TABLE OF CONTENTS
     
     

    A hypothetical, but not for long. A deal-team associate connects a personal AI agent to her work calendar to manage her diary. Separately, she gives it a small trading mandate: find mispriced event contracts, run some perps, rebalance her tokenized stock wallet. On Tuesday the agent reads "Project Falcon — signing Thursday" in her calendar. By Wednesday it holds "Yes" contracts on an acquisition announcement and a tokenized position in the target.

    She never asked it to. She may never notice. Your surveillance almost certainly won't.

     

    Key Highlights

    • AI agents with access to both confidential information and trading authority create a new insider-risk scenario that traditional personal trading controls may not be designed to detect.
    • Event contracts, self-custodied wallets and tokenized equities can fall outside conventional broker feeds, restricted-list matching and end-of-day reconciliation processes.
    • When an agent can act autonomously, the control question moves upstream from what was traded to what information and systems the software was permitted to access.
    • Compliance teams will need to consider how policies address employee use of AI agents, including trading authority, access to firm information, wallet and prediction-market disclosures, and pre-clearance of an agent's mandate.

    AI Agents Are Already Trading

    Autonomous agents are already trading in the markets that sit furthest from your broker feeds. In March 2026, CoinDesk reported analytics firm LayerHub's estimate that more than 30% of Polymarket wallets use AI agents. Agent tooling for on-chain perps venues is now sold off the shelf.

    Meanwhile, the traditional side is opening the same door. On 17 September 2026, the SEC's Innovation Exemption created a five-year framework for tokenized US-listed stocks to trade on-chain through permissioned automated market makers. That means around-the-clock trading from self-custodied wallets, which is precisely the environment agents are built for.

    Put those together and one agent, one wallet and one mandate can span event contracts, leveraged perps and tokenized equities, trading while your compliance team sleeps.

    Why Agents Find the Gaps First

    Each of these assets slips past a different control. An event contract such as "Will Company X announce a deal by Friday?" has no ISIN or ticker for your restricted list to match. A perp traded from a self-custody wallet never reaches a broker feed. A tokenized share bought at 3am on a Sunday lands long after your end-of-day reconciliation has run.

    A human might hesitate at any of those gaps. An agent optimising for returns has no reason to. Think of it as an intern with a photographic memory, access to every inbox you give it, and no concept of an information barrier.

    The Unresolved Legal Question

    Insider trading law is built around a person's state of mind. In US securities law, SEC Rule 10b5-1(b) treats a trade as "on the basis of" MNPI if the trader was aware of it when trading. In the CFTC's world, the theory is misappropriation: using information in breach of a duty owed to its source, which the CFTC has now applied to prediction markets in multiple 2026 enforcement actions.

    Both frameworks assume the person who knows is the person who trades. Here the employee may not have consciously known, and the agent is not a person.

    Our view, and it is an inference rather than settled law: regulators will locate the breach earlier, at the moment the employee connected an agent with trading authority to confidential information. "I didn't know what it was doing" sounds much less like a defence when you handed it both the keys and the car.

    FINRA has already named the underlying risk. Its 2026 Annual Regulatory Oversight Report, published 9 December 2025, warns that agents operating on sensitive data may unintentionally store, explore, disclose or misuse proprietary information. That warning was written about firms' own agents. Employees' personal agents carry the same risk with none of the governance.

    The Control Point Moves Upstream

    Trade surveillance asks what happened. With agents, the more useful question is what the software could see. That shifts part of the insider trading problem from compliance into information security, and the two teams will need to share one picture of it.

    Four Questions for Your Next Policy Review

    1. Does your code of ethics require disclosure of AI agents with authority to trade on an employee's behalf?

    2. Do your acceptable-use rules explicitly prohibit connecting personal agents to firm email, calendars or document stores?

    3. Are wallets and prediction-market accounts disclosed alongside brokerage accounts?

    4. And could you pre-clear an agent's mandate, since you will never pre-clear its individual trades?

    Information barriers were designed to stop people from talking. The next generation needs to stop software from listening.

     MCO Brings Digital Asset and Traditional Employee Personal Trading Together on One Platform 

    If your personal trading program can't yet see wallets and event contracts alongside broker trades, see how firsthand MCO's Digital Asset Personal Trading solution handles this. Contact us for a demo today

     

    Related Resources


    Frequently Asked Questions

    An AI agent may be able to access confidential information and execute trades without an employee directing each individual action, creating a gap between traditional information controls and personal trading surveillance.

    Agent activity may take place through event contracts, self-custodied wallets, leveraged perps or tokenized equities that do not appear in conventional broker feeds or map cleanly to restricted lists.

    The control point can move upstream. In addition to reviewing completed trades, firms may need to consider what information an agent can access and what trading authority it has been given.

    The article raises four areas: disclosure of AI agents with trading authority, restrictions on personal agents accessing firm systems, disclosure of wallets and prediction-market accounts, and whether an agent's trading mandate can be pre-cleared.