Skip to content
This is NOT an official site of the Government of Canada. Click here for the official AI registry.

AI-Assisted Cybercrime and Fraud Intelligence Coordination

Enforcement · Risk Assessment & Triage · Safety & Security

What it collects that can identify you

Sensitive personal information
Identifiable data
  • Personal information from cybercrime and fraud reports submitted by law enforcement partners and public reports; the register confirms involvement of personal information.

Also collects operational data, which is anonymized data.

Run by
Royal Canadian Mounted Police (RCMP)
Where
No fixed location
Kept
Not stated by the Helpful Places.
Shared with
Accountable organization, 3rd parties

What it is for

The National Cybercrime Solution is used by the RCMP's National Cybercrime Coordination Centre and Canadian Anti-Fraud Centre to coordinate complex cybercrime and fraud investigations across Canadian and international law enforcement partners. It categorizes data, translates information, and recognizes entities and patterns to produce intelligence packages. The system involves personal information reported by partners and members of the public, and the use of AI has been disclosed to users.

What it collects and what happens to it

Data taken in

Sensitive personal information
Identifiable data
  • Personal information from cybercrime and fraud reports submitted by law enforcement partners and public reports; the register confirms involvement of personal information.
Operational data
Anonymized data
  • Case data, intelligence reports, and cybercrime/fraud incident data from law enforcement partners and Canadian Anti-Fraud Centre public reports used to coordinate and deconflict investigations.

Processing

Classification & Prediction
  • Data categorization capability classifies cybercrime and fraud reports into case types and risk tiers to support prioritization and coordination across law enforcement partners.
Anomaly Detection
  • Entity and pattern recognition capabilities identify connections, anomalies, and emerging threat patterns across cybercrime and fraud case data.

What it does

Deciding (Analytical AI)
Human decides
  • Performs risk assessment, entity recognition, and pattern recognition to classify and score cybercrime and fraud cases; outputs feed intelligence packages reviewed by GC employees before action.
Understanding (Semantic AI)
Human decides
  • Performs data translation and entity recognition, extracting meaning and linking related information across cybercrime and fraud reports submitted by partners and the public.

Outputs

A recommendation or prediction
Anonymized data
  • Comprehensive cybercrime and fraud intelligence packages produced for law enforcement and security partner organizations in Canada and abroad, supporting investigative decision-making.
Sensitive personal information
Identifiable data
  • Intelligence packages may contain personal information about individuals identified as subjects or victims in cybercrime and fraud investigations, shared with law enforcement partners.

Run by

Royal Canadian Mounted Police (RCMP)
  • The RCMP, through its National Cybercrime Coordination Centre (NC3) and Canadian Anti-Fraud Centre (CAFC), is the federal agency deploying and operating the National Cybercrime Solution to coordinate cybercrime and fraud investigations.

National Cybercrime Solution — AI Register

Built by

FTI Consulting Inc. and Hubstream
  • FTI Consulting Inc. and Hubstream are the technology vendors that supplied the National Cybercrime Solution platform. The system was also developed in part by the RCMP itself.

National Cybercrime Solution — AI Register

Kept for

Not stated by the Helpful Places.

Shared with

Available to the accountable organization
  • Output data and intelligence packages are accessible to RCMP employees (NC3 and CAFC), as the primary users are identified as GC employees.
Available to 3rd parties
  • Intelligence packages are shared with law enforcement and security partner organizations in Canada and abroad, as described in the system's stated purpose.

Stored

Not stated by the Helpful Places.

How to read the colours

Can it identify you?

Anonymized data
Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
Pseudonymous data
Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
Identifiable data
The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.

Who completes the loop?

Human decides
This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
Human executes
This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
Autonomous
This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.

Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.

What you can do

Ask about this system

Questions go to the Helpful Places, not the vendor.

Your rights

  • Right to Be Informed of AI UseThe use of AI in the National Cybercrime Solution has been disclosed. Members of the public who submit fraud or cybercrime reports to the Canadian Anti-Fraud Centre should be aware that AI tools are used to process and analyze reported information.
  • Right to Algorithmic TransparencyThe Government of Canada has published information about this AI system in its public AI register, disclosing that AI capabilities including data categorization, entity recognition, pattern recognition, and risk assessment are used. Further information may be requested from the RCMP.

Risks and safeguards

  • Civil liberties harmThe system processes personal information in the context of law enforcement, creating risks of surveillance overreach, misidentification, or chilling effects on lawful activity.Safeguard: AI use is disclosed to users; the system is operated by GC employees who review intelligence packages before action; developed under RCMP oversight with coordination controls to deconflict cases.
  • Reputational harmPattern recognition and entity linking could lead to false associations or misidentification of individuals in cybercrime and fraud investigations, causing reputational harm.Safeguard: Intelligence packages are reviewed by GC employees; the system supports human decision-making rather than automated determinations; deconfliction processes reduce the risk of erroneous case associations.