Karsten Wenzlaff, Advisor
August 26th, 2025
AI Innovation | Sep 24, 2025

Image: Freepik
On September 16, 2024, Counterforce Health reported that U.S. platforms are using artificial intelligence to help patients appeal denied health insurance claims by analyzing rejection letters and generating tailored responses at scale.
The rise of AI powered tools is a growing insurtech trend where technology is being used to challenge entrenched industry practices that unfairly hurt consumers. For NCFA's community, the story raises important questions about where AI could play a similar role in our own insurance markets.
Let's look at the data to better understand the scope of the problem. In 2021, insurers on the federal HealthCare.gov marketplace denied about 17% of in network claims. These are services from doctors and hospitals already under contract with the insurer, showing that even approved providers faced a high denial rate.
Yet fewer than 0.2% of these denials were appealed, despite nearly 59% of appeals being successful when filed.
Separate research from the American Medical Association found that prior authorization denials are overturned more than 80% of the time when challenged, but only a small share of patients ever appeal.
The above figures point to a structural imbalance where insurers rely on consumers giving up. By automating appeal letters with expertly assessed supporting evidence, AI systems are changing the game.
Canada’s universal healthcare system means most core medical services are covered publicly, so denials are less about hospital visits or surgeries and more about supplemental benefits such as prescription drugs, dental care, physiotherapy, and other extended health services. Private insurers play a major role in these areas, and disputes are common.
What Canada lacks is transparent national reporting on denial and appeal rates. Unlike the U.S. system where denial data is published for marketplace insurers, Canadian insurers are not required to release such information. The limited statistics that do exist come from independent research or regulator snapshots, which highlight problems but don't provide a complete national picture. This lack of transparency creates a barrier to accountability and also an opportunity for Insurtech innovators.
Even without standardized national data, the available evidence shows that denial issues are widespread across several types of insurance:
Disability insurance denial rates are high. For example, about 60% of Canada Pension Plan disability applications are rejected, a figure that highlights the steep barriers claimants face, even if it is not directly comparable to private disability insurance.
In Quebec, 20% of critical illness and life insurance claims are denied according to the Autorité des marchés financiers. Disputes often stem from exclusions or non-disclosure clauses.
Extended health and drug benefits. Expensive specialty drugs and therapies are frequently denied as “not medically necessary” or outside policy coverage. Appeal processes can be slow and opaque.
Accident benefit disputes are frequent, especially with auto insurance in Ontario. The provincial tribunal system handles thousands of contested denials each year. AI insurtech solutions could help provinces reduce backlogs and streamline case processing.
Property insurance denials are common enough. Regulators report that property insurance denial ratios are around 16%, with most rejections tied to lack of coverage.
For fintech and Insurtech players, the opportunity spams the broader insurance ecosystem. AI could provide consumers with tools to navigate opaque processes, improve transparency, and reduce the cost of disputes.
Regulators have already outlined pan-Canadian guiding principles for responsible AI in health systems (Health Canada), establishing an innovation framework that balances fairness and accountability.
With insurance denial data so limited in Canada, new platforms that integrate appeals with data collection could simultaneously drive consumer protection and market competitiveness.
Denial data transparency can expose inefficiencies between insurers and individuals and AI solutions can help rebalance power. While Canada’s insurance system is structured differently than the U.S., denial disputes are still widespread and certainly costly in terms of time and money for stakeholders.
Fintechs and insurtech innovators should view this is a market opportunity while also protecting consumers. Canada can either wait for U.S. platforms to cross the border, or develop homegrown solutions that lead in fairness, transparency, and competitiveness.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create aa vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Cybersecurity | Sep 23, 2025

Image: Freepik/DC Studio
On September 18, 2025, researchers at Radware disclosed a zero click indirect prompt injection called ShadowLeak that caused ChatGPT Deep Research to leak Gmail data after it encountered a booby trapped email. It's a new class of risk where hidden instructions can manipulate agents while being invisible to users, so NCFA wants to ensure that fintechs and key stakeholders are aware of how attackers can turn AI helpers into data thieves in a way that users including developer's can't see.
Radware’s analysis shows that the leak originated from OpenAI’s own cloud infrastructure rather than a user’s device. A malicious email carried hidden HTML instructions such as white text on a white background. When the user later asked the agent to summarize emails, the agent followed the invisible prompt and sent private details to an attacker controlled URL.
Because the action happened in the cloud, the victim’s network defenses never saw it.
The researchers warned that the same trick could work on other connectors including Google Drive, Dropbox, Outlook, calendars, and GitHub. That means sensitive business data such as financial contracts, HR records, and meeting notes could also be exposed.
Radware reported the issue on June 18, 2025. OpenAI deployed fixes by early August and closed the case on September 3. An OpenAI spokesperson told Recorded Future News that the company continually improves safeguards against exploits like prompt injections.
ShadowLeak is not the only case of an AI agent being manipulated into acting against its user.
At Black Hat in August 2025, researchers demonstrated an attack called AgentFlayer that used a poisoned Google Drive document to leak secrets through ChatGPT connectors. The document contained hidden instructions that looked harmless to a person but were machine readable. When the agent processed the file, it followed the malicious prompt and attempted to extract sensitive data.
On August 20, 2025, security researchers at Brave (website browser company) disclosed a similar flaw in Perplexity’s Comet browser. They showed how a hidden Reddit prompt could read Gmail one time passcodes and expose them to an attacker.
On September 13, 2025, Tom's Hardware wrote about a malicious Google Calendar invite method could steer ChatGPT agents with connectors enabled to leak sensitive data, again by embedding hidden instructions in content that appears ordinary to the user.
From Radware’s advisory and government sources such as the U.S. National Institute of Standards and Technology, here are some suggested practices.
AI agents are being connected to sensitive systems at a time when fintech firms face increasing scrutiny over privacy and security.
If a connector exploit can quietly leak contracts, loan records, or customer identifiers, the implications are massive, such as regulatory fines, reputational loss, and reduced trust from partners and investors.
In Canada, where regulators are preparing rules on open banking and digital identity, firms cannot afford to treat agent security as an afterthought. Research shows that 57% to 80% of injection attempts succeed when attackers repeat them (i.e. 25 times), which is why layered defenses are essential.
Banks and financial technology firms must implement agent safeguards into compliance frameworks, risk models, and vendor contracts that will protect customer trust and reduce liability. Canadian fintechs should approach agent security not only as a technical concern but part of core competitiveness functionality.
Board oversight is also critical, as regulators and investors will expect firms to demonstrate how they manage AI risks.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create aa vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Cybersecurity | Sep 17, 2025
Image: Freepik/Rawpixel.com
On September 17, 2025, the Canadian Investment Regulatory Organization (CIRO) confirmed through a detailed FAQ that registration data of all current and former registrants had been compromised in the cybersecurity incident first detected on August 11. The regulator emphasized that Social Insurance Numbers and credit card data were not affected, but a wide range of personal and professional registration information was exposed.
CIRO is Canada’s national self-regulatory body for investment dealers and mutual fund dealers, overseeing trading activity across Canadian debt and equity marketplaces. Its mandate is to protect investors, support fair and efficient markets, and maintain trust in Canada’s financial system. The incident underscores that cyber risk is a critical challenge not only for the firms CIRO supervises but also for regulators themselves.
According to CIRO’s official updates regarding the cyber breach incident:
On August 11, CIRO identified the cybersecurity threat and shut down systems as a precaution
On August 17, preliminary investigation showed that some personal information of member firms and their registered employees was affected. CIRO acknowledged the seriousness of the breach and pledged to notify those impacted and provide risk mitigation services
On August 18, CIRO confirmed in a public update that it was working with external cybersecurity experts, legal counsel, and law enforcement. It also stressed that Canadians’ investments were not at risk
On August 28, CIRO announced that access to its systems had been restored, including CIRO Services, COMSET, CERTS, the Mutual Fund Dealers Member-only Site, EFS, MTRS, and Corporate and Government Debt Trading Information. CIRO reminded firms of their regulatory reporting obligations, granting five business days after notification to file reports that were due during the outage, while requiring timely submissions for all obligations due September 2 or later.
On September 9, CIRO confirmed that registration information of member firms and registered individuals was breached. The regulator began contacting all impacted individuals directly, offering two years of free credit monitoring and identity theft protection through TransUnion and Equifax. CIRO also clarified that emails from ciro@cyberscout.com or ciro@m.cyberscout.com are legitimate. In its update, CIRO issued an apology and promised to continue providing updates as the investigation progresses.
On September 17, CIRO released an FAQ update on the cybersecurity incident, now confirming that the August 11, 2026 breach affected registration data of all current and former registrants.
What data was exposed
Not included in the breach was Social Insurance Numbers and credit card or other payment information.
National Registration Database (NRD) - CIRO confirmed that the NRD system itself was not breached. The incident only involved registration information that CIRO maintains.
Notification process - CIRO began sending notifications on September 9. If an email is on file in the NRD, individuals will receive a message from ciro@cyberscout.com.
CIRO stated that personal information connected to member firms and registered employees was impacted by the incident. As part of its response, the regulator is offering two years of coverage through Equifax and TransUnion. CIRO confirmed that it only receives a limited sample of investor information through compliance functions, and emphasized that Canadians’ investments are not at risk. If any investor information were determined to be affected, CIRO committed to notify them directly and provide support.
CIRO has issued a clear warning that it will never contact registrants about this event through unsolicited phone calls or emails requesting personal or financial information. This message is designed to protect registrants from potential phishing attempts that may exploit news of the breach.
CIRO is contacting all impacted registrants directly by email or mail. Each individual will receive a letter signed by CIRO and sent by TransUnion with instructions and an access code to register for free protection services. Registrants should consider:
No organization is immune from cyber attacks, including those tasked with overseeing the integrity of markets. The investigation remains ongoing. CIRO has pledged to provide further updates as more details emerge. Market participants and stakeholders will be watching closely how the regulator continues to manage the response and what additional measures are introduced to safeguard sensitive information.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create aa vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Mental Health | Sep 17, 2025
Image: Freepik/Rawpixel.com
On September 17, 2025, CBC news published a sobering story of the growing number of Canadians who have reported mental health crises linked to prolonged conversations with AI chatbots. Some are describing these cases as a type of artificial intelligence induced psychosis. NCFA is covering this article in hopes to provide Canadian mental health resources to support those struggling with AI related mental health issues.
Everyone is at risk who interacts with AI for prolonged periods of use. If you think you are immune, think again. The B.C. Psychosis Program warns that chatbots can reinforce delusional thinking rather than challenge it. Community-led Canadian efforts are building support resources and ethics workstreams.
Toronto developer Anthony Tan believed he was living inside a simulation and was hospitalized after weeks without sleep. He later launched the AI Mental Health Project to support those struggling with similar issues.
Allan Brooks of Ontario spent over 300 hours with ChatGPT, convinced he had discovered a breakthrough mathematical theory. When his delusion collapsed, he co-founded the Human Line Project, which now connects more than 125 people with similar experiences.
International reporting shows similar risks. Parents testified to Congress about teen suicides after chatbot interactions, as covered by CBS reporting. OpenAI has announced age verification plans following a lawsuit involving a 16 year old.
Research indicates a tendency for language models to mirror user beliefs. Researchers at Anthropic published a study, 'Towards Understanding Sycophancy in Language Models" (see Anthropic's research summary).
Data driven evidence shows that chatbots often agree with users, even when it ignites harmful thinking. To prevent this, financial AI tools should be designed to test ideas against reality, point users to verified and transparent external information, and clearly signal when content is speculative.
Fintech firms also need to be transparent about safety. They should publish regular audits that show how their systems respond to emotionally sensitive conversations and what safeguards are in place.
Industry can also demonstrate leadership by creating a code of ethics that directly addresses mental health risks. This voluntary framework should include independent reviews and compliance checks, building on the kind of work already happening through community groups like the Human Line Project.
Regulators however should avoid blanket restrictions that could slow innovation. Instead, oversight should be based on the level of psychological and financial risk, ensuring protections are strong where they need to be while leaving room for responsible growth.
As fintech platforms increasingly adopt AI for customer service and advice, trust remains critical, and if broken adoption will slow and regulatory scrutiny will intensify affecting the competitiveness and growth outlook.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create aa vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Data Breach | Sep 9, 2025
Image: Freepik/Rawpixel.com
On September 5 2025, Wealthsimple (WS) confirmed that a data security breach occurred on August 30. The company emphasized that it “acted quickly and in a few hours the issue was contained. Our security team, with the help of external experts, immediately began a thorough investigation.”
The breach exposed sensitive personal data including contact details, government IDs submitted at signup, financial account numbers, IP addresses, Social Insurance Numbers, and dates of birth.
All accounts remain secure, and “no funds were accessed or stolen. No passwords were compromised… All accounts remain fully secure.” Less than 1% of clients were impacted out of WS's client base of about three million.
The breach resulted from a compromised component in a third party software package described by the company as “written by a trusted third party”. Wealthsimple confirmed the incident was not linked to any Salesforce breaches circulating in the media.
They said, “We learned that a specific software package had been compromised.” No attackers have been publicly identified, and the specific vendor has not been disclosed.
Wealthsimple detected the compromise on August 30 and contained it within hours. By 10:30 AM EST on September 5 the company had emailed all affected clients and published its public update in the Help Centre at 14:43 ET. The statement included: “If you did not receive an email from us about this, your data was not impacted.”
Wealthsimple is offering every impacted client two years of free credit monitoring, dark web monitoring, identity theft protection, and insurance. Regulators and law enforcement were notified in alignment with standard protocols.
According to the PR statement that Wealthsimple provided NCFA Canada with:
"We apologize for this incident, which happened as a result of a third-party vulnerability. We informed impacted clients as quickly as possible and set up complimentary credit and dark web monitoring, as well as identity theft protections. Significantly less than 1% of our clients were affected. We’re continually strengthening our security infrastructure and have already made improvements to prevent this type of issue from happening again."
Wealthsimple confirmed that improved protections have been implemented to better protect against similar threats.
While technical details weren't disclosed, the breach confirms that even the most advanced fintech platforms are only as resilient as their weakest external link (AKA supply chain risk).
Fintech firms must treat vendor risk management with the same rigor applied to their in house systems, including rigorous assessments of third party dependencies, continuous monitoring of software integrity, well rehearsed incident response plans, and transparent communication with clients and regulators.
For policymakers and regulators, the incident raises important questions about oversight. How can industry standards for supply chain risk be established and enforced before breaches occur?
Trust is the most vital currency. Companies of all sizes must ensure that every link from internal databases to external software is secure to protect clients and preserve consumer and business confidence.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create aa vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Economy and Policy | Aug 25, 2025

Nearly three decades ago, Carl Sagan warned in The Demon-Haunted World (1996) that when technological power is concentrated in a few hands and public institutions lose expertise, societies risk “sliding, almost without noticing, back into superstition and darkness.”
On Aug 22, 2025, Andrea Bonime-Blanc in a LinkedIn post discusses how recent U.S. federal budget cuts and policy changes are accelerating a “brain drain” of scientific and economic expertise. This article looks at the business impacts and implications for fintech of the significant human capital and policy changes taking place in the U.S. and how Canada and other collaborative countries should be responding.
The departure of experts at the Bureau of Labor Statistics (BLS) erodes confidence in U.S. economic indicators that businesses and markets rely on.
- President Trump fired BLS Commissioner Erika McEntarfer on August 1, 2025 after controversy over jobs report revisions
- The July 2025 jobs report showed 73,000 jobs gained and revisions down of 86,000 in May and 64,000 in June
- In July 2025 only 58% of employers answered the U.S. government’s payroll survey, which normally tracks over 120,000 workplaces. With so few responses, the jobs numbers are less reliable and more likely to be revised
Takeaway: 👉 For fintech lenders and investment platforms that depend on U.S. labor and wage data, model uncertainty and risk costs may increase.
Cuts to cybersecurity agencies increase systemic risk for payments and banking networks, and weaken the ability to build secure AI systems.
In 2025, the main federal agency that protects critical infrastructure including finance, energy, and healthcare, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), had about $3 billion in funding and just over 3,600 staff. These resources cover everything from monitoring threats to helping banks and utilities recover from cyberattacks. Lawmakers are now weighing a $135 million cut to CISA’s 2026 budget or equal to about 4.5% of its funding. On paper it may sound small, but it reduces the agency’s ability to share intelligence, build new defenses, and support partners in both the public and private sectors.
Takeaway: 👉 Reduced federal cyber capacity raises exposure for cross-border fintech systems.
Environmental and climate science cuts reduce access to datasets critical for insurers, lenders, and ESG related products.
- EPA workforce cut from 16,155 in January 2025 to 12,448 , a 23% reduction with closure of its scientific research division
- NOAA terminated staff for its Climate.gov portal on May 31, 2025, halting new content
- NOAA seeks a 17% workforce cut after firing hundreds of probationary employees in early 2025
Takeaway: 👉 For fintech ESG products, fewer trusted U.S. datasets could degrade climate related financial models. Canada can step in with trusted open-data collaborations.
Graduate students and researchers face reduced U.S. funding, pushing talent abroad.
- PBS reports that at least 17 immigration judges were fired across 10 states in July 2025, adding delays to skilled worker case processing
Takeaway: 👉 Processing delays affect STEM talent inflows. Canada could capture this talent to strengthen fintech innovation by accelerating recruitment by offering scholarships, innovation hub partnerships, and fast-track visas.
Federal compliance and AI governance structures are weakening, raising trust issues.
- Elizabeth Kelly the inaugural director of the U.S. AI Safety Institute departed in February 2025 leaving a leadership vacuum
Takeaway: 👉 With U.S. leadership unsettled, Canada and the EU can shape AI assurance frameworks for fintech. Canadian regtech firms are well positioned to step up and help lead.
Canada needs to open up the country as a trusted hub for financial data integrity, cyber resilience and AI governance by focusing on the following practical steps:
- Map out data sources and diversify away from over reliance on U.S. federal inputs
- Invest in AI enabled cybersecurity and fraud detection systems
- Explore alternative and open-source data partnerships to fill data gaps (NGOs, universities, private market collaborations)
- Support STEM students and researchers displaced by U.S. funding cuts
- Build compliance and governance tools that embed transparency into fintech systems
The U.S. brain drain is visible in staff firings, layoffs, budget cuts and agency closures and contractions. Carl Sagan’s caution from 1996 reminds us that losing expertise erodes both science and democracy. By investing in data integrity, global standards, and fintech innovation, Canada can transform today’s U.S. retreat into a foundation for stronger, competitive growth. This is a chance for Canada to step up and lead.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |