Can AI Agents Trade Your Money? Risks of Autonomous Investing

AI agents can now trade crypto and access investment accounts. Learn how autonomous investing works, its risks and the safeguards investors should demand.

Can AI Agents Trade Your Money? Risks of Autonomous Investing

Traditional investing software may screen stocks, rebalance a portfolio or recommend an allocation. An AI agent can potentially go further: inspect a portfolio, decide what action matches a user's instructions and then execute a trade through a connected financial account.

That is no longer theoretical. Coinbase launched Coinbase for Agents in June 2026, allowing AI agents to connect directly to users' accounts and trade, make payments and execute workflows within user-defined limits. German broker Scalable Capital has since opened its investment platform to major AI assistants, allowing customers to analyze portfolios and initiate trades through AI interfaces. 

The question is therefore changing from “Can AI help me invest?” to “How much control should I give it?”

Our coverage of Coinbase's AI trading tools shows how quickly that transition is happening.

How AI Trading Agents Are Different From Robo-Advisers

Robo-advisers are already widely used in investing, but they normally operate inside tightly defined models.

A conventional robo-adviser might ask about an investor's age, risk tolerance and goals, then allocate money across a predetermined group of ETFs and periodically rebalance them.

An AI trading agent can be much more flexible.

A user could theoretically give an instruction such as:

“Keep 60% of my portfolio in large-cap stocks, reduce exposure if volatility rises sharply and invest spare cash in the strongest-performing sector.”

The agent could then combine market data, portfolio information and external research before deciding what to do.

More advanced agents may also perform multiple steps: research an asset, compare alternatives, check available cash, calculate position size and submit the trade.

This flexibility is also the source of much of the risk.

FINRA defines AI agents as systems capable of planning, deciding and taking actions with varying degrees of autonomy. The regulator specifically warns that agents may act beyond their intended authority, be difficult to audit, mishandle sensitive information or make poor decisions because they lack sufficient financial-domain knowledge. 

The Biggest Risk Is Not a Bad Prediction

Investors may naturally focus on whether an AI can predict markets correctly.

That may not be the most important risk.

A wrong stock prediction from a chatbot is inconvenient. A wrong decision from an agent with permission to execute trades can immediately become a financial loss.

Consider an investor who tells an agent:

“Protect my portfolio if markets start crashing.”

What constitutes a crash?

A 3% decline? A 10% decline? A volatility spike? A negative news headline?

If the instructions are ambiguous, an autonomous agent must interpret them. That creates the possibility that it sells investments the user intended to hold.

FINRA highlights this scope-and-authority problem as one of the central risks of agentic AI. 

The same issue appears in crypto. Coinbase's own autonomous-trading risk disclosures warn that AI-driven agents and large language models introduce risks beyond those already inherent in digital assets. 

Coinpaper has also covered agentic wallets, where software can manage crypto within predefined permissions rather than waiting for a human to approve every transaction.

AI Trading Agent Risks

RiskWhat could happenPossible safeguard
Excess authorityAgent trades assets the investor never intended to sellAsset and trade permissions
HallucinationAgent acts on false or misunderstood informationIndependent data verification
OvertradingAgent reacts excessively to short-term signalsTrade-frequency limits
Position sizingAgent creates an unexpectedly large positionMaximum order limits
Account securityCompromised agent gains financial accessRestricted credentials and authentication
Poor auditabilityInvestor cannot reconstruct why a trade occurredDetailed action logs
Market stressModel fails during unusual volatilityHuman approval during extreme conditions

AI Can Be Wrong at Exactly the Worst Time

Machine-learning systems frequently perform best when market conditions resemble the data on which they were developed.

Financial crises are often defined by the opposite.

FINRA has warned that unusual conditions—including major geopolitical events, pandemics or extreme volatility—can create circumstances that models did not adequately encounter during training. The result can be unwanted autonomous trading behavior. 

This is particularly important because markets are adaptive.

Suppose thousands of agents receive similar data and use similar models. They could independently reach the same conclusion and buy or sell simultaneously.

That creates a potential feedback loop.

FINRA has raised concerns that widespread AI trading could contribute to herding, unpredictable market behavior or even forms of machine-driven coordination

The idea has become serious enough to reach central-bank discussions. At the 2026 Jackson Hole symposium, Princeton economist Markus Brunnermeier warned that increasingly capable AI systems could potentially anticipate central-bank behavior and alter how markets react to monetary policy. 

AI Agents Also Create a Security Problem

Allowing an AI agent to trade requires giving software access to something valuable.

That could include:

  • brokerage balances;
  • portfolio holdings;
  • API credentials;
  • transaction permissions;
  • personal financial information.

An agent does not necessarily need unrestricted account control, however.

A safer architecture uses delegated permissions.

For example, an investor might allow an agent to:

  • trade only approved securities;
  • place orders below $500;
  • never withdraw money;
  • make no leveraged trades;
  • require approval before selling long-term holdings.

This is similar to the permission structure emerging in agentic payments, where AI agents receive restricted spending authority instead of complete access to a user's finances.

The distinction will become increasingly important as investment platforms adopt agent integrations.