Back to Insights
  • Markets & Trading
  • AI & Technology
  • Enforcement

Always on, fully delegated: the risk map for agentic AI trading

Robinhood, moomoo, Futu and Alpaca now let an AI agent place real trades from a plain-English prompt, and the market is drifting toward round-the-clock. The technology is new. The ways it goes wrong are not. Fifteen years of enforcement already drew the map.

Abstract blue illustration of a luminous decision core sending multiple paths through a guarded gateway into a circular market

AI & MARKETS · RISK BRIEFING

Agentic AI Trading · MCP Infrastructure · 24/7 Markets

The new execution path

natural language in // real orders out // no market close

  1. “buy the dip”
  2. AI agent reasons + acts
  3. MCP
  4. broker
  5. market 24 / 7

A natural-language instruction can now pass through an AI agent and MCP connector to become a live broker order in a market moving toward 24/7.

Source · Alpaca MCP Server, Robinhood Cortex and 24 Hour Market, and moomoo / Futu API Skills, 2025 to 2026.

4 brokersshipping agentic access
Real ordersfrom a natural-language prompt
No closemarkets moving toward 24/7
01

Overview

In the space of a year, delegated trading stopped being a developer feature and became a consumer one. Alpaca, which describes itself as agent-first brokerage infrastructure, shipped an official Model Context Protocol server that exposes dozens of trading tools to assistants like Claude and lets an agent research, analyse and place real stock, options and crypto orders in plain English. Robinhood unveiled its Cortex assistant with voice-activated order placement and has been rolling out an agentic trading feature alongside its automated Strategies product. Moomoo, the international brand of Futu Holdings, launched moomoo API Skills, which it markets as turning a customer's own AI into a trading agent on standby around the clock. The common thread is that a language model can now move real money on a real account, and the human is increasingly a supervisor rather than a clicker.

Two forces compound each other here. The first is autonomy: an agent that decides what and when to trade, not just how to route an instruction. The second is time. Robinhood was the first US retail brokerage to offer overnight trading of single stocks, its 24 Hour Market now spans hundreds of symbols, and on its busiest days as much as a quarter of daily volume has come from outside regular hours. As the market drifts toward 24/7, the human supervisor is asleep for a growing share of the trading day, and the maintenance windows and natural pauses that used to contain errors are disappearing.

None of this is inherently improper, and naming these firms is not an allegation against any of them; they are simply the clearest examples of where the industry is heading. The point of this briefing is narrower and more useful. Every way an agentic, always-on trading stack can hurt a firm or its customers has an enforcement precedent behind it, some of it fifteen years old. The failure modes did not change; the speed, scale and autonomy did. What follows is the risk map, drawn from the cases that already tested each risk.

Alpaca
MCP 65 trading tools
Robinhood
Cortex agentic + 24hr
moomoo / Futu
API Skills “24/7 agent”
Precedent
15 yrs 2010 to 2026

Alpaca Securities

MCP Server · since Apr 2025

Official MCP server exposing ~65 Trading and Market Data tools; trades equities, options and crypto by natural language. Docs warn that keys are sensitive and the server can place real trades.

Robinhood

Cortex + Agentic · from Sep 2025

Voice-activated order placement, an AI market scanner, automated Strategies, and a 24 Hour Market that made it the first US retail broker to offer overnight single-stock trading.

moomoo (Futu)

API Skills · Apr 2026

Lets retail customers connect their own AI agents and convert plain-English intent into executable orders across US, Canadian, Hong Kong, Singapore and Japanese markets, marketed as a 24/7 agent.

The direction

industry-wide

eToro and others have shipped comparable tooling; several firms cite agentic AI in cost and headcount decisions. Delegated, always-on execution is becoming a default, not an edge case.

02

Fifteen years, one lesson

Before the risks themselves, the arc. Regulators have been penalising automated-trading failures since before the modern AI stack existed, and the through-line is consistent: when execution outruns human oversight, the law reaches the firm that deployed the system, not the system. Each marker below maps to a risk in the register that follows.

Fifteen years of automated-trading enforcement

Selected precedents mapped to the risk register, 2010 to 2026

  1. The Flash Crashautomated selling cascades; ~$1tn in value briefly evaporates
  2. AXA Rosenberg · SEC $242Mconcealed error in a quant model; first quant-model case
  3. Biremis & Hold Brotherssponsored-access layering; brokers failed to supervise overseas traders
  4. Knight Capital · SEC $12Muntested code loses ~$460M in 45 minutes; Market Access Rule
  5. Wedbush · SEC $2.44Msponsored access to thousands of anonymous traders; Rule 15c3-5
  6. Athena Capital · SEC $1Mthe "Gravy" algorithm marks the close; first HFT-manipulation case
  7. Coscia · first criminal spoofing convictionalgorithms built to place-and-cancel
  8. Wealthfront & Hedgeablefirst robo-adviser enforcement actions
  9. Robinhood PFOF $65M · JPMorgan spoofing $920Mrouting conflicts; algorithmic manipulation at scale
  10. Robinhood · FINRA $70Moutages during volatility, misleading information, options approvals
  11. Robinhood Crypto · NYDFS $30Mcrypto business line's AML and cyber controls could not keep pace
  12. Charles Schwab robo · SEC $187Mundisclosed automated-advice conflict (cash drag)
  13. CSRC v. Futu & Tigercross-border brokerage into mainland China ruled illegal
  14. Coinbase · NYDFS $100M100,000+ unreviewed alerts; AML program overwhelmed
  15. AI-washing $400K · Blue Ocean overnight outagefirst AI-capability fraud cases; a 24-hour venue overwhelmed
  16. Robinhood · SEC $45Mdata breach, Reg S-P, identity theft, recordkeeping, Reg SHO
  17. Mirae · multi-venue surveillance sweepfailure to surveil omnibus flow for momentum ignition

The through-line is consistent: when automated execution outruns human oversight, regulators reach the firm that deployed and supervised the system.

Source · Enforcement records listed under Sources below.

03

The risk register

Sixteen risks, each with the precedent that already tested it. For each, we set out what the risk is and how it arises, how it changes in an agentic, always-on context, and how a firm should be thinking about it. Read the case not as a curiosity but as the shape of the examination a firm running agentic infrastructure should expect.

R1 Runaway automation with no kill switch

The oldest automation risk is also the simplest: a system that does the wrong thing very fast, at a scale no human can catch up to. It arises whenever order generation is decoupled from human reaction time, so that a bad instruction, a mis-deployed change, or an unhandled edge case becomes thousands of live orders before anyone notices. Deterministic algorithms already made this dangerous, which tells you the hazard is the speed, not the sophistication.

Agentic systems raise the stakes on two axes. The trigger is now probabilistic rather than scripted, so the failure can be stranger and harder to anticipate than a coding bug: a misread prompt, a hallucinated ticker, a tool call that loops. And in a 24/7 window the human circuit-breaker may be asleep, so the interval between the first bad order and human intervention can be hours rather than seconds. An agent that keeps buying into a falling market at 3 a.m. has no colleague to tap it on the shoulder.

The Market Access Rule already frames the answer: pre-trade risk controls that are hard, external to the agent, and sized for a machine that never hesitates. That means price and size limits, credit and exposure thresholds, order-rate throttles, and a kill switch a human or an automated supervisor can pull instantly and that the agent cannot route around. The controls must sit outside the model, because a control the agent can reason about is a control the agent can eventually defeat.

R2 The agent that manipulates, with or without intent

Manipulation law was built around intent, and an autonomous optimiser complicates that without dissolving it. An agent rewarded for profit can independently converge on strategies the law calls spoofing, layering or momentum ignition, because those strategies work, not because anyone instructed it to break the rules. The firm's exposure does not wait for a finding of intent, because it also runs through the separate, strict duty to surveil its own flow for exactly these patterns.

The agentic context makes both halves harder. A reinforcement-style agent may discover manipulative micro-strategies that no human designed and that are invisible in the code, and it may express them across thousands of small orders that look benign one at a time. Routed through omnibus or aggregated arrangements, that flow is even harder to attribute, so the manipulation and the failure to detect it compound into one problem.

Assume your agent can, and eventually will, find these patterns, and build to catch them: surveillance that scores the agent's own flow for spoofing, layering, momentum ignition and marking the close; explicit constraints that forbid place-and-cancel behaviour; and a governance record showing you looked. "The model did it on its own" is not a defence. You are liable for what your automation does and for failing to watch it.

R3 Overstating the intelligence: AI washing

The fastest route to an enforcement action in this space is not a trading loss; it is a marketing claim. "AI-powered," "autonomous," "predictive" and "agentic" are representations, and a regulator will test each against what the system actually does. The risk arises the moment marketing outruns engineering, which in a hype cycle is most of the time.

Agentic branding is especially exposed, because the gap between the demo and the deployed reality is often wide, and because the claims are made everywhere: on the site, in an app-store listing, in a founder's post. Every one of those is subject to the antifraud and marketing rules, and "the model can do this in principle" is not the same as "our product does this reliably for customers."

Treat every capability claim as something you must be able to substantiate on demand: what the agent does, its limits, its error rate, and the human oversight around it. State what it cannot do as clearly as what it can. The bar is substantiation, not enthusiasm, and the cheapest control is a compliance review of the marketing copy before it ships.

R4 Best execution and conflicts in autonomous routing

When an agent decides where an order goes, the firm still owes best execution, and any payment-for-order-flow economics still create a conflict between the firm's revenue and the customer's price. The risk arises because automation buries the routing logic inside a model or a configuration, where the duty to compare against competing venues quietly stops happening.

An agentic router makes the conflict less visible, not less real. The decision that used to be a documented committee review is now an emergent behaviour of a system, and the incentive to favour venues that pay can be encoded subtly or even learned. If the agent is never tested against the venues it did not choose, "best execution" degrades into "consistent execution at our preferred venues."

The duty is comparative, so the control is comparative: benchmark the agent's executions against competing markets, security by security and order type by order type, including price disimprovement; disclose the economics plainly; and keep the evidence. The examiner's question is simple and unchanged: show me the comparison to the venues you did not route to.

R5 When the agent advises: suitability and hidden conflicts

The moment an agent recommends a security or manages a portfolio, it crosses from execution into advice, and the standards of conduct attach: Regulation Best Interest for brokers, fiduciary duty for advisers, and full conflict disclosure. The risk arises because automated advice makes conflicts easy to bury in a product design that looks neutral.

A conversational agent is a persuasive adviser, and its recommendations can be shaped by conflicts the customer never sees: a revenue-sharing default, a house product, a cash allocation that quietly benefits the firm. Personalisation sharpens this, because the advice is generated per user and is hard to audit after the fact.

If the agent recommends, it inherits every duty a human adviser has, so treat it that way: a documented reasonable basis for recommendations, conflicts surfaced rather than buried, and testing that the agent is not steering customers toward whatever pays the firm most. Undisclosed conflicts embedded in a model are still undisclosed conflicts.

R6 Credentials, data and the MCP attack surface

Connecting an agent to a brokerage through MCP hands a language model live access to accounts, and that widens the attack surface in ways the old web-and-app model did not: over-broad API scopes, leaked keys, prompt injection that hijacks the agent, and tool calls that execute in ways nobody intended. The safeguarding, disposal and identity-theft rules that already govern customer data apply in full.

The novel threat is that the agent is a confused deputy. A malicious instruction hidden in a webpage, a document, or a market-data feed can redirect an agent that holds trading and withdrawal permissions, turning a research task into an exfiltration or an unauthorised trade. Alpaca's own documentation flags that its server can place real trades and that keys must be treated as sensitive, which is exactly the right instinct.

Least-privilege everything: scope the agent's permissions to the minimum, separate read from trade from withdrawal, rotate and vault credentials, and build prompt-injection defences and human-in-the-loop confirmation for high-impact actions. Then keep the breach-response and identity-theft plan the rules require, because when access is this broad, a security lapse is also a compliance failure.

R7 The black box you cannot explain

When an agent trades or recommends, the firm has to be able to explain why: the reasoning, the inputs, and the basis for the decision. The risk arises because a language-model agent is far harder to interrogate than a rules-based script, so "the model decided" becomes the only available answer, and that is not a defence.

Explainability is not an academic nicety; it underpins concrete duties. You need a reasonable basis for a recommendation under Reg BI and suitability, the ability to notice when the model is quietly malfunctioning, and the ability to disclose material risks and errors in a model-driven strategy. A model too opaque to interrogate hides its own failures until they are large.

Build for interrogability from the start: capture the inputs, the model version, the agent's stated rationale and the resulting action, and be able to reconstruct a decision on demand. Independent review of the model's behaviour matters more, not less, as the model grows more capable, because the failure mode is a hidden error nobody can see because nobody can read the box.

R8 Resilience and the 24/7 problem

Round-the-clock trading removes the maintenance windows and natural pauses that used to absorb errors, and overnight books are thin, with wider spreads and less liquidity to cushion a bad order. The risk arises because the same order that is harmless at midday can move a price violently at 3 a.m., and a venue outage in that window can trap or cancel trades with no daytime desk to intervene.

Agents make the 24/7 problem worse, because they are the participants most likely to be active overnight and most likely to react to one another. A thin overnight market populated by fast agents is precisely the setup for a self-reinforcing move, and the human who would normally step in is asleep. The infrastructure was often built for a market that closes; the agents assume one that never does.

Treat overnight and 24/7 as a distinct risk regime rather than an extension of the day: liquidity-aware limits that tighten when books thin, circuit breakers calibrated for off-hours volatility, overnight-grade system resilience, and a documented answer to who intervenes, and how, at 3 a.m.

R9 Model risk, hallucination and herding

Two model-specific failures round out the map. An agent can act on a hallucinated fact or a misread number and trade on something that is simply not true. And if thousands of agents share a handful of underlying models and data feeds, their decisions correlate, so one flawed signal can trigger synchronised, one-directional trading across the whole market.

Both failures scale with adoption. A single hallucination is a bad trade; the same hallucination replicated across every firm running the same base model is a market event. The concentration of the industry on a few model providers is itself a systemic risk factor, the modern echo of the automated-selling cascades that produced the Flash Crash.

Govern the model as a model: hallucination controls and sanity checks on the data an agent acts on, stress-testing for correlated behaviour, and an honest view of how much of your stack, and your competitors', depends on the same few providers. The regulators' enforcement leadership has already named both AI mistakes in investor materials and the systemic risk of shared reliance, so the herding risk is not hypothetical.

R10 The new business line: delegation, outsourcing and controls that never caught up

Agentic trading is not a feature bolted onto an existing product; it is, in substance, a new business line, and new business lines have a way of outrunning the compliance function that is supposed to govern them. The risk arises when a firm stands up a fast-growing capability on borrowed frameworks, or delegates critical compliance functions to a vendor or affiliate, while assuming the old controls will stretch to fit. They rarely do.

An agentic stack also delegates the cognition itself to outside providers: the model, the MCP infrastructure, the data feeds. Outsourcing the function does not outsource the responsibility for it, and a provider's outage, silent model update or security gap propagates straight into your live trading. The combination of a new business line and heavy external dependency is exactly where controls fall through the cracks.

Treat agentic trading as its own supervised business from day one: purpose-built AML, surveillance, suitability and recordkeeping controls scaled to its actual growth rather than inherited from the parent product; vendor oversight with real visibility into what the model and MCP providers do; and a compliance function resourced to keep pace. Regulators have been explicit that rapid growth is not an excuse for controls that lag.

R11 Authority and consent: is the agent exercising discretion?

If an agent decides what and when to trade rather than carrying out a specific instruction, it may be exercising discretion, which requires prior written authorization and firm approval. The risk arises from a mismatch between what the customer actually consented to and what the agent is technically able to do: an over-broad permission scope, or an agent that acts beyond the customer's intent, is unauthorized trading.

Agentic delegation blurs the line the rules draw. "Buy the dip" is not a specific order; it is a grant of discretion, and the scope of that grant is often implicit, ambiguous and unlogged. When the agent then acts autonomously, potentially in ways the customer would not have chosen, the firm is squarely in discretionary-account territory whether or not it papered it as such.

Define, document and bound what the agent is authorized to do, and make the customer's consent explicit and specific: what it can trade, within what limits, and where its authority ends. Then supervise for trades outside that boundary. Autonomous trading beyond a customer's written consent is unauthorized trading, full stop, and the paperwork has to match the capability.

R12 AML and abuse surveillance when you cannot see the human

Agentic accounts can obscure who is really directing the trading, and machine-generated flow strains the systems meant to detect suspicious activity, market abuse and money laundering. The risk arises because know-your-customer, transaction monitoring and beneficial-ownership obligations do not relax when an algorithm places the order. If anything, they have to be sharper when the trader is a bot acting for a person you cannot see.

Volume and opacity are the core problem. Agents generate far more transactions than humans, so alert backlogs build faster, and the layer of automation between the customer and the market makes attribution harder. A firm that lets its monitoring fall behind its growth is the recurring pattern in crypto enforcement, and agentic trading recreates the same growth-outruns-controls dynamic in a new setting.

Scale monitoring to the machine, not the human baseline: near-real-time transaction surveillance, resourced alert-clearing that does not build a backlog, and clear attribution of agent-driven flow to the human ultimately responsible. Regulators have made clear that a backlog of unreviewed alerts is itself the violation, whether or not laundering is ever proven.

R13 Gamification and engagement, amplified by AI

An agent that personalises prompts, nudges and framing can steer customers toward more trading or riskier products, and regulators already treat behavioural design as a conduct and supervision issue rather than a marketing flourish. The risk arises because engagement optimisation and the customer's best interest can point in opposite directions.

Agentic personalisation makes the nudge sharper and harder to police, because it is generated on the fly for each user rather than designed once and reviewed. An assistant that "helpfully" suggests the next trade, tuned to what keeps a particular person engaged, is a powerful and largely invisible influence, and the line between assistance and inducement is thin.

Govern the agent's engagement design as a supervised conduct surface: test what it nudges customers toward, constrain it away from inducing more or riskier trading, and be able to show that its help serves the customer rather than the firm's activity metrics. An agent's framing is a supervisable practice, not a neutral feature.

R14 Cross-border and multi-jurisdiction exposure

Agentic tools increasingly reach across markets, and an agent trading globally collides with conflicting rules, registration perimeters and cross-border market-abuse regimes. The risk arises because a single agent can touch venues and customers in multiple jurisdictions at once, each with its own regulator, licensing requirement and view of what is lawful.

moomoo's API Skills, for instance, routes plain-English intent into orders across US, Canadian, Hong Kong, Singapore and Japanese markets. Where the customer sits, where the venue sits, and where the agent runs may each answer to a different authority, and a model that is compliant in one market can be an unlicensed operation in another. Automation makes it trivially easy to cross a border you did not mean to cross.

Map the jurisdictions your agent can actually reach and build the perimeter into the system: block or license the markets and customer geographies you are not authorised for, and treat cross-border solicitation as the licensing question it is. An agent inherits every jurisdiction it touches, and "we did not realise it was onboarding those customers" is not a defence.

R15 Direct and sponsored access: you remain the gatekeeper

Agentic infrastructure is, in effect, market access at scale. When a broker lets an agent, its own or a customer's, push orders into the market through its pipes, it is doing what the Market Access Rule (15c3-5) governs: it must keep direct and exclusive control of the pre-trade risk controls and cannot rent out its gateway without owning the gate. The risk arises whenever a firm treats access as a pipe to lease rather than a duty to supervise.

A fleet of customer agents plugging into a broker is the sponsored-access problem in new clothes, and arguably a harder one: the traders on the other end are numerous, fast and semi-autonomous, and the broker may understand them less well than it understood a human day-trader. The rule's requirement of direct and exclusive control over risk settings is precisely what a permissive agent integration tends to erode.

Own the gate. Keep the pre-trade risk controls under the broker's exclusive control, not the agent's or a vendor's; know your access customers even when they are bots; and surveil what comes through the pipe. The enforcement history is unambiguous that the firm providing the access, not the trader on the other end, answers for the controls.

R16 Trade surveillance that cannot keep up with the machine

A firm must run surveillance reasonably designed to detect manipulative and abusive order patterns in the flow it handles: layering, spoofing, quote stuffing, marking the close, momentum ignition. The risk arises because agentic flow produces these patterns faster and in far greater volume than human trading, and an automated system can quietly behave in ways its own operator never intended.

Algorithmic manipulation is not a hypothetical; it is a documented reality, and it looks nothing like a human entering orders. An algorithm can dominate the tape in the final seconds of the day, or thread thousands of place-and-cancel orders through a book, at a speed and scale that surveillance calibrated for human behaviour will simply miss. Agents raise both the odds that such a pattern emerges and the difficulty of catching it once it does.

Surveillance has to watch two things at machine speed: the patterns your customers' agents can create, and the behaviour of your own automated systems. That means detection tuned to algorithmic timescales, back-testing against known manipulative scenarios, and reviews of your own agent's conduct. Inadequate surveillance is a violation in its own right, before any manipulation is even proven.

04

The stakes are already set

The precedent is not only instructive; it is expensive. The penalties attached to these failure modes span three orders of magnitude, from a few hundred thousand dollars for an overstated AI claim to nearly a billion for algorithmic manipulation. A firm deploying agentic infrastructure is not operating in a regulatory vacuum waiting to be filled; it is operating inside a fully-priced enforcement history.

Penalties behind the risks, by precedent

Selected outcomes mapped to the register · horizontal axis is logarithmic · violation types differ

AI-washing R3 · 2024

$0.4m

Citadel Securities R16 · 2020

$0.7m

tastytrade best-ex R4 · 2026

$0.85m

Wedbush access R15 · 2014

$2.44m

Robinhood gamification R13 · 2024

$7.5m

Knight Capital R1 · 2013

$12m

Robinhood Crypto R10 · 2022

$30m

Robinhood data / records R6 · 2025

$45m

Robinhood PFOF R4 · 2020

$65m

Robinhood outages R8 · 2021

$70m

Coinbase AML R12 · 2023

$100m

Schwab robo R5 · 2022

$187m

AXA Rosenberg R7 · 2011

$242m

JPMorgan spoofing R2 · 2020

$920m

The selected penalties range from $400,000 for AI-washing to $920 million for spoofing, showing that the risk register sits inside an already costly enforcement history.

Source · SEC, FINRA, CFTC releases

A log axis is used because the amounts span from $400,000 to $920 million. These are different violations at different firms, shown together to map the register to real outcomes, not to imply a single trend.

The pattern across all fifteen years is the same, and it is the single most important thing to carry into an agentic build. In every case, the regulator reached the firm that deployed the system, on the theory that automating a function does not delegate the responsibility for it. An agent is a faster, tireless, always-on version of the trader, router, adviser or surveillance analyst it replaces, and it inherits every duty that role carried. The firms that stay clear of this decade's version of these cases will be the ones that build the controls before the agent is switched on, not after an examiner asks to see them.

This article is an independent editorial analysis for information only and is not legal or investment advice.

Sources

  1. Product facts: Alpaca (MCP Server, 2025 to 2026), Robinhood (Cortex and 24 Hour Market, 2023 to 2026), moomoo / Futu (API Skills, 2026).
  2. Enforcement: SEC v. Knight Capital ($12m, 2013); U.S. v. Coscia (2015); SEC and CFTC / DOJ JPMorgan spoofing ($920m, 2020); SEC Delphia and Global Predictions ($400k, March 2024); SEC Robinhood PFOF ($65m, 2020); FINRA Robinhood ($70m, 2021); SEC Robinhood ($45m, January 2025); SEC Charles Schwab robo ($187m, 2022); SEC Wealthfront and Hedgeable (2018); SEC AXA Rosenberg ($242m, 2011); the August 2024 Blue Ocean ATS overnight disruption (under examination); and the 2026 Mirae multi-venue surveillance actions.
  3. Additional cases: NYDFS Robinhood Crypto ($30m, 2022) and Coinbase ($100m, 2023); FINRA Rule 3260 unauthorized-discretion enforcement; the Massachusetts Securities Division's gamification case against Robinhood (2020 complaint, $7.5m consent order 2024); and China's CSRC actions against Futu and Tiger (2022).
  4. Market access and surveillance: SEC Wedbush Securities ($2.44m, admitted wrongdoing, 2014); SEC Biremis (registration revoked, principals barred, 2012); SEC Hold Brothers ($4m, 2012); FINRA Citadel Securities ($700k, 2020); and SEC Athena Capital Research ($1m, 2014, algorithmic marking-the-close).
  5. Naming a firm's agentic product is not an allegation of wrongdoing.
Twenty seconds before the bell: how BMO Nesbitt Burns marked the closeTwenty-seven minutes late, and a $65,000 lesson in margin disciplineBelow the line: how a risk score of 20 cost Merrill Lynch $7.5 million