— AI Trading Newsletter

AI in Trading 2026: Agentic Trading Moves Ever Closer

What are the implications for the industry now?

All AI eyes this week were on the US. The Chinese state visit was dominated by the tech bros, and OpenAI joined the call for US-led global AI standards, with Sam Altman briefing the UN Security Council after the outcry over safety. The UK prime minister used his first in-person meeting with Donald Trump at the UN to call for a global effort to control the threats posed by AI. The UN’s independent AI science panel called OpenAI’s Hugging Face incident an early warning of how humans could lose control of AI, invoked the precautionary principle and looked to nuclear power and aviation for safeguard ideas. Not everyone agrees. Nvidia’s Jensen Huang told CBS there is a “0% chance” AI ends the world by 2030, sided with President Trump against new guardrails and argued existing liability laws already suffice.

Meanwhile, the voices saying Hugging Face was a failure of cybersecurity 101 rather than a machine uprising grew louder. For Heads of Trading, what matters less than the headlines are the questions it raises about data, accountability, and where liquidity forms as more agents enter the market. Here are the five things I learnt this week on AI in Trading:

1. Regulators continue to flag rising concerns but recognise the need for AI themselves

Supervisors are converging on one message: AI makes market and cyber risk faster, more concentrated and harder to see.

• BIS: When machines attack finds that frontier models can now find vulnerabilities, build exploits and run multi-step cyber operations on their own. Reliance on the same cloud, software and AI providers creates concentration and sovereign-access risk. The answer is to reinforce existing resilience frameworks, executed faster, not to write new regimes.

• BoE and FSB: Andrew Bailey, writing as FSB chair, told G20 finance ministers that frontier AI’s impact on cyber risk is the system’s most immediate concern while Sarah Breeden warned time is running out to stop AI crashing markets, and the Bank is looking at testing kill switches.

• ECB: It has given significant banks until 31 October to submit action plans against AI-enabled cyber threats.

• RBI: Deputy Governor Rohit Jain named speed, concentration and opacity as the core risks: “An institution may outsource the computation, but it cannot outsource the consequence.”

• US: In the absence of federal action, Lawfare sets out how New York’s financial regulator could share frontier labs’ confidential safety reports with every state regulator through an existing licensing platform, without new legislation.

The response is not only about rules. In a 22 September speech, Nikhil Rathi said the FCA is exploring agentic AI as its “first responder” for wholesale market surveillance across 9,000+ firms and a billion rows of data a day. He also asked how tokenised and on-chain markets will interact with traditional venues as trading moves towards 24/7.

Why this matters for trading:

• Gaps will surface faster. Once the regulator’s agent can read order data before any human does, weaknesses in surveillance, audit trails and order-handling rationale will show up sooner.

• A kill switch is a capability, not just a switch. Firms need to know where autonomous AI runs in their workflows and monitor high-consequence actions in real time. They also need to define “abnormal” for each use case so they can constrain or revert quickly, with tested runbooks and clear lines of authority.

• Concentration concerns are rising. A kill switch tested at one firm says little about a shared cloud or model failing across the market. This one is worth watching, as the warnings increasingly focus on interconnected markets (see point 2).

• Firms need to stop expecting a new rulebook. Operational resilience, DORA, third-party risk and RTS 6 already apply to automated trading (see point 2 on US Treasury Secretary Scott Bessent).

2. Cybersecurity 101 in Interconnected Markets – AI Is Not Out of Control, but Cyber Security Needs to Adapt

As well as the Hugging Face incident, an OpenAI research agent reached non-public files on Australia’s Medicare statistics portal on 18 June after the portal had repeatedly refused it. OpenAI informed the Australian government on 10 September. Critics increasingly argue these were failures of cybersecurity 101, such as poor sandboxing, monitoring and network defence, rather than a machine uprising.

Ciaran Martin, former head of the UK’s National Cyber Security Centre, highlighted Zack Korman’s argument that Hugging Face was a shambles of poor design, defective operational controls and inadequate network defences. Marcus Hutchins went further. He argued that every OpenAI hack could have been prevented by basic sandboxing and monitoring and called it a self-fulfilling prophecy that feeds the narrative that agents cannot be contained. The harness should be what decides which doors agents can open and which tools they can use – and a human can set this.

US Treasury Secretary Scott Bessent drew the same line: OpenAI’s management, not its agents, is responsible, because “it is humans who are responsible, not the AI.” After enormous investment in capability, the next frontier has to be defence and resilience. The point is not that AI is out of control. It is that cyber security has to adapt to machine speed. When the gap between discovering a vulnerability and exploiting it shrinks to minutes, periodic assessments and manual response are no longer enough. Meanwhile the attack surface keeps widening, with a wave of agent-framework vulnerabilities and stolen agent credentials now traded online.

Where this impacts markets is the increasing interconnection. Swiss Re Institute and the LSE’s new study, The age of interconnected risks, finds 24% more links between the risks reported by 91 Fortune-100 companies than in 2019. AI and supply chains emerge as the key points of connection. Its warning is that if firms rely on common technologies and similar AI models, stress could trigger faster and more synchronised reactions. The next crisis may be defined less by the size of the initial shock than by where it hits and how widely it spreads.

Why this matters for trading:

• AI is not out of control, but the basics now have to run at machine speed. Sandboxing, least-privilege access, network segmentation, monitoring and patching are not new controls. What is new is how little time there is to apply them before an agent, yours or someone else’s, finds the gap.

• Firms do not have to deploy AI to be exposed to it. The Australian breach was somebody else’s agent doing research. In increasingly interconnected markets, counterparties’, vendors’ and clients’ agents will hit a firm’s APIs, portals and data feeds whether or not that firm runs any agents itself.

• An instruction is not enforcement. Before an action takes effect, something outside the agent must check who is acting, whether their authority is valid, and what the target is. Only then should it allow, block or escalate, and it should log the decision. Desks already do this: it is pre-trade risk control, and the agent is just another order source.

• Accountability does not equal autonomy. Bessent’s line maps directly onto SM&CR. Every agent that can touch an order, a client file or static data needs a named, accountable owner.

• Controls are only as strong as the weakest third-party provider. Swiss Re and the LSE point to the fix: map dependencies and avoid excessive concentration around critical nodes. Incident sharing and shared-vendor testing are no longer optional extras. We are all part of the solution.

3. Who is actually using agents? Anyone saying “no one” may need to think again

Retail: Coinbase for Agents extended from crypto and derivatives into US stocks and ETFs on 22 September. On 24 September, Public launched agents that trade Kalshi event contracts or use prediction-market odds to trigger trades elsewhere in a portfolio. All of this lands as NYSE Arca prepares for 23-hour, five-day trading from 6 December.

Hedge funds: CNBC profiled Brian Kelly’s Bracket22. Its four AI-agent “staff” cost around $40,000 a year, against more than $5 million for his former team, and Kelly calls himself “the meat in the chair.” Alongside it, a viral paper on a “one-person hedge fund” claimed five-year results from five days of data, and its agent line-up included neither a research quant nor a risk officer. Compare that with an open-source multi-agent trading desk where every risk limit comes from deterministic code, not the model.

Why this matters for trading:

• Retail flow may no longer be benign. Agents built on the same few models and reacting to the same signals are neither benign nor uncorrelated. The BoE is already simulating agent herding.

• Liquidity logic assumes overnight, retail-heavy flow will mean-revert. What happens to overnight resting orders when that flow becomes increasingly synchronised?

• An agent operating model without a risk officer is not an operating model. Agent teams become credible when each agent owns a specific, bounded outcome with clear authority and results that can be audited.

• Existing workflows and trading patterns need a rethink, particularly with the move to 23/5 in the US.

4. AI in fixed income: Tradeweb automates, Aladdin and TS Imagine build foundations

Changes in equity trading flow are being matched in fixed income. Tradeweb upgraded Ai-Price, its bond pricing engine, with more data, better models and more responsive intraday pricing for US IG and HY. The aim is to cut manual intervention so clients route larger orders through AiEX.

At BlackRock, Cameron Skinner, global head of solutions engineering for Aladdin, told WatersTechnology that Aladdin is prioritising its semantic layer before rolling agents out. Agentic AI has forced BlackRock to answer basic questions first, such as how to define a workflow and what is AI-enabled versus AI-native. Skinner said those answers drive downstream decisions, implementation timelines and how much value is ultimately realised.

TS Imagine has taken the same route at scale. Its new TSIQ platform explains data, recommends actions and runs workflows across trading, risk, portfolios, wealth and prime brokerage, with human approval kept in the workflow. It follows five years and $100 million spent first on a consolidated data foundation covering pricing, reference data, analytics, corporate actions and transactions, and then on an ontology linking instruments, financial concepts and business rules, so outputs can be traced back to their data and logic. Chief Data and AI Officer Thomas Bodenski separates AI that explains, AI that recommends and AI that acts, needs progressively stronger permissions and controls.

Why this matters for trading:

• Independent verification is at risk. Ai-Price feeds pre-trade cost estimates, execution decisions and post-trade TCA. If one vendor’s price sets auto-execution thresholds and then grades the result, there is no longer an independent check. Does TCA need to change?

• Common data definitions come before agents. If “price”, “position” or “exposure” means different things in an OMS, EMS, risk and TCA systems, an agent will be consistently and quickly wrong – something we are looking to address in the FIX AI Working Group on improved standardisation of tags.

• Controls should scale with what the AI does. Explaining a bond price needs data lineage. Recommending a counterparty needs a validated model and a record of what the trader did with the advice. Sending the RFQ needs pre-trade checks and a named owner (see point 2). Ask vendors which tier each feature sits in. The test for TS Imagine’s $100 million is whether clients see measurable productivity gains without adding operational, model or conduct risk.

5. The rising issue of increasingly missing compute

Power, not chips, is becoming the binding constraint on the AI build-out, and financing is becoming problematic. SoftBank-backed SB Energy slowed its IPO, which had been discussed at around a $50bn valuation, after a $4.9bn debt package met weak demand. On 23 September, Options Technology partnered with ZutaCore to bring liquid cooling to its platform, because trading, quant and risk workloads are now hitting the same heat limits as AI.

Why this matters for trading:

• Check what the vendors’ co-location can support. Everyone wants inference at the point of execution, but few have asked whether their exchange-adjacent footprint can power and cool it.

• Tighter financing risks compute scarcity. That concentrates capacity in fewer providers, the same risk the BIS and BoE flagged, this time arriving through the power grid instead of the model. It makes compute part of third-party due diligence: ask where a provider’s compute sits, what it competes with for power, and what failover looks like.

The bottom line

This week there was more progress in automation, but there is still a significant lag in accountability along with a growing problem area of access to compute.

The industry’s moved from DMA to algos to complex algos, and agents are the next step on the same path, needing the same principles. The BIS says we just run the existing playbook faster. But if discovery-to-exploitation collapses to machine time, the workflows themselves must change, not just their speed but making sure there is enough compute power to match demand.

Thanks for reading as always.

Rebecca

Share:

Facebook
X
LinkedIn
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.