Getting to Know your (AI) Agent

Monday, 17/08/2026 | 13:00 GMT by Adonis Adoni
  • Without agentic trading legislation, lawyers, regulatory experts and brokers discuss a key question: who is liable if an agent misfires?
  • Robinhood tells Finance Magnates that “customers are solely responsible for how the agents are built and any resulting actions the agents take.”
  • It is, though, unlikely for regulation to shift the blame completely on the trader, with future "Know Your Agent" rules adding compliance costs for firms.
Agentic trading MCP tutorials
YouTube tutorials to connect agents with trading accounts abound. (Source:Peter Müller-Traders Meta)

It has been only six months since brokers started connecting AI agents to their platforms, so expecting regulation to arrive already would be optimistic, if not premature. It is, however, brewing. The Bank of England Deputy Governor Sarah Breeden, during a Q&A at the European Central Bank Forum in Portugal in June, noted that human-in-the-loop safeguards, where someone can review, approve or change the automated action, are unrealistic for the speed of agentic trading.

Instead, among other things, they are thinking about kill switches and circuit breakers, tried-and-true safeguards in algorithmic trading. Until then, the question remains: Who pays when the agent goes rogue?

No Clear Direction Yet

“The reality is,” says Nauman Anees, CEO and co-founder of ThinkMarkets, “there is no AI governance or rules and any would be difficult, to say the least, to implement and enforce.”

Nauman Anees, co-founder and CEO of ThinkMarkets
Nauman Anees, co-founder and CEO of ThinkMarkets

The multi-regulated broker was an early mover, releasing Chelsea AI in June. Chelsea is the plug-in that enables Claude, Gemini, ChatGPT and so on, to take over a trader’s brokerage account. Many have followed, including Robinhood, IG Group and eToro.

Most crucially, MetaQuotes and Spotware, which combined own most of the third-party infrastructure layer of the industry, have their own versions. Spinning up these plug-ins has become easy.

In the EU, the clearest regulatory direction so far was a February supervisory Briefing by ESMA, which covered what it called “AI-based algorithmic trading systems”.

If they are AI systems, they will need to comply with the EU AI Act’s requirements, which in itself is not exactly clear on agentic trading. For one, it does not have a separate category for agents.

Neither ESMA nor the Act have really wrapped their heads around it just yet.

It’s worth mentioning that the UK’s Financial Conduct Authority published the Mills Review in July, which detailed how AI will reshape the financial services sector by 2030. Although the report explicitly discussed agentic AI and its potential to steer consumers' financial choices, it did not have a direct reference to agentic trading.

Better Safe Than Sorry

The reality is that agentic trading is still young. It is messy, unpredictable and requires an adult. Recent contests involving public, real-money AI trading where leading models, from OpenAI to Alibaba, were tasked with trading equities, crypto and so on, most models lost money, traded too much and gave wildly different decisions even when given the same instructions.

It’s no surprise regulators are struggling to put it in a box, or that brokers have not given the agent the keys to the castle.

Robinhood released AI Agent Accounts in July. In a month, out of some 14 million active users on the trading platform, it piqued the interest of at least 50,000.

“We’ve built a number of safeguards to enable customers to limit the capital and assets the agent can access, give them visibility into their agent’s actions and let them quickly disconnect the agent if anything looks off,” a Robinhood spokesperson tells Finance Magnates.

Other safeguards include spending controls, limited account access, the ability to instantly disable the agents and fraud detection.

“If a trade or payment looks off, the company’s support team can review exactly what you asked the agent to do, see what it actually did, and help you quickly resolve any disputes,” Robinhood explains.

There is also a human-in-the-loop button for good measure; someone can opt in to manually approve every credit card purchase before it goes through.

“When appropriate, agents will preview orders with customers whenever they ask to place a trade so customers can see all the details of the order before it’s processed. But ultimately, customers are solely responsible for how the agents are built and any resulting actions the agents take,” says the Robinhood spokesperson.

“If You Give the AI Agent Permission, You Are Responsible”

Sophie Gerber, the co-founder and CEO of TRAction, an Australian regulatory reporting services company, echoes that sentiment. “If a retail trader wants to install an AI agent to do their trading with, I cannot see an issue with this,” Gerber notes. “However, the person who installed the AI agent to carry out trading is still going to be responsible for the conduct of that agent.”

Someone can’t cry foul just because they used an AI agent. “If you give the AI agent permission, you are responsible for its actions as though you did it yourself,” Gerber adds.

Sophie Gerber, co-founder and CEO, TRAction

After all, even current regulatory frameworks don’t guarantee trading performance.

Other brokers and platform providers have also added their own safeguards, from carving out separate accounts to prohibiting access to wallets, all of which aim to do one thing: limit what the plug-in allows the trader to do.

One way to read these controls is that the industry expects, and rightfully so, that when the regulatory fence emerges, it will not be entirely privatised.

And current literature might have some clues as to how tall that fence will be.

When Are Brokers Liable? It’s Complicated.

Christiana Aristidou, the founder and Managing Partner of the Hybrid LawTech Firm, explains that besides not having a separate category for agents, the AI Act does not classify AI-based algorithmic trading as a high-risk use case.

“This position, though,” she warns, “is not necessarily permanent.”

If the level of market-wide damage proves to be high, there would be updates, tailored legislation, the works. One of the systemic risks that seems to bother regulators is herding behaviour. Bank of England’s Deputy Governor said as much in the conference; agents can follow each other and do the same thing at the same time much faster than any system before.

It’s not an unfounded fear: From ten major brokers and platforms that have enabled MCPs, nine allow Claude.

Then there is DORA, the extra steps Brussels forced financial firms to take against cyber threats. Aristidou says brokers would need to assess the MCP connector, agent-access layer and supporting vendors within the scope of the framework.

This might be less of a worry for now, though, as regulators are being uncharacteristically patient with enforcement.

There are also market abuse considerations, particularly if an AI agent can generate manipulative trading patterns, or even the perception thereof, without being explicitly told to do so.

“The AI did it,” says Aristidou, “is not a defence to inadequate surveillance.”

Obligations Not Excluded

What it boils down to, Aristidou notes, is the controls on the agent. Some cases could fall under current algorithmic trading rules, like when an agent is allowed to determine price, quantity, timing, order type or any other trading parameter.

Christiana Aristidou, founder and Managing Partner, The Hybrid LawTech
Christiana Aristidou, founder and Managing Partner, The Hybrid LawTech Firm

The agent, though, is to algo what the smartphone is to the rotary phone; there are plenty of cases outside of what was understood about algorithmic trading. So, at the moment, most of that control will continue to fall squarely on the risk and engineering teams inside brokers and platforms.

This includes identifying the functions that are performed across the board, setting up pre-trade and real-time controls, stress-testing beyond algo to find misunderstood natural language prompts and making sure there’s compliant execution.

The latter, she says, “will become particularly important where an agent favours products generating higher commission, payment for order flow spread revenue, token investment or other benefits for the platform.”

There should also be clear-cut communication.

Know Your Agent

One common thread to shield against potential, and arguably inevitable, litigation is Terms & Conditions: explaining what the agent does, how it misbehaves, limits and kill mechanisms and so on.

These are strong enough, Gerber says, that it is “very unlikely, even based on current T&Cs, an AI agent's trades can somehow not be considered valid trades.” If and when a disputed scenario arises, you can expect those documents to change and account for it.

In case of litigation, Aristidou says that the decisive question may not initially be who is liable, but whether anyone can reconstruct what happened.

To be defensible, a system would then need to maintain the full chain of decision-making and execution: the user’s original mandate, data and context supplied, broker-side controls, warnings, blocks, overnights and so on. Can everyone involved reliably prove the authority of the agent, which version acted, what controls were applied and the conduct departed from the authorised mandate?

“This is more than conventional explainability. It is decision provenance and evidential integrity,” she says.

Aristidou predicts that legislation might borrow a few things from Web3 principles, like tamper-evident logs, cryptographic attestations and verifiable agent credentials. “It will become a normal part of financial-market infrastructure,” she expects.

So, Know Your Agent will be next to Know Your Customer.

Inevitably, that would lift the control off the companies’ shoulders. In exchange, it would add compliance costs.

“The Days of Staring at the Charts Are Going Away”

According to Anees, most people now use ThinkMarket’s Chelsea AI for analysis and research, but there’s been an uptick in generated trading volume. He expects it to grow. More so, he believes anyone who doesn’t adapt now will be faced with siloed systems and a dramatically lower market for users. They would be left behind.

“The days of staring at the charts are going away,” Anees says.

For how many traders this will be true remains to be seen. The future could be hybrid, where traders continue to use AI agents for research and analysis but don’t completely upend the way they interact with the markets.

It could also come to pass that agentic trading is strong enough to swallow the market. Brussels, London and their peers would then classify agents as a major threat and the cost will be proportional, or disproportional, depending on which side of compliance you are on.

Aristidou expects that in agentic finance, responsibility will increasingly follow capability, control and the ability to prevent harm, not the software or the protocol. If that’s the case, the regulatory noose will be tight enough that it could stifle.

At the end of the day, the ultimate question might not even be who to blame, but how much blame would cost.

It has been only six months since brokers started connecting AI agents to their platforms, so expecting regulation to arrive already would be optimistic, if not premature. It is, however, brewing. The Bank of England Deputy Governor Sarah Breeden, during a Q&A at the European Central Bank Forum in Portugal in June, noted that human-in-the-loop safeguards, where someone can review, approve or change the automated action, are unrealistic for the speed of agentic trading.

Instead, among other things, they are thinking about kill switches and circuit breakers, tried-and-true safeguards in algorithmic trading. Until then, the question remains: Who pays when the agent goes rogue?

No Clear Direction Yet

“The reality is,” says Nauman Anees, CEO and co-founder of ThinkMarkets, “there is no AI governance or rules and any would be difficult, to say the least, to implement and enforce.”

Nauman Anees, co-founder and CEO of ThinkMarkets
Nauman Anees, co-founder and CEO of ThinkMarkets

The multi-regulated broker was an early mover, releasing Chelsea AI in June. Chelsea is the plug-in that enables Claude, Gemini, ChatGPT and so on, to take over a trader’s brokerage account. Many have followed, including Robinhood, IG Group and eToro.

Most crucially, MetaQuotes and Spotware, which combined own most of the third-party infrastructure layer of the industry, have their own versions. Spinning up these plug-ins has become easy.

In the EU, the clearest regulatory direction so far was a February supervisory Briefing by ESMA, which covered what it called “AI-based algorithmic trading systems”.

If they are AI systems, they will need to comply with the EU AI Act’s requirements, which in itself is not exactly clear on agentic trading. For one, it does not have a separate category for agents.

Neither ESMA nor the Act have really wrapped their heads around it just yet.

It’s worth mentioning that the UK’s Financial Conduct Authority published the Mills Review in July, which detailed how AI will reshape the financial services sector by 2030. Although the report explicitly discussed agentic AI and its potential to steer consumers' financial choices, it did not have a direct reference to agentic trading.

Better Safe Than Sorry

The reality is that agentic trading is still young. It is messy, unpredictable and requires an adult. Recent contests involving public, real-money AI trading where leading models, from OpenAI to Alibaba, were tasked with trading equities, crypto and so on, most models lost money, traded too much and gave wildly different decisions even when given the same instructions.

It’s no surprise regulators are struggling to put it in a box, or that brokers have not given the agent the keys to the castle.

Robinhood released AI Agent Accounts in July. In a month, out of some 14 million active users on the trading platform, it piqued the interest of at least 50,000.

“We’ve built a number of safeguards to enable customers to limit the capital and assets the agent can access, give them visibility into their agent’s actions and let them quickly disconnect the agent if anything looks off,” a Robinhood spokesperson tells Finance Magnates.

Other safeguards include spending controls, limited account access, the ability to instantly disable the agents and fraud detection.

“If a trade or payment looks off, the company’s support team can review exactly what you asked the agent to do, see what it actually did, and help you quickly resolve any disputes,” Robinhood explains.

There is also a human-in-the-loop button for good measure; someone can opt in to manually approve every credit card purchase before it goes through.

“When appropriate, agents will preview orders with customers whenever they ask to place a trade so customers can see all the details of the order before it’s processed. But ultimately, customers are solely responsible for how the agents are built and any resulting actions the agents take,” says the Robinhood spokesperson.

“If You Give the AI Agent Permission, You Are Responsible”

Sophie Gerber, the co-founder and CEO of TRAction, an Australian regulatory reporting services company, echoes that sentiment. “If a retail trader wants to install an AI agent to do their trading with, I cannot see an issue with this,” Gerber notes. “However, the person who installed the AI agent to carry out trading is still going to be responsible for the conduct of that agent.”

Someone can’t cry foul just because they used an AI agent. “If you give the AI agent permission, you are responsible for its actions as though you did it yourself,” Gerber adds.

Sophie Gerber, co-founder and CEO, TRAction

After all, even current regulatory frameworks don’t guarantee trading performance.

Other brokers and platform providers have also added their own safeguards, from carving out separate accounts to prohibiting access to wallets, all of which aim to do one thing: limit what the plug-in allows the trader to do.

One way to read these controls is that the industry expects, and rightfully so, that when the regulatory fence emerges, it will not be entirely privatised.

And current literature might have some clues as to how tall that fence will be.

When Are Brokers Liable? It’s Complicated.

Christiana Aristidou, the founder and Managing Partner of the Hybrid LawTech Firm, explains that besides not having a separate category for agents, the AI Act does not classify AI-based algorithmic trading as a high-risk use case.

“This position, though,” she warns, “is not necessarily permanent.”

If the level of market-wide damage proves to be high, there would be updates, tailored legislation, the works. One of the systemic risks that seems to bother regulators is herding behaviour. Bank of England’s Deputy Governor said as much in the conference; agents can follow each other and do the same thing at the same time much faster than any system before.

It’s not an unfounded fear: From ten major brokers and platforms that have enabled MCPs, nine allow Claude.

Then there is DORA, the extra steps Brussels forced financial firms to take against cyber threats. Aristidou says brokers would need to assess the MCP connector, agent-access layer and supporting vendors within the scope of the framework.

This might be less of a worry for now, though, as regulators are being uncharacteristically patient with enforcement.

There are also market abuse considerations, particularly if an AI agent can generate manipulative trading patterns, or even the perception thereof, without being explicitly told to do so.

“The AI did it,” says Aristidou, “is not a defence to inadequate surveillance.”

Obligations Not Excluded

What it boils down to, Aristidou notes, is the controls on the agent. Some cases could fall under current algorithmic trading rules, like when an agent is allowed to determine price, quantity, timing, order type or any other trading parameter.

Christiana Aristidou, founder and Managing Partner, The Hybrid LawTech
Christiana Aristidou, founder and Managing Partner, The Hybrid LawTech Firm

The agent, though, is to algo what the smartphone is to the rotary phone; there are plenty of cases outside of what was understood about algorithmic trading. So, at the moment, most of that control will continue to fall squarely on the risk and engineering teams inside brokers and platforms.

This includes identifying the functions that are performed across the board, setting up pre-trade and real-time controls, stress-testing beyond algo to find misunderstood natural language prompts and making sure there’s compliant execution.

The latter, she says, “will become particularly important where an agent favours products generating higher commission, payment for order flow spread revenue, token investment or other benefits for the platform.”

There should also be clear-cut communication.

Know Your Agent

One common thread to shield against potential, and arguably inevitable, litigation is Terms & Conditions: explaining what the agent does, how it misbehaves, limits and kill mechanisms and so on.

These are strong enough, Gerber says, that it is “very unlikely, even based on current T&Cs, an AI agent's trades can somehow not be considered valid trades.” If and when a disputed scenario arises, you can expect those documents to change and account for it.

In case of litigation, Aristidou says that the decisive question may not initially be who is liable, but whether anyone can reconstruct what happened.

To be defensible, a system would then need to maintain the full chain of decision-making and execution: the user’s original mandate, data and context supplied, broker-side controls, warnings, blocks, overnights and so on. Can everyone involved reliably prove the authority of the agent, which version acted, what controls were applied and the conduct departed from the authorised mandate?

“This is more than conventional explainability. It is decision provenance and evidential integrity,” she says.

Aristidou predicts that legislation might borrow a few things from Web3 principles, like tamper-evident logs, cryptographic attestations and verifiable agent credentials. “It will become a normal part of financial-market infrastructure,” she expects.

So, Know Your Agent will be next to Know Your Customer.

Inevitably, that would lift the control off the companies’ shoulders. In exchange, it would add compliance costs.

“The Days of Staring at the Charts Are Going Away”

According to Anees, most people now use ThinkMarket’s Chelsea AI for analysis and research, but there’s been an uptick in generated trading volume. He expects it to grow. More so, he believes anyone who doesn’t adapt now will be faced with siloed systems and a dramatically lower market for users. They would be left behind.

“The days of staring at the charts are going away,” Anees says.

For how many traders this will be true remains to be seen. The future could be hybrid, where traders continue to use AI agents for research and analysis but don’t completely upend the way they interact with the markets.

It could also come to pass that agentic trading is strong enough to swallow the market. Brussels, London and their peers would then classify agents as a major threat and the cost will be proportional, or disproportional, depending on which side of compliance you are on.

Aristidou expects that in agentic finance, responsibility will increasingly follow capability, control and the ability to prevent harm, not the software or the protocol. If that’s the case, the regulatory noose will be tight enough that it could stifle.

At the end of the day, the ultimate question might not even be who to blame, but how much blame would cost.

About the Author: Adonis Adoni
Adonis Adoni
  • 84 Articles
  • 2 Followers
About the Author: Adonis Adoni
Adonis Adoni is a News Editor at Finance Magnates, with more than six years of experience covering the financial services industry, technology, and their intersection. His work includes C-suite interviews with leading technology and fintech companies across Europe, the US and Asia, exclusive coverage of M&A activity and capital raising, and data-driven industry reporting, with a strong emphasis on engagement and clear storytelling. Areas of Coverage: Online trading industry news Fintech companies Digital assets and crypto markets Regulatory and compliance developments Executive interviews Education: BA in Law – Nottingham Trent University LLM in Health Law – Nottingham Trent University
  • 84 Articles
  • 2 Followers

More from the Author

Retail FX

!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|} !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}