Skip to content
This is NOT an official site of the Government of Canada. Click here for the official AI registry.

AI-Powered Fraud Detection in CRA Secure Portals

Safety & Security · Enforcement

What it collects that can identify you

About behaviour
Pseudonymous data
  • Access logs capturing the interactions of all users with the CRA's secure portals — billions of historical records of portal activity such as login events, transaction requests, and navigation patterns.
About a measurement
Pseudonymous data
  • Digital fingerprint data — technical device and session attributes (e.g. browser type, IP characteristics, device identifiers) used as signals in anomaly detection. The register states this data does not constitute personal information.
Run by
Canada Revenue Agency (CRA)
Where
No fixed location
Kept
Not stated by the Helpful Places.
Shared with
Not stated by the Helpful Places.
Your copy
You cannot see the data it holds about you. What you can do

What it is for

This system uses artificial intelligence and machine learning to scan billions of access-log records from the Canada Revenue Agency's secure online portals and flag suspicious or potentially fraudulent transactions. It is used internally by Government of Canada employees and does not directly affect the general public's portal access. The system is currently in development. The CRA states that the data processed does not constitute personal information.

What it collects and what happens to it

Data taken in

About behaviour
Pseudonymous data
  • Access logs capturing the interactions of all users with the CRA's secure portals — billions of historical records of portal activity such as login events, transaction requests, and navigation patterns.
About a measurement
Pseudonymous data
  • Digital fingerprint data — technical device and session attributes (e.g. browser type, IP characteristics, device identifiers) used as signals in anomaly detection. The register states this data does not constitute personal information.

Processing

Anomaly Detection
  • Machine learning–based anomaly detection applied to portal access logs to identify patterns that deviate from a baseline of normal user behaviour and may indicate fraudulent transactions.

What it does

Deciding (Analytical AI)
Human decides
  • The system scans access-log records and scores or flags transactions as suspicious. The primary users are GC employees who review and act on these outputs, indicating human decision authority downstream.
Sensing (Perceptive AI)
Autonomous
  • Automatically ingests and processes billions of historical access-log records and digital fingerprint data, converting raw portal interaction signals into structured anomaly detections without per-record human review.

Outputs

A recommendation or prediction
Anonymized data
  • Flags or anomaly scores identifying suspicious and potentially fraudulent transactions, surfaced to GC employees for review. These are advisory outputs — the register indicates that GC employees are the primary users, implying human follow-up action.

Run by

Canada Revenue Agency (CRA)
  • The Canada Revenue Agency (CRA) is the federal department accountable for deploying and operating this AI-based anomaly detection system within its secure portals.

Government of Canada AI Register — 2526-CRA-ARC-012

Built by

Government of Canada
  • The system was developed by the Government of Canada, indicating in-house development rather than a commercial vendor.

Government of Canada AI Register — 2526-CRA-ARC-012

Kept for

Not stated by the Helpful Places.

Shared with

Not available to me
  • The anomaly detection outputs and access-log data are used internally by GC employees. There is no mechanism described for individuals to access the data or outputs produced by this system.

Stored

Not stated by the Helpful Places.

How to read the colours

Can it identify you?

Anonymized data
Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
Pseudonymous data
Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
Identifiable data
The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.

Who completes the loop?

Human decides
This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
Human executes
This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
Autonomous
This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.

Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.

What you can do

Ask about this system

Questions go to the Helpful Places, not the vendor.

Your rights

  • Right to Algorithmic TransparencyThe CRA has published a description of this system in the Government of Canada's AI Register, which provides basic information about its purpose and data sources. Detailed information about the model logic or specific detection thresholds is not publicly disclosed. Contact the CRA for further information about this system.

Risks and safeguards

  • Civil liberties harmSystematic surveillance of portal access behaviour could have a chilling effect on legitimate users or lead to erroneous flags that restrict access to government services. The register states no personal information is involved, and primary users are GC employees who review outputs, providing a human-in-the-loop safeguard. The system is currently in development, suggesting mitigations are still being designed. No additional technical or policy mitigations are described in the source material.