AI Trading Newsletter

AI in Trading 2026: When the implications of the Kill Switch Got Real

The new race for sovereignty, and rethinking how models are used

If last week was about how fast AI adoption is moving – particularly in agentic workflows – this week delivered a short, sharp reality check. Anthropic was forced to abruptly suspend worldwide access to its two newest and most capable models, Fable 5 and the underlying Mythos 5, after a U.S. government export-control directive citing national security barred access by “any foreign national, whether inside or outside the United States,” including Anthropic’s own foreign employees. Because a cloud-served model can’t verify a user’s nationality, “US persons only” collapsed into “nobody, anywhere.” For an industry that spent last week debating how to deploy agents, the lesson was blunt: the ground you’re building on can be pulled out from under you by a decision made in another capital, overnight. For Europe, that hit home hard – our AI economy runs on US discretion. That single event reframes almost everything else that happened. Here’s what else I learnt on AI in Trading this week:

1. Fable Folds – Time to Follow Finland?

The timing was almost satirical. On 11th June a group of European researchers, commentators and VC investor Judith Dada released a science-fiction-style scenario, “Europe 2031”, part of which imagines what happens if the US pulls the plug on European access to frontier AI. Twenty-four hours later, the US government did just that.

The official rationale was a reported jailbreak of Fable 5’s safeguards – the guardrails meant to wall off Mythos’s potent cyber capabilities – but the framing invites hard questions. If a jailbreak genuinely unlocks dangerous cyber or bio capability, that capability is dangerous in anyone’s hands; a vulnerability that lets a model write malware doesn’t become safe simply because the user is American. In its statement, Anthropic said the technique it understood to be at issue surfaced only a small number of previously known, minor vulnerabilities that other publicly available models could also discover, calling the government’s position a misunderstanding. The directive itself came from the U.S. Commerce Department – a letter from Commerce Secretary Howard Lutnick instructing Anthropic to suspend access for any foreign national, which the company said required disabling the models entirely. The “foreign only” carve-out therefore looks less like a safety measure and more like export control – with suspicions of retaliation against Anthropic, given the prior Pentagon “supply chain risk” designation the company is still litigating and its refusals on domestic surveillance and autonomous weapons.

Why this matters for trading: Recent CCAF research flagged how dependent the industry has become on a handful of frontier models and just three cloud providers serving more than 80% of the industry. This episode shows what happens when a single government can switch off a critical service globally, turning model access from a commercial dependency into a geopolitical one. It urgently reignites the sovereignty debate: the ability to keep critical services running even when access depends on another government’s discretion. The Finnish example – building genuine indigenous capability rather than waiting, leaning on EU instruments already in motion (the Cloud and AI Development Act, AI “gigafactories,” an open-source strategy, a Chips Act 2.0) – positions Finland as the model to follow, given its strength across AI, HPC, semiconductors, quantum, telecoms and cybersecurity. The reality for trading desks is simpler: don’t bet your moat on a single frontier provider. Keep smaller open-weight models (Gemma, SLMs) in reserve, so no one jurisdiction becomes a hard dependency.

2. European Coordination Continues Towards a Global Framework

In the UK, the FCA previously confirmed that AI use already sits within existing SM&CR accountability, but this week went further toward understanding how the industry is actually adopting AI, in a speech from Alex Smith, Head of Cross-cutting Policy & Strategy – highlighting the reopening of the AI Input Zone to gather stakeholder evidence on what works and where clarity is needed, which closes on 19 June 2026. Alongside this, Germany announced late Monday that, after its National Security Council assessed the cybersecurity implications of advanced AI models, it will establish a national AI Safety Institute – analysing model performance and risks, and intensifying information-sharing with similar bodies abroad to work toward global standards. That makes Germany the third European country with a government-backed institute after the UK and France, joining a roster that outside Europe includes the US, Canada, Japan, Singapore and South Korea. Will global AI governance finally take off? It’s a hard ask amid the AI nationalism that has countries tying their political, economic and military plans to AI development – but given the latest from the US, institutes like these can at least help on safety standards, research collaboration and ongoing dialogue.

Why this matters for trading: Trading crosses borders. A thickening web of national institutes pushing harmonised standards – alongside international bodies like ISO and IOSCO – points towards an evidentiary bar rather than separate regional demands, but it also raises the floor on what counts as adequate AI governance. The Five Eyes risk taxonomy, published back on May 1st, is a preview of what examiners will expect firms running agentic systems to have controlled for. Firms now need to build infrastructure that satisfies multiple regimes at once, with audit trails and authority models verifiable at execution time – and have to reckon with the implications of agent chains, not just the models inside them.

3. Stochastic Engine, Deterministic Pipeline

Enterprise AI still runs into the same problem – business logic demands deterministic outcomes, but AI models are inherently probabilistic. In traditional software a transaction either clears or fails with a specific error code. Drop an unconstrained LLM into that workflow and you’ve swapped hard-coded instructions for a variable outcome. The common rebuttal – “humans are stochastic too” – misses that human variance is constrained: you can fire a person or sue a vendor, but you can’t sue a roulette wheel. You can’t prompt your way out of statistical probability, and parsing an LLM’s output into tidy JSON isn’t a safety gate – it’s just writing the workflow order neatly. Even the argument for architectural isolation – a deterministic “safety cage” where the AI proposes but hard-coded boundaries enforce the payout – doesn’t guarantee a successful outcome.

Why this matters for trading: This is the growing difference between drift governance (monitoring what happened) and behavioural governance (verifying what’s allowed before it happens). If an agent has authority to rebalance or hedge and its reasoning shifts after a model update, the desk needs to know before positions move, not after. One more for the FIX AI Working Group to add to the proposal currently being debated: agent identity, managing the harness, and just how a deterministic control envelope could optimally work.

4. Still Rethinking Agents

Most teams designing “an agent” are still describing a workflow. If you can map the decision tree, a workflow wins – it’s cheaper, faster and more reliable – and agents should be reserved for genuinely high-value, ambiguous tasks. Cost is one reason. A widely shared analysis showed a coding agent burning ~412,000 tokens to answer a structural question a pre-built knowledge graph answers in ~3,400 – a 99%+ cut – by avoiding the dozens of round-trips you pay for every time. The point isn’t a smarter model; but instead ensuring the agent doesn’t re-read the same files all day. As the author put it, the token bill was never the model – it was the file-by-file habit nobody questioned.

Why this matters for trading: A brilliant model connected to nothing is an analyst locked in a room with no phone and no Bloomberg. Increasingly we are recognising that the edge is not the model; it’s what you’ve plumbed into it – and, in particular – how efficiently. As desks scale agentic research, the cost structure needs to be an architecture decision, not a model decision. Firms treating context retrieval as an engineering problem (index once, query cheaply) rather than brute force (bigger context windows, bigger bills) will run the same workflows at a fraction of the cost – which, at thousands of runs a day, is itself an edge. Let alone before we start taking into consideration the compute costs.

5. How AI is actually being used today

The week’s clearest signal that frontier AI is moving from pilots into core investment workflows: Janus Henderson announced on June 10th it is building a suite of AI-native tools with Percepta, a General Catalyst transformation company building the infrastructure, and Anthropic’s Claude as the model layer. The $480 billion manager is putting Claude at the centre of two purpose-built platforms: PRISM, a global client-intelligence and engagement tool for distribution teams, and LIBROS, a research-management system for investment professionals – with LIBROS synthesising internal and external research alongside public market data so analysts and PMs surface signals faster, and PRISM helping client teams prioritise outreach and prepare tailored communications. Beyond the bespoke tools, the firm is deploying Claude Code for engineering and Cowork across investment, distribution and corporate functions. The integrated, embedded model addresses a problem that has slowed AI adoption in asset management – generic tools rarely fit how an active manager analyses markets, manages portfolios and serves clients. It echoes a broader pattern: Nordea, for instance, has paired a multi-year research partnership with Aalto University with platform-level governance built in before scaling, rolling AI out to around 10,000 employees with compliance treated as a technical property rather than a sign-off bottleneck.

Why this matters for trading: The value isn’t the model – it’s Claude connected to Janus Henderson’s proprietary research, client and market data, with workflows rebuilt around it. That’s engineering embedded inside the business, not software bought off a shelf, and a direct rebuttal to the idea that AI advantage in asset management can be licensed. But note the irony: the same week the industry was reminded that frontier-model access is a geopolitical dependency, one of the world’s largest active managers went all-in on a single frontier provider. The opportunity and the fragility of AI in trading are increasingly becoming the same story.

The infrastructure shift is showing up at the market-structure level too. Morgan Stanley opened its workplace wealth platform to external AI agents, letting corporate clients’ agents pull data and act directly – bypassing the human interface but not, crucially, the CFO’s liability for who authorised the agent, who owns its instructions, and who certifies its outputs at audit. And ICE launched ICE Compass, an AI-powered analytics platform giving buy-side fixed-income desks ranked counterparty recommendations and pre-trade price estimates, with T. Rowe Price signing on as anchor client. As one observer put it, a firm with serious execution standards signing on isn’t a publicity gesture – it’s validation that the tool produces actionable intelligence. The platforms are opening to agents; the accountability structures around them mostly aren’t yet.

Thanks for reading,

Rebecca

Share:

Facebook
X
LinkedIn
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.