METAL

Brokerages open accounts for AI agents

This spring, eToro, Moomoo, and Robinhood each rolled out dedicated channels letting AI agents like Claude and Codex place orders directly. In an era where you can command a strategy in plain language without writing code, the question is how far you should hand over the keys to your account.

Brokerages open accounts for AI agents

Image: generated by METAL AI

Summary

  • This spring, eToro, Moomoo, and Robinhood rolled out dedicated accounts, built on MCP, that let AI agents place orders directly.
  • Combined API trading volume at three South Korean brokerages hit 37.41 trillion won in 2025 and had already topped 17 trillion won by mid-April this year.
  • Research shows AI tends to pile into stocks with heavy media coverage and struggles to size bets properly, so setting a loss limit first is essential.

Starting this spring, US brokerages have opened dedicated channels one after another that let AI agents place orders directly. eToro launched an MCP server alongside a developer app store on April 14, Moomoo unveiled its API Skill on April 23, and Robinhood began an agentic trading beta on May 27. What the three have in common is that the investor isn't writing code — they're giving instructions in plain language to an agent like Claude or Codex, and that agent then reaches into the brokerage account itself. This marks a shift from an era when individuals quietly ran their own bots to one where brokerages open the front door to bots directly.

To unpack that a bit: MCP is a connection protocol that lets AI agents call an external service's functions in a standardized way. When a brokerage exposes order placement and account queries through this protocol, an agent can call those functions directly and place orders instead of tapping through a screen.

Robinhood's setup has been disclosed in the most detail. A customer opens a separate agentic-only account alongside their existing one, then connects an MCP-compatible tool — Claude Code, Claude Desktop, ChatGPT, Codex, Cursor, or Grok — to a single address Robinhood provides. The agent can read balances and trade history across all accounts, but it can only place orders within the dedicated account, and a notification appears in the main app every time an order goes out. Robinhood's own guidance states, side by side, that if an investor instructs the agent to act without approval, it can trade without confirmation — and that ultimate responsibility rests entirely with the investor.

This structure resembles a valet key. Many cars today come with a valet key that starts the engine but can't open the trunk or glove compartment — and that's exactly the role Robinhood's dedicated account plays. You hand the car to the agent, but the door to the trunk holding money in your other accounts stays locked. The key point of this analogy is that after handing over the key, you only see where the car goes through a notification — the agent is already driving.

Moomoo emphasized something different. According to its April 23 announcement, the API Skill converts an investor's plainly worded trading intent into an executable strategy and monitors the US, Canadian, Hong Kong, Singaporean, and Japanese markets around the clock. Data stays on the investor's local environment and doesn't pass through third-party AI servers, and paper trading is the default, meaning strategies get backtested against historical data before touching a live market. Neil McDonald, Moomoo's US CEO, said: "We're seeing a fundamental shift where investors are moving from simply accessing information to finding structured ways to act on that information."

eToro moved a month earlier. When it opened its developer app store on April 14, it also released agent skills, an MCP server, and no-code app-publishing tools, letting investors set a budget and risk limits on a sub-account and hand trading over to an agent connected to it. Germany's Scalable Capital also launched Agentic Investing, connecting Claude, ChatGPT, and Grok via MCP. Within half a year, four online brokerages across the US and Europe opened the same door through the same protocol.

The numbers are already large domestically, too. According to a tally reported by the Seoul Economic Daily on May 5, combined API trading volume at three South Korean brokerages — Korea Investment & Securities, Kiwoom Securities, and Daishin Securities — reached 37.41 trillion won for all of 2025, and had already surpassed 17 trillion won by mid-April 2026. At the current pace, the report calculates, annual volume could top 60 trillion won, and if Meritz Securities launches its open API this year as planned, the 100-trillion-won mark comes into view. One brokerage official predicted that brokerage platforms will evolve beyond apps into trading infrastructure, with AI agents fused into the front end.

The domestic setup looks somewhat different from the US model. The new APIs from Korea Investment & Securities and Kiwoom Securities use a REST-based format authenticated with an app key and secret key, so they work on Mac or Linux too, and code written by an agent can be plugged straight in. But unlike in the US, where brokerages opened MCP servers directly, there's an extra step here: the agent writes code, and that code calls the API. If the US model hands the valet key straight to the agent, the domestic model is still at the stage where the agent writes the driving manual rather than driving itself.

Before this structure spreads further, two pieces of research deserve attention. In an April working paper from the National Bureau of Economic Research, Bruce Carlin, Ryan Israelsen, and Christopher Wasan had several large language models generate daily stock recommendations and compiled the results into a time series. Rather than diversifying, the AI models piled into large-cap stocks with strong momentum and high price-to-book ratios — and above all, they favored companies with heavy media coverage. Whether the positions were traded actively or simply held, no statistically significant excess return emerged. Buying stocks that get a lot of news coverage is exactly the behavior individual investors are most often warned against.

The second is an experiment Elm Wealth ran in June. Shown historical front pages of newspapers and asked to predict market direction, Claude beat human performance in about 200 sessions 76% of the time, followed by ChatGPT at 63%, Grok at 51%, and Gemini at 43%. But when it came to deciding how much to bet, the models — even while apparently aware of risk-management theories like the Kelly criterion — bet excessively in practice. In other words, they were good at picking what to buy but bad at deciding how much to buy — and in a structure where an entire account is handed over, that second weakness is far more dangerous than the first.

Brokerages are aware of this weakness too, which is why they've only opened the door halfway. Robinhood restricts its dedicated account to cash only, blocking margin trading, lets users require human approval for every order if they choose, and includes a button to sever the connection instantly. Moomoo defaults to paper trading, and eToro requires budget and risk limits to be set on the sub-account first. Three companies, describing it in different terms, built essentially the same safeguard — because the real danger isn't the agent being wrong, it's the agent betting too big.

So for anyone looking to actually try this, what matters isn't a list of tools but a sequence. First, grant read-only access and watch how the agent reads your account. Then run it for a month in paper trading or on a small dedicated account. Only after that should you write out a loss limit and a maximum daily order count in plain sentences and hand them to the agent as rules. Telling the agent, before anything else, under what conditions it must never buy — rather than simply telling it what to buy — is the one place where an individual can actually guard against the weaknesses both studies point to.

Now that brokerages have opened the front door, bots no longer need to sneak in through the back. A structure where the party granting access also sets the rules and sends notifications is clearly safer than the era when individuals quietly ran their own bots on the side. But that safety only works if the investor writes down the limits before handing over the key — and none of the safeguards built by the four brokerages that opened their doors this year can write that one line for you.

Comments