Thank you for the question.
First, I'll clarify that the legislation being discussed today does not create a surveillance infrastructure. It does not mandate specific types of capabilities. That's a process that won't even be done through regulation because it will not mandate a massive surveillance infrastructure. As the development of the regulations proceed, security will be part of that process. Systemic vulnerability analysis will be part of that process.
I will also say that the legislation creates, for companies, a framework that will need to be followed to level the playing field in terms of being able to provide this information, and the information will be provided to law enforcement only if and when there's a judicially authorized production order to do so. It will be up to the company, at that point, to fulfill their obligations under that court-ordered production order.
At the end of the day, as I said earlier, right now the companies already have a lot of this data that might be subject to the regulations and to ministerial orders, and they already take a number of steps to protect that. In the face of the threats that you just mentioned, in terms of AI capabilities to sniff out cybersecurity vulnerabilities, they are very good at protecting their systems, and they continually try to get better by engaging third parties and by working with folks like those at CSIS and the Canadian centre for cybersecurity.
