Matt Holland, a former cyber-espionage specialist with Canada’s Communications Security Establishment, has shifted his focus from national security threats to the emerging challenges posed by artificial intelligence within corporate environments. In June, his Ottawa-based company, Field Effect Software Inc., launched an AI detection-and-response tool aimed at helping small and medium-sized businesses manage risks associated with the increasing use of AI technologies.
The tool is designed to monitor and control so-called “shadow AI,” which refers to hidden or unauthorized AI applications embedded within corporate software or employed by employees, often without oversight. It prevents the inadvertent uploading of sensitive corporate data to external AI platforms such as Claude or ChatGPT, enforces compliance with corporate policies, and plans to introduce prompt-tracking capabilities that monitor the instructions users provide to AI systems.
Field Effect’s AI product has contributed to a significant growth in the company’s customer base, which has expanded by roughly one-third over four months to 12,000 companies, up from 9,000. The firm’s annualized revenue has almost doubled since last year, approaching $50 million. Holland anticipates adding another 3,000 clients before year-end and aims to raise US$100 million in 2027 to support further expansion. Plans are also underway to offer the AI tool as a standalone service suitable for companies of all sizes.
The development of tools like Field Effect’s occurs amid broader industry concerns about the proliferation of AI applications and the potential risks they pose to organizational security and compliance. Several firms, including Signal 1, Teramind Inc., and Nvidia Corp., are introducing systems to monitor AI use within corporate settings. These solutions serve to ensure AI-generated outputs meet organizational standards, prevent data leaks, and mitigate the risks of rogue AI behavior.
Cybersecurity experts highlight a widespread lack of awareness among organizations about how AI is being used internally and what data it can access. Jeff Farr, CEO of Sera Brynn LLC, which deploys Field Effect products, noted that many clients have been surprised by what their AI monitoring reveals. Similarly, Rob Schenk from Intelligent Technical Solutions described AI as both a security challenge and an emerging source of revenue within the cybersecurity sector, acknowledging that tools like Field Effect’s are accelerating important conversations about AI governance.
Holland’s background traces to his early 2000s tenure with Canada’s elite cyber-espionage unit, where he developed expertise in offensive and defensive cyber operations. After leaving in 2007, he founded Linchpin Labs, providing cyberintelligence software to Canada and its Five Eyes allies before selling the company in 2018. With Field Effect, he has aimed to deliver comprehensive, affordable cybersecurity solutions tailored for smaller businesses, incorporating a “zero trust” approach that verifies actions proactively and guards against unauthorized AI activity.
As organizations continue to integrate AI into their operations, tools like those offered by Field Effect reflect a growing effort within the cybersecurity industry to address both the innovative potential and the emergent risks of this technology.
