AI · Market Structure · Featured Research

AI Agents in the Market: Tool, Trader, or Transmission Mechanism?

The governing variable in AI trading is authority: which components may infer and propose, which independent controls may authorise and constrain action, and how the system can be reconstructed after the fact.

The AI trading control boundary A left-to-right pipeline. Data perception, reasoning, and strategy proposal feed an independent risk gate, then an execution router and audit log. A dashed boundary marks the transfer of authority from inference to controlled action. A human-control box represents escalation and kill capability at a timescale appropriate to the workflow, while a feedback path returns post-trade evidence to monitoring. The AI trading control boundary inference proposes · controls authorise CONTROL BOUNDARY Human override ESCALATE Data perception Reasoning layer Strategy proposal Risk gate pre-trade Execution router Audit log MODEL SIDE PROBABILISTIC · PROPOSES CONTROLLED SIDE BOUNDED · AUTHORISED · LOGGED MONITOR · FEEDBACK · POST-TRADE SURVEILLANCE Schematic only. The boundary marks where model inference becomes action subject to independent limits, traceability, and intervention.
Figure 6 · The AI trading control boundary Perception → reasoning → proposal ‖ risk gate → execution → audit The model's proposal acquires market authority only after independent controls. Execution logic may itself be adaptive, but limits, ownership, intervention, and record-keeping must not depend solely on the proposing model.

Artificial intelligence enters a trading system in at least three analytically distinct roles. As a tool, it produces information for another decision-maker. As a trader, its output can change orders or positions within delegated authority. As a transmission mechanism, common models, data, providers, or objectives can correlate behaviour across firms. The first two roles concern authority inside an institution. The third concerns interaction across institutions. Conflating them turns a design problem into a debate about intelligence.

The firm-level question is therefore an allocation of authority. Figure 6 separates inference and proposal from authorisation, execution, and record-keeping. The components on the right need not all be simple or deterministic, but they must be bounded, testable, attributable, and independently capable of constraining the proposer. Capability changes the quality of proposals. It does not answer who is permitted to act.

Section 01Three framings

The tool and trader framings can be located by authority. If a human or separate system decides whether to act on the output, the model is a tool. If the output can alter orders within delegated limits, the model participates in trading. The transmission framing is different: it can arise under either architecture when many firms share inputs, providers, or optimisation targets. Strong local controls reduce firm-specific errors; they do not automatically diversify market-wide behaviour.

The current practitioner evidence is cautious rather than definitive. The Financial Markets Standards Board reported in February 2026 that advanced AI in wholesale trading remained at a relatively early stage and was generally embedded within existing infrastructure, subject to established algorithmic-trading and model-risk controls and direct or indirect human supervision. That finding describes the surveyed landscape, not a permanent boundary or a guarantee that every deployment follows it.

Section 02The control boundary

Figure 6 makes one reference architecture explicit. The proposing model feeds a separately owned risk gate. The gate checks hard limits and market-access controls; the router executes within its own tested policy; the log preserves enough inputs, versions, constraints, orders, and outcomes to reconstruct the decision. Human control is not necessarily a person approving every order, which would be meaningless at microsecond horizons. It is the ability to set authority, review exceptions, suspend the system, and invoke a kill mechanism at the timescale the workflow permits.

The invariant is not a particular diagram but separation of concerns. The component proposing an action should not be the sole authority defining, applying, and waiving its own limits. Every order should pass controls appropriate to the venue and strategy; model and policy versions should be traceable; and accountable owners should retain credible suspension and remediation powers. More capable inference may justify broader delegated authority, but that delegation remains explicit, bounded, and reviewable.

Capability can widen the set of admissible proposals. It does not erase the need to specify who grants authority, under which limits, and with what evidence.

On control architecture

Section 03Governance as engineering

Read this way, governance stops being a matter of principles posted on a wall and becomes a matter of where the boundary is drawn and how well the right-hand side is built. Supervisors have converged on the same view. ESMA's February 2026 supervisory briefing on algorithmic trading treats AI not as a separate regime but as something to be handled within existing controls, emphasising governance of algorithms, testing and stress-testing, outsourcing arrangements, and pre-trade controls, with explicit attention to the use of AI inside algorithmic-trading workflows. The Dutch AFM, in its work on AI in capital markets, makes the complementary point that human oversight and accountability must remain firmly embedded in the system rather than delegated to the model. Neither is exotic. Both are descriptions of keeping the control boundary in Figure 6 meaningful.

The engineering implications are concrete. Hard pre-trade limits should be independently owned and difficult for the proposing model to circumvent. Records should preserve source data, model and policy versions, material intermediate outputs where feasible, orders, control decisions, and timestamps. Human oversight should be designed around the system's operating horizon: pre-approval for some workflows, exception review and kill capability for faster ones. Accountability remains with the firm and its designated owners regardless of model complexity.

Treat the right-hand side of the boundary as a set of invariants the model cannot relax:

for every proposed action:
    assert passes(independently_owned_pre_trade_controls)
    assert within(authority, position, loss, and market_access_limits)
    record(data_version, model_version, policy_version, action, timestamp)
    assert accountable_owner_is_named
    assert suspension_and_kill_paths_are_tested

The controls should be proportionate to the strategy, but their ownership and traceability should not collapse into the proposing model.

Section 04The transmission question

The transmission framing cannot be solved by architecture inside one firm. The Financial Stability Board identifies third-party concentration, market correlation, cyber risk, and model risk as potential system-wide channels. The Dutch AFM's April 2026 analysis adds a market-integrity mechanism: systems using similar data and objectives may mirror or reinforce one another without explicit coordination. These are prospective vulnerabilities, not evidence that AI-driven synchronisation is already a dominant source of market instability.

Even a perfectly governed firm can be one node in a badly correlated system.

This rejoins the crowded-signal problem through common inputs rather than shared papers. Local controls govern what one system may do; system resilience depends on provider diversity, strategy heterogeneity, market depth, and whether common defensive actions become common order flow. The decisive distinction is between authority and correlation. Authority can be assigned and audited within a firm. Correlation must be measured across firms, which is why monitoring frameworks and dependency mapping are necessary complements to model governance.

  • Figure 6 is a reference architecture, not a depiction of any specific firm's system. Real deployments vary widely, and many place the boundary differently.
  • The state of practice changes quickly. The cited materials describe conditions through April 2026 and should not be treated as a permanent account of deployment.
  • This research deliberately avoids claims about specific products, vendors, or models. It is about architecture and governance, not about any particular system's capability.

This research is analysis and commentary for general information. It is not investment advice, legal or compliance advice, an offer, or a solicitation, and it contains no price forecasts. Regulatory and industry descriptions are summaries of the cited sources; the interpretation is the author's.

References & notes

  1. Financial Markets Standards Board (13 February 2026). AI in Trading: A Practitioners' View of the Current Landscape. Spotlight Review. Source for the description of current wholesale-market practice as embedded within existing infrastructure and controls.
  2. European Securities and Markets Authority (26 February 2026). Supervisory Briefing on Algorithmic Trading in the EU. Non-binding convergence material on governance, testing, outsourcing, pre-trade controls, and AI considerations.
  3. Autoriteit Financiële Markten (April 2026). AI in Capital Markets: Balancing Innovation and Integrity. Exploratory analysis of accountability, auditability, common inputs, and possible unintended model interaction.
  4. Financial Stability Board (14 November 2024). The Financial Stability Implications of Artificial Intelligence. Source for the four system-wide vulnerability channels.
  5. Financial Stability Board (10 October 2025). Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector. Follow-up framework for monitoring adoption and concentration.

Return to the front page