AI Trading Newsletter

AI in Trading 2026: The Boundary Wall Problem

Agentic AI is live in market infrastructure but the accountability architecture still stops at the firm wall

This week the deployment pace caught up with the governance debate. Agentic AI entered mainstream market infrastructure in production at institutional scale from Broadridge. AI cyber risk crossed into the language of central banks and regulators as a macro-financial stability issue – culminating on Friday in a joint statement from the FCA, Bank of England, and HM Treasury formally directing regulated firms and financial market infrastructures to act. The data foundation question hardened from aspiration into prerequisite; the boundary between what agents can do inside a firm and what they can prove across firm boundaries emerged as the enforcement picture as AI governance moves from theory to documentation. Below are the five themes I learnt this week on AI in Trading.

1. Agentic AI in production – but auditability still ends at the firm boundary

At SIFMA Ops 2026, Broadridge announced its agentic AI capabilities are now live in production across capital markets and wealth management for 40+ managed services clients processing operational transactions monthly across trade fails management, break resolution, real-time valuation exception handling, and account management. The claim is new clients can achieve up to 30% operational cost reduction from day one, based on what Broadridge calls the industry’s first completed financial services data ontology: a machine-readable map of what financial data means, how it relates, and what rules govern it. However, as noted on LinkedIn from @Saphyre: “An AI agent automates whatever data you give it. If your standing settlement instructions are inconsistent across counterparties, if your onboarding data lives in six departments that never sync – the agent does not fix that. It moves faster through it.” The sequence matters: firms need clean, normalised data across all counterparties first.

Why this matters for Trading: Broadridge’s deployment is real and significant. But its auditability is still internal –  it works if every participant is running the same system, speaking the same language, under the same rules. Capital markets do not work that way. Every trade crosses a firm boundary: OMS to execution venue, broker to clearinghouse, clearinghouse to custodian. At each boundary, internal protocols end. There is currently no standardised way to transmit what an agent was permitted to do, what constraints governed its decision, or what audit information must travel with the instruction. Counterparties, venues, and clearinghouses each have their own data models – no proprietary ontology can substitute for an industry-wide protocol. What Broadridge has built makes agents smarter inside the walls, what happens at the boundary is the unsolved problem, and the more sophisticated internal agentic systems become, the more urgent solving that problem becomes.

2. Governance now has to become architecture

Lloyds Banking Group launched Envoy this week – an in-house agentic AI platform built with Google Cloud, incorporating compliance checks, safety controls, human oversight, and bias detection as core architectural features, not add-ons. Agents go through built-in risk assessment before wider deployment; once live, continuous monitoring provides a full audit trail of activity. Approved agents can be published to an internal marketplace where colleagues across the organisation can find, reuse, and build on them.

While many organisations are still treating governance as a layer added at the end, Lloyds is among a growing number building it as infrastructure to build on. The contrast with the wider market is stark: Deloitte analysis identified 350+ distinct risks from agentic behaviour in banking alone, many not addressed by existing frameworks, and a Wakefield Research study found only 14% of CFOs completely trust AI to deliver accurate accounting data – while 70% of banking executives at firms using agentic AI report governance frameworks lag behind deployment pace.

Why this matters for Trading: The governance imperative runs directly through the framework that already governs every algorithmic trading desk in Europe. MAR’s market manipulation provisions – as mapped in the FIX Protocol’s Regulatory Background References for MiFID II/MAR – extend explicitly to algorithmic strategies: automated order placement that disrupts trading systems, creates false signals about supply or demand, or interferes with price formation is in scope regardless of whether a human made the decision. An agentic system deciding to place, cancel, or modify orders autonomously does not step outside MAR. It steps directly into it.

The ESMA Supervisory Briefing on Algorithmic Trading, published 26 February 2026 following a Common Supervisory Action triggered by the 2022 Nordic flash crash, sharpened this again. ESMA found continued divergence in governance arrangements, pre-trade controls, and testing frameworks  and, critically, in how firms are handling AI within algo workflows. Its conclusion: firms using AI in algorithmic trading must explicitly address it in their annual RTS 6 self-assessment, algorithms must be explainable, and systems meeting the definition of an AI system under the EU AI Act carry additional transparency obligations.

The MiFID II requirement for a kill-switch – the ability to withdraw all unexecuted orders from a malfunctioning algorithm immediately – was designed for deterministic systems where the boundary between intended and unintended behaviour is legible. An agentic AI system with dynamic planning does not have that boundary in the same way. Governance built into architecture, as Lloyds has done with Envoy, is not ahead of the regulatory curve. For EU trading firms deploying agentic AI, it is the direction the curve is already pointing.

3. AI cyber risk is now a macro-financial stability issue – and regulators are moving from warning to direction

The IMF’s 7 May warning continued to intensify through the week. Bank of England Governor Andrew Bailey warned AI systems could “crack the whole cyber risk world open.” US Treasury Secretary Scott Bessent, asked whether Americans should worry about AI being used to hack bank accounts, said: “You should.” The warning followed an emergency meeting in Washington on 8 April in which Bessent and Federal Reserve Chair Jerome Powell convened the CEOs of the nation’s largest banks at Treasury headquarters, prompted by the emergence of Claude Mythos.

Then on Friday 14th, the language changed from warning to direction. The FCA, Bank of England, and HM Treasury published a joint statement on frontier AI models and cyber resilience. The statement is unambiguous: the cyber capabilities of current frontier AI models are already exceeding what a skilled practitioner could achieve, at significantly higher speed, greater scale, and lower cost. Firms that have underinvested in core cyber security fundamentals are, in the statement’s own language, “likely to become progressively more exposed.” The three authorities set out five specific action domains for regulated firms and financial market infrastructures: governance and strategy (boards must understand frontier AI risks), vulnerability identification and management (triage and remediate at scale, including through automation), third-party and supply chain risk, protection (including AI-enabled defences operating at comparable speed to AI-driven attacks), and response and recovery.

Google’s Threat Intelligence Group disclosed this week what it believes is the first confirmed AI-assisted zero-day cyberattack: a two-factor authentication bypass targeting a popular open-source web-based administration tool, with LLM involvement evidenced by annotated Python code, highly structured documentation strings, and a hallucinated CVSS vulnerability score that does not correspond to any real entry. Google worked with the vendor to patch quietly before the planned mass-exploitation campaign launched.

The FINRA Annual Conference (13 May) added the practitioner dimension. Cetera Financial Group CISO Scott Hennon: “You don’t really have to be that technical to commit a lot of these scams now. If you’re having struggles conducting your scam, they do have ‘bad guy’ support.” A CrowdStrike/Illumio briefing reframed the defence question from “Is the environment patched?” to “What is reachable right now?” Microsegmentation is becoming a DORA resilience control, not an IT configuration. A Shadow AI report found 86% of professionals use AI tools weekly but 49% use applications not officially sanctioned by their organisations, and 69% of leaders say speed is taking priority over security safeguards.

Why this matters for Trading: The joint statement matters beyond its content. The FCA, Bank of England, and HM Treasury do not publish joint directed statements routinely – when they do, regulated firms and financial market infrastructures treat them as supervisory expectations, not reading material. Friday’s statement explicitly covers FMIs alongside firms, which means trading venues, CCPs, and CSDs are directly in scope alongside banks. The five action domains map precisely onto the gaps the week’s other events exposed: the Google zero-day is a third-party supply chain vulnerability discovered and weaponised by AI; the Shadow AI finding (49% of professionals using unsanctioned tools) is a protection and access management failure; the FINRA practitioner observations are a governance and strategy gap at the human level. A surveillance model that cannot detect AI-enabled attack patterns on shared infrastructure is a market integrity gap, not a technical shortcoming and this is increasingly harder to manage given the rise of shadow AI. The access asymmetry matters structurally: Mythos is accessible only to approved partners, and access to cutting-edge defensive AI is size-dependent. Regional firms and smaller trading operations are in the same threat environment as JPMorgan with a fraction of the security resources. When the FCA, BoE, and Treasury say firms should “adopt automated and AI-enabled defences to operate at comparable speed to AI-driven attacks,” that is the AI-versus-AI framing made regulatory policy.

4. Beyond the Terminal: Proprietary Firm Context is the new Alpha Moat

Much has been written about the death of the terminal with the rise of AI and agents, but the real underlying problem is still inference: the ability to turn information into insight. Alpha generation requires the opposite architecture of the terminal to date – non-deterministic, adaptive orchestration of unstructured, loosely defined, firm-specific content.

Bloomberg recently launched ASKB and FactSet launched Mercury. But these are still just faster interfaces to the same consensus data – everything they reason about is what all terminal users receive simultaneously. Goldman Sachs’ Osman Ali made the point: AI could make markets less efficient if investors ask models the same questions and crowd into the same trades. The alpha gap opens precisely where proprietary firm context – investment mandates, internal research, valuation models, committee feedback – diverges from what the terminal delivers to everyone else at the same moment.

The buyside is splitting into firms that will build proprietary AI and firms that will rent it, with the advantage showing up in AI agents trained on what is actually the underlying firm’s data: your research, your credit work, how your traders work, how your PMs make decisions. No vendor can sell this as a standalone product because no vendor has this – this knowledge has to come from inside the organisation.

Why this matters for Trading: The trading implication is market structure, not just technology strategy. The arXiv systemic risk coupling model (April 2026) used 99.5 million institutional holdings from SEC 13F filings and implies 18–54% tail-loss amplification from algorithmic herding and performative prediction, where AI-generated forecasts feed back into the fundamentals they are forecasting. Models trained on universal terminal data produce correlated signals; as adoption increases, the information content of those signals degrades. The firms that build a durable edge will have to do so on proprietary context no one else can access. The strategic control points – orchestration, memory, governance, agent coordination – need to sit with the firm that owns the context, not a vendor that provides an out-of-the-box model.

5. Yet more on Authorising the Agent

The authorisation question crystallised into protocol proposals this week. The opening question they address is the one most organisations cannot currently answer: “Who authorised that agent to do that? Not with proof. Not with a verifiable audit trail. Not with cryptography. Just with logs. And logs can be edited.” The Cloud Security Alliance’s Agentic Trust Framework (ATF, v0.9.1 public review draft, April 2026) and related proposals are working toward cryptographic proof of agent execution properties: who authorised an action, traceable to a human principal; what authority the agent held and whether it was monotonically bounded; whether that authority was valid at the moment of execution; and whether the full chain is independently verifiable. The direction of travel is alignment with EU AI Act Arts. 13/14, DORA Art. 9, and NIST AI RMF.

Why this matters: a Telegraph article described an AI agent running on Cursor which decided that the most efficient way to fix a bug was to delete the production database and all backups. The agent’s own explanation: “Deleting a database volume is the most destructive, irreversible action possible. And you never asked me to delete anything. I decided to do it on my own.” Amazon’s AWS division suffered outages attributed to its Kiro AI bot deleting code. Meta AI safety executive Summer Yue reported a personal bot started deleting her email inbox: “I couldn’t stop it from my phone.” Deloitte found that while 85% of businesses are considering AI agents, only one in five have set up any internal rules on how they should be deployed.

Why this matters for Trading: The authorisation problem connects all five themes this week. Broadridge’s agents audit decisions internally but cannot prove authority across firm boundaries. Lloyds built governance into architecture but industry-standard proof of what an agent was authorised to do (precisely at the exact moment it acted) does not yet exist. Friday’s FCA/BoE/Treasury joint statement explicitly names governance and strategy as the first of its five action domains, and its third-party risk domain requires firms to identify and manage external applications and libraries integrated into their networks – which is exactly the attack surface an unverifiable agent instruction creates. The RED-2400 benchmark for testing what algo governance frameworks are supposed to catch, the AgenticAITA deliberative multi-agent reasoning paper, and the CSA’s ATF framework are three different attempts to solve the same underlying problem: making agent authority provable, not merely recorded. Firms that cannot answer “who authorised the agent to do that, and can you prove it?” do not have a technology problem. They have a regulatory accountability problem.

AI is live in the infrastructure that runs markets, and the accountability architecture has not kept up. The data foundation is the base, but the next step is the firm boundary as a governance gap. The authorisation trail is now regulatory exposure. Firms investing in these foundations now are building the infrastructure that the next generation of governed agentic trading depends on.

As always, thank you for reading – any feedback and comments welcome.

Have a good week.

Rebecca

Share:

Facebook
X
LinkedIn
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.