Karsten Wenzlaff, Advisor
August 26th, 2025

July 21, 2026 | NCFA Companies On The Move | Cybersecurity And Fraud, Identity Privacy And Data Governance, Artificial Intelligence And Data
Tailscale is a Toronto founded secure networking company built around WireGuard, identity controls and direct connections between devices. By July 2026, it was nearing 40,000 paid business clients and approximately 300 employees, according to BetaKit. Tailscale’s website separately reports 2.5 million active devices and 100,000 monthly active users.
The core business makes private networks easier to deploy and govern, while Aperture and Border0 take Tailscale into AI access and privileged infrastructure—two markets with bigger security budgets and much heavier competition. This profile looks at what customers are buying today, where the next leg of growth could come from and what the public evidence still can’t tell us.
The best public clues come from customers describing work they no longer have to do. Instacart reduced internal VPN support requests from about 10 each week to nearly zero, cut new user onboarding to less than one minute and reported no outages after deployment. Cribl grew from 18 to approximately 550 employees without hiring a dedicated networking team to administer access, while Corelight reports saving more than 1,000 hours annually and Positron estimates it saves an hour each time a prospect is onboarded.
These are selected Tailscale case studies, not audited results or a measure of what the average customer should expect. Still, they help explain how the product spreads: it removes the VPN tickets, slow onboarding and constant access administration that technical teams already dislike. A developer can start with one live problem, and if the network holds up, IT and security have a practical reason to standardize it, add controls and bring more of the company onto the same service.
Core Tailscale appears to be the product that pays today. It creates an encrypted private network among approved users, devices, servers and services, with identity based policy deciding what can connect. Developers can get started without rebuilding the company network; as use grows, IT and security can add centralized administration, device posture, logs and tighter access controls. Tailscale’s client, command line tool and relay server code are open source, but the hosted coordination server is proprietary. That coordination service distributes public keys and access rules, while customer traffic normally moves directly between endpoints or through encrypted relays. Tailscale Raises $230M To Power Identity-First Networking looked at why this model could pressure conventional VPN and firewall products.
The pricing supports the same bottom up motion. Tailscale currently lists a free Personal plan, Standard at US$8 per user per month, Premium at US$18 and custom Enterprise terms, with paid plans adding provisioning, device posture, administrative roles, network flow logs, regional routing and support. The cost of trying the product is low; the account becomes more valuable as more people, devices and company controls move onto it.
Revenue is the important missing number. Tailscale doesn’t publish it, and the outside estimates aren’t close enough to treat as fact. GetLatka puts 2025 revenue at US$45.2 million, although it says the figure is modelled and that management wasn’t interviewed. Northmetric estimates US$60.1 million in current annual recurring revenue with medium confidence, relying partly on an assumed 54,000 paying customers—well above BetaKit’s July 2026 report of nearly 40,000 paid business clients. Taken together, the estimates point to a company with real commercial scale, but they don’t establish Tailscale’s actual revenue.
Aperture is the move into AI access and cost control. Sitting between approved users or agents and AI model providers, it centralizes credentials while applying access rules, usage visibility and spending limits. That puts platform, security and AI infrastructure teams squarely in the buyer group. AI Agents Enter Governed Financial Workflows explains why permissions, approved tools and audit records matter once agents touch regulated work. Existing Tailscale networks could give Aperture a useful distribution advantage, but the product remains in beta and is currently available without extra cost during testing. Six users are included, with additional access handled through the company; usage, paid conversion and final pricing haven’t been published.
Border0 moves Tailscale into privileged infrastructure access. It governs sensitive connections to servers, databases, Kubernetes environments and internal applications, adding approval workflows, session recording and audit visibility. Those capabilities put Tailscale in front of security, compliance and operations buyers—not just the teams managing everyday network access. After acquiring Border0 in March 2026, Tailscale began connecting the product to its identity and networking layer, although the combined offering remains in beta. Adoption, revenue and final packaging haven’t been disclosed, so Border0 is best viewed as a credible expansion route rather than a proven second engine.
Tailscale now overlaps with secure networking, identity security, privileged access and AI gateways. Each move opens another budget, but it also brings the company up against much larger security platforms with broader bundles, established enterprise sales teams and far more acquisition firepower.
Large security platforms are buying identity. Palo Alto Networks completed its acquisition of CyberArk in February 2026, adding privileged access and identity security to a platform that already spans network, cloud and security operations. CrowdStrike agreed to acquire SGNL for continuous identity controls, while Zscaler agreed to acquire Symmetry Systems for data and AI access visibility. Buyers are clearly paying for identity and access control, but they may increasingly prefer to buy it inside a larger security contract.
SASE rivals have more capital and enterprise reach. Netskope’s September 2025 IPO raised approximately US$992 million and valued the company at about US$9.6 billion on a fully diluted basis. Netskope, Zscaler, Cloudflare and Palo Alto Networks can bundle network access with wider security products and sell through established enterprise teams. Tailscale’s counter is that technical users can adopt its product before a large security procurement begins, although that advantage could narrow as buyers consolidate more of their security spending with fewer vendors.
AI gateways are becoming a real product category. Cloudflare AI Gateway added real time spending limits and identity based controls in June 2026, while Kong sells governance for models, MCP servers and AI agents. Neo Raises US$100M To Control Enterprise AI Agents shows how quickly money and products are gathering around agent inventory, permissions and policy. Aperture approaches the same problem from inside a customer’s private network, which gives it an interesting opening; whether that opening lasts will depend on policy depth, auditability and model coverage.
Canadian financial institutions face clearer AI and vendor controls. OSFI’s July 2026 bulletin on generative and agentic AI connects AI use to existing expectations for technology risk, operational resilience and third party oversight. Its technology and cyber risk guideline and third party risk guideline make identity, logs, access policy and vendor diligence commercially relevant. OSFI And GRI Workshops Reveal What Regulated AI Needs found that weak identity, provider concentration and vendor oversight are already limiting adoption. Tailscale’s SOC 2 Type II status helps. CSA Cybersecurity Guidance For Registered Firms shows why firms will still need documented vendor diligence, access controls and current assurance reports.
Open source keeps the paid product honest. Tailscale identifies Headscale as an independent alternative to its proprietary coordination server, which means a capable technical team can self host that layer. The subscription therefore has to keep earning its place through reliability, administration, policy, support and company controls—not connectivity alone.
Easy adoption doesn’t remove enterprise budget friction. A Tailscale commissioned survey of 1,000 technology leaders found that 42% cited workflow or integration disruption when security upgrades were delayed, while one third cited an unclear business case. Customer results give Tailscale’s sales team concrete savings to work with, but a company wide deployment still needs an owner, a budget and proof that another security vendor can be retired or avoided.
Tailscale’s edge starts with how it gets in. A developer or infrastructure team can solve a live networking problem without waiting for a company wide migration; if the product works, IT and security can add policy, device controls, logs and support around a network that people are already using. Reported results from Instacart, Cribl, Corelight and Positron give that approach substance beyond the usual product pitch. It also places Tailscale across several areas in the NCFA Financial Innovation Map, including digital identity, cyber resilience, AI governance and enterprise infrastructure.
The next act is harder because Aperture and Border0 ask those customers to trust Tailscale with AI access and privileged infrastructure, where the budgets are larger and the incumbents are stronger. Nearly 40,000 paid business clients and 2.5 million active devices give Tailscale a meaningful starting point; what isn’t public yet is whether either product is creating meaningful new revenue.
The Company Intelligence Snapshot follows the funding, customer growth and product decisions that brought Tailscale to this point.
Tailscale was founded in 2019 to reduce the complexity of connecting people, devices and services across the internet. Its first generally available product combined WireGuard encryption, identity and direct connections without requiring companies to rebuild their existing networks.
TailscaleA Canadian founded secure networking company
LaunchGeneral availability arrived in April 2020
US$3M SeedLed by Heavybit with Uncork Capital and others
GlobalRemote teams, cloud infrastructure and personal networks
Developers FirstIndividuals and technical teams could start without enterprise deployment
Simpler VPNDirect encrypted connections reduced reliance on central VPN concentrators
Rather than begin with a top down security sale, Tailscale gave developers a faster way to connect private infrastructure and let working networks make the case for wider adoption.
Information notice: Private-company estimates are identified and attributed. Information may change after the stated update date. This content is provided for informational purposes only and does not constitute investment, financial or legal advice.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 20, 2026 | NCFA Resource | Cybersecurity And Fraud, Risk Compliance And Regtech, Capital Markets And Market Infrastructure

On July 15, 2026, the Canadian Securities Administrators published new cybersecurity guidance for registered dealers, advisers, and investment fund managers (Download the 12 page PDF report). CSA Staff Notice 33-322 combines findings from a focused review of 73 firms with practical expectations for policies, employee training, risk assessments, third party oversight, and incident response.
The notice is most useful as a compliance review tool. Firms can compare their written controls, operating practices, and supporting records against the deficiencies and effective practices identified by securities regulators. The guidance is particularly relevant for smaller and medium sized firms that may not have dedicated cybersecurity teams.
The notice organizes cybersecurity readiness around five areas that regulators examined under section 11.1 of National Instrument 31-103:
The review found useful benchmarks. 8% of firms had no written cybersecurity policies, while 55% had policies that needed improvement. Twenty one per cent provided no employee cybersecurity training. Forty five per cent completed risk assessments that could have been stronger, and 12% had no documented assessment during the review period.
Third party oversight was one of the clearest weaknesses. All examined firms used service providers with access to systems or data, but 62% had no documentation or limited documentation supporting their cybersecurity oversight. The CSA expects firms to complete and document due diligence before onboarding a provider and repeat that review throughout the relationship.
The guidance identifies information firms should assess, including data storage, encryption, access controls, patch management, incident notification, subcontractors, operating jurisdictions, and shared responsibility in cloud environments. It also recommends maintaining a complete vendor register and reviewing current SOC 2 or similar reports where available.
Incident preparedness also receives detailed attention. Fifteen per cent of firms had no written incident response plan. Among firms with a plan, 53% needed stronger procedures and 63% should have tested their plans more regularly. The notice describes tabletop exercises and simulated attacks as practical ways to test whether people, processes, and technical controls work together during an incident.
The primary audience is firms registered as dealers, advisers, portfolio managers, investment fund managers, exempt market dealers, and restricted portfolio managers. Chief compliance officers, directors, technology leaders, privacy professionals, and internal audit teams can use the notice to organize a control review and identify missing documentation.
Boards and senior executives can also use it to test whether cybersecurity oversight is tied to clear responsibilities, regular reporting, and evidence that controls operate as intended. Written policies alone aren’t enough when actual practices, testing schedules, or access controls differ from the documented process.
Cybersecurity consultants, legal advisers, insurance providers, managed service providers, and software vendors can use the findings to better understand the records and evidence registered firms may need during a regulatory review.
The notice is strong because it combines regulatory expectations with observed deficiencies, percentages, effective practices, and practical takeaways. It covers both governance and technical controls, including multifactor authentication, encryption, backups, access rights, patching, email filtering, endpoint protection, and activity logging.
It also makes documentation a central requirement. Firms should be able to show when policies were reviewed, who completed training, how risks were assessed, what vendor due diligence occurred, and when incident plans or backup recovery procedures were tested.
The guidance does not create a complete technical cybersecurity standard, and it doesn’t replace obligations under privacy, securities, corporate, or other applicable laws. Expectations also vary with the firm’s size, operating complexity, client information, service provider reliance, and exposure to cyber risk.
Firms should therefore use the notice as a regulatory gap assessment and evidence checklist, then supplement it with appropriate legal advice, technical standards, testing, and controls suited to their operations.
CSA Staff Notice 33-322 (cybersecurity examination findings and guidance for registered firms)
CSA Staff Notice 33-321 (foundational 2017 cybersecurity and social media guidance)
NIST Cybersecurity Framework (risk management structure for identifying, protecting, detecting, responding, and recovering)
CIS Critical Security Controls (prioritized technical and operational safeguards)
Wealthsimple Confirms Breach Impacting Clients (third party exposure and incident response)
Proposed Class Action Targets Equifax Access Controls (access governance and third party permissions)
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 20, 2026 | NCFA Market Activity | Cybersecurity And Fraud, Artificial Intelligence And Data, Risk Compliance And Regtech

On July 20, 2026, Neo emerged from stealth with US$100 million in combined seed and Series A financing from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures and Merlin Ventures.
The Boston cybersecurity company was founded in 2025 by Nick Warner, Shlomi Salem and Eran Shirazi. Note that it's unrelated to Calgary based Neo Financial. Warner previously served as SentinelOne president and COO, Salem led detection engineering and threat research at SentinelOne, and Shirazi previously co-founded EasySend after leading vulnerability research in Israel’s Unit 8200.
Neo is building what it calls an agentic software control layer. The platform gives security teams an inventory of AI agents, AI enabled applications, plugins, extensions, MCP servers and traditional software that has gained agentic capabilities. It then maps permissions, attributes actions and applies policy before software reaches sensitive data or systems.
The company plans to use the financing to expand engineering and go to market operations. Neo hasn't disclosed revenue, customer counts, named customers, valuation or the allocation between its seed and Series A rounds.
Enterprise security was built around human users, known applications and recognizable data flows. AI agents can act differently. They may inherit a user’s permissions, call several tools, reach files and credentials, communicate with other agents and continue operating without a conventional interface.
That means risky activity may not even resemble a conventional intrusion. An agent can use valid credentials and approved applications while still exporting too much data, reading a secret, pushing code or initiating an action that exceeds the authority its operator intended to grant. NCFA’s analysis of AI agents gaining identity and wallet access shows how quickly this issue reaches financial APIs and real infrastructure.
Neo’s platform combines four functions. It finds AI software, checks what it can access, shows who or what is behind each action, and lets security teams allow, block or pause that action for approval.
Threat's aren't limited to deliberately malicious agents. ShadowLeak demonstrated how hidden instructions could manipulate an AI agent and expose private information without a user clicking a malicious link.
Its Neoverse knowledge base maps the capabilities, risks and behaviour of agentic software before it enters an enterprise environment. Neo says enforcement occurs natively at the endpoint, where the software can intercept tool calls, API access, credential reads and data transfers before the action is completed.
Neo combines software inventory, posture intelligence, attribution and endpoint enforcement across agentic and traditional applications.
Check Point is developing a wider AI security control plane covering employee AI use, AI applications and agentic systems.
SailPoint is extending identity governance to AI agents and other non-human identities.
Existing endpoint security providers already control devices, files and processes, but may not yet map the permissions and chained actions occurring inside agentic software.
Cloud and application security companies can govern models, APIs and data access, creating a competitive question around whether customers will buy a separate agentic control layer or expect existing security platforms to absorb the function.
Banks and other regulated organizations will need more than a list of approved AI tools. They need to know which person authorized an agent, what credentials it inherited, which systems it can call, what information it can export and when human approval is mandatory.
Neo’s opportunity is to show who or what can access each system and enforce clear limits on what they can do. Its challenge is that endpoint, identity, cloud and network security companies are all pursuing parts of the same problem. Large institutions may prefer one more specialized control layer, or they may demand that existing suppliers add agent governance to products already deployed across the organization.
Financial institutions are adopting AI while remaining accountable for privacy, cybersecurity, third party risk, operational resilience and auditability. An agent that can access customer information, initiate a payment, change code or communicate externally will need authority limits that security, risk and compliance teams can understand.
Neo has the capital and founding team to compete early, but the category is still forming. Enterprise adoption, integration depth and the quality of its policy enforcement will matter more than the size of the launch financing.
Will enterprises buy a dedicated control layer for agentic software, or will endpoint, identity and cloud security providers absorb the function before the category becomes independent?
Nick Warner, Shlomi Salem and Eran Shirazi founded Neo in 2025 to build security controls for enterprise software gaining autonomous and agentic capabilities.
Neo SecurityEnterprise cybersecurity company focused on agentic software
FormationExperienced operators assemble before the public launch
Early Institutional BackingSeed and Series A allocation not publicly disclosed
Enterprise SecurityAI driven software environments
SecOps TeamsLarge organizations adopting AI enabled software
Operator ExperienceFounders previously built and scaled enterprise security companies
Neo begins with founders who have built cybersecurity products and commercial organizations before. That lowers some execution risk, but it does not yet establish enterprise adoption.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 17, 2026 | NCFA Insight | Regulation And Policy, Wealth Investing And Trading, Risk Compliance And Regtech

On July 9, 2026, the UK Financial Conduct Authority reported the results of its finfluencer enforcement campaign. A coordinated week of action involving 9 international regulators produced 3 arrests, 6 criminal proceedings, 11 warning or cease and desist letters, 50 warning alerts and 650 social media takedown requests.
Canadian regulators weren’t watching from the sidelines. The Alberta Securities Commission, Autorité des marchés financiers, British Columbia Securities Commission and Ontario Securities Commission participated in the June 2025 operation. Earlier analysis asked whether finfluencers were facing a crackdown or clearer regulation.
The FCA’s latest figures show that enforcement has now become repeatable. Investigators can identify illegal content, connect creators to products and firms, request platform removals, issue public warnings and escalate selected cases into criminal proceedings.
The scale of the FCA’s supporting operation is just as relevant. During 2025, it issued 2,329 warnings about unauthorized or potentially fraudulent firms, compared with 2,240 in 2024. It secured 17 criminal convictions involving fraud, insider dealing, money laundering and data protection offences. Twelve people paid a combined £1.77 million in market abuse fines for market abuse.
Technology is improving that capacity. FCA automation reduced the handling time for simpler supervisory cases from as much as 4 hours to about 6 minutes on average. That doesn’t automate consequential decisions. It clears routine work so investigators can spend more time on repeat promoters, hidden compensation, unauthorized firms and cross border distribution.
The 650 takedown requests are the most commercially relevant number. Arrests attract attention, but removing hundreds of accounts and posts targets distribution. Illegal promotions lose value when creators can’t reach an audience, acquire leads or direct followers to a trading platform.
The FCA can examine multiple parties within one campaign. A creator may publish the content, a financial firm may pay for it, an affiliate network may track referrals and a platform may distribute it. The underlying product can then lead investigators to an unauthorized operator or regulated firm with weak approval controls.
Criminal proceedings provide the upper end of that response. The FCA accused 3 people charged after the 2025 operation of promoting high risk contracts for difference without authorization. Each faces an allegation of communicating an invitation to engage in investment activity contrary to section 21 of the UK Financial Services and Markets Act.
The April 2026 second global week of action showed how quickly the system had expanded. Seventeen regulators participated. The FCA requested the removal of 120 accounts and identified 1,267 illegal financial advertisements that reached at least 2,338,372 accounts. People or firms already listed on its Warning List accounted for 66% of those advertisements.
That 66% figure exposes a persistent enforcement problem. Many promoters aren’t unknown actors. They continue publishing after regulators have already identified the related firm, person or offer. Effective supervision therefore depends on account removal, repeat offender monitoring and platform cooperation, not warnings alone.
The FCA also secured a guilty plea, began criminal proceedings against 2 more people, issued 34 new warning alerts and updated 14 existing warnings during the April operation. Coordination now combines prosecution, surveillance, education and content removal rather than treating each promotion as an isolated post.
Canada’s legal foundation is already in place. In December 2025, the CSA and CIRO published Staff Notice 31-369, which explains how securities law applies to finfluencers, issuers and registered firms. The practical requirements appear in Canada’s finfluencer guidance.
The guidance doesn’t create a separate licence for creators. It examines the activity itself. A creator may need registration when they provide investment advice as a business, facilitates trades, arranges referrals or connects paid subscribers to copy trading. General market commentary may qualify for an exemption, but creators must still disclose financial interests and other conflicts clearly and on time.
Compensation also changes the compliance analysis. Cash payments, securities, affiliate income, referral fees and free products can establish a commercial relationship. A disclaimer such as “not financial advice” doesn’t cancel the substance of a recommendation, the creator’s compensation or the transaction being encouraged.
Responsibility extends beyond the creator. Registered firms must supervise people acting on their behalf, address referral arrangements, retain records and review relevant communications. Issuers remain responsible for paid investor relations activity and promotional claims made for their benefit. The joint staff notice applies the same principles to AI generated content and digital personas.
The investor evidence explains why regulators are paying attention. An OSC study of 655 Canadian retail investors found that 35% had made a financial decision based on finfluencer content. Those who acted on it were 12.2 times more likely to report being scammed on social media and 2.3 times more likely to have experienced a significant investment loss.
The OSC also ran a simulated investment experiment involving 1,465 Canadians. After viewing a promotional social media post, 38% bought the featured asset. Only 8% of the control group did the same. The full findings and behavioural differences appear in the finfluencer effect on Canadian investors.
Canada has also produced direct enforcement results. In September 2025, the Alberta Securities Commission imposed sanctions on James Domenic Floreani and Jayconomics Inc. for promoting 4 issuers through YouTube, X and Patreon without clearly disclosing that they published the content on behalf of those issuers.
The respondents received a $30,000 administrative penalty, $10,185.10 in costs and 2 year restrictions covering investor relations activity, public securities promotion and securities or derivatives advice.
British Columbia added a preventive layer during the April 2026 operation. The BCSC issued 14 compliance letters to YouTubers and other promoters who had discussed publicly traded B.C. companies. It also referred to an active proceeding alleging that sponsored issuer promotions weren’t disclosed clearly.
The FCA operates a national financial promotions regime and can report one consolidated set of arrests, warnings, takedowns and prosecutions. Provincial and territorial authorities administer Canadian securities regulation, while CIRO supervises investment dealers, mutual fund dealers and regulated marketplaces.
Canadian action may therefore appear as several provincial cases, coordinated review periods, issuer investigations, warning letters and firm supervision rather than one national enforcement tally. That can make the activity look smaller even when regulators review the same creators, platforms and promotional networks.
The operating implications are already clear.
Platforms are also becoming part of the enforcement process. When regulators can connect warnings to hundreds of removal requests, account access becomes a compliance dependency. Firms using social media for distribution can’t treat the creator’s channel as an independent marketing asset beyond their control.
Canada doesn’t need to duplicate the FCA’s structure to produce comparable enforcement. Its regulators are already participating in the same international operations, applying national guidance and using provincial proceedings. The open question is whether those actions will become visible as a coordinated Canadian program or remain distributed across separate regulators and cases.
Will Canada’s finfluencer guidance support coordinated enforcement across provinces, platforms and firms, or will separate cases continue defining the compliance boundary?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA engages with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 13, 2026 | NCFA Market Activity | Cybersecurity And Fraud, Artificial Intelligence And Data, Banking And Credit

On June 25, 2026, Jack Henry expanded its Google Cloud collaboration to develop agentic AI security for banks and credit unions. The U.S. banking technology provider serves about 7,400 community financial institutions and plans to combine Google Security Operations, Gemini Enterprise Agent Platform, and Mandiant Consulting across Google Cloud, other cloud services, and on-premises systems.
The deal is less about access to an advanced model than the work required to deploy one inside a bank. Security evidence is spread across user accounts, devices, applications, networks, and cloud services. Analysts must connect those records quickly enough to determine whether an alert is harmless or part of an attack. Smaller institutions often lack the security teams and integration capacity to do that across several enterprise products.
The divide and conquer commercial logic of the deal is Google brings the models, security software, and threat expertise. While Jack Henry brings the bank relationships and operating knowledge required to put them to work.
Google Security Operations collects security data from across an institution’s systems and connects related alerts into an investigation. Its Triage and Investigation Agent can retrieve evidence, apply threat intelligence, assess likely causes, and explain its findings.
Google says the agent has processed more than five million alerts and reduced a typical 30-minute manual investigation to about 60 seconds. Those are Google product results, not outcomes reported by Jack Henry customers.
The operating gain comes from completing the early investigation before an analyst steps in. Instead of opening several products, finding related records, and rebuilding the sequence of events, the analyst receives an assembled case with supporting evidence and a proposed response.
Sensitive actions still require clear limits and human oversight. Google can pair AI investigations with fixed playbooks and require approval before isolating a device, disabling an account, or blocking traffic. Jack Henry hasn’t said where it will draw those boundaries, how customers will audit agent decisions, or what happens when an automated recommendation is wrong.
Release timing, pricing, implementation requirements, and the first participating institutions also remain undisclosed, so the announcement is good on tech direction but light on adoption or performance figures inside an operating bank.
Mandiant Consulting adds threat modelling, security assessments, and red team testing. That work tests the design before attackers do. Gemini handles reasoning, while Google Security Operations provides the data and investigation tools.
Jack Henry must make the combined service fit each institution’s systems, controls, and support model. That integration is the difficult part.
A bank could buy Google’s security products directly. It would still need to connect the right data, define agent permissions, build response procedures, satisfy audit requirements, and decide who remains accountable for each action.
Jack Henry already operates inside that environment. Its core processing, digital banking, payments, lending, and operational products support institutions that rarely replace critical systems. It also manages hosted and on-premises deployments that a cloud provider may not control.
The companies began working together in 2022 on cloud data, reporting, and integration services. Security extends that relationship into a product Jack Henry can configure around each customer and deliver through an existing technology and support contract.
That could make AI security another banking software service rather than a separate enterprise purchase. Core providers already control the connections, implementation work, and customer access needed to distribute agents at scale.
Security specialists still compete on detection quality, threat intelligence, and response tools. CrowdStrike and Palo Alto Networks are adding agents to their products, while Fiserv offers managed cybersecurity services and is developing AI capabilities. Jack Henry competes from a different position. Its advantage is knowing how community institutions run and where security tools must connect.
Google gains a route into thousands of regulated institutions without implementing its products one bank at a time. Jack Henry can add a service whose value depends on its knowledge of each customer’s systems and operating requirements.
This is where enterprise AI economics become clearer. Foundation models can be sourced from a small group of large providers. The commercial asset is access to the workflow where the model can complete useful work under controlled permissions.
That favours software companies with deep customer integration. Fintech founders don’t need to build a foundation model, but a general AI interface won’t be enough. TD’s AI loan decisioning deployment shows why the value comes from placing verification and decision tools inside an active lending workflow. A specialized process, regulated decision, proprietary dataset, or difficult integration gives an agent work that an incumbent can’t easily reproduce.
Jack Henry hasn’t announced a Canadian release, but the deployment problem is familiar. Canadian regulated AI workshops have identified vendor dependence, data quality, model validation, and accountability as barriers to production use.
Access to a capable model isn’t the constraint. Banks need to connect it to existing systems without losing control of data, permissions, decisions, or operational risk. National Bank’s Sardine deployment follows that reality by embedding external device intelligence and risk scoring into retail, commercial, and wealth operations.
The Canada AI Consortium is working on common controls for models, agents, users, and enterprise systems. Its use cases differ from Jack Henry’s security project, but the operating requirement is the same: agents need restricted access, visible decisions, and accountable people.
For Canadian banks and fintechs, the commercial challenge is solving those controls inside regulated workflows. Products that leave the integration and governance work to the bank may struggle to progress beyond a pilot.
As foundation models become easier to replace, will banking software competition depend less on who owns the AI and more on who controls the workflows where agents can act?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |