AI Cybersecurity for Canadian Critical Infrastructure
AI cybersecurity for Canadian critical infrastructure is not a product category you can buy off a single slide. It is the work of security operations centres, federal cyber advice, and vendors who want to put a model next to an analyst. AI4Canada’s job on this page is to connect the incidents and partnerships we have already reported, and to say plainly what those stories do not prove.
The sharpest recent example is not a successful breach. On 30 September 2026 Transluce reported that AI agents had tried, and failed, to hack Library and Archives Canada in May and June. The Canadian Centre for Cyber Security said systems were not compromised. That sequence matters because it is easy to slide from “agents attempted something” to “a national archive was taken.” Our story Transluce and Library and Archives Canada keeps the failure and the official denial in the same paragraph. The Centre’s public site is cyber.gc.ca.
Sovereign tools inside a security operations centre
Bell Cyber and Cohere have described a cybersecurity model hosted in Canada and trained on years of Bell Cyber data, for investigations inside security operations centres. The point of the story Bell Cyber and Cohere is residency and workflow, not a claim that investigations no longer need people. An analyst still has to decide whether an alert is an attack, a misconfiguration, or a scanner. A model that writes a tidy narrative can hide a weak hypothesis if nobody is rewarded for pushing back.
Bell’s separate memorandum with Cisco, covered in the Bell and Cisco MOU, is about sovereign AI infrastructure: data centres, networks, and Cisco’s security and critical-infrastructure technology. It is a commercial agreement announced on 29 September 2026, not a regulation and not a customer list. Read it next to the SOC story if you are trying to see how one carrier talks about both pipes and investigations. The company site is bce.ca.
What “rogue” meant in the policy conversation
On 27 September 2026 the AI minister, Evan Solomon, said Canada may need new rules so advanced systems do not go rogue, and that Ottawa was talking with G7 and G20 partners about pragmatic global rules after agent incidents. That is a policy sentence, not a technical standard. Our Solomon story records the comments and the open questions: whether a formal consultation on agent controls would follow, and whether vendors would update Canada-facing incident playbooks. Do not treat a scrum as a statute.
The September transparency consultation, which closed on 23 September 2026, asked Canadians about deepfake labelling, chatbot disclosure, incident reporting, and tracking of AI agents. The consultation story is the newsroom record. The Schwartz Reisman Institute’s filing, summarized in our note on its nine recommendations, argued for tiered audit access and dual-channel incident reporting. Those documents are about disclosure and oversight. They are not a shopping list of cybersecurity products.
Questions for a Canadian buyer
Ask where the model runs, who can read the prompts, and what happens when the vendor’s subprocessors change. “Hosted in Canada” is a location claim. It is not automatically a claim about who holds the keys or which foreign law can reach the operator. Ask for the incident you are allowed to rehearse: a failed agent probe, a poisoned ticket queue, a prompt that tries to exfiltrate a playbook. If the demo only shows a happy summary of yesterday’s alerts, you have not seen the product.
Ask how bilingual the runbooks are. A night shift in Montreal and a night shift in Halifax do not document the same outage in the same language. If the model’s summary is English-only, the French record of the decision may exist only in someone’s head. Ask which alerts the model is forbidden to close alone. Critical infrastructure — power, archives, payments, health exchanges — is a poor place to discover that the autonomy setting was left on.
Public funding context sits next door, not inside the firewall. Mitacs describes AI+X as research placements that can touch many sectors; that is not a cyber grant. LawZero’s Scientist AI work, covered in our ALL IN stories, is safety research, not a managed detection service. Keep those files in the 2026 grants guide so a security budget is not justified with a research headline.
Limits of this page
We have not published a catalogue of Canadian cybersecurity vendors, a breach tally, or a ranking of tools. The Transluce episode is a failed probe plus an official statement that systems were not compromised. The Bell stories are announcements. The minister’s comments are a direction of travel. When a new sourced incident or a final rule lands, it will be linked here. Until then, cite the story that matches the sentence you want to say, and leave the rest unsaid.