AI-Powered Cybersecurity Threat Detection for IT Infrastructure
Safety & Security
What it collects
- System logs, network activity data, and security event data from the department's internal IT infrastructure. The register states no personal information is involved.
- Run by
- Innovation, Science and Economic Development Canada (ISED)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Accountable organization
What it is for
This system uses artificial intelligence to monitor patterns of activity across Innovation, Science and Economic Development Canada's IT environment, flagging unusual behaviour that may indicate cybersecurity threats, insider risks, or compromised accounts. It applies machine learning and large language models to detect anomalies and display security trends on visual dashboards. The system processes system logs and network activity data but does not involve personal information according to the department's disclosure. Government of Canada employees are informed that AI is in use.
What it collects and what happens to it
Data taken in
- System logs, network activity data, and security event data from the department's internal IT infrastructure. The register states no personal information is involved.
Processing
- Machine learning models learn baselines of normal user and entity behaviour from historical logs, then flag deviations that may indicate insider threats, compromised accounts, or external intrusions.
- Large language models are used alongside machine learning to identify anomalies in user and entity behaviour patterns within the IT environment.
What it does
- Scores and classifies user and entity activity patterns to identify anomalies and prioritize potential security threats for review by security analysts.
- Ingests and structures raw system logs, network activity data, and security event streams from internal IT infrastructure into features usable by downstream analytical models.
Outputs
- Security alerts and visual trend dashboards surfacing anomalies and suspicious behaviour patterns for review by security analysts; outputs are advisory and support human-led investigation rather than triggering automated enforcement actions.
Run by
- The federal department that deploys and operates this AI system to monitor its internal IT environment for cybersecurity threats.
Built by
- The system was developed by the Government of Canada, with the department identified as the developing entity in the official register.
Kept for
Not stated by the Helpful Places.
Shared with
- Security alerts, anomaly detections, and visual dashboard outputs are available to authorized security personnel within Innovation, Science and Economic Development Canada. Primary users are identified as GC employees in a security operations context.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada Algorithmic Impact Assessment Register — Entity and User Behavior Analytics (2526-ISED-ISDE-021)Innovation, Science and Economic Development Canada. AI Register ID 2526-ISED-ISDE-021. Status: In production.
- AI registerGovernment of Canada AI Register — 2526-ISED-ISDE-021
- AI registerGovernment of Canada AI Register — 2526-ISED-ISDE-021
- Register entryPublished by the Helpful Places. Reference 972cb435. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseGovernment of Canada employees are informed that this AI system is in use within the department's IT environment. The register confirms AI use is disclosed to users (field: AI use disclosed to users = Y).
- Right to Algorithmic TransparencyThe system is listed in the Government of Canada's public AI register, providing public-facing disclosure that AI is used to monitor IT activity for cybersecurity purposes. The register entry can be consulted at the source URL. Further details about the system's logic and the significance of its processing are not described in the public register entry.
Risks and safeguards
- Civil liberties harmContinuous behavioural monitoring of employees across an IT environment creates a risk of chilling effects on lawful activity or disproportionate surveillance of individuals, even when no personal information is formally recorded. The register discloses that AI use is communicated to GC employees, providing a transparency mitigation. However, the register does not describe oversight mechanisms, purpose-limitation controls, or audit procedures that would further bound the surveillance risk. The extent of human review before any action is taken on flagged individuals is not documented.