AI Trading Newsletter

AI in Trading 2026: A Global Regulatory Approach is Emerging

ASIC arrives at the same checklist while the US stays silent, as agents increasingly become a market participant no-one can yet audit

This week Australia became the sixth jurisdiction to tell boards to decide who is in charge of Frontier AI usage before the incident rather than during it, Fidelity research highlighted the growth and impact of agents, and DeepSeek raised its prices while OpenAI cut twice inside five days – which changes the argument for everybody who signed a three-year licence on the old numbers. Here’s what I learnt this week on AI in Trading:

1. Six Jurisdictions Now Say the Same Thing. Washington Still Isn’t One of Them

On 26th August APRA and ASIC urged financial market entities to move from awareness to action on frontier AI, following nine roundtables across June and July involving more than 600 attendees, supported by the Australian Signals Directorate with the Reserve Bank of Australia, Treasury and the ACCC. Five themes emerged: cyber fundamentals, from asset identification and patching to identity controls, attack-surface reduction, backups and third-party risk; board decisions taken before a crisis, as frontier AI compresses response times; interest in defensive AI, though capability is limited; shared provider dependencies that can turn one incident sector-wide; and industry-led dependency mapping, supplier assurance and incident coordination. There is an information paper and a preparedness checklist for boards and executives.

This is in line with MAS SAFR on 3rd July: verified identity, checkable rule, bounded outcome, immutable record; The FCA’s Mills Review on 6th July named concentration among model providers and hyperscalers as one of two headline risks, and its Critical Third Parties regime went live on 13th July. The Bank of England’s FPC reclassified frontier AI as a financial stability risk, Claudia Buch wrote to around 110 institutions with remediation plans due 31st October, and the ESRB issued a parallel warning. On 31st July the ESAs published the operational annex, asking for live inventories including APIs and AI/ML components, continuous rather than periodic scanning, incident response rebuilt for simultaneous multi-system failure, and management-body accountability moving from periodic oversight to continuous, informed decision making. Then MAS confirmed agentic AI already sits inside its supervisory expectations, as did FINRA – without writing a rule.

Against which: Foster and Sherman’s thirteen questions on agentic trading were due to the SEC on 31st July and are now a month overdue. The White House framework for reviewing covered frontier models was finished on 1st August, reviewed with the labs, but is still not published. The most substantive US contribution this week came from Jackson Hole, where Markus Brunnermeier argued AI introduces asymmetric understanding rather than asymmetric information – the counterparty cannot interpret an agent’s decision rule in her own concepts, so price revelation fails, humans become shock amplifiers rather than absorbers, and the kill switch is largely an illusion where algorithmic liquidity dominates.

Why this matters for trading:

• ASIC and APRA’s five themes are the ESAs’ annex from four weeks earlier, restated. “Board-level decisions before a crisis” is “periodic oversight to continuous, informed decision making” in plainer English. Six supervisors in five jurisdictions have now converged on one checklist, which makes this the new baseline for firms.

• It also pushes the work outward. “Industry-led dependency mapping and supplier assurance” is the Australian regulator declining to build the dependency map itself.

• Australia’s financial regulators are still ahead of their own government – the national AI Standards are due in 2027, and legislation is not expected before early that year. Supervisory letters are filling an eighteen-month statutory gap, which is the same manoeuvre MAS and the ESAs have already made.

• For a firm operating across jurisdictions the binding constraint is now whichever supervisor published first, because it is the only one with text you can build a control against. That remains the practical case for treating the European and Singaporean expectations as the house standard and treating the US position as an open item, not an absence of risk.

2. Fidelity’s view on Agents

After yet another panel prep call where a bank insisted no-one is using AI for anything more than summaries, TheStreet published Fidelity Digital Assets research on what they believe is happening as AI agents increasingly become capable of initiating transactions, managing portfolios and buying services – all without a person in the loop. Its conclusion on infrastructure is that agents will route across multiple systems based on cost, reliability and counterparty acceptance, and no single rail will dominate – “multi-fi”.

Why this matters for trading:

• Routing across settlement rails on cost, reliability and counterparty acceptance is the next step up from smart order routing logic – now being applied to the settlement leg. No order execution policy currently written describes how that choice gets made, or who is accountable for it – which is the same algo wheel question from a month ago.

• Identity, permissioning, bounded authority and immutable record are the four properties MAS specified in SAFR on 3rd July, and Fidelity now forecasts them as a commercial selection criterion rather than a supervisory one. But recording what an agent did is not the same control as proving it stayed inside what it was authorised to do – SAFR captures the moment of proposal, CAT logs events, and neither establishes mandate compliance. That gap is what regulators are now asking boards to close.

• Stripe built the machine-payments rail in March and bought the model-routing layer in August. The layer choosing which model answers and the layer moving the money are becoming one counterparty and were on nobody’s third-party register a year ago.

3. The Cheap Chinese Model Raises Its Price & US Frontier Cuts Twice

On 31st July DeepSeek re-post-trained V4-Flash, then on 16th August split the whole V4 family into peak and off-peak tiers: Flash at $0.44 and $1.32 peak, $0.22 and $0.66 off-peak; Pro at $1.32 and $3.96. Off-peak is not a discount on the old rate, it is half of a raised peak.

Five days later OpenAI went the other way. GPT-5.6 Sol fell from $5 and $30 to $4 and $20 on 21st August, after Terra dropped to $2 and $12 and Luna to $0.20 and $1.20 on 30th July. Two repricings inside a month on one model family is a firm defending share. Claude Opus 5 has been $5 and $25 since 24th July.

Why this matters for trading:

• Two suppliers moved in opposite directions in the same week, and the one that raised prices has the most users. Neither pricing power nor share defence is a stable basis for a three-year cost assumption.

• The surcharge is UTC-anchored, and 01:00 to 10:00 spans the Asian session and the European morning: a desk running agents into the open pays peak, overnight batch does not. Inference cost now varies by when you trade.

• The saving is flagship-tier only. Against Opus or Sol it holds; if the work could have run on Luna or Terra it never did – and nobody re-ran the comparison, because the eval does not yet exist.

• Dependence has displaced cost as the live question. If a third of your routed tokens sit with Chinese-origin suppliers, subject to policy on both sides, that is the concentration risk of item 1.

4. Which Leaves the Three-Year Licence Problem

The price-capability frontier has moved five times since most 2026 contracts were signed: Anthropic halving near-frontier intelligence in JulyKimi K3’s weights two days laterOpenAI cutting Terra and Luna on 30th JulyDeepSeek raising on 16th August and OpenAI cutting Sol on the 21st. As noted a fortnight ago, firms that hard-wired one provider are buying their way out through an orchestration layer – and the exit route is becoming an asset class of its own. Fireworks raised $1.5bn at a $17.5bn valuation on 16th July, serving 40 trillion tokens a day, more than the OpenAI and Gemini APIs combined on its CEO’s account, with over 95% of those tokens running on models fine-tuned to a customer’s own data. Stripe bought OpenRouter last week. The open alternative, NVIDIA’s Switchyard, now sits alongside Redpanda, CrowdStrike, Cloudflare, LiteLLM and Portkey.

The discipline is the one Nadella described in July: measure quality per task, set a floor for each workload, route to the cheapest model that clears it. The test is still the same: would your evaluation results keep improving if any single model were removed tomorrow?

Why this matters for trading:

• A licence is a floor on spend, not a ceiling on architecture: nothing in a committed contract stops new workloads routing elsewhere, and at the API layer migration is a base-URL and model-name change. What locks a firm in is the contract and the absence of per-task evals.

• Building the eval harness before the gateway is the only asset that survives every repricing, every release and the contract itself. Without it a desk cannot substitute, cannot negotiate, and cannot show a supervisor why a model was chosen for a decision.

• Self-hosting open weights answers the residency and continuity questions an API cannot, and crosses over against API spend at roughly $150,000 a month – at the price of owning evaluation, safeguards and incident reporting.

5. The Risk Appetite Framework Has No Line for Any of This

Item 1 asks boards to set risk appetite before the incident. The ESAs were more specific on 31st July: the Risk Appetite Framework should carry metrics and tolerance thresholds for both internal model use and indirect exposure to frontier models.

The standard toolkit is well documented – see Jón Daníelsson’s Financial Risk Forecasting, updated for 2026 for more information. Volatility models assume regimes shift at human speed and revert. Agent-driven deleveraging does not have to. If enough desks run similar strategies, prompted in similar ways, on a shared pool of suppliers, tail correlation can far exceed the mean and backtesting validates a model against history generated by a microstructure being replaced while the model runs. Stress testing survives, because it never claimed the past was a guide. Brunnermeier proposes the scenario: assume a widely used foundation model fails, is compromised or is abruptly withdrawn, then test whether firms can switch to rival models, fall back on previous generations and keep critical functions running – and because the same few models are used across jurisdictions, coordinate it internationally.

Why this matters for trading:

• The regulators have asked for a number but currently “Tolerance threshold for indirect exposure to frontier models” has no standard estimator, no reference implementation, nor back-history. First movers will be defining the metric, not calculating it.

• Indirect exposure is the harder half. Direct exposure is your own model spend, which finance can total. Indirect is what your counterparties, liquidity providers and peers run – the same suppliers, in the same hours, under the same export review. None of it appears in a correlation matrix estimated from returns.

• Backtest windows are dated in a way they were not: data generated before agentic execution was widespread now validates models operating after it. Write that assumption into the model documentation – a supervisor asking how the model was validated will get there eventually.

• The one control that scales is the stress test, and it is the cheapest thing here to build. What happens to the book if a supplier is unavailable for an hour in your peak session, peers deleverage into the same window, and your own fast-layer risk model is what went dark? Brunnermeir has a few suggestions.

Thanks for reading. As ever, any questions or feedback, let me know.

Rebecca

Share:

Facebook
X
LinkedIn
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.