Skip to content
This is NOT an official site of the Government of Canada. Click here for the official AI registry.

AI-Powered Cybersecurity Threat Detection for Government Networks

Safety & Security

What it collects that can identify you

Sensitive personal information
Pseudonymous data
  • Identity and access logs, including user account activity and authentication events, which may be tied to specific employees or accounts on the Commission's networks.
About behaviour
Pseudonymous data
  • Endpoint activity and network usage patterns across devices and users, used to establish behavioral baselines and detect deviations indicative of threats.

Also collects about a measurement, which is anonymized data.

Run by
Canadian Grain Commission (CGC)
Where
No fixed location
Kept
Not stated by the Helpful Places.
Shared with
Accountable organization, Vendor
Your copy
You cannot see the data it holds about you. What you can do

What it is for

Darktrace is an AI cybersecurity system deployed by the Canadian Grain Commission to detect, investigate, and respond to cyber threats on its networks in real time. It learns normal patterns of behavior across networks, devices, and users, then flags anomalies that may signal malicious activity. The system can act autonomously to contain threats without requiring human intervention. It processes network traffic, endpoint activity, cloud telemetry, email metadata, and identity and access logs, some of which may include personal information.

What it collects and what happens to it

Data taken in

Sensitive personal information
Pseudonymous data
  • Identity and access logs, including user account activity and authentication events, which may be tied to specific employees or accounts on the Commission's networks.
About behaviour
Pseudonymous data
  • Endpoint activity and network usage patterns across devices and users, used to establish behavioral baselines and detect deviations indicative of threats.
About a measurement
Anonymized data
  • Network traffic data, cloud and SaaS telemetry, and email metadata used to detect anomalies in system-level communications and data flows.

Processing

Anomaly Detection
  • Uses unsupervised machine learning to learn normal behavioral baselines across networks, devices, and users, then flags deviations that may signal malicious activity without relying on predefined rules or signatures.

What it does

Deciding (Analytical AI)
Human decides
  • Continuously classifies network traffic, endpoint behavior, and access events as normal or anomalous, producing risk scores and threat classifications that security staff can review.
Sensing (Perceptive AI)
Autonomous
  • Ingests and interprets raw network traffic, endpoint telemetry, cloud and SaaS signals, email metadata, and identity and access logs, converting them into structured detections for downstream analysis.
Acting (Agentic AI)
Autonomous
  • Autonomously responds to and contains detected cyber threats without requiring manual human intervention, executing containment actions directly on the network.

Outputs

A recommendation or prediction
Pseudonymous data
  • Threat alerts, anomaly scores, and visualizations of network activity flagging potential malicious behavior for review by security personnel.
A physical action
Anonymized data
  • Autonomous threat containment actions executed directly on the network, such as blocking connections, isolating devices, or restricting user access in response to detected threats.

Run by

Canadian Grain Commission (CGC)
  • A federal government department that deploys and operates the Darktrace cybersecurity AI system on its networks.

Darktrace AI Register Entry

Built by

Darktrace
  • The vendor that builds and supplies the Darktrace AI cybersecurity platform, including the underlying models and threat-detection algorithms.

Darktrace AI Register Entry

Kept for

Not stated by the Helpful Places.

Shared with

Not available to me
  • Employees and the public cannot access the data processed by this system. The primary users are identified as neither employees nor the public, and AI use is not disclosed to users.
Available to the accountable organization
  • Threat detection outputs, network visualizations, and anomaly alerts are available to the Canadian Grain Commission's security operations staff.
Available to vendor
  • As a vendor-supplied and operated system, Darktrace the company may have access to telemetry and operational data as part of platform operation and support; the register does not specify the scope of vendor data access.

Stored

Not stated by the Helpful Places.

How to read the colours

Can it identify you?

Anonymized data
Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
Pseudonymous data
Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
Identifiable data
The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.

Who completes the loop?

Human decides
This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
Human executes
This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
Autonomous
This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.

Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.

What you can do

Ask about this system

Questions go to the Helpful Places, not the vendor.

Your rights

  • Right to Be Informed of AI UseThe register indicates that AI use is not disclosed to users (employees whose network activity is monitored). Individuals currently have no stated mechanism to be informed that this AI system is in operation on networks they use. This is a transparency gap that should be addressed.
  • Right to Algorithmic TransparencyNo information is provided in the register about how affected individuals can learn how this system works or what logic is used to flag their activity. Contact the Canadian Grain Commission for further information about the system's operation.

Risks and safeguards

  • Civil liberties harmThe system monitors employee network behavior and email metadata, creating risks of surveillance chilling effects on staff communications and movement on government networks. Personal information is involved. Mitigations are not described in the register entry; however, the system is scoped to internal network security and not disclosed to users (AI use disclosed to users: N), raising transparency concerns. Recommended mitigations include staff notification of monitoring scope, purpose limitation to security use cases, and independent review of autonomous containment actions.
  • Loss of autonomyThe system can autonomously contain threats without human review, potentially restricting employee access to network resources or blocking legitimate activity. Autonomous response reduces the opportunity for human intervention before containment actions are executed. The register does not describe override procedures or human-in-the-loop safeguards for containment decisions. Recommended mitigations include documented override procedures, human authorization for high-impact containment actions, and clear redress paths for affected employees.