From every AI system becoming a listed contract, to matching logic becoming critical infrastructure, with the layer that picks your model becoming payments infrastructure – and the cost of the AI trade becoming clearer
Two weeks ago the story was the rulebook. Last week it was the agents meeting each other. This week the market started to price what all of this runs on, and DARPA moved to fund proof that market designs hold before they trade. Meanwhile the layer deciding which model answers your question was bought by a payments company, and a $15bn loss showed where the AI trade sits on a market maker’s balance sheet. Here’s what I learnt this week on AI in Trading:
1. Compute Gets a Ticker – and Three Benchmarks Fight Over It
On 19th August the CFTC issued a request for comment on listing compute derivatives, published in the Federal Register on 21st August with comments due 20th October. Bloomberg had trailed it two days earlier, reporting the request had gone to the Office of Management and Budget (and again on 19th August). It asks about the size and liquidity of compute cash markets, susceptibility to manipulation, customer protection and perpetual compute futures. Chairman Michael Selig called it “the first step toward establishing clear rules of the road” for US compute markets.
CME and Silicon Data confirmed on 11th August that two cash-settled contracts – the H100 and B200 Rental Index Futures, each a month of GPU rent – are targeting 5th October under NYMEX rules. ICE has announced one in May on Ornn’s Compute Price Index, and one on 1st July with NATIVX on its COIL Index, which normalises by energy use and would sit alongside ICE’s gas and power books. Architect Financial Technologies, founded by former FTX US president Brett Harrison, bought designated contract market IMX Health in May to build the American Innovation Exchange on Compute Desk indices, and already runs compute perpetuals through Bermuda-regulated Architect Bermuda.
February’s newsletter argued that compute capacity was becoming a systemic input rather than a line in an IT budget. This is what that looks like with a contract attached – and it raises the question the RFC is really asking: what is a compute benchmark, and who gets to publish one? Three answers are live. The exchange-appointed incumbent: CME with Silicon Data, whose backer is DRW. The neutral third-party reference layer, is being pitched by Chicago-based Setara. And physical delivery, where settlement is capacity changing hands rather than a survey of published rates – in July Architect partnered with Compute Desk on ComputeConnect, converting futures positions into actual GPU capacity.
Days earlier the CFTC’s Innovation Advisory Committee had held its inaugural meeting, chaired by the FIA’s Walt Lukken, with 40-plus members from CME, Nasdaq, Cboe, ICE, DTCC, OCC, Robinhood, Coinbase, Kalshi and Polymarket. Thirty-five minutes went on AI, ending on agentic finance and whether existing Commission principles already reach autonomous participants.
Why this matters for trading:
• A new asset class with no price history, a fragmented physical market and no agreement on what the settlement price even is. GPU rent varies by hardware, region, configuration, power and service quality – which makes benchmark selection, not contract selection, the diligence question. An energy-normalised index and a rental-rate index will not move together, so basis risk against the actual compute bill depends on which one the venue picked.
• Most compute still prices in opaque bilateral deals, which is why the question of manipulation is being raised: a settlement price computed from posted rates can be moved by the same providers who post them. The incumbent benchmark is also published by a firm backed by a major trading house.
• Every firm running AI in production holds an unhedged compute exposure it has never had to describe. A desk spending $24m a year on LLMs (item 3) has a commodity cost line, and the CFO’s next question is whether it needs hedging like one.
• Two live comment windows: 20th October on the RFC, 27th August on the committee. The SEC’s answers to Foster and Sherman’s thirteen questions, due 31st July, are still outstanding.
2. The Pentagon Decides Matching Logic Is Critical Infrastructure
The committee in item 1 asked whether the existing rulebook reaches autonomous participants. Earlier this month DARPA put the harder version into a procurement notice: is the mechanism robust regardless of who turns up to trade it?
Intrinsic Market Resilience is not yet a programme – it is a Proposers Day notice (DARPA-SN-26-110) from DARPA’s Information Processing Techniques Office, ahead of an anticipated solicitation. The proposed work would use large language models, formal methods and automated reasoning to turn technical specifications and regulatory filings into machine-readable representations of market design, evaluate mathematical properties describing resilient behaviour, and propose validated fixes. Scope covers financial trading, energy distribution and cloud computing. Imandra’s Grant Passmore notes it arrives nine years to the day after he and Denis Ignatovich presented Formal Verification of Financial Algorithms at CADE.
Why this matters for trading:
• Every governance mechanism the industry is building describes what happened. SAFR records the moment an agent proposes to act; CAT logs events, not intent – which is what the FIX proposal is trying to carry in the message. None establishes that the venue behaved as specified. Formal verification is the only approach on the table that proves the matching engine matches its own rulebook before the trade rather than after the incident.
• If order protection is rescinded under Rule 611, best execution stops being a market-wide guarantee and becomes a per-venue claim that will need evidence.
• Regulatory text is becoming an input rather than an output: DARPA proposes to parse filings into formal specifications, and the FCA opened the Handbook via API on 6th August. That is a very different compliance function from the one most firms staff today.
• A defence agency scoping civilian market microstructure tells you deliberate disruption of an exchange is now a national security problem, not just a market integrity one.
3. Who Decides Which Model You Run
On 18th August OpenAI published Pacing model development in an era of cyber-critical capabilities, rewriting a Preparedness Framework mostly dating to 2023. It paused two weeks of deployment-focused reinforcement-learning training, is holding its largest planned frontier RL run, and keeps Astra and cyber research workloads paused pending a tougher security standard.
Axios called it OpenAI blinking first. On 14th August Anthropic published its 186-page Risk Report, which moved catastrophic harm from misalignment in high-stakes settings from “very low” to “low”, said its task-based evaluations have saturated, and disclosed that human-feedback vendor traffic ran for eleven months without its biological classifiers active. It did not conclude a pause was needed. On 16th August Dario Amodei described pacing as slowing the very best models without holding back those catching up. OpenAI has separately lost its head of ethics, head of safety systems, chief futurist and a former safety lead in recent months. Neither position is a slowdown in commercial terms – both are shipping, both are training, and what OpenAI paused is training, not deployment.
Whether the model you depend on arrives on schedule or is removed is at one end of the issue. The new one to consider is now who picks it. Stripe agreed to acquire OpenRouter, the layer routing each request across 400-plus models from 80-plus providers on task, price, speed and reliability. Reported figures range from Bloomberg’s $7bn-plus to Reuters’ $8bn, against $1.3bn at May’s Series B. Two data points on why the layer exists: one hedge fund spending about $24m a year on LLMs with roughly a third wasted, and CNBC’s July finding that Chinese-origin models have held above 30% of the tokens US organisations route through OpenRouter every week since February, peaking at 46%.
Why this matters for trading:
• The continuity point from a fortnight ago now has a second data point. Two suppliers, same week, opposite answers – the roadmaps at the two most likely vendors are heading in different directions, for reasons neither will fully publish.
• “Pacing” is a procurement term now. The question at renewal is not whether a vendor has a safety framework but whether it is currently rewriting it, and what happens to a firm’s roadmap if it concludes the answer is a hold.
• Last week the observation was that the differentiator is the software orchestrating multiple models, not any single model. Seven days later that layer has been bought by the company that runs internet payments – it has stopped being a tooling choice and become infrastructure with an owner and a billing relationship.
4. Binance Ships an Execution-Capable MCP Server
On 20th August Binance launched Agent OS, pulling its APIs, Wallet Agentic Hub, x402 machine payments, Skill Hub and Model Context Protocol support into one platform, with a public MCP server that lets Claude, Codex, ChatGPT and Cursor reach liquidity without local key management. Market data needs no authentication; account actions do. Agents run in dedicated subaccounts, cannot withdraw externally and cannot pull assets from the main account, and users choose per-order approval or autonomous execution. There is no separate cap on what an agent can trade or lose – the subaccount balance is the limit. Binance can see the orders but not the reasoning, which runs inside the user’s AI application. Not available in the EEA.
Why this matters for trading:
• Last week ADX was the first exchange to open market data to general-purpose assistants. This week the boundary moved from reading to trading, with the hard line drawn at moving money out rather than at sending an order.
• That is the fourth distinct execution boundary design in five months – per-order approval at Interactive Brokers, per-workflow at Public, a bounded account at Robinhood, now unauthenticated data with authenticated order entry and blocked withdrawals.
• The venue holds the orders and the client holds the intent. Surveillance calibrated to infer a decision-maker from an order pattern is working with half the evidence. Meanwhile x402 puts machine-initiated payment in the same stack as machine-initiated trading, and settlement was the last part of this chain that still had a person in it.
5. The AI Trade Shows Up on the Balance Sheet
Jane Street lost roughly $15bn in July, its first down month in about a decade, on its stake in Situational Awareness and wrong-way positions in Asian equities – the unwind this newsletter covered on 2nd August. Aschenbrenner’s fund peaked near $45bn in early July, ran leverage of up to 400% on AI infrastructure names, met margin calls and sold most of its public book to Citadel at a discount. Jane Street called the stake roughly flat on the year and disclosed it while preparing $14.6bn of bonds, with year-to-date net trading revenue still above the ~$40bn it made in all of 2025. Same tape, opposite month: Hudson River Trading posted a record $11.4bn of Q2 trading revenue and $7.4bn of net income, roughly four times the year-earlier quarter, and had no direct exposure.
Separately, Optiver is taking a majority stake in European power and gas trader Northpool, completing in November, and Anthropic’s run rate passed $65bn at end-July, with Bloomberg reporting it could file publicly as soon as this month. Meanwhile the rule that constrains where an agent can route remains in play: the SEC published Regulation Crypto Assets on 18th August, but the innovation exemption for tokenised listed securities is stalled, because Rule 611 requires execution at the best displayed automated quotation and an automated market maker displays no firm quote at all. The SEC’s fix is to rescind Rule 611 across all equity markets; Nasdaq, NYSE and Cboe are fighting both.
Why this matters for trading:
• Two market makers had opposite months – but the difference was not execution quality or market share – it was the investment book.
• Your counterparty’s capital may be long the same theme an agent is trading, and HRT’s July gain came from volatility the unwind itself produced. When the same names sit in the strategy, the vendor equity and the liquidity provider’s own book, diversification is thinner than the risk report suggests.
• Optiver buying power and gas capacity is item 1 from the other end – compute is an energy story, and firms are taking positions before the contract even lists. A public Anthropic filing does the same on the other side, turning model-supplier concentration from an educated guess into a disclosed, quarterly, tradeable number.
• Removing Rule 611 removes the mechanical backstop for every routing decision an agent makes. Whatever replaces it will be something each venue asserts about itself – which is the argument for item 2 in one line. Markets are definitely changing, yet again.
Thanks for reading. As ever, any questions or feedback, let me know.
Rebecca


