Critical Infrastructure

How Bill C-8 applies to AI systems in critical infrastructure

Most Bill C-8 compliance programs do not cover AI. Here is why they need to, and what AI-specific controls regulators will expect.

By Krikor Tengerian · Co-founder, SecuritAI Technologies Ltd. · Updated June 21, 2026

Bill C-8 AI security critical infrastructure Canada

Bill C-8 received Royal Assent on June 16, 2026. It requires designated critical infrastructure operators to establish cybersecurity programs covering their critical systems, with administrative penalties reaching $15 million per day for non-compliance. What most compliance teams building those programs have not yet grappled with: AI systems are now critical systems in every designated sector, and the existing cybersecurity playbook does not cover them.

For the full overview of the law, see What is Bill C-8?. For the four-obligation action list, see the Bill C-8 compliance checklist. For how SecuritAI supports a Bill C-8 cybersecurity program, see Bill C-8 compliance. This guide focuses on the AI layer those programs keep missing.

AI is now operational in every designated sector

Consider what AI actually does in Canada’s federally regulated critical infrastructure sectors today:

  • Telecommunications: AI-powered network anomaly detection, fraud identification, and customer-facing chatbots with access to account data
  • Banking and finance: AI models in credit decisioning, transaction monitoring, and customer service with access to personal financial data
  • Energy: AI in grid management, predictive maintenance, and operational control systems
  • Transportation: AI in logistics optimization, air traffic support systems, and passenger-facing services

In every case, the AI system has access to sensitive data or operational authority. In every case, it can be attacked, not through code vulnerabilities, but through the prompts and inputs it processes. And in almost every case, the organization’s Bill C-8 cybersecurity program does not mention it.

What makes AI systems different as a security risk

Traditional cybersecurity programs are designed around a clear model: attackers exploit code vulnerabilities, misconfigured systems, or stolen credentials. Defenses are firewalls, patch management, access control, and monitoring.

AI systems introduce a fundamentally different attack surface. The attack vector is language, ordinary text that the model processes as instructions. A sophisticated attacker does not need to find a code exploit. They need to find the right words.

The four AI attack categories Bill C-8 programs must cover

  • Prompt injection: hidden instructions that override the AI’s rules or extract confidential data
  • Jailbreaks: inputs that bypass safety guardrails, causing the model to act outside its intended scope
  • Data exfiltration: techniques that cause the model to leak system prompts, internal data, or PII in its responses
  • Agent manipulation: for AI agents with tool access, attacks that cause the agent to take unauthorized actions, call APIs, query databases, or escalate privileges

None of these attack categories appear in traditional cybersecurity frameworks. The OWASP LLM Top 10 defines them explicitly, and regulators reviewing AI-inclusive cybersecurity programs are beginning to reference it.

How Bill C-8’s obligations extend to AI

Cybersecurity program — AI must be in scope

The cybersecurity program obligation requires operators to identify critical systems and implement controls. Any AI system that processes operational data, has access to citizen or customer personal information, or can take autonomous actions qualifies as a critical system. It must appear in the program’s asset inventory, risk assessment, and control documentation.

Security testing — adversarial testing is the standard

For traditional systems, security testing means vulnerability scanning and penetration testing. For AI systems, the equivalent is adversarial red teaming, systematic testing using attack prompts across the OWASP LLM Top 10 categories. Organizations that can show a documented red team engagement with findings and remediation evidence will be in a defensible position. Organizations that cannot will struggle to demonstrate due diligence.

Incident detection — AI needs runtime monitoring

The incident reporting obligation requires operators to detect and report significant incidents. For AI systems, an incident might be a successful prompt injection that extracted customer data, a jailbroken chatbot that gave dangerous advice, or an AI agent that was manipulated into an unauthorized transaction. Detecting these requires runtime monitoring of AI inputs and outputs, a capability that does not exist in traditional security tooling.

Supply chain — AI APIs are supply chain risk

If an operator uses a third-party AI model via API, OpenAI, Anthropic, any cloud provider, that vendor is supply chain. The operator must assess the vendor’s security posture, understand data handling and incident notification practices, and document supply chain risk. Canadian data residency requirements make on-premises or Canadian-hosted AI deployment the cleanest solution for federally regulated operators.

What a C-8 compliant AI security program looks like

The practical components regulators will expect to see:

  • AI systems identified in the asset inventory and risk register
  • Documented adversarial testing (red team engagement) with findings and remediation evidence, at least annually
  • Runtime monitoring and logging of AI inputs and outputs (minimum 90-day retention)
  • Incident escalation path that includes AI-specific incident types
  • AI vendor security assessments with documented risk treatment
  • Canadian data residency or documented risk acceptance for offshore AI processing

Not sure where you stand? The free AI Security Readiness Check scores your AI setup in 60 seconds, no signup.

SecuritAI covers the AI layer of your C-8 program

AI Red Teaming: documented adversarial testing across OWASP LLM Top 10 categories. Produces a findings report and remediation evidence your C-8 program can use directly.

AI Firewall: runtime monitoring and blocking of AI attacks. Full audit log of every prompt and response, exportable for incident reporting and regulatory review.

SecuritComply: compliance automation for the full C-8 program, policy documentation, evidence management, risk register, and audit readiness.

Get your AI C-8 posture assessed

Book a 15-minute briefing to see exactly where your AI systems sit in your Bill C-8 cybersecurity program, and what it takes to close the gaps.

Book a Government Briefing

Bill C-8 and AI security questions

Are AI systems covered by Bill C-8?

Yes. Bill C-8’s cybersecurity program requirements cover all critical systems. AI systems that process sensitive data, have operational authority, or provide public-facing services in designated critical infrastructure sectors must be included in scope, with documented risk assessments, security testing, and runtime controls.

What AI security testing does Bill C-8 require?

Bill C-8 does not prescribe specific testing methods but requires that cybersecurity programs include appropriate controls and evidence of their operation. For AI systems, the appropriate equivalent of penetration testing is adversarial red teaming, systematic testing across prompt injection, jailbreaks, data exfiltration, and agent manipulation attack categories. Documented findings and remediation evidence demonstrate due diligence.

Does using a US-based AI API create Bill C-8 supply chain risk?

Yes. Third-party AI providers used in critical operations are supply chain. Operators must assess the provider’s security posture, data handling, and incident notification practices. For federally regulated critical infrastructure, Canadian data residency requirements often make on-premises or Canadian-hosted AI deployment necessary to fully satisfy supply chain and data sovereignty obligations.

What is the difference between an AI firewall and a traditional security tool for C-8 purposes?

Traditional security tools (network firewalls, WAFs, SIEM) monitor traffic, packets, and system events. They cannot read or analyze natural language. An AI firewall monitors the prompt-response layer, detecting and blocking injection attacks, jailbreaks, and policy violations that arrive as ordinary text. For C-8 incident detection at the AI layer, an AI firewall provides the runtime monitoring and audit logging that traditional tools cannot.


KT

Krikor Tengerian

Co-founder, SecuritAI Technologies Ltd.

Krikor Tengerian is the co-founder of SecuritAI Technologies and has over 25 years of experience in cybersecurity and IT infrastructure. He leads the company’s AI security platform and works with Canadian organizations and government bodies to secure their AI deployments against adversarial threats.



LinkedIn

← Back to the blog



Scroll to Top