That is, I understand, an addition to that same point of order.
MP Lawton.
Evidence of meeting #44 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was reasonable.
A video is available from Parliament.
Liberal
The Chair Liberal Jean-Yves Duclos
That is, I understand, an addition to that same point of order.
MP Lawton.
Conservative
Andrew Lawton Conservative Elgin—St. Thomas—London South, ON
Just in the spirit of collaboration here, Ms. Acan had mentioned the importance of passing part 1. Are the Liberals taking us up on our offer to expeditiously pass part 1, which we've been offering for weeks now and which is not even all that contentious?
Liberal
Jacques Ramsay Liberal La Prairie—Atateken, QC
I have a point of order. Mr. Lawton should know very well that part 1 without part 2 is not a bill. It doesn't make sense.
Liberal
The Chair Liberal Jean-Yves Duclos
My understanding of what MP Acan said is that if we want to proceed efficiently through part 1 and eventually part 2, then we have to do that in the sequence of the amendments. That's therefore why it is suggested, though obviously not made obligatory by the chair, to focus on the topic of the amendment that is currently under consideration if we want to proceed eventually to other amendments thereafter.
MP Cody.
Conservative
Connie Cody Conservative Cambridge, ON
Thank you.
Through you, Chair, in the matter of trying to collaborate with the members across, I will reduce the number of questions, but I do feel that there are important questions I want to ask and I'll continue with them. I'll be able to continue more quickly if their points of order do not interrupt. I think that would be a fair compromise. I'll continue.
To go back to the question, the security of the interception infrastructure this bill requires to be built to follow these production orders will depend entirely on whether that infrastructure can withstand the tools currently available to those who want to break into it. Before Claude Mythos was released to the public, it found a security flaw that had been sitting undetected in a widely used operating system for 27 years. It cost only $50 and took hours, where human researchers would have needed months. Just last week—
Liberal
Liberal
The Chair Liberal Jean-Yves Duclos
You must be saying relevance to the amendment.
Ms. Cody, you would have heard that before.
Conservative
Connie Cody Conservative Cambridge, ON
Yes, I hear it. You're asking someone to make an order based on what they believe. To do that, they're going to use a tool and they have to be confident that the tool is going to access the information properly, correctly and accurately. If you're going to have a judge who is looking to be satisfied by the information on oath, these questions do need to be answered, so they are relevant. Thank you.
I'll go from the top and continue again so that there's no miscommunication with the question. The security of the interception infrastructure this bill requires to be built to follow production orders will depend entirely on whether that infrastructure can withstand the tools currently available to those who want to break into it. Before Claude Mythos was released to the public, it found a security flaw that had been sitting undetected in a widely used operating system for 27 years. It cost only $50 and took hours, where human researchers would have needed months. Just last week, Anthropic released Claude Fable 5 and Claude Mythos 5, making that level of capability broadly available for the first time. The U.S. government's response was immediate, an export control directive forcing Anthropic to suspend global access to both models entirely. It was the first time a government has shut down an AI company's products over national security concerns.
Has the Department of Public Safety looked at what AI-powered vulnerability discovery at that speed and that cost actually means for the long-term security of what this bill is asking to be built?
Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness
The short answer to that is no, because the legislation does not mandate that specific things be built. That will be something that will be done through regulation and/or ministerial orders subject to that. As part of that process, we expect security conversations to be part of the consultation process, whether it's with internal government experts or with the people who may be subject to regulation. Obviously, it's an evolving environment. I am not one of those foremost cybersecurity experts, and I won't delve too much into that. However, we will be consulting with experts as we move forward and, subject to the regulations, that will dictate how we approach it.
Conservative
Connie Cody Conservative Cambridge, ON
One of the core assumptions underlying this bill is that data moves only when someone with legal authority requests it, but the infrastructure SAAIA creates will operate in an environment where that assumption does not hold. Claude Mythos did not wait to be asked. During a controlled stress test directly relevant to the kind of security environment this bill's infrastructure will face, it decrypted—
Liberal
The Chair Liberal Jean-Yves Duclos
I'm sorry, Ms. Cody. What you're saying is both dense and quick, and I suspect that it must be quite difficult for interpreters to follow the rhythm.
Conservative
Connie Cody Conservative Cambridge, ON
Okay. I was just trying to hurry so that I could get through it.
Anyway, one of the core assumptions underlying this bill is that data moves only when someone with legal authority requests it, but the infrastructure SAAIA creates will operate in an environment where that assumption does not hold. Claude Mythos did not wait to be asked. During a controlled stress test directly relevant to the kind of security environment this bill's infrastructure will face, it decrypted and exposed confidential internal documentation on its own, following its own logic to a place nobody directed it to go, and then flagged to a researcher that it had gotten out. That is not a malfunction. That is the system working as designed and going further than anyone intended.
Claude Mythos is not unique in this. AI systems of this capability class, built by any number of companies in any number of countries, operate the same way. The interception infrastructure this bill creates will exist in an environment where AI systems can reach, surface and expose data without a request, without authorization and without anyone knowing it is happening until after the fact. Where in this bill does the government account for that?
Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness
Thank you for the question.
First, I'll clarify that the legislation being discussed today does not create a surveillance infrastructure. It does not mandate specific types of capabilities. That's a process that won't even be done through regulation because it will not mandate a massive surveillance infrastructure. As the development of the regulations proceed, security will be part of that process. Systemic vulnerability analysis will be part of that process.
I will also say that the legislation creates, for companies, a framework that will need to be followed to level the playing field in terms of being able to provide this information, and the information will be provided to law enforcement only if and when there's a judicially authorized production order to do so. It will be up to the company, at that point, to fulfill their obligations under that court-ordered production order.
At the end of the day, as I said earlier, right now the companies already have a lot of this data that might be subject to the regulations and to ministerial orders, and they already take a number of steps to protect that. In the face of the threats that you just mentioned, in terms of AI capabilities to sniff out cybersecurity vulnerabilities, they are very good at protecting their systems, and they continually try to get better by engaging third parties and by working with folks like those at CSIS and the Canadian centre for cybersecurity.
Conservative
Connie Cody Conservative Cambridge, ON
Thank you.
When a production order is requested and the officer believes that there is a reason to pursue or to inquire, SAAIA does not appear to draw any practical distinction between the data of a person who is the subject of a production order and the data of innocent people who share an account with that person. I see that as a significant gap.
Most Canadians share phone plans, cloud storage and digital accounts with family members. A production order targeting one person on a shared account does not stop at that person's data. It pulls everything on that account, including the private information of people who have never been suspected of anything and have no idea that an order was ever made. The bill may intend for providers to limit disclosure to what is ordered, but the technical reality of shared accounts is that one person's data cannot always be practically separated from another's.
Canadian law already recognizes this principle in other contexts. A joint bank account holder cannot be compelled to hand over funds or information belonging to the other holder simply because that person is under investigation. Why does that protection exist at the bank, but when it comes to a telecom or digital service provider through which a family shares an account, the technical architecture makes that same separation nearly impossible? What enforcement mechanism in this bill ensures providers actually achieve it?
Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness
Thank you for the question.
The bill doesn't speak to production orders or address tools that, whether it's CSIS or law enforcement, are already used to compel production of information. The situation that you describe exists today in the current environment, whether it's within telecommunications or others.
I might turn to the RCMP for a practical perspective about how they deal with that. I don't know whether the Department of Justice or the service can also add to that. It is more of a question about how production orders are applied for and then given by judges.
Acting Officer-in-Charge, RCMP Lawful Access, Royal Canadian Mounted Police
I appreciate the question. Actually, I very much appreciate your highlighting the complexities that police are currently dealing with.
This is something, as mentioned by my colleague previously, that we regularly deal with, and it's partly why we have experts who do analysis on the information we actually receive. Their intention is to establish who might be the originator of a particular type of traffic. That speaks to the information we actually request when we're asking for information—for example, in production orders—because it's not just the information related to the offence itself. It's also information related to the use of a particular device, at a particular time and in a particular place that we try to collect. We use that for attribution to a particular individual at a particular time.
This is something that we're actually very familiar with, and we do it on a regular basis. However, I very much appreciate your highlighting the complexity.
Conservative
Connie Cody Conservative Cambridge, ON
The National Security and Intelligence Review Agency, the body that would be expected to oversee the authorities, has raised concerns about whether it has sufficient access to do that job effectively. At the same time, SAAIA stops service providers from telling anyone that a demand was ever made against them. The public does not know, the oversight body cannot fully see, the companies cannot say anything and the person whose data was accessed may never find out.
How does that combination produce real accountability, and who, exactly, is in a position to catch a problem if one comes up?
Liberal
Anthony Housefather Liberal Mount Royal, QC
I have a point of order.
Mr. Chair, I respectfully listened to Ms. Cody's last question. It is the same as her others.
We're in a section in which we're making a determination whether we should amend “reasonable grounds to suspect” to “reasonable grounds to believe”, which is a debate about what legal standard to apply to part of this bill. It's a very important debate. It's a very important discussion, but this question is entirely unrelated to the discussion, which is the purpose of this amendment.
Mr. Chair, if these questions are allowed, then it means that these same questions could be repeated with each and every amendment and each and every subamendment that is introduced, irrespective of the relevance to that amendment or subamendment.
I would respectfully submit, Mr. Chair, this is not how clause-by-clause is supposed to proceed.
Liberal
The Chair Liberal Jean-Yves Duclos
That's right. Part of the blame is on me, and I appreciate that. I have, also, the responsibility to allow some freedom. However, it is true that if we want to vote on a particular amendment, the topic of the discussion needs to be on that amendment; otherwise, we will never proceed to the consideration of other amendments.
If we want to consider amendment BQ-5, then I would certainly encourage everyone to focus on the topic, the content of that amendment, in the questions and answers.
Conservative
Connie Cody Conservative Cambridge, ON
I will conclude with the last two questions, then. I've had several, and I've turned them away. I do feel that these are correct to ask because we are asking our law enforcement to believe in what they put in the order. To do so, they have to understand and have confidence in the accuracy of what they're going to be retrieving, and what may or may not happen before they do it. I do think that it does have some relevance to believing, so I will continue.
The United States just demonstrated that it can shut down AI tools used by Canadian service providers overnight, with no notice and by executive order. Canada is asking those same providers to build and maintain permanent interception infrastructure under this bill. What is the government's continuity plan when the tools a service provider depends on are switched off by a foreign government's decision? Does this bill create any obligation to disclose that kind of disruption to the people whose data sits behind it?
Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness
Thank you for the question. The bill doesn't address that. It's not within the scope of the legislation.
Conservative
Connie Cody Conservative Cambridge, ON
Again, I'm going to mention that Anthropic flagged the cybersecurity risk of Claude Fable 5 and Claude Mythos 5 before the United States government acted. The company raised the alarm first. The U.S. ban came within days of release. Canada has said nothing.
This bill asks Canadians to trust that the government understands the AI threat environment well enough to build permanent interception infrastructure inside it. However, when both the company that built the tool and then a foreign government moved, before Canada even asked a question, that trust has to be earned.
Is the government's position that it needs a foreign government to identify an AI national security threat before it will act? If that is the standard, how many days behind Washington should Canadians expect their government to be?
Liberal
Anthony Housefather Liberal Mount Royal, QC
I have a point of order.
Mr. Chair, people are not here to answer for the government as to the government's intentions on something that has nothing to do with this bill. That is a question she could ask in question period. This is not a question for these witnesses. It's on a subject that is not part of the bill. She's asking them a much greater question about the government's intention. The question is unreceivable.