Karsten Wenzlaff, Advisor
August 26th, 2025
July 22, 2026 | NCFA Story Intelligence | Capital Markets And Market Infrastructure, Risk Compliance And Regtech, Regulation And Policy

On July 16, 2026, two prediction market integrity fights surfaced on opposite sides of the Atlantic. France ordered internet providers to block Polymarket, citing illegal gambling, potential losses and wagers that could be manipulated. In Washington, an insider trading report placed a White House teleprompter operator at the centre of the same debate.
Kalshi identified unusual activity through customer onboarding and market surveillance, froze the account before more than $90,000 in reported profits could be withdrawn and referred the trades to the U.S. Commodity Futures Trading Commission. The CFTC wouldn’t confirm or deny an investigation.
The alleged advantage was access to prepared remarks before the public heard them. Five months earlier, trader Caden Booth found a different kind of edge. He tracked travel activity, located a Super Bowl rehearsal and waited on a public sidewalk with a stopwatch. He then wagered more than $50,000 that the national anthem would finish in less than 117 seconds. It lasted 104 seconds.
Both traders acted before the crowd knew the answer. One used public observation. The other allegedly relied on privileged access. France responded to the wider integrity problem by closing access to a platform. Kalshi responded to one account by freezing funds and referring the activity.
Prediction markets need people who find information first. The market breaks down when a winning trade no longer reflects better work and instead reflects a breached duty, an illegal tip or control over the result. Their regulatory future depends on whether platforms can separate those advantages before more governments decide that some contracts are too difficult or harmful to allow.
Prediction markets reward information that other traders miss. Public records, travel data, local observation, specialist knowledge and faster interpretation can all improve a price. Removing that advantage would remove the reason informed traders participate.
The same successful trade can also expose an unfair market. Employees, government officials, contractors, advisers and event participants may know an answer because someone trusted them with information other traders cannot obtain.
The trade begins with public clues. Booth tracks when rehearsals are likely to occur, follows publicly visible travel activity and listens from a public sidewalk. His advantage comes from assembling information before the crowd.
The result still looks suspicious to people who only see the profit. A concentrated wager, unusual confidence and a successful outcome can resemble insider trading after the event. Profitability shows that the trader was right. It doesn’t show how the trader learned enough to act.
Kalshi’s investigation connects access, duty and trading. The exchange concludes that the editor likely had advance knowledge through employment or another formal affiliation and a reasonable basis exists to believe the information was misappropriated in breach of a prior duty.
The CFTC places event contracts inside federal market abuse enforcement. Its enforcement advisory says the facts could support a misappropriation case under the Commodity Exchange Act and Regulation 180.1. Related NCFA intelligence: Kalshi Fines MrBeast Editor In Insider Trading Case.
Kalshi prohibits trading where a person has direct or indirect influence. The candidate acknowledged that the trades were improper. Kalshi imposed a $2,246.36 financial penalty and a five year suspension.
The regulator now asks whether some contracts carry too much control risk. The CFTC’s prediction market rulemaking asks how contracts should be treated when one person or a small group controls the event and whether information advantages create useful prices, unfairness or manipulation.
Public records make suspicious timing visible. The blockchain preserves wallet activity, transfers and trades. Bloomberg’s flagged Polymarket trades show how analysts can find concentrated activity around sensitive events.
Onchain visibility does not reveal the source of knowledge. A wallet can show what happened without identifying the trader or proving why the trader acted. Related NCFA intelligence: When Prediction Markets Start Pricing Geopolitics.
Kalshi connects known customers to exchange enforcement. Customer onboarding, employment information, market surveillance, whistleblower reports, account interviews, freezes and referrals help the exchange determine whether unusual trading reflects access or control.
Polymarket states the boundary for its global market. Its market integrity policy prohibits trades based on stolen confidential information, illegal tips or authority sufficient to influence an outcome. It pairs public blockchain records with specialist monitoring and wallet referrals.
American enforcement starts after a contract reaches the market. The CFTC can investigate fraud, manipulation, confidential information and trading by people who influence an event. Those powers do not settle whether every political, military, weather or entertainment contract should have been listed.
Other regulators act before the trade can occur. Licensing requirements, product limits and access blocks place the regulatory decision at the market entrance. This reduces local exposure but also removes the prices, liquidity and information the platform claims to provide.
The tools make execution faster and more capable. The integration includes algorithmic order types, a block trading interface and planned data normalization across prediction venues. It shows professional infrastructure entering the category without proving broad institutional adoption.
Integrity controls have to keep pace with execution. Faster trading and larger positions improve liquidity and price formation when the advantage is legitimate. They also allow confidential information or event control to be used more efficiently when the controls fail.
A winning trade becomes an integrity problem because of how the advantage was obtained or used, not simply because the trader was right.
Prediction markets cannot treat knowledge itself as misconduct. The price improves when traders find public information faster, connect overlooked facts or understand a subject better than the crowd.
Confidential access changes that relationship. A trader who receives material information through employment, government service, a contract or another trusted position may owe duties that a public observer does not. A person who can control the event creates an additional conflict because the trade can reward conduct that changes the result.
Surveillance sits between those categories and proof. It can identify a new wallet, concentrated position, extraordinary success or trade placed minutes before an announcement. Investigators still need identity, access, communications, duties and control to determine what happened.
Contract design is the earliest control. A market on a prepared speech creates predictable access for writers, production staff and teleprompter operators. A market on a company announcement creates access for employees, advisers and vendors. A contract controlled by one person may be unsuitable without participant restrictions or other safeguards.
Market abuse rules begin after a contract exists. They do not decide whether a military, political, weather or entertainment event should be traded, whether the product is a derivative or a bet, which regulator owns the risk or whether a global platform can enforce one standard across several legal systems.
The commercial opening extends beyond the exchanges. Identity checks, conflict screening, relationship data, wallet attribution, alert scoring, case management and contract risk reviews are becoming part of the product. The harder opportunity is deciding which contracts can be supervised before liquidity arrives. NCFA Innovation Opportunity: Regulated Event Contract Infrastructure.
Canada’s regulated route is narrower, but limiting the available contracts does not remove information risk. A Canadian platform still needs to know who can access or influence the event, which information is public and what evidence supports an account restriction or referral.
Interactive Brokers Canada received the first Canadian approval, followed by Wealthsimple. Related NCFA intelligence: Prediction Markets Tighten As Wealthsimple Enters.
Before Canadian dealers add more contracts and distribution channels, they need controls that identify access, influence and unusual trading without penalizing legitimate public research.
Canada can define the information boundary during product design, connect customer and employment records to surveillance and publish clear escalation rules. Traders should know when better public work is welcome and when access, influence or a breached duty makes the trade improper.
Can prediction markets separate public intelligence from confidential access and event control well enough to keep controversial contracts open?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 22, 2026 | NCFA Companies On The Move | Wealth Investing And Trading, Artificial Intelligence And Data, Risk Compliance And Regtech

d1g1t is a Toronto wealthtech company whose enterprise platform brings portfolio management, performance and risk analytics, trading, reporting, billing, compliance and client engagement into one system. The company says more than 90 wealth firms across North America use the platform, representing over C$200 billion in assets across 600,000 accounts, 250,000 clients, 2,000 advisors and 20,000 users. Those assets belong to client firms and their investors; d1g1t supplies the technology rather than managing the money.
Its July 2026 launch of a server built on Model Context Protocol (MCP) connects that governed portfolio data to Claude, ChatGPT, Microsoft Copilot and other compatible AI tools. Advisors can ask questions about households, holdings, performance, exposures and mandate breaches without working through every screen by hand. The launch matters because d1g1t isn’t adding AI to an empty interface. It’s making an established wealth operating system callable by the assistants firms are beginning to use.
Wealth firms rarely replace a core platform for one clever feature. They do it because too many systems, spreadsheets and handoffs have made the business difficult to run. d1g1t sells against that fragmentation. Its platform gives advisors, operations teams, portfolio managers and compliance staff a common set of household, account, portfolio and risk data, then uses the same engine across reporting, trading, billing and client work.
Recent customer decisions show the size of the jobs it is winning. PWL Capital selected d1g1t in March 2026 for integrated portfolio management, trading, reporting, compliance, billing and client engagement, including bilingual delivery. In June, Goodreid Investment Counsel deployed the platform after using its previous system for a decade. Goodreid manages approximately C$900 million. Neither example proves a typical implementation result, but both show d1g1t being trusted with core operating work rather than a peripheral dashboard.
There is another useful clue in the cap table. CI Financial, National Bank’s NAventures, Purpose Financial and FigTree Financial have invested in d1g1t, partnered with it or used its technology. In 2025, RBC selected d1g1t’s analytics engine and made a strategic investment. For a wealth software company, customers that also supply capital can do more than validate the product. They can sharpen product priorities, open distribution and make the platform harder to dislodge once it sits inside important workflows.
The performance and risk engine is the foundation. d1g1t’s founders built their careers in quantitative finance and enterprise risk systems, including at Algorithmics and R2 Financial Technologies. That history matters because high-net-worth portfolios are rarely a neat list of public securities. Wealth firms may need to connect family entities, several custodians, private funds, partial ownership, off-book assets and different reporting rules before an advisor can answer a seemingly simple question. The engine calculates performance, exposure and risk across that structure, while the application layer turns those calculations into daily work.
The integrated workflow is what firms buy. The platform covers portfolio and model management, trading and rebalancing, performance reporting, billing, compliance, document management, business monitoring and a client portal. d1g1t says it supports traditional and alternative assets and works across multi-family offices, independent advisors, broker-dealers, custodians and bank advisor networks. That breadth creates a larger contract opportunity than a single analytics tool, but it also raises the implementation bar: the company has to handle data conversion, integrations, controls and firm-specific operating rules well enough to become the system people actually use.
MCP changes how users reach the platform. Instead of asking an advisor to click through several modules, the server exposes approved d1g1t capabilities to an AI assistant. A user can request a morning brief, summarize an upcoming meeting, check portfolio drift, examine exposures, prepare a report or flag a mandate breach in natural language. AI agents entering governed financial workflows need permission boundaries, traceable actions and reliable source data. d1g1t already organizes much of that underlying context inside the client’s wealth platform, which is more interesting than attaching a general chatbot to a collection of disconnected files.
d1g1t describes the MCP connection as governed. Public materials explain the intended workflows, although named customer deployments, pricing and detailed implementation specifications haven’t yet been released. Those details will show how quickly the product becomes part of daily advisor work and whether it helps expand existing contracts.
d1g1t is selling into a market where data quality, switching risk and regulatory responsibility matter as much as the interface. Its integrated platform gives the company several ways to win, but the field around it is getting more capable.
MCP is becoming a wealthtech connector, not a moat by itself. Canadian wealth platform OneVest launched its own MCP connection in April 2026, giving AI tools access to live wealth data, portfolios, pipeline information and tasks. OneVest’s continuing wealth-platform expansion makes it a particularly relevant Canadian comparison. d1g1t’s case will rest on the depth of its analytics, complex-portfolio support, integrated workflows and enterprise relationships, not simply on supporting an open protocol.
Large platforms are building native advisor assistants. Addepar’s Addison queries permission-aware portfolio data across a platform used by more than 1,400 firms, while Orion’s Denali AI connects portfolio, risk, CRM and planning information with audit controls. InvestCloud is automating meeting preparation and follow-up. These companies arrive with large installed bases and mature integrations. d1g1t doesn’t need to beat every platform everywhere, but it does need to make AI meaningfully better for the complex firms it already serves.
Good AI depends on clean, usable wealth data. Portfolio answers are only as reliable as the account, ownership, transaction and security data underneath them. PureFacts’ work with wealth platforms on data readiness reflects the same commercial reality: firms want automation, but first they need consistent data and clear operating definitions. d1g1t’s single-platform design can reduce some of that fragmentation. Client-specific data mapping and integration work won’t disappear.
Documents remain part of the advisor record. Holdings and performance data tell only part of a client’s story. Agreements, statements, correspondence and planning records also shape advice and compliance. FutureVault’s agentic document intelligence for advisors shows another route into the same workflow. d1g1t includes document management, but specialized providers can compete or partner around the edges of the platform.
The regulated firm still owns the decision. d1g1t is presented as a software provider, not an investment dealer or portfolio manager. Its clients remain responsible for suitability, supervision, books and records, privacy, cybersecurity and third-party oversight. Canadian cybersecurity guidance for registered firms makes vendor controls and incident readiness part of the buying decision. d1g1t’s SOC 2 Type II work is relevant assurance, though firms will still assess the current AI connection, permissions and data handling for their own use.
Enterprise growth can be lumpy. A core wealth platform can produce durable revenue once installed, but sales and implementation cycles are long. Each customer may require integrations, migration, testing and training before the contract reaches full use. d1g1t’s 96% revenue growth from 2021 through 2024 and recent PWL and Goodreid wins show progress; revenue, recurring-revenue mix, retention and implementation economics remain private.
d1g1t has spent years doing the difficult part: organizing complex wealth data and placing the same analytics inside reporting, trading, billing, compliance and client work. Its current scale, recent customer wins and relationships with major Canadian financial institutions give the MCP launch a credible base. The product isn’t asking wealth firms to trust an AI tool with data that sits somewhere else. It connects the assistant to a platform already used to run the business. On the NCFA Financial Innovation Map, that puts d1g1t at a useful intersection of wealth infrastructure, portfolio data, AI interfaces and compliance technology.
What matters next is adoption. Named firms using the MCP server in live advisor workflows, measurable time savings and evidence of larger or stickier contracts would show that natural-language access is becoming a commercial feature rather than a useful demonstration. That is a fair question for every wealth platform now adding agents, not a problem unique to d1g1t.
The Company Intelligence Snapshot below follows the capital, customer relationships and product decisions that brought d1g1t to this point.
d1g1t was founded in Toronto by financial technology veterans Dr. Dan Rosen, Philippe Rouanet and Benoit Fleury. Incubated at the Fields Institute, the company set out to bring institutional portfolio and risk analytics into a single operating platform for wealth firms. By late 2018 it had four customers representing approximately C$13 billion and 5,000 households.
d1g1tToronto wealth-management technology company
FoundationProduct and first enterprise customers
C$9M+Raised across two early rounds led by Purpose Financial
CanadaIndependent wealth firms and portfolio managers
4 FirmsApproximately C$13B and 5,000 households
One PlatformAnalytics and advisor work replace a fragmented stack
d1g1t began with a difficult but valuable wedge: institutional analytics adapted for wealth firms. The founders’ earlier enterprise systems gave the company credibility with buyers who would be trusting it with core portfolio data.
Information notice: Private-company estimates are identified and attributed. Information may change after the stated update date. This content is provided for informational purposes only and does not constitute investment, financial or legal advice.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 20, 2026 | NCFA Story Intelligence | Regulation And Policy, Capital Markets And Market Infrastructure, Competition And Market Structure

On July 15, 2026, Ontario Finance Minister Peter Bethlenfalvy announced that Ontario had committed to joining Canada’s securities regulatory passport system. The federal Finance Department highlighted the commitment following the federal, provincial and territorial finance ministers’ meeting in Charlottetown, ending almost two decades as the only jurisdiction outside the system.
Finance ministers described the decision as regulatory harmonization, removal of an interprovincial trade barrier and progress toward one Canadian economy. It also resolved a contradiction Ontario had carried for years. The province repeatedly documented duplication, delay and disproportionate compliance costs while continuing to require a separate Ontario decision where most of Canada relied on one principal regulator.
Ontario stayed outside because passport was never the prize it wanted. The province backed a single national regulator, then a cooperative authority with a wider institutional redesign. The first model failed in court. The second survived legally but never opened.
Companies carried the cost of waiting. Equity crowdfunding showed what fragmentation did at company level. A financing model designed to connect issuers and investors online became a provincial compliance exercise that excluded supporters, consumed employee time and made some smaller raises uneconomical.
The story isn’t that Ontario suddenly discovered regulatory friction in 2026. Every alternative gradually weakened while the economic cost of maintaining a separate process became harder to defend.
Canada has one capital market but several securities authorities. Each province and territory retains its legislation, regulator and enforcement powers. The Canadian Securities Administrators develops common instruments, policies and filing systems so companies don’t face entirely different frameworks in every jurisdiction.
Coordination reduces differences without eliminating repeated work. A filing, interpretation, fee or local review may appear reasonable on its own. A company raising capital or operating nationally experiences the accumulated cost through the same legal budget, employees and management time needed to build the business.
Most jurisdictions accept mutual reliance. The principal regulator can develop familiarity with the company, conduct the main review and issue a decision recognized elsewhere. The market gains a national operating mechanism without requiring provinces to surrender jurisdiction.
Ontario remains outside the compromise. An interface arrangement connects it to passport jurisdictions, but companies can still require a separate Ontario decision to access Canada’s largest capital market. The additional step remains while Ontario pursues a more ambitious institution.
The federal proposal reaches far beyond passport. The Canadian Securities Act would place registration, prospectuses, disclosure, derivatives, civil remedies and market offences within one federal regime. Ontario supports a structure that could replace the provincial coordination model rather than simply improve it.
The constitutional loss leaves Ontario without its preferred destination. In 2011, the Supreme Court rejected the proposed Act because Parliament couldn’t assume ordinary provincial securities regulation through its general trade and commerce power. Ontario loses the national model but still doesn’t join passport.
The cooperative model fixes the constitutional problem. Participating provinces would enact uniform laws administered by a common authority, while complementary federal legislation would address systemic risk and national criminal matters. Each legislature remains free to join, amend or leave.
Legal approval cannot assemble the institution. The Supreme Court approved the design in 2018, but major provinces remain outside and implementation dates recede. The first model fails because it takes too much provincial authority. The second preserves authority so carefully that no common regulator opens.
Several provincial rule books confront one digital market. Jurisdictions adopt different offering limits, investor caps, portal obligations, disclosures and filings. NCFA’s archive includes NCFA Canada Response to the Proposed Multilateral Instrument 45-108 Crowdfunding and Start-Up Prospectus Exemption.
The losses appear outside ordinary regulatory statistics. No portal initially registers under MI 45-108. More than 100 startups reportedly lose economical access to Ontario supporters, while one small firm assigns two employees for months to historical compliance work. The underlying record is available in March 1, 2019: NCFA Submission to the Ontario Securities Commission on Regulatory Burden. NI 45-110 harmonizes the market in 2021, but it cannot recover the financing, participation and productive work already lost.
The OSC confirms a pattern rather than a few difficult files. It receives 199 suggestions and identifies 34 underlying concerns, including repeated filings, difficult regulatory navigation, unclear service expectations, outdated technology and requirements that fall more heavily on smaller firms.
The response reveals the jurisdictional limit. The OSC announces 107 initiatives to improve service and remove avoidable work. Related NCFA coverage: OSC Makes Doing Business Easier for Ontario Market Participants. Ontario can improve its own processes, but it cannot eliminate national duplication while continuing to require a separate Ontario decision.
The Taskforce reaches beyond procedural burden. Its recommendations cover governance, competition, capital formation, disclosure, innovation, enforcement and investor protection. NCFA’s formal response is NCFA Response to the Modernizing Ontario’s Capital Markets Consultation Taskforce.
Ontario divides authority inside the OSC while preserving duplication outside it. Capital formation and competition enter the mandate, the Chair and CEO roles are separated and adjudication is placed within a distinct tribunal. The proposed Capital Markets Act does not replace the existing statutes, and no public tracker supports a claim that the complete 74 recommendation program was implemented.
The cooperative transition project winds down without transferring authority. Existing commissions remain responsible, the CSA continues coordinating national policy and passport keeps serving the jurisdictions that joined it. The practical system survives while the ambitious replacement recedes.
Ontario’s holdout loses its destination. The province is no longer choosing between passport and an approaching national regulator. It is choosing between passport and continued duplication with no replacement institution in sight. The original reason for waiting has disappeared, but companies still face the additional process.
The Bank of Canada turns weak productivity into an emergency. In March 2024, Senior Deputy Governor Carolyn Rogers says it is time to break the glass. Weak investment, limited competition and lengthy or unpredictable approvals discourage companies from committing capital.
Ontario’s separate review becomes part of the economic diagnosis. Every repeated filing, legal opinion and approval cycle uses the same employees, financing and management attention needed for technology, customers and expansion. Related NCFA coverage: How Competition Powers Canada’s Economic Growth. Passport doesn’t remove scrutiny. It prevents several regulators from consuming company resources to deliver substantially the same protection.
The cost of duplication is no longer only regulatory. It is productive work that doesn’t happen.
Ontario gives up duplication rather than jurisdiction. One principal regulator can conduct the main review while Ontario retains its legislation, commission, enforcement capability and voice in national policy. The province no longer has to choose between complete institutional control and surrendering its capital market.
The political commitment now faces an operating test. Industry advocates said passport can create a “single regulator experience through a principal regulator,” but harmonization in policy must also deliver harmonization in practice across legislation, policy and regulatory operations. Investment Executive reports the implementation direction and industry response. The strongest evidence of success will be fewer repeated reviews, lower compliance costs and faster interprovincial access while maintaining investor protection.
Ontario’s decision closes a long loop in Canadian capital markets policy.
The province rejected passport because it wanted a more ambitious national regulator. The first version failed constitutionally. The cooperative version survived in court but never became operational. Ontario then documented extensive burden inside its own market, implemented selected modernization reforms and continued requiring a separate provincial process after the national alternative receded.
Equity crowdfunding showed what the delay meant for companies. The market was divided before it could mature nationally. Legal work, platform controls and continuing obligations consumed a large share of modest financings. Investors were excluded by geography. Employees were assigned to compliance work instead of customers and growth.
The productivity emergency raised the stakes. Canada cannot describe weak investment, limited competition and poor productivity as urgent while treating avoidable duplication as institutionally harmless. The same capital and employee time cannot be used twice.
Passport is not a single national regulator, and it does not eliminate provincial authority. Its value is practical. One qualified regulator does the principal work while the others rely on the result.
Ontario didn’t suddenly discover regulatory friction in 2026. It gradually accepted that preserving every layer of control carried an economic cost that internal reform and an unfinished national project had not removed.
Ontario should publish an implementation schedule, identify the decisions covered by passport and report whether review periods, professional costs and duplicate regulatory interactions decline. Results for smaller firms should be reported separately because they carry fixed compliance costs most heavily.
Investor protection remains central. Reliance should remove repetition, not scrutiny. Principal regulators need the information, expertise and authority required to make decisions every participating jurisdiction can trust.
The larger question extends beyond securities regulation. Canada often pursues national economic outcomes through provincial institutions. Governments may continue debating the ideal architecture, but companies shouldn’t be required to finance avoidable friction while they wait.
When governments measure regulatory burden, should they count only compliance expenses that appear on company records, or also the financings, investment and productive work that never occur because the combined process makes them uneconomical?
Share this story → Explore related intelligence → Subscribe
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 20, 2026 | NCFA Resource | Cybersecurity And Fraud, Risk Compliance And Regtech, Capital Markets And Market Infrastructure

On July 15, 2026, the Canadian Securities Administrators published new cybersecurity guidance for registered dealers, advisers, and investment fund managers (Download the 12 page PDF report). CSA Staff Notice 33-322 combines findings from a focused review of 73 firms with practical expectations for policies, employee training, risk assessments, third party oversight, and incident response.
The notice is most useful as a compliance review tool. Firms can compare their written controls, operating practices, and supporting records against the deficiencies and effective practices identified by securities regulators. The guidance is particularly relevant for smaller and medium sized firms that may not have dedicated cybersecurity teams.
The notice organizes cybersecurity readiness around five areas that regulators examined under section 11.1 of National Instrument 31-103:
The review found useful benchmarks. 8% of firms had no written cybersecurity policies, while 55% had policies that needed improvement. Twenty one per cent provided no employee cybersecurity training. Forty five per cent completed risk assessments that could have been stronger, and 12% had no documented assessment during the review period.
Third party oversight was one of the clearest weaknesses. All examined firms used service providers with access to systems or data, but 62% had no documentation or limited documentation supporting their cybersecurity oversight. The CSA expects firms to complete and document due diligence before onboarding a provider and repeat that review throughout the relationship.
The guidance identifies information firms should assess, including data storage, encryption, access controls, patch management, incident notification, subcontractors, operating jurisdictions, and shared responsibility in cloud environments. It also recommends maintaining a complete vendor register and reviewing current SOC 2 or similar reports where available.
Incident preparedness also receives detailed attention. Fifteen per cent of firms had no written incident response plan. Among firms with a plan, 53% needed stronger procedures and 63% should have tested their plans more regularly. The notice describes tabletop exercises and simulated attacks as practical ways to test whether people, processes, and technical controls work together during an incident.
The primary audience is firms registered as dealers, advisers, portfolio managers, investment fund managers, exempt market dealers, and restricted portfolio managers. Chief compliance officers, directors, technology leaders, privacy professionals, and internal audit teams can use the notice to organize a control review and identify missing documentation.
Boards and senior executives can also use it to test whether cybersecurity oversight is tied to clear responsibilities, regular reporting, and evidence that controls operate as intended. Written policies alone aren’t enough when actual practices, testing schedules, or access controls differ from the documented process.
Cybersecurity consultants, legal advisers, insurance providers, managed service providers, and software vendors can use the findings to better understand the records and evidence registered firms may need during a regulatory review.
The notice is strong because it combines regulatory expectations with observed deficiencies, percentages, effective practices, and practical takeaways. It covers both governance and technical controls, including multifactor authentication, encryption, backups, access rights, patching, email filtering, endpoint protection, and activity logging.
It also makes documentation a central requirement. Firms should be able to show when policies were reviewed, who completed training, how risks were assessed, what vendor due diligence occurred, and when incident plans or backup recovery procedures were tested.
The guidance does not create a complete technical cybersecurity standard, and it doesn’t replace obligations under privacy, securities, corporate, or other applicable laws. Expectations also vary with the firm’s size, operating complexity, client information, service provider reliance, and exposure to cyber risk.
Firms should therefore use the notice as a regulatory gap assessment and evidence checklist, then supplement it with appropriate legal advice, technical standards, testing, and controls suited to their operations.
CSA Staff Notice 33-322 (cybersecurity examination findings and guidance for registered firms)
CSA Staff Notice 33-321 (foundational 2017 cybersecurity and social media guidance)
NIST Cybersecurity Framework (risk management structure for identifying, protecting, detecting, responding, and recovering)
CIS Critical Security Controls (prioritized technical and operational safeguards)
Wealthsimple Confirms Breach Impacting Clients (third party exposure and incident response)
Proposed Class Action Targets Equifax Access Controls (access governance and third party permissions)
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 20, 2026 | NCFA Market Activity | Cybersecurity And Fraud, Artificial Intelligence And Data, Risk Compliance And Regtech

On July 20, 2026, Neo emerged from stealth with US$100 million in combined seed and Series A financing from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures and Merlin Ventures.
The Boston cybersecurity company was founded in 2025 by Nick Warner, Shlomi Salem and Eran Shirazi. Note that it's unrelated to Calgary based Neo Financial. Warner previously served as SentinelOne president and COO, Salem led detection engineering and threat research at SentinelOne, and Shirazi previously co-founded EasySend after leading vulnerability research in Israel’s Unit 8200.
Neo is building what it calls an agentic software control layer. The platform gives security teams an inventory of AI agents, AI enabled applications, plugins, extensions, MCP servers and traditional software that has gained agentic capabilities. It then maps permissions, attributes actions and applies policy before software reaches sensitive data or systems.
The company plans to use the financing to expand engineering and go to market operations. Neo hasn't disclosed revenue, customer counts, named customers, valuation or the allocation between its seed and Series A rounds.
Enterprise security was built around human users, known applications and recognizable data flows. AI agents can act differently. They may inherit a user’s permissions, call several tools, reach files and credentials, communicate with other agents and continue operating without a conventional interface.
That means risky activity may not even resemble a conventional intrusion. An agent can use valid credentials and approved applications while still exporting too much data, reading a secret, pushing code or initiating an action that exceeds the authority its operator intended to grant. NCFA’s analysis of AI agents gaining identity and wallet access shows how quickly this issue reaches financial APIs and real infrastructure.
Neo’s platform combines four functions. It finds AI software, checks what it can access, shows who or what is behind each action, and lets security teams allow, block or pause that action for approval.
Threat's aren't limited to deliberately malicious agents. ShadowLeak demonstrated how hidden instructions could manipulate an AI agent and expose private information without a user clicking a malicious link.
Its Neoverse knowledge base maps the capabilities, risks and behaviour of agentic software before it enters an enterprise environment. Neo says enforcement occurs natively at the endpoint, where the software can intercept tool calls, API access, credential reads and data transfers before the action is completed.
Neo combines software inventory, posture intelligence, attribution and endpoint enforcement across agentic and traditional applications.
Check Point is developing a wider AI security control plane covering employee AI use, AI applications and agentic systems.
SailPoint is extending identity governance to AI agents and other non-human identities.
Existing endpoint security providers already control devices, files and processes, but may not yet map the permissions and chained actions occurring inside agentic software.
Cloud and application security companies can govern models, APIs and data access, creating a competitive question around whether customers will buy a separate agentic control layer or expect existing security platforms to absorb the function.
Banks and other regulated organizations will need more than a list of approved AI tools. They need to know which person authorized an agent, what credentials it inherited, which systems it can call, what information it can export and when human approval is mandatory.
Neo’s opportunity is to show who or what can access each system and enforce clear limits on what they can do. Its challenge is that endpoint, identity, cloud and network security companies are all pursuing parts of the same problem. Large institutions may prefer one more specialized control layer, or they may demand that existing suppliers add agent governance to products already deployed across the organization.
Financial institutions are adopting AI while remaining accountable for privacy, cybersecurity, third party risk, operational resilience and auditability. An agent that can access customer information, initiate a payment, change code or communicate externally will need authority limits that security, risk and compliance teams can understand.
Neo has the capital and founding team to compete early, but the category is still forming. Enterprise adoption, integration depth and the quality of its policy enforcement will matter more than the size of the launch financing.
Will enterprises buy a dedicated control layer for agentic software, or will endpoint, identity and cloud security providers absorb the function before the category becomes independent?
Nick Warner, Shlomi Salem and Eran Shirazi founded Neo in 2025 to build security controls for enterprise software gaining autonomous and agentic capabilities.
Neo SecurityEnterprise cybersecurity company focused on agentic software
FormationExperienced operators assemble before the public launch
Early Institutional BackingSeed and Series A allocation not publicly disclosed
Enterprise SecurityAI driven software environments
SecOps TeamsLarge organizations adopting AI enabled software
Operator ExperienceFounders previously built and scaled enterprise security companies
Neo begins with founders who have built cybersecurity products and commercial organizations before. That lowers some execution risk, but it does not yet establish enterprise adoption.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 17, 2026 | NCFA Insight | Regulation And Policy, Wealth Investing And Trading, Risk Compliance And Regtech

On July 9, 2026, the UK Financial Conduct Authority reported the results of its finfluencer enforcement campaign. A coordinated week of action involving 9 international regulators produced 3 arrests, 6 criminal proceedings, 11 warning or cease and desist letters, 50 warning alerts and 650 social media takedown requests.
Canadian regulators weren’t watching from the sidelines. The Alberta Securities Commission, Autorité des marchés financiers, British Columbia Securities Commission and Ontario Securities Commission participated in the June 2025 operation. Earlier analysis asked whether finfluencers were facing a crackdown or clearer regulation.
The FCA’s latest figures show that enforcement has now become repeatable. Investigators can identify illegal content, connect creators to products and firms, request platform removals, issue public warnings and escalate selected cases into criminal proceedings.
The scale of the FCA’s supporting operation is just as relevant. During 2025, it issued 2,329 warnings about unauthorized or potentially fraudulent firms, compared with 2,240 in 2024. It secured 17 criminal convictions involving fraud, insider dealing, money laundering and data protection offences. Twelve people paid a combined £1.77 million in market abuse fines for market abuse.
Technology is improving that capacity. FCA automation reduced the handling time for simpler supervisory cases from as much as 4 hours to about 6 minutes on average. That doesn’t automate consequential decisions. It clears routine work so investigators can spend more time on repeat promoters, hidden compensation, unauthorized firms and cross border distribution.
The 650 takedown requests are the most commercially relevant number. Arrests attract attention, but removing hundreds of accounts and posts targets distribution. Illegal promotions lose value when creators can’t reach an audience, acquire leads or direct followers to a trading platform.
The FCA can examine multiple parties within one campaign. A creator may publish the content, a financial firm may pay for it, an affiliate network may track referrals and a platform may distribute it. The underlying product can then lead investigators to an unauthorized operator or regulated firm with weak approval controls.
Criminal proceedings provide the upper end of that response. The FCA accused 3 people charged after the 2025 operation of promoting high risk contracts for difference without authorization. Each faces an allegation of communicating an invitation to engage in investment activity contrary to section 21 of the UK Financial Services and Markets Act.
The April 2026 second global week of action showed how quickly the system had expanded. Seventeen regulators participated. The FCA requested the removal of 120 accounts and identified 1,267 illegal financial advertisements that reached at least 2,338,372 accounts. People or firms already listed on its Warning List accounted for 66% of those advertisements.
That 66% figure exposes a persistent enforcement problem. Many promoters aren’t unknown actors. They continue publishing after regulators have already identified the related firm, person or offer. Effective supervision therefore depends on account removal, repeat offender monitoring and platform cooperation, not warnings alone.
The FCA also secured a guilty plea, began criminal proceedings against 2 more people, issued 34 new warning alerts and updated 14 existing warnings during the April operation. Coordination now combines prosecution, surveillance, education and content removal rather than treating each promotion as an isolated post.
Canada’s legal foundation is already in place. In December 2025, the CSA and CIRO published Staff Notice 31-369, which explains how securities law applies to finfluencers, issuers and registered firms. The practical requirements appear in Canada’s finfluencer guidance.
The guidance doesn’t create a separate licence for creators. It examines the activity itself. A creator may need registration when they provide investment advice as a business, facilitates trades, arranges referrals or connects paid subscribers to copy trading. General market commentary may qualify for an exemption, but creators must still disclose financial interests and other conflicts clearly and on time.
Compensation also changes the compliance analysis. Cash payments, securities, affiliate income, referral fees and free products can establish a commercial relationship. A disclaimer such as “not financial advice” doesn’t cancel the substance of a recommendation, the creator’s compensation or the transaction being encouraged.
Responsibility extends beyond the creator. Registered firms must supervise people acting on their behalf, address referral arrangements, retain records and review relevant communications. Issuers remain responsible for paid investor relations activity and promotional claims made for their benefit. The joint staff notice applies the same principles to AI generated content and digital personas.
The investor evidence explains why regulators are paying attention. An OSC study of 655 Canadian retail investors found that 35% had made a financial decision based on finfluencer content. Those who acted on it were 12.2 times more likely to report being scammed on social media and 2.3 times more likely to have experienced a significant investment loss.
The OSC also ran a simulated investment experiment involving 1,465 Canadians. After viewing a promotional social media post, 38% bought the featured asset. Only 8% of the control group did the same. The full findings and behavioural differences appear in the finfluencer effect on Canadian investors.
Canada has also produced direct enforcement results. In September 2025, the Alberta Securities Commission imposed sanctions on James Domenic Floreani and Jayconomics Inc. for promoting 4 issuers through YouTube, X and Patreon without clearly disclosing that they published the content on behalf of those issuers.
The respondents received a $30,000 administrative penalty, $10,185.10 in costs and 2 year restrictions covering investor relations activity, public securities promotion and securities or derivatives advice.
British Columbia added a preventive layer during the April 2026 operation. The BCSC issued 14 compliance letters to YouTubers and other promoters who had discussed publicly traded B.C. companies. It also referred to an active proceeding alleging that sponsored issuer promotions weren’t disclosed clearly.
The FCA operates a national financial promotions regime and can report one consolidated set of arrests, warnings, takedowns and prosecutions. Provincial and territorial authorities administer Canadian securities regulation, while CIRO supervises investment dealers, mutual fund dealers and regulated marketplaces.
Canadian action may therefore appear as several provincial cases, coordinated review periods, issuer investigations, warning letters and firm supervision rather than one national enforcement tally. That can make the activity look smaller even when regulators review the same creators, platforms and promotional networks.
The operating implications are already clear.
Platforms are also becoming part of the enforcement process. When regulators can connect warnings to hundreds of removal requests, account access becomes a compliance dependency. Firms using social media for distribution can’t treat the creator’s channel as an independent marketing asset beyond their control.
Canada doesn’t need to duplicate the FCA’s structure to produce comparable enforcement. Its regulators are already participating in the same international operations, applying national guidance and using provincial proceedings. The open question is whether those actions will become visible as a coordinated Canadian program or remain distributed across separate regulators and cases.
Will Canada’s finfluencer guidance support coordinated enforcement across provinces, platforms and firms, or will separate cases continue defining the compliance boundary?
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA engages with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |