AI Trading Newsletter

AI in Trading 2026: Who Controls the Agent?

From model risk to trajectory risk – the move to governing just what agents are allowed to do

Building on last week’s TradeTech note, the debate continues to move from “how do we use AI?” to “what happens when AI becomes part of the execution, data, risk and control stack?” The regulatory signals, research, and market developments this week are all beginning to point in the same direction. Here’s what I learnt this week on AI in Trading:

1. AI agents are the new day traders – and regulators will notice

Bloomberg this week reported that retail traders are training AI agents to trade across equities, crypto, and prediction markets. Open-source platforms such as OpenClaw allow anyone to instruct an agent through WhatsApp – no technical background required. One profiled trader spent two weeks teaching Claude his risk appetite and entry signals before setting it loose on a $100k simulated account. It returned 7% over 30 days against an S&P gain of 4.5% – but only after he repeatedly overrode its default caution to push it toward riskier trades. His own verdict: “Anybody could do that with dumb luck on options.” Read more here.

Why this matters for trading: the 1990s day trader parallel is a good example – increasing retail flows, correlated behaviour, and eventual regulatory scrutiny. AI agents will compress that timeline considerably. Flow becomes more systematic and concentrated, clustering around opens, closes, and rebalancing events. The 0DTE options market already shows what correlated short-horizon retail positioning looks like at scale. Add agents operating continuously across thousands of participants on similar signals, and the market structure implications are not theoretical. Regulators who have spent two years focused on institutional AI deployment now have a much more visible retail dimension to contend with.

2. The volatility regime has already shifted – and agent governance hasn’t caught up

The retail agent story also raises a harder structural question: what happens when thousands of agents run on similar signals simultaneously in markets whose volatility characteristics have already changed? VIX regimes have shifted materially over the past decade – higher floors, bigger swings – with algorithmic and ML-driven trading a contributing factor. Historical backtests built on pre-2020 data are increasingly inadequate as a governance foundation.

New research from Zhuohan Wang and Carmine Ventre at King’s College London could provide a solution. DiffLOB proposes a regime-conditioned diffusion model that generates synthetic LOB trajectories under counterfactual market states – liquidity shocks, volatility spikes, trend reversals, order-flow imbalance – enabling firms to stress test how order books would evolve under conditions never historically observed. Read more here.

Why this matters for trading: current algo governance asks whether a strategy performed well on historical data. Agentic governance needs to ask whether an agent remains controllable under plausible future regimes it has never seen. That is a fundamentally different certification question – and tools like DiffLOB point toward what answering it could look like in practice. The open question is whether governance infrastructure can be built fast enough to keep pace with deployment.

3. “I did not understand it” is not a defence

The FCA, Bank of England, and HMT published their formal responses to the Treasury Select Committee’s AI in Financial Services report on 16 April. The Bank of England’s Financial Policy Committee has specifically tasked both institutions with further work on agentic AI in payments and financial markets – not AI generally, but agents. HMT declined to commit to designating major AI and cloud providers as Critical Third Parties before end of 2026, despite the Committee’s explicit recommendation. Read more here.

In the October oral evidence sessions that preceded these responses, FCA Executive Director David Geale was direct: senior managers are “on the hook” for harm caused through AI, SM&CR applies without needing a new function, and as models get more sophisticated and self-learn, somebody has to be accountable for the deployment of the technology. The message is clear: “I did not understand it” is not a defence. Read the oral evidence here.

Why this matters for trading: the FPC’s specific instruction to examine agentic AI in financial markets signals that the retail trader story and the institutional governance story are the same conversation. Whether the agent is deployed by a systematic fund, an execution desk, or a retail trader on WhatsApp, regulators are now formally asking identical questions: who authorised it, under what constraints, and who is accountable when it causes harm? Firms that moved fast without building that accountability layer are accumulating a risk they have not yet priced.

4. The real competitive edge is not the model – and lighter regulation is not the answer

A contribution to the Forum on Financial Supervision by David Cabral, a senior Bank of England advisor, makes the argument that competitive advantage in AI is not who has the most advanced model or the most permissive regulatory regime – it is who builds the organisational and data infrastructure to deploy AI at industrial scale, across hundreds of workflows, at low marginal cost. He uses Ping An as the example: its edge is not frontier models – it is pervasive production deployment that compounds over time. That is the capability Western firms, including in financial services, are struggling to replicate. Read more here.

Requirements become burdensome when treated as compliance checks applied after a proof of concept. The picture changes when controls are embedded from the outset – governance becomes part of the infrastructure rather than a constraint on it. The UK already has a permissive framework. Firms not moving are not held back by regulation – they lack the foundations that make deployment safe at scale.

Why this matters for trading: if humans working alongside AI systems systematically defer to those systems even when wrong the quality of upstream human judgment, the one control firms are relying on, is itself compromised. The governance challenge is not only technical. It is about designing processes that preserve genuine expert challenge at the points where it matters, built into the workflow from the start, not added afterward.

5. The control layer is the new competitive edge

Two market developments this week illustrate where advantage is actually forming. Citi’s Arc platform, now rolling out internally, is a controlled orchestration layer for AI agents across the bank – with embedded monitoring, permissioning, and kill-switch capability across portfolio data, market trend analysis, and scenario testing. Arc is not evidence of agentic trading in production. It is the control infrastructure being built ahead of it: supervision shifting from algo IDs and FIX tags toward agent identity, entitlements, and permissible actions across the trading stack. Read more here.

Bloomberg’s 2026 ASKB roadmap makes the same point from a different direction. The platform is explicitly multi-model – with BloombergGPT absent from any production use. The durable advantage is not the model; it is the data graph, entity linkages, orchestration layer, and integration into PORT and RMS. Vendor lock-in is shifting from terminals to integrated data and agent workflows. Read more here.

Why this matters for trading: the competitive layer in execution has never been the fastest algorithm – it has been who controls the routing logic and information advantage around it. The same is now true for AI. As we explored in the papers – permissioning, audit trails, kill-switch design, and entitlement boundaries are becoming strategic control points. The firms that win will not be those that deployed agents fastest – they will be those that can prove, systematically, that their agents behave within defined, testable, and enforceable boundaries before they reach the market.

The thread running through all of this is consistent. The retail trader with an agent on WhatsApp, the bank building an internal orchestration platform, and the regulator asking who is accountable when automation causes harm are part of the same structural shift. The control layer is becoming the new market structure. Risk is moving upstream from execution errors to decision formation and infrastructure design. And governance has to become executable – embedded into systems and workflows, not documented alongside them.

As David Cabral’s argument makes clear, that starts not with compliance frameworks but with the organisational and data infrastructure that makes safe deployment possible in the first place. The window to build that foundation before regulatory expectations harden is narrowing – but it is still open. For now.

As always, thank you for reading – any comments or feedback very welcome.

Rebecca

Share:

Facebook
X
LinkedIn
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.