Skip to content

Montréal Times

Harnessing the Promise of Generative AI Without Sacrificing Trust

Cover Image for Harnessing the Promise of Generative AI Without Sacrificing Trust
Share:

Artificial intelligence (AI) has moved from experimentation to a strategic priority for organizations across Canada. It is being used to speed up customer service, lending decisions and administrative work. According to Statistics Canada, nearly one in five Canadian businesses (19.2%) used AI to produce goods or deliver services in the second quarter of 2026, up from 12.2% a year earlier.[1]

A newer generation of agentic AI goes further. Rather than generating content or answering questions, these software agents can complete tasks on behalf of users: comparing financial products, submitting applications, managing customer accounts and coordinating transactions across platforms with little human intervention.

For organizations, the productivity gains are compelling. But as AI becomes more autonomous, one question becomes increasingly important: How do you trust software to act on someone's behalf?

The answer depends on the digital identities that govern how these agents act.

Canada's Digital Economy Is Entering a New Phase

Canada is simultaneously advancing several transformative initiatives, including Real-Time Rail (RTR), Open Banking and broader digital service modernization. These developments promise faster, more seamless interactions for consumers and businesses while creating new opportunities for innovation across financial services, telecommunications and other regulated industries.

At the same time, Canada's National AI Strategy emphasizes that organizations must pair AI adoption with responsible governance to ensure trust, privacy and long-term confidence in digital services.[2]

These trends are deeply connected. Whether someone is opening a bank account, authorizing a payment, changing a mobile service or applying for credit, every digital interaction depends on verifying one fundamental element: identity.

As AI agents begin performing these tasks on behalf of individuals, organizations must shift their thinking from simply authenticating users to securely authorizing intelligent software acting in their name.

Why Traditional Authentication Is No Longer Enough

For decades, digital systems assumed that people directly interacted with websites and applications. Users entered passwords, completed forms and personally approved transactions.

Agentic AI changes that model entirely. Instead of navigating multiple systems themselves, consumers will increasingly instruct AI assistants to accomplish goals such as comparing mortgage options, renewing insurance policies or switching telecommunications providers.

The AI agent becomes the operator while the individual remains the decision-maker. That shift raises security questions organizations have not had to answer before: whether an agent genuinely represents the customer, what the customer has authorized, how much authority has been delegated, and whether every action can be traced if something goes wrong.

Traditional authentication methods were never designed to answer these questions. As AI adoption accelerates, digital identity becomes the trust layer that enables secure automation.

When AI Creates Risk by Working as Designed

AI security discussions tend to focus on sophisticated cyberattacks. Those threats matter, but AI can also create risk when it behaves exactly as designed.

An AI assistant attempting to speed up customer onboarding could unintentionally share more personal information than necessary. Another might bypass verification steps to complete a task more efficiently. Others may interpret a user's request too broadly, creating unintended compliance or privacy risks.

These situations illustrate why AI governance extends beyond cybersecurity. Organizations must ensure AI agents operate within clearly defined boundaries, with permissions that align precisely with user intent.

This becomes especially important as fraud grows more sophisticated. Survey data from earlier this year found that 75% of Canadians say AI advancements make them feel more vulnerable to fraud, while 82% believe scams are becoming progressively harder to spot, reinforcing the need for stronger identity verification across digital services.[3]

Trust Requires Human Oversight

As AI assumes greater responsibility, human judgment remains essential. Organizations should establish clear guardrails defining which activities AI can perform independently and which require explicit human approval. High-risk actions, such as financial transfers, identity changes or access to sensitive customer information, should continue to involve customer authorization or human review.

This "human-in-the-loop" approach accomplishes more than reducing risk. It strengthens customer confidence by ensuring people remain in control of critical decisions while allowing AI to automate routine work. It also creates transparency through audit trails that help organizations understand how decisions were made and demonstrate accountability to regulators and customers alike.

Digital Identity Will Determine AI's Success

The long-term success of agentic AI will depend less on increasingly sophisticated algorithms than on trusted digital identity.

Organizations need identity frameworks that allow users to securely delegate authority, limit permissions to specific tasks and revoke access whenever necessary. Authentication must become continuous rather than relying on a single login event, while authorization should be dynamic enough to reflect changing levels of risk throughout an interaction. These are capabilities that leading digital identity infrastructures are already beginning to support, verifying who is acting in a transaction, under what authority, and whether this authority remains valid throughout the interaction. The same principles will need to extend to software acting on a customer's behalf.

These capabilities become even more important as Canada's payment ecosystem evolves. Faster payments, Open Banking and connected digital services reduce the time available to detect fraud after transactions begin. Verifying identity before actions occur becomes far more valuable than trying to stop fraud after the fact.

This requires collaboration across financial institutions, telecommunications providers, technology companies and government organizations because identity fraud rarely affects only one industry. A compromised digital identity can quickly move across multiple sectors, making trusted identity infrastructure a shared responsibility.

Building Canada's Trusted AI Future

Generative AI and intelligent software agents will fundamentally change how Canadians interact with digital services. The opportunity to improve customer experiences and increase operational efficiency is significant.

Innovation alone will not determine which organizations benefit. Those that build trust into their AI strategies through secure digital identity, transparent governance and user control will be the ones able to deploy agentic AI at scale.

For Canada, the value of agentic AI will come down to a practical question: whether the identity and authorization infrastructure exists to let people trust software to act for them.


About the Author: Andrew Johnston is the Business Development Executive for Giesecke+Devrient, a global SecurityTech company. He is based in Ontario, Canada.