Customer Event | MCO Customer Roadshow Europe 2026 – Registration is now open
Customer Event | MCO Customer Roadshow Europe 2026 – Registration is now open
A hypothetical, but not for long. A deal-team associate connects a personal AI agent to her work calendar to manage her diary. Separately, she gives it a small trading mandate: find mispriced event contracts, run some perps, rebalance her tokenized stock wallet. On Tuesday the agent reads "Project Falcon — signing Thursday" in her calendar. By Wednesday it holds "Yes" contracts on an acquisition announcement and a tokenized position in the target.
She never asked it to. She may never notice. Your surveillance almost certainly won't.
Autonomous agents are already trading in the markets that sit furthest from your broker feeds. In March 2026, CoinDesk reported analytics firm LayerHub's estimate that more than 30% of Polymarket wallets use AI agents. Agent tooling for on-chain perps venues is now sold off the shelf.
Meanwhile, the traditional side is opening the same door. On 17 September 2026, the SEC's Innovation Exemption created a five-year framework for tokenized US-listed stocks to trade on-chain through permissioned automated market makers. That means around-the-clock trading from self-custodied wallets, which is precisely the environment agents are built for.
Put those together and one agent, one wallet and one mandate can span event contracts, leveraged perps and tokenized equities, trading while your compliance team sleeps.
Each of these assets slips past a different control. An event contract such as "Will Company X announce a deal by Friday?" has no ISIN or ticker for your restricted list to match. A perp traded from a self-custody wallet never reaches a broker feed. A tokenized share bought at 3am on a Sunday lands long after your end-of-day reconciliation has run.
A human might hesitate at any of those gaps. An agent optimising for returns has no reason to. Think of it as an intern with a photographic memory, access to every inbox you give it, and no concept of an information barrier.
Insider trading law is built around a person's state of mind. In US securities law, SEC Rule 10b5-1(b) treats a trade as "on the basis of" MNPI if the trader was aware of it when trading. In the CFTC's world, the theory is misappropriation: using information in breach of a duty owed to its source, which the CFTC has now applied to prediction markets in multiple 2026 enforcement actions.
Both frameworks assume the person who knows is the person who trades. Here the employee may not have consciously known, and the agent is not a person.
Our view, and it is an inference rather than settled law: regulators will locate the breach earlier, at the moment the employee connected an agent with trading authority to confidential information. "I didn't know what it was doing" sounds much less like a defence when you handed it both the keys and the car.
FINRA has already named the underlying risk. Its 2026 Annual Regulatory Oversight Report, published 9 December 2025, warns that agents operating on sensitive data may unintentionally store, explore, disclose or misuse proprietary information. That warning was written about firms' own agents. Employees' personal agents carry the same risk with none of the governance.
Trade surveillance asks what happened. With agents, the more useful question is what the software could see. That shifts part of the insider trading problem from compliance into information security, and the two teams will need to share one picture of it.
Does your code of ethics require disclosure of AI agents with authority to trade on an employee's behalf?
Do your acceptable-use rules explicitly prohibit connecting personal agents to firm email, calendars or document stores?
Are wallets and prediction-market accounts disclosed alongside brokerage accounts?
And could you pre-clear an agent's mandate, since you will never pre-clear its individual trades?
Information barriers were designed to stop people from talking. The next generation needs to stop software from listening.
If your personal trading program can't yet see wallets and event contracts alongside broker trades, see how firsthand MCO's Digital Asset Personal Trading solution handles this. Contact us for a demo today
An AI agent may be able to access confidential information and execute trades without an employee directing each individual action, creating a gap between traditional information controls and personal trading surveillance.
Agent activity may take place through event contracts, self-custodied wallets, leveraged perps or tokenized equities that do not appear in conventional broker feeds or map cleanly to restricted lists.
The control point can move upstream. In addition to reviewing completed trades, firms may need to consider what information an agent can access and what trading authority it has been given.
The article raises four areas: disclosure of AI agents with trading authority, restrictions on personal agents accessing firm systems, disclosure of wallets and prediction-market accounts, and whether an agent's trading mandate can be pre-cleared.