Skip to content

Technology

Canada’s bank regulator starts work on an AI ‘safety code’ as Routledge calls AI agent risks ‘frightening’

OSFI superintendent Peter Routledge says there is no draft or approved timeline yet, but a consultation could come as early as spring. He pointed to Anthropic’s restricted Mythos model as a sharp increase in cyber risk for lenders.

Published: October 8, 2026 · Updated: October 8, 2026 · 3 min read

Canada’s bank regulator starts work on an AI ‘safety code’ as Routledge calls AI agent risks ‘frightening’
File photo: Office towers in Toronto’s financial district, including First Canadian Place and Scotia Plaza, seen from street level on Aug. 5, 2017. OSFI says it is developing an AI “safety code” for the institutions it regulates. Photo: Arild Vågen / Wikimedia Commons, CC BY-SA 4.0

Canada’s federal banking regulator is preparing an artificial intelligence “safety code” for the financial institutions it oversees, superintendent Peter Routledge said Wednesday at a Global Risk Institute conference in Toronto. Routledge has tasked his team at the Office of the Superintendent of Financial Institutions (OSFI) with creating the code to improve cybersecurity and mitigate risks, The Globe and Mail reported. Routledge said OSFI has shifted from a largely hands-off approach to considering minimum standards for how banks use AI, according to The Logic.

The work is at an early stage. Routledge said there is no draft yet and no formally approved timeline for releasing the code, though a consultation could come as early as spring, according to The Logic. He told the Globe the code could consist of broad, high-level standards that provide a basic level of safety and protection for the financial system while establishing a “wide perimeter for innovation.” OSFI wants to set a “minimum level of safety or resilience” across the system, according to The Logic, so that weaknesses at one institution are less likely to spread to others.

Until now, OSFI has guided banks to “do no harm,” Routledge said, according to the Globe, which noted that the regulator and the Global Risk Institute published a report on AI in financial services in 2023. The Logic said the safety code would go beyond OSFI’s previous AI advisory reports and would likely build on the Financial Industry Forum on Artificial Intelligence and on OSFI’s work with the Financial Stability Board. A report on OSFI’s website from the forum’s second phase, run with the Department of Finance, the Bank of Canada and the Global Risk Institute, says workshop participants warned that Canada’s financial sector relies on a concentrated set of AI suppliers, and that 52 per cent of participants polled supported new legislation to regulate third-party AI service providers.

Routledge said the arrival of Anthropic’s Mythos model was the catalyst for considering firmer guardrails, the Globe reported. “That was an event that signifies the advancing capabilities of frontier AI models, which could be turned for illicit purposes and attack the financial institutions. That constituted a major increase in cyber risk,” he told reporters. On its Project Glasswing page, Anthropic describes Mythos Preview as an unreleased frontier model that has found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. The company says it is providing the model to launch partners and more than 40 other organizations that build or maintain critical software so they can use it for defensive security work.

Routledge also pointed to autonomous AI agents. “And then the more recent stories we’re reading about how agents are interpreting their task authorizations liberally and potentially posing dangers to institutions – that’s frightening, and that is a risk that is front and centre for us,” he said, according to the Globe.

He said he is generally satisfied with how prepared Canada’s banks are, but that “not all institutions across the system are equal on AI.” Because banks are connected, a problem at one could spread through the system, he said. “You’re connected to your counterparties, and if there’s poison at the counterparties, it’s flowing through to you as an institution,” Routledge said. “Our highest utility is to try and lessen the risk that some poison gets into one institution and scatters throughout the system.” The Globe reported that on Tuesday, AI benchmarking platform Evident ranked all five of Canada’s biggest banks in the top 30 of a list of 50 global financial institutions on AI adoption.

OSFI will also need more specialized expertise at a time when federal agencies are under pressure to cap headcount, The Logic reported. Routledge said OSFI has enough staff overall but plans to prioritize hiring experts in emerging risks, particularly AI and digital technology. “We know the very technology required to strengthen our resilience also creates new threats to our institutions, to our national security, and to democracy itself,” Global Risk Institute chief executive Sonia Baxendale said, according to the Globe.

Routledge also cited private credit and private equity as mounting risks and said OSFI would highlight the issue in its risk outlook, which the Globe said was set to be published Thursday. Separately, he told reporters he did not dispute a Financial Action Task Force report published last week that downgraded Canada’s supervision of financial institutions to “partially compliant” from “largely compliant,” The Logic reported, though he argued OSFI has made significant changes, including treating money laundering as a prudential risk and building a national security team of roughly 30 people.

Sources: The Globe and Mail (Oct. 7, 2026); The Logic (Oct. 7, 2026); OSFI: FIFAI II workshop report on AI and financial stability; Anthropic: Project Glasswing.

Sources

Newsletter

News. Context. What matters.

One essential briefing, written for people who would rather understand the story than scroll it.

Unsubscribe anytime. We don’t sell addresses.

Recommended