Global fintech and funding innovation ecosystem

Category Archives: Regtech, Compliance, Governance

When Does A Smart Prediction Become Insider Trading?

July 22, 2026 | NCFA Story Intelligence | Capital Markets And Market Infrastructure, Risk Compliance And Regtech, Regulation And Policy

AI Image – Prediction market research, confidential access and surveillance

Public Research, Confidential Access, Event Control And Rules Still Being Written

On July 16, 2026, two prediction market integrity fights surfaced on opposite sides of the Atlantic. France ordered internet providers to block Polymarket, citing illegal gambling, potential losses and wagers that could be manipulated. In Washington, an insider trading report placed a White House teleprompter operator at the centre of the same debate.

Kalshi identified unusual activity through customer onboarding and market surveillance, froze the account before more than $90,000 in reported profits could be withdrawn and referred the trades to the U.S. Commodity Futures Trading Commission. The CFTC wouldn’t confirm or deny an investigation.

The alleged advantage was access to prepared remarks before the public heard them. Five months earlier, trader Caden Booth found a different kind of edge. He tracked travel activity, located a Super Bowl rehearsal and waited on a public sidewalk with a stopwatch. He then wagered more than $50,000 that the national anthem would finish in less than 117 seconds. It lasted 104 seconds.

Both traders acted before the crowd knew the answer. One used public observation. The other allegedly relied on privileged access. France responded to the wider integrity problem by closing access to a platform. Kalshi responded to one account by freezing funds and referring the activity.

Prediction markets need people who find information first. The market breaks down when a winning trade no longer reflects better work and instead reflects a breached duty, an illegal tip or control over the result. Their regulatory future depends on whether platforms can separate those advantages before more governments decide that some contracts are too difficult or harmful to allow.

Prediction markets reward information that other traders miss. Public records, travel data, local observation, specialist knowledge and faster interpretation can all improve a price. Removing that advantage would remove the reason informed traders participate.

The same successful trade can also expose an unfair market. Employees, government officials, contractors, advisers and event participants may know an answer because someone trusted them with information other traders cannot obtain.

Better Information Is The Product February 2026

Booth’s Super Bowl trade shows why unusual success cannot establish misconduct. He develops an advantage through open clues, physical observation and patience. Other traders could have attempted the same work.

The trade begins with public clues. Booth tracks when rehearsals are likely to occur, follows publicly visible travel activity and listens from a public sidewalk. His advantage comes from assembling information before the crowd.

The result still looks suspicious to people who only see the profit. A concentrated wager, unusual confidence and a successful outcome can resemble insider trading after the event. Profitability shows that the trader was right. It doesn’t show how the trader learned enough to act.

Confidential Access Changes The Trade February 25, 2026

The CFTC draws a different line when a YouTube editor trades with likely advance knowledge of unpublished video content. The concern is not superior forecasting. It is the alleged use of confidential information obtained through an employment relationship.

Why Ordinary Insider Trading Language Falls Short

Duty comes before the trade. Securities cases usually start with information about a company or its securities. Event contracts can price a speech, election, military action, entertainment result or company announcement, so the relevant duty may come from employment, government service, a contract or another trusted relationship.

The source of the advantage matters. A trader who assembles public records has no special access simply because the work produces an accurate result. An employee who receives the answer through a private briefing may be using information that was entrusted for another purpose.

Control creates a different conflict. A candidate, athlete, executive or event participant may be able to change the outcome instead of merely predicting it. That can raise manipulation or fraud concerns even when no confidential document changes hands.

Platform rules can act before a federal case exists. An exchange may restrict a participant, freeze an account or cancel access under its own rules. A regulator still needs evidence connecting identity, information, duty and conduct before alleging a legal violation.

The familiar insider trading label can therefore cover several different problems: misappropriation, fraud, manipulation, exchange rule violations and government ethics duties.

Kalshi’s investigation connects access, duty and trading. The exchange concludes that the editor likely had advance knowledge through employment or another formal affiliation and a reasonable basis exists to believe the information was misappropriated in breach of a prior duty.

The CFTC places event contracts inside federal market abuse enforcement. Its enforcement advisory says the facts could support a misappropriation case under the Commodity Exchange Act and Regulation 180.1. Related NCFA intelligence: Kalshi Fines MrBeast Editor In Insider Trading Case.

Control Over The Outcome Creates A Separate Conflict 2025 to 2026

A political candidate trading on his own candidacy does not require a leaked document. The conflict exists because the trader can affect the event being priced. The same problem appears when an executive trades on words they control, an event participant trades on their own decision or a person can influence the settlement source.

Kalshi prohibits trading where a person has direct or indirect influence. The candidate acknowledged that the trades were improper. Kalshi imposed a $2,246.36 financial penalty and a five year suspension.

The regulator now asks whether some contracts carry too much control risk. The CFTC’s prediction market rulemaking asks how contracts should be treated when one person or a small group controls the event and whether information advantages create useful prices, unfairness or manipulation.

Surveillance Finds Patterns Before It Finds Proof First Half Of 2026

Bloomberg reviews roughly 34,000 Polymarket trades flagged by Polysights and reports about $200 million in flagged activity during the first half of 2026. Military and geopolitical contracts account for much of the increase. The figures describe trades selected by a surveillance model, not $200 million of proven insider trading.

What Gets A Wallet Flagged

Timing and concentration create the first alert. Polysights considers trade size, concentration in one event or a few related contracts, activity shortly before a public announcement and unusually large profits from low probability outcomes.

Wallet history adds context. A new wallet that receives funds, places one confident trade and withdraws after settlement can look different from an established account with activity across many markets. Related wallets and repeated funding patterns can also help analysts connect positions.

The identity gap remains. Public blockchain records show transactions and timing. They do not establish who controlled a wallet, where the information came from, whether the trader owed a duty or whether several wallets belong to one person.

A flag starts the investigation. Platforms still need customer records, employment information, communications, device data, interviews and event relationships. Without that evidence, an unusual trade remains a reason to investigate rather than proof of misconduct.

A new wallet making one concentrated winning trade could belong to an insider. It could also belong to a skilled trader who created the wallet for that opportunity.

Public records make suspicious timing visible. The blockchain preserves wallet activity, transfers and trades. Bloomberg’s flagged Polymarket trades show how analysts can find concentrated activity around sensitive events.

Onchain visibility does not reveal the source of knowledge. A wallet can show what happened without identifying the trader or proving why the trader acted. Related NCFA intelligence: When Prediction Markets Start Pricing Geopolitics.

Platforms Turn Rules Into Operating Controls February To July 2026

Market integrity now depends on what happens between a surveillance alert and a final decision. Platforms need identity records, relationship disclosures, contract restrictions, audit trails, investigators, account controls, evidence preservation and a route to regulators or law enforcement.

Kalshi connects known customers to exchange enforcement. Customer onboarding, employment information, market surveillance, whistleblower reports, account interviews, freezes and referrals help the exchange determine whether unusual trading reflects access or control.

Polymarket states the boundary for its global market. Its market integrity policy prohibits trades based on stolen confidential information, illegal tips or authority sufficient to influence an outcome. It pairs public blockchain records with specialist monitoring and wallet referrals.

Countries Disagree On What These Markets Are 2026

The United States is developing federal derivatives rules while France and Spain block access and Great Britain treats current products as gambling. A contract can be supervised as a financial market in one country, require a betting licence in another and remain unavailable somewhere else.

How Major Markets Currently Treat Prediction Markets

Status at July 22, 2026. Availability can change by platform and jurisdiction.

United States: CFTC regulated exchanges can list qualifying event contracts under federal derivatives law. Draft rules still have to address prohibited contracts, event control, market abuse and the boundary with state gambling laws.

France: The National Gambling Authority ordered internet providers to block Polymarket on July 16, 2026. The regulator cited an illegal gambling offering, potential losses and wagers that could be manipulated. Polymarket plans a legal challenge.

Spain: The government temporarily blocked Polymarket and Kalshi in May 2026 while it investigates whether they operated without required gambling licences.

Great Britain: The Gambling Commission says current prediction market products resemble betting exchanges. Operators need the appropriate gambling licence and unlicensed platforms should not transact with British consumers.

Canada: There is no single national treatment. Polymarket currently restricts new orders from Ontario, British Columbia, Alberta and Quebec, while supervised Canadian distribution has started with a narrower product set.

Other restricted markets: Polymarket’s current restrictions also prevent new orders from Australia, Belgium, Brazil, Germany, Italy, Poland, Singapore, Taiwan and Thailand. Platform geoblocking records availability. It does not establish that every country has enacted the same type of legal prohibition.

American enforcement starts after a contract reaches the market. The CFTC can investigate fraud, manipulation, confidential information and trading by people who influence an event. Those powers do not settle whether every political, military, weather or entertainment contract should have been listed.

Other regulators act before the trade can occur. Licensing requirements, product limits and access blocks place the regulatory decision at the market entrance. This reduces local exposure but also removes the prices, liquidity and information the platform claims to provide.

Professional Execution Raises The Stakes July 22, 2026

Talos adds Kalshi event contracts to the interface used by select institutional clients. Prediction markets begin receiving algorithmic execution, block trading and normalized market data tools that resemble the systems used in established asset classes.

The tools make execution faster and more capable. The integration includes algorithmic order types, a block trading interface and planned data normalization across prediction venues. It shows professional infrastructure entering the category without proving broad institutional adoption.

Integrity controls have to keep pace with execution. Faster trading and larger positions improve liquidity and price formation when the advantage is legitimate. They also allow confidential information or event control to be used more efficiently when the controls fail.

A winning trade becomes an integrity problem because of how the advantage was obtained or used, not simply because the trader was right.

The Contract Can Be Legal Before Its Information Rules Are Ready

Prediction markets cannot treat knowledge itself as misconduct. The price improves when traders find public information faster, connect overlooked facts or understand a subject better than the crowd.

Confidential access changes that relationship. A trader who receives material information through employment, government service, a contract or another trusted position may owe duties that a public observer does not. A person who can control the event creates an additional conflict because the trade can reward conduct that changes the result.

Surveillance sits between those categories and proof. It can identify a new wallet, concentrated position, extraordinary success or trade placed minutes before an announcement. Investigators still need identity, access, communications, duties and control to determine what happened.

Contract design is the earliest control. A market on a prepared speech creates predictable access for writers, production staff and teleprompter operators. A market on a company announcement creates access for employees, advisers and vendors. A contract controlled by one person may be unsuitable without participant restrictions or other safeguards.

Market abuse rules begin after a contract exists. They do not decide whether a military, political, weather or entertainment event should be traded, whether the product is a derivative or a bet, which regulator owns the risk or whether a global platform can enforce one standard across several legal systems.

The commercial opening extends beyond the exchanges. Identity checks, conflict screening, relationship data, wallet attribution, alert scoring, case management and contract risk reviews are becoming part of the product. The harder opportunity is deciding which contracts can be supervised before liquidity arrives. NCFA Innovation Opportunity: Regulated Event Contract Infrastructure.

Canada Starts With Fewer Contracts And More Gatekeeping

Canada’s regulated route is narrower, but limiting the available contracts does not remove information risk. A Canadian platform still needs to know who can access or influence the event, which information is public and what evidence supports an account restriction or referral.

Interactive Brokers Canada received the first Canadian approval, followed by Wealthsimple. Related NCFA intelligence: Prediction Markets Tighten As Wealthsimple Enters.

Before Canadian dealers add more contracts and distribution channels, they need controls that identify access, influence and unusual trading without penalizing legitimate public research.

Canada can define the information boundary during product design, connect customer and employment records to surveillance and publish clear escalation rules. Traders should know when better public work is welcome and when access, influence or a breached duty makes the trade improper.

Talking Point

Can prediction markets separate public intelligence from confidential access and event control well enough to keep controversial contracts open?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Inside d1g1t: Wealth Platform Growth And AI Strategy

July 22, 2026 | NCFA Companies On The Move | Wealth Investing And Trading, Artificial Intelligence And Data, Risk Compliance And Regtech

NCFA Companies On The Move profile of d1g1t, a Canadian enterprise wealth management technology company, July 2026.

d1g1t Company Profile: Growth, Wealth Platform And AI Strategy

Founded2017
OriginToronto, Canada
FoundersDr. Dan Rosen, Philippe Rouanet and Benoit Fleury
Company StageExpand / Scale

d1g1t is a Toronto wealthtech company whose enterprise platform brings portfolio management, performance and risk analytics, trading, reporting, billing, compliance and client engagement into one system. The company says more than 90 wealth firms across North America use the platform, representing over C$200 billion in assets across 600,000 accounts, 250,000 clients, 2,000 advisors and 20,000 users. Those assets belong to client firms and their investors; d1g1t supplies the technology rather than managing the money.

Its July 2026 launch of a server built on Model Context Protocol (MCP) connects that governed portfolio data to Claude, ChatGPT, Microsoft Copilot and other compatible AI tools. Advisors can ask questions about households, holdings, performance, exposures and mandate breaches without working through every screen by hand. The launch matters because d1g1t isn’t adding AI to an empty interface. It’s making an established wealth operating system callable by the assistants firms are beginning to use.

Why Wealth Firms Are Choosing d1g1t

Wealth firms rarely replace a core platform for one clever feature. They do it because too many systems, spreadsheets and handoffs have made the business difficult to run. d1g1t sells against that fragmentation. Its platform gives advisors, operations teams, portfolio managers and compliance staff a common set of household, account, portfolio and risk data, then uses the same engine across reporting, trading, billing and client work.

Recent customer decisions show the size of the jobs it is winning. PWL Capital selected d1g1t in March 2026 for integrated portfolio management, trading, reporting, compliance, billing and client engagement, including bilingual delivery. In June, Goodreid Investment Counsel deployed the platform after using its previous system for a decade. Goodreid manages approximately C$900 million. Neither example proves a typical implementation result, but both show d1g1t being trusted with core operating work rather than a peripheral dashboard.

There is another useful clue in the cap table. CI Financial, National Bank’s NAventures, Purpose Financial and FigTree Financial have invested in d1g1t, partnered with it or used its technology. In 2025, RBC selected d1g1t’s analytics engine and made a strategic investment. For a wealth software company, customers that also supply capital can do more than validate the product. They can sharpen product priorities, open distribution and make the platform harder to dislodge once it sits inside important workflows.

The Platform Behind The AI Launch

The performance and risk engine is the foundation. d1g1t’s founders built their careers in quantitative finance and enterprise risk systems, including at Algorithmics and R2 Financial Technologies. That history matters because high-net-worth portfolios are rarely a neat list of public securities. Wealth firms may need to connect family entities, several custodians, private funds, partial ownership, off-book assets and different reporting rules before an advisor can answer a seemingly simple question. The engine calculates performance, exposure and risk across that structure, while the application layer turns those calculations into daily work.

The integrated workflow is what firms buy. The platform covers portfolio and model management, trading and rebalancing, performance reporting, billing, compliance, document management, business monitoring and a client portal. d1g1t says it supports traditional and alternative assets and works across multi-family offices, independent advisors, broker-dealers, custodians and bank advisor networks. That breadth creates a larger contract opportunity than a single analytics tool, but it also raises the implementation bar: the company has to handle data conversion, integrations, controls and firm-specific operating rules well enough to become the system people actually use.

MCP changes how users reach the platform. Instead of asking an advisor to click through several modules, the server exposes approved d1g1t capabilities to an AI assistant. A user can request a morning brief, summarize an upcoming meeting, check portfolio drift, examine exposures, prepare a report or flag a mandate breach in natural language. AI agents entering governed financial workflows need permission boundaries, traceable actions and reliable source data. d1g1t already organizes much of that underlying context inside the client’s wealth platform, which is more interesting than attaching a general chatbot to a collection of disconnected files.

d1g1t describes the MCP connection as governed. Public materials explain the intended workflows, although named customer deployments, pricing and detailed implementation specifications haven’t yet been released. Those details will show how quickly the product becomes part of daily advisor work and whether it helps expand existing contracts.

Competition, Regulation And Market Pressure

d1g1t is selling into a market where data quality, switching risk and regulatory responsibility matter as much as the interface. Its integrated platform gives the company several ways to win, but the field around it is getting more capable.

MCP is becoming a wealthtech connector, not a moat by itself. Canadian wealth platform OneVest launched its own MCP connection in April 2026, giving AI tools access to live wealth data, portfolios, pipeline information and tasks. OneVest’s continuing wealth-platform expansion makes it a particularly relevant Canadian comparison. d1g1t’s case will rest on the depth of its analytics, complex-portfolio support, integrated workflows and enterprise relationships, not simply on supporting an open protocol.

Large platforms are building native advisor assistants. Addepar’s Addison queries permission-aware portfolio data across a platform used by more than 1,400 firms, while Orion’s Denali AI connects portfolio, risk, CRM and planning information with audit controls. InvestCloud is automating meeting preparation and follow-up. These companies arrive with large installed bases and mature integrations. d1g1t doesn’t need to beat every platform everywhere, but it does need to make AI meaningfully better for the complex firms it already serves.

Good AI depends on clean, usable wealth data. Portfolio answers are only as reliable as the account, ownership, transaction and security data underneath them. PureFacts’ work with wealth platforms on data readiness reflects the same commercial reality: firms want automation, but first they need consistent data and clear operating definitions. d1g1t’s single-platform design can reduce some of that fragmentation. Client-specific data mapping and integration work won’t disappear.

Documents remain part of the advisor record. Holdings and performance data tell only part of a client’s story. Agreements, statements, correspondence and planning records also shape advice and compliance. FutureVault’s agentic document intelligence for advisors shows another route into the same workflow. d1g1t includes document management, but specialized providers can compete or partner around the edges of the platform.

The regulated firm still owns the decision. d1g1t is presented as a software provider, not an investment dealer or portfolio manager. Its clients remain responsible for suitability, supervision, books and records, privacy, cybersecurity and third-party oversight. Canadian cybersecurity guidance for registered firms makes vendor controls and incident readiness part of the buying decision. d1g1t’s SOC 2 Type II work is relevant assurance, though firms will still assess the current AI connection, permissions and data handling for their own use.

Enterprise growth can be lumpy. A core wealth platform can produce durable revenue once installed, but sales and implementation cycles are long. Each customer may require integrations, migration, testing and training before the contract reaches full use. d1g1t’s 96% revenue growth from 2021 through 2024 and recent PWL and Goodreid wins show progress; revenue, recurring-revenue mix, retention and implementation economics remain private.

What Makes d1g1t Different In Summer 2026

d1g1t has spent years doing the difficult part: organizing complex wealth data and placing the same analytics inside reporting, trading, billing, compliance and client work. Its current scale, recent customer wins and relationships with major Canadian financial institutions give the MCP launch a credible base. The product isn’t asking wealth firms to trust an AI tool with data that sits somewhere else. It connects the assistant to a platform already used to run the business. On the NCFA Financial Innovation Map, that puts d1g1t at a useful intersection of wealth infrastructure, portfolio data, AI interfaces and compliance technology.

What matters next is adoption. Named firms using the MCP server in live advisor workflows, measurable time savings and evidence of larger or stickier contracts would show that natural-language access is becoming a commercial feature rather than a useful demonstration. That is a fair question for every wealth platform now adding agents, not a problem unique to d1g1t.

The Company Intelligence Snapshot below follows the capital, customer relationships and product decisions that brought d1g1t to this point.

NCFA Company Intelligence Snapshot

d1g1t

Integrated portfolio, risk and advisor infrastructure for North American wealth firms
Last updated Jul 22, 2026

Company At A Glance

Founded2017 by Dr. Dan Rosen, Philippe Rouanet and Benoit Fleury
BaseToronto, Canada; serving firms across North America
StatusPrivate enterprise software company
FundingMore than C$25M disclosed across 2018 and 2021, followed by undisclosed 2023 and 2025 rounds
Growth96% revenue growth from 2021 through 2024; revenue amount remains private
ProductsPortfolio management, analytics, reporting, trading, billing, compliance, documents, client experience and MCP connectivity
TechnologyInstitutional performance and risk engine with integrated wealth workflows and API-driven connectivity
CustomersRIAs, portfolio managers, multi-family offices, broker-dealers, custodians and bank advisor networks
Operating PositionEnterprise wealth-management software provider; customer firms retain regulated advisory and dealer responsibilities
Business ModelEnterprise software contracts and implementation relationships; pricing and recurring-revenue mix are not public
Milestones
Select a milestone to follow how d1g1t developed from a portfolio analytics venture into AI-connected wealth infrastructure
Milestone 1

Domain Experts Build An Integrated Wealth Platform (2017–2018)

d1g1t was founded in Toronto by financial technology veterans Dr. Dan Rosen, Philippe Rouanet and Benoit Fleury. Incubated at the Fields Institute, the company set out to bring institutional portfolio and risk analytics into a single operating platform for wealth firms. By late 2018 it had four customers representing approximately C$13 billion and 5,000 households.

Company

d1g1tToronto wealth-management technology company

Stage

FoundationProduct and first enterprise customers

Capital

C$9M+Raised across two early rounds led by Purpose Financial

Markets

CanadaIndependent wealth firms and portfolio managers

Customers

4 FirmsApproximately C$13B and 5,000 households

Competition

One PlatformAnalytics and advisor work replace a fragmented stack

Additional Company Data

  • Rosen, Rouanet and Fleury brought experience from Algorithmics and R2 Financial Technologies
  • R2 Financial Technologies was acquired by S&P Capital IQ in 2012
  • The early product joined portfolio analytics with client and advisor workflows
  • Dan Rosen’s 2019 NCFA profile captured the initial four-customer operating base

Why This Milestone Matters

d1g1t began with a difficult but valuable wedge: institutional analytics adapted for wealth firms. The founders’ earlier enterprise systems gave the company credibility with buyers who would be trusting it with core portfolio data.

Frequently Asked Questions About d1g1t

What is d1g1t?
d1g1t is a Toronto enterprise wealth-management software company. Its platform combines portfolio and model management, performance and risk analytics, trading, reporting, billing, compliance, documents and client engagement for wealth firms.
Who founded d1g1t?
d1g1t was founded in 2017 by Dr. Dan Rosen, Philippe Rouanet and Benoit Fleury. The founders previously built financial risk and portfolio systems, including at Algorithmics and R2 Financial Technologies. The company was incubated at the Fields Institute in Toronto.
Is d1g1t a Canadian company?
Yes. d1g1t was founded and is headquartered in Toronto. It serves wealth-management firms across North America, including Canadian and U.S. advisors, multi-family offices, broker-dealers, custodians and bank advisor networks.
What does the d1g1t platform do?
The platform gives a wealth firm one environment for portfolio analytics, performance reporting, trading and rebalancing, model management, billing, compliance, document management and digital client service. It is designed for complex household structures, several custodians and portfolios containing public and alternative assets.
What is the d1g1t MCP server?
The d1g1t MCP server uses Model Context Protocol to connect approved capabilities and live data in the wealth platform to compatible AI tools such as Claude, ChatGPT and Microsoft Copilot. Advisors can use natural language to prepare meetings, review portfolios, generate reports and surface compliance issues. Named customer deployments and pricing have not yet been published.
How large is d1g1t?
d1g1t reports more than 90 wealth-management firms, C$200 billion in assets represented, 600,000 accounts, 250,000 clients, 2,000 advisors and 20,000 users on its platform. The assets belong to client firms and their investors; d1g1t is the software provider.
How much funding has d1g1t raised?
d1g1t had raised more than C$9 million across two rounds by November 2018, then announced a C$16 million round in 2021. It later disclosed a 2023 equity and venture-debt round and a 2025 strategic investment led by RBC without publishing the amounts. More than C$25 million is public, but a reliable total is not.
Does d1g1t disclose revenue?
d1g1t does not publish its revenue or profitability. Its 2025 Globe and Mail growth-company entry reported 96% revenue growth from 2021 through 2024, which shows the rate of growth across that period but not the company’s revenue amount.
Is d1g1t a registered investment dealer or advisor?
d1g1t is presented in its public materials as an enterprise software provider, not an investment dealer, portfolio manager or financial advisor. Its regulated customers remain responsible for advice, suitability, supervision, records, privacy and oversight of third-party technology.
Who uses d1g1t?
d1g1t serves registered investment advisors, portfolio managers, multi-family offices, broker-dealers, custodians and bank advisor networks. Publicly named relationships include RBC Wealth Management, PWL Capital, Goodreid Investment Counsel, CI Financial, National Bank, Purpose, Raymond James and FigTree Financial, although the scope of each relationship differs.
Who competes with d1g1t?
Competitors vary by firm and workflow. Integrated wealth platforms such as OneVest, Addepar, Orion and InvestCloud overlap with parts of d1g1t’s offer. Portfolio accounting, performance, CRM, trading, reporting, document and AI providers can also compete for individual modules. d1g1t’s pitch is that firms can run more of those jobs on one data and analytics foundation.
Is d1g1t publicly traded?
No. d1g1t is a privately held company. It does not publish the financial statements, market capitalization or continuous disclosure required of a public issuer.

Information notice: Private-company estimates are identified and attributed. Information may change after the stated update date. This content is provided for informational purposes only and does not constitute investment, financial or legal advice.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

How Ontario Finally Chose Canada’s Securities Passport

July 20, 2026 | NCFA Story Intelligence | Regulation And Policy, Capital Markets And Market Infrastructure, Competition And Market Structure

NCFA Story – How Ontario Finally Chose Canada’s Securities Passport

How Ontario Finally Chose Canada’s Securities Passport

On July 15, 2026, Ontario Finance Minister Peter Bethlenfalvy announced that Ontario had committed to joining Canada’s securities regulatory passport system. The federal Finance Department highlighted the commitment following the federal, provincial and territorial finance ministers’ meeting in Charlottetown, ending almost two decades as the only jurisdiction outside the system.

Finance ministers described the decision as regulatory harmonization, removal of an interprovincial trade barrier and progress toward one Canadian economy. It also resolved a contradiction Ontario had carried for years. The province repeatedly documented duplication, delay and disproportionate compliance costs while continuing to require a separate Ontario decision where most of Canada relied on one principal regulator.

Ontario stayed outside because passport was never the prize it wanted. The province backed a single national regulator, then a cooperative authority with a wider institutional redesign. The first model failed in court. The second survived legally but never opened.

Companies carried the cost of waiting. Equity crowdfunding showed what fragmentation did at company level. A financing model designed to connect issuers and investors online became a provincial compliance exercise that excluded supporters, consumed employee time and made some smaller raises uneconomical.

The story isn’t that Ontario suddenly discovered regulatory friction in 2026. Every alternative gradually weakened while the economic cost of maintaining a separate process became harder to defend.

Canada has one capital market but several securities authorities. Each province and territory retains its legislation, regulator and enforcement powers. The Canadian Securities Administrators develops common instruments, policies and filing systems so companies don’t face entirely different frameworks in every jurisdiction.

Coordination reduces differences without eliminating repeated work. A filing, interpretation, fee or local review may appear reasonable on its own. A company raising capital or operating nationally experiences the accumulated cost through the same legal budget, employees and management time needed to build the business.

Passport Offers A Practical National Compromise 2004

Passport gives one principal regulator the leading role in reviewing a company while participating jurisdictions rely on that decision. Provincial laws, commissions and enforcement remain in place. The system reduces repetition without creating one national regulator.

Most jurisdictions accept mutual reliance. The principal regulator can develop familiarity with the company, conduct the main review and issue a decision recognized elsewhere. The market gains a national operating mechanism without requiring provinces to surrender jurisdiction.

Ontario remains outside the compromise. An interface arrangement connects it to passport jurisdictions, but companies can still require a separate Ontario decision to access Canada’s largest capital market. The additional step remains while Ontario pursues a more ambitious institution.

Ontario Chooses Institutional Ambition Over Immediate Relief 2004 to 2011

Ontario backs a single federal regulator with authority over ordinary securities regulation. The larger proposal promises one statute and one institution, but companies continue paying for the existing provincial structure while governments test whether the new model is constitutional.

The federal proposal reaches far beyond passport. The Canadian Securities Act would place registration, prospectuses, disclosure, derivatives, civil remedies and market offences within one federal regime. Ontario supports a structure that could replace the provincial coordination model rather than simply improve it.

The constitutional loss leaves Ontario without its preferred destination. In 2011, the Supreme Court rejected the proposed Act because Parliament couldn’t assume ordinary provincial securities regulation through its general trade and commerce power. Ontario loses the national model but still doesn’t join passport.

The National Project Survives By Becoming Harder To Build 2011 to 2018

Governments redesign the national regulator around voluntary provincial participation. The compromise preserves provincial authority and survives in court, but implementation now depends on several governments aligning legislation, governance, funding and institutional transfers.

The cooperative model fixes the constitutional problem. Participating provinces would enact uniform laws administered by a common authority, while complementary federal legislation would address systemic risk and national criminal matters. Each legislature remains free to join, amend or leave.

Legal approval cannot assemble the institution. The Supreme Court approved the design in 2018, but major provinces remain outside and implementation dates recede. The first model fails because it takes too much provincial authority. The second preserves authority so carefully that no common regulator opens.

Companies Pay While Governments Keep Designing 2013 to 2021

Equity crowdfunding turns regulatory fragmentation into a company level loss. A financing model designed to reach investors online is divided by provincial exemptions, portal requirements and investor limits before the market can prove its economics.

Why Small Financings Feel Fixed Costs First

Legal advice, audited or reviewed statements, portal controls and continuing disclosure don’t decline in proportion to the amount raised. The smaller the financing, the larger the share consumed by fixed compliance costs.

Large institutions can spread those costs across more transactions and revenue. Young issuers and new platforms can’t. A requirement that appears manageable in isolation can make a modest financing uneconomical when combined with every other obligation.

Investor protection still requires disclosure, gatekeeping and enforcement. The policy question is whether those safeguards can be delivered without preventing legitimate companies from testing the market.

Several provincial rule books confront one digital market. Jurisdictions adopt different offering limits, investor caps, portal obligations, disclosures and filings. NCFA’s archive includes NCFA Canada Response to the Proposed Multilateral Instrument 45-108 Crowdfunding and Start-Up Prospectus Exemption.

The losses appear outside ordinary regulatory statistics. No portal initially registers under MI 45-108. More than 100 startups reportedly lose economical access to Ontario supporters, while one small firm assigns two employees for months to historical compliance work. The underlying record is available in March 1, 2019: NCFA Submission to the Ontario Securities Commission on Regulatory Burden. NI 45-110 harmonizes the market in 2021, but it cannot recover the financing, participation and productive work already lost.

Ontario Diagnoses A Burden It Cannot Remove Alone 2017 to 2019

Ontario turns from defending its framework to documenting its friction. The review confirms that repeated filings, unclear expectations and disproportionate requirements are not isolated complaints. It also exposes the limit of reform inside one provincial regulator.

The OSC confirms a pattern rather than a few difficult files. It receives 199 suggestions and identifies 34 underlying concerns, including repeated filings, difficult regulatory navigation, unclear service expectations, outdated technology and requirements that fall more heavily on smaller firms.

The response reveals the jurisdictional limit. The OSC announces 107 initiatives to improve service and remove avoidable work. Related NCFA coverage: OSC Makes Doing Business Easier for Ontario Market Participants. Ontario can improve its own processes, but it cannot eliminate national duplication while continuing to require a separate Ontario decision.

Ontario Modernizes Without Completing The Modernization 2020 to 2023

Ontario accepts that the problem is structural. The Capital Markets Modernization Taskforce proposes a wider reconstruction, but only part of the 74 recommendation program becomes reality.

The Taskforce reaches beyond procedural burden. Its recommendations cover governance, competition, capital formation, disclosure, innovation, enforcement and investor protection. NCFA’s formal response is NCFA Response to the Modernizing Ontario’s Capital Markets Consultation Taskforce.

Ontario divides authority inside the OSC while preserving duplication outside it. Capital formation and competition enter the mandate, the Chair and CEO roles are separated and adjudication is placed within a distinct tribunal. The proposed Capital Markets Act does not replace the existing statutes, and no public tracker supports a claim that the complete 74 recommendation program was implemented.

The Alternative Disappears While The Extra Process Remains 2021 to 2024

The cooperative regulator stops looking like a credible replacement. Ontario is left defending a separate process after the institution used to justify that position recedes.

The cooperative transition project winds down without transferring authority. Existing commissions remain responsible, the CSA continues coordinating national policy and passport keeps serving the jurisdictions that joined it. The practical system survives while the ambitious replacement recedes.

Ontario’s holdout loses its destination. The province is no longer choosing between passport and an approaching national regulator. It is choosing between passport and continued duplication with no replacement institution in sight. The original reason for waiting has disappeared, but companies still face the additional process.

Canada Breaks The Glass On Productivity 2024 to 2026

Regulatory duplication stops looking like a tolerable feature of federalism. It becomes labour, capital and company capacity an economy with weak investment and productivity can no longer afford to waste.

The Bank of Canada turns weak productivity into an emergency. In March 2024, Senior Deputy Governor Carolyn Rogers says it is time to break the glass. Weak investment, limited competition and lengthy or unpredictable approvals discourage companies from committing capital.

Ontario’s separate review becomes part of the economic diagnosis. Every repeated filing, legal opinion and approval cycle uses the same employees, financing and management attention needed for technology, customers and expansion. Related NCFA coverage: How Competition Powers Canada’s Economic Growth. Passport doesn’t remove scrutiny. It prevents several regulators from consuming company resources to deliver substantially the same protection.

The cost of duplication is no longer only regulatory. It is productive work that doesn’t happen.

Ontario Chooses The System That Outlasted The Alternatives July 15, 2026

Ontario doesn’t obtain the single national regulator it once sought. It accepts the working national compromise that remained in place while larger institutional projects stalled. Bethlenfalvy said participation would advance regulatory harmonization while maintaining investor protection and that he had directed the Ontario Securities Commission to build on discussions for Ontario’s full participation.

What Ontario Still Needs To Clarify

When will Ontario formally enter the passport system?

Which registration, prospectus and discretionary relief decisions will qualify?

Which duplicate filings, reviews and approvals will end?

How will active applications be treated during the transition?

What legislative, policy and systems changes will be required?

What service standards and performance measures will be published?

How will Ontario measure effects on smaller issuers and registrants?

How will investor protection and enforcement quality be preserved?

Ontario gives up duplication rather than jurisdiction. One principal regulator can conduct the main review while Ontario retains its legislation, commission, enforcement capability and voice in national policy. The province no longer has to choose between complete institutional control and surrendering its capital market.

The political commitment now faces an operating test. Industry advocates said passport can create a “single regulator experience through a principal regulator,” but harmonization in policy must also deliver harmonization in practice across legislation, policy and regulatory operations. Investment Executive reports the implementation direction and industry response. The strongest evidence of success will be fewer repeated reviews, lower compliance costs and faster interprovincial access while maintaining investor protection.

The Practical System Outlasts The Perfect One

Ontario’s decision closes a long loop in Canadian capital markets policy.

The province rejected passport because it wanted a more ambitious national regulator. The first version failed constitutionally. The cooperative version survived in court but never became operational. Ontario then documented extensive burden inside its own market, implemented selected modernization reforms and continued requiring a separate provincial process after the national alternative receded.

Equity crowdfunding showed what the delay meant for companies. The market was divided before it could mature nationally. Legal work, platform controls and continuing obligations consumed a large share of modest financings. Investors were excluded by geography. Employees were assigned to compliance work instead of customers and growth.

The productivity emergency raised the stakes. Canada cannot describe weak investment, limited competition and poor productivity as urgent while treating avoidable duplication as institutionally harmless. The same capital and employee time cannot be used twice.

Passport is not a single national regulator, and it does not eliminate provincial authority. Its value is practical. One qualified regulator does the principal work while the others rely on the result.

Ontario didn’t suddenly discover regulatory friction in 2026. It gradually accepted that preserving every layer of control carried an economic cost that internal reform and an unfinished national project had not removed.

The Commitment Is Only The Beginning

Ontario should publish an implementation schedule, identify the decisions covered by passport and report whether review periods, professional costs and duplicate regulatory interactions decline. Results for smaller firms should be reported separately because they carry fixed compliance costs most heavily.

Investor protection remains central. Reliance should remove repetition, not scrutiny. Principal regulators need the information, expertise and authority required to make decisions every participating jurisdiction can trust.

The larger question extends beyond securities regulation. Canada often pursues national economic outcomes through provincial institutions. Governments may continue debating the ideal architecture, but companies shouldn’t be required to finance avoidable friction while they wait.

Talking Point

When governments measure regulatory burden, should they count only compliance expenses that appear on company records, or also the financings, investment and productive work that never occur because the combined process makes them uneconomical?

Share this story → Explore related intelligence → Subscribe


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

CSA Cybersecurity Guidance for Registered Firms

July 20, 2026 | NCFA Resource | Cybersecurity And Fraud, Risk Compliance And Regtech, Capital Markets And Market Infrastructure

NCFA Resource – CSA Cybersecurity Guidance for Registered Firms

Policies, Training, Vendor Risk, And Incident Response

On July 15, 2026, the Canadian Securities Administrators published new cybersecurity guidance for registered dealers, advisers, and investment fund managers (Download the 12 page PDF report). CSA Staff Notice 33-322 combines findings from a focused review of 73 firms with practical expectations for policies, employee training, risk assessments, third party oversight, and incident response.

The notice is most useful as a compliance review tool. Firms can compare their written controls, operating practices, and supporting records against the deficiencies and effective practices identified by securities regulators. The guidance is particularly relevant for smaller and medium sized firms that may not have dedicated cybersecurity teams.

What It Does In Practice

The notice organizes cybersecurity readiness around five areas that regulators examined under section 11.1 of National Instrument 31-103:

  1. written cybersecurity policies and procedures
  2. employee cybersecurity training
  3. cybersecurity risk assessments and controls
  4. oversight of third party service providers
  5. written and tested incident response plans

The review found useful benchmarks. 8% of firms had no written cybersecurity policies, while 55% had policies that needed improvement. Twenty one per cent provided no employee cybersecurity training. Forty five per cent completed risk assessments that could have been stronger, and 12% had no documented assessment during the review period.

Third party oversight was one of the clearest weaknesses. All examined firms used service providers with access to systems or data, but 62% had no documentation or limited documentation supporting their cybersecurity oversight. The CSA expects firms to complete and document due diligence before onboarding a provider and repeat that review throughout the relationship.

The guidance identifies information firms should assess, including data storage, encryption, access controls, patch management, incident notification, subcontractors, operating jurisdictions, and shared responsibility in cloud environments. It also recommends maintaining a complete vendor register and reviewing current SOC 2 or similar reports where available.

Incident preparedness also receives detailed attention. Fifteen per cent of firms had no written incident response plan. Among firms with a plan, 53% needed stronger procedures and 63% should have tested their plans more regularly. The notice describes tabletop exercises and simulated attacks as practical ways to test whether people, processes, and technical controls work together during an incident.

Who Gets Value

The primary audience is firms registered as dealers, advisers, portfolio managers, investment fund managers, exempt market dealers, and restricted portfolio managers. Chief compliance officers, directors, technology leaders, privacy professionals, and internal audit teams can use the notice to organize a control review and identify missing documentation.

Boards and senior executives can also use it to test whether cybersecurity oversight is tied to clear responsibilities, regular reporting, and evidence that controls operate as intended. Written policies alone aren’t enough when actual practices, testing schedules, or access controls differ from the documented process.

Cybersecurity consultants, legal advisers, insurance providers, managed service providers, and software vendors can use the findings to better understand the records and evidence registered firms may need during a regulatory review.

Strengths And Limits

The notice is strong because it combines regulatory expectations with observed deficiencies, percentages, effective practices, and practical takeaways. It covers both governance and technical controls, including multifactor authentication, encryption, backups, access rights, patching, email filtering, endpoint protection, and activity logging.

It also makes documentation a central requirement. Firms should be able to show when policies were reviewed, who completed training, how risks were assessed, what vendor due diligence occurred, and when incident plans or backup recovery procedures were tested.

The guidance does not create a complete technical cybersecurity standard, and it doesn’t replace obligations under privacy, securities, corporate, or other applicable laws. Expectations also vary with the firm’s size, operating complexity, client information, service provider reliance, and exposure to cyber risk.

Firms should therefore use the notice as a regulatory gap assessment and evidence checklist, then supplement it with appropriate legal advice, technical standards, testing, and controls suited to their operations.

Key Resources

CSA Staff Notice 33-322 (cybersecurity examination findings and guidance for registered firms)

CSA Staff Notice 33-321 (foundational 2017 cybersecurity and social media guidance)

NIST Cybersecurity Framework (risk management structure for identifying, protecting, detecting, responding, and recovering)

CIS Critical Security Controls (prioritized technical and operational safeguards)

Wealthsimple Confirms Breach Impacting Clients (third party exposure and incident response)

Proposed Class Action Targets Equifax Access Controls (access governance and third party permissions)


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Neo Raises US$100M To Control Enterprise AI Agents

July 20, 2026 | NCFA Market Activity | Cybersecurity And Fraud, Artificial Intelligence And Data, Risk Compliance And Regtech

AI Image – Enterprise security team controlling AI agent access and actions

Former SentinelOne Leaders Build A Control Layer For Agentic Software

On July 20, 2026, Neo emerged from stealth with US$100 million in combined seed and Series A financing from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures and Merlin Ventures.

The Boston cybersecurity company was founded in 2025 by Nick Warner, Shlomi Salem and Eran Shirazi. Note that it's unrelated to Calgary based Neo Financial. Warner previously served as SentinelOne president and COO, Salem led detection engineering and threat research at SentinelOne, and Shirazi previously co-founded EasySend after leading vulnerability research in Israel’s Unit 8200.

Neo is building what it calls an agentic software control layer. The platform gives security teams an inventory of AI agents, AI enabled applications, plugins, extensions, MCP servers and traditional software that has gained agentic capabilities. It then maps permissions, attributes actions and applies policy before software reaches sensitive data or systems.

The company plans to use the financing to expand engineering and go to market operations. Neo hasn't disclosed revenue, customer counts, named customers, valuation or the allocation between its seed and Series A rounds.

Agents Can Operate Inside Trusted Permissions

Enterprise security was built around human users, known applications and recognizable data flows. AI agents can act differently. They may inherit a user’s permissions, call several tools, reach files and credentials, communicate with other agents and continue operating without a conventional interface.

That means risky activity may not even resemble a conventional intrusion. An agent can use valid credentials and approved applications while still exporting too much data, reading a secret, pushing code or initiating an action that exceeds the authority its operator intended to grant. NCFA’s analysis of AI agents gaining identity and wallet access shows how quickly this issue reaches financial APIs and real infrastructure.

Neo’s platform combines four functions. It finds AI software, checks what it can access, shows who or what is behind each action, and lets security teams allow, block or pause that action for approval.

Threat's aren't limited to deliberately malicious agents. ShadowLeak demonstrated how hidden instructions could manipulate an AI agent and expose private information without a user clicking a malicious link.

Its Neoverse knowledge base maps the capabilities, risks and behaviour of agentic software before it enters an enterprise environment. Neo says enforcement occurs natively at the endpoint, where the software can intercept tool calls, API access, credential reads and data transfers before the action is completed.

Competition Is Forming Around Agentic Security

Neo combines software inventory, posture intelligence, attribution and endpoint enforcement across agentic and traditional applications.

Check Point is developing a wider AI security control plane covering employee AI use, AI applications and agentic systems.

SailPoint is extending identity governance to AI agents and other non-human identities.

Existing endpoint security providers already control devices, files and processes, but may not yet map the permissions and chained actions occurring inside agentic software.

Cloud and application security companies can govern models, APIs and data access, creating a competitive question around whether customers will buy a separate agentic control layer or expect existing security platforms to absorb the function.

Financial Institutions Will Need Authority Maps For Agents

Banks and other regulated organizations will need more than a list of approved AI tools. They need to know which person authorized an agent, what credentials it inherited, which systems it can call, what information it can export and when human approval is mandatory.

Neo’s opportunity is to show who or what can access each system and enforce clear limits on what they can do. Its challenge is that endpoint, identity, cloud and network security companies are all pursuing parts of the same problem. Large institutions may prefer one more specialized control layer, or they may demand that existing suppliers add agent governance to products already deployed across the organization.

See:  AI Agents Enter Governed Financial Workflows

Financial institutions are adopting AI while remaining accountable for privacy, cybersecurity, third party risk, operational resilience and auditability. An agent that can access customer information, initiate a payment, change code or communicate externally will need authority limits that security, risk and compliance teams can understand.

Neo has the capital and founding team to compete early, but the category is still forming. Enterprise adoption, integration depth and the quality of its policy enforcement will matter more than the size of the launch financing.

Talking Point

Will enterprises buy a dedicated control layer for agentic software, or will endpoint, identity and cloud security providers absorb the function before the category becomes independent?

NCFA Company Intelligence Snapshot

Neo

Agentic software inventory, attribution and real time policy control for enterprise security teams
Last updated Jul 20, 2026

Company At A Glance

Founded2025 by Nick Warner, Shlomi Salem and Eran Shirazi
HeadquartersBoston, United States
StatusPrivate
Capital / FundingUS$100M across seed and Series A financing
InvestorsAndreessen Horowitz, Bessemer Venture Partners, Craft Ventures and Merlin Ventures
ProductsNeo platform and Neoverse agentic software knowledge base
CustomersEnterprise SecOps teams; named customers not publicly disclosed
Public LaunchJuly 20, 2026
DisclosureRevenue, valuation and round allocation not publicly disclosed
Milestones
Select a milestone to follow Neo’s development
Milestone 1

Founding Team Assembles (2025)

Nick Warner, Shlomi Salem and Eran Shirazi founded Neo in 2025 to build security controls for enterprise software gaining autonomous and agentic capabilities.

Company

Neo SecurityEnterprise cybersecurity company focused on agentic software

Stage

FormationExperienced operators assemble before the public launch

Capital

Early Institutional BackingSeed and Series A allocation not publicly disclosed

Markets

Enterprise SecurityAI driven software environments

Customers

SecOps TeamsLarge organizations adopting AI enabled software

Competition

Operator ExperienceFounders previously built and scaled enterprise security companies

Additional Company Data

  • Warner previously served as SentinelOne president and COO
  • Salem led detection engineering and threat research at SentinelOne
  • Shirazi previously co-founded EasySend
  • The company is unrelated to Canada’s Neo Financial

NCFA Perspective

Neo begins with founders who have built cybersecurity products and commercial organizations before. That lowers some execution risk, but it does not yet establish enterprise adoption.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

NCFA Weekly Fintech Intelligence Jul 11-17, 2026

July 11, 2026 | NCFA Fintech Whisperer | Risk Compliance And Regtech, Digital Assets Blockchain And Tokenization, Payments And Money Movement, Wealth Investing And Trading, Capital Markets Infrastructure And Funding, Competition And Market Structure, Digital Banking And BaaS, Lending Consumer Credit And BNPL, Regulation And Policy, Identity Privacy And Data Governance Cybersecurity Fraud And Financial Crime

Image Freepik, Data visualization signals

Image: Freepik

This live weekly NCFA intelligence page tracks financial technology developments that significantly affect how fintechs build, sell, raise capital, and operate under scrutiny. Coverage prioritizes Canada and includes global events that directly influence competitive conditions, market access, and execution realities across fintech sectors.  This page will be updated throughout the week with market movers in a live format and then each week we'll close the prior week's contents in prep for the upcoming week, and continue on a rolling basis.  (Missed prior week's Fintech Whisperer?  (December 6-12, 2025, December 13-19, 2025, January 1-9, 2026, January 10-16, 2026, January 17-23, 2026, January 24-30, 2026, January 31-February 6, 2026, February 7-13, 2026, February 14-20, 2026, February 21-27, 2026, February 28-March 6, 2026, March 7-13, 2026, March 14-20, 2026, March 21-27, 2026, March 28-April 3, 2026, April 4-10, 2026, April 11-17, 2026, April 18-24, 2026, April 25-May 1, 2026, May 2-8, 2026, May 9-15, 2026, May 16-22, 2026, May 23-29, 2026, May 30-June 5, 2026, June 6-12, 2026, June 13-19, 2026, June 20-26, 2026, June 27-July 3, 2026, July 4-July 10, 2026).

Weekly Fintech Market Intelligence Jul 11 - 17, 2026

Digital Banking And BaaS

Standard Chartered Runs 70% Of Infrastructure On Private Cloud

July 15, 2026, United Kingdom / Singapore / Global
  • Standard Chartered standardized its global infrastructure on a software defined private cloud using VMware Cloud Foundation to support critical banking services across 54 markets.
  • Approximately 70% of the bank’s global infrastructure footprint already operates on the new architecture.
  • The platform embeds zero trust security into the infrastructure layer and reduces infrastructure deployment time from weeks to one day.

Private cloud remains a production architecture for regulated banks that need consistent control across countries and critical workloads. The 70% deployment gives other banks a concrete benchmark for weighing resilience, security, workload portability and regulatory oversight when deciding which systems belong in private environments and which can run with hyperscalers.

Capital Markets Infrastructure And Funding

BitGo Adds Custody And T+0 Settlement For Onchain Sovereign Bond

July 17, 2026, Marshall Islands / United States / Global
  • BitGo Bank & Trust will provide qualified custody and off exchange settlement for USDM1, a dollar denominated sovereign bond issued natively onchain by the Republic of the Marshall Islands.
  • USDM1 is structured under New York law, backed 1:1 by U.S. Treasuries and available to institutions on Stellar, Ethereum and Solana.
  • Eligible clients can deploy USDM1 to connected venues around the clock with T+0 settlement without transferring the asset onto an exchange.

The structure places sovereign issuance, Treasury backing, regulated custody and continuous settlement inside one institutional collateral workflow. It gives banks, dealers and custodians a concrete test of how tokenized sovereign instruments could support secured finance while reducing intraday exposure and prefunding requirements.

CSA Opens Review Of Public Company Regulation

July 16, 2026, Canada
  • CSA Consultation Paper 51-406 opens a 120 day review of how Canadian public companies are regulated, with comments accepted until November 13, 2026.
  • The consultation asks whether venture and non-venture issuer status should be determined differently to support more proportionate requirements.
  • The CSA is considering whether some venture issuers should receive relief from parts of International Financial Reporting Standards.
  • The paper also examines private placement hold periods, material change reporting and how U.S. reforms to reporting, disclosure and capital raising should influence Canada.
  • More than 10% of eligible companies have adopted the CSA’s voluntary semi-annual reporting framework, while recent Listed Issuer Financing Exemption changes have generated significant financing activity.

The review extends beyond one exemption or reporting rule. It connects the semi-annual reporting pilot and higher LIFE financing limits to the cost of staying public, the information investors receive and Canada’s ability to compete for issuers and capital.

Ontario Commits To Canada’s Securities Passport System

July 15, 2026, Canada
  • Ontario committed to join Canada’s national securities regulatory passport system following discussions among federal, provincial and territorial finance ministers.
  • Under the passport system, a market participant obtains a decision from its principal regulator that applies across participating jurisdictions under harmonized laws.
  • Ontario has been the only jurisdiction outside the system and currently uses an interface that can require a separate Ontario Securities Commission decision; implementation timing has not been announced.

Ontario’s commitment could remove a longstanding layer of duplicated review for issuers and registrants operating nationally. The operational test is whether full participation reduces filing cost and approval time without weakening investor protection. It also delivers the coordinated model sought in earlier calls for Ontario to adopt passport.

Grove And Galaxy Create US$500 Million Lending Facility

July 15, 2026, United States / Global
  • Grove committed a US$500 million warehouse facility to finance institutional loans originated and serviced by Galaxy Digital.
  • The senior secured loans may use BTC and ETH as collateral, including staked ETH, with assets held by Anchorage Digital and BitGo.
  • The facility uses USDS capital, defined eligibility requirements, concentration limits and continuous loan to value monitoring through independent price feeds.

The facility brings a familiar credit structure into institutional digital asset lending at substantial scale. It places onchain liquidity closer to loan origination and gives the market a clearer test of how stablecoin capital, qualified custody and crypto collateral can support structured credit.

Competition And Market Structure

Stripe And Advent Submit Reported US$53 Billion PayPal Bid

July 15, 2026, United States / Global
  • Reuters reported that Stripe and Advent International submitted a joint offer of US$60.50 per share for PayPal, valuing the company at more than US$53 billion.
  • The proposal is backed by approximately US$50 billion in committed bank financing and would give Stripe and Advent equal ownership of PayPal.
  • PayPal, Stripe and Advent declined to comment, PayPal had not responded to the proposal when it was reported, and there is no certainty that an agreement will result.

A combined Stripe and PayPal would connect merchant processing, consumer checkout, Venmo and stablecoin distribution under one ownership structure. Even without a transaction, the bid tests whether control of merchant acceptance and consumer distribution will become a defining advantage across wallets, agentic commerce and digital payments.

SME Finance And Business Banking

ConnectOne Bank Builds Commercial Lending Agents On nCino

July 14, 2026, United States
  • ConnectOne Bank is building multiple commercial lending agents on nCino’s Agentic Operating System.
  • The deployment targets frontline efficiency across commercial lending workflows rather than one isolated task.
  • nCino positions the system as an operating layer for agents working across lending data, processes and institutional controls.

Commercial lending agents are entering regulated bank workflows at the operating system level. Their value will depend on whether banks can reduce manual work while keeping credit judgment, accountability and exception handling under institutional control.

Wealth Investing And Trading

Blockchain.com Adds Polymarket Prediction Markets

July 14, 2026, Global
  • Blockchain.com partnered with Polymarket to add prediction market access inside its app for users in eligible markets.
  • Users will be able to use assets already held in their Blockchain.com accounts to open and manage event positions without a separate wallet connection or deposit process.
  • Blockchain.com said it serves more than 43 million verified users across more than 70 jurisdictions, giving Polymarket a large new distribution channel.

Prediction markets are becoming a standard feature inside crypto trading apps. Wider distribution could increase participation and liquidity, while raising sharper questions about eligibility, market integrity and the trust controls surrounding prediction markets.

Payments And Money Movement

Alipay+ Connects Global Wallets To Argentina’s National QR Network

July 17, 2026, Argentina / Global
  • Alipay+ integrated with Argentina’s Transferencias 3.0 national QR payment network through Latin American payment technology provider PVS.
  • International travellers using participating Alipay+ wallets will be able to scan the QR codes already displayed by millions of Argentine merchants.
  • Alipay+ connects more than 50 wallets and banking apps representing 2 billion user accounts with 150 million merchants globally, with the Argentine service launching in phases.

Argentina is turning a domestic interoperable QR standard into an international acceptance layer without requiring merchants to replace their checkout technology. It gives Canadian operators a useful comparator as Canada opens payment infrastructure to more PSPs and credit unions while developing instant payment access, shared acceptance and stronger operating controls.

Thredd Joins Visa Agentic Ready Programme

July 15, 2026, Europe
  • Thredd joined Visa’s Agentic Ready programme to help issuers support payments initiated by AI agents.
  • The processor said its platform provides tokenisation, authentication and fraud capabilities needed for agent initiated transactions.
  • Zilch is among the first issuers using the platform to support agent initiated payments in Europe.

Agentic commerce is reaching the issuer processing layer. Delegated authority, transaction controls, authentication and dispute handling are becoming core payment functions rather than responsibilities left only to agents and merchants.

Stable Launches StablePay On USDT Payment Rails

July 15, 2026, Global
  • Stable launched StablePay, a mobile app for instant USDT transfers using phone numbers, email addresses or QR codes.
  • The self custody service removes the need for users to manage blockchain accounts, gas fees or separate wallet connections.
  • Stable said the app is already supporting peer payments, cross border remittances and international payroll, with a built in feature for earning yield on USDT.

StablePay packages payment, custody and yield inside one consumer experience. Its traction will show whether simplified stablecoin products can win users beyond crypto markets while meeting the compliance expectations attached to global payments and yield.

Emirates NBD Launches Real Time USD Payments On Partior

July 14, 2026, United Arab Emirates / Global
  • Emirates NBD went live on Partior’s multicurrency blockchain clearing and settlement network.
  • The bank completed a live USD transaction with J.P. Morgan acting as settlement bank and beneficiary bank.
  • Corporate and institutional clients can now send real time USD payments to beneficiary accounts held at J.P. Morgan, with additional currencies and bank connections planned.

This is live bank settlement rather than another proof of concept. Partior now has a regional deployment that can test whether continuous liquidity, faster finality and programmable treasury services improve cross border banking at production scale.

ECB Selects 36 Payment Providers For Digital Euro Pilot

July 14, 2026, European Union
  • The European Central Bank selected 36 payment service providers from more than 50 applicants to participate in the digital euro pilot.
  • The 12 month pilot is scheduled to begin during the second half of 2027 using a beta version of the digital euro across the ECB and 19 national central banks.
  • The programme will test online and offline person to person payments, merchant acceptance, software point of sale and ecommerce transactions with banks, payment firms and selected merchants.

The digital euro has entered a new implementation stage. Attention now turns from policy design toward operational readiness, participant integration and whether the pilot demonstrates that public digital money can work alongside existing payment networks.

JCB And Circle Explore Stablecoin Merchant Payments

July 14, 2026, Japan
  • JCB and Circle signed a memorandum of understanding to explore USDC payments across JCB's merchant network.
  • The collaboration will examine cross border payments, merchant acceptance and settlement using stablecoin infrastructure.
  • The initiative builds on JCB's existing digital payment work with Japanese banking and technology partners.

Stablecoin adoption is expanding beyond crypto native platforms into established payment networks. The next phase will depend on merchant acceptance, operational integration and regulatory treatment across major consumer payment markets.

SCB And Citi Launch Near Real Time Cross Border USD Payments

July 11, 2026, Thailand / Global
  • Siam Commercial Bank became the first financial institution client to go live with Citi's integrated 24/7 USD Clearing and Citi Token Services solution.
  • The service enables near real time cross border USD payments at any time of day using tokenized deposits within Citi's regulated banking network.
  • The first live transaction transferred U.S. dollars between Citi in London and Siam Commercial Bank in Thailand during the U.S. holiday weekend, demonstrating continuous cross border payment capability.

The industry is beginning to demonstrate how tokenized deposits can support continuous cross border payments inside regulated banking networks. Alongside Swift’s bank ledger work with RBC and TD, the next measure is how quickly live services spread across institutions and payment corridors.

Cybersecurity Fraud And Financial Crime

FIS Tests Frontier AI Across Critical Financial Software

July 16, 2026, United States / Global
  • FIS joined Anthropic’s Project Glasswing and is actively testing the Mythos 5 frontier model against its own systems.
  • FIS operates software that clears payments, transfers money and runs core banking for thousands of financial institutions worldwide.
  • The controlled security initiative is separate from FIS’s commercial AI agent partnership with Anthropic and focuses on identifying vulnerabilities in critical software infrastructure.

Frontier AI is entering the security testing layer of widely shared banking and payment infrastructure. The initiative extends AI security across mixed banking systems into controlled testing of critical financial software. Banks and infrastructure providers will need clear controls for model access, finding validation, remediation ownership and disclosure as advanced models identify vulnerabilities faster than conventional security teams can process them.

CSA Sets Updated Cybersecurity Expectations For Registered Firms

July 15, 2026, Canada
  • CSA Staff Notice 33-322 reports findings from a focused compliance examination of 73 registered firms.
  • The review examined policies, employee training, risk assessments, controls, third party oversight and incident response planning.
  • CSA staff identified gaps across the firms reviewed and issued practical guidance intended to scale across small, medium and large registrants.

Cybersecurity expectations are becoming more concrete through examination findings rather than high level principles alone. Registered firms now have a clearer basis for testing governance, third party controls and incident readiness before the next compliance review.

INETCO Adds Agentic AI Fraud Investigation

July 14, 2026, Canada / Global
  • INETCO added agentic AI investigation capabilities to BullzAI for banks, payment processors and other financial institutions.
  • The agents collate transaction data, triage alerts, prioritize high risk cases and provide explainable scores and recommendations for fraud teams.
  • The capability uses a proprietary model deployed within the customer environment and improves through supervised human feedback.

Fraud operations are beginning to automate the investigation layer, not only transaction detection. The practical value will come from cutting case backlogs while preserving analyst control, explainability and sensitive payment data inside the institution.

ENISA Gives SMEs A Cyber Resilience Act Readiness Model

July 13, 2026, European Union
  • ENISA released a maturity model and downloadable assessment tool for SMEs that manufacture or supply products with digital elements covered by the Cyber Resilience Act.
  • The model evaluates governance, security by design, risk management, vulnerability management, product lifecycle practices and cybersecurity skills.
  • An accompanying survey of 194 organizations across 31 countries found that 66% knew about the Act, while practical understanding, incident response and product lifecycle readiness remained limited.

Canadian fintech and software vendors selling covered products into Europe need operational evidence behind their compliance claims. The model gives customers and partners a common way to examine product security maturity as the Act’s vulnerability reporting requirements begin in September 2026 and its main obligations approach.

Risk Compliance And Regtech

FATF Finds Crypto Travel Rule Enforcement Still Lags

July 16, 2026, Global
  • FATF found that 83% of surveyed jurisdictions, 91 of 109, had passed legislation implementing the Travel Rule, up from 73% in 2025.
  • However, 55 of those 91 jurisdictions had not issued findings or directives or taken Travel Rule related supervisory or enforcement action.
  • FATF reported that a Cambodia based financial services conglomerate laundered at least US$4 billion between August 2021 and January 2025, including at least US$37 million linked to North Korean cyber thefts.

Travel Rule adoption is advancing faster than supervision and enforcement. Crypto firms, banks and compliance providers need stronger counterparty screening, interoperable originator and beneficiary data, offshore VASP controls, and escalation procedures for stablecoins and unhosted wallet exposure.

FINTRAC Updates Canadian Controls For FATF Country Risks

July 15, 2026, Canada / Global
  • FINTRAC updated its advisory for Canadian reporting entities following the Financial Action Task Force’s June plenary.
  • Bosnia and Herzegovina and Iraq were added to the FATF list of jurisdictions under increased monitoring, while Algeria and Namibia were removed after completing their action plans.
  • Canadian reporting entities must account for connections to monitored jurisdictions when assessing geographic risk, applying controls and determining whether suspicious transaction reports are required.
  • Transactions connected to the Democratic People’s Republic of Korea and Iran remain subject to specific Canadian directives covering high risk treatment, identity verification, source of funds or virtual currency, beneficial ownership, recordkeeping and sanctions evasion controls.
  • The advisory also preserves enhanced requirements and reporting considerations for Myanmar, Russia, Afghanistan, Islamic State controlled areas and transactions connected to the Middle East.

The update requires banks, fintechs, payment companies, money services businesses and virtual asset firms to review country risk classifications, transaction monitoring rules and correspondent banking controls. Grey list status should inform a risk based assessment rather than automatic rejection of every transaction, while Canadian ministerial directives create specific mandatory treatment for designated jurisdictions.

UK Starts Direct Oversight Of Critical Technology Providers

July 13, 2026, United Kingdom
  • The Bank of England, PRA and FCA began joint oversight of the first Critical Third Parties designated by HM Treasury.
  • The regime covers Amazon Web Services, Google Cloud, Microsoft and Oracle services that support the UK financial system.
  • Designated providers must manage risks to critical services, communicate with regulators during major incidents and support system level resilience.

Direct supervision of major technology providers changes where operational resilience responsibility sits. Financial firms still own their outsourcing risk, but the largest shared dependencies now face regulatory scrutiny at source.

Digital Assets Blockchain And Tokenization

AMINA Embeds Mesh Verified Digital Asset Deposits

July 16, 2026, Switzerland / Global
  • FINMA regulated AMINA Bank integrated Mesh’s verified deposit technology directly into its online banking platform.
  • Clients will be able to select a wallet provider, verify ownership and deposit stablecoins or other digital assets through connections spanning more than 300 wallets and providers.
  • The deposit capability will soon become available to AMINA clients, with withdrawals, payouts and simplified wallet verification during onboarding planned as later additions.

Regulated crypto banking still breaks at the point where customers must prove ownership of external wallets. Embedding verification into deposit authorization can reduce manual address checks while preserving compliance controls. Banks considering similar connections will need clear responsibility for wallet screening, transaction monitoring, sanctions controls and failed transfers.

Lending Consumer Credit And BNPL

UK Buy Now Pay Later Rules Take Effect

July 15, 2026, United Kingdom
  • Interest free Buy Now Pay Later products are now regulated by the Financial Conduct Authority, covering providers including Klarna, PayPal and Clearpay.
  • Providers must conduct affordability checks before extending credit and give consumers clearer information during checkout.
  • Consumers gain enforceable refund protections for faulty goods, access to the Financial Ombudsman Service and support before debt collection when experiencing financial difficulty.

BNPL now operates as supervised consumer credit across the customer journey. Providers serving the UK need affordability, disclosure, complaints, refunds and collections controls that work inside merchant checkout flows. Canadian policymakers and lenders have a live comparator for testing whether product specific safeguards can protect consumers while preserving short term payment flexibility.

Regulation And Policy

UK Proposes Unified Rules For Tokenised And Agentic Payments

July 14, 2026, United Kingdom
  • HM Treasury opened a 12 week consultation containing 42 questions on payment services and electronic money regulation, with responses due October 6, 2026.
  • The proposals create common regulated activities for traditional and tokenised payments, bring certain stablecoins into the payments perimeter and require firms to obtain permission for tokenised payment services.
  • The consultation addresses agentic payment consent, authentication and liability alongside variable recurring payment access, commercial Open Banking pricing and expanded FCA supervision.

One consultation connects digital money, AI agents and Open Banking to the same operating rulebook. Payment firms need to test which permissions, safeguarding models, access rights and liability controls their products would require. Canadian regulators can compare this integrated approach with separate domestic work on stablecoins, consumer driven banking and Real Time Rail implementation.

Identity Privacy And Data Governance

Austrian Court Treats Inferred Political Profiles As Sensitive Data

July 16, 2026, Austria / European Union
  • Austria’s Administrative Court confirmed that statistically calculated political affinities are special categories of personal data protected under Article 9 of the GDPR.
  • The profiles covered approximately 2.2 million people and were stored and partly sold to third parties without consent or another applicable exception.
  • The court set the administrative fine at €13 million and confirmed that group wide annual revenue could be considered when determining the penalty.

The decision extends sensitive data protection beyond information people expressly provide to conclusions generated about them. Fintechs using behavioural analytics, customer segmentation, alternative data or AI models must consider whether inferred attributes can create heightened privacy obligations even when the underlying inputs appear ordinary.

Dutch Privacy Regulator Sets GDPR Guardrails For Generative AI

July 13, 2026, Netherlands / European Union
  • The Dutch Data Protection Authority published GDPR guidance for organizations developing generative AI models or taking responsibility for putting them into use.
  • The guidance addresses lawful grounds, indirect collection, training data and how personal information is managed, cleaned, enriched, retained and protected.
  • A separate implementation checklist asks organizations purchasing or using generative AI to first determine whether they can achieve their purpose without processing personal information.

The guidance brings privacy decisions into AI procurement and development before deployment. Financial institutions and fintechs using customer information with generative AI will need to justify why personal data is necessary, identify their legal role and preserve evidence across training, vendor selection, implementation and ongoing use.

Faster Finance Needs Faster Control

This week’s developments share one operating pattern. BitGo and Galaxy place tokenized assets inside collateral and lending. Alipay+, Partior and Citi connect domestic payment access with international distribution. FIS, the CSA and FATF reinforce the control layer required to run these systems safely at speed. For Canadian operators, the strategic question is which layer they truly control. Distribution without settlement access creates dependency. Automation without governance creates liability. Tokenization without custody, liquidity and legal certainty stays experimental. Durable businesses will own a useful layer, meet its control burden and connect cleanly to the rest.

NCFA offers various curated resources to help founders and investors stay current on developments that impact fintech markets. Get the weekly Whisperer and related market intelligence through NCFA's newsletter, view the latest fintech insights, industry research, or launch into emerging financial innovation opportunities.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

FCA Finfluencer Crackdown Meets Canadian Guidance

July 17, 2026 | NCFA Insight | Regulation And Policy, Wealth Investing And Trading, Risk Compliance And Regtech

AI Image – Finfluencer regulation and social media investment enforcement

FCA Finfluencer Enforcement And Canada’s Regulatory Position

On July 9, 2026, the UK Financial Conduct Authority reported the results of its finfluencer enforcement campaign. A coordinated week of action involving 9 international regulators produced 3 arrests, 6 criminal proceedings, 11 warning or cease and desist letters, 50 warning alerts and 650 social media takedown requests.

Canadian regulators weren’t watching from the sidelines. The Alberta Securities Commission, Autorité des marchés financiers, British Columbia Securities Commission and Ontario Securities Commission participated in the June 2025 operation. Earlier analysis asked whether finfluencers were facing a crackdown or clearer regulation.

The FCA’s latest figures show that enforcement has now become repeatable. Investigators can identify illegal content, connect creators to products and firms, request platform removals, issue public warnings and escalate selected cases into criminal proceedings.

The scale of the FCA’s supporting operation is just as relevant. During 2025, it issued 2,329 warnings about unauthorized or potentially fraudulent firms, compared with 2,240 in 2024. It secured 17 criminal convictions involving fraud, insider dealing, money laundering and data protection offences. Twelve people paid a combined £1.77 million in market abuse fines for market abuse.

Technology is improving that capacity. FCA automation reduced the handling time for simpler supervisory cases from as much as 4 hours to about 6 minutes on average. That doesn’t automate consequential decisions. It clears routine work so investigators can spend more time on repeat promoters, hidden compensation, unauthorized firms and cross border distribution.

What The Enforcement Data Reveals

The 650 takedown requests are the most commercially relevant number. Arrests attract attention, but removing hundreds of accounts and posts targets distribution. Illegal promotions lose value when creators can’t reach an audience, acquire leads or direct followers to a trading platform.

The FCA can examine multiple parties within one campaign. A creator may publish the content, a financial firm may pay for it, an affiliate network may track referrals and a platform may distribute it. The underlying product can then lead investigators to an unauthorized operator or regulated firm with weak approval controls.

Criminal proceedings provide the upper end of that response. The FCA accused 3 people charged after the 2025 operation of promoting high risk contracts for difference without authorization. Each faces an allegation of communicating an invitation to engage in investment activity contrary to section 21 of the UK Financial Services and Markets Act.

The April 2026 second global week of action showed how quickly the system had expanded. Seventeen regulators participated. The FCA requested the removal of 120 accounts and identified 1,267 illegal financial advertisements that reached at least 2,338,372 accounts. People or firms already listed on its Warning List accounted for 66% of those advertisements.

That 66% figure exposes a persistent enforcement problem. Many promoters aren’t unknown actors. They continue publishing after regulators have already identified the related firm, person or offer. Effective supervision therefore depends on account removal, repeat offender monitoring and platform cooperation, not warnings alone.

The FCA also secured a guilty plea, began criminal proceedings against 2 more people, issued 34 new warning alerts and updated 14 existing warnings during the April operation. Coordination now combines prosecution, surveillance, education and content removal rather than treating each promotion as an isolated post.

Canada Has Rules, Research And Active Cases

Canada’s legal foundation is already in place. In December 2025, the CSA and CIRO published Staff Notice 31-369, which explains how securities law applies to finfluencers, issuers and registered firms. The practical requirements appear in Canada’s finfluencer guidance.

The guidance doesn’t create a separate licence for creators. It examines the activity itself. A creator may need registration when they provide investment advice as a business, facilitates trades, arranges referrals or connects paid subscribers to copy trading. General market commentary may qualify for an exemption, but creators must still disclose financial interests and other conflicts clearly and on time.

Compensation also changes the compliance analysis. Cash payments, securities, affiliate income, referral fees and free products can establish a commercial relationship. A disclaimer such as “not financial advice” doesn’t cancel the substance of a recommendation, the creator’s compensation or the transaction being encouraged.

Responsibility extends beyond the creator. Registered firms must supervise people acting on their behalf, address referral arrangements, retain records and review relevant communications. Issuers remain responsible for paid investor relations activity and promotional claims made for their benefit. The joint staff notice applies the same principles to AI generated content and digital personas.

The investor evidence explains why regulators are paying attention. An OSC study of 655 Canadian retail investors found that 35% had made a financial decision based on finfluencer content. Those who acted on it were 12.2 times more likely to report being scammed on social media and 2.3 times more likely to have experienced a significant investment loss.

The OSC also ran a simulated investment experiment involving 1,465 Canadians. After viewing a promotional social media post, 38% bought the featured asset. Only 8% of the control group did the same. The full findings and behavioural differences appear in the finfluencer effect on Canadian investors.

Canada has also produced direct enforcement results. In September 2025, the Alberta Securities Commission imposed sanctions on James Domenic Floreani and Jayconomics Inc. for promoting 4 issuers through YouTube, X and Patreon without clearly disclosing that they published the content on behalf of those issuers.

The respondents received a $30,000 administrative penalty, $10,185.10 in costs and 2 year restrictions covering investor relations activity, public securities promotion and securities or derivatives advice.

British Columbia added a preventive layer during the April 2026 operation. The BCSC issued 14 compliance letters to YouTubers and other promoters who had discussed publicly traded B.C. companies. It also referred to an active proceeding alleging that sponsored issuer promotions weren’t disclosed clearly.

How Canadian Enforcement Could Develop

The FCA operates a national financial promotions regime and can report one consolidated set of arrests, warnings, takedowns and prosecutions. Provincial and territorial authorities administer Canadian securities regulation, while CIRO supervises investment dealers, mutual fund dealers and regulated marketplaces.

Canadian action may therefore appear as several provincial cases, coordinated review periods, issuer investigations, warning letters and firm supervision rather than one national enforcement tally. That can make the activity look smaller even when regulators review the same creators, platforms and promotional networks.

The operating implications are already clear.

  • Issuers need to know who promotes their securities and how they compensate those people
  • Dealers and fintech platforms need approval, monitoring and record keeping controls for creator campaigns
  • Affiliate arrangements require the same scrutiny as traditional referrals
  • Creators need to separate education from recommendations and disclose commercial interests where followers can actually see them

Platforms are also becoming part of the enforcement process. When regulators can connect warnings to hundreds of removal requests, account access becomes a compliance dependency. Firms using social media for distribution can’t treat the creator’s channel as an independent marketing asset beyond their control.

Canada doesn’t need to duplicate the FCA’s structure to produce comparable enforcement. Its regulators are already participating in the same international operations, applying national guidance and using provincial proceedings. The open question is whether those actions will become visible as a coordinated Canadian program or remain distributed across separate regulators and cases.

Talking Point

Will Canada’s finfluencer guidance support coordinated enforcement across provinces, platforms and firms, or will separate cases continue defining the compliance boundary?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA engages with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter