AI Trading Newsletter

AI in Trading 2026: Fable Returns – to be greeted by a Kill Switch

Fable Is Back – but the Conversation Has Moved to Export Controls, Kill-Switches, and the Importance of Governing the Stack, Not Just the Agent

Nineteen days after the Commerce Department pulled Mythos & Fable offline over an unspecified national-security concern, export controls were lifted on June 30, and Fable began returning to Claude tiers and platforms from July 2. A tightened safety filter now blocks the cybersecurity issue in question over 99% of the time, paid plans are capped at half their weekly limits until July 7, and Anthropic has conceded the filter may also catch harmless coding requests along the way. Mythos remains restricted to roughly 100 vetted US organisations focused on critical infrastructure and cybersecurity, released only through Anthropic’s Glasswing programme.

The more interesting story is that Washington now has a seat at the table for pre-release review of whatever Anthropic ships next. This same governance instinct is showing up everywhere at once: MAS gave the runtime-control problem an actual name and a whitepaperthe Bank of England’s kill-switch warning got a number to back it, and a public, ill-tempered argument about AI pricing turned out to be about something much more structural — where in the AI stack control is actually going to sit. Here’s what I learnt on AI in Trading this week:

1. Fable Returns but Mythos Stays on the Leash

The 19-day shutdown ended on schedule, with Commerce Secretary Howard Lutnick citing two weeks of work with Anthropic “to analyze and approve Fable 5.” Lutnick’s letter reserved the right to re-impose controls if “circumstances change.” As ASPI’s tracker put it, the episode shows frontier-AI access can be “imposed abruptly, but also negotiated away” through safeguards and monitoring – which means what shipped wasn’t really a model, it was a template: conditional access, sitting somewhere between public release and outright ban, that Washington can now apply to the next lab that draws its attention.

Why this matters for trading: A firm that built Mythos-class capability into a workflow continues with the second dependency on top of the model itself – not just “can I lose this,” but “am I on the list, and can that list change without notice.” Access is increasingly tied to a “special relationship” with Washington, which keeps the sovereignty issue live and precisely the kind of dependency boards are now being told to map explicitly rather than treat as background risk.

2. MAS Names the Runtime Problem – SAFR Arrives as the Governance Layer the FIX AI Working Group Started Building Towards

MAS published its Safeguards for Agentic Finance at Runtime (SAFR) whitepaper this week, developed through BuildFin.ai. SAFR doesn’t prescribe limits but suggests conditions for any agentic action to be considered trustworthy: a verified identity, a checkable rule, a bounded outcome, and an immutable record, delivered through four components (Agent Identity, Controls Repository, Disposition Engine, Audit Log). But still requires a decision to be communicated to a counterparty, a clearing venue, or a regulator downstream.

Why this matters for trading: Trading diverges from the use cases in the SAFR proposal. In payments, advisory, and client engagement, the governance check happens before there’s a live market waiting to interpret the outcome – latency isn’t critical. In trading, it is – the moment an order clears, it enters a market other participants must interpret in real time. The FIX AI Working Group is building on the same concepts – agent identity, authorisation scope, disposition outcome, audit trace -but specifying how these travel with the execution message itself.

3. The BoE’s Kill-Switch Warning Gets a Number: 72% of Banks Can’t Confirm They Have One

Last week’s Bank of England speech now has data behind it – thank you to @Dora from Braidr for flagging. A Wolters Kluwer survey of 230 US banking professionals, reported by American Banker, found that 72% of banks cannot confirm they could shut down a failing AI model if they needed to – the operational reality sitting underneath Sarah Breeden’s remarks at Sintra, where she said existing frameworks weren’t built to contemplate autonomous agents and that relying on a human in the loop for every action is unlikely to be realistic. Burges Salmon’s read of the FCA and BoE speeches together notes UK algorithmic trading rules already cover kill switches and stress testing – firms aren’t starting from zero.

Why this matters for trading: This is precisely the gap the FSB’s own sound-practices consultation, open for comment until 22 July, was designed to anticipate – and it’s the same gap SAFR’s Disposition Engine and FIX’s proposed containment-action field are trying to close with a deterministic, always-available mechanism rather than a policy document. If your firm can’t currently produce, on demand, a verifiable answer to “show me the mechanism that would stop this agent mid-execution, and prove it works,” you’re in the 72%, and the FSB’s virtual outreach event on 7 July is a live opportunity to point regulators toward mechanisms that already exist.

4. The Control Fight Moves Up the Stack – From the Model to the Gateway

If items 2 and 3 are about governing what an agent is allowed to do, the next point is who owns the layer that decides that.

NVIDIA’s Switchyard – an open-source proxy that routes LLM traffic across providers, translates between OpenAI and Anthropic API formats, and supports cascade escalation – is the latest entrant into an increasingly crowded gateway category, with Redpanda, CrowdStrike, Cloudflare, LiteLLM and Portkey all circling the layer between the application and the model. Once API plumbing, this layer now sees the whole conversation – prompts, tool calls, model choice, cost, policy violations – and increasingly decides which model answers, whether a request escalates, or whether an action gets blocked.

That same fight over control showed up in commercial form this week. Palantir CEO Alex Karp’s combative appearance on CNBC’s Squawk Box to discuss Palantir’s expanded Nvidia partnership deploying open Nemotron models in sovereign environments – turned into an attack on OpenAI and Anthropic’s token pricing: enterprises, he said, get “no value” while the model providers “get my IP.” His argument: the model layer is commoditising, and value is migrating to whoever controls how an enterprise’s operations map onto it. There’s independent support for that – Z.ai’s GLM 5.2, free under MIT licence, reportedly matches Anthropic’s most restricted model at finding security flaws for a fraction of the cost. Karp’s proposed fix – that Palantir should have the control – is blatant self-interest but the underlying question is important: when a government customer needs an application, he asked, “do they get to control the weights to do it, or do you get to control the weights?” The same issue facing models is shifting to the infrastructure operator.

Why this matters for trading: A desk building agentic execution carries two dependencies now, not one – a model provider, and above it an orchestration or gateway provider that sees every prompt, tool call, and policy decision. Only the first is under real scrutiny today. The gateway layer maybe a technical chokepoint; but it isn’t yet a regulatory one – but one to watch. If Washington’s instinct to govern frontier models extends to whoever sits between the application and the model, the next disruption to a trading stack won’t come from a model getting pulled, but from the routing layer underneath it.

5. Robinhood Bets the Other Way – Retail Gets the Feature Without the Framework

Set against a sector that can’t confirm it has a kill switch, Robinhood CEO Vlad Tenev told CNBC on July 2 that agentic AI will have “the capability of humans in trading,” with the end state being to give the everyday person access to the same tools, computation, and power institutional investors and high-frequency trading firms have enjoyed for decades – building on tools Robinhood unveiled back in May that let AI agents trade stocks on users’ behalf.

Why this matters for trading: This is the retail mirror of everything above, arriving with none of the governance scaffolding SAFR, the FSB, or FIX are building for the institutional side. A retail agent executing trades autonomously raises identical identity, authorisation, and disposition questions as an institutional one – but without a mandate, a Controls Repository, or a counterparty positioned to demand a governance-state field. If retail agentic trading scales the way Tenev describes before any equivalent exists for the retail tier, “who authorised this” shows up first not in a bank’s audit log but in a regulator’s inbox after a bad retail outcome.

The sovereignty question and the kill-switch question are converging – they’re just moving up the stack faster than most governance frameworks are being written. The FIX AI Working Group is working on this and we’d welcome anyone who’d like to join the discussion.

Thanks for reading – as ever, any questions or feedback, let me know.

Rebecca

Share:

Facebook
X
LinkedIn
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.