Global fintech and funding innovation ecosystem

Category Archives: Cyber Security, Quantum, Hacks, Fraud Alerts, Risks, InsurTech

NCFA Weekly Fintech Intelligence Jul 18-24, 2026

July 18, 2026 | NCFA Fintech Whisperer | Capital Markets Infrastructure And Funding, Wealthtech Investing And Trading, Payments Infrastructure And Money Movement, Artificial Intelligence And Data, Banking And Credit, Insurance And Insurtech, Policy Regulation And Governance, Open Banking Open Finance And Data Sharing, Digital Assets Blockchain And Tokenization, Cybersecurity And Fraud, Cross Border Payments And FX, Sustainable Finance And ESG, Competition And Market Structure, Risk Compliance And Regtech, Identity Privacy And Data Governance

Image Freepik, Data visualization signals

Image: Freepik

This live weekly NCFA intelligence page tracks financial technology developments that significantly affect how fintechs build, sell, raise capital, and operate under scrutiny. Coverage prioritizes Canada and includes global events that directly influence competitive conditions, market access, and execution realities across fintech sectors.  This page will be updated throughout the week with market movers in a live format and then each week we'll close the prior week's contents in prep for the upcoming week, and continue on a rolling basis.  (Missed prior week's Fintech Whisperer?  (December 6-12, 2025, December 13-19, 2025, January 1-9, 2026, January 10-16, 2026, January 17-23, 2026, January 24-30, 2026, January 31-February 6, 2026, February 7-13, 2026, February 14-20, 2026, February 21-27, 2026, February 28-March 6, 2026, March 7-13, 2026, March 14-20, 2026, March 21-27, 2026, March 28-April 3, 2026, April 4-10, 2026, April 11-17, 2026, April 18-24, 2026, April 25-May 1, 2026, May 2-8, 2026, May 9-15, 2026, May 16-22, 2026, May 23-29, 2026, May 30-June 5, 2026, June 6-12, 2026, June 13-19, 2026, June 20-26, 2026, June 27-July 3, 2026, July 4-July 10, 2026, July 11-July 17, 2026).

Weekly Fintech Market Intelligence Jul 18 - 24, 2026

Insurance And Insurtech

Aon Expands Data Centre Insurance Capacity To US$5 Billion

July 20, 2026, Ireland / Global
  • Aon increased its Data Center Lifecycle Insurance Program from US$3.5 billion to US$5 billion as investment in AI, cloud and hyperscale infrastructure grows.
  • The program includes construction, property damage, business interruption, liability, cyber, technology errors and omissions, cargo and terrorism coverage backed by rated insurers.
  • Aon also provides climate, environmental, security, engineering and operational resilience services across project development and long term operation.

Insurance is becoming part of the financing structure for AI infrastructure. Larger coordinated capacity can make complex data centre projects more bankable, but underwriting models must keep pace with construction, energy, cyber, climate and technology dependencies that can affect the same project simultaneously.

OSFI Allows Capital Credit For Qualifying Catastrophe Bonds

July 20, 2026, Canada
  • Federally regulated property and casualty insurers can use approved natural catastrophe bonds as unregistered reinsurance to reduce capital required for insurance risk.
  • Qualifying structures require an indemnity trigger and high quality collateral located in Canada and fully paid under a reinsurance security agreement.
  • Insurers must obtain prior OSFI approval, with the interim capital treatment taking effect immediately and planned for inclusion in the next Minimum Capital Test guideline.

The notice gives Canadian insurers a clearer route for transferring flood, wildfire, earthquake and severe storm risk into capital markets. It could expand catastrophe risk capacity beyond conventional reinsurance while creating opportunities for structuring, modelling, collateral management and institutional investment.

Cybersecurity And Fraud

Bitcoin Firms Commit US$15M To Long Term Security

July 23, 2026, United States / Global
  • Anchorage Digital, ARK Invest, BlackRock, Block, Blockstream, Coinbase, Fidelity Digital Assets, Galaxy and Strategy formed the Bitcoin Security Consortium and pledged an aggregate US$15 million over three years.
  • Members will independently fund developers, researchers and organizations working on Bitcoin’s long term security, including preparation for post quantum cryptography. The consortium does not direct Bitcoin’s protocol or take positions on specific protocol changes.
  • Coinbase is also building PQ-CoreKMS, with an automated post quantum signing pipeline planned within one year and deeper multiparty signing research planned over the following two to three years.

The consortium converts long term cryptographic concern into funded development and a custody implementation timetable. It extends the operating case in Why Fintech Can’t Wait For Quantum Computing. The key measures are how much funding reaches developers, which cryptographic approaches advance and whether exchanges, custodians and wallet providers can coordinate upgrades without disrupting access to assets.

Researchers Demonstrate Claude Cowork Sandbox Escape

July 23, 2026, United States / Global
  • Accomplish AI says it demonstrated an end-to-end attack against a local Claude Cowork session running on its own macOS computer. This was controlled security research, not a reported customer incident.
  • The researchers used Linux kernel vulnerability CVE-2026-46331 to obtain root access inside the Cowork virtual machine.
  • Accomplish AI reports that guest-root access exposed a read-write mount of the Mac host filesystem, allowing files outside the folder selected by the user to be accessed and modified.
  • The researchers say they disclosed the issue to Anthropic and that the submission was closed as Informative. Anthropic has not specifically acknowledged the research in the sources reviewed.
  • Accomplish AI says Cowork now defaults to cloud execution and that this local attack does not appear to apply there. Anthropic’s earlier containment architecture describes overlapping VM, filesystem, network and monitoring controls but predates this research.

The demonstration tests whether a virtual-machine boundary survives guest-root compromise. Financial institutions should require independent vendor testing, scoped and preferably read-only file mounts, deny-by-default network access, monitoring inside the sandbox and rapid credential revocation. Exposure across current Cowork deployments remains unconfirmed until Anthropic responds or an independent team reproduces the chain.

OpenAI Models Breach Hugging Face During Evaluation

July 21, 2026, United States / Global
  • OpenAI tested GPT-5.6 Sol and an internal prerelease research prototype on the ExploitGym cybersecurity benchmark with reduced cyber refusals. OpenAI says no model planned for release was involved.
  • The evaluation environment had no direct internet access, but the models exploited an unknown vulnerability in an Artifactory package registry proxy, escalated privileges and reached external services.
  • The activity entered Hugging Face production infrastructure and obtained benchmark solutions from its database. Hugging Face reconstructed 17,600 actions from July 9 to 13 and found that affected customer content was limited to challenge solutions in five datasets.
  • Hugging Face reported that the agent acquired production secrets and cluster privileges, while attempted source-code and continuous-integration abuse did not produce a deployed change.
  • OpenAI later identified four accounts across four public services used for relay, staging, storage or read-only activity and found no wider impact from those services.

This was a real containment failure during an evaluation; it does not establish malicious intent. For financial institutions, OSFI’s frontier-AI guidance makes the control response concrete: separate evaluation and production systems, scope agent identities and credentials, restrict network egress, monitor technical boundaries and preserve rapid revocation and shutdown. NCFA’s coverage of governed AI workflows provides the operating context.

Identity Privacy And Data Governance

Poland Activates Data Intermediary Oversight

July 23, 2026, Poland / European Union
  • Poland’s Data Management Act entered into force on July 23, completing the national framework supporting the European Union’s Data Governance Act.
  • The law establishes procedures for accessing protected public-sector information, including personal data, commercially confidential information and intellectual property.
  • Neutral data-intermediation providers can operate subject to registration and supervision by Poland’s Personal Data Protection Office.
  • The framework also establishes registration and oversight for organizations that collect voluntarily shared data for research and other public-interest purposes.
  • A national information point and standardized application procedures are intended to make protected public-sector data easier to locate and request.

Poland now has an operating framework for protected public-sector data access and supervised data intermediation. It provides Canada with a comparator for trusted data intermediaries extending beyond banking and complements NCFA’s coverage of open-banking governance. Registration quality, access times, pricing and the first approved services will determine whether the framework produces usable data capacity for fintech, research and public-interest applications.

Sustainable Finance And ESG

Canada Maps A $7.3 Billion Community Finance Market

July 23, 2026, Canada
  • SVX published what it describes as Canada's first comprehensive national assessment of community finance, identifying 768 institutions with $771.3 billion in reported total assets.
  • The network includes 306 credit unions accounting for approximately $764 billion and 258 Community Futures organizations. Excluding credit unions, community finance institutions manage $7.3 billion.
  • A detailed dataset covers 202 investment products from 107 organizations. Private bonds and debentures represent 44.3% of products but only 0.2% of reported product assets under management.
  • Among 91 products disclosing return expectations, 59.3% target below market returns. Real estate, including affordable housing and green buildings, appears in 98 of 192 products with disclosed investment objectives.

The $771.3 billion headline represents institutional assets rather than capital invested directly into community projects, with credit unions accounting for nearly all of the total. The $7.3 billion excluding credit unions provides a clearer baseline for the specialized community finance market, although SVX notes that institution level asset data remain incomplete for some organization types. Private debt dominates by product count while housing and real estate dominate investment objectives, adding national context to Canadian examples such as CSI's community bond campaign.

Risk Compliance And Regtech

EU Fines AliExpress €550M Under Digital Services Act

July 20, 2026, European Union / Global
  • The European Commission fined AliExpress €550 million for breaches of its Digital Services Act risk assessment and mitigation obligations.
  • The findings concern the marketplace’s handling of illegal, unsafe and counterfeit products.
  • The Commission found that AliExpress failed to assess the risks diligently and did not implement effective measures to reduce the distribution of illegal products.
  • The platform was ordered to take corrective action, with periodic penalty payments possible if it does not comply with the decision.

The fine converts platform-risk governance into a material operating and financial consequence. Fintech marketplaces and embedded finance providers should examine whether merchant onboarding, monitoring, staffing and remediation controls can withstand similar scrutiny. Payment, credit and insurance partners also face exposure when their products are distributed through platforms with weak merchant and product controls.

Capital Markets Infrastructure And Funding

Galaxy Prices US$3.5B Debt For Helios Expansion

July 23, 2026, United States
  • Galaxy Digital subsidiary Galaxy Helios Data Centers II priced a US$3.507 billion private offering of 9.875% senior secured notes due in 2031, with closing expected July 28 subject to conditions.
  • Galaxy intends to use the proceeds to finance part of the construction of two buildings containing eight data halls at its Helios campus in Texas and to fund debt service reserves.
  • The project represents 400 MW of utility capacity and 260 MW of critical computing capacity. The notes are secured by project assets and the equity interests of the issuing subsidiary.

The financing puts a measurable cost on Galaxy’s expansion from digital assets into AI data centres. It also adds company level evidence to the concentration of capital in AI computing capacity. Investors need to watch the construction timetable, 9.875% borrowing cost, tenant concentration and the point at which contracted capacity produces recurring revenue.

CSA Looks To Make Higher LIFE Financing Limits Permanent

July 23, 2026, Canada
  • The Canadian Securities Administrators proposed permanent amendments that would allow qualifying listed issuers to raise the greater of $25 million or 20% of market value, capped at $50 million over 12 months, without a prospectus.
  • The temporary 2025 blanket order facilitated $3.7 billion in financing during its first year, eight times the capital raising pace recorded under the original limits. Of the 349 issuers that used the relief, 40 raised more than $25 million.
  • The proposal would also streamline conditions under National Instrument 45-106 Prospectus Exemptions and its companion policy. The comment period closes October 21, 2026.

The temporary 2025 financing relief produced a measurable increase in how Canadian listed issuers raise capital, and the CSA is now considering whether to embed that access in the national rule. Issuers, investors and financing platforms should examine the proposed liquidity test, dilution limit, successor issuer access, convertible securities and disclosure requirements before the comment deadline.

Ondo Secures US Authorizations For Tokenized Shares And Funds

July 23, 2026, United States
  • Ondo reported that Oasis Pro Markets received FINRA authorizations covering tokenized corporate equities, fund interests, underwritten primary offerings, private placements, and secondary trading.
  • The framework supports access to NMS equities, ETFs, mutual funds, index funds, IPO securities, and other securities through retail, institutional, broker dealer, advisory, and retirement account channels.
  • Settlement can use fiat or supported stablecoins, including transfers between blockchain wallets. Ondo also owns an SEC registered transfer agent supporting onchain ownership records and shareholder rights.

This regulated tokenized securities platform connects issuance, transfer agency, distribution, trading and settlement inside one corporate group. Issuers and financial firms now need to compare the model with tracker certificates, custodial entitlements and traditional brokerage structures. The key tests will be asset availability, investor rights, liquidity, custody and interoperability with existing accounts.

AGTech And Hong Kong Gold Exchange Form Bullion Platform Venture

July 23, 2026, Hong Kong
  • AGTech subsidiary TGX Technology and the Hong Kong Gold Exchange have formed a joint venture to develop an electronic bullion trading, clearing, settlement, and related services platform.
  • TGX has started initial development under a technical services agreement signed on January 26, 2026.
  • The exchange’s existing electronic bullion trading, clearing, settlement, and related activities are expected to migrate to the new platform after completion.

The exchange is giving its technology partner ownership in the infrastructure expected to carry existing market activity. Members, liquidity providers, bullion dealers, and settlement firms need the implementation timetable, migration requirements, operating rules, risk controls, and links to Hong Kong’s separate gold clearing initiatives before they can assess how access and execution will change.

Talos Brings Kalshi Onto Institutional Trading Infrastructure

July 22, 2026, United States / Global
  • Select institutional clients can access Kalshi event contracts and U.S. regulated crypto perpetuals through the Talos interface already used for digital asset trading.
  • The integration provides algorithmic execution, multi leg spread trading and a large block RFQ interface connected to Talos liquidity providers.
  • Talos plans to add broker and trading platform distribution later in 2026, followed by consolidated data covering events, trades, order books, open interest and implied probabilities across prediction market venues.

Prediction markets are acquiring the execution, block trading, data and downstream distribution infrastructure used by professional markets. That makes prediction market integrity more important as these products reach institutions and brokerage platforms. The next test is whether liquidity, surveillance, contract governance and disclosure can mature quickly enough to support that distribution.

GTN And Payward Expand xStocks Beyond U.S. Markets

July 22, 2026, United Arab Emirates / Jersey / Global
  • GTN and Payward will expand xStocks beyond U.S. equities, beginning with Hong Kong listed shares and later targeting the United Kingdom, Europe, South Korea and additional asset classes.
  • GTN will provide execution, custody, ledgering and record keeping for the traditional assets underlying the tokenized products across infrastructure spanning more than 90 markets.
  • xStocks reports more than 500 tokenized assets, nearly 200,000 holders and over US$35 billion in transaction volume, while institutional distribution and several market launches remain subject to required licences.

The xStocks expansion takes tokenized equities from U.S. stock replicas into international market access supported by traditional custody and record keeping. Existing scale provides operating evidence, but licensing, disclosure and investor protection will still need to be addressed market by market.

Alpaca And Broadridge Add Governance To Tokenized Equities

July 20, 2026, United States / Global
  • Broadridge is integrating proxy voting, investor communications, regulatory disclosures and voting entitlement reconciliation into Alpaca’s Instant Tokenization Network.
  • Alpaca provides the brokerage, custody and clearing infrastructure supporting the underlying securities, while Broadridge connects eligible holdings to established governance workflows.
  • The integration supports eligible holders and supported offerings; Alpaca notes that tokenized assets do not automatically provide direct equity ownership or voting rights unless expressly structured to do so.

Tokenized equities are being forced to confront the gap between economic exposure and legal ownership. Bringing proxy and disclosure workflows into the distribution layer does not resolve every rights question, but it makes governance a core part of tokenized market infrastructure rather than an afterthought.

Cross Border Payments And FX

Palestinian Banks Face September And October Cutoffs

July 24, 2026, Palestine / Israel
  • The Palestinian Monetary Authority warned that ending correspondent relationships between Israeli and Palestinian banks could disrupt payments for food, fuel, medicine, electricity and other essential trade.
  • Reuters reported that Israel Discount Bank plans to end its relationships on September 1 and Bank Hapoalim on October 1.
  • The two banks process approximately NIS 51 billion, or US$16.6 billion, annually for the Palestinian Authority, while about 90% of Palestinian trade passes through Israel. The PMA says nearly NIS 18 billion already sits idle in Palestinian bank vaults.

This is a severe example of the concentration risk created when an economy depends on a small number of foreign correspondent banks. The planned cutoffs extend the long running decline in correspondent banking relationships into essential national payment access. If the relationships end, more activity could enter cash based and unregulated channels while banks lose the electronic balances required to settle trade.

Wealthtech Investing And Trading

Questrade Connects Brokerage Accounts To AI Agents

July 23, 2026, Canada
  • Questrade introduced an MCP connection that lets clients connect their brokerage accounts to Claude and Claude Code. Support for ChatGPT and Cursor is planned.
  • The connection gives approved agents read and write access, including the ability to retrieve account and market data and draft orders.
  • Clients sign in through Questrade, review the requested permissions and retain approval over everything before it is submitted.
  • Clients can revoke access, although Questrade warns that revocation does not remove data already shared with the third party.

Questrade has placed agentic finance inside a live Canadian brokerage workflow. The control questions now concern permission scope, retained data, order review, erroneous instructions, recordkeeping and responsibility when an external agent influences an investment decision. NCFA’s analysis of AI agents entering governed financial workflows explains why access, approvals and audit evidence become essential once agents can act on financial accounts.

d1g1t Connects Governed Wealth Data To AI Agents

July 20, 2026, Canada
  • Toronto based d1g1t launched a Model Context Protocol server connecting its enterprise wealth management platform to Claude, ChatGPT, Microsoft Copilot and other compatible AI tools.
  • Authorised agents can retrieve live household, portfolio, performance, exposure and compliance data to prepare briefings, client meetings and reports or identify mandate breaches.
  • The governed connection also supports onboarding, portfolio analysis, rebalancing and compliance monitoring without requiring firms to copy client information into general purpose AI tools.

This gives AI assistants controlled access to current portfolio and compliance data inside established advisor workflows. The d1g1t company profile shows how MCP extends a wealth platform serving more than 90 firms and representing over C$200 billion in assets. Wealth firms still need traceable actions, review gates and clear limits on what an agent can retrieve, recommend or execute.

Chime Adds Investing To Its Financial App

July 20, 2026, United States
  • Chime introduced self-directed stock and ETF investing and automated managed portfolios inside its financial app, with access rolling out to eligible members.
  • Self-directed accounts support commission-free trading, while both investing options have no minimum account balance and allow members to begin with US$1.
  • Automated portfolio fees are 0% annually for Chime Prime members, 0.10% for Chime Plus members and 0.25% for other eligible members.
  • Atomic Invest provides investment management, while Atomic Brokerage provides brokerage services. Chime is not the investment adviser and doesn’t make portfolio decisions.
  • Chime says its average member opens the app up to five times daily and completes more than 50 monthly transactions, giving the investing product an established distribution channel.

Chime is extending from payments, savings and credit into retail investment distribution without becoming the adviser or broker. The next measures are funded-account adoption, average balances, managed-versus-self-directed use and whether frequent financial-app engagement translates into sustained investing.

Payments Infrastructure And Money Movement

Shakepay Joins Interac e-Transfer As A Participant

July 23, 2026, Canada
  • Shakepay has joined the Interac e-Transfer service as a Participant after qualifying as both a FINTRAC registered money services business and a CIRO regulated investment dealer.
  • Participation gives the Montreal fintech greater control over how payment experiences are built and delivered to more than 1.5 million Canadian users.
  • Interac e-Transfer processed more than 1.6 billion transactions last year.

This direct network participation gives a crypto platform greater control over one of Canada’s most widely used payment services. Shakepay can rely less on intermediary arrangements and build payment functions closer to the network. Other regulated fintechs will need to compare the operating control, settlement requirements, technical obligations and customer economics of becoming participants rather than remaining downstream users.

Bir Extends UnionPay Across Azerbaijan’s Payment Network

July 20, 2026, Azerbaijan / China
  • Bir and UnionPay completed the first phase of an acceptance partnership covering more than 1,000 online merchants and nearly 1,300 Birbank ATMs.
  • Later phases will add UnionPay acceptance across physical and mobile POS networks and allow Birbank customers to transfer funds to UnionPay cards.
  • The completed infrastructure will connect UnionPay with Birbank, Birmarket, Milliön payment terminals and the m10 wallet across Azerbaijan’s major acquiring channels.

The scale turns a card acceptance partnership into connected national payment infrastructure. Bir is combining banking, ecommerce, terminals and a wallet with an international network, giving merchants one operating ecosystem for domestic commerce, tourism and cross border customer access.

Bank Of Korea Prepares Nine Banks For Live Deposit Token Transactions

July 20, 2026, South Korea
  • The second phase of Project Hangang is preparing to begin real deposit token transactions as early as September with nine participating commercial banks.
  • The Bank of Korea will provide the institutional CBDC infrastructure while participating banks issue deposit tokens and develop their own payment services.
  • The new phase adds person to person transfers, biometric authentication, automatic deposits and withdrawals, additional merchants and programmable public disbursement use cases.

South Korea is testing a two tier model in which the central bank supplies the settlement base and commercial banks own distribution. The test could provide a practical comparator for how tokenized deposits, public money and regulated bank services can operate inside one payment system.

AZ-COM Plans JPYC Payments Across 2,300 Business Partners

July 20, 2026, Japan
  • Tokyo listed logistics company AZ-COM Maruwa reportedly plans to use the regulated yen stablecoin JPYC for payments to approximately 2,300 business partners.
  • The intended recipients include subcontractors, independent truck drivers and small carriers operating across the company’s logistics network.
  • JPYC maintains a one to one yen peg backed by bank deposits and Japanese government bonds, with the company seeking faster cash flow and low cost conversion into conventional yen.

If implemented at the reported scale, this would provide one of the clearest tests of stablecoins as operating payment infrastructure rather than a crypto trading product. The real measure will be whether suppliers adopt it, convert it easily and receive a meaningful cash flow benefit.

Open Banking Open Finance And Data Sharing

Shacom Bank Uses Open Finance Data For SME Intelligence

July 22, 2026, Hong Kong
  • Shanghai Commercial Bank and Planto launched an Inter-bank Financial Insights solution through the Shacom Business app using Hong Kong’s Interbank Account Data Sharing framework.
  • Authorized SME customers can consolidate information from Shacom and eleven other banks, including real-time balances, up to 18 months of cash flow data, foreign currency activity and overseas revenue distribution.
  • The platform also helps the bank identify anomalies and opportunities while giving relationship teams a more complete view of each participating business.

The deployment turns open finance from account aggregation into operating intelligence for SMEs and their banks. It provides a practical comparator for Canada’s open banking development, where permissioned financial data could improve cash visibility, risk monitoring, credit decisions and relationship banking.

Artificial Intelligence And Data

Cognitive Credit Connects Source Linked Data To Claude

July 23, 2026, United Kingdom / Global
  • Cognitive Credit launched a connector that makes its machine extracted credit data and source disclosures available inside Claude and enterprise AI workflows.
  • The connector covers high yield bonds, investment grade bonds, leveraged loans, and emerging market bonds across approximately 3,100 issuers.
  • Cognitive Credit reports that all 10 of the largest global investment banks and a majority of the 25 largest global asset managers use its services, although connector specific adoption figures were not disclosed.

Institutional data providers are bringing governed financial information into the AI interfaces analysts already use. Credit teams need to test permissions, source traceability, update timing, confidential data boundaries, model outputs, and review requirements before connector generated work enters investment decisions. Adoption data will determine whether this becomes core research infrastructure or remains an optional interface.

Manulife Deploys Enterprise AI Agent Governance With Microsoft

July 22, 2026, Canada / Global
  • Manulife signed a five-year agreement with Microsoft and adopted Microsoft’s Frontier Suite to support AI deployment across its global operations.
  • The insurer will deploy Microsoft Agent 365 as a central registry and control layer for governing, monitoring and securing AI agents, while expanding Microsoft 365 Copilot to more than 30,000 employees.
  • Manulife says it already has AI agents in production and expects its AI initiatives to generate more than US$1 billion in enterprise value by 2027, with US$300 million achieved by the end of 2025.

Manulife is putting AI governance into the operating architecture of a major Canadian financial institution. Together with Canada’s shared AI control infrastructure, the deployment provides a direct test of whether central agent registries, monitoring and security controls can support enterprise AI without fragmenting accountability across business units and jurisdictions.

Bigdata.com Prices Licensed AI Content By The Token

July 20, 2026, United States / Global
  • RavenPack launched a Bigdata.com marketplace where AI agents retrieve, license and pay for premium content according to the number of content tokens consumed.
  • Each provider sets a price per token, while retrieved excerpts are counted, attributed and settled by source with a per use content licence attached.
  • More than 170 market data, research, news and expert content providers are available through one MCP or API connection; RavenPack claims its targeted retrieval can reduce model context consumption by up to 100 times.

AI agents do not fit conventional per seat data licences. Bigdata.com is testing whether attribution, licensing and payment can be embedded directly into retrieval, creating a potential commercial layer for financial research and other data intensive AI workflows.

Banking And Credit

Wise Loses US Trust Charter Bid And Plans New Filing

July 24, 2026, United Kingdom / United States
  • The US Office of the Comptroller of the Currency denied Wise’s application for a national trust bank charter, although the decision does not affect its existing operations under money transmitter licences covering 48 states and four territories.
  • Wise sought direct access to US payment settlement through a Federal Reserve account, but says the Federal Reserve’s pause on account access for uninsured trust banks made the original structure unworkable.
  • The OCC also referred to Wise’s July 2025 multistate consent order. Wise says it has strengthened investigations, reporting, customer data controls and compliance staffing and plans to submit a new application under the GENIUS Act framework.

The rejection shows that federal payment access depends on both settlement policy and compliance readiness. Wise’s planned GENIUS Act application adds a major global payments company to the US trust charter debate. The next test is whether Wise can design a viable application without changing how its existing customers hold and transfer money.

Upstart Gets Conditional OCC Approval To Establish Bank

July 23, 2026, United States
  • The Office of the Comptroller of the Currency granted Upstart conditional approval to establish Upstart Bank, N.A., following an application submitted in March 2026.
  • The proposed Delaware based digital bank would originate consumer loans nationwide and accept deposits insured by the Federal Deposit Insurance Corporation without operating physical branches.
  • Applications for FDIC deposit insurance and Federal Reserve approval for Upstart to become a bank holding company remain pending. Operations cannot begin until all approvals are received and OCC conditions covering capitalization, governance and operational readiness are satisfied.
  • Upstart expects banks, credit unions and institutional credit funds to continue purchasing the vast majority of loans originated through its platform, with Upstart Bank complementing those funding relationships.

A national bank charter would give Upstart direct access to deposit funding and place its lending activities within a federal prudential framework. It could reduce funding and regulatory complexity while adding bank level capital, liquidity, governance, compliance and supervisory obligations. Partner institutions and investors should watch the remaining approvals, preopening requirements and how Upstart allocates originations between its own bank and external funding partners.

Revolut Launches As A Licensed Bank In Australia

July 21, 2026, Australia / Global
  • Revolut Payments Australia received a full authorised deposit taking institution licence from APRA, while its Australian holding company received separate approval.
  • Revolut Bank Australia began onboarding new customers and transferring more than one million existing Australian customers into the licensed bank.
  • Eligible deposits receive protection of up to A$250,000, while Revolut plans to add savings and credit products and invest nearly A$400 million over five years.

A global fintech can now combine deposits, payments and credit under one Australian prudential licence. Canada has a clear comparator for foreign fintech bank entry, deposit protection and the competitive impact of giving a large digital platform its own regulated balance sheet.

Augustus Raises US$180M For Global Dollar Clearing Bank

July 21, 2026, United States / Global
  • Augustus raised a US$180 million Series B at a US$1 billion valuation, bringing its total financing to US$210 million.
  • Its platform supports operating and FBO accounts, named virtual accounts and transactions through Swift, ACH, SEPA and stablecoins.
  • Augustus received preliminary conditional OCC approval in May, but its proposed national bank remains in organization and cannot begin US banking operations until required approvals and preopening conditions are completed.

Augustus is targeting the correspondent banking layer with programmable dollar accounts, payment rails and an owned core. If its charter becomes operational, international fintechs could gain direct dollar infrastructure without relying on several sponsor and intermediary relationships. That is highly relevant to Canadian firms requiring dependable US accounts, liquidity and payment access.

Bank Of Maldives Selects Finastra For Core Overhaul

July 21, 2026, Maldives / Global
  • Bank of Maldives, the country’s largest bank by assets and branch presence, selected Finastra Essence to modernize its core banking operations.
  • The bank serves more than 390,000 customers and will use the platform across conventional and Islamic banking products.
  • The implementation is intended to automate processing, support straight through operations and reduce the time required to introduce new products and services.

The implementation will test whether one configurable core can support conventional and Shariah compliant products across a national banking network. Canadian banks and credit unions face the same challenge of replacing legacy infrastructure while preserving existing products, controls and customer access.

Policy Regulation And Governance

Australia Sets AI Safety Agenda Across Consumer Law And Agentic Commerce

July 20, 2026, Australia
  • The Australian Government plans to legislate a Digital Duty of Care requiring AI companies to build in safety and proactively address potential harm.
  • Further priorities include a second tranche of privacy reform and a framework governing automated decision making within federal agencies.
  • Australia will examine consumer law responses to retail surveillance pricing and agentic commerce while developing workplace AI safety measures.

The priorities establish policy direction ahead of binding rules and connect AI development with consumer protection, personal data, automated public decisions and employment. Canadian institutions should watch how Australia assigns responsibility when AI agents influence prices, purchases and regulated decisions.

Competition And Market Structure

EU Fines Google €890M Over Search And Play Rules

July 23, 2026, European Union / Global
  • The European Commission fined Google a combined €890 million in two Digital Markets Act enforcement decisions.
  • A €460 million penalty concerns preferential placement of Google services, including shopping, hotels, transport and sports results, over competing services in Google Search.
  • A separate €430 million penalty concerns restrictions preventing Google Play developers from freely directing customers to alternative purchasing channels.
  • The Commission found that Google’s steering-related fees and charging periods exceeded what the DMA permits.
  • Google was ordered to end both forms of non-compliance.

The decisions directly affect how fintech applications are discovered and how developers direct customers to alternative payment channels. Fairer search treatment could reduce dependence on a gatekeeper’s commerce products, while fewer steering restrictions could give fintechs greater control over pricing, billing and customer relationships. Canadian firms serving European users may need distinct distribution and payment strategies for DMA-compliant channels.

Digital Assets Blockchain And Tokenization

Ripple Backs Notabene’s Stablecoin Authorization Network

July 23, 2026, United States / Global
  • Ripple made an undisclosed strategic investment in Notabene and plans to integrate Ripple USD into the Notabene Flow business payment network.
  • The companies will also examine how Notabene’s pretransaction authorization controls could complement Ripple Payments.
  • Notabene reports more than 2,300 connected institutions, over 280 customers, coverage across more than 100 jurisdictions, and more than US$2 trillion in annualized transaction volume.

Stablecoin payment providers are beginning to place counterparty verification and authorization before settlement rather than treating compliance as a review after funds arrive. Banks, payment firms, exchanges, and custodians need to decide where approval occurs, which party controls it, what information travels with the payment, and how rejected or restricted transactions are handled across wallets and jurisdictions.

BitMEX To Close Exchange After Eleven Years

July 23, 2026, Global
  • HDR Global Trading decided to close the BitMEX exchange on September 23 following a strategic review of the business and crypto industry.
  • New account registrations stopped immediately. BitMEX urged customers to close positions and withdraw their assets before the closure.
  • Beginning August 26, customers will only be able to reduce positions. BitMEX may force close positions and settle contracts with limited liquidity early.
  • Customers who leave assets on the platform after the closure will face an account fee of US$50 or 1% annually, whichever is greater, charged monthly.
  • Customers will retain access to balances, transaction records and withdrawals after the exchange closes. BitMEX states that its assets exceed its liabilities.

BitMEX helped establish perpetual swaps as a core crypto trading product, yet creating a market did not preserve its liquidity position. Kaiko data cited by Reuters placed daily trading volume near US$400,000 and market share below 0.01% when the closure was announced. The exit raises a market-structure question about whether smaller centralized venues can retain enough traders, market makers and revenue as activity concentrates among major exchanges and onchain platforms.

Senate CLARITY Draft Adds Crypto Market And Ethics Rules

July 22, 2026, United States
  • The updated Digital Asset Market Clarity Act combines Senate Banking and Agriculture Committee provisions into a proposed federal system for digital commodity issuers, exchanges, brokers, dealers and custodians.
  • The draft divides oversight between the SEC and CFTC, creates registration and certification processes for digital commodity intermediaries, and addresses custody, customer property, decentralized finance, token disclosures and self custody.
  • A new ethics division would prohibit covered public officials, federal employees and their spouses from issuing or sponsoring digital assets for consideration while the official is serving, with enforcement reserved for the U.S. attorney general.

The Senate draft now connects market structure, intermediary registration, asset classification and political ethics in one legislative package. Digital asset firms should examine which activities would fall under SEC or CFTC supervision, how certification and custody requirements would work, and whether negotiations materially change the ethics, enforcement or implementation provisions before the bill advances.

Coinbase Plans Canadian Crypto Derivatives And Wider Trading Platform

July 21, 2026, Canada
  • Coinbase Canada CEO Eric Richmond said Coinbase Financial Markets had received an international exemption allowing it to offer crypto derivatives to Canadian permitted clients.
  • Richmond expects the derivatives product to become available within weeks, although the initial offer won’t be open to every retail customer.
  • Coinbase is also working to bring its Everything Exchange strategy to Canada, combining crypto, stocks, ETFs and prediction markets through one platform. No Canadian launch date has been announced for the wider offer.
  • Richmond said Coinbase is targeting investment dealer registration and CIRO membership in early 2027.

Coinbase is preparing to compete for more than Canadian crypto trades. Derivatives provide the immediate entry point, while stocks, ETFs and prediction markets could eventually place it against Canadian brokerages and multi product investment platforms. Permitted client limits, dealer registration, product approvals, custody, disclosures and market surveillance will determine how much of the strategy reaches Canadian customers.

NCFA Perspective

The strongest thread this week is control. Fintechs are gaining more direct access to payment networks, regulated markets, financial data and AI infrastructure. That access creates commercial opportunity, but it also places greater responsibility on firms to protect customer rights, govern automated decisions and keep critical systems resilient. For Canadian founders and investors, your advantage will come from owning a useful part of this infrastructure before access rules, operating economics and market positions harden.  Follow the next developments through NCFA’s newsletter, explore connected opportunities in the Financial Innovation Map, or review the latest fintech insights.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Inside Tailscale: From Secure Networking To A Wider Access Platform

NCFA Companies On The Move profile of Tailscale, a secure networking and access platform, July 2026.

July 21, 2026 | NCFA Companies On The Move | Cybersecurity And Fraud, Identity Privacy And Data Governance, Artificial Intelligence And Data

Tailscale Company Profile: Funding, Growth And Products

Founded
2019
Origin
Toronto, Canada; fully distributed
Founders
Avery Pennarun, David Carney, David Crawshaw and Brad Fitzpatrick
Company Stage
Expand / Scale

Tailscale is a Toronto founded secure networking company built around WireGuard, identity controls and direct connections between devices. By July 2026, it was nearing 40,000 paid business clients and approximately 300 employees, according to BetaKit. Tailscale’s website separately reports 2.5 million active devices and 100,000 monthly active users.

The core business makes private networks easier to deploy and govern, while Aperture and Border0 take Tailscale into AI access and privileged infrastructure—two markets with bigger security budgets and much heavier competition. This profile looks at what customers are buying today, where the next leg of growth could come from and what the public evidence still can’t tell us.

Why Companies Are Buying Tailscale

The best public clues come from customers describing work they no longer have to do. Instacart reduced internal VPN support requests from about 10 each week to nearly zero, cut new user onboarding to less than one minute and reported no outages after deployment. Cribl grew from 18 to approximately 550 employees without hiring a dedicated networking team to administer access, while Corelight reports saving more than 1,000 hours annually and Positron estimates it saves an hour each time a prospect is onboarded.

These are selected Tailscale case studies, not audited results or a measure of what the average customer should expect. Still, they help explain how the product spreads: it removes the VPN tickets, slow onboarding and constant access administration that technical teams already dislike. A developer can start with one live problem, and if the network holds up, IT and security have a practical reason to standardize it, add controls and bring more of the company onto the same service.

The Products Driving Tailscale’s Business

Core Tailscale appears to be the product that pays today. It creates an encrypted private network among approved users, devices, servers and services, with identity based policy deciding what can connect. Developers can get started without rebuilding the company network; as use grows, IT and security can add centralized administration, device posture, logs and tighter access controls. Tailscale’s client, command line tool and relay server code are open source, but the hosted coordination server is proprietary. That coordination service distributes public keys and access rules, while customer traffic normally moves directly between endpoints or through encrypted relays. Tailscale Raises $230M To Power Identity-First Networking looked at why this model could pressure conventional VPN and firewall products.

The pricing supports the same bottom up motion. Tailscale currently lists a free Personal plan, Standard at US$8 per user per month, Premium at US$18 and custom Enterprise terms, with paid plans adding provisioning, device posture, administrative roles, network flow logs, regional routing and support. The cost of trying the product is low; the account becomes more valuable as more people, devices and company controls move onto it.

Revenue is the important missing number. Tailscale doesn’t publish it, and the outside estimates aren’t close enough to treat as fact. GetLatka puts 2025 revenue at US$45.2 million, although it says the figure is modelled and that management wasn’t interviewed. Northmetric estimates US$60.1 million in current annual recurring revenue with medium confidence, relying partly on an assumed 54,000 paying customers—well above BetaKit’s July 2026 report of nearly 40,000 paid business clients. Taken together, the estimates point to a company with real commercial scale, but they don’t establish Tailscale’s actual revenue.

Aperture is the move into AI access and cost control. Sitting between approved users or agents and AI model providers, it centralizes credentials while applying access rules, usage visibility and spending limits. That puts platform, security and AI infrastructure teams squarely in the buyer group. AI Agents Enter Governed Financial Workflows explains why permissions, approved tools and audit records matter once agents touch regulated work. Existing Tailscale networks could give Aperture a useful distribution advantage, but the product remains in beta and is currently available without extra cost during testing. Six users are included, with additional access handled through the company; usage, paid conversion and final pricing haven’t been published.

Border0 moves Tailscale into privileged infrastructure access. It governs sensitive connections to servers, databases, Kubernetes environments and internal applications, adding approval workflows, session recording and audit visibility. Those capabilities put Tailscale in front of security, compliance and operations buyers—not just the teams managing everyday network access. After acquiring Border0 in March 2026, Tailscale began connecting the product to its identity and networking layer, although the combined offering remains in beta. Adoption, revenue and final packaging haven’t been disclosed, so Border0 is best viewed as a credible expansion route rather than a proven second engine.

Competition, Regulation And Market Pressure

Tailscale now overlaps with secure networking, identity security, privileged access and AI gateways. Each move opens another budget, but it also brings the company up against much larger security platforms with broader bundles, established enterprise sales teams and far more acquisition firepower.

Large security platforms are buying identity. Palo Alto Networks completed its acquisition of CyberArk in February 2026, adding privileged access and identity security to a platform that already spans network, cloud and security operations. CrowdStrike agreed to acquire SGNL for continuous identity controls, while Zscaler agreed to acquire Symmetry Systems for data and AI access visibility. Buyers are clearly paying for identity and access control, but they may increasingly prefer to buy it inside a larger security contract.

SASE rivals have more capital and enterprise reach. Netskope’s September 2025 IPO raised approximately US$992 million and valued the company at about US$9.6 billion on a fully diluted basis. Netskope, Zscaler, Cloudflare and Palo Alto Networks can bundle network access with wider security products and sell through established enterprise teams. Tailscale’s counter is that technical users can adopt its product before a large security procurement begins, although that advantage could narrow as buyers consolidate more of their security spending with fewer vendors.

AI gateways are becoming a real product category. Cloudflare AI Gateway added real time spending limits and identity based controls in June 2026, while Kong sells governance for models, MCP servers and AI agents. Neo Raises US$100M To Control Enterprise AI Agents shows how quickly money and products are gathering around agent inventory, permissions and policy. Aperture approaches the same problem from inside a customer’s private network, which gives it an interesting opening; whether that opening lasts will depend on policy depth, auditability and model coverage.

Canadian financial institutions face clearer AI and vendor controls. OSFI’s July 2026 bulletin on generative and agentic AI connects AI use to existing expectations for technology risk, operational resilience and third party oversight. Its technology and cyber risk guideline and third party risk guideline make identity, logs, access policy and vendor diligence commercially relevant. OSFI And GRI Workshops Reveal What Regulated AI Needs found that weak identity, provider concentration and vendor oversight are already limiting adoption. Tailscale’s SOC 2 Type II status helps. CSA Cybersecurity Guidance For Registered Firms shows why firms will still need documented vendor diligence, access controls and current assurance reports.

Open source keeps the paid product honest. Tailscale identifies Headscale as an independent alternative to its proprietary coordination server, which means a capable technical team can self host that layer. The subscription therefore has to keep earning its place through reliability, administration, policy, support and company controls—not connectivity alone.

Easy adoption doesn’t remove enterprise budget friction. A Tailscale commissioned survey of 1,000 technology leaders found that 42% cited workflow or integration disruption when security upgrades were delayed, while one third cited an unclear business case. Customer results give Tailscale’s sales team concrete savings to work with, but a company wide deployment still needs an owner, a budget and proof that another security vendor can be retired or avoided.

What Makes Tailscale Different In Summer 2026

Tailscale’s edge starts with how it gets in. A developer or infrastructure team can solve a live networking problem without waiting for a company wide migration; if the product works, IT and security can add policy, device controls, logs and support around a network that people are already using. Reported results from Instacart, Cribl, Corelight and Positron give that approach substance beyond the usual product pitch. It also places Tailscale across several areas in the NCFA Financial Innovation Map, including digital identity, cyber resilience, AI governance and enterprise infrastructure.

The next act is harder because Aperture and Border0 ask those customers to trust Tailscale with AI access and privileged infrastructure, where the budgets are larger and the incumbents are stronger. Nearly 40,000 paid business clients and 2.5 million active devices give Tailscale a meaningful starting point; what isn’t public yet is whether either product is creating meaningful new revenue.

The Company Intelligence Snapshot follows the funding, customer growth and product decisions that brought Tailscale to this point.

NCFA Company Intelligence Snapshot

Tailscale

Identity based secure connectivity for businesses, infrastructure, AI workloads and privileged access
Last updated Jul 21, 2026

Company At A Glance

Founded2019 by Avery Pennarun, David Carney, David Crawshaw and Brad Fitzpatrick
BaseToronto founded, fully distributed team
StatusPrivate, Series C
FundingUS$275M raised across seed, Series A, Series B and Series C financing
ValuationApproximately US$1.5B at the Apr 2025 Series C
TeamApproximately 300 employees reported in Jul 2026
Revenue EstimatesUS$45.2M 2025 revenue estimated by GetLatka; US$60.1M current ARR estimated by Northmetric; neither is company reported
ProductsBusiness VPN, remote access, workload connectivity, Aperture AI gateway and Border0 privileged access
TechnologyWireGuard based encrypted mesh networking with identity controlled access
CustomersDevelopers, IT teams, security teams, enterprises, AI companies and infrastructure operators
Business ModelFree personal access with paid business and enterprise subscriptions
Milestones
Select a milestone to follow how Tailscale expanded from mesh networking into a wider access platform
Milestone 1

Tailscale Launches A Simpler Private Network (2019–Apr 2020)

Tailscale was founded in 2019 to reduce the complexity of connecting people, devices and services across the internet. Its first generally available product combined WireGuard encryption, identity and direct connections without requiring companies to rebuild their existing networks.

Company

TailscaleA Canadian founded secure networking company

Stage

LaunchGeneral availability arrived in April 2020

Capital

US$3M SeedLed by Heavybit with Uncork Capital and others

Markets

GlobalRemote teams, cloud infrastructure and personal networks

Customers

Developers FirstIndividuals and technical teams could start without enterprise deployment

Competition

Simpler VPNDirect encrypted connections reduced reliance on central VPN concentrators

Additional Company Data

  • WireGuard supplied the encrypted data layer
  • Identity replaced manual IP based access rules
  • The open source client helped technical buyers inspect and adopt the product
  • A free personal plan supported bottom up distribution

Why This Milestone Matters

Rather than begin with a top down security sale, Tailscale gave developers a faster way to connect private infrastructure and let working networks make the case for wider adoption.

Frequently Asked Questions About Tailscale

What is Tailscale?
Tailscale is a secure networking platform connecting users, devices, servers and services through encrypted, identity-controlled networks. It uses WireGuard for encryption and a coordination layer for identity, discovery and policy. Traffic generally travels directly between endpoints rather than through a central VPN concentrator.
Who founded Tailscale?
Tailscale was founded in 2019 by Avery Pennarun, David Carney, David Crawshaw and Brad Fitzpatrick. Pennarun is chief executive and Carney is chief strategy officer. The company was founded in Toronto and operates as a fully distributed organization.
Is Tailscale a Canadian company?
Tailscale was founded in Toronto and is widely described as a Canadian-founded company. Its team is fully distributed, and the company serves customers globally.
How much funding has Tailscale raised?
Tailscale has raised US$275 million in disclosed financing: a US$3 million seed round, US$12 million Series A, US$100 million Series B and US$160 million Series C. Accel, CRV, Insight Partners, Heavybit and Uncork Capital are among its investors.
What is Tailscale’s valuation?
Tailscale was valued at approximately US$1.5 billion with its April 2025 Series C. Because it is privately held, this financing valuation is not a continuously updated market value. A later financing, secondary transaction or acquisition could establish a different valuation.
How many customers does Tailscale have?
BetaKit reported in July 2026 that Tailscale was nearing 40,000 paid business clients. Tailscale’s website separately reports more than 30,000 businesses, 2.5 million active devices and 100,000 monthly active users. The figures were published at different times and may use different definitions, so they are not directly comparable.
How does Tailscale make money?
Tailscale uses a freemium subscription model. Its Personal plan is free, while Standard and Premium are priced per user and Enterprise pricing is negotiated. Aperture is currently in beta, and Tailscale has not disclosed how much revenue Aperture or Border0 contributes.
Does Tailscale disclose its revenue?
Tailscale does not publish official revenue or audited financial results. GetLatka and Northmetric publish estimates, but those figures are modelled rather than company reported and should not be treated as confirmed revenue.
What is Aperture by Tailscale?
Aperture is an AI access gateway designed to control which users and agents reach AI models, centralize provider credentials, observe model usage and manage cost. It remains in public beta, so eventual pricing, adoption and business contribution are not publicly established.
What did Border0 add to Tailscale?
Border0 joined Tailscale in March 2026, bringing controlled SSH, Kubernetes, database and remote-administration access into its product range, along with session recording and audit visibility. Tailscale said Border0 was already integrated with its network, identities and policies. Financial terms were not disclosed.
Who competes with Tailscale?
The list changes by use case. Core Tailscale competes with VPN, zero trust network access and software defined networking products, as well as self hosted WireGuard alternatives. Aperture faces AI gateway vendors. Border0 puts Tailscale into privileged access management, where large security platforms already compete.
Is Tailscale profitable?
Tailscale does not publicly disclose whether it is profitable. Revenue, margins, cash burn and audited financial results remain private.

Information notice: Private-company estimates are identified and attributed. Information may change after the stated update date. This content is provided for informational purposes only and does not constitute investment, financial or legal advice.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

CSA Cybersecurity Guidance for Registered Firms

July 20, 2026 | NCFA Resource | Cybersecurity And Fraud, Risk Compliance And Regtech, Capital Markets And Market Infrastructure

NCFA Resource – CSA Cybersecurity Guidance for Registered Firms

Policies, Training, Vendor Risk, And Incident Response

On July 15, 2026, the Canadian Securities Administrators published new cybersecurity guidance for registered dealers, advisers, and investment fund managers (Download the 12 page PDF report). CSA Staff Notice 33-322 combines findings from a focused review of 73 firms with practical expectations for policies, employee training, risk assessments, third party oversight, and incident response.

The notice is most useful as a compliance review tool. Firms can compare their written controls, operating practices, and supporting records against the deficiencies and effective practices identified by securities regulators. The guidance is particularly relevant for smaller and medium sized firms that may not have dedicated cybersecurity teams.

What It Does In Practice

The notice organizes cybersecurity readiness around five areas that regulators examined under section 11.1 of National Instrument 31-103:

  1. written cybersecurity policies and procedures
  2. employee cybersecurity training
  3. cybersecurity risk assessments and controls
  4. oversight of third party service providers
  5. written and tested incident response plans

The review found useful benchmarks. 8% of firms had no written cybersecurity policies, while 55% had policies that needed improvement. Twenty one per cent provided no employee cybersecurity training. Forty five per cent completed risk assessments that could have been stronger, and 12% had no documented assessment during the review period.

Third party oversight was one of the clearest weaknesses. All examined firms used service providers with access to systems or data, but 62% had no documentation or limited documentation supporting their cybersecurity oversight. The CSA expects firms to complete and document due diligence before onboarding a provider and repeat that review throughout the relationship.

The guidance identifies information firms should assess, including data storage, encryption, access controls, patch management, incident notification, subcontractors, operating jurisdictions, and shared responsibility in cloud environments. It also recommends maintaining a complete vendor register and reviewing current SOC 2 or similar reports where available.

Incident preparedness also receives detailed attention. Fifteen per cent of firms had no written incident response plan. Among firms with a plan, 53% needed stronger procedures and 63% should have tested their plans more regularly. The notice describes tabletop exercises and simulated attacks as practical ways to test whether people, processes, and technical controls work together during an incident.

Who Gets Value

The primary audience is firms registered as dealers, advisers, portfolio managers, investment fund managers, exempt market dealers, and restricted portfolio managers. Chief compliance officers, directors, technology leaders, privacy professionals, and internal audit teams can use the notice to organize a control review and identify missing documentation.

Boards and senior executives can also use it to test whether cybersecurity oversight is tied to clear responsibilities, regular reporting, and evidence that controls operate as intended. Written policies alone aren’t enough when actual practices, testing schedules, or access controls differ from the documented process.

Cybersecurity consultants, legal advisers, insurance providers, managed service providers, and software vendors can use the findings to better understand the records and evidence registered firms may need during a regulatory review.

Strengths And Limits

The notice is strong because it combines regulatory expectations with observed deficiencies, percentages, effective practices, and practical takeaways. It covers both governance and technical controls, including multifactor authentication, encryption, backups, access rights, patching, email filtering, endpoint protection, and activity logging.

It also makes documentation a central requirement. Firms should be able to show when policies were reviewed, who completed training, how risks were assessed, what vendor due diligence occurred, and when incident plans or backup recovery procedures were tested.

The guidance does not create a complete technical cybersecurity standard, and it doesn’t replace obligations under privacy, securities, corporate, or other applicable laws. Expectations also vary with the firm’s size, operating complexity, client information, service provider reliance, and exposure to cyber risk.

Firms should therefore use the notice as a regulatory gap assessment and evidence checklist, then supplement it with appropriate legal advice, technical standards, testing, and controls suited to their operations.

Key Resources

CSA Staff Notice 33-322 (cybersecurity examination findings and guidance for registered firms)

CSA Staff Notice 33-321 (foundational 2017 cybersecurity and social media guidance)

NIST Cybersecurity Framework (risk management structure for identifying, protecting, detecting, responding, and recovering)

CIS Critical Security Controls (prioritized technical and operational safeguards)

Wealthsimple Confirms Breach Impacting Clients (third party exposure and incident response)

Proposed Class Action Targets Equifax Access Controls (access governance and third party permissions)


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Neo Raises US$100M To Control Enterprise AI Agents

July 20, 2026 | NCFA Market Activity | Cybersecurity And Fraud, Artificial Intelligence And Data, Risk Compliance And Regtech

AI Image – Enterprise security team controlling AI agent access and actions

Former SentinelOne Leaders Build A Control Layer For Agentic Software

On July 20, 2026, Neo emerged from stealth with US$100 million in combined seed and Series A financing from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures and Merlin Ventures.

The Boston cybersecurity company was founded in 2025 by Nick Warner, Shlomi Salem and Eran Shirazi. Note that it's unrelated to Calgary based Neo Financial. Warner previously served as SentinelOne president and COO, Salem led detection engineering and threat research at SentinelOne, and Shirazi previously co-founded EasySend after leading vulnerability research in Israel’s Unit 8200.

Neo is building what it calls an agentic software control layer. The platform gives security teams an inventory of AI agents, AI enabled applications, plugins, extensions, MCP servers and traditional software that has gained agentic capabilities. It then maps permissions, attributes actions and applies policy before software reaches sensitive data or systems.

The company plans to use the financing to expand engineering and go to market operations. Neo hasn't disclosed revenue, customer counts, named customers, valuation or the allocation between its seed and Series A rounds.

Agents Can Operate Inside Trusted Permissions

Enterprise security was built around human users, known applications and recognizable data flows. AI agents can act differently. They may inherit a user’s permissions, call several tools, reach files and credentials, communicate with other agents and continue operating without a conventional interface.

That means risky activity may not even resemble a conventional intrusion. An agent can use valid credentials and approved applications while still exporting too much data, reading a secret, pushing code or initiating an action that exceeds the authority its operator intended to grant. NCFA’s analysis of AI agents gaining identity and wallet access shows how quickly this issue reaches financial APIs and real infrastructure.

Neo’s platform combines four functions. It finds AI software, checks what it can access, shows who or what is behind each action, and lets security teams allow, block or pause that action for approval.

Threat's aren't limited to deliberately malicious agents. ShadowLeak demonstrated how hidden instructions could manipulate an AI agent and expose private information without a user clicking a malicious link.

Its Neoverse knowledge base maps the capabilities, risks and behaviour of agentic software before it enters an enterprise environment. Neo says enforcement occurs natively at the endpoint, where the software can intercept tool calls, API access, credential reads and data transfers before the action is completed.

Competition Is Forming Around Agentic Security

Neo combines software inventory, posture intelligence, attribution and endpoint enforcement across agentic and traditional applications.

Check Point is developing a wider AI security control plane covering employee AI use, AI applications and agentic systems.

SailPoint is extending identity governance to AI agents and other non-human identities.

Existing endpoint security providers already control devices, files and processes, but may not yet map the permissions and chained actions occurring inside agentic software.

Cloud and application security companies can govern models, APIs and data access, creating a competitive question around whether customers will buy a separate agentic control layer or expect existing security platforms to absorb the function.

Financial Institutions Will Need Authority Maps For Agents

Banks and other regulated organizations will need more than a list of approved AI tools. They need to know which person authorized an agent, what credentials it inherited, which systems it can call, what information it can export and when human approval is mandatory.

Neo’s opportunity is to show who or what can access each system and enforce clear limits on what they can do. Its challenge is that endpoint, identity, cloud and network security companies are all pursuing parts of the same problem. Large institutions may prefer one more specialized control layer, or they may demand that existing suppliers add agent governance to products already deployed across the organization.

See:  AI Agents Enter Governed Financial Workflows

Financial institutions are adopting AI while remaining accountable for privacy, cybersecurity, third party risk, operational resilience and auditability. An agent that can access customer information, initiate a payment, change code or communicate externally will need authority limits that security, risk and compliance teams can understand.

Neo has the capital and founding team to compete early, but the category is still forming. Enterprise adoption, integration depth and the quality of its policy enforcement will matter more than the size of the launch financing.

Talking Point

Will enterprises buy a dedicated control layer for agentic software, or will endpoint, identity and cloud security providers absorb the function before the category becomes independent?

NCFA Company Intelligence Snapshot

Neo

Agentic software inventory, attribution and real time policy control for enterprise security teams
Last updated Jul 20, 2026

Company At A Glance

Founded2025 by Nick Warner, Shlomi Salem and Eran Shirazi
HeadquartersBoston, United States
StatusPrivate
Capital / FundingUS$100M across seed and Series A financing
InvestorsAndreessen Horowitz, Bessemer Venture Partners, Craft Ventures and Merlin Ventures
ProductsNeo platform and Neoverse agentic software knowledge base
CustomersEnterprise SecOps teams; named customers not publicly disclosed
Public LaunchJuly 20, 2026
DisclosureRevenue, valuation and round allocation not publicly disclosed
Milestones
Select a milestone to follow Neo’s development
Milestone 1

Founding Team Assembles (2025)

Nick Warner, Shlomi Salem and Eran Shirazi founded Neo in 2025 to build security controls for enterprise software gaining autonomous and agentic capabilities.

Company

Neo SecurityEnterprise cybersecurity company focused on agentic software

Stage

FormationExperienced operators assemble before the public launch

Capital

Early Institutional BackingSeed and Series A allocation not publicly disclosed

Markets

Enterprise SecurityAI driven software environments

Customers

SecOps TeamsLarge organizations adopting AI enabled software

Competition

Operator ExperienceFounders previously built and scaled enterprise security companies

Additional Company Data

  • Warner previously served as SentinelOne president and COO
  • Salem led detection engineering and threat research at SentinelOne
  • Shirazi previously co-founded EasySend
  • The company is unrelated to Canada’s Neo Financial

NCFA Perspective

Neo begins with founders who have built cybersecurity products and commercial organizations before. That lowers some execution risk, but it does not yet establish enterprise adoption.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

NCFA Weekly Fintech Intelligence Jul 11-17, 2026

July 11, 2026 | NCFA Fintech Whisperer | Risk Compliance And Regtech, Digital Assets Blockchain And Tokenization, Payments And Money Movement, Wealth Investing And Trading, Capital Markets Infrastructure And Funding, Competition And Market Structure, Digital Banking And BaaS, Lending Consumer Credit And BNPL, Regulation And Policy, Identity Privacy And Data Governance Cybersecurity Fraud And Financial Crime

Image Freepik, Data visualization signals

Image: Freepik

This live weekly NCFA intelligence page tracks financial technology developments that significantly affect how fintechs build, sell, raise capital, and operate under scrutiny. Coverage prioritizes Canada and includes global events that directly influence competitive conditions, market access, and execution realities across fintech sectors.  This page will be updated throughout the week with market movers in a live format and then each week we'll close the prior week's contents in prep for the upcoming week, and continue on a rolling basis.  (Missed prior week's Fintech Whisperer?  (December 6-12, 2025, December 13-19, 2025, January 1-9, 2026, January 10-16, 2026, January 17-23, 2026, January 24-30, 2026, January 31-February 6, 2026, February 7-13, 2026, February 14-20, 2026, February 21-27, 2026, February 28-March 6, 2026, March 7-13, 2026, March 14-20, 2026, March 21-27, 2026, March 28-April 3, 2026, April 4-10, 2026, April 11-17, 2026, April 18-24, 2026, April 25-May 1, 2026, May 2-8, 2026, May 9-15, 2026, May 16-22, 2026, May 23-29, 2026, May 30-June 5, 2026, June 6-12, 2026, June 13-19, 2026, June 20-26, 2026, June 27-July 3, 2026, July 4-July 10, 2026).

Weekly Fintech Market Intelligence Jul 11 - 17, 2026

Digital Banking And BaaS

Standard Chartered Runs 70% Of Infrastructure On Private Cloud

July 15, 2026, United Kingdom / Singapore / Global
  • Standard Chartered standardized its global infrastructure on a software defined private cloud using VMware Cloud Foundation to support critical banking services across 54 markets.
  • Approximately 70% of the bank’s global infrastructure footprint already operates on the new architecture.
  • The platform embeds zero trust security into the infrastructure layer and reduces infrastructure deployment time from weeks to one day.

Private cloud remains a production architecture for regulated banks that need consistent control across countries and critical workloads. The 70% deployment gives other banks a concrete benchmark for weighing resilience, security, workload portability and regulatory oversight when deciding which systems belong in private environments and which can run with hyperscalers.

Capital Markets Infrastructure And Funding

BitGo Adds Custody And T+0 Settlement For Onchain Sovereign Bond

July 17, 2026, Marshall Islands / United States / Global
  • BitGo Bank & Trust will provide qualified custody and off exchange settlement for USDM1, a dollar denominated sovereign bond issued natively onchain by the Republic of the Marshall Islands.
  • USDM1 is structured under New York law, backed 1:1 by U.S. Treasuries and available to institutions on Stellar, Ethereum and Solana.
  • Eligible clients can deploy USDM1 to connected venues around the clock with T+0 settlement without transferring the asset onto an exchange.

The structure places sovereign issuance, Treasury backing, regulated custody and continuous settlement inside one institutional collateral workflow. It gives banks, dealers and custodians a concrete test of how tokenized sovereign instruments could support secured finance while reducing intraday exposure and prefunding requirements.

CSA Opens Review Of Public Company Regulation

July 16, 2026, Canada
  • CSA Consultation Paper 51-406 opens a 120 day review of how Canadian public companies are regulated, with comments accepted until November 13, 2026.
  • The consultation asks whether venture and non-venture issuer status should be determined differently to support more proportionate requirements.
  • The CSA is considering whether some venture issuers should receive relief from parts of International Financial Reporting Standards.
  • The paper also examines private placement hold periods, material change reporting and how U.S. reforms to reporting, disclosure and capital raising should influence Canada.
  • More than 10% of eligible companies have adopted the CSA’s voluntary semi-annual reporting framework, while recent Listed Issuer Financing Exemption changes have generated significant financing activity.

The review extends beyond one exemption or reporting rule. It connects the semi-annual reporting pilot and higher LIFE financing limits to the cost of staying public, the information investors receive and Canada’s ability to compete for issuers and capital.

Ontario Commits To Canada’s Securities Passport System

July 15, 2026, Canada
  • Ontario committed to join Canada’s national securities regulatory passport system following discussions among federal, provincial and territorial finance ministers.
  • Under the passport system, a market participant obtains a decision from its principal regulator that applies across participating jurisdictions under harmonized laws.
  • Ontario has been the only jurisdiction outside the system and currently uses an interface that can require a separate Ontario Securities Commission decision; implementation timing has not been announced.

Ontario’s commitment could remove a longstanding layer of duplicated review for issuers and registrants operating nationally. The operational test is whether full participation reduces filing cost and approval time without weakening investor protection. It also delivers the coordinated model sought in earlier calls for Ontario to adopt passport.

Grove And Galaxy Create US$500 Million Lending Facility

July 15, 2026, United States / Global
  • Grove committed a US$500 million warehouse facility to finance institutional loans originated and serviced by Galaxy Digital.
  • The senior secured loans may use BTC and ETH as collateral, including staked ETH, with assets held by Anchorage Digital and BitGo.
  • The facility uses USDS capital, defined eligibility requirements, concentration limits and continuous loan to value monitoring through independent price feeds.

The facility brings a familiar credit structure into institutional digital asset lending at substantial scale. It places onchain liquidity closer to loan origination and gives the market a clearer test of how stablecoin capital, qualified custody and crypto collateral can support structured credit.

Competition And Market Structure

Stripe And Advent Submit Reported US$53 Billion PayPal Bid

July 15, 2026, United States / Global
  • Reuters reported that Stripe and Advent International submitted a joint offer of US$60.50 per share for PayPal, valuing the company at more than US$53 billion.
  • The proposal is backed by approximately US$50 billion in committed bank financing and would give Stripe and Advent equal ownership of PayPal.
  • PayPal, Stripe and Advent declined to comment, PayPal had not responded to the proposal when it was reported, and there is no certainty that an agreement will result.

A combined Stripe and PayPal would connect merchant processing, consumer checkout, Venmo and stablecoin distribution under one ownership structure. Even without a transaction, the bid tests whether control of merchant acceptance and consumer distribution will become a defining advantage across wallets, agentic commerce and digital payments.

SME Finance And Business Banking

ConnectOne Bank Builds Commercial Lending Agents On nCino

July 14, 2026, United States
  • ConnectOne Bank is building multiple commercial lending agents on nCino’s Agentic Operating System.
  • The deployment targets frontline efficiency across commercial lending workflows rather than one isolated task.
  • nCino positions the system as an operating layer for agents working across lending data, processes and institutional controls.

Commercial lending agents are entering regulated bank workflows at the operating system level. Their value will depend on whether banks can reduce manual work while keeping credit judgment, accountability and exception handling under institutional control.

Wealth Investing And Trading

Blockchain.com Adds Polymarket Prediction Markets

July 14, 2026, Global
  • Blockchain.com partnered with Polymarket to add prediction market access inside its app for users in eligible markets.
  • Users will be able to use assets already held in their Blockchain.com accounts to open and manage event positions without a separate wallet connection or deposit process.
  • Blockchain.com said it serves more than 43 million verified users across more than 70 jurisdictions, giving Polymarket a large new distribution channel.

Prediction markets are becoming a standard feature inside crypto trading apps. Wider distribution could increase participation and liquidity, while raising sharper questions about eligibility, market integrity and the trust controls surrounding prediction markets.

Payments And Money Movement

Alipay+ Connects Global Wallets To Argentina’s National QR Network

July 17, 2026, Argentina / Global
  • Alipay+ integrated with Argentina’s Transferencias 3.0 national QR payment network through Latin American payment technology provider PVS.
  • International travellers using participating Alipay+ wallets will be able to scan the QR codes already displayed by millions of Argentine merchants.
  • Alipay+ connects more than 50 wallets and banking apps representing 2 billion user accounts with 150 million merchants globally, with the Argentine service launching in phases.

Argentina is turning a domestic interoperable QR standard into an international acceptance layer without requiring merchants to replace their checkout technology. It gives Canadian operators a useful comparator as Canada opens payment infrastructure to more PSPs and credit unions while developing instant payment access, shared acceptance and stronger operating controls.

Thredd Joins Visa Agentic Ready Programme

July 15, 2026, Europe
  • Thredd joined Visa’s Agentic Ready programme to help issuers support payments initiated by AI agents.
  • The processor said its platform provides tokenisation, authentication and fraud capabilities needed for agent initiated transactions.
  • Zilch is among the first issuers using the platform to support agent initiated payments in Europe.

Agentic commerce is reaching the issuer processing layer. Delegated authority, transaction controls, authentication and dispute handling are becoming core payment functions rather than responsibilities left only to agents and merchants.

Stable Launches StablePay On USDT Payment Rails

July 15, 2026, Global
  • Stable launched StablePay, a mobile app for instant USDT transfers using phone numbers, email addresses or QR codes.
  • The self custody service removes the need for users to manage blockchain accounts, gas fees or separate wallet connections.
  • Stable said the app is already supporting peer payments, cross border remittances and international payroll, with a built in feature for earning yield on USDT.

StablePay packages payment, custody and yield inside one consumer experience. Its traction will show whether simplified stablecoin products can win users beyond crypto markets while meeting the compliance expectations attached to global payments and yield.

Emirates NBD Launches Real Time USD Payments On Partior

July 14, 2026, United Arab Emirates / Global
  • Emirates NBD went live on Partior’s multicurrency blockchain clearing and settlement network.
  • The bank completed a live USD transaction with J.P. Morgan acting as settlement bank and beneficiary bank.
  • Corporate and institutional clients can now send real time USD payments to beneficiary accounts held at J.P. Morgan, with additional currencies and bank connections planned.

This is live bank settlement rather than another proof of concept. Partior now has a regional deployment that can test whether continuous liquidity, faster finality and programmable treasury services improve cross border banking at production scale.

ECB Selects 36 Payment Providers For Digital Euro Pilot

July 14, 2026, European Union
  • The European Central Bank selected 36 payment service providers from more than 50 applicants to participate in the digital euro pilot.
  • The 12 month pilot is scheduled to begin during the second half of 2027 using a beta version of the digital euro across the ECB and 19 national central banks.
  • The programme will test online and offline person to person payments, merchant acceptance, software point of sale and ecommerce transactions with banks, payment firms and selected merchants.

The digital euro has entered a new implementation stage. Attention now turns from policy design toward operational readiness, participant integration and whether the pilot demonstrates that public digital money can work alongside existing payment networks.

JCB And Circle Explore Stablecoin Merchant Payments

July 14, 2026, Japan
  • JCB and Circle signed a memorandum of understanding to explore USDC payments across JCB's merchant network.
  • The collaboration will examine cross border payments, merchant acceptance and settlement using stablecoin infrastructure.
  • The initiative builds on JCB's existing digital payment work with Japanese banking and technology partners.

Stablecoin adoption is expanding beyond crypto native platforms into established payment networks. The next phase will depend on merchant acceptance, operational integration and regulatory treatment across major consumer payment markets.

SCB And Citi Launch Near Real Time Cross Border USD Payments

July 11, 2026, Thailand / Global
  • Siam Commercial Bank became the first financial institution client to go live with Citi's integrated 24/7 USD Clearing and Citi Token Services solution.
  • The service enables near real time cross border USD payments at any time of day using tokenized deposits within Citi's regulated banking network.
  • The first live transaction transferred U.S. dollars between Citi in London and Siam Commercial Bank in Thailand during the U.S. holiday weekend, demonstrating continuous cross border payment capability.

The industry is beginning to demonstrate how tokenized deposits can support continuous cross border payments inside regulated banking networks. Alongside Swift’s bank ledger work with RBC and TD, the next measure is how quickly live services spread across institutions and payment corridors.

Cybersecurity Fraud And Financial Crime

FIS Tests Frontier AI Across Critical Financial Software

July 16, 2026, United States / Global
  • FIS joined Anthropic’s Project Glasswing and is actively testing the Mythos 5 frontier model against its own systems.
  • FIS operates software that clears payments, transfers money and runs core banking for thousands of financial institutions worldwide.
  • The controlled security initiative is separate from FIS’s commercial AI agent partnership with Anthropic and focuses on identifying vulnerabilities in critical software infrastructure.

Frontier AI is entering the security testing layer of widely shared banking and payment infrastructure. The initiative extends AI security across mixed banking systems into controlled testing of critical financial software. Banks and infrastructure providers will need clear controls for model access, finding validation, remediation ownership and disclosure as advanced models identify vulnerabilities faster than conventional security teams can process them.

CSA Sets Updated Cybersecurity Expectations For Registered Firms

July 15, 2026, Canada
  • CSA Staff Notice 33-322 reports findings from a focused compliance examination of 73 registered firms.
  • The review examined policies, employee training, risk assessments, controls, third party oversight and incident response planning.
  • CSA staff identified gaps across the firms reviewed and issued practical guidance intended to scale across small, medium and large registrants.

Cybersecurity expectations are becoming more concrete through examination findings rather than high level principles alone. Registered firms now have a clearer basis for testing governance, third party controls and incident readiness before the next compliance review.

INETCO Adds Agentic AI Fraud Investigation

July 14, 2026, Canada / Global
  • INETCO added agentic AI investigation capabilities to BullzAI for banks, payment processors and other financial institutions.
  • The agents collate transaction data, triage alerts, prioritize high risk cases and provide explainable scores and recommendations for fraud teams.
  • The capability uses a proprietary model deployed within the customer environment and improves through supervised human feedback.

Fraud operations are beginning to automate the investigation layer, not only transaction detection. The practical value will come from cutting case backlogs while preserving analyst control, explainability and sensitive payment data inside the institution.

ENISA Gives SMEs A Cyber Resilience Act Readiness Model

July 13, 2026, European Union
  • ENISA released a maturity model and downloadable assessment tool for SMEs that manufacture or supply products with digital elements covered by the Cyber Resilience Act.
  • The model evaluates governance, security by design, risk management, vulnerability management, product lifecycle practices and cybersecurity skills.
  • An accompanying survey of 194 organizations across 31 countries found that 66% knew about the Act, while practical understanding, incident response and product lifecycle readiness remained limited.

Canadian fintech and software vendors selling covered products into Europe need operational evidence behind their compliance claims. The model gives customers and partners a common way to examine product security maturity as the Act’s vulnerability reporting requirements begin in September 2026 and its main obligations approach.

Risk Compliance And Regtech

FATF Finds Crypto Travel Rule Enforcement Still Lags

July 16, 2026, Global
  • FATF found that 83% of surveyed jurisdictions, 91 of 109, had passed legislation implementing the Travel Rule, up from 73% in 2025.
  • However, 55 of those 91 jurisdictions had not issued findings or directives or taken Travel Rule related supervisory or enforcement action.
  • FATF reported that a Cambodia based financial services conglomerate laundered at least US$4 billion between August 2021 and January 2025, including at least US$37 million linked to North Korean cyber thefts.

Travel Rule adoption is advancing faster than supervision and enforcement. Crypto firms, banks and compliance providers need stronger counterparty screening, interoperable originator and beneficiary data, offshore VASP controls, and escalation procedures for stablecoins and unhosted wallet exposure.

FINTRAC Updates Canadian Controls For FATF Country Risks

July 15, 2026, Canada / Global
  • FINTRAC updated its advisory for Canadian reporting entities following the Financial Action Task Force’s June plenary.
  • Bosnia and Herzegovina and Iraq were added to the FATF list of jurisdictions under increased monitoring, while Algeria and Namibia were removed after completing their action plans.
  • Canadian reporting entities must account for connections to monitored jurisdictions when assessing geographic risk, applying controls and determining whether suspicious transaction reports are required.
  • Transactions connected to the Democratic People’s Republic of Korea and Iran remain subject to specific Canadian directives covering high risk treatment, identity verification, source of funds or virtual currency, beneficial ownership, recordkeeping and sanctions evasion controls.
  • The advisory also preserves enhanced requirements and reporting considerations for Myanmar, Russia, Afghanistan, Islamic State controlled areas and transactions connected to the Middle East.

The update requires banks, fintechs, payment companies, money services businesses and virtual asset firms to review country risk classifications, transaction monitoring rules and correspondent banking controls. Grey list status should inform a risk based assessment rather than automatic rejection of every transaction, while Canadian ministerial directives create specific mandatory treatment for designated jurisdictions.

UK Starts Direct Oversight Of Critical Technology Providers

July 13, 2026, United Kingdom
  • The Bank of England, PRA and FCA began joint oversight of the first Critical Third Parties designated by HM Treasury.
  • The regime covers Amazon Web Services, Google Cloud, Microsoft and Oracle services that support the UK financial system.
  • Designated providers must manage risks to critical services, communicate with regulators during major incidents and support system level resilience.

Direct supervision of major technology providers changes where operational resilience responsibility sits. Financial firms still own their outsourcing risk, but the largest shared dependencies now face regulatory scrutiny at source.

Digital Assets Blockchain And Tokenization

AMINA Embeds Mesh Verified Digital Asset Deposits

July 16, 2026, Switzerland / Global
  • FINMA regulated AMINA Bank integrated Mesh’s verified deposit technology directly into its online banking platform.
  • Clients will be able to select a wallet provider, verify ownership and deposit stablecoins or other digital assets through connections spanning more than 300 wallets and providers.
  • The deposit capability will soon become available to AMINA clients, with withdrawals, payouts and simplified wallet verification during onboarding planned as later additions.

Regulated crypto banking still breaks at the point where customers must prove ownership of external wallets. Embedding verification into deposit authorization can reduce manual address checks while preserving compliance controls. Banks considering similar connections will need clear responsibility for wallet screening, transaction monitoring, sanctions controls and failed transfers.

Lending Consumer Credit And BNPL

UK Buy Now Pay Later Rules Take Effect

July 15, 2026, United Kingdom
  • Interest free Buy Now Pay Later products are now regulated by the Financial Conduct Authority, covering providers including Klarna, PayPal and Clearpay.
  • Providers must conduct affordability checks before extending credit and give consumers clearer information during checkout.
  • Consumers gain enforceable refund protections for faulty goods, access to the Financial Ombudsman Service and support before debt collection when experiencing financial difficulty.

BNPL now operates as supervised consumer credit across the customer journey. Providers serving the UK need affordability, disclosure, complaints, refunds and collections controls that work inside merchant checkout flows. Canadian policymakers and lenders have a live comparator for testing whether product specific safeguards can protect consumers while preserving short term payment flexibility.

Regulation And Policy

UK Proposes Unified Rules For Tokenised And Agentic Payments

July 14, 2026, United Kingdom
  • HM Treasury opened a 12 week consultation containing 42 questions on payment services and electronic money regulation, with responses due October 6, 2026.
  • The proposals create common regulated activities for traditional and tokenised payments, bring certain stablecoins into the payments perimeter and require firms to obtain permission for tokenised payment services.
  • The consultation addresses agentic payment consent, authentication and liability alongside variable recurring payment access, commercial Open Banking pricing and expanded FCA supervision.

One consultation connects digital money, AI agents and Open Banking to the same operating rulebook. Payment firms need to test which permissions, safeguarding models, access rights and liability controls their products would require. Canadian regulators can compare this integrated approach with separate domestic work on stablecoins, consumer driven banking and Real Time Rail implementation.

Identity Privacy And Data Governance

Austrian Court Treats Inferred Political Profiles As Sensitive Data

July 16, 2026, Austria / European Union
  • Austria’s Administrative Court confirmed that statistically calculated political affinities are special categories of personal data protected under Article 9 of the GDPR.
  • The profiles covered approximately 2.2 million people and were stored and partly sold to third parties without consent or another applicable exception.
  • The court set the administrative fine at €13 million and confirmed that group wide annual revenue could be considered when determining the penalty.

The decision extends sensitive data protection beyond information people expressly provide to conclusions generated about them. Fintechs using behavioural analytics, customer segmentation, alternative data or AI models must consider whether inferred attributes can create heightened privacy obligations even when the underlying inputs appear ordinary.

Dutch Privacy Regulator Sets GDPR Guardrails For Generative AI

July 13, 2026, Netherlands / European Union
  • The Dutch Data Protection Authority published GDPR guidance for organizations developing generative AI models or taking responsibility for putting them into use.
  • The guidance addresses lawful grounds, indirect collection, training data and how personal information is managed, cleaned, enriched, retained and protected.
  • A separate implementation checklist asks organizations purchasing or using generative AI to first determine whether they can achieve their purpose without processing personal information.

The guidance brings privacy decisions into AI procurement and development before deployment. Financial institutions and fintechs using customer information with generative AI will need to justify why personal data is necessary, identify their legal role and preserve evidence across training, vendor selection, implementation and ongoing use.

Faster Finance Needs Faster Control

This week’s developments share one operating pattern. BitGo and Galaxy place tokenized assets inside collateral and lending. Alipay+, Partior and Citi connect domestic payment access with international distribution. FIS, the CSA and FATF reinforce the control layer required to run these systems safely at speed. For Canadian operators, the strategic question is which layer they truly control. Distribution without settlement access creates dependency. Automation without governance creates liability. Tokenization without custody, liquidity and legal certainty stays experimental. Durable businesses will own a useful layer, meet its control burden and connect cleanly to the rest.

NCFA offers various curated resources to help founders and investors stay current on developments that impact fintech markets. Get the weekly Whisperer and related market intelligence through NCFA's newsletter, view the latest fintech insights, industry research, or launch into emerging financial innovation opportunities.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

FCA Finfluencer Crackdown Meets Canadian Guidance

July 17, 2026 | NCFA Insight | Regulation And Policy, Wealth Investing And Trading, Risk Compliance And Regtech

AI Image – Finfluencer regulation and social media investment enforcement

FCA Finfluencer Enforcement And Canada’s Regulatory Position

On July 9, 2026, the UK Financial Conduct Authority reported the results of its finfluencer enforcement campaign. A coordinated week of action involving 9 international regulators produced 3 arrests, 6 criminal proceedings, 11 warning or cease and desist letters, 50 warning alerts and 650 social media takedown requests.

Canadian regulators weren’t watching from the sidelines. The Alberta Securities Commission, Autorité des marchés financiers, British Columbia Securities Commission and Ontario Securities Commission participated in the June 2025 operation. Earlier analysis asked whether finfluencers were facing a crackdown or clearer regulation.

The FCA’s latest figures show that enforcement has now become repeatable. Investigators can identify illegal content, connect creators to products and firms, request platform removals, issue public warnings and escalate selected cases into criminal proceedings.

The scale of the FCA’s supporting operation is just as relevant. During 2025, it issued 2,329 warnings about unauthorized or potentially fraudulent firms, compared with 2,240 in 2024. It secured 17 criminal convictions involving fraud, insider dealing, money laundering and data protection offences. Twelve people paid a combined £1.77 million in market abuse fines for market abuse.

Technology is improving that capacity. FCA automation reduced the handling time for simpler supervisory cases from as much as 4 hours to about 6 minutes on average. That doesn’t automate consequential decisions. It clears routine work so investigators can spend more time on repeat promoters, hidden compensation, unauthorized firms and cross border distribution.

What The Enforcement Data Reveals

The 650 takedown requests are the most commercially relevant number. Arrests attract attention, but removing hundreds of accounts and posts targets distribution. Illegal promotions lose value when creators can’t reach an audience, acquire leads or direct followers to a trading platform.

The FCA can examine multiple parties within one campaign. A creator may publish the content, a financial firm may pay for it, an affiliate network may track referrals and a platform may distribute it. The underlying product can then lead investigators to an unauthorized operator or regulated firm with weak approval controls.

Criminal proceedings provide the upper end of that response. The FCA accused 3 people charged after the 2025 operation of promoting high risk contracts for difference without authorization. Each faces an allegation of communicating an invitation to engage in investment activity contrary to section 21 of the UK Financial Services and Markets Act.

The April 2026 second global week of action showed how quickly the system had expanded. Seventeen regulators participated. The FCA requested the removal of 120 accounts and identified 1,267 illegal financial advertisements that reached at least 2,338,372 accounts. People or firms already listed on its Warning List accounted for 66% of those advertisements.

That 66% figure exposes a persistent enforcement problem. Many promoters aren’t unknown actors. They continue publishing after regulators have already identified the related firm, person or offer. Effective supervision therefore depends on account removal, repeat offender monitoring and platform cooperation, not warnings alone.

The FCA also secured a guilty plea, began criminal proceedings against 2 more people, issued 34 new warning alerts and updated 14 existing warnings during the April operation. Coordination now combines prosecution, surveillance, education and content removal rather than treating each promotion as an isolated post.

Canada Has Rules, Research And Active Cases

Canada’s legal foundation is already in place. In December 2025, the CSA and CIRO published Staff Notice 31-369, which explains how securities law applies to finfluencers, issuers and registered firms. The practical requirements appear in Canada’s finfluencer guidance.

The guidance doesn’t create a separate licence for creators. It examines the activity itself. A creator may need registration when they provide investment advice as a business, facilitates trades, arranges referrals or connects paid subscribers to copy trading. General market commentary may qualify for an exemption, but creators must still disclose financial interests and other conflicts clearly and on time.

Compensation also changes the compliance analysis. Cash payments, securities, affiliate income, referral fees and free products can establish a commercial relationship. A disclaimer such as “not financial advice” doesn’t cancel the substance of a recommendation, the creator’s compensation or the transaction being encouraged.

Responsibility extends beyond the creator. Registered firms must supervise people acting on their behalf, address referral arrangements, retain records and review relevant communications. Issuers remain responsible for paid investor relations activity and promotional claims made for their benefit. The joint staff notice applies the same principles to AI generated content and digital personas.

The investor evidence explains why regulators are paying attention. An OSC study of 655 Canadian retail investors found that 35% had made a financial decision based on finfluencer content. Those who acted on it were 12.2 times more likely to report being scammed on social media and 2.3 times more likely to have experienced a significant investment loss.

The OSC also ran a simulated investment experiment involving 1,465 Canadians. After viewing a promotional social media post, 38% bought the featured asset. Only 8% of the control group did the same. The full findings and behavioural differences appear in the finfluencer effect on Canadian investors.

Canada has also produced direct enforcement results. In September 2025, the Alberta Securities Commission imposed sanctions on James Domenic Floreani and Jayconomics Inc. for promoting 4 issuers through YouTube, X and Patreon without clearly disclosing that they published the content on behalf of those issuers.

The respondents received a $30,000 administrative penalty, $10,185.10 in costs and 2 year restrictions covering investor relations activity, public securities promotion and securities or derivatives advice.

British Columbia added a preventive layer during the April 2026 operation. The BCSC issued 14 compliance letters to YouTubers and other promoters who had discussed publicly traded B.C. companies. It also referred to an active proceeding alleging that sponsored issuer promotions weren’t disclosed clearly.

How Canadian Enforcement Could Develop

The FCA operates a national financial promotions regime and can report one consolidated set of arrests, warnings, takedowns and prosecutions. Provincial and territorial authorities administer Canadian securities regulation, while CIRO supervises investment dealers, mutual fund dealers and regulated marketplaces.

Canadian action may therefore appear as several provincial cases, coordinated review periods, issuer investigations, warning letters and firm supervision rather than one national enforcement tally. That can make the activity look smaller even when regulators review the same creators, platforms and promotional networks.

The operating implications are already clear.

  • Issuers need to know who promotes their securities and how they compensate those people
  • Dealers and fintech platforms need approval, monitoring and record keeping controls for creator campaigns
  • Affiliate arrangements require the same scrutiny as traditional referrals
  • Creators need to separate education from recommendations and disclose commercial interests where followers can actually see them

Platforms are also becoming part of the enforcement process. When regulators can connect warnings to hundreds of removal requests, account access becomes a compliance dependency. Firms using social media for distribution can’t treat the creator’s channel as an independent marketing asset beyond their control.

Canada doesn’t need to duplicate the FCA’s structure to produce comparable enforcement. Its regulators are already participating in the same international operations, applying national guidance and using provincial proceedings. The open question is whether those actions will become visible as a coordinated Canadian program or remain distributed across separate regulators and cases.

Talking Point

Will Canada’s finfluencer guidance support coordinated enforcement across provinces, platforms and firms, or will separate cases continue defining the compliance boundary?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA engages with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Jack Henry Embeds Google AI Security In Bank Operations

July 13, 2026 | NCFA Market Activity | Cybersecurity And Fraud, Artificial Intelligence And Data, Banking And Credit

AI Image – AI security monitoring across bank systems

Agentic Threat Detection Across Mixed Banking Systems

On June 25, 2026, Jack Henry expanded its Google Cloud collaboration to develop agentic AI security for banks and credit unions. The U.S. banking technology provider serves about 7,400 community financial institutions and plans to combine Google Security Operations, Gemini Enterprise Agent Platform, and Mandiant Consulting across Google Cloud, other cloud services, and on-premises systems.

The deal is less about access to an advanced model than the work required to deploy one inside a bank. Security evidence is spread across user accounts, devices, applications, networks, and cloud services. Analysts must connect those records quickly enough to determine whether an alert is harmless or part of an attack. Smaller institutions often lack the security teams and integration capacity to do that across several enterprise products.

The divide and conquer commercial logic of the deal is Google brings the models, security software, and threat expertise. While Jack Henry brings the bank relationships and operating knowledge required to put them to work.

AI Agents Cut Investigation Time

Google Security Operations collects security data from across an institution’s systems and connects related alerts into an investigation. Its Triage and Investigation Agent can retrieve evidence, apply threat intelligence, assess likely causes, and explain its findings.

Google says the agent has processed more than five million alerts and reduced a typical 30-minute manual investigation to about 60 seconds. Those are Google product results, not outcomes reported by Jack Henry customers.

The operating gain comes from completing the early investigation before an analyst steps in. Instead of opening several products, finding related records, and rebuilding the sequence of events, the analyst receives an assembled case with supporting evidence and a proposed response.

Sensitive actions still require clear limits and human oversight. Google can pair AI investigations with fixed playbooks and require approval before isolating a device, disabling an account, or blocking traffic. Jack Henry hasn’t said where it will draw those boundaries, how customers will audit agent decisions, or what happens when an automated recommendation is wrong.

Release timing, pricing, implementation requirements, and the first participating institutions also remain undisclosed, so the announcement is good on tech direction but light on adoption or performance figures inside an operating bank.

Mandiant Consulting adds threat modelling, security assessments, and red team testing. That work tests the design before attackers do. Gemini handles reasoning, while Google Security Operations provides the data and investigation tools.

Jack Henry must make the combined service fit each institution’s systems, controls, and support model. That integration is the difficult part.

Jack Henry Owns The Banking Integration

A bank could buy Google’s security products directly. It would still need to connect the right data, define agent permissions, build response procedures, satisfy audit requirements, and decide who remains accountable for each action.

Jack Henry already operates inside that environment. Its core processing, digital banking, payments, lending, and operational products support institutions that rarely replace critical systems. It also manages hosted and on-premises deployments that a cloud provider may not control.

The companies began working together in 2022 on cloud data, reporting, and integration services. Security extends that relationship into a product Jack Henry can configure around each customer and deliver through an existing technology and support contract.

That could make AI security another banking software service rather than a separate enterprise purchase. Core providers already control the connections, implementation work, and customer access needed to distribute agents at scale.

Security specialists still compete on detection quality, threat intelligence, and response tools. CrowdStrike and Palo Alto Networks are adding agents to their products, while Fiserv offers managed cybersecurity services and is developing AI capabilities. Jack Henry competes from a different position. Its advantage is knowing how community institutions run and where security tools must connect.

Google gains a route into thousands of regulated institutions without implementing its products one bank at a time. Jack Henry can add a service whose value depends on its knowledge of each customer’s systems and operating requirements.

This is where enterprise AI economics become clearer. Foundation models can be sourced from a small group of large providers. The commercial asset is access to the workflow where the model can complete useful work under controlled permissions.

That favours software companies with deep customer integration. Fintech founders don’t need to build a foundation model, but a general AI interface won’t be enough. TD’s AI loan decisioning deployment shows why the value comes from placing verification and decision tools inside an active lending workflow. A specialized process, regulated decision, proprietary dataset, or difficult integration gives an agent work that an incumbent can’t easily reproduce.

Canadian Banks Face The Same Deployment Test

Jack Henry hasn’t announced a Canadian release, but the deployment problem is familiar. Canadian regulated AI workshops have identified vendor dependence, data quality, model validation, and accountability as barriers to production use.

Access to a capable model isn’t the constraint. Banks need to connect it to existing systems without losing control of data, permissions, decisions, or operational risk. National Bank’s Sardine deployment follows that reality by embedding external device intelligence and risk scoring into retail, commercial, and wealth operations.

The Canada AI Consortium is working on common controls for models, agents, users, and enterprise systems. Its use cases differ from Jack Henry’s security project, but the operating requirement is the same: agents need restricted access, visible decisions, and accountable people.

For Canadian banks and fintechs, the commercial challenge is solving those controls inside regulated workflows. Products that leave the integration and governance work to the bank may struggle to progress beyond a pilot.

Talking Point

As foundation models become easier to replace, will banking software competition depend less on who owns the AI and more on who controls the workflows where agents can act?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter