Canada's national cyber security authority has published a plain-language list of what actually goes wrong with generative AI from a security standpoint — and most of the fixes it recommends are the same basic hygiene that protects against everything else, not exotic new controls.
Key takeaways
Canada's Cyber Centre lays out its assessment of generative AI risk in ITSAP.00.041, Generative artificial intelligence, dated December 2025. Eight risks are named as headings, each with its own short explanation:
(All eight quotations: ITSAP.00.041.) None of these risks require an exotic new security discipline to understand. Most map directly onto categories a security team already manages — data handling, social engineering, supply-chain integrity — with generative AI as a new delivery mechanism rather than a wholly new threat category.
A more recent Cyber Centre publication, Top 10 artificial intelligence security actions, organizes the same territory into three pillars: protecting against the adversarial use of AI by attackers (prompt injection, deepfakes, AI-accelerated attacks), protecting AI systems themselves (testing and red-teaming, data poisoning, model theft), and protecting users and business processes (vendor contracts, human oversight, resilience against model drift and hallucination). The specific mechanics of the first pillar — how a hidden instruction actually redirects a model — are covered in more depth in how hidden text hijacks an AI, and a fuller run of documented 2024–2025 incidents behind these pillars is in what actually goes wrong with AI in practice.
ITSAP.00.041's own mitigation advice is ordinary on purpose: “organizations and individuals should practice basic cyber security hygiene as a starting point in understanding risks and taking the appropriate measures to mitigate them” (ITSAP.00.041). Two measures the guidance names specifically: enforcing strong authentication (multi-factor authentication on any account or system with access to an AI tool or its data), and applying security patches and updates promptly, including for the platforms an AI tool runs on top of. Neither is AI-specific — both are standard security practice that happens to cover a meaningful share of the eight named risks above.
The full mitigation list in ITSAP.00.041 names three more organizational measures worth stating specifically: “stay informed” on current AI-related threats and vulnerabilities; “protect your network” with detection tools that can flag abnormal activity quickly, including watching for the same techniques being used defensively; and “train your employees” to recognize social-engineering attempts and report suspicious communications through an easy, known channel. None of the five organizational measures in the full list is specific to generative AI on its own — together they are simply what a reasonably careful organization already does, applied to a new source of risk.
The guidance also puts a specific duty on the person using the output, not just the system administering it: “it is also important to be careful and analyze AI content before acting or using it. You should always be aware of and validate your sources to verify whether the content being presented is accurate” (ITSAP.00.041). That single habit — checking before acting — is the practical core of most of the guidance's other recommendations.
The Cyber Centre operates as part of the Communications Security Establishment, Canada's national cryptologic agency, which describes its mandate as providing the Government of Canada with “information technology security and foreign signals intelligence” (CSE, about the Communications Security Establishment) — the institutional source behind the guidance quoted throughout this page.
For a business evaluating an AI vendor as part of a wider acquisition or partnership, the same data-practice questions apply as in any other technology purchase — a starting checklist for the general case is (treadstonelaw.ca, data privacy due diligence in a business acquisition).
The FAQ above notes the guidance is consistent with PIPEDA’s own security duty; the specific requirement it is consistent with is Schedule 1, Principle 7, which states that “personal information shall be protected by security safeguards appropriate to the sensitivity of the information”, and that those safeguards must protect against “loss or theft, as well as unauthorized access, disclosure, copying, use, or modification” (Personal Information Protection and Electronic Documents Act, Schedule 1). Unlike the Cyber Centre’s awareness guidance, this one is a binding legal obligation on any organization covered by PIPEDA, not a recommendation.
Mostly no. Canada's Cyber Centre frames most of its eight named risks as existing categories — phishing, malicious code, data exposure — that generative AI makes faster, cheaper, and available to less-skilled attackers, rather than categories that didn't exist before.
Yes — it's one of the two specific measures the Cyber Centre names, because unauthorized access to an account connected to an AI tool or its data is one of the most direct routes to several of the eight named risks at once, from data exposure to malicious use of the tool itself.
The Canadian Centre for Cyber Security, part of the Communications Security Establishment. Its ITSAP series is awareness guidance, not a binding regulation — it doesn't create a legal obligation on its own, though following it is generally consistent with the security safeguards PIPEDA already requires.
Turning eight named risks into an actual monitoring and access-control setup is the day-to-day work of running an AI system safely after launch.