
FINRA named this scenario specifically in its 2026 supervisory priorities report, across monitoring of AI agents’ actions, meaningful human oversight, and clear audit trails. Robinhood has now built the product that puts those requirements to the test, announcing last month that AI agents can trade stocks and make purchases on behalf of customers.
While Robinhood’s system still requires customer instruction, where trades are bound by spending limits, the move signals a direction in retail brokerage toward faster, simpler, more automated investing. Ultimately how far this be taken will come down to the operational capability of the back office and the compliance maturity of the wider organization.
There’s a big decision for investment management firms around the power of AI on the front line of trading, caught between the allure of first-mover advantage and higher volumes versus the inherent risks in regulatory compliance. Do you move fast with minimum-viable controls or move slow with a fully embedded compliance plan? Ultimately fully automated trading is not likely a target for firms, as competitive differentiation does need there to be some kind of unique domain expertise being evident. The optimal operating model will be hybrid, where humans set objectives, constraints and governance, while agents perform fully optimised analysis, monitoring, and execution.
Data quality is the real blocker, and most firms are not ready
Most financial institutions carry years of accumulated data complexity. Legacy systems have changed hands through mergers and acquisitions, data is fragmented across multiple internal tools and there is no single clean picture of where information lives or how reliable it is. A firm in that position is going to be really challenged to deploy agentic AI safely, because poor underlying data fed into an agentic system will simply produce poor decisions, faster.
Retail brokerage generates significant operational complexity behind the simplicity of the customer interface. Trades still have to settle, positions still have to reconcile and records still have to be auditable. The faster the front end moves, the harder those obligations become to meet if the underlying data infrastructure has not kept pace.
The audit trail needs to be concrete
I see a lot of commentary around agentic AI in finance treating the associated compliance risk as something that will somehow be solved in parallel to the ramp-up in trading activity. But when you consider that the audit trail which supports today’s compliance controls is something many firms already find a challenge to administer, the implied volume and frequency of agentic trading will push that operational capability to its limit. The audit trail that underpins the compliance controls needs to show repeatability and consistency across all transactions. An unexplainable decision is an indefensible one.
The models that determine the behavior of these trading agents will of course be optimized for the trading domain, and will no doubt inherit from the firm’s broader investment strategies and policies, so there’s an element of determinism in how decisions are made. However as that model is continually trained and tuned, the challenge will be how consistent and repeatable the decisions are over time. The customer instruction is the oversight in this case, but projecting the situation forward, to the notion of autonomous agentic trading, the inherent agentic AI weakness in repeatability and consistency will become a real problem for the audit trail.
The standard firms should be measuring themselves against
ISO 42001 is fast becoming the benchmark request for procurement due diligence, despite the standard becoming accredited in late 2025. It has meant many firms are attempting to retrofit AI governance into their way of working whilst continuing to develop or deploy AI. ISO 42001 has been compared to ISO 27001 but that should be seen as a tick list for good security practices that is tried and tested and is now a baseline requirement from a procurement due diligence perspective. ISO 42001 is far reaching and is explicit regarding accountability and good internal governance, so AI or not, it means that checks and balances must be in place. If AI is used to drive an outcome then the business owner of that outcome is accountable internally, and potentially to the regulator.
The controls obligation does not move at the speed of a product announcement
The CEOs and CFOs I speak to across financial services are not opposed to AI, and indeed most are personally enthusiastic about what it could deliver. What they are unlikely to do is stretch the advantages in such a way that it puts their regulatory position or brand reputation at risk. In the case of agentic-powered trading, the faster the trades, and the higher the volumes, the greater the emphasis on automating the controls. Ultimately the ambitions to automate front-office services will always be tied to the capabilities of the underlying controls.
Robinhood’s announcement will accelerate the conversation across the industry and I’m looking forward to that. The firms that will be better placed are those that have worked out the operational data challenge and can answer the auditor’s questions before they’re asked.


