AI for All Needs Security for All: Why Canada’s AI Strategy Must Treat Critical Infrastructure as a Core Test Case

Published On: September 2026Categories: 2026 Editorial Series, Canada's New AI Strategy, Editorials

Author(s):

David Medcalfe

494210414_1721064748484527_5199402618522760821_n
Disclaimer: The French version of this text has been auto-translated and has not been approved by the author.

Canada’s new National Artificial Intelligence (AI) Strategy, AI for All, is ambitious in the right ways. It seeks to accelerate AI adoption, build skills, strengthen Canada’s AI foundations, support Canadian firms, and foster trust and confidence in AI across the economy and public services (Innovation, Science and Economic Development Canada [ISED], 2026). This reflects an important reality: AI is no longer a niche research field, it is becoming part of Canada’s economic and institutional foundation. 

Yet the strategy’s success will not be measured only by how quickly Canadian organizations adopt AI. It will also be measured by whether Canada can deploy AI securely and with accountability in the systems on which Canadians depend. 

That requires treating critical infrastructure as a central test case for trustworthy AI. 

AI is increasingly being integrated into systems and services where it may influence resource allocation, anomaly detection, maintenance, routing, access control, fraud detection, and operational response. As systems become more connected and increasingly agentic, the consequences of error, misuse, or compromise become less contained. 

A flawed AI-enabled system in a low-stakes consumer application may frustrate a user. A flawed or compromised system embedded in critical infrastructure can disrupt essential services, create safety risks, and undermine public trust. Canada’s National Cyber Threat Assessment identifies cybercrime and state-sponsored cyber activity as enduring threats to Canadian organizations and warns that critical infrastructure remains an attractive target for malicious actors (Canadian Centre for Cyber Security [CCCS], 2024). 

Canada’s strategy appropriately treats trust and confidence as part of the national AI agenda. But “trustworthy AI” must mean more than broad principles concerning fairness, transparency, or responsible use. In critical infrastructure, trust must be operational. It must be reflected in procurement requirements, cybersecurity controls, vendor accountability, incident reporting, auditability, testing, and clear lines of human responsibility. 

The challenge is especially acute as AI systems move from passive tools toward more autonomous or agentic systems. A conventional model may generate a recommendation. An AI agent may retrieve information, call external tools, interact with other systems, and pursue multi-step tasks with limited human intervention. These capabilities can create value, but they also expand the attack surface. Systems with access to organizational data, software tools, operational workflows, or connected infrastructure may be exposed to manipulated inputs, unsafe integrations, compromised dependencies, excessive permissions, or failures in monitoring and oversight. 

The Canadian Centre for Cyber Security has advised organizations adopting AI to address risks through measures including asset awareness, identity and access controls, secure configurations, monitoring, incident planning, and supply-chain risk management (CCCS, 2026). These are not peripheral technical details. They are conditions for making high-impact AI systems governable.

Canada should therefore use the implementation of AI for All to establish a practical assurance agenda for high-impact AI systems. 

First, public procurement should become a central lever. Governments are already major buyers and deployers of digital systems. Procurement for AI used in sensitive or infrastructure-adjacent contexts should require cybersecurity assurance, documentation of known limitations, clear data governance practices, and defined responsibilities where vendors rely on third-party models, cloud providers, or software components. Procurement must also address lifecycle risks. Model updates, software dependencies, vulnerability disclosure, deprecation, and incident response cannot be treated as afterthoughts. 

Second, Canada should support stronger AI incident-reporting and learning mechanisms.  Organizations deploying high-impact AI need clear processes for documenting serious failures, cybersecurity incidents, unsafe behaviour, and material changes in system performance. The objective should not be punitive reporting for its own sake. It should be institutional learning: identifying weaknesses, improving safeguards, and reducing the likelihood that comparable failures recur. This approach aligns with the broader emphasis in Canada’s National Cyber Security Strategy on resilience, collaboration, and the protection of Canada’s digital systems and services (Public Safety Canada, 2025). 

Third, Canada should connect AI policy to software supply-chain and infrastructure security. AI systems do not exist in isolation. They depend on data pipelines, APIs, cloud services, hardware, open-source libraries, external models, and human operators. A strategy focused only on model capability or innovation finance will overlook vulnerabilities created by this broader ecosystem.  Cybersecurity expectations for AI should therefore include dependency transparency, secure update processes, access controls, logging, red-teaming, and independent testing proportionate to the risks involved. 

Fourth, standards must be treated as a strategic tool rather than a technical afterthought. Standards shape interoperability, security expectations, conformity assessment, procurement requirements, and market access. Canada has established strengths in AI research, cybersecurity, intelligent transportation, and standards participation. It should use these strengths to advance practical expectations for secure and accountable AI deployment, particularly in cyber-physical and infrastructure settings. 

Finally, Canada should preserve meaningful human accountability. “Human in the loop” cannot become a slogan used to justify systems that operators do not understand, cannot override, or are not resourced to supervise. For high-impact systems, institutions need to define who can approve deployment, monitor performance, halt or roll back a system, and answer when automated decisions cause harm. This is not an argument against innovation. It is a condition for durable innovation. 

Canada has an opportunity to distinguish itself from jurisdictions that frame AI primarily as a race for scale, capital, or model capability. Competitive advantage can come from building systems that public institutions, businesses, and citizens can actually trust. That requires treating security, resilience, and accountability as components of innovation, rather than constraints imposed after deployment. 

AI for All should make critical infrastructure a proving ground for the strategy’s broader promises.  If Canada can deploy AI securely and accountably in the systems that sustain everyday life, it will have built more than an AI economy. It will have built public confidence in the institutions governing it. 

References 

Canadian Centre for Cyber Security. (2024). National cyber threat assessment 2025–2026.  Government of Canada. 

Canadian Centre for Cyber Security. (2026). Top 10 artificial intelligence security actions: A  primer (ITSAP.10.049). Government of Canada. 

Innovation, Science and Economic Development Canada. (2026). Canada’s National Artificial  Intelligence Strategy: AI for All. Government of Canada. 

Public Safety Canada. (2025). Canada’s National Cyber Security Strategy. Government of  Canada. 

More on the Author(s)

David Medcalfe

Data Mining and Security Lab, McGill University

Research Consultant