Karsten Wenzlaff, Advisor
August 26th, 2025
AI | Aug 21, 2025
Image: Freepik/Rawpixel.com
On August 20, 2025, Forbes revealed that Elon Musk’s xAI had published hundreds of thousands of Grok chatbot conversations that became searchable on Google without warning. The exposed chats ranged from personal medical questions and passwords to instructions for creating drugs, malware, and even a plan to assassinate Musk himself.
The problem was related to Grok’s “share” button. When users clicked it, the platform generated a unique URL that was publicly crawlable by search engines. There was no disclaimer or safeguard, and ultimately private exchanges and shared personal information would immediately be published and available online. TechCrunch reporting confirmed that thousands of Grok conversations containing sensitive data are indexed on Google.
Among the published material were uploaded spreadsheets, text documents, and conversations disclosing names, personal details, and at least one password. Experts noted that xAI’s approach mirrored and exceeded a failed OpenAI experiment last month in July 2025, when ChatGPT briefly allowed chats to be discoverable before pulling back after user backlash.
Opportunists are already exploiting Grok’s share function to manipulate Google search results, proving that careless design choices can spawn entirely new risks.
The Grok and ChatGPT leaks illustrate the absolute need for privacy by design and transparent governance in AI. For fintech and financial services, the implications are massive given that trust is foundational.
If users believe that their conversations or sensitive data could be exposed online without consent, it will only hinder AI adoption and long term growth. With global media and regulators now scrutinizing the exposure, the lesson is clear: innovation cannot come at the expense of trust.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
AI Ethics | Aug 15, 2025

Image: Freepik AI
A Reuters investigation into Meta’s AI content standards has revealed internal guidelines that allowed the company’s chatbots to have interactions with children, generate racially demeaning content, and produce false medical information if a disclaimer was included.
The 200-plus page policy called, "GenAI: Content Risk Standards", applied to chatbots across Facebook, Instagram, and WhatsApp. Meta confirmed the document was authentic and said some sections have now been removed. Meta described the controversial examples as “erroneous and inconsistent” with its policies, but admitted its enforcement was inconsistent.
Reuters reviewed internal policy materials that included Meta chatbot guideline examples related to children and examples related to race. These outlined scenarios the company considered acceptable and unacceptable under its AI behaviour standards.
The leaked rules have triggered a bipartisan backlash in Washington. As reported by Reuters on the U.S. Senate response, Republican senators Josh Hawley and Marsha Blackburn have called on congress to investigate, linking the AI ethics gap to the Kids Online Safety Act (KOSA). The bill would require platforms to take stronger measures to protect minors. Democratic senators Ron Wyden and Peter Welch also condemned the policies. Wyden argued that Section 230 protections for online platforms should not apply to generative AI chatbots. Welch said the findings show the urgent need for enforceable AI safeguards.
Canada introduced a Voluntary Code of Conduct for generative AI in September 2023 that includes commitments to safety testing, fairness, transparency, human oversight, and privacy protection. These commitments aim to prevent the kind of harm seen in Meta’s internal examples, but the code isn't legally binding, and no AI specific enforcement exists until the proposed Artificial Intelligence and Data Act is passed. So until then, it means that AI guardrails in Canada is largely up to companies to self police and public pressure, unless existing laws such as the Criminal Code or hate speech provisions are triggered.
Unchecked AI rules can allow GenAI outputs that many see as ethically unacceptable. Canadian fintechs, AI developers, and digital platforms should build stronger, enforceable guardrails before regulators step in.
With the U.S. now advancing legislation like KOSA, Canadian companies could soon face a higher ethics bar at home and abroad.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Biometric Guidance | Aug 13, 2025
Image: Freepik/rawpixel.com
On August 11, 2025, the Privacy Commissioner of Canada (OPC) released final guidance on handling biometric information such as facial recognition, fingerprint scanning, and voice identification.
how federal institutions and businesses must handle biometric information such as facial recognition, fingerprint scanning, and voice identification. The new privacy guidance applies to federal institutions and businesses across all sectors and follows more than a year of public consultation that included input from 34 written submissions and 31 stakeholder meetings. The updated guidance is Canada's response to mounting privacy risks thanks to the rapid growth of using biometric technology in authentication, security, and service delivery.
Biometric data is uniquely tied to an individual’s body and remains consistent over time, making it valuable for verification and sensitive for privacy, but it can reveal health indicators, racial and gender characteristics, and other personal details. Unlike passwords, it cannot be replaced if compromised.
The permanent nature and sensitivity of biometric data increases the risk for organizations collecting, storing, and processing without special safeguards. As the OPC guidance states, "Biometric information is sensitive personal information, and in most cases, it should be treated and protected as such."
Philippe Dufresne, Privacy Commissioner stressed:
“Organizations need to approach the use of biometric information in a privacy-protective way, building privacy considerations at the beginning of any new program or initiative.”
The guidance for private sector organizations clarifies when and how biometrics can be collected, used, and disclosed under the Personal Information Protection and Electronic Documents Act (PIPEDA). Businesses must ensure there is a clearly defined and appropriate purpose for any biometric program, supported by a proportionality test to weigh benefits against privacy risks.
They must also obtain meaningful consent from individuals, be transparent about how data will be used, ensure systems are accurate through testing, and apply robust security measures to prevent unauthorized access.
Federal institutions adhere to similar principles under the Privacy Act but face additional obligations. They must identify lawful authority before collecting biometric data and conduct a formal Privacy Impact Assessment to evaluate risks and mitigation strategies.
The federal guidance simplifies the rules for doing impact and risk assessments so they are easier to follow when planning a program. It also asks federal institutions to think carefully about whether biometrics are truly needed, if the benefits outweigh the privacy risks, and whether other options could work before moving ahead.
The final guidance incorporates several adjustments based on stakeholder feedback, including clearer definitions of sensitive information, closer alignment with legal requirements, more detailed technical explanations and best practices, refined consent guidance for private sector use, and expanded discussion of lawful authority for public sector programs.
| Area | Private Sector (PIPEDA) | Federal Institutions (Privacy Act) |
| Legal authority | No specific law needed, but must have a clear, appropriate purpose | Must confirm lawful authority before collecting biometrics |
| Risk assessment | Should assess proportionality and risks, but not formally required | Must complete a formal Privacy Impact Assessment |
| Consent | Must get meaningful, informed consent | Consent may not apply if collection is legally authorized |
| Proportionality | Required to weigh benefits vs privacy risks | Required with added focus on necessity and exploring alternatives |
| Security safeguards | Must apply strong protections to prevent misuse | Same requirement, plus oversight within government frameworks |
For fintechs, payment providers, and digital identity innovators, the guidance sets a higher compliance bar for wherever biometric services may be used, such as customer on-boarding, fraud prevention, and authentication. Companies will need to integrate privacy risk analysis into early product design, justify and write-down decision-making, and ensure biometric tools are tested for accuracy and fairness.
Meeting these requirements will add compliance costs but will be important to maintain consumer trust and avoiding regulatory scrutiny as biometric use expands in financial services.
With it's latest guidance, the Privacy Commissioner is making biometric governance a core compliance area in Canada. For fintechs, this is both a regulatory obligation and a competitive opportunity. Those that build privacy into biometric solutions from the beginning can improve market credibility while remaining compliant.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Banking Policy | Aug 12, 2025

AI generated image of financial exclusion
On August 7, 2025, the White House issued an executive order aimed at ending “politicized or unlawful” debanking. The order directs U.S. regulators to ensure that banks cannot deny service based on political views, religious beliefs, or lawful industry participation, including cryptocurrency. It's the highest profile intervention in U.S. banking in decades and could influence how other jurisdictions handle access to financial services. In Canada, let us not forget the swift debanking of key persons related to the trucker convoy debacle only a few years ago.
Federal banking regulators are to remove “reputational risk” from examination manuals within 180 days. All decisions to deny or close accounts must be based on looking at each customer’s situation on its own, using facts rather than opinions, and assessing real financial and compliance risks instead of relying on broad labels or assumptions.
Regulators must review past cases of account closures or denials within 120 days and take corrective actions, including fines, consent orders, or reinstatement of clients. The Small Business Administration is tasked with urging lenders to reinstate borrowers affected by unlawful debanking. The Office of the Comptroller of the Currency has already updated its materials to comply.
Supporters of the order point to documented cases where lawful businesses, advocacy groups, or individuals lost access to banking without clear justification. Critics argue banks must retain the ability to consider reputational factors when managing compliance obligations under anti-money laundering and counter-terrorist financing laws. A Financial Times analysis notes that crypto companies have been prominent among those alleging discrimination, alongside political organizations and religious nonprofits.
While Canada has not adopted similar measures (yet), there are high profile cases revealing parallels, such as in 2022 when former-PM Trudeau invoked the Emergencies Act to freeze more than 76 bank accounts worth $3.2 million CAD tied to the Freedom Convoy. The Federal Court later ruled this unconstitutional, and the decision is under appeal.
In another reported case, a trucker convoy lawyer said that her Royal Bank of Canada account was closed after small cryptocurrency transactions. Crypto business operators have also described difficulty maintaining accounts, though no comprehensive national data exists.
Canadian banks operate under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and oversight from the Office of the Superintendent of Financial Institutions. Reputational risk is explicitly considered in supervisory frameworks. Consumers are entitled to open personal bank accounts unless specific conditions apply, and must be given written reasons for refusal under the Access to Basic Banking Services Regulations. Complaints can be escalated to the Financial Consumer Agency of Canada or the Ombudsman for Banking Services and Investments, but there is no mandated systemic review or reinstatement process.
| Feature | United States (Post-EO) | Canada |
| Stance on Debanking | Prohibits ideological or industry-based debanking | No federal rule prohibiting ideological or lawful industry debanking |
| “Reputational Risk” | Removed from regulatory supervision criteria | Integral to OSFI guidance and AML compliance |
| Remediation Process | Regulator-led review, possible fines, reinstatement | Individual complaints through FCAC or Ombuds |
| Transparency | Mandated objective, individualized reasoning for account decisions | Written refusal required, but criteria remain broad |
The U.S. executive order aims to reduce bias in access to financial services which should not be denied based on lawful activity or beliefs. For fintech and crypto entrepreneurs, the change should make banking access more predictable and less influenced by subjective judgments. While Canada’s regulatory approach emphasizes prudence and reputational safeguards, it may need to review these protections that remain at the expense of inclusion and competitiveness.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |