Karsten Wenzlaff, Advisor
August 26th, 2025
July 3, 2026 | NCFA Insight | Cybersecurity And Fraud, Digital Identity And Trust, Risk Compliance And Regtech, Payments And Money Movement, Digital Assets Blockchain And Tokenization, Artificial Intelligence And Data

Governments are no longer treating post-quantum cryptography as a research topic. They're now publishing migration plans.
On June 22, 2026, the White House issued an order on advanced cryptographic attacks, including the risk that adversaries collect encrypted data today so they can decrypt it later. The same day, a separate White House order advanced U.S. quantum innovation across computing, sensing, networking, applications, and industry partnerships.
That combination is the useful development marker for fintech. Governments are funding quantum capability while also pushing organizations to prepare for the security risk that follows.
The financial sector doesn't need to know the exact year a cryptographically relevant quantum computer arrives before it starts planning. Long time customer data, payment credentials, digital identity systems, API certificates, custody systems, vendor software, archived records, and cryptographic keys may remain sensitive for years.
Quantum readiness is therefore becoming an operating requirement. Not someday. Now.
The policy picture is getting clearer.
NIST finalized its first three post quantum cryptography standards in August 2024. The standards are FIPS 203 for ML-KEM, FIPS 204 for ML-DSA, and FIPS 205 for SLH-DSA. NIST says organizations should begin migrating systems to quantum resistant cryptography.
NCFA has already tracked how post quantum cryptography is entering implementation, with payments, digital identity, secure messaging, APIs, and financial data all exposed to the migration challenge.
Canada has started, too. The Canadian Centre for Cyber Security published a roadmap for migrating Government of Canada non classified IT systems to post quantum cryptography, covering stakeholders, phases, milestones, governance, and departmental planning.
Financial authorities are paying attention too. The Bank for International Settlements published a quantum readiness roadmap for the financial system, and the G7 Cyber Expert Group issued a roadmap for the financial sector's transition to post quantum cryptography.
The practical message is this. Start with awareness, find where cryptography is used, assess risk, plan migration, and work with vendors before deadlines become urgent.
The hardest quantum risk is not only future system compromise. It is long term data.
Financial institutions protect account records, payments data, identity documents, loan files, custody records, private market documents, insurance records, tax files, transaction histories, and compliance archives. Some of that data must stay confidential for years or decades.
That creates the harvest now, decrypt later problem. An attacker can collect encrypted data now and wait for stronger decryption capability later.
For fintechs, this impacts the planning window. A company doesn't need to be systemically important to hold sensitive data. A payments provider, open banking intermediary, wallet provider, identity service, lending platform, wealthtech app, regtech vendor, or crypto custodian may all depend on cryptography that was never designed for a quantum era.
Post quantum migration starts with discovery.
Most organizations know they use TLS, certificates, signing keys, databases, cloud services, APIs, authentication systems, payment connections, and vendor platforms. Fewer have a current inventory of which cryptographic algorithms protect each system, which assets must remain confidential long term, and which vendors control the upgrade path.
That's why cryptographic inventory keeps appearing across official guidance.
A fintech should be able to answer basic questions:
Without that inventory, migration plans become guesswork.
Fintech security is rarely managed by one company anymore.
A single product may rely on cloud hosting, identity verification, payment processors, data aggregators, card issuing platforms, custodians, wallet technology, fraud systems, CRM tools, analytics software, email providers, certificate authorities, and outsourced compliance systems.
That makes post quantum readiness a vendor risk issue.
A fintech can upgrade its own code and still remain exposed through a vendor that cannot explain its cryptographic dependencies. Banks and credit unions face the same issue in reverse. They may need to ask whether fintech partners can support post quantum requirements before onboarding, renewing, or expanding contracts.
The procurement question changes from "is this vendor secure today?" to "can this vendor survive a cryptographic transition without disrupting our product, customers, or regulatory obligations?"
Quantum readiness touches more than cybersecurity teams.
In payments, cryptography protects authentication, transaction integrity, messaging, API connections, certificates, and sensitive account data.
In digital identity, it protects credentials, signatures, documents, device binding, verification records, and trust chains.
In crypto and digital assets, it touches wallets, custody, private keys, signing systems, transaction authorization, smart contract administration, and institutional key management. BTQ's quantum safe Bitcoin and stablecoin roadmap highlights one approach to preparing digital asset infrastructure for post quantum cryptography.
In open banking, it affects API security, consent records, data sharing, third party access, and customer authentication.
In capital markets, it touches trading access, fund administration, investor records, tokenized securities, transfer agency, data rooms, reporting, and long term documents.
In AI and data systems, it affects model access, training data, confidential records, synthetic data pipelines, and secure data exchange.
That breadth is why the topic belongs with executives, product leaders, compliance teams, boards, and investors, not only cryptography specialists.
Canada's Cyber Centre roadmap gives public sector organizations a starting point. It also gives fintech and financial services leaders useful guidance that migration will take planning, governance, technical discovery, budgets, and coordination.
Canada doesn't yet have a full financial sector post quantum mandate comparable to a hard compliance deadline, but that statement should not create comfort.
Canadian fintechs operate in a global market. They sell into banks, credit unions, enterprises, governments, insurers, capital markets, payment networks, and regulated financial institutions. Their buyers may start asking post quantum questions before Canadian rules require formal answers.
A fintech that can show cryptographic inventory, vendor readiness, migration planning, and crypto agility may have an advantage in enterprise sales. A fintech that cannot answer basic questions may face longer diligence, higher security friction, or blocked procurement.
The near term opportunity is not building quantum computers. It's helping financial organizations prepare for the cryptographic transition. Quantum Bridge's USD $8M raise shows Canadian capital already backing deployment ready quantum safe security for finance, telecom, government, and defence.
Product opportunities include:
These opportunities are practical because they map to work financial firms already need to do. They need to know what they use, what they protect, which systems carry the highest risk, which vendors control dependencies, and how migration can happen without breaking production systems.
These are the kinds of tools that belong on NCFA's Financial Innovation Map, such as identity, payments, custody, regtech, data governance, and cyber resilience.
Quantum readiness won't arrive as a single upgrade.
Organizations will need inventories, test environments, migration sequencing, vendor commitments, product changes, audit evidence, customer communications, and fallback plans. Some systems will be easy to update. Others will depend on old software, hardware limits, contracts, third party platforms, or regulatory approvals.
That's why waiting for a precise quantum break date is the wrong approach for operators. Ask yourself, your team, your leadership this simpler question, "If a regulator, bank partner, insurer, enterprise buyer, or board asked tomorrow where vulnerable cryptography sits in the business, could the company answer?"
For many fintechs, the honest answer is probably no. So that's the opening to start.
Takeaway: Post quantum cryptography isn't a distant science fiction story anymore. It's becoming part of how financial organizations prove they can protect data, manage vendors, maintain trust, and keep critical services running through the next security transition.
If post quantum readiness starts with knowing where cryptography lives, should fintech due diligence now include a cryptographic inventory before major bank, payments, custody, or identity partnerships?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer to peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: [www.ncfacanada.org](http://www.ncfacanada.org)
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 2, 2026

Picture the moment a Canadian fintech dreads most. A regulator's letter arrives. A customer in Quebec, or in a newcomer community you were proud to serve, relied on a disclosure written in their own language, and that disclosure said something the English original did not. Now you are explaining to a supervisor how the wording was produced, who checked it, and why a fee, a risk, or an obligation came out wrong. There is no comfortable answer, because the honest one is this: a single AI model wrote it, and nobody verified it.
That scenario is no longer rare or hypothetical. As fintechs scale into new markets and serve multilingual communities at home, more and more compliance language, terms of service, risk disclosures, consent flows, regulatory filings, is being produced by one AI model with no accuracy standard behind it. It feels efficient. It looks clean. And it quietly builds a liability that only reveals its price later, at the point where it is most expensive to fix.
What makes this gap so dangerous is that its cost stays invisible until it is realized. A mistaken clause does not throw an error message. It sits inside your disclosure reading perfectly, right up until an audit, a customer complaint, or an enforcement review turns it into a remediation project, a forced re-disclosure, a penalty, or a stalled market launch. Regulators do not distinguish between an error a person made and one a machine made. Across Canada's framework, from FINTRAC's obligations under the PCMLTFA, to provincial securities disclosure rules, to the Retail Payment Activities Act, the accuracy of what a customer is told is a supervised matter, not a marketing preference. For firms serving official-language communities, bilingual accuracy is frequently a legal expectation rather than a courtesy.
Every one of those outcomes carries a number. Legal hours. Remediation. Re-issued documents. Delayed revenue while a launch is held. And the quiet, compounding cost of a regulator who now watches you more closely than your competitors. The bill for one wrong word is rarely small, and it almost never arrives on your schedule.
Here is what most teams have not priced in: AI models disagree with one another, and they disagree most on the language that matters most. Independent testing makes this concrete. In Intento's State of Translation Automation 2025, baseline machine systems averaged roughly 10 to 15 errors per text before customization, and synthesized industry data places single top-tier large language model hallucination rates in translation tasks between 10% and 18%. On a marketing tagline, a 12% error band is a style problem. On a regulatory disclosure, it is a liability with a dollar figure attached.
Those errors are idiosyncratic to each model: one engine mishandles a defined term, another drops a conditional clause, a third invents a plausible equivalent that does not exist in the target jurisdiction's regulatory vocabulary. And the risk compounds with length, so the longer the document, a prospectus, a payment services agreement, a full disclosure set, the more independent points of failure a single model introduces. Then there is the cost even a correct-looking output creates. Someone still has to check it. Every hour a compliance lead spends re-reading machine output they cannot fully trust is an hour billed to the single-model shortcut, a verification backlog that never appears on the invoice but is paid every single week.
The way out is architectural, not aspirational. If individual models fail idiosyncratically, then running many at once and keeping only what most of them independently produce turns disagreement into a filter. Intento's own findings point the same way: Slator's reporting on that study noted that a multi-agent workflow explicitly designed to avoid compounding hallucinations delivered the highest quality across nine of eleven language pairs, outperforming any single engine.
This is the principle behind MachineTranslation.com, an AI translation platform built for exactly this failure mode. Its SMART mechanism runs a text through 22 AI models simultaneously, evaluates the source context to determine the most accurate rendering, and returns the output the majority of those models agree on. Because hallucinations are model-specific, cross-model agreement functions as an automated audit: the outlier renderings that shift what an obligation means are structurally filtered out before anyone sees the result. Internal benchmarks put the effect at roughly a 90% reduction in critical error risk, with agreed errors falling below 2% and up to 85% of outputs reaching professional-quality standard. The point is not speed. The point is certainty, and certainty is precisely what removes the hidden costs: fewer errors to remediate, and far less of the verification backlog that quietly drains a compliance team's time.
Cross-model agreement handles accuracy at scale. For the documents where a single error is unthinkable, a regulator-facing filing, a signed customer agreement, a prospectus, certainty has to be absolute, and that is where a second pillar matters. On the same platform, human verification escalates any output to a professional reviewer, adding a validated final check on top of the machine layer. This is not theoretical. Tomedes, the language company behind the platform, documents its high-stakes work in a library of recent translation case studies spanning certified legal filings, court-ready documents, and financial materials handled under confidentiality and delivered to compliance standards. The economics are blunt: the cost of one professional reviewer is trivial next to the cost of one enforcement action. Consensus for accuracy across volume, human verification for certainty on the documents that cannot be wrong.
None of this asks Canadian fintechs to become linguists. It asks them to govern this control the way they already govern every other one. Regulators are moving in exactly that direction on AI more broadly. NCFA's own coverage of the IOSCO AI supervisory toolkit for capital markets frames the expectation plainly: where AI touches a supervised process, firms are expected to show governance, oversight, and accountability for how the system behaves.
Translating compliance content is one of those processes, and today it is often the least governed one in the building. The practical steps are small. Add multilingual accuracy to the risk register. Ask who verified the language a customer relied on, and how. Replace a single ungoverned model with an architecture that removes the error by design and validates the highest-stakes content with a human. The cost of getting the language right the first time is a rounding error next to the cost of explaining why you did not. For a Canadian fintech scaling across markets or serving communities in more than one language, that is the whole choice: money spent on prevention, or money lost to a disclosure you have to defend.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
June 29, 2026 | NCFA Feature | Open Banking And Open Finance, Digital Identity And Trust, Cybersecurity And Fraud, Risk Compliance And Regtech, Fintech And Innovation

On June 26, 2026, the Government of Canada published Consumer Driven Banking regulations together with new fraud prevention regulations, the most significant progress in Canada's open banking implementation since legislation received Royal Assent earlier this year.
At first glance, the two regulatory packages appear separate. One establishes the operating rules for consumer driven banking. The other requires federally regulated banks to strengthen fraud prevention for electronic funds transfers.
Together, however, they reveal something much bigger.
Canada isn't simply launching open banking. It's building the trust infrastructure needed before open finance can scale.
The problem is that millions of Canadians already share their financial information through screen scraping, a practice tracked as a core open banking risk in Bank Of Canada Signals Open Banking Timing Risk. Finance Canada estimates roughly nine million Canadians currently use screen scraping despite the security, liability, and consumer protection concerns it creates. The new framework is designed to replace that model with accredited participants, standardized APIs, consumer controlled consent, and clear accountability.
Much of the early discussion around open banking has focused on data portability. The regulations suggest Finance Canada sees the challenge differently.
Data sharing is only one part of the system.
Only after these pieces exist does secure data sharing become practical.
The Regulatory Impact Analysis estimates the framework will generate approximately $13.2 billion in net benefits over ten years, compared with implementation costs of about $457.7 million, largely through greater competition, improved consumer choice, reduced friction, and innovation.
Those numbers reinforce that Consumer Driven Banking is being treated as national financial infrastructure rather than another fintech initiative.
Some viewed the fraud regulations as a separate announcement, but the timing suggests otherwise.
As consumers gain greater control over financial data and eventually broader payment functionality, fraud risks also change. Criminals increasingly exploit social engineering, account takeover, impersonation, and authorized push payment scams rather than technical weaknesses alone.
Finance Canada's fraud framework responds by requiring federally regulated banks to establish policies and procedures to detect, prevent, and mitigate consumer targeted fraud involving electronic funds transfers.
The regulations also introduce stronger expectations around consumer controls, including the ability to manage transaction capabilities and limits, express consent before enabling electronic funds transfer functionality, and fraud reporting to the Financial Consumer Agency of Canada.
Greater consumer control must be matched by stronger consumer protection. The inherent message is that the federal government wants to make fraud prevention part of the architecture rather than an afterthought.
Reading the regulations together shows that trust is no longer treated as a policy objective. It's becoming operational and the framework combines:
None of those capabilities creates value on its own, but collectively they create an environment where consumers, banks, fintechs, and regulators can exchange financial information with greater confidence than today's screen scraping model.
The regulations therefore answer an important implementation question that has existed since Canada's open banking discussions began several years ago.
Trust is not assumed. It's engineered.
The regulations also strengthen several areas already appearing across NCFA's Financial Innovation Map.
Consumer consent requirements create opportunities for consent orchestration platforms that help consumers understand, grant, renew, and withdraw permissions across multiple financial relationships.
Accreditation requirements create opportunities for compliance operations platforms that help fintech companies prepare for accreditation, maintain operational controls, manage evidence, and demonstrate ongoing compliance.
Fraud obligations strengthen demand for behavioural fraud analytics, scam detection, mule account monitoring, transaction risk scoring, and real time payment controls.
Authentication requirements reinforce opportunities for digital identity, credential management, and secure customer authentication.
Technical standards create demand for API testing, interoperability tools, certification services, and developer infrastructure.
Liability and complaint provisions strengthen opportunities for workflow automation covering dispute management, evidence collection, case handling, and regulatory reporting.
None of these businesses exists because regulators explicitly created them, but they will emerge because every operational requirement creates work that financial institutions and technology providers must perform efficiently. And that's often where durable fintech companies are built.
The initial Consumer Driven Banking framework focuses on secure consumer permissioned data sharing. It's an intentional starting point.
Once accreditation, liability, consent management, authentication, and technical standards mature, the same infrastructure can support broader open finance capabilities, including additional financial products and, potentially, future write access.
The regulations therefore describe more than the first phase of open banking. They establish the operating foundation for future financial data ecosystems.
The opportunity is not limited to data sharing. It extends into the systems that make data sharing safe, usable, auditable, and commercially scalable.
That includes trust infrastructure, fraud infrastructure, consent systems, API reliability, compliance operations, data governance, and consumer protection workflows.
The next phase of Canada's open banking market will depend on whether these operating layers mature quickly enough for banks, fintechs, consumers, and businesses to use the framework with confidence.
That makes today's implementation decisions highly important because many of tomorrow's fintech products will inherit the rules established now.
For Canada's fintech ecosystem, this strengthens the opportunity case outlined in NCFA's Open Banking Opportunity Brief. The next iteration of value will come from tools that make consent, risk, identity, fraud controls, interoperability, and compliance easier to operate at scale.
If trust, consent, fraud controls, liability, and interoperability become core infrastructure for open banking, which product category will create the greatest competitive advantage for Canadian fintech companies over the next five years?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
June 22, 2026 | NCFA Insight | Artificial Intelligence And Data, Risk Compliance And Regtech

On June 22, 2026, Banco Santander reported that its AI first strategy generated €35 million in business value in Q1 2026, with expected value of more than €200 million by year end and a target of more than €1 billion between 2026 and 2028. That's a regulated bank putting numbers around AI execution.
The more interesting part is how Santander is trying to get there. The bank has extended AI access to all 185,000 employees, reported more than 280 AI automation agents in production, and previously described its ambition to become an AI native bank.
Ricardo Martín Manjón, Chief Data & AI Officer at Banco Santander, put the strategy plainly:
“For me, being AI-first means applying AI where it can have tangible impact.”
For Canada, the timing of this announcement is important because Santander recently received approval to operate as a federally regulated bank in Canada. So its AI operating model more than a global case study. It's a preview of how new banking competitors may bring AI, governance, fraud controls, and measurable operating discipline into regulated Canadian markets.
The first AI cycle rewarded access. Banks tested foundation models, launched copilots, built internal assistants, and looked for productivity wins. That phase is maturing fast. Models are easier to access. Cloud tools are easier to use. Building a convincing demo is no longer the hardest part.
The harder test is operating AI inside a regulated financial institution without losing control of risk, data, decisions, accountability, or customer trust.
That's where Santander’s publicly released data become strategically useful. Specifically, the update points to measurable business value, enterprise wide access, employee adoption, automation agents, and governance controls across ethical, legal, cybersecurity, and risk requirements. This is what AI moving from lab work into operating infrastructure looks like.
One underappreciated piece of the story is Santander AI Lab’s open source work. Its Gen Fraud Graph project is described as an Apache 2.0 open source initiative for generating synthetic fraud graphs and advancing fraud detection capabilities. The technical repository is also available on SantanderAI’s GitHub.
Fraud detection is one of the fastest ways to expose whether financial AI can be trusted. It touches financial crime, AML controls, identity checks, transaction monitoring, customer friction, model risk, and auditability. A model that performs well in a slide deck but cannot be tested, explained, monitored, or reviewed isn't ready for regulated scale.
Synthetic fraud graphs help solve a practical problem. Banks need realistic fraud scenarios to test detection systems, but they cannot freely share customer data or investigative information. Synthetic environments provide a safer way to benchmark performance, validate models, and document results.
The choice of fraud is revealing. Santander didn't launch its open source thread with a marketing assistant or a generic productivity tool. It highlighted infrastructure connected to risk.
Fraud teams need speed, but they also need evidence. Compliance teams need explainability. Risk teams need controls. Boards need accountability. Regulators need confidence that systems can be monitored and challenged.
For fintechs, this move by Santander is both a warning and an opportunity. AI claims won't be enough in fraud, AML, onboarding, underwriting, customer service, complaints, trading, surveillance, or compliance workflows. Buyers will increasingly ask for testing evidence, audit trails, human review, data controls, drift monitoring, and proof that the system works under pressure.
Recent work from IOSCO, OSFI, the European Union, the FCA, and other supervisory bodies points in the same direction. Institutions want measurable results. Customers expect accountability. The result is a growing focus on how AI systems are tested, monitored, explained, and challenged. That's why AI is creating a new compliance burden at the same time it creates productivity gains.
Santander reports more than 280 AI agents operating across the organization alongside enterprise wide training, governance controls, and measurable business outcomes. The same operating question now appears across AI agents entering financial workflows, customer onboarding, fraud detection, transaction monitoring, and compliance operations. The challenge is proving that it can operate safely inside regulated environments, and fraud amplifies the challenge immediately.
AI clones, biometric breaches, faster payments, and cyberattacks are weakening older trust signals, which raises the value of new verification controls for financial trust. Synthetic fraud graphs fit into that bigger problem because they give teams a safer way to test detection systems without exposing customer data or live investigations.
For banks, fintechs, payments firms, and infrastructure providers, that changes the economics of competition. Access to advanced models is becoming easier. Building a prototype is becoming easier. Producing evidence that a system can be trusted under real operating conditions remains difficult.
The first AI race was about capability. The next one is quickly focusing on proof.
If access to advanced AI becomes commonplace, will governance infrastructure and proof of control become more valuable than proprietary models in regulated financial services?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |