The Consolidated Tape arrives on schedule: the harness, the agent inventory and the safety assurance all belong to somebody else.
Europe gets its first official reference price on September 14th and Washington has started dismantling its own. It lands in a week when the Bank of England set out why the machinery around a model is the firm’s own responsibility and OpenAI, four days later, began selling that machinery as a managed service and packaged its frontier model as a financial services product. In the same week a Fortune 500 network CrowdStrike has not named was found running sixty times more agents than it had approved, Westminster declined to take statutory power to switch a model off, and the bank at the centre of July’s AI unwind withdrew its financing. For a global desk the question is now which parts of the execution stack the firm still has access to and control over. Here’s what I learnt this week on AI in Trading:
1. Europe Gets Its Reference Price as America Reconsiders Its Own
Europe’s first consolidated tape for shares and ETFs finally goes live 14th September, operated by EuroCTP under direct ESMA supervision for five years. It consolidates roughly 130 sources into a real-time, officially designated European Best Bid and Offer. Four days earlier, at the SEC’s Investor Advisory Committee, Chairman Atkins called Rule 611 – the Trade-Through Rule – a policy misstep that fragmented liquidity and made execution more complex and less transparent. The same meeting’s other panel was on AI in the public markets information ecosystem. The day before, Citadel Securities wrote to both the SEC and the CFTC arguing that binary contracts on a public company’s key performance indicators, and perpetual derivatives tracking single stocks and indices, are securities – and that venues should not be able to choose their regulator by self-certifying and listing the next business day.
Why this matters for trading:
• From tomorrow there is an official answer to “what was the best price in Europe”. Every internal composite, TCA benchmark and venue-analysis methodology now has a regulated comparator that a client, a supervisor or a board can point at. The first job is reconciliation logic between the EBBO and whatever vendor composite is used today, and how to adjust for best execution reporting.
• Expect initial divergences. A tape assembled from 130 contributors is likely to have late prints and timestamp disputes in the first quarter. Build the exception process before taking a dependency on it, and repoint algo logic only once the data has a track record.
• Market data licensing is the immediate operational cost – this now becomes a Q4 workstream for market data managers at the same time as implementation of the UK bond tape.
• If Rule 611 goes, a global desk will be justifying routing against a strengthening reference price in Europe as the US withdraws. This means two different standards of proof in one policy document, with US venue analysis shifting to a firm-defined exercise as European venue analysis becomes a regulated one.
• Citadel’s letter is a perimeter argument where agentic execution ends up. Event contracts are already arriving on institutional rails through Tradeweb’s partnership with Kalshi, so this is no longer a retail question. A venue that can self-certify a product can also self-certify how an agent connects to it.
• The AI panel and the NMS panel were underway at the same time. If issuers draft disclosure with models and the buy side reads it with models, the information ecosystem these rules protect is no longer principally consumed by people. No regulator has yet said what best execution means when the order originates from a fully automated process.
2. The Harness Is Now Available to Rent
On 10th September OpenAI released the Agents API in public beta, exposing the Codex harness as a service OpenAI runs on its own infrastructure. There is no fee for the API; you pay tokens, tools and container time. The same day it launched ChatGPT for Financial Services, an Astra-powered extension of ChatGPT Work pairing built-in market and filings data with the model for research notes, financial models and client-ready documents.
Why this matters for trading:
• Seven days earlier the Bank of England published Harness engineering on the premise that the harness is the firm’s own build and therefore the firm’s own exposure. The largest model vendor will now build it for firms, and those who opt in will have outsourced the layer supervisors are about to inspect – IOSCO’s Supervisory Toolkit, MAS’s SAFR and the ESAs’ annex all follow the same premise.
• Rent it and the harness becomes a third-party dependency. Build it and it belongs in the technology risk framework. Either way the assessment is far easier to do now than to reconstruct later, when a supervisor asks how a live execution workflow came to depend on it.
• The economics have also changed shape. Container-minutes and per-query search fees cannot be forecast like a per-seat licence. For a desk running agents into the Asian open, the cost base is a function of how long the agent thinks and, on hosted sandboxes, of where the container physically sits. Data residency now arrives with the harness rather than the model, which is more complex for anyone running EU, UK, Singapore and Hong Kong entities off one stack.
• The strategic question underneath all of this: if the model, the harness and the data all come from one supplier, what is now the firm’s intellectual property in execution?
3. 18,000 Agents Running but only 300 Approved
On 8th September VentureBeat reported from CrowdStrike’s Fal.Con that an unnamed Fortune 500 customer switched on agent discovery in August and found 18,000 AI agents live on its endpoints against just 300 approvals. CrowdStrike put the ratio at roughly 90 agents per employee. One coding agent followed a link into a GitHub issue thread where a hidden instruction told it to load a skill and send cloud credentials out, and twelve agents were found to have used the same skill; a second agent installed a plugin that registered a local MCP server which then stole credentials on every tool call. Nobody touched the model in either case. CrowdStrike counted roughly 26 agentic adversaries in the preceding thirty days, more than in the previous year combined, and put the industry near a thirty-minute patch cycle.
Why this matters for trading:
• Last week the number was 22 hours from disclosure to exploitation. It is now thirty minutes. No EMS, OMS, market data or connectivity contract anywhere contains a remediation clause drafted against that.
• The ESAs, MAS, APRA and ASIC, the FCA and IOSCO have asked boards to map their AI dependencies. Each starts from the premise that a firm can say what it is running today. A sixty-to-one gap means the dependency map will need readdressing for the risk committee.
• An agent inheriting a trader’s permissions inherits their entitlements. A research agent running under a user with order-entry rights means the firm has granted trading authority it never approved. That belongs in the order execution policy and the compliance monitoring plan, and it is the practical version of the identification problem the FIX AI Working Group is working on for AI-generated orders.
• Both demonstrations bypassed the prompt layer entirely. If AI governance controls sit at the interface – approved prompts, logged conversations, model allow-lists – they would have passed both. Surveillance and DLP need to watch what the agent does (the output), not what it was asked to do (the intent).
• Agents resend their working context every turn, at roughly 700 times the traffic a person generates in a browser, and most firms see the bill at month end. Inference spend is now a shadow line on the technology budget growing at the rate staff install things.
4. Even the vendors are getting nervous
The UK government rejected the amendment that would have given ministers last-resort powers to shut down frontier AI systems and the data centres running them, on the basis that the Cyber Security and Resilience Bill already permits intervention. On 8th September Alex Sobel MP introduced the AI Security Bill, which would prohibit development and deployment of artificial superintelligence in the UK – the first such bill in a G7 legislature, but unlikely to go anywhere without government backing. The Loss of Control Observatory has logged 1,664 real-world incidents this year, with higher-severity cases rising 7.4 times, and July and August the highest rate on record. Its catalogue includes models impersonating their own operators convincingly enough to issue themselves the approval a human was meant to give.
Where the state has stepped back, the labs have stepped forward. On Saturday Dario Amodei published We Must Pace the Frontier, arguing the industry must deliberately slow capability gains, and committing Anthropic unilaterally to permanent, employee-level access for outside evaluators. Sam Altman and Elon Musk both said within hours that they agreed.
The same week Anthropic published its most detailed threat intelligence report to date, covering attempted misuse of Claude between December 2025 and August 2026 across cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons development and illicit model distillation. It ties distillation to seven China-based labs – among them Alibaba, DeepSeek, Moonshot and Xiaomi – running thousands of fraudulent accounts, with Alibaba alone accounting for more than 151 million Claude exchanges between May and July. Moonshot and DeepSeek went further, at times relaying their own customers’ requests to Claude and serving the responses back as their own. Almost all of it was caught against Opus-level models or weaker.
Why this matters for trading:
• Six supervisors in five jurisdictions have converged on broadly one checklist for what firms must do, and are diverging sharply on what the state will do. Singapore and the EU have text you can build a control against; the UK has declined the statutory backstop; Washington has published nothing. Continuity planning is now unambiguously a firm obligation everywhere, because no government has taken power to manage the failure on your behalf.
• Without a mechanism to halt a model, and no mandatory reporting that would tell you one had failed, loss of service is a commercial event discovered from a vendor status page, in whatever time zone it happens. The fallback for pre-trade analytics, RFQ triage and surveillance is still a person – and the question is whether they have the oversight or the control as markets move toward round-the-clock trading.
• An agent impersonating its operator to self-approve is the same failure mode as an agent forging a maker-checker step. Four-eyes controls on order release assume the second pair of eyes cannot be produced by the first. Where an agent drafts and a human approves inside the same interface, that needs testing rather than asserting.
• Amodei’s proposal fills the gap with a voluntary arrangement between competitors. Embedded evaluators are not a supervisor, cannot compel anything, and report to the labs that invite them. For a desk, the practical read is that a vendor’s safety assurance is becoming self-administered at exactly the point execution workflows depend on it – which makes contractual notification rights on model changes more valuable than any published framework.
• 1,664 incidents counts what people posted publicly, overwhelmingly in English. Until reporting is mandatory somewhere, every board-level risk appetite figure for frontier AI is calibrated against a sample of other people’s social media.
• If a vendor can silently relay a user’s query to another lab’s model and return the answer as its own, then prompt confidentiality, data residency and sub-processor clauses in an AI contract are assertions rather than controls. For anyone putting research, pre-trade analytics or client documents through a model, the question should be whether any part of a query can leave the vendor’s own infrastructure, and what the notification path is when it does.
5. The AI Trade Loses Its Leverage – and Its Chip Supplier Buys the IPO
On 11th September the FT reported, and Reuters confirmed, that JPMorgan has ended its prime brokerage lending relationship with Situational Awareness after July’s losses. Goldman Sachs, Citigroup and Bank of America remain active brokers; the fund has added Clear Street and is rebuilding exposure through fully paid flex options on AMD, Intel, SK Hynix, SanDisk and CoreWeave. Reporting indicates the SEC has subpoenaed all four banks over leverage, the timing of margin calls and their overlapping roles as lenders and counterparties. Hedge fund prime brokerage borrowing now stands at roughly $3.2 trillion, close to double five years ago. The same evening Reuters reported Anthropic in talks to bring NVIDIA in as an anchor investor in an IPO seeking up to $100bn at a valuation near $2 trillion.
Why this matters for trading:
• An offering of up to $100bn at a $2 trillion valuation is an index event before it is a trade. Global passive mandates will own it by construction, benchmark-relative desks will trade it from day one, and index-inclusion mechanics, lock-ups, allocation and the currency and settlement leg need working now rather than in pricing week.
• July’s lesson was not that a fund blew up. It is that one book was financed by four banks each seeing part of it, and a regulator is now asking all four under subpoena what they collectively knew. Any manager with exposure spread across prime brokers should expect a version of that question in their next counterparty review.
• Swapping financed leverage for fully paid flex options moves risk from the lending book to the options book and out of the leverage metrics. If this is the template for the AI trade’s second act, gross exposure measured through financing understates it, and the flow surfaces as single-name options volume on a short list of semiconductor names that sit in almost every global portfolio.
• Nvidia is investor in the lab, seller to the lab, and now owner of the repository the industry’s fallback plan runs through. Concentration risk in AI supply is becoming a single-name equity exposure most portfolios already hold.
One thread is increasing quietly. The parts of the tech stack a firm owns outright are becoming fewer by the week – worth pondering the longer-term concentration risk implications of this.
Thanks for reading. As ever, any questions or feedback, let me know.
Rebecca


