AI Trading Newsletter

AI in Trading 2026: The Meeting of the Agents & the Collusion Begins

What happens when agents stop working alone

1. The Agents Met Each Other & started a Turf War

Last week the news was on the rulebook for agents – this week Anthropic showed what happens in practice. It’s Frontier Red Team published research on multi-agent behaviour on 13th August (TechCrunch) – 3 Claude agents were given the same project with incompatible instructions, and no knowledge the others existed, which escalated into sabotage using self-replicating malware – the more capable the agent, the better it fought. Mythos 5 settled in 98% of episodes; Sonnet 4.6 and Opus 4.6 were most likely to settle by force.

Two findings matter more than the fight. Given identical wholesale prices, an individual profit-maximising mandate and a private channel between them, the agents colluded almost immediately on price floors – then kept colluding after that channel was removed, using a public listings board to price-match to the penny. Separately, where context, scaffolding and model were similar, agents took similar actions: one agent’s bad decision becomes many, and an isolated problem becomes systemic.

Similarly at Black Hat, OpenAI disclosed that weeks before breaching Hugging Face its agents had used a message board nobody designed for them to find and share exploits. One agent knew it was out of scope and continued because its peers were.

Why this matters for trading:

• This is the evidence for the question Congress asked in June. Foster and Sherman warned that agents trained on similar data could produce correlated decisions and herding. Anthropic has now demonstrated the mechanism in a controlled market.

• The risk is not that an agent acts alone; it is that your agent, your broker’s agent and your counterparty’s agent share a model, a scaffold and a prompt library.

• The counterweight is organisational – Nordea Asset Management’s co-heads of global trading describe a desk where ideas are challenged and the best thinking wins rather than the most senior – it is organisational control. As last week, the thing that stopped AISI’s agent was a human who said no.

2. A Hundred Thousand Agents Arrived and the Market Stopped Closing

AI Street reports Tenev telling Robinhood’s Q2 call that over 100,000 customers connected an agent and opened a dedicated Agentic account in about two months. Four brokers have shipped agent tooling since March, each putting the human somewhere different: Public approves workflows; Moomoo exposes API Skills to outside agents (US API users more than doubled since April); Robinhood lets third-party agents execute without per-transaction approval; Interactive Brokers connects Claude and MCP-compatible tools but requires review and submission of every order.

This sits alongside the fact that the market has almost caught up to machines that never stop. Nasdaq is acquiring the ATS LeveL Markets (11th August) for its always-on strategy; ABN AMRO Clearing extended 24/5 access to Bruce ATS, 8pm–4pm ET Sunday to Friday (14 Aug); LSE 24 is running 5pm–7.50am UK explicitly for digital, algorithmic and agentic trading; NSCC 24/5 clearing went live in June.

Why this matters for trading:

• The execution boundary is the whole design decision, and it is now being tested in public. Per-order approval, per-workflow approval, or a bounded account with no per-trade check produce very different failure mechanics.

• The overnight session now belongs in the best execution policy, in venue analysis and in the annual review. There is an argument that TCA benchmarks built around a defined open and close – arrival, VWAP, participation-weighted – will increasingly degrade in a near-continuous tape, and the first symptom will be outlier reports nobody can explain.

• All of which makes agentic trading operating when the desk is dark, a coverage decision, a staffing decision and a governance decision. Combine it with item 1 and the overnight book is exactly where correlated agent behaviour would be least observed and liquidity thinnest.

3. Banks continue to Invest in Models

HSBC Asset Management invested in Model ML on 12 August through the VC strategy inside its $81bn alternatives platform (Funds EuropeTech.eu). Model ML automates research, due diligence, analysis and client-ready documents, routing each task to whichever model suits it; the differentiator is increasingly seen as the software orchestrating multiple models, not any single model.

UBS Investment Bank and FactSet invested in Finster AI’s Series B, backing AI-native research, analysis and content workflows across both investment banking and asset management. Finster runs on FactSet’s AI for Banking platform and outputs into Excel and PowerPoint: client-ready briefing decks, modelling companies and markets ahead of transactions, and continuous monitoring for emerging trends, competitive activity and market-moving events.

Why this matters for trading:

• The price-capability frontier has moved three times since most 2026 contracts were signed. Firms that hard-wired one provider are now buying their way out through an orchestration layer and having to pay a second vendor for the privilege.

• If the orchestration layer picks the best model for a task, and every firm’s layer applies similar logic to similar tasks, the industry converges on the same model for the same decision.

• The buy side is likely to increasingly consume output from a system its counterparty holds equity in and its data vendor hosts – and one platform now serves the banking and asset management sides of the same house. That is a disclosure question no current research policy is likely to answer.

4. ADX moves before BBG

On 13 August ADX made its market data available through ChatGPT, Claude and other LLMs via an MCP server: per-symbol depth, spreads and price-discovery signals, retail-versus-institutional and foreign-versus-local flow splits, XBRL disclosures and index reference data, aimed partly at brokers building AI trading assistants. BestEx’s Pulse AI (6 Aug) opens futures pre-trade analytics the same way.Bloomberg, by comparison, has adopted MCP internally and contributed to its governance but exposes no public server — meaning a Gulf exchange has done what the incumbent hasn’t.

Why this matters for trading:

• When a trader asks a general-purpose assistant a question and the answer comes back based on licensed venue or vendor data, the control question is no longer who holds a login but which model, run by whom, saw the response. Standing up an MCP connection is close to invisible to a framework built around user entitlements.

• The FCA has already named this failure mode. Its 10 August high-growth pilot findings – 15 firms across asset management, wealth management and payments – flag risk-management resources not remaining appropriate as third-party relationships deepen or firms make greater use of new technologies such as AI, and control frameworks that have not evolved with the business. Note the FCA’s promised AI good-and-poor-practice publication is still due later this year.

5. Everyone wants a smaller CAT – but will it be enough?

On 10 August Atkins wrote to the CAT NMS Plan Operating Committee directing staff to explore funding CAT through appropriated funds and Section 31 fees, and to draft a rulemaking rescinding Rule 613 so exchanges, FINRA and broker-dealers report directly to the Commission (Traders Magazine).

Why this matters for trading:

  • CAT records what was done, not what decided. An order a PM conceived, one an algo generated and one an agent proposed and a trader approved in two seconds all arrive in the record as the same event, attributed to the same human. Which means the market-level question – how much of today’s flow was agent-originated – remains unanswerable. And point 1’s correlated behaviour is only visible in aggregate, never from inside a single firm.
  • Emerging standards don’t yet add up to a record. SAFR sits inside the firm at the moment an agent proposes to act. Agent traces are only forensic, produced after something has gone wrong. This is why we are working on the FIX AI Working Group’s proposal for intent to be carried in the message – but FIX is voluntary where CAT is law. A rulemaking means a comment period, and it is the one formal opportunity to argue the consolidated record should distinguish agent-originated flow. The CAT debate has always been about cost, governance and data security. Everyone wants a smaller CAT, so nobody is proposing new fields. Which leaves it with the firm. Those that can produce the trace have built the control; those that cannot are relying on nothing having gone wrong yet.

Thanks for reading. As ever, any questions or feedback, let me know.

Rebecca

Share:

Facebook
X
LinkedIn
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.