AI-Powered Malware Detection for Government Devices
Safety & Security
What it collects
- Software executables and documents present on or transmitted to Government of Canada employee devices. These are file-level operational artifacts with no personal information involved in the assessment.
- Run by
- Canada Revenue Agency (CRA)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Accountable organization, Vendor
What it is for
This system uses supervised machine learning to evaluate software and documents and determine whether they are malicious. It was deployed by the Canada Revenue Agency to protect government employees' computers from threats. The system does not process personal information about citizens and was used solely for internal cybersecurity purposes. Note: this system has been retired and is no longer in active use.
What it collects and what happens to it
Data taken in
- Software executables and documents present on or transmitted to Government of Canada employee devices. These are file-level operational artifacts with no personal information involved in the assessment.
Processing
- Supervised machine learning classifier that assigns a maliciousness label or score to each evaluated file or document, trained on vendor-curated threat intelligence datasets.
What it does
- Classifies software and documents as malicious or benign using supervised machine learning. Security personnel receive threat assessments and make downstream decisions about quarantine or remediation actions.
Outputs
- Threat assessment output indicating whether a file or document is classified as malicious. This advisory output is acted upon by GC security employees and automated endpoint protection processes.
Run by
- The Canada Revenue Agency deployed McAfee Adaptive Threat Protection to protect its internal IT environment and government employees' devices from malicious software and documents.
Built by
- McAfee is the vendor that built and supplied the Adaptive Threat Protection system, including the underlying machine learning models and training datasets.
Kept for
Not stated by the Helpful Places.
Shared with
- Threat detection outputs and logs are accessible to Canada Revenue Agency security and IT staff for monitoring and incident response purposes.
- Training data was sourced from McAfee vendor datasets. The register notes data sources are unavailable, suggesting McAfee retains control over the training data used to develop the models.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada Algorithmic Impact Assessment Register — McAfee Adaptive Threat Protection (2526-CRA-ARC-004)Canada Revenue Agency AI Register entry 2526-CRA-ARC-004, accessed 2026-05-08.
- AI register2526-CRA-ARC-004 Register Entry
- AI register2526-CRA-ARC-004 Register Entry
- AI register2526-CRA-ARC-004 Register Entry
- AI register2526-CRA-ARC-004 Register Entry
- AI register2526-CRA-ARC-004 Register Entry
- AI register2526-CRA-ARC-004 Register Entry
- AI register2526-CRA-ARC-004 Register Entry
- Register entryPublished by the Helpful Places. Reference b91866be. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Algorithmic TransparencyThe Canada Revenue Agency did not disclose AI use to affected users (GC employees). The system has since been retired. Employees seeking information about past automated systems used on their devices may contact CRA through official government channels.
Risks and safeguards
No risks or safeguards have been published for this system yet.