Treadstone Associates
Article · 8 min read

AI and cyber security basics

Canada's national cyber security authority has published a plain-language list of what actually goes wrong with generative AI from a security standpoint — and most of the fixes it recommends are the same basic hygiene that protects against everything else, not exotic new controls.

Treadstone Associates · Updated 2026

Key takeaways

  • • The Canadian Centre for Cyber Security names eight specific generative-AI risks in its guidance: misinformation and disinformation, phishing, privacy of data, malicious code, buggy code, poisoned datasets, biased content, and loss of intellectual property.
  • • A newer Cyber Centre publication organizes the same territory into three pillars: protecting against adversarial use of AI, protecting AI systems themselves, and protecting users and business processes.
  • • The Cyber Centre's own advice is not exotic: multi-factor authentication, timely patching, and validating AI output before acting on it cover most of the eight named risks.
  • • Generative AI lowers the skill bar for an attack rather than inventing new attack categories — the Cyber Centre notes that “those with little or no coding experience can use generative AI to easily write functional malware.”

The eight risks, named plainly

Canada's Cyber Centre lays out its assessment of generative AI risk in ITSAP.00.041, Generative artificial intelligence, dated December 2025. Eight risks are named as headings, each with its own short explanation:

  • Misinformation and disinformation — “Content not clearly identified as being AI-generated can result in the spread of misinformation, disinformation and confusion.”
  • Phishing — threat actors “can craft targeted spear-phishing attacks more frequently, automatically, and with a higher level of sophistication.”
  • Privacy of data — users “may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts.”
  • Malicious code — “those with little or no coding experience can use generative AI to easily write functional malware that could disrupt a business or organization.”
  • Buggy code — developers “may inadvertently introduce insecure and buggy code into the development pipeline.”
  • Poisoned datasets — threat actors “can inject malicious code into the dataset used to train the generative AI system,” which “could also increase the potential for large-scale supply-chain attacks.”
  • Biased content — “most of the training datasets fed into LLMs come from the open Internet,” so “generated content has a fundamental bias in that only limited amounts of the world's total data are online and available for AI to use.”
  • Loss of intellectual property — generative AI tools “may enable sophisticated threat actors to steal corporate data more easily, quickly and in larger quantities.”

(All eight quotations: ITSAP.00.041.) None of these risks require an exotic new security discipline to understand. Most map directly onto categories a security team already manages — data handling, social engineering, supply-chain integrity — with generative AI as a new delivery mechanism rather than a wholly new threat category.

The newer picture: three pillars, not eight isolated risks

A more recent Cyber Centre publication, Top 10 artificial intelligence security actions, organizes the same territory into three pillars: protecting against the adversarial use of AI by attackers (prompt injection, deepfakes, AI-accelerated attacks), protecting AI systems themselves (testing and red-teaming, data poisoning, model theft), and protecting users and business processes (vendor contracts, human oversight, resilience against model drift and hallucination). The specific mechanics of the first pillar — how a hidden instruction actually redirects a model — are covered in more depth in how hidden text hijacks an AI, and a fuller run of documented 2024–2025 incidents behind these pillars is in what actually goes wrong with AI in practice.

Basic hygiene still does most of the work

ITSAP.00.041's own mitigation advice is ordinary on purpose: “organizations and individuals should practice basic cyber security hygiene as a starting point in understanding risks and taking the appropriate measures to mitigate them” (ITSAP.00.041). Two measures the guidance names specifically: enforcing strong authentication (multi-factor authentication on any account or system with access to an AI tool or its data), and applying security patches and updates promptly, including for the platforms an AI tool runs on top of. Neither is AI-specific — both are standard security practice that happens to cover a meaningful share of the eight named risks above.

The full mitigation list in ITSAP.00.041 names three more organizational measures worth stating specifically: “stay informed” on current AI-related threats and vulnerabilities; “protect your network” with detection tools that can flag abnormal activity quickly, including watching for the same techniques being used defensively; and “train your employees” to recognize social-engineering attempts and report suspicious communications through an easy, known channel. None of the five organizational measures in the full list is specific to generative AI on its own — together they are simply what a reasonably careful organization already does, applied to a new source of risk.

The guidance also puts a specific duty on the person using the output, not just the system administering it: “it is also important to be careful and analyze AI content before acting or using it. You should always be aware of and validate your sources to verify whether the content being presented is accurate” (ITSAP.00.041). That single habit — checking before acting — is the practical core of most of the guidance's other recommendations.

The Cyber Centre operates as part of the Communications Security Establishment, Canada's national cryptologic agency, which describes its mandate as providing the Government of Canada with “information technology security and foreign signals intelligence” (CSE, about the Communications Security Establishment) — the institutional source behind the guidance quoted throughout this page.

For a business evaluating an AI vendor as part of a wider acquisition or partnership, the same data-practice questions apply as in any other technology purchase — a starting checklist for the general case is (treadstonelaw.ca, data privacy due diligence in a business acquisition).

The FAQ above notes the guidance is consistent with PIPEDA’s own security duty; the specific requirement it is consistent with is Schedule 1, Principle 7, which states that “personal information shall be protected by security safeguards appropriate to the sensitivity of the information”, and that those safeguards must protect against “loss or theft, as well as unauthorized access, disclosure, copying, use, or modification” (Personal Information Protection and Electronic Documents Act, Schedule 1). Unlike the Cyber Centre’s awareness guidance, this one is a binding legal obligation on any organization covered by PIPEDA, not a recommendation.

Common questions

Does generative AI create entirely new categories of cyber risk?

Mostly no. Canada's Cyber Centre frames most of its eight named risks as existing categories — phishing, malicious code, data exposure — that generative AI makes faster, cheaper, and available to less-skilled attackers, rather than categories that didn't exist before.

Is multi-factor authentication actually relevant to AI-specific risk?

Yes — it's one of the two specific measures the Cyber Centre names, because unauthorized access to an account connected to an AI tool or its data is one of the most direct routes to several of the eight named risks at once, from data exposure to malicious use of the tool itself.

Who publishes this guidance, and is it mandatory?

The Canadian Centre for Cyber Security, part of the Communications Security Establishment. Its ITSAP series is awareness guidance, not a binding regulation — it doesn't create a legal obligation on its own, though following it is generally consistent with the security safeguards PIPEDA already requires.

Where this goes next

Turning eight named risks into an actual monitoring and access-control setup is the day-to-day work of running an AI system safely after launch.