Karsten Wenzlaff, Advisor
August 26th, 2025
May 8, 2026 | NCFA Insight | Regulation And Policy, Cybersecurity And Fraud, Artificial Intelligence And Data

On May 7, 2026, Apple and Meta warned that Canada’s Bill C-22 could weaken encryption, pushing a long running lawful access debate back into the spotlight. The bill reaches far beyond Silicon Valley politics. It touches the same infrastructure that supports digital banking, fintech apps, cloud platforms, AI systems, wallets, fraud detection, secure communications, and identity verification.
What started as a policing and national security issue increasingly looks like a broader fight over cybersecurity, digital trust, and how governments regulate access to modern technology systems.
Bill C-22 creates a lawful access framework for electronic service providers operating in Canada.
Part 1 updates investigative powers related to subscriber information and transmission data.
Part 2 creates the Supporting Authorized Access to Information Act, which would require certain providers to maintain operational and technical capabilities that allow them to comply with lawful access requests under existing Criminal Code or CSIS Act authorities.
The scope is broad. The bill applies to electronic service providers involved in creating, storing, processing, transmitting, receiving, or making information available electronically. That definition reaches beyond telecom networks and traditional internet providers. Depending on regulations and ministerial orders, the framework could affect cloud providers, messaging platforms, device ecosystems, AI infrastructure, payment systems, digital identity platforms, and fintech companies handling sensitive customer information.
The government argues that Canada’s investigative framework no longer matches modern communications technology. Public Safety Canada says current lawful access rules still reflect a 1995 voice telephony environment, even though investigations now involve encrypted messaging systems, cloud services, internet platforms, and cross border digital infrastructure.
The FBI, RCMP, and other law enforcement agencies have long referred to encrypted communications and inaccessible digital evidence as the “going dark” problem.
Investigators increasingly struggle to access information tied to organized crime, online fraud, ransomware, terrorism, child exploitation, and financial crime because modern services collect less accessible data or use strong encryption that even the provider cannot access directly.
The Canadian Association of Chiefs of Police publicly supported the legislation and argued that police need updated tools to investigate serious crimes in digital environments. Justice Canada also says the bill would allow judges to authorize requests for subscriber information or transmission data from foreign telecommunications or social media providers where there are reasonable grounds to suspect an offence and the information would help the investigation.
The fraud backdrop strengthens the government’s case politically. Competition Bureau Canada reported CAFC data showing Canadians lost more than $704 million to fraud in 2025, while only 5% to 10% of fraud gets reported. Reported losses since 2022 have surpassed $2.4 billion.
Critics argue the proposed solution risks weakening the same security architecture modern digital systems depend on. Reuters reported that Apple warned the bill could allow Canada to “force companies to break encryption by inserting backdoors.”
Meta argued the legislation could force providers to weaken encryption protections or undermine zero knowledge systems designed so providers themselves cannot access customer data.
Public Safety Canada disputes that interpretation. Government officials say the legislation would not require providers to create a “systemic vulnerability” in encryption systems, which is now at the center of the debate.
The problem is technical as much as legal. Security engineers often argue that once a system preserves exceptional access for any party, it creates a potential weak point that can eventually attract criminals and and insider abuse.
For fintechs and financial institutions, it's the same strong encryption that protects account credentials, wallet keys, transaction approvals, secure communications, and increasingly AI workflows that may soon handle sensitive financial tasks autonomously.
The UK offers an important lesson for Canada. Earlier this year, Apple removed Advanced Data Protection for new UK users after government pressure around encrypted cloud access. Apple later stated that UK users would no longer have access to the feature and said, “we have never built a backdoor or master key.”
The UK outcome shows how a lawful access demand can expand into a wider cybersecurity and trade problem. Instead of settling the issue, Apple’s feature rollback intensified scrutiny from privacy advocates, security experts, and U.S. officials concerned about government access to encrypted cloud data.
Canada could face the same kind of fallout if Bill C-22 leaves companies unclear about what they may be forced to build, disclose, weaken, or keep secret under future access orders.
Timing isn't great. Canada is already dealing with pressure around digital sovereignty, platform regulation, AI governance, and trade relations with the United States.
In June 2025, Canada rescinded its Digital Services Tax to restart trade negotiations with the U.S. The CUSMA review is an active pressure point for companies operating across borders through cloud infrastructure, data systems, and digital financial services.
Europe is moving differently. The European Commission imposed the first Digital Markets Act penalties in April 2025, including €500 million against Apple and €200 million against Meta. Meanwhile, the Trump administration has taken a more defensive posture toward American technology firms facing foreign digital regulation, including ordering U.S. diplomats to push back against foreign data sovereignty rules.
That leaves Canada to balance a convergence of pressure around public safety expectations, cybersecurity concerns, platform dependence, trade risk, and digital sovereignty ambitions.
Large platforms will likely absorb the first round of scrutiny. The second order effects may matter more for fintech operators and infrastructure providers.
Fintechs, digital identity companies, crypto wallet providers, cloud based banking platforms, AI finance systems, payment processors, fraud vendors, and regulated financial institutions could all face pressure around compliance architecture, data retention, encryption design, and cross jurisdiction operational requirements.
The cost may not appear immediately through direct enforcement. It may emerge through audits, vendor obligations, insurance requirements, infrastructure redesign, compliance overhead, or changes to how secure systems get built and marketed in Canada.
Encryption is key to financial infrastructure. Customer trust, cybersecurity resilience, fraud prevention, and digital competitiveness now all depend heavily on whether secure systems remain genuinely secure.
Does Canada need to choose between ineffective investigations and weakened encryption for everyone?
A better version of the bill would be more precise. It should clearly say which companies can receive access orders, protect end to end encryption and zero knowledge systems, require independent technical review before any order is approved, and give companies a real way to challenge orders that put security at risk.
The core dispute is not whether courts can authorize lawful investigations. It is whether governments should be able to force companies to preserve technical access inside systems designed specifically to remove that access. That is the fight at the centre of the global encryption debate.
Encryption is foundational infrastructure for finance, AI, communications, identity, and cloud systems. Canada’s challenge is no longer simply how to access digital evidence. It's how to modernize investigations without creating weaker systems that undermine cybersecurity, trust, and long term digital competitiveness.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
May 1, 2026 | NCFA Fintech Market Activity | Risk Compliance And Regtech, Artificial Intelligence And Data

On May 1, 2026, Datavault AI and CyberCatch announce a binding letter of intent for Datavault AI to acquire 100% of CyberCatch in an all stock transaction structured as a court approved plan of arrangement under the Business Corporations Act (British Columbia).
The proposed deal values CyberCatch at about CAD $136.8 million (CAD $5.11 per share). CyberCatch shareholders would hold about 7.52% of the combined company, with Datavault AI shareholders holding about 92.48% on a non fully diluted basis.
CyberCatch CYBE is listed on the TSX Venture Exchange and OTCQB US Venture Market, focuses on continuous compliance and AI driven cyber risk testing. Its platform uses generative AI to assess whether controls are in place, then uses agentic AI to simulate attack scenarios and produce a Cyber Breach Score. The model is built around continuous validation rather than periodic audit cycles.
Timing aligns with rising demand for continuous security assurance. The release cites Gartner estimates that global information security spending will reach $240 billion in 2026, while AI driven security could grow to $160 billion by 2029 (up from $49 billion 2025). IBM’s 2025 Cost of a Data Breach report places the average U.S. breach at $10.22 million and the global average at $4.44 million.
Regulatory pressure is picking up. The U.S. Department of Defense started rolling out its CMMC program on Nov 10, 2025, and stricter certification requirements are expected to expand in 2026 across about 220,000 contractors and suppliers. CyberCatch aligns its platform with widely used standards such as CMMC 2.0, NIST, ISO 27001, HIPAA, and PCI.
There’s also a growing focus on future security risks. As computing power increases, current encryption methods may become easier to break. CyberCatch is working on quantum resistant encryption, and signs like Google’s 2029 timeline for upgrading its systems show that companies are starting to prepare now.
Nathaniel T. Bradley, CEO, Datavault AI:
“Cybersecurity is no longer a separate stack from data and AI - it is the precondition for both. CyberCatch's continuous compliance platform is expected to provide another strategic advantage by adding to DataValue®, DataScore®, and the IDE® a real-time risk and compliance signal at every node of our quantum-secured edge fleet, from federal contractors to enterprise data customers.”
For Datavault AI, the transaction adds a compliance layer to its broader data, edge computing, and tokenization infrastructure. The company positions CyberCatch as a way to deliver real time assurance across regulated environments, including fintech, healthcare, energy, and defence.
CyberCatch brings a Canadian public market cybersecurity and regtech platform into a U.S. AI infrastructure strategy.
The transaction is subject to a definitive agreement, due diligence, board approvals, CyberCatch shareholder approval, British Columbia court approval, Nasdaq approval, TSX Venture Exchange approval, and other customary closing conditions. The parties have agreed to a 45 day exclusivity period.
Will continuous, AI driven compliance become a required layer for regulated industries, or will firms continue relying on periodic audits that do not reflect real time risk?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Apr 29, 2026 | NCFA Resource | Artificial Intelligence And Data, Risk Compliance And Regtech

The MIT AI Risk Repository is an open database created by researchers at MIT to bring structure to AI risk. It compiles more than 1,700 documented risks from 74 existing frameworks and studies into a single system. The aim is practical. AI risk guidance exists, but it is scattered and inconsistent across sources. This repository organizes it into a shared taxonomy, with links that show how risks connect and compound across systems.
In practice, this gives teams a consistent way to map risk across AI systems.
Teams already running AI in production will get the most from this. If you’re operating models in lending, fraud, onboarding, or customer support, it gives you a structured way to think about risk across systems. Larger fintechs and financial institutions dealing with audit and regulatory pressure will find it useful quickly. Early stage teams without deployed models will likely find it heavy and not immediately relevant.
The strength here is structure. It turns fragmented AI risk concepts into something teams can actually use, and the causal links add depth that most frameworks miss. At the same time, it does not rank risks by likelihood or impact, and it does not translate directly into controls or regulatory compliance. Some classifications reflect interpretation across sources, and emerging risks may not be fully captured. Teams still need to apply judgment and build their own control layer on top.
Repository Homepage (AI risk overview and navigation)
Full Risk Database (AI risk dataset for audits)
Causal Taxonomy (AI risk relationships mapping)
Domain Taxonomy (AI risk classification framework)
Research Paper (AI risk methodology and design)
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Apr 28, 2026 | NCFA Insight | Risk Compliance And Regtech

Image: Freepik
On Apr 26, 2026, the CBC reported that Premier Wab Kinew announced at a weekend fundraiser that Manitoba plans to restrict youth access to social media and AI chatbots.
At the time of publishing, an official government release, bill or consultation paper wasn't available so treat this as early insight rather than a confirmed regulatory event (just yet). The stronger proof is already visible in global policy patterns, so it's only a matter of time.
Australia’s social media minimum age rules took effect on Dec 10, 2025, and eSafety reported that platforms had removed access to 4.7 million under 16 accounts across Australia by mid December 2025.
In Europe, the European Commission has published minor protection guidelines under the Digital Services Act, and the European Parliament has backed a minimum age of 16 for access to social media, video sharing platforms, and AI companions.
Given the trajectory and potential risks of AI, the debate isn't just about doom scrolling any more. It's fuelling a compliance market for age assurance, safer design, and AI access controls.
Australian government's rules put responsibility on age restricted platforms to take reasonable steps, not on parents to police every account. So age restrictions and assurance are now an infrastructure issue. A checkbox, self declared birth date, or parental reminder won't satisfy regulators when millions of accounts need to be assessed, restricted, or removed.
Children can get pulled into endless feeds, autoplay videos, harmful recommendations, bullying, sexual exploitation, self harm content, eating disorder content, and late night scrolling that cuts into sleep. That's why social media is getting the attention from lawmakers first. The bigger question for fintech and digital identity comes next. Once governments make platforms check age, the same requirement can spread to other digital services used by minors.
The EU hasn't implemented a social media ban on age just yet, but it's building the infrastructure that could support stricter controls. On July 14, 2025, the European Commission released an age verification app prototype under the Digital Services Act. The Commission says the app would let users prove they are over 18 when accessing restricted adult content while keeping control of other personal information, including their exact age and identity.
The Commission’s age verification page says the solution was technically ready for implementation as of Apr 15, 2026. The blueprint also gives platforms a practical build plan. It covers the technical specs, system design, data connections, and open source code needed to support age checks. Age assurance now has to protect children without creating a new privacy problem. Platforms need a trusted age signal. Users should not have to share a full identity file just to prove they meet an age limit.
The clearest policy clue comes from Europe’s treatment of AI companions. On Nov 26, 2025, the European Parliament voted 483 in favour, 92 against, and 86 abstentions on a non legislative report calling for a minimum age of 16 for social media, video sharing platforms, and AI companions, unless parents authorize access for users aged 13 to 16.
The same Parliament release cites research that 97% of young people go online every day, 78% of 13 to 17 year olds check their devices at least hourly, and one in four minors show problematic or dysfunctional smartphone use. It also cites 2025 Eurobarometer impact of digitalisation findings that more than 90% of Europeans see online child protection as urgent, including 93% for social media’s negative impact on mental health, 92% for cyberbullying, and 92% for restricting access to age inappropriate content.
Those numbers explain why AI gets pulled into the same debate. Doom scrolling rules target addictive design and harmful content discovery. AI companion rules target interaction, dependency, personalized responses, manipulation, and adult like conversations with minors. NCFA has already examined youth AI protection risks, including lawsuits involving generative AI and vulnerable users. Regulators are starting to connect age, vulnerability, consent, product design, and AI behaviour into one compliance problem.
The public debate may start with under 16 social media bans. The business reality runs deeper. Governments want digital services to know when a user is a child, adjust the experience, and prove that controls work. Age assurance is becoming part of digital trust infrastructure. AI makes the stakes higher because the product doesn't just offer access to content anymore. It talks back, adapts, remembers, and can build dependence. That's why kid risk now part of the compliance stack. Once age becomes a regulated access condition, the same logic can reach payments, gaming, lending, investing, AI assistants, marketplaces, app stores, and identity wallets.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Apr 27, 2026 | NCFA Fintech Insight | Cybersecurity And AI Risk

On April 21, 2026, Mozilla's Firefox team said early access to Anthropic’s Claude Mythos Preview helped identify 271 vulnerabilities in Firefox 150, after an earlier Anthropic collaboration with Opus 4.6 helped fix 22 security sensitive bugs in Firefox 148. It's a real world test Warning that AI has started to compress months of expert vulnerability research into a much shorter discovery cycle.
The deeper issue for financial services isn’t whether AI can find bugs. Mozilla’s post makes that answer fairly clear. The harder question is whether banks, fintechs, payment providers, cloud vendors, and critical infrastructure operators can test, rank, schedule, and deploy fixes fast enough once the bug volume rises?
Security teams have always fought an unfair game. That is attackers only need one weakness while defenders have to protect the full surface. Mozilla’s Bobby Holley wrote that elite security researchers find bugs that fuzzers miss by reasoning through source code, and that computers “were completely incapable of doing this a few months ago, and now they excel at it.” He also wrote that Mythos Preview was “every bit as capable” as the best security researchers Mozilla has studied.
Limited human cyber security expertise no longer limits discovery in the same way. Once AI can reason through large codebases, the volume of known vulnerabilities rises quickly. Mozilla for example jumped from 22 bugs in Firefox 148 to 271 vulnerabilities in Firefox 150. Detection capacity jumps faster than operational capacity.
For fintechs, that means security teams may see more vendor alerts, more emergency updates, more dependency risk, and more pressure to patch without breaking customer facing systems. More discovery helps defenders, but only when organizations can practically execute on the risk.
The Financial Times reported that companies with Mythos access want stronger joint defense across government and business, especially for hospitals, banks, utilities, and other critical infrastructure. It also reported that Microsoft, Fifth Third’s technology provider, has rolled out almost 150 software updates since Mythos’s release. Patching can affect numerous areas, such as customer access, payments, fraud controls, and vendor dependencies.
Financial infrastructure like core banking systems, payment gateways, and fraud engines operate on tight turnaround schedules and a bad patch or gap can interrupt service, leaving a known weakness open. And the tradeoff becomes harder when AI expands the queue of fixes beyond human capacity.
A 2026 analysis summarized on the Harvard Law School Forum on Corporate Governance found that Russell 3000 companies hit by significant cyber incidents underperformed the broader market by about 5% on average over three years. The study reviewed 176 unique cyber events from 2022 through 2024, and found that finance, banking, and health care accounted for more than half of reported incidents. That means board failures, patch delays, poor vendor oversight can damage shareholder value for years.
The old comfort of quarterly patch cycles won’t hold up well in a world where AI can surface hundreds of issues at once.
Reuters reported on April 21 that unauthorized users accessed Mythos through what Anthropic described as a third party vendor environment. Anthropic said it was investigating the report and had no evidence that the access affected Anthropic systems.
If a tool can find bugs as well as top security experts, then that tool becomes a prime target. Anyone who gets access to it could shortcut months of work and go straight to weak points. That means security is no longer just about protecting your systems. It also includes controlling who can use these AI security tools, how they’re accessed, and what they can see across your vendors and environments.
Warnings from Palo Alto Networks point to where this could go. These tools may allow attackers to link multiple weaknesses together and automate attacks. That’s why the unauthorized access issue matters even without confirmed misuse. The real risk is that the capability itself could leak.
Canadian fintechs don’t run everything themselves. They depend on cloud providers, banks, payment networks, identity services, and other vendors. That means they don’t control when fixes happen, but they still carry the risk if something goes wrong.
That puts pressure on knowing how vendors handle security. Fintech teams need to understand how quickly partners fix serious issues, how they report problems, and whether important updates get priority. Even smaller firms can push for clearer answers before relying on a vendor for critical services.
Regulators should pay attention too. AI can help find problems faster, but only if companies can act on that information in a coordinated way. If not, bigger firms with early access move ahead, while smaller ones fall behind. In Canada, where many fintechs depend on a few key providers, that gap could widen quickly.
Mozilla believes there’s a limit to how many bugs exist, and that defenders may finally be able to find them all. That could happen over time. Right now, though, things will feel messy. More bugs will show up. Fix lists will get longer. Vendors will have to decide what to fix first. Leaders will have to choose between keeping systems running and fixing issues right away. For banks and fintechs, the edge will go to those who can move faster, work closely with partners, and handle frequent updates without disrupting customers, payments, or data.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |