Press play to start listening
Markets have been automated three times. Electronic execution emptied the pits, algorithmic trading took over the processing of orders, and mobile brokerage put an account in every pocket.
Each wave changed how investors and institutions accessed markets, while regulators adapted to risks that became clearer as the technology spread. The current wave is different because automation is moving closer to the decision itself.
Three Waves, and What Each One Actually Automated
Electronic trading automated the venue. Algorithmic execution automated the professional’s order handling. Mobile brokerage automated distribution. Each took over a step in a process a human still owned end to end, and none of them touched the decision itself.
That is the line the current wave crosses. Software capable of making decisions creates a different problem when it is also given authority to act on them. That makes authorization and limits as important as the underlying model, requiring infrastructure designed for delegated authority.
Binance framed the requirement that way when it launched Agent OS on August 20, describing systems built around “allowing users to define what an agent can do,” says Jeff Li, VP of Product at Binance, “and keeping actions transparent and auditable.”
A system that automates delegation therefore needs a permission model from the start. When an agent can both form an instruction and act on it, authorization controls become part of the system rather than a separate supervisory step.
This Wave Automates the Decision, Not the Keystroke
An algorithmic execution system took a decision a portfolio manager had already made and worked it into the market efficiently.
An agent starts a step earlier. Given an objective, it reads the data, forms a view, and produces the instruction, moving automation from the mechanics of a trade into the judgment behind it.
History suggests the consequences take a while to characterize. The IMF found in its October 2025 Global Financial Stability Report that more speculative high-frequency activity can worsen liquidity and raise intraday volatility (PDF), a conclusion that arrived long after the practice had become standard.
If it took roughly a decade to settle what automating execution did to market quality, the honest position on automating delegation is that nobody knows yet. That makes the safeguards in place during the interval more consequential than any forecast about the end state.
The Controls Arrived With the Capability This Time
Many of the controls governing earlier waves of market automation were developed or strengthened after those technologies were already in widespread use. IOSCO, for example, published (PDF) guidance on managing electronic trading risks in 2015, well into the algorithmic era.
Some early agent products are taking a different approach by putting permission controls into the initial design. These can include sandboxed accounts, credentials kept outside the model, spending limits set by the account holder, and mechanisms for revoking an agent’s access.
Binance shipped Agent OS with agents confined to a dedicated sub-account, no withdrawal scope available to grant, and an emergency stop that revokes every connected agent at once. It also states plainly that the platform “is not an autonomous trading system” and “does not remove the need for authorization, safeguards, or careful judgement.”
The design premise is that an agent is a new client of the market, not a new kind of market. “AI agents are becoming another way people interact with financial markets, but they need the same reliable data, infrastructure and controls that users and developers expect today,” Li says. “That makes it easier to create AI-driven financial applications without having to recreate the underlying infrastructure each time.”
The difference is in the sequencing: the permission model is being built into the product rather than left entirely to rules introduced later.
What Regulators Do Next Decides the Rest
The governance response is forming ahead of mass deployment. Singapore’s IMDA published a model governance framework for agentic AI this year built around ex-ante risk assessment, explicit limits on an agent’s autonomy and tool access, defined checkpoints requiring human approval, and end-user transparency.
The complication rarely mentioned is that safeguards carry costs. The Bank of England noted after its February 2026 AI roundtables that human-in-the-loop approval is not free, and that a payment held for review can increase liquidity risk and blunt a hedging strategy. Controls that impose operational costs can also face pressure to be relaxed over time, making their effectiveness under real-world conditions an important part of the equation.
What the Record Actually Predicts
Every previous automation wave widened participation and was survived, which is evidence rather than a guarantee.
The variable this time is whether controls designed before the first serious incident hold up during one.
Market resilience through the agent era may increasingly depend on how well those perimeters are maintained once they start costing something.
(Photo by Behnam Norouzi on Unsplash)

