Karsten Wenzlaff, Advisor
August 26th, 2025
```html
August 18, 2026 | NCFA Insight | Artificial Intelligence And Data, Payments Infrastructure And Money Movement, Digital Assets

On August 18, 2026, Amazon Web Services made AgentCore Payments generally available, taking the capability from its May preview into production. AI agents can now encounter paid APIs, services accessed through Model Context Protocol (MCP), or other digital resources during a workflow and initiate payment through infrastructure that connects spending controls with external wallets.
AWS can enforce how much an agent is allowed to spend and for how long, manage access to wallet providers and coordinate the payment from inside the same infrastructure used to run the agent. Coinbase or Stripe's Privy provides the wallet, while external providers and blockchain networks handle signing, verification and settlement.
AWS isn't taking custody of customer money. It is taking a position earlier in the transaction, where software determines whether it has permission to buy something and which payment connection to use. That puts payment authority closer to the AI execution layer.
AgentCore Payments already supported Coinbase and Privy wallets, spending controls and x402 payments during preview. General availability adds the Machine Payments Protocol (MPP), easier Coinbase wallet setup, improved discovery of paid x402 services and an x402 pricing option called upto.
The upto model is designed for services whose final cost isn't known before use. An agent can approve a maximum amount, while the provider charges for what was actually consumed. AWS points to model inference, compute and other usage-based APIs where a flat price per request may not reflect the real cost.
That fits how autonomous software may buy digital services. Instead of establishing a subscription with every provider in advance, an agent can encounter a paid resource during a task, check whether the price fits its delegated budget, pay for it and continue.
MPP adds another payment protocol. Developed by Stripe and Tempo, it lets software exchange payment requirements during an online transaction and can support different payment models, including microtransactions and recurring payments.
x402 takes a somewhat different approach. It lets an online service respond to an agent's request by saying payment is required before the resource is released. The agent can then authorize the payment through its connected wallet and retry the request.
Stripe says MPP can support stablecoins as well as conventional payment methods, but AgentCore Payments currently documents an embedded crypto wallet as its supported payment instrument.
The architecture adds useful boundaries around the word autonomous. A user or business first provides the wallet and grants authority. AWS then applies rules around how the agent can use that authority during a payment session. NCFA's Financial Innovation Map tracks this convergence of AI agents, financial permissions and programmable infrastructure.
Those controls can include an expiry and a maximum amount the agent is permitted to spend. Before a transaction proceeds, AgentCore checks whether the request fits within that budget. A payment that exceeds the limit is rejected at the infrastructure level rather than left to the agent's judgement.
AWS also keeps the wallet-provider credentials away from the agent itself. Coinbase or Privy provides the wallet infrastructure, while AWS uses controlled access to request operations such as signing a transaction.
The result is delegated spending rather than independent control of money. The person or business sets the authority, AWS enforces part of the operating boundary and the connected wallet provider controls the financial instrument.
AWS also records payment activity through its monitoring tools, giving developers logs and transaction information they can use to review what agents attempted and what payments succeeded. That adds an audit layer around activity that would otherwise be difficult to supervise once agents begin buying resources during longer workflows.
This is where AWS gains a potentially valuable position. It doesn't need to become a bank or payment processor to influence whether an agent-side transaction can proceed.
Coinbase is one supported provider, not an exclusive requirement. Its developer infrastructure provides embedded wallets and supports x402 payments, while Coinbase's Bazaar service helps agents discover online services that accept the protocol.
Coinbase documents payments in the USDC stablecoin on Base and Solana for its AgentCore implementation. That makes digital assets a substantive part of the current product architecture rather than a side effect of Coinbase's involvement. It also connects directly to NCFA's Programmable Stablecoin Payments opportunity brief, which examines programmable money movement and payment infrastructure.
Privy provides another embedded-wallet option. The company is now part of Stripe, but its role in AgentCore is still wallet infrastructure rather than ordinary card processing through Stripe's full payments stack.
AgentCore Payments doesn't require every payment protocol to use cryptocurrency, and MPP itself can support other payment methods. But AWS's currently documented AgentCore payment instrument is still a crypto wallet.
Payment companies therefore remain important underneath the agent platform. They provide the wallet, credentials and financial infrastructure needed to execute transactions, while AWS controls more of the environment where an agent decides when to call them.
This isn't the only infrastructure model emerging. Circle's USDC infrastructure for AI agents combines policy-controlled wallets, service discovery and programmable payments under predefined guardrails.
Travala provides a useful production example because its implementation shows where the customer's authority remains. Its current Travel MCP lets an AI agent search and book hotels, with payment settled in the USDC stablecoin on Base from a Coinbase wallet connected through AgentCore.
The customer still has to authorize the spending relationship. Travala says the permission is revocable and time-limited, the company never receives the private key and the customer must explicitly confirm the hotel purchase before payment is made.
Once that permission is in place, the agent can complete the payment within the delegated limits and continue the booking workflow. That is more precise than saying an AI agent independently controls money.
AWS also names Anchor Browser, SpreadX's Incarna, Elsa AI and Heurist AI among customers or integrations using AgentCore Payments. AWS does not provide transaction volumes for those implementations, so there isn't yet enough evidence to describe agent-led payments as broadly adopted at scale.
The Travala example is still important. It shows a live consumer transaction where conversational software can search, obtain approval and complete payment without sending the customer into a separate checkout flow.
Traditional electronic payments divide responsibility among merchants, gateways, processors, acquirers, networks, issuers and customer interfaces. Agent commerce adds another decision point before many of those functions because software has to decide whether a paid service is useful, whether the price is acceptable and whether the purchase falls within the user's authority.
AWS now controls part of that decision environment. It doesn't set the merchant's price, supply the customer's money or settle the transaction. It can, however, determine whether the agent's payment request fits its permitted spending session and coordinate access to the wallet needed to proceed.
That creates a new distribution question for payment companies. A wallet provider may still own the financial relationship underneath the transaction, while the cloud or AI platform controls the environment where an agent discovers a service and decides which payment connection to use.
AgentCore Payments still has important limits. AWS isn't providing general merchant acquiring, and its documentation doesn't establish native chargebacks, universal merchant controls or a standalone fraud-screening service inside AgentCore Payments. Those functions may remain with the merchant, application, wallet provider or other payment infrastructure.
Control of the agent execution environment can still become valuable payment real estate even when the platform never holds the money. If agents increasingly choose services and initiate purchases on behalf of users, the infrastructure governing those decisions becomes another point where payment providers compete for access.
AgentCore Payments is currently available in 12 AWS regions across the United States, Europe, Singapore and Australia. AWS does not currently offer the capability from its Canadian region, even though several other AgentCore services are available there.
That creates a practical constraint for Canadian developers that want to keep this part of the stack in an AWS Canadian region. They can deploy AgentCore Payments elsewhere, but there is no Canadian region for the capability today.
The longer-term issue for Canadian fintechs and financial institutions is less about one AWS region and more about where financial authority is being placed. Agent payments combine AI governance, delegated spending, wallets and payment infrastructure inside one operating workflow.
Firms will need to decide which controls remain inside their own applications and which can be delegated to cloud, wallet and protocol providers. That becomes more important as agents gain permission to buy services during a task rather than simply recommend what a person should buy.
If AI and cloud platforms control the environment where agents receive spending authority and decide whether a transaction can proceed, while payment companies provide wallets and settlement underneath them, which layer will ultimately control distribution in agent-led commerce?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
```
Aug 17, 2026

A mid-size alternative lender in Vilnius pulls company registry filings, marketplace pricing and sanctions lists into its underwriting model every night. None of it is illegal to read. Most of it becomes a liability the moment it is copied, stored and combined with something else. That gap between "publicly visible" and "lawfully processed" is where fintech compliance teams keep losing arguments with their own data science departments.
Public web data – company filings, marketplace listings, court dockets, sanctions databases, social media bios – has become a standard input for credit scoring, fraud detection, KYB and competitive pricing in financial services. In Meta Platforms v. Bright Data, a federal district court held that Bright Data had not breached Meta's terms of service by collecting data from logged-out pages, which was the specific conduct at issue. The ruling turned on Bright Data's particular conduct and its contractual relationship with Meta rather than establishing a general rule for scraping public websites. For a regulated entity, that distinction is not academic. A bank's third-party risk team, an EU DORA auditor or a state attorney general does not care whether the data was "technically public" if the collection method itself created exposure.
hiQ Labs v. LinkedIn is still the reference case for US practitioners, and it is more nuanced than the headlines from 2019 suggest. The Ninth Circuit held twice, first in 2019 and again on remand in 2022, that scraping data from pages open to any visitor does not amount to accessing a computer "without authorization" under the Computer Fraud and Abuse Act. That took the CFAA off the table as a criminal exposure for reading public pages. It did not end the case. hiQ and LinkedIn settled the remaining contract claims in 2022, and hiQ agreed to destroy the data it had already collected and pay damages, because its scraping still violated LinkedIn's user agreement. The lesson for a fintech legal team is specific: CFAA risk and contract risk are two separate questions, and winning on one does not close the other.
On the EU side, the CFAA question barely matters, because GDPR does not distinguish between public and private personal data. Article 4 defines personal data by whether it relates to an identifiable natural person, not by where it was found. A LinkedIn bio, a court filing with a defendant's name, or a marketplace seller profile with a real name attached all fall inside GDPR's scope the moment they are collected, and Article 6 still requires a lawful basis – legitimate interest is workable for adverse-media or fraud screening, but it requires a documented balancing test, not just a note in a Confluence page.
Four use cases account for most of the public-data traffic coming out of fintech data engineering teams. Alternative underwriting pulls e-commerce store metrics, invoice marketplaces and gig-platform ratings to score borrowers who lack conventional credit files – Kabbage and, later, Amex built entire product lines on this. AML and sanctions screening cross-references OFAC, EU and UN lists against onboarding data, refreshed daily because list updates are unscheduled. Competitive pricing intelligence in embedded finance and BNPL tracks merchant-facing rates across marketplaces to benchmark interchange and fee structures. Fraud and adverse-media screening checks court records, press mentions and social profiles as a secondary signal alongside device fingerprinting.
Not all four carry the same regulatory weight. The table below is the one compliance teams actually need before greenlighting a collection project, not a generic "data source" taxonomy.
| Data source | Typical fintech use | Regulatory sensitivity | Main legal basis to check |
| Company registries (Companies House, EDGAR, EU BRIS) | KYB, beneficial ownership checks | Low to medium | Public register rules and applicable data protection law; filings may contain personal data of directors, officers, beneficial owners and other natural persons |
| Sanctions and PEP lists (OFAC, EU, UN) | AML/KYC screening | Low | Government-published, but update frequency and source authenticity matter |
| E-commerce and marketplace pricing | Competitive intelligence, embedded-finance pricing models | Low to medium | Terms of service and contract law; CFAA exposure may be lower for pages accessible without login (per hiQ v. LinkedIn) |
| Public social media profiles | Alternative credit signals, fraud indicators | Medium to high | GDPR/CCPA personal-data rules apply even if the profile is public |
| Court records and litigation databases | Adverse media, fraud investigation | High | Jurisdiction-specific rules on re-use of judicial data (varies widely, e.g. France's Article 33) |
The engineering choices matter as much as the legal analysis, because a regulator or a bank's third-party risk assessor will ask for logs, not intentions. A defensible pipeline has five properties, and they map to concrete infrastructure decisions rather than policy statements.

Figure 1
Figure 1. Each control maps to an artifact a third-party risk assessor can actually inspect. The first four are described below; request logging is the fifth, and the one the practical takeaway returns to.
Reading a site's robots.txt crawl-delay directive and setting concurrency accordingly is a five-minute engineering task that changes the legal character of the whole program. A crawler hitting a company registry at 200 requests per second looks like a denial-of-service test to the target's security team, regardless of what the data is used for afterward. Most production fintech scrapers we've reviewed cap at 1 request per 2-4 seconds per domain, which keeps CPU load on the target negligible and avoids the WAF triggers that generate abuse complaints in the first place.
This is the point where proxy infrastructure choice stops being a procurement decision and starts being a compliance decision. Rotating through residential or datacenter IPs to maintain a stable success rate against rate limits is standard engineering practice. Rotating IPs specifically to re-access a source after being blocked for a terms-of-service violation is the fact pattern that turned hiQ's win on CFAA into a loss on contract claims. The distinction sounds semantic until an opposing counsel reconstructs your request logs during discovery.
Filtering personal identifiers (names, emails, phone numbers, biometric-adjacent fields) before the data lands in a warehouse is materially cheaper than filtering it after ten analysts have already queried the raw table. A regex-and-NER pass at the collection layer, logged with a timestamp and a rule version, is the artifact a DPO can actually show an auditor.
GDPR's storage limitation principle (Article 5(1)(e)) and most US state privacy laws expect a defined retention period. "We keep everything indefinitely for model retraining" is the single most common finding in the DPIAs we've read for alt-data underwriting programs, and it is usually fixable with a 90-180 day rolling window plus a documented exception process for flagged accounts.
Proxy and scraping infrastructure choice affects three things a compliance file will ask about: whether the vendor itself runs KYC on IP sourcing, whether the billing model matches your actual usage pattern (per-IP monthly vs. per-GB bandwidth), and whether the vendor's own terms indicate the network is ethically sourced rather than built from compromised devices.
| Provider | Billing model | Entry price | Where it fits a fintech workload |
| Proxys.io | Per dedicated IP / month | From $1.40/mo (individual IPv4), $0.13/mo (IPv6) | Steady, low-volume monitoring jobs (registry checks, sanctions list refresh) where a fixed, auditable IP per data feed is easier to log than rotating bandwidth pools |
| Decodo (formerly Smartproxy) | Per GB, tiered | $2.00-$3.75/GB depending on volume | Mid-volume scraping across many source domains where bandwidth, not IP count, is the cost driver |
| Oxylabs | Per GB, sales-assisted | Roughly $8/GB at entry tier, KYC required before provisioning | Enterprises that want a vendor-side KYC record as part of their own third-party risk file |
| Bright Data | Per GB (PAYG or committed) | $8.40/GB PAYG residential, down to ~$3/GB committed; datacenter from ~$0.90/GB | Large, multi-region collection programs where volume discounts offset the higher entry rate |
The billing model split matters more than the headline price. A sanctions-list refresh job that hits the same twelve government sources every night at a predictable, low volume is a poor fit for per-GB bandwidth pricing – you're paying for a metric (data transferred) that has almost nothing to do with your actual constraint, which is IP reputation and consistency of access over time. Vendors like Proxys.io bill per dedicated IP per month, which lines up better with that access pattern and makes cost forecasting for a fixed set of monitored sources straightforward. A marketplace-pricing crawl that touches thousands of product pages across dozens of domains is the opposite case: bandwidth is the real cost driver, and a per-GB model from Decodo, Oxylabs or Bright Data scales more predictably with that workload. Enterprises already running Oxylabs' or Bright Data's own KYC process may lean on that as one input to their own vendor risk assessment, though it doesn't substitute for one.

Figure 2
Figure 2. The two variables that move cost are how many domains a run touches and how much data it moves, not the headline price per unit. Per-IP and per-GB rates are quoted in different units and cannot be compared directly.
None of these vendors, including the ones with published ethics or KYC pages, remove the fintech's own obligation to define a lawful basis, log what was collected, and honor retention limits. The proxy layer solves an availability and reliability problem – consistent access to public pages without disproportionate load on the source – not a data protection problem.
Three signals usually mean a proxy or scraping setup needs to change, independent of price. First, a rising block rate on sources with unchanged rate limits – that's an IP-reputation problem the vendor's pool has accumulated, not something a compliance policy fixes. Second, the compliance team asking for source-level access logs the engineering stack can't currently produce – that's a signal the collection layer needs structured logging before it needs a new vendor. Third, a shift in workload shape, for example moving from a handful of steady, low-volume registry checks to broad multi-domain marketplace crawling, which usually means the per-IP pricing that worked for the first case stops making sense for the second.
A fintech data program built on public web sources holds up under regulatory review when three things are documented before the first request is ever sent: the lawful basis for each data category (not a blanket justification), the technical controls that keep collection proportionate to the source (rate limits, minimization, retention), and a request log detailed enough to reconstruct what was collected and why if a regulator or a counterparty's third-party risk team asks. The infrastructure vendor is a smaller decision than most procurement processes treat it as – it changes reliability and cost, not the underlying legal analysis.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
August 14, 2026 | NCFA Companies On The Move | Artificial Intelligence And Data, Risk Compliance And Regtech, Banking And Credit

Fisent Technologies is a Toronto enterprise AI company founded in 2021 by Adrian Murray. Its BizAI platform reads and interprets unstructured content such as applications, claims, statements, contracts and correspondence, then turns the results into data and actions that existing business workflows can use.
The company now has enough operating evidence to look beyond the technology itself. Fisent says BizAI has more than 20 enterprise use cases in production, with customers across banking, lending, wealth management, insurance and other industries. Public examples include Aruba Bank through Orco Group, AEGIS London, CMG Financial and Westinghouse.
On August 11, Fisent closed a US$4.3 million venture round led by FINTOP, bringing disclosed funding to US$6.3 million. The financing arrives after Fisent reported 206% revenue growth in 2025, 173% net revenue retention and a third consecutive year without customer churn. Those percentages are company-reported, and Fisent does not disclose the revenue amount or total customer count.
Banks, insurers and other large companies still receive important information in documents, emails, forms, scans and files that don't arrive in one clean structure. Employees have to read the content, decide what it means, enter the relevant information and route the work. Fisent is selling automation into that gap.
In 2024, Orco Group used BizAI at Aruba Bank to process documents following its acquisition of CIBC FirstCaribbean operations. The company case study reports a 90% decrease in errors, more than 70% faster processing and capacity for as many as 10,000 unstructured documents a day. Those are customer case-study results, not audited benchmarks.
In mortgage lending, CMG Financial selected BizAI for underwriting and processing workflows. AEGIS London has deployed it for insurance endorsement processing. Outside financial services, Pega independently featured Westinghouse and Fisent at PegaWorld 2026, describing a live workflow that combines Fisent's AI with Pega automation to improve parts fulfillment and route exceptions to people.
Those examples give Fisent something many enterprise AI companies still lack, which is proof that customers are putting the software into operating workflows. That is especially useful in regulated finance, where AI adoption depends on controls, data quality and third party oversight as much as model capability.
Adrian Murray, Founder and CEO, Fisent:
“Enterprises are moving beyond AI experimentation and choosing the capabilities they can trust to operate at scale.”
BizAI can classify content, split complex files, extract information, verify it against defined criteria, analyze context and standardize tables. Fisent lets customers choose different models and hosting options, then uses its GenAI Efficacy Framework to compare model configurations on measures such as accuracy, speed, consistency and cost.
That model flexibility is important when a bank or insurer doesn't want one provider deciding where its data is processed or which model supports every use case. Fisent says its default architecture retains no customer content and does not use customer data to train models. The company completed a SOC 2 Type II examination in 2025 and says its controls were expanded during that year's review.
BizAI Studio launched in May 2026, giving business and automation teams a visual environment to design, test, deploy and maintain workflows with review gates, versioning and traceability. That changes where Fisent competes. A customer can build directly with a model provider, use AI functions inside a large workflow platform, buy a document-processing product or use Fisent as the content intelligence layer between models and existing systems. Fisent has to keep earning that position as larger platforms add their own AI capabilities.
Pega is particularly important because it is both an investor and a workflow partner. That relationship gives Fisent a route into enterprise processes already running on Pega, while also making the surrounding platform ecosystem part of its distribution strategy. Governed financial AI increasingly depends on exactly these workflow controls: permissions, evidence, review, escalation and records of what the system did.
Pricing isn't public. Fisent reports strong growth in licensing revenue and enterprise expansion, but contract size, recurring revenue mix and implementation economics remain private.
Fisent's bottleneck is changing. It already has product and deployment evidence. The next job is selling and implementing it repeatedly across more large enterprises.
The US$4.3 million round is Fisent's first priced venture financing and follows US$2 million of earlier disclosed investment from investors including Pega, Cloudberry Pioneer Investments and Sand Dollar Capital. Pega participated again in the FINTOP round, and FINTOP Partner John Philpott is joining Fisent's board.
FINTOP says its strategic investor network includes about 100 banks with US$1.3 trillion in combined assets, along with other financial services companies. That network doesn't automatically give Fisent 100 prospects, pilots or customers. It does put an investor with deep financial institution relationships beside a company trying to sell regulated enterprise AI.
Fisent says the new capital will expand sales, customer enablement, deployment engineering and product development while widening distribution through workflow and technology partners. Those uses fit the current stage. Enterprise AI can fail commercially even when the model works if implementation takes too much specialist effort or every customer becomes a custom project.
Fisent reports impressive growth in 2025 with 206% total revenue growth, 365% licensing revenue growth and 173% net revenue retention. It says customers now run more than three BizAI implementations on average, 90% added at least one production use case during 2025 and none has churned in three years.
Those numbers reflect expansion inside existing accounts. They don't tell us how large Fisent is in absolute terms. Revenue, profitability, valuation, contract values and total customer count are not public. Its first Fortune 50 customer in 2026 is also a company-reported milestone and the customer has not been named.
The evidence puts Fisent beyond initial validation without placing it in the same scale category as established enterprise platforms. Its current position is best described as Accelerate / Commercialize: real production use, repeat deployments and rising revenue, with absolute scale still private.
The FINTOP round raises the commercial bar. More named financial institution deployments, a larger base of repeatable implementations and evidence that BizAI Studio reduces deployment work would show that Fisent can grow without services effort rising at the same pace as software adoption.
On the NCFA Financial Innovation Map, Fisent sits where enterprise AI, workflow automation, financial operations and regtech meet.
The Company Intelligence Snapshot below follows the evidence that brings Fisent from formation into its current commercialization stage.
Adrian Murray founded Fisent in Toronto in 2021 after more than a decade working in financial services technology and operations, including core banking, digital banking, compliance, regtech and payments.
FisentToronto financial technology company
FoundationCompany formation and early product work
PrivateEarly financing details not publicly disclosed
Financial ServicesBanking technology, compliance and operations
UnavailableEarly customer evidence is not public
Enterprise AutomationWorkflow and financial technology providers
Fisent's foundation gives the company operating knowledge of financial institutions before generative AI becomes its commercial focus.
Information notice: Private company estimates are identified and attributed. Information may change after the stated update date. This content is provided for informational purposes only and does not constitute investment, financial or legal advice.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Aug 13, 2026

Artificial intelligence (AI) is rapidly becoming part of the day-to-day operations of Canadian financial advice firms. From automating administrative tasks and analyzing client portfolios to supporting investment research and improving client communications, AI has the potential to make advisors more efficient and help firms deliver a better client experience.
But as adoption accelerates, governance isn't always keeping pace.
Many firms are experimenting with AI tools before establishing clear policies around how those tools should be used, monitored, and supervised. That creates significant risk in an industry where investment advice is built on trust, accountability, and regulatory compliance.
Using AI without proper governance is a bit like prescribing medication without understanding the side effects or drug interactions. The technology may offer benefits, but without safeguards, oversight, and a clear understanding of the risks, unintended consequences can quickly outweigh the advantages.
For Canadian financial advisors, governance shouldn't be viewed as unnecessary bureaucracy. It's an essential part of responsible innovation.
Canada's financial regulatory environment already places significant responsibilities on advisors, and those obligations don't disappear simply because AI enters the picture. The Canadian Investment Regulatory Organization (CIRO), together with provincial securities regulators such as the Ontario Securities Commission (OSC) and the Canadian Securities Administrators (CSA), have made it clear that existing regulatory obligations continue to apply whenever technology influences regulated activities. Firms remain responsible for ensuring investor protection, fair dealing, appropriate supervision, cybersecurity, privacy, and sound governance, regardless of whether decisions are supported by artificial intelligence.
AI governance is no longer simply a future consideration. CIRO's 2026 Compliance Report identifies artificial intelligence and emerging technologies as areas of supervisory focus, signalling that firms should expect regulators to examine how AI systems are being used, what controls are in place, and whether appropriate oversight exists. The message is clear: firms remain accountable for the outcomes produced by the technology they choose to implement.
At its core, Canadian financial advisors continue to operate under well-established regulatory obligations. For most registered firms, this includes complying with Know Your Client (KYC), Know Your Product (KYP), and suitability requirements under the Client Focused Reforms. In certain advisory relationships, such as discretionary portfolio management, a fiduciary duty may also apply. Regardless of the business model, advisors are expected to understand the rationale behind every recommendation they provide and be able to explain why it is appropriate for each client. That expectation becomes much more challenging if an AI system produces recommendations that advisors cannot clearly explain, let alone defend or stress test.
Explainability is only one piece of the governance puzzle. Firms must also consider data privacy, cybersecurity, recordkeeping, model bias, third-party vendor oversight, and ongoing monitoring of AI systems. Regulators expect firms to demonstrate not only that technology delivers operational benefits, but also that associated risks are identified, documented, and actively managed.
History provides plenty of reasons for this scrutiny. AI systems used in other industries, such as HR, have produced biased hiring decisions, inaccurate healthcare recommendations, and flawed credit assessments due to inadequate oversight or unintended algorithmic behaviour. Financial advice firms cannot assume similar issues won't emerge within investment or wealth management applications.
Another emerging consideration is AI-generated investment commentary. Recent guidance from the CSA and CIRO reinforces that securities laws apply regardless of how investment recommendations are delivered. Whether commentary comes from a financial advisor, an online platform, or an AI-powered tool, firms remain responsible for ensuring communications comply with applicable registration, disclosure, and investor protection requirements. AI cannot be used to distance a firm from its regulatory responsibilities; introducing it does not reduce those responsibilities. If anything, it increases the need for governance.
Strong AI governance starts long before a new tool is deployed. Rather than allowing employees to independently adopt AI solutions across different departments, firms should first define exactly where AI will be used and where human expertise must remain central to the decision-making process. Administrative automation, document summarization, workflow management, and research support may represent lower-risk applications than suitability assessments, portfolio recommendations, or investment decisions that directly affect clients. Establishing clear use cases helps prevent AI from gradually expanding into areas where the risks may outweigh the benefits.
Governance also requires clear accountability. Every AI-enabled process should have an identified owner who is responsible for monitoring performance, addressing concerns, and escalating issues when necessary. Responsibility cannot rest with the software itself. Human accountability remains essential.
Transparency should be another guiding principle. Clients deserve to understand when AI contributes to services they receive, particularly if it influences recommendations, communications, or financial planning outputs. Transparency builds trust while helping clients better understand how technology supports, rather than replaces, professional judgment.
Bias testing is equally important because AI models learn from historical data, which can contain unintended biases. If left unchecked, algorithms may produce outcomes that disadvantage certain investor groups or reinforce patterns that conflict with principles of fairness and equal access. Regular testing allows firms to identify and correct these issues before they affect clients. The objective isn't simply to deploy AI; it's to deploy AI responsibly.
Creating governance policies is only the first step. Maintaining them requires ongoing operational discipline. There are some daily practices that could help firms in this aspect:
Proper documentation: Every meaningful AI-assisted recommendation or decision should be properly documented. Firms should be able to demonstrate how information was generated, how it was reviewed, and how the final recommendation was reached. Comprehensive documentation not only supports internal quality control but also prepares firms for future regulatory reviews.
Continuous monitoring: AI systems are not static. Performance can change over time as market conditions evolve, new data becomes available, or models begin exhibiting algorithmic drift. Regular reviews help ensure systems continue operating as intended while identifying unexpected behaviours before they become larger problems. Many firms may benefit from conducting quarterly governance reviews that assess model performance, review exceptions, evaluate client outcomes, and confirm compliance with internal policies.
Employee education: This should also remain a priority. Advisors need to understand both the strengths and limitations of AI. Training should focus not only on how to use new tools but also on recognizing situations where human judgment should override automated recommendations.
AI should not be treated as a set-and-go replacement for professional expertise. It should be used responsibly as a tool that enhances decision-making and quality investment advice while preserving the experience, judgment, and accountability that clients expect from trusted financial advisors.
AI will undoubtedly reshape financial advice in Canada, but technology alone won't determine which firms succeed. Governance will. Organizations should establish clear policies, maintain transparency, monitor performance, and preserve meaningful human oversight while using AI. Without adequate governance, firms may expose themselves to compliance failures, reputational damage, and increased regulatory scrutiny.
As AI capabilities continue to expand, firms should regularly ask themselves one important question: Could we clearly explain every AI-assisted recommendation to a client and, if necessary, to a regulator? If the answer is yes, governance is likely supporting innovation. If the answer is no, governance deserves attention before AI adoption moves any further.
Ultimately, responsible AI is not a roadblock to the adoption of innovation. It's about ensuring innovation strengthens the quality, integrity, and trust that define professional financial advice.
— — —

Nadeem Kassam, Marnoa Private Wealth Counsel
Nadeem Kassam, CFA®, MBA
Chief Investment Strategist, Chief Operating Officer & Portfolio Manager at Marnoa Private Wealth Counsel
Nadeem is a Chief Investment Strategist and Portfolio Manager with 20+ years' experience across major global banks, including senior-level roles at RBC, Raymond James, CIBC, Deutsche Bank, and Citigroup. At Marnoa, he leads investment strategy and portfolio management with a focus on North American equities and is a frequent commentator in the media, including regular appearances on BNN Bloomberg.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
August 13, 2026 | NCFA Insight | Artificial Intelligence And Data, Competition And Market Structure, Public Sector Policy And Industrial Strategy

On August 10, 2026, Meta published The Future Is For Everyone, Mark Zuckerberg's wide sweeping proposal for how superintelligence should fit into society.
The central idea is personal empowerment. Zuckerberg argues that advanced AI should give individuals more ability to create, learn, build businesses, improve their health and pursue their own goals rather than placing most of that intelligence under the control of governments, large institutions or a handful of AI companies.
Meta's vision imagines personal agents working continuously on a user's behalf, small teams building companies that once required much larger organizations, personalized tutors, faster scientific discovery and powerful creative tools available to billions of people.
Meta wants AI capability spread widely, while the compute, models, release decisions and government relationships needed to provide it remain concentrated among a handful of organizations.
Mark Zuckerberg, Founder and CEO, Meta:
“The defining questions of our age are who will have access to superintelligence and what will we direct it towards.”
One of Zuckerberg's strongest economic arguments is that AI's biggest contribution could come from helping people invent things rather than simply automating today's jobs.
Meta expects individuals to become capable of doing work that currently requires larger teams, more capital or specialized expertise. Zuckerberg predicts more small businesses, more experimentation and potentially more employment as people use AI to create products, services and jobs that don't exist today.
That is a different vision from a future where AI mainly replaces knowledge work. Meta argues that if personal agents increase people's capabilities quickly enough, workers can adapt and new demand can grow alongside automation.
For founders, that could change the economics of starting a company. Product development, research, design, marketing and operations could require fewer people and less initial capital. Small firms could reach meaningful scale much earlier.
Financial services will feel the same pressure. Meta already has AI that can plan work, connect with email and calendars and continue tasks after the user leaves. As agents gain access to financial information and connected services, permissions and accountability become part of the operating model, especially when an agent can act rather than simply advise.
The more unusual part of Zuckerberg's argument is about safety.
He rejects the idea that one centrally controlled superintelligence can be aligned to a single set of values that works for everyone. People disagree about politics, economics, culture and what makes a good life.
Meta's answer is to distribute powerful AI widely enough that people, businesses, governments and competing AI systems check one another.
It is essentially a balance of power argument. One person with vastly better legal, financial or cybersecurity intelligence could gain an enormous advantage. If many people have access to comparable capabilities, Meta argues that power becomes harder to monopolize. (There’s some irony here. Zuckerberg built his fortune by controlling access to data, distribution and network effects that others couldn’t easily replicate.)
That philosophy also influences Meta's approach to alignment. Personal agents should primarily help users pursue their own goals within legal and safety boundaries rather than enforce one company's view of what those goals should be.
Meta says it plans to build a private mode where even Meta can't access a user's information, and it intends to resume releasing some open models. It is also giving its independent board authority to approve safety criteria for model releases rather than leaving those decisions entirely with Zuckerberg or management.
Meta's existing algorithmic products are already under legal scrutiny, including a federal trial involving 29 U.S. states over alleged harm to children. Meta denies the allegations. A company asking people to trust far more capable personal agents will have to show that user empowerment, privacy and safety work in practice. Algorithmic accountability is already moving into the courts as AI and automated systems take on a larger role in people's lives.
Zuckerberg's decentralization argument has limits.
He wants individuals to have broad access to powerful AI, but he also argues that the United States and its allies should retain leadership in advanced models, silicon and infrastructure. Meta supports continued restrictions on exports of leading chips to geopolitical rivals and wants U.S. policy to make it easier to build data centres and energy capacity.
He also proposes closer cooperation between frontier AI labs and government. Rather than waiting until an advanced model is finished, Meta wants labs to share intermediate model checkpoints and technical staff so governments can identify cybersecurity and other security risks earlier.
The result still leaves considerable power with governments, frontier labs and the companies that control advanced compute. Individuals would gain far more capability. Governments would receive earlier access for security purposes. Independent boards would get more authority over release standards. Frontier labs would still control development of the most capable models.
Meta's vision is therefore decentralized at the user level while retaining substantial institutional coordination at the frontier.
Meta expects capital spending of US$130 billion to US$145 billion in 2026 and spent US$31.08 billion in the second quarter alone. It is investing in models, data centres, energy, networking, its own chips and outside accelerators while trying to deliver AI across products already used by billions of people.
If personal superintelligence is going to be free or affordable at global scale, someone still has to pay for the compute..
Meta wants superintelligence broadly distributed, but scarce compute still has to be allocated. Its answer is a dynamic auction for additional capacity, which means the vision of AI for everyone could still produce tiers of access based partly on what users can afford. (conflict?)
The business model hasn't been proven. Meta's second quarter free cash flow fell to US$784 million as infrastructure spending accelerated, even while its core advertising business remained highly profitable.
Meta is making these commitments under real pressure. Its infrastructure spending has climbed rapidly, the company is still building the compute capacity and custom chips needed to compete at the frontier, and its existing platforms face growing legal scrutiny.
The scale of the investment also reinforces a central tension in Zuckerberg's vision. Meta wants personal AI to give individuals more power, but only a small number of companies can currently finance the systems needed to provide it.
Meta's vision has clear upside for Canada.
Canadian entrepreneurs, researchers and smaller businesses could gain access to capabilities they would never be able to finance themselves. If AI lowers the cost of creating companies, learning new skills and developing new products, a smaller economy can participate without matching U.S. frontier model spending dollar for dollar.
Canada is already debating how to keep more domestic intellectual property, capital and compute capacity while using global AI platforms. The country's AI sovereignty debate is partly about preserving enough domestic capability to avoid becoming only a customer of technology developed and controlled elsewhere.
A recent pro-human AI initiative backed by researchers, business and labour groups also argues for human agency, limits on concentrated power and accountability for AI companies. Zuckerberg reaches some similar principles from a very different starting point.
Canada needs enough choice, competition, data control and domestic capability for its companies and citizens to use increasingly powerful AI on their own terms.
Zuckerberg's bet is that superintelligence can give individuals more power to learn, invent, work and build. Meta has the reach and financial capacity to put that idea in front of billions of people. The cost of doing so is already putting heavy pressure on cash flow.Whether users ultimately gain more control will depend on who controls the models, data, compute and rules behind their personal AI.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
August 13, 2026 | NCFA Resource | Risk Compliance And Regtech, Artificial Intelligence And Data, Regulation And Policy

On August 6, 2026, the UK Financial Conduct Authority launched the FCA Handbook API, giving firms, developers and RegTech providers direct access to structured Handbook data. The free service lets software retrieve current rules, guidance, technical standards and glossary content for use inside compliance and regulatory change systems.
The practical value is real. Firms no longer have to rely only on website searches, monthly downloads or manually maintained rule libraries when they want FCA source material inside their own systems. The API creates a direct route from the Handbook into software that tracks obligations, maps rules to business activities or supports AI assisted compliance work.
The API provides structured access to the FCA Handbook, Technical Standards and Glossary. Users need a free Handbook account, and the FCA says the data can be used in firms’ own applications or through third party technology providers.
The FCA identifies several practical uses:
AI can help retrieve, classify and compare regulatory information, but the quality of the output still depends on the source material it receives. A direct FCA data feed reduces one common problem which is compliance tools working from copied, stale or inconsistently maintained rule text.
NCFA has already identified this problem in AI powered regulatory reporting. The opportunity isn't simply to add AI to compliance work. Systems need reliable regulatory inputs, clear controls and a way to trace outputs back to the underlying rule or guidance.
The API can also reduce manual work around regulatory updates. Firms can connect Handbook content to internal rule inventories, product governance, control libraries or change management processes rather than repeatedly checking individual pages for updates.
There are some practical access conditions. Users cannot work with the API directly through the Handbook website. They need a compatible external application such as Postman or RapidAPI, or another system built to use the interface. Protected endpoints are also subject to rate limits.
The clearest users are compliance teams, legal teams, RegTech providers, financial institutions and fintechs that need FCA rules inside operational systems.
Large firms with internal technology teams can connect the data to their own compliance architecture and tailor how Handbook content is matched to business lines, products or controls.
Smaller firms may get more value indirectly through RegTech providers that use the API to improve rule monitoring, change alerts, obligation management or policy tools.
Developers and AI teams also gain a cleaner source for regulated workflows. For example, a compliance assistant could retrieve relevant Handbook content, compare current and future text, or help staff identify which internal policies may need review after a rule update.
That doesn't make the API a compliance decision engine. A system can retrieve the rule accurately and still reach a poor conclusion about how it applies to a particular firm, product or client situation. Human review, legal interpretation and internal accountability remain necessary.
The main strength is source quality. The API automatically draws from the latest Handbook rather than requiring firms or vendors to maintain their own copy of the rulebook. That can improve consistency and reduce the delay between a Handbook update and its appearance inside a compliance system.
It is also useful that the FCA has made the service available without a separate licence fee. Firms can choose whether to connect directly or use a technology provider, which lowers the barrier for developers and RegTech companies testing new compliance tools.
The API is not a complete regulatory archive. It does not provide historic Handbook versions. Requests for past dates return an error, although current and future versions are available through the API. Firms that need a full historical record will still need the Handbook website, archive tools or their own retained records.
The API also does not cover every piece of FCA information. The FCA Handbook contains rules, guidance and standards, while other FCA publications, supervisory communications, consultations, speeches and notices remain outside that core source. Compliance systems therefore still need broader regulatory monitoring.
Direct access to current regulatory text improves the input, but it does not guarantee accurate interpretation. Firms using AI for compliance should still test outputs, keep records, control permissions and make it clear when a person needs to review the result. The IOSCO AI Supervisory Toolkit provides useful additional guidance on governance, oversight, data quality and control expectations for AI in regulated financial environments.
The FCA Handbook API is most useful when treated as authoritative source infrastructure. It can make regulatory information easier for software to retrieve and keep current, while firms remain responsible for deciding what the rules mean for their own operations.
FCA Handbook API Launch (use cases for compliance, RegTech and AI)
FCA Handbook API FAQ (access, current data, limits and usage requirements)
FCA Handbook API (API access and developer entry point)
FCA Handbook (current rules, guidance and technical standards)
AI Powered Regulatory Reporting (regulatory data, automation and AI opportunity)
IOSCO AI Supervisory Toolkit For Capital Markets (AI governance, controls and oversight)
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: [www.ncfacanada.org](http://www.ncfacanada.org)
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
August 12, 2026 | NCFA Market Activity | Artificial Intelligence And Data, Capital Markets And Market Infrastructure, Competition And Market Structure

On August 6, 2026, AMD agreed to acquire Taalas, a Toronto AI chip company that designs specialized chips to run individual AI models more efficiently. The price wasn't disclosed and the transaction hasn't closed yet, as it's subject to customary closing conditions and regulatory approvals.
AMD plans to bring Taalas technology into its accelerator portfolio alongside Instinct GPUs. That's a useful clue to the strategy. GPUs remain valuable because they can handle many models and workloads. Taalas gives AMD another option for cases where a model is used often enough that more specialized hardware could lower the cost of running it.
Running an AI model requires processors to work through huge numbers of stored parameters. On conventional accelerators, much of that data has to travel between memory and compute hardware. The transfers take time, consume power and make high bandwidth memory an expensive part of an AI system. Taalas brings more storage and computation onto the same silicon and tailors the hardware to the model being run. The design can reduce the external memory, advanced packaging and data movement required by conventional accelerator systems.
Ljubisa Bajic, Founder and CEO, Taalas:
“The production of optimal silicon for each individual model.”
Its first HC1 demonstrator runs Meta's Llama 3.1 8B model on a TSMC 6nm chip with 53 billion transistors. Taalas packages the system in a 2.5 kW server and currently provides access through a beta inference service and API.
The trade-off is straightforward. A GPU can be reprogrammed for many models. HC1 is largely built around one. It supports different context lengths and LoRA fine tuning, but a substantially different model requires another hardware implementation.
Taalas says it can turn a new model into silicon in about two months. If that process works economically at larger scale, AMD could use specialized chips for mature, heavily used models while keeping programmable accelerators for workloads that change more often.
Taalas says HC1 can generate about 17,000 output tokens per second per user on Llama 3.1 8B using a 1K input and 1K output sequence.
That's a company benchmark. Taalas ran its own HC1 result and measured the Nvidia B200 comparison itself, while several other comparison figures came from Artificial Analysis. It shows what the architecture can do on this model and configuration. It doesn't establish that Taalas hardware is faster than Nvidia or other accelerators across AI inference.
HC1 also uses a custom format combining 3-bit and 6-bit parameters. Taalas acknowledges some loss in model quality compared with GPU benchmarks and says its next generation will use standard 4-bit floating point formats.
The company also reports large advantages in power use and system cost in its comparison. Those claims haven't been independently demonstrated across a wide range of models or production environments. It makes the acquisition a calculated bet. AI companies are spending enormous amounts to train models, but every model that reaches widespread use can create an equally serious inference problem: how to serve millions of requests quickly enough and cheaply enough.
That pressure is already changing how AI infrastructure companies compete on cost and performance. Taalas gives AMD a way to explore much deeper specialization without abandoning the flexibility of Instinct.
Taalas was founded in Toronto in 2023 by Ljubisa Bajic, Drago Ignjatovic and Lejla Bajic. The team brought processor experience from AMD, Nvidia and Tenstorrent, which Ljubisa Bajic previously founded.
The company raised US$50 million before emerging from stealth in 2024 and another US$169 million in February 2026, bringing reported funding to about US$219 million. Investors included Quiet Capital, Fidelity and semiconductor investor Pierre Lamond.
Taalas says 24 people developed HC1, which shows how concentrated the engineering effort behind the first chip was.
The deal adds another company to Canada's growing AI hardware record. Toronto and Waterloo based Astrus is working on automated chip design, while Tenstorrent has built a much larger processor business from Toronto.
It also follows another major Canadian semiconductor transaction. U.S.-based Qualcomm agreed in 2025 to acquire Toronto-founded Alphawave Semi for US$2.4 billion, putting another Canadian-founded chip company under foreign ownership.
AMD will control Taalas if this acquisition closes, but it has also said it plans to retain and grow Canadian talent. There is no disclosed commitment to a specific Toronto headcount or to keeping Taalas as a separate company.
That makes the Canadian issue less about whether foreign capital is inherently good or bad and more about how much ownership, intellectual property and future economic value Canada retains as its AI companies scale. Canada's own AI strategy debate has put sovereign capital and domestic IP retention directly on the table.
Taalas raised more than US$200 million, built working silicon and attracted a strategic buyer in about three years. Canada can clearly produce teams and technology that global semiconductor companies want. The difficult question is whether enough domestic capital, procurement and infrastructure exist for more of those companies to scale further before selling.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |