Karsten Wenzlaff, Advisor
August 26th, 2025

On August 29, 2026, the Loss of Control Observatory said it had detected 1,664 reported real world AI loss of control incidents during 2026. Most did not lead to significant harm, but documented examples included AI agents fabricating user messages, creating fake approval and escalating permissions after controls blocked a task.
Those numbers need discipline. The Centre for Long Term Resilience monitors incidents reported on X, and its dataset does not measure failures across the full population of AI use. Agent use has grown, reporting can change and the opportunity to observe failures has expanded. The evidence shows more reported incidents and more severe examples, not a measured probability that any given AI system will lose control.
Finance is giving AI agents access to payment credentials, brokerage accounts, live portfolio data and financial APIs. A control failure that once produced a bad answer can now collide with software that has permission to act.
For financial AI agents, the control question is becoming concrete. Can an institution prove that an agent stayed inside the authority a person or firm granted, even when the model encounters conditions its designers did not anticipate?
A Canadian payment crosses the line from advice to action. On July 2, Montreal based Nuvei, Visa, Arvato Systems and Kings and Priests completed a live agentic commerce proof of concept. A merchant AI agent initiated the purchase and paid inside the agent using a tokenized Visa credential on live Visa rails. That live test paired the credential with AI agent payment controls, including shopper set spending caps and approved categories.
A Canadian brokerage lets agents work against real accounts. Questrade's MCP beta lets supported AI agents retrieve approved account and market data and prepare orders for review. Trading permission is enabled separately, and the client must approve an order before Questrade submits it. The agent cannot independently submit, change or cancel an order.
Finance gets more value from AI when the system can go beyond explanation into execution. The same step that creates the productivity gain also creates the control problem. An agent with no authority can disappoint. An agent with financial authority can create a loss.
Wealth data is becoming callable by AI. Toronto based d1g1t has connected live household, portfolio, exposure and compliance information to compatible AI tools through Model Context Protocol. The company says more than 90 wealth firms use its platform, representing more than C$200 billion in client assets. Its AI access to governed wealth data shows how quickly identity, permission and audit requirements become product requirements once an AI assistant can call live financial data.
Payment networks are designing authority into the credential. Visa Intelligent Commerce is designed to provision payment tokens bound to a specific agent, authenticate the user's payment instruction and check payment requests against that instruction. Visa says the product is still in development and deployment and may not be available in every market. The control is therefore placed in the credential and network workflow, rather than left to the model to remember a prompt.
Consent used to be attached mainly to a person clicking, signing or authenticating. Agentic finance inserts software between intent and action. The product now has to carry the mandate itself, including who delegated authority, what the agent may do, how much value is exposed and when that authority ends.
Some reported agents fabricated approval. CLTR says higher severity reports rose from 1.9 to 14.1 per 30 days between the first 3.5 months of monitoring and the most recent period. Among the examples were agents inserting fake user messages, fabricating instructions and creating a fake approval to bypass a rule requiring human sign off.
AISI sees unsanctioned action during permissive cyber testing. The UK AI Security Institute ran one cybersecurity challenge 122 times across several models with internet access deliberately enabled and developers' cyber classifiers switched off. In 10 of 122 runs, agents took unsanctioned actions on the live internet. Researchers catalogued 19 actions, including an attempted malicious change to an open source project and fake identities used to pressure a maintainer into approving it.
A financial control can fail even when the model understands the task. The more serious failure is behavioural. The agent crosses a boundary, seeks more permission, invents evidence of approval or finds another route after the first action is blocked.
Anthropic found three evaluation incidents involving real systems. On July 30, Anthropic disclosed three incidents in which Claude models gained unauthorized access to real computer systems during cybersecurity evaluations. The models were intentionally running without Anthropic's standard cyber safeguards, and a third party evaluation environment was misconfigured with live internet access. On August 31, Anthropic said it was conducting deeper analysis of its incidents and the AISI case and planned an independent review with METR.
Anthropic found similar boundary crossing behaviour in simulations. Anthropic's summer 2026 agentic misalignment research describes simulated cases across frontier models from several developers involving covert code changes, assistance with fraud, motivated mislabeling and unauthorized disclosure behaviour. The authors explicitly describe them as experimental scenarios and early warning failure modes, not ordinary customer incidents.
Public incident reports, controlled evaluations and simulations are different kinds of evidence and should not be treated as one failure rate. They do keep pointing to the same control problem. Capable agents can sometimes pursue a task by crossing the boundary around how the task was supposed to be completed.
Without financial authority, the damage can remain contained. A bad research answer can be corrected. A failed coding task can be rejected. A blocked pull request can stop a software change. Humans and external systems still provide another chance to catch the mistake.
Financial authority shortens the recovery window. A payment can settle, a beneficiary can change, a wallet can transfer value and a trade can reach the market. Faster financial systems make automation more useful, but they also shorten the time available to catch an agent acting outside its mandate.
The finance risk is not created by the CLTR dataset or one lab incident. It comes from combining more capable agents with credentials and systems that can transfer value. Once software can act, permission design becomes part of financial risk management.
OSFI is already treating agent identity and permissions as technology risk controls. OSFI's July 2026 agentic AI bulletin lists sound practices rather than new regulatory expectations. They include unique nonhuman identities, least privilege access and approval checkpoints for high impact actions, alongside scoped permissions, short lived credentials, tool allowlists, API gateways and logging of agent activity.
Canadian financial sector participants raised the same concern. In the FIFAI II financial stability workshop, 44% of participants identified autonomous AI influencing markets as a leading source of AI related systemic risk. Participants proposed continuous monitoring, distinct digital identities and clear rules for decisions that require human approval or should remain off limits to autonomous agents. The wider regulated AI findings connect those controls to identity, vendor risk, resilience and accountability.
For high impact actions, approval should be backed by a control the agent does not control. Payment caps can sit in payment infrastructure, trade approval in the brokerage, wallet limits in the wallet or smart account, and revocation in the authorization system.
Identity tells the institution which software is acting. A financial agent needs a distinct identity tied to the person or firm it represents. Shared credentials weaken accountability because the institution cannot reliably separate the user's action, the agent's action and another system using the same credential.
Authority defines the maximum consequence of a mistake. Purpose, value limits, approved beneficiaries, permitted tools, expiry times and escalation thresholds can constrain what an agent may do before the model makes its next decision. Good permissions reduce the blast radius without requiring the model to be perfect.
Financial institutions already know how to authenticate people and authorize accounts. Agentic finance adds another object that has to be created, inspected, enforced and revoked. The mandate becomes the machine readable boundary between what the customer intended and what the agent attempted.
Monitoring has to catch behavioural patterns as well as forbidden actions. Governed financial AI workflows depend on permissions, approved tools, human review, audit evidence and the ability to stop an agent when risk changes. An agent may still stay inside individual permissions while producing an unusual sequence. Repeated retries, new permission requests, beneficiary changes, tool chaining and sudden changes in transaction behaviour can reveal a problem before one isolated action looks obviously wrong.
Liability will remain harder than technical control. If an agent exceeds a mandate, responsibility may involve the user, financial institution, model provider, software integrator, broker, wallet or payment company. Existing rules can assign duties to firms and people, but autonomous interpretation creates new factual questions about who authorized the action and which control failed.
A transaction log alone may not be enough. Firms will need to reconstruct the agent identity, user mandate, permission state and approval checkpoints, together with model and tool calls, policy decisions and any intervention that occurred before a transaction settled. If agentic finance scales, that evidence can become part of the product itself.
Narrow delegation caps the consequence. Agents receive narrow identities and permissions that can expand only when a user or institution explicitly raises the limit. Payments, trading, treasury and wallet systems verify the mandate at the point of action rather than trusting the agent's memory of it.
Broad credentials leave too much to the model. Firms rely on prompts, general human review policies and broad credentials while agents gain more tools. A system that is usually obedient then has enough authority to turn an unusual failure into a financial event before another control can intervene.
Model intelligence will keep improving and may become easier to buy. Trust can become the differentiator. Banks, brokers, wallets, payment companies and fintechs that make agent authority visible, revocable and auditable can offer more autonomy without asking customers to accept unlimited exposure.
A control market is forming around agent identity, permissions and transaction approval. Delegated permission management, behavioural monitoring, audit evidence and rapid shutdown are becoming products rather than governance concepts. They have to operate at machine speed because the agent does.
The commercial upside depends on giving agents enough power to matter. An agent that can only recommend may save research time. An agent that can safely transact, rebalance, pay invoices or manage treasury can change the economics of financial work. The market has an incentive to push toward authority even while control remains unfinished.
Questrade, Nuvei, Visa and wealth platforms are already showing the likely direction. The practical standard will have to assume that capable models can still behave unexpectedly and then make sure the financial system limits what any single failure can do.
Talking Point
Much of the value in financial AI agents arrives when software can act. Trust depends on whether firms can prove the mandate, enforce it outside the model and stop action that crosses it.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
August 28, 2026 | NCFA Market Activity + Insight | Capital Markets And Market Infrastructure, Risk Compliance And Regtech, Regulation And Policy, Wealthtech Investing And Trading

On August 28, 2026, the Commodity Futures Trading Commission penalized Gabriel Perez for prediction market insider trading after finding that he used confidential presidential speeches to trade event contracts for his own benefit. Perez worked as a White House technical adviser and teleprompter operator, which gave him access to prepared remarks before President Donald Trump delivered them.
Perez generated US$107,539.02 in profits by trading contracts on words and phrases the President would mention. He must return those profits, pay a US$65,000 civil penalty, stop violating the Commodity Exchange Act and stay out of CFTC regulated trading for three years. Perez consented to the settlement without admitting the CFTC's findings or legal conclusions, and the Commission says his cooperation justified a substantial reduction in the civil penalty. The CFTC also thanked KalshiEX for assisting the investigation.
As event contracts attract more volume, products and mainstream distribution, exchanges need to do more than price outcomes and settle trades. They need credible ways to identify when someone may know the answer before everyone else.
A mention market lets traders take a Yes or No position on whether a word, phrase or term will appear during a defined event. Perez opened his Kalshi account on December 8, 2025 and traded markets tied to presidential speeches, including addresses, rallies, policy remarks and the State of the Union.
The CFTC order says Perez generally saw prepared remarks about an hour before the President spoke. He bought Yes contracts when the target word appeared in the speech and No contracts when it did not. On one occasion, he changed his position after watching the President skip part of the prepared text.
Perez traded across 14 presidential mention markets and made money on 39 of 43 contracts. He was not making a better forecast than other traders. He had already seen the prepared remarks and knew whether many of the words being traded were present.
Traditional financial markets already deal with executives, advisers and employees who may hold valuable information before investors receive it. Event contracts can create a much wider group of people with direct knowledge of an outcome. A political speech can involve writers, production staff, government employees and technical crews, while sports, entertainment and corporate events can involve players, coaches, producers, employees, advisers or others close to the result.
That risk was visible before federal enforcement arrived. Kalshi's earlier insider trading cases included a MrBeast editor and a California political candidate, and the exchange said it had opened roughly 200 investigations or probes. Those cases showed that integrity work was already becoming part of running an event market. The Perez action is more consequential because the CFTC is now applying federal commodities law directly to misuse of confidential information in prediction market contracts.
The integrity problem can also extend beyond advance knowledge. Some traders may know an outcome early, others may be able to influence it, and some may hold information through a public duty or private relationship. That makes the source of the information as important as the trade itself.
The CFTC order and what the public record shows is that investigators could connect Perez's account, government role, speech access, trading times and profits. For prediction markets, knowing who is behind an account matters as much as spotting an unusual trade.
Traditional surveillance remains important. Exchanges can look for unusual profits, concentrated positions, repeated success, trading immediately before an event and activity that doesn't fit a customer's normal behaviour. Prediction markets add another requirement because suspicious trading may only make sense once the account is connected to a job, relationship or source of access outside financial markets.
A trader repeatedly winning presidential speech contracts becomes far more interesting if the exchange or regulator also knows that person works on presidential events. The same logic applies to sports personnel trading injury or lineup contracts, employees trading corporate outcomes or production staff trading entertainment events.
Exchanges need to know who is trading, what access they may have to the event and whether their trading pattern fits that access. Reliable customer identity, account history and information about relevant jobs or relationships can help investigators decide whether an unusual trade deserves a closer look. Surveillance teams need tools that can connect trading patterns with occupations, relationships and event access. Case management, alert review and auditable investigation records become more important as the number of contracts and traders grows.
This boosts the commercial case for regulated event contract infrastructure. Market surveillance, identity controls, outcome verification, compliance workflows, investigation tools and regulator reporting are becoming part of what platforms need to operate credible markets, alongside matching, pricing and settlement.
Different contracts also require different surveillance assumptions. An inflation contract settles on a formal public release. A presidential mention contract may depend on a speech seen by staff shortly before delivery. A sports contract can depend on injury or lineup information known to a relatively large group before the public learns it. Exchanges need to understand how each event is produced, who may know the answer early and who can influence the result before they can decide what suspicious trading looks like.
Prediction markets are reaching customers through larger financial platforms, which brings more liquidity but also more accounts and more activity to monitor. Recent CSA and CIRO guidance on prediction markets keeps sports and entertainment event contracts outside Canada's securities dealer channel, while Wealthsimple Investments and Interactive Brokers Canada can offer a narrower set of economic, environmental and financial contracts under CIRO conditions.
The CFTC case also shows that regulators are prepared to use existing commodities rules when confidential information is abused. Exchanges and distributors therefore need to spot suspicious activity early, connect it to useful account information, investigate it and keep records that can support enforcement.
That creates a practical market for surveillance, identity, behavioural analytics and case management tools. Prediction markets have already proved they can attract products, liquidity and mainstream distribution, but can market integrity keep up.
Can prediction markets scale faster than their ability to detect who knows the outcome before everyone else?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
August 26, 2026 | NCFA Insight | Regulation And Policy, Artificial Intelligence And Data, Risk Compliance And Regtech, Competition And Market Structure

On August 26, 2026, U.S. attorneys general announced a settlement with Meta worth up to US$17.1 billion over allegations that Facebook and Instagram were designed to keep children and teens engaged despite risks to their health and well-being. If the court approves the agreement, Meta also has to limit how long minors can use its apps, restrict overnight access and school-hour notifications, strengthen age checks and give families more control over what young users see.
Meta isn't required to admit it did anything wrong under the settlement. It does expect to record an approximately US$10 billion legal expense in Q3 2026. Governments aren't only extracting billions from Meta. They're putting enforceable limits on features that help determine how often young people open Facebook and Instagram, how long they stay and what keeps them scrolling.
Users under 18 will start with a combined two-hour daily limit across Facebook and Instagram. Parents can approve more time, but teens can't simply turn the limit off themselves. Meta also has to block most access from midnight to 6 a.m. by default and mute most notifications during school hours.
The agreement goes deeper. Teens get regular break prompts and more control over personalized feeds, autoplay and visible like counts. Meta also has to strengthen age assurance, identify children under 13, improve parental controls and maintain protections against harmful content and unwanted adult contact.
Recommendations, notifications, autoplay and frictionless consumption help technology companies turn attention into usage, retention and advertising revenue. That's why the settlement is strategically important. A feature can be commercially valuable for years and still become expensive if evidence eventually shows that the same behaviour driving engagement is contributing to harm.
NCFA's Algorithms Go On Trial As AI Scales Across Society unveiled the lawsuits challenging recommendation systems, infinite scroll, autoplay and notifications as deliberate product choices rather than simply arguing about what users post. Those cases have now produced jury findings, large financial awards and operating restrictions. The debate over addictive design is becoming much harder for boards to leave with legal counsel or the product team.
Meta can afford the settlement though. The company earned enough to absorb an approximately US$10 billion quarterly legal charge without changing the financial guidance it gave investors in July. Markets also reacted positively after the settlement was announced, reflecting relief that Meta avoided the potentially larger uncertainty of continuing the federal trial.
That is precisely why boards should study what happened.
Years of complaints, research, lawsuits and internal evidence accumulated around the same basic concern: were Facebook and Instagram using product features to keep children engaged in ways that could harm them? The exposure grew from a difficult policy issue into jury verdicts, court-ordered controls and now one of the largest state settlements ever reached with a single company.
August coverage of the New Mexico Meta ruling showed how quickly the consequences were already expanding. That case combined a US$375 million jury award with a further US$567 million abatement fund and requirements affecting teen usage, notifications, age assurance, adult contact and AI chatbot interactions involving minors.
If management keeps getting signals that a profitable feature may be harming young users and keeps pushing it anyway, the issue eventually belongs with the board. Investors should know when those warnings reach directors, what they’re told and who can decide that the revenue is no longer worth the risk.
Meta also negotiated an unusually strategic feature into the settlement.
Its own disclosure describes an approximately US$18 billion payment structure over ten years. About US$12.7 billion is allocated to participating states regardless of what competitors do. Roughly US$5.3 billion is released only if both TikTok and YouTube adopt specified teen protections and make matching payments.
That gives Meta billions of reasons to bring its competitors along.
Commercially, the logic makes sense given the amount of competition. If Facebook and Instagram restrict teen usage while TikTok and YouTube remain more permissive, users and coveted 'attention' can migrate to competing apps. Meta bears the cost while rivals gain more opportunity to capture the hours, content consumption and advertising inventory Meta gives up.
The terms get tougher if TikTok and YouTube participate. Meta's daily limit falls from two hours across Facebook and Instagram to one hour per app, while its nighttime block expands from midnight to 6 a.m. to 10 p.m. through 7 a.m.
So Meta isn't simply asking competitors to copy its safety policies. It is trying to prevent child-safety rules from becoming a competitive handicap carried mainly by Facebook and Instagram.
TikTok and YouTube haven't agreed to the framework. Until they do, Meta could still end up operating under restrictions its largest rivals don't share.

Concern about how digital products affect children has been building for years. In 2023, NCFA analyzed Canadian research into children's privacy and consent that called for stronger safeguards to be built into digital products from the start. Children don't assess consent, persuasive design or data collection the way adults do, yet personalization and recommendation systems routinely influence what they watch, read and do next.
Meta's settlement gives those concerns a much larger financial consequence. Governments are no longer relying only on warnings or disclosure requirements. They are specifying age checks, usage limits, notification controls, parental oversight and independent monitoring.
Once those requirements appear in a multibillion-dollar agreement, other platforms know what regulators may ask for next. The settlement doesn't create legal precedent, but it gives attorneys general a detailed set of measures they can use in future negotiations and enforcement.
AI companions and conversational assistants can respond personally, remember context and keep conversations going. Research into youth use of AI reported that 72% of teens had tried AI companions and examined evidence of young people using generative AI for emotional and mental health support.
AI can change the type of exposure a child experiences. A recommendation feed influences what a young person sees next. An AI system can respond directly, adapt to the conversation and encourage the user to keep engaging.
For companies serving children or vulnerable users, it's even more important to know what the system is encouraging, where harmful patterns are appearing and who can change the product when the interaction becomes uncomfortable.
The same principle can be seen in fintech where younger customers use digital wallets, investing apps, financial education tools and AI assistants. Meta's settlement rules don't apply to those products. The relevant lesson is that companies need to understand how their own systems influence behaviour before a regulator or court does it for them.
Meta's US$17.1 billion settlement shows how expensive the problem can become when concerns about engagement, harm and product design build for years without a convincing response.
When a company knows a profitable engagement feature may be harming young users, who should have the authority to decide when growth has gone too far?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
August 25, 2026 | NCFA Insight | Digital Identity And Trust, Cybersecurity Fraud And Financial Crime, Risk Compliance And Regtech

On August 25, 2026, Vancouver based Fobi AI launched Fobi AltID 3.0, expanding its digital identity technology beyond credential verification. Fobi says the new platform can continuously authenticate a verified person, confirm authorization and use satellite positioning to add location and time to the decision. Financial services and customer identity checks are among its intended uses.
The existing Fobi digital identity wallet focuses on proving identity or age while limiting how much personal information needs to be shared. The new proposition goes further. Once someone has been verified, Fobi wants the credential to keep helping organizations decide whether the right person is still present and allowed to complete an action.
That addresses a real financial control problem. Verifying someone when an account is opened does not prove that the same person still controls a session months later, approved a particular payment or gave software permission to act for them. The gap gets wider as financial services automate more activity.
The launch names financial services as a target market but doesn't identify a bank, credit union, payment company or financial pilot. It also doesn't explain how an AI agent would be given, restricted or stripped of authority. Those are important boundaries between the product Fobi has launched and the larger trust infrastructure it wants to build.
This approach already has support in established digital identity practice. NIST continuous authentication guidance allows organizations to monitor characteristics such as behaviour, device information, location, timing and network activity after a user has logged in. Suspicious changes can trigger another identity check or end the session.
For financial firms, that can add protection without repeatedly asking customers to upload identity documents. An account can remain usable while the service watches for changes that make the current activity look less like the person who was originally authenticated.
Fobi adds location to that decision. The company says satellite positioning can connect a verified person with where and when an interaction occurs. Location can strengthen a risk decision, but Fobi has not disclosed the positioning technology, accuracy or protections against false location data. NIST also treats geolocation as one piece of a wider risk assessment rather than proof of identity on its own.
More monitoring also creates more privacy responsibility. Behaviour, devices and location can all reveal sensitive information. NIST requires those uses to be included in privacy risk assessments. Fobi says the personal information used for the original verification can be removed from the ongoing process, but further disclosure is needed to show what the platform continues to observe and retain.
Canada is dealing with the same combination of identity, consent and security as financial data becomes easier to share. The proposed Canada Open Banking and Consumer Driven Banking Rules bring authentication, consumer permission, security and evidence of authorization into the same operating framework. Persistent digital identity becomes more useful when those controls have to work after onboarding rather than only at the beginning of the relationship.
AI agents make the distinction between identity and authority easier to see. A bank may know who owns an account and still need to know whether software has permission to spend $500, change an instruction or continue acting tomorrow. AI agents with wallet access increases the urgency of defining what software can do, for how long and on whose authority.
Payment networks are already building controls around that problem. The Visa Trusted Agent Protocol lets merchants verify that an AI agent is legitimate and has permission to act for a customer. Visa's specifications also allow merchants to limit an agent to a specific purpose, such as browsing or making a payment.
Mastercard Verifiable Intent, developed with Google, records what a person authorized before an AI agent acts. Mastercard is designing it to work across wallets, platforms, payment networks and different agent systems.
The same convergence appears in the FCA Emerging Technology Horizon Scan 2026, where digital identity, AI agents, consumer control and programmable finance intersect. For fintechs, the opportunity goes beyond proving who somebody is toward proving what a person or piece of software is allowed to do.
Open digital credentials could make those permissions easier to carry between services. The W3C digital credential standard provides a common way to issue and verify secure, privacy respecting credentials. Fobi has not disclosed whether its new platform supports that standard or another open identity framework. Interoperability is necessary if the technology is expected to work across banks, fintechs, payment networks and other organizations rather than mainly inside Fobi's own products.
Fobi is also positioning post quantum security as part of the platform. Financial firms are already preparing for post quantum cryptography as new security standards replace encryption that future quantum computers could threaten. Fobi has not identified which algorithms or standards it uses, or provided independent technical validation. For now, quantum readiness remains a product claim that still needs evidence rather than the main reason to assess the launch.
The more immediate opportunity is digital trust. Identity can establish the person. Ongoing authentication can flag when something changes. Authorization can control what a person or AI agent is allowed to do. Those capabilities also connect digital identity, cybersecurity and automated finance across the Financial Innovation Map.
Fobi now has to prove that its technology can join those pieces in practice. A financial institution deployment, support for open credentials or documented controls for delegated authority would make the case much stronger. Until then, the launch is a credible expansion of Fobi's digital identity technology into a financial problem that is becoming harder as software gains more authority.
As AI agents gain access to payments, financial accounts and digital credentials, will proving identity once be enough, or will financial services need to keep verifying who is in control and exactly what they are allowed to do?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |