Karsten Wenzlaff, Advisor
August 26th, 2025
May 8, 2026 | NCFA Insight | Regulation And Policy, Cybersecurity And Fraud, Artificial Intelligence And Data

On May 7, 2026, Apple and Meta warned that Canada’s Bill C-22 could weaken encryption, pushing a long running lawful access debate back into the spotlight. The bill reaches far beyond Silicon Valley politics. It touches the same infrastructure that supports digital banking, fintech apps, cloud platforms, AI systems, wallets, fraud detection, secure communications, and identity verification.
What started as a policing and national security issue increasingly looks like a broader fight over cybersecurity, digital trust, and how governments regulate access to modern technology systems.
Bill C-22 creates a lawful access framework for electronic service providers operating in Canada.
Part 1 updates investigative powers related to subscriber information and transmission data.
Part 2 creates the Supporting Authorized Access to Information Act, which would require certain providers to maintain operational and technical capabilities that allow them to comply with lawful access requests under existing Criminal Code or CSIS Act authorities.
The scope is broad. The bill applies to electronic service providers involved in creating, storing, processing, transmitting, receiving, or making information available electronically. That definition reaches beyond telecom networks and traditional internet providers. Depending on regulations and ministerial orders, the framework could affect cloud providers, messaging platforms, device ecosystems, AI infrastructure, payment systems, digital identity platforms, and fintech companies handling sensitive customer information.
The government argues that Canada’s investigative framework no longer matches modern communications technology. Public Safety Canada says current lawful access rules still reflect a 1995 voice telephony environment, even though investigations now involve encrypted messaging systems, cloud services, internet platforms, and cross border digital infrastructure.
The FBI, RCMP, and other law enforcement agencies have long referred to encrypted communications and inaccessible digital evidence as the “going dark” problem.
Investigators increasingly struggle to access information tied to organized crime, online fraud, ransomware, terrorism, child exploitation, and financial crime because modern services collect less accessible data or use strong encryption that even the provider cannot access directly.
The Canadian Association of Chiefs of Police publicly supported the legislation and argued that police need updated tools to investigate serious crimes in digital environments. Justice Canada also says the bill would allow judges to authorize requests for subscriber information or transmission data from foreign telecommunications or social media providers where there are reasonable grounds to suspect an offence and the information would help the investigation.
The fraud backdrop strengthens the government’s case politically. Competition Bureau Canada reported CAFC data showing Canadians lost more than $704 million to fraud in 2025, while only 5% to 10% of fraud gets reported. Reported losses since 2022 have surpassed $2.4 billion.
Critics argue the proposed solution risks weakening the same security architecture modern digital systems depend on. Reuters reported that Apple warned the bill could allow Canada to “force companies to break encryption by inserting backdoors.”
Meta argued the legislation could force providers to weaken encryption protections or undermine zero knowledge systems designed so providers themselves cannot access customer data.
Public Safety Canada disputes that interpretation. Government officials say the legislation would not require providers to create a “systemic vulnerability” in encryption systems, which is now at the center of the debate.
The problem is technical as much as legal. Security engineers often argue that once a system preserves exceptional access for any party, it creates a potential weak point that can eventually attract criminals and and insider abuse.
For fintechs and financial institutions, it's the same strong encryption that protects account credentials, wallet keys, transaction approvals, secure communications, and increasingly AI workflows that may soon handle sensitive financial tasks autonomously.
The UK offers an important lesson for Canada. Earlier this year, Apple removed Advanced Data Protection for new UK users after government pressure around encrypted cloud access. Apple later stated that UK users would no longer have access to the feature and said, “we have never built a backdoor or master key.”
The UK outcome shows how a lawful access demand can expand into a wider cybersecurity and trade problem. Instead of settling the issue, Apple’s feature rollback intensified scrutiny from privacy advocates, security experts, and U.S. officials concerned about government access to encrypted cloud data.
Canada could face the same kind of fallout if Bill C-22 leaves companies unclear about what they may be forced to build, disclose, weaken, or keep secret under future access orders.
Timing isn't great. Canada is already dealing with pressure around digital sovereignty, platform regulation, AI governance, and trade relations with the United States.
In June 2025, Canada rescinded its Digital Services Tax to restart trade negotiations with the U.S. The CUSMA review is an active pressure point for companies operating across borders through cloud infrastructure, data systems, and digital financial services.
Europe is moving differently. The European Commission imposed the first Digital Markets Act penalties in April 2025, including €500 million against Apple and €200 million against Meta. Meanwhile, the Trump administration has taken a more defensive posture toward American technology firms facing foreign digital regulation, including ordering U.S. diplomats to push back against foreign data sovereignty rules.
That leaves Canada to balance a convergence of pressure around public safety expectations, cybersecurity concerns, platform dependence, trade risk, and digital sovereignty ambitions.
Large platforms will likely absorb the first round of scrutiny. The second order effects may matter more for fintech operators and infrastructure providers.
Fintechs, digital identity companies, crypto wallet providers, cloud based banking platforms, AI finance systems, payment processors, fraud vendors, and regulated financial institutions could all face pressure around compliance architecture, data retention, encryption design, and cross jurisdiction operational requirements.
The cost may not appear immediately through direct enforcement. It may emerge through audits, vendor obligations, insurance requirements, infrastructure redesign, compliance overhead, or changes to how secure systems get built and marketed in Canada.
Encryption is key to financial infrastructure. Customer trust, cybersecurity resilience, fraud prevention, and digital competitiveness now all depend heavily on whether secure systems remain genuinely secure.
Does Canada need to choose between ineffective investigations and weakened encryption for everyone?
A better version of the bill would be more precise. It should clearly say which companies can receive access orders, protect end to end encryption and zero knowledge systems, require independent technical review before any order is approved, and give companies a real way to challenge orders that put security at risk.
The core dispute is not whether courts can authorize lawful investigations. It is whether governments should be able to force companies to preserve technical access inside systems designed specifically to remove that access. That is the fight at the centre of the global encryption debate.
Encryption is foundational infrastructure for finance, AI, communications, identity, and cloud systems. Canada’s challenge is no longer simply how to access digital evidence. It's how to modernize investigations without creating weaker systems that undermine cybersecurity, trust, and long term digital competitiveness.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
May 6, 2026 | NCFA Feature | Artificial Intelligence And Data

On May 5, 2026, Anthropic introduced finance agent templates for work that financial teams already manage every day. The list covers five agent templates and five workflow control templates all ready to go. This isn't just another AI product update and points to import changes to how financial services will operate in the near future. It also confirms that AI once again is leaving the loose prompt box and entering into controlled workflow systems.
These systems keep work inside permissioned data rules, use approved tools, review evidence, and provide risk teams a record that they can inspect and follow-up on. Regulated financial fintechs and financial institutions need these controlled AI agents inside defined workflows along with human review before output reaches a client file, compliance record, valuation, trade document, or board package.
The first wave of generative AI in finance looked like a personal productivity tool. Staff used chat assistants to summarize documents, draft emails, explain code, build first cut memos, and prepare research notes. That helped save some workers a lot of time, but it kept AI at the edge of the operating model. Now there's a return on intelligence in finance applications.
Anthropic’s new finance agents look capable of handling work on a more serious level. Each template combines task instructions, governed data connectors, and subagents for specific jobs such as peer company review, checking valuation methods, or reviewing source material. Teams can also adapt the agents to their own modelling conventions, risk policies, approval flows, and data access rules.
A governed agent can follow a checklist, call a tool, update a model, prepare a file, and hand the work to a reviewer. It can also create a record inside Claude Console. An audit section that doesn't auto correct the output by itself but makes the work easier to inspect. Model access is becoming common. Controlled execution is harder to obtain.
For operators, the useful question is where can an agent reduce manual drag without taking final judgment away from people. The measurable benefit should come from workflow metrics, not AI hype. Anthropic’s primary source gives one hard implementation claim. Teams can put Claude on finance work in days rather than months.
1. Pitch Builder A human banker builds a pitchbook by gathering company data, picking peers, checking comparables, drafting a story, and turning numbers into slides. An agent can run that process as a controlled sequence. It can pull approved data, prepare peer company comparisons, draft pages, and carry figures into a deck. The banker still decides which story is credible. The agent cuts the assembly work and leaves a clearer trail of sources and assumptions.
2. Meeting Preparer A human relationship manager often prepares by searching email, notes, filings, news, and prior client material. That process depends on memory and time. An agent can assemble a brief from connected sources, organize recent events, flag open issues, and keep the context ready for the meeting. The constraint is conduct risk. Firms need approved sources, stale data warnings, and a clear line between internal preparation and client ready advice.
3. Earnings Reviewer A human analyst reads filings, transcripts, guidance changes, and prior models to find what changed. An agent can do the first pass faster. It can compare current results with previous periods, update a draft model, flag changed language, and highlight items tied to an investment thesis. The analyst still decides what's important.
4. Model Builder A human analyst builds and updates models by entering figures, linking sheets, checking formulas, and adjusting assumptions. An agent can pull data from filings and feeds, create a first draft model, update assumptions, and help test formula consistency. That can save time, but it also raises the control bar. Firms need version control, formula review, source tagging, and named ownership before model output supports pricing, credit, valuation, or investment decisions.
5. Market Researcher A human researcher scans news, filings, broker research, sector reports, and internal notes to decide which facts matter. An agent can monitor connected sources, group findings by issuer or sector, and surface items for credit, risk, or investment review. The value is less search time and a better first cut of the evidence people need to judge.
6. Valuation Reviewer A human reviewer checks valuation work by testing inputs, peers, methods, policy thresholds, and judgment calls. An agent can run a structured first pass against approved comparisons, methodology rules, and company standards. It can flag gaps or inconsistencies before a reviewer signs off. That helps private markets, credit teams, fund administrators, and auditors, but the firm still has to control the inputs. In valuation, speed without discipline can multiply risk.
7. General Ledger Reconciler A human finance team reconciles accounts by matching records, finding breaks, explaining differences, and routing exceptions. An agent can compare account records, identify mismatches, prepare exception notes, and support net asset value calculations against books of record. The practical gain is cleaner exception handling. Reviewers still need the break list, explanations, approvals, and audit trail.
8. Month End Closer A human close team runs checklists, prepares entries, confirms balances, and packages reports under deadline pressure. An agent can run the checklist, prepare draft journal entries, assemble support, and produce close reports for review. That helps speed and consistency. Finance leaders still need approval evidence, segregation of duties, and a clean record of changes before final sign off.
9. Statement Auditor A human reviewer checks financial statements for consistency, completeness, formula issues, disclosure gaps, and unexplained changes. An agent can run those checks across statements and supporting files, then package exceptions before external review. The value is earlier detection and better reports. Audit judgment stays with people.
10. KYC Screener A human compliance analyst gathers documents, checks entity details, reviews risk flags, and escalates unclear cases. An agent can assemble entity files, compare source documents, identify missing information, and prepare escalation packages for compliance review. The strategic value is a cleaner file, fewer manual searches, better evidence capture, and faster escalation when risk is unclear.
On Apr 30, 2026, APRA called for a step change in AI risk management and governance across banks, insurers, and superannuation trustees. APRA warned that AI use is growing faster than governance, risk management, assurance, and operational resilience practices.
It also raised concerns about concentration risk, weak contingency planning, fragmented assurance, and reduced transparency when AI features come embedded within larger software platforms.
The FCA is testing similar issues in live environments. On Apr 21, 2026, the FCA named firms in its second AI Live Testing cohort, with use cases that include agentic payments, anti money laundering detection, credit score insights, KYC, and investment support. Testing runs through the end of 2026, with an evaluation report expected in Q1 2027.
Buyers won't only ask if the tool works. They'll ask what evidence proves it works, where humans review it, how errors surface, how permissions operate, and how the firm can stop the workflow when risk changes.
Financial institutions should treat finance agents as workflow infrastructure:
For banks, controlled scale should start where process discipline already exists. Good candidates include KYC reviews, credit memo preparation, internal research, model checking, finance close support, and audit readiness. These workflows already have owners, policies, and reviewer structures. That makes them better candidates than open ended client advice or autonomous transaction decisions.
For wealth firms, the strongest use cases sit in client preparation, research support, portfolio review notes, and compliance ready documentation. The danger is blurred accountability. A meeting brief can become advice in practice if staff reuse it without review. Wealth firms need templates, source labels, approval gates, and retention rules that fit suitability, disclosure, and conduct obligations.
For capital markets platforms and private market operators, agents can improve diligence speed. They can search data rooms, compare issuer materials, prepare investor questions, review disclosure consistency, and draft internal summaries. The platform must show where each fact came from and keep investment judgment with people.
For regtech vendors, the opening is clear. Build around review evidence, role based permissions, source traceability, escalation records, model monitoring, and shutoff controls. Don’t sell a generic AI layer. Sell the control fabric that lets financial firms use agents without losing accountability.
For investors, the better diligence question is where AI enters the workflow, what data it can touch, who reviews its output, and what record proves the process worked. AI adoption without operational evidence isn't a moat. It's a future remediation cost.
Small and mid sized financial institutions face a practical capacity gap. Many do not have deep AI engineering, data governance, risk, and integration teams. Anthropic’s May 4 announcement of a new enterprise AI services company with Blackstone, Hellman & Friedman, and Goldman Sachs speaks to that constraint. Anthropic said companies from community banks to mid sized manufacturers and regional health systems can benefit from AI, but lack the in house resources to build and run frontier deployments.
AI agents in finance don't need more use cases. Startups shouldn't copy bank scale infrastructure too early, and banks shouldn't treat agentic AI like another desktop tool. The right balance is to start with narrow workflows, measure the time saved, add controls as risk rises, and stop before governance costs outrun the value.
But once an agent touches regulated records, client decisions, and audit files, cheap experimentation ends. The real cost isn't only the model. It's all the other infrastructure from data access, permissions, monitoring, review gates, and vendor oversight that make work usable in finance.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |