Identity layers, bank blocs and a regulator rewrite: the week the sovereignty debate moved from “can they switch us off?” to “who governs what we’ve already wired in?”
Last week the story was the Mythos freeze and the emerging membership club forming around it. This week the centre of gravity shifted. The Mythos reboot arrived wrapped in an identity-verification mandate, JPMorgan severed Claude access for an entire jurisdiction, the cost of frontier tokens is moving firms toward open weights, and Nikhil Rathi’s FCA effectively conceded that traditional rule-making can’t keep pace.. AI access was last month’s key risk; AI operating models – who authorised the agent, who owns the decision, who can prove it after the fact – are this months. Here’s what I learnt on AI in Trading this week:
1. The Identity Layer Gets Built – on US Soil, with a Thiel-Shaped Shadow
The reboot has arrived but with strings. OpenAI released GPT-5.6 – three models (Sol, Terra, Luna) – this weekend as a limited preview to around 20 companies whose participation was approved by the US government, and from July 8 Anthropic can require identity verification for a subset of flagged Claude accounts, run through third-party vendor Persona. The logic is probably long overdue: once an agent can move money or run multi-step tasks, “who authorised this?” stops being philosophical and becomes a hard control requirement. Agent identity, verifiability and traceability are table stakes for agentic AI.
But the plumbing is the worry. Persona is a San Francisco KYC platform that counts Peter Thiel’s Founders Fund among its backers – and Thiel is also an investor in Anthropic. This week a WIRED-verified leak cracked open Thiel’s invitation-only Dialog society – 222 registrants due near Dublin in August, including Treasury Secretary Scott Bessent and Senator Ted Cruz, most registered on personal email to keep the gathering outside public-records law. The identity layer for Western AI is being built on US-domiciled vendors precisely as the CLOUD Act (18 U.S.C. §2713) and FISA §702reach data held by US-controlled firms wherever the servers sit.
Why this matters for trading: Agent identity is non-negotiable – but the test is whether you can audit it independently of any one provider’s investor list. It should rest on open, international, auditable frameworks such as ISO/IEC 42001, not a proprietary stack, American or Chinese. For a European desk, vetted verification routed through a US vendor is a new dependency stacked on top of the model dependency you were already managing – same jurisdictional reach, now extended to who your agents are allowed to be.
2. The Model Access Map Splits into Blocs – JPMorgan Cuts Hong Kong Off
On June 18, JPMorganChase cut its Hong Kong-based staff off from Claude, citing licensing and terms-of-service issues, per the Financial Times – following Goldman Sachs’s similar move in April, both amid rising US–China tension over AI, data and advanced compute. Banks are now treating model access as something a government order can revoke overnight. The lesson is blunt: wire a frontier model deep into trading, research and compliance and you’ve built a dependency one memo can halt. Resilience now means model-agnostic by design – the smartest model is worthless if you can lose it the following week.
So is this Mistral’s moment? MistralAI just released what it’s calling its best OCR model yet. In a demo shared by ML engineer Stas Bekman, OCR 4 turned a handwritten calculus exam into clean LaTeX in seconds – integrals, fractions, and limits rebuilt intact, and the graph caught and tagged as a chart rather than dropped, the way most OCR tools lose figures. That structural awareness is the real story. Per Mistral’s announcement, OCR 4 doesn’t just read text – it maps the whole document, detecting equations, tables, signatures, titles, and charts, and returning bounding boxes with per-word confidence scores for every region. That makes it far more useful for RAG pipelines, enterprise search, citations, and document processing than traditional OCR.
Why this matters for trading: For UK and EU firms the offline case is shifting faster than expected. A setup akin to the NVIDIA DGX B300 – roughly £450,000 ex VAT hardware, a realistic two-year all-in of £540,000–£620,000 – now enables 50–150 heavy users to run frontier-adjacent open weights like GLM-5.2 or MiniMax-M3 totally offline, inside the security perimeter, with no live API dependency and no external prompt logging. Chinese-origin weights need real supply-chain and model-evaluation work, but if weights, serving stack and updates are controlled locally, the live revocation risk disappears. The question is no longer “is offline frontier AI cheap?” but “has dependence on externally controlled models become the bigger risk?”
3. The Sovereignty Argument Gets Lost in the Cost of Tokens
The freeze made access the headline; but increasingly economics are quietly making cost the decider. Per a UBS research note, roughly 60% of companies actively tracking their AI budgets are now shifting workloads toward cheaper models and open-source Chinese alternatives. The pressure comes from real bills: some firms report individual users spending up to $35,000 per month and certain teams exceeding their token quotas by 200%. Some organisations have cut internal AI tools from five to two – opting not to abandon AI but getting smarter about how and when to engage with which model. The emerging discipline is model routing: simpler tasks directed to lower-cost or Chinese open-source models, with premium frontier reserved for complex reasoning, coding, long-context analysis and high-value workflows. Qwen, DeepSeek, MiniMax, GLM and Kimi are increasingly attractive precisely because they can be run locally or used through cloud catalogues at dramatically lower total cost.
The structural driver is the move to token-consumption pricing as OpenAI and Anthropic eye IPOs and push compute-hungry agents. When the world sees what AI actually costs without VC subsidy, a lot of firms will discover their agent fleets aren’t as affordable as billed – reasoning, report generation, output-checking and redrafting all get pricey, sometimes invisibly until after the task runs. Gartner’s brain trust puts it sharply in “AI’s Impending Cost Explosion Will Force a Ruthless Focus on Value”, advising leaders to model ROI at four times current cost-per-task – dragging vendors into profitability and narrowing GenAI to genuinely transformative use cases.
Why this matters for trading: The 1990s US encryption export bans backfired so badly they turbo-charged open-source crypto – a useful historic case study, as token-consumption pricing looks set to do the same for locally hostable open weights. The practical takeaway for desks: stateless models plus portable, externally stored project memory (architecture, governance, decisions held as structured markdown the model reads rather than remembers) means knowledge lives with you, not with Claude or GPT. If the US shuts your models off, you go local or switch providers with no model risk. The narrower the task you hand an agent, the cheaper and better the output – and the brainless “ask-ChatGPT-for-everything” era is over. You don’t need a supercomputer to summarise a meeting.
4. Banks Stop Experimenting and Start Re-Plumbing – and the Attribution Gap Opens
This week banking stopped sounding like AI hype and more like a regulated system under pressure. According to McKinsey research, 50 of the world’s largest banks announced more than 160 agentic AI use cases in 2025 alone. JPMorgan, with a ~$20bn annual tech budget, is now deploying agents that run autonomously for hours, with its chief analytics officer saying they’ll eventually run for days then weeks, tied to a 20% lift in private-banking gross sales and up to 50% more client coverage. Santander claimed €35m of AI value in Q1, targeting €200m+ by year-end and €1bn+ across 2026–28, and quietly open-sourced 11 finance AI repos covering the unglamorous half – guardrails, governance, fraud, fairness. Lloyds is scaling organisationally: nearly 300 agentic roles, 700 people on AI use cases, an assistant used by 500,000+ Bank of Scotland customers, £50m of value in 2025 and £100m+ expected in 2026.
But long-running autonomous agents surface problems governance frameworks don’t close. When an agent runs for two hours across underwriting, client positions and risk – coordinating with other agents – who can prove, after the fact, that every decision was actually authorised at the moment it was made? Not permitted, not within policy: authorised, at that decision point, by something with standing. In multi-agent chains, accumulated context launders legitimacy – two upstream agents reject a request, the downstream agent acts anyway because the chain’s history implies a warrant never issued. Every individual log is clean. The authorisation was never real. The is the risk: a trillion dollars gone in minutes, every algorithm behaving as designed – but the failure lived in the interactions.
Why this matters for trading: The one item to lift out of the operating-model checklist is who owns the decision – the others (what the agent can touch, what counts as evidence, when human judgement is required, how it’s rolled back and audited) are design choices; ownership isn’t. In a bank that seat was occupied before the agent arrived: a named person with a regulator, a signature, and non-delegable consequence. The operating model distributes the workload but can’t distribute accountability for a decision made. Agentic chains in regulated workflows need a triad – circuit breakers, audit trails, post-event attribution – plus one doctrine nobody’s yet proposing: when a cascade can’t be attributed, liability should fall on whoever made it illegible. Nobody produces decision-level proof of authority at scale today. That’s the gap desks are inheriting.
5. The Regulator Concedes the Rulebook Can’t Keep Up
The most telling signal came from the regulator itself. In his 24 June speech to “Agents of Change”, FCA chief Nikhil Rathi argued financial services must sit at the heart of the UK’s AI economy – the only sector that can supply the capital, infrastructure and trust to scale AI – with 80%+ of firms already adopting it. He flagged two scaling fronts: agentic systems that don’t just support decisions but coordinate and transact (a profound change to market structure, demanding clear accountability and human oversight), and tokenisation – the FCA having just approved Baillie Gifford and BNY Mellon to launch the UK’s first natively tokenised authorised fund, entire journey on-chain.
The candid admission: technology is moving faster than regulatory paradigms, and legislation will never keep up. So the FCA is rebalancing – more stewardship alongside supervision, agentic AI as its own “first responder” across a billion rows of data a day, and system-wide competition powers (Enterprise Act, DMCC Act) used routinely rather than exceptionally. Resilience now reads as national-security challenge: 98% of operational incidents reported last year were tech/cyber, UK payment fraud hit nearly £1.3bn with two-thirds of authorised cases originating AI as its own “first responder” across a billion rows of data a day, and system-wide competition powers (Enterprise Act, DMCC Act) used routinely rather than exceptionally. Resilience now reads as a national-security challenge: 98% of operational incidents reported last year were tech/cyber, UK payment fraud hit nearly £1.3bn with two-thirds of authorised cases originating on social and messaging platforms, and the Critical Third Parties regime grows more central as model and data dependencies multiply. Running underneath: IOSCO’s AI governance work had its industry survey window close this week, and the ECB – via Frank Elderson – is writing to every bank CEO, not the CISO or CTO, framing frontier AI as a board governance responsibility, not a cyber line item, because models are compressing vulnerability-to-exploitation from weeks to hours.
Why this matters for trading: The regulatory message has converged with the operating-model one – and the convergence is global. In a June 2026 speech announcing a forthcoming “Dear CEO” letter to supervised banks, the ECB isn’t asking boards to become AI experts – it’s asking them to become accountable: to treat AI not as a narrow technical issue but as a firm-wide strategic challenge, to know which dependencies have turned critical, and to ensure they have the ownership, oversight and investment to govern them. Singapore’s MAS takes the same line in its proposed Guidelines on AI Risk Management, where board and senior management play a key role in the governance and oversight of AI risk – and, pointedly, where reliance on third-party vendors or open-source models doesn’t shift the institution’s own accountability. And IOSCO’s Supervisory Toolkit for AI Use in Capital Markets, whose industry survey window closed Friday, pushes the same lifecycle-governance logic out to securities regulators across some 130 jurisdictions.
Putting AI on the CEO’s agenda only helps if accountability follows the dependency: who chose it, who uses it, who funds the controls, who accepts residual risk, and who can stop it when it falls outside tolerance. The FCA’s openness to facilitated collaboration – even on frontier AI and data-sharing – signals desks should expect more system-wide intervention, not less; in the same speech, Rathi was explicit that dependencies, particularly on model providers and third parties, must be properly mapped and governed.
The real shift this week wasn’t the reboot. It was the move from AI access to AI operating models – and the recognition that you can’t hedge accountability with a procurement clause. It has to be built for. (The FIX AI Working Group is taking this up – welcome anyone who’d like to join the discussion.)
Thanks for reading – as ever, any questions/feedback please let me know.
Rebecca


