and team staff, and introduced a whistleblower feature to tighten insider risk controls.
These aren't minor changes. They prove Kalshi and Polymarket understand that insider risk is now a live issue. Prediction markets want to be treated as financial infrastructure, but financial infrastructure has to show it can police insiders, document rules, and respond fast when abuse appears. NCFA covered that tension earlier when prediction markets started pricing geopolitical events.
Canada is taking a narrower approach. The Globe and Mail reported today that Wealthsimple cleared a regulatory hurdle to offer forecast contracts in Canada, but only for economic indicators, financial markets, and climate trends. Sports and election contracts are out. Wealthsimple is the second firm to receive this approval in Canada, after Interactive Brokers Canada.
Interactive Brokers Canada has positioned contracts around government, economic, finance, and climate events, not sports books in a different wrapper. The product is already live in Canada on that basis.
Wealthsimple now brings local retail distribution, stronger brand reach, and a better chance of testing whether forecast contracts can find a market here without leaning on the sports volume that pushed the US fight into the open.
Can a prediction market still grow once sports contracts face a ban, insider screening gets tighter, and compliance costs rise? Some firms may adapt by leaning into macro, rates, inflation, climate, earnings, and other information markets. Others may find that the most profitable contracts were also the ones most likely to trigger a crackdown.
The CFTC is also reviewing the rules. On March 12 2026, the CFTC opened an Advance Notice of Proposed Rulemaking on prediction markets and asked for public comment on which event contracts may be contrary to the public interest, how current rules apply, and what changes may be needed. That means this fight is not limited to one Senate bill or one week of headlines. The federal rule in the U.S. is now under review.
For Canadian dealers, fintechs, and market operators, there is room to build forecast products here, but the lane is narrower than in the US.
Prediction markets already proved they can attract users and volume. The next test is whether prediction markets can still grow once product limits tighten, regulators draw a harder line around what is allowed, and compliance demands rise.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
March 23, 2026 | NCFA Insight | AI Governance And Data Sovereignty

On March 22, 2026, the Guardian reported that UK Financial Conduct Authority has hired US firm Palantir for a three month trial worth more than £30,000 a week to analyze its intelligence data lake. The reported scope includes highly sensitive material tied to fraud, money laundering, insider trading, case files, suspected wrongdoing reports, and consumer complaints. It's a significant AI governance and privacy risk given that the FCA regulates around 42,000 businesses across the UK's financial ecosystem.
Palantir is a US based data and analytics company that builds software platforms used by governments, intelligence agencies, and financial institutions to organize and analyze large, sensitive datasets. Its systems combine data integration with artificial intelligence and machine learning tools, which allows users to run complex analysis across entire data environments. That capability makes it effective for regulatory and investigative work, and also places it at the centre of ongoing concerns about data access, oversight, and reliance on external vendors in critical public systems.
The FCA has stated that Palantir acts only as a processor, the data stays hosted in the UK, the data cannot be used to train Palantir systems, encryption keys for the most sensitive files stay with the FCA, and the data must be destroyed at the end of the contract. These are all good safeguards but that doesn't end the debate.
The real question is whether a regulator should give a foreign AI operator working access to one of its most sensitive data environments.
The FCA wants better tools to detect financial crime across a very large supervisory perimeter. However, the concern is that once a foreign vendor obtains access to a highly sensitive operating environment, the public risk grows beyond just legal ownership of the data. What happens if controls fail beyond what the contract itself governs?
If a system ingests more than expected, if metadata creates a wider intelligence layer than planned, if privileges become too powerful, or if future use expands beyond the original trial, the exposure can widen even when formal safeguards remain in place. While none of this proves failure it does highlight why sensitive AI contracts and said deployments need much closer scrutiny than standard software procurement.
The trial is short, the weekly cost is disclosed in reporting, the data environment is sensitive, and the FCA says it has placed strict limits on processor role, hosting, training use, encryption control, and deletion. A second report on the FCA Planatir deal indicates the trial is designed to test whether advanced analytics an improve fraud detection, AML/KYC procedures, and insider training within the scope of firms the FCA supervised. But most already concur that AI, if given enough data, can perform small miracles compared to current data tools.
So the harder policy question becomes are the current safeguards enough when the downside of failure is so high, and the data risk in question is a primary financial services regulator, and not a low sensitivity pilot?
Many jurisdictions now rely on a small number of leading foreign AI and cloud firms to quickly integrate, operate, and scale advanced systems. Once workflows, analytics, procurement, and staff capability start to rest on a handful of outside platforms, exiting becomes more difficult due to dependence.
A country can keep data local and still lose practical control if key capability depends on foreign firms for models, compute, software layers, and operational support. This is why the question is bigger than privacy alone. It reaches into resilience, sovereignty, and the future of digital public infrastructure.
Europe is addressing this problem with both law and capacity. The EU AI Act already sets binding rules for higher risk AI use, while the EU’s wider strategy ties AI policy to competitiveness and technological sovereignty. The question in Europe is no longer whether to regulate AI. It is how to enforce those rules while building enough domestic capacity to avoid overdependence on foreign providers.
Canada isn't yet at Europe’s stage. Ottawa still leans on privacy law, sector rules, and evolving AI policy rather than a fully enacted economy wide AI framework. It is progressing more directly on capability, though. The Canadian Sovereign AI Compute Strategy makes clear that domestic control over compute and data infrastructure is a matter of national security and economic resilience issue, not only an industry growth objective.
That concern is already visible in Canadian data. In Canada AI Strategy Confronts Capital Flight, federal consultation inputs point to risks around sovereign capital, procurement, domestic IP retention, and keeping more AI value inside Canada. Also, the acceleration of AI deployments is exposing AI Governance Gaps that many legal experts have flagged.
The FCA Planatir contact creates at least five questions Canadian policymakers should ask early.
The AI race isn't just about who deploys and adopts first. It's also about who keeps control over sensitive data, institutional leverage, and critical digital infrastructure while deploying.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |