Technically, yes. Legally, it depends on a question nobody has answered: financial rules are written about what “persons” and “firms” decide, and an autonomous agent is neither. Here is what the law actually says, what the platforms actually allow, and where the liability lands when it goes wrong.
THE SHORT ANSWER
Automated and AI-driven trading is legal in the major markets. Nobody needs special permission to run a bot.
But the rules governing it assume a human supervises the strategy — and several explicitly require it.
Major platforms have chosen to require human confirmation for trades even where the law might not compel it.
Liability, when something goes wrong, lands on developers, operators, promoters, service providers or end users. Never on the agent.
The technical answer to this question is boring: yes, obviously. An API key and a script have been able to trade without human approval since exchanges had APIs. Nothing about attaching a language model to that loop changes what is physically possible.
The interesting answer is regulatory, and it is genuinely unresolved. Financial regulation was built for a world in which a person decides and a machine executes. Autonomous agents invert that, and the rulebooks have not caught up.
What the platforms actually allow
Start with practice rather than theory, because the platforms have already made a choice.
When Binance launched Agent OS and its MCP server in August 2026, it built in a specific constraint: for actions involving trades or fund transfers, the user remains responsible for confirming the transaction before it is executed. The connection carries no withdrawal scope, agent activity is isolated in a dedicated sub-account, and Binance stated plainly that the system does not make investment decisions on a user’s behalf.
The largest exchange in the world shipped agentic trading with a human confirmation step it was not obviously required to include. That is a signal about where the legal risk is understood to sit.
Coinbase has taken a comparable approach with its agentic finance products, allowing agents to interact with accounts within permissions and limits set by users. The pattern across the industry is the same: agents propose, humans dispose.
Note what this means practically. On a regulated major venue, you generally cannot today hand an agent unsupervised authority to trade your account. You can automate around that with your own infrastructure and raw API keys — which is legal — but you are then the operator, and everything below applies to you.
The law: automation is legal, supervision is assumed
There is no jurisdiction where using AI to trade is itself prohibited. Regulators permit AI tools provided they comply with existing financial law. The constraints come from rules that were written with a supervising human in mind.
Rule | Jurisdiction | What it requires |
SEC Rule 15c3-5 (Market Access Rule) | US | Broker-dealers providing market access must establish, document and maintain risk management controls and supervisory procedures reasonably designed to manage financial, regulatory and other risks. |
FINRA Rule 3110 (Supervision) | US | Firms must maintain supervisory arrangements — in practice, human oversight capable of explaining and justifying AI-driven trades. |
MiFID II algorithmic trading provisions | EU | Algorithmic trading firms must maintain systems and risk controls, keep detailed records and notify regulators of their activities. |
MiCA | EU | Licensing plus organisational, operational, prudential, market abuse and AML expectations for crypto-asset service providers. |
EU AI Act | EU | Risk-based framework. In force since August 2024, GPAI obligations from August 2025, transparency rules from August 2026, high-risk rules on a revised timetable. High-risk systems face requirements on risk management, data quality, logging, documentation, human oversight, robustness, cybersecurity and accuracy. |
DORA | EU | Digital operational resilience, ICT risk and third-party dependency — directly relevant to agents relying on external models and cloud tooling. |
The Market Access Rule is worth dwelling on, because it exists for exactly this reason. It was implemented after a series of algorithmic failures, most memorably the 2012 Knight Capital incident in which an unchecked algorithm lost roughly $440 million in 45 minutes. Everything in modern automated-trading supervision descends from the recognition that software can destroy a firm faster than anyone can react.
The gap: rules about “persons”
Here is the structural problem, stated by researchers surveying the regulatory landscape more clearly than any regulator has managed.
Existing frameworks assume that algorithms execute predefined strategies under close human supervision. They do not adequately address systems that modify their own strategies, learn market conditions and make autonomous decisions about risk-taking without predetermined boundaries.
And the drafting compounds it: regulatory language consistently refers to persons or firms making decisions, which creates ambiguity about how rules apply when an autonomous agent makes consequential choices without direct human approval for each action.
So the honest answer to the headline question in a regulated context is: an agent can place the order, but somebody is always deemed to have made the decision. The law has no category for a decision nobody made. It resolves that by attributing the decision to whoever deployed the system.
What stays illegal no matter who — or what — does it
This is the part builders most often get wrong, because it is invariant to the automation question.
Spoofing and layering — placing orders with no intention of execution to mislead the market.
Wash trading — trades that create artificial volume without genuine change in ownership.
Front-running and manipulative liquidity signalling.
AI washing — false or exaggerated claims about AI capabilities, which regulators actively penalise.
The uncomfortable implication for anyone building learning systems: an agent optimising for profit may independently discover that spoofing works. It has no concept of market abuse; it has a reward function. If it converges on a manipulative strategy, the conduct is still market abuse and the operator still owns it.
AI compresses decision cycles from minutes to milliseconds, which improves execution quality but also amplifies precisely the behaviours regulators already target. That is why AI systems are increasingly treated as autonomous market actors requiring controls, auditability and user protections rather than as neutral tools.
Who is liable
The answer is consistent across every analysis of this question, and it is the single most important thing to understand before deploying anything.
Where AI-driven tools are used for unlawful purposes, liability is more likely to fall on developers, operators, promoters, service providers or end users rather than on the system itself. There is no legal person called “the agent” to hold responsible.
Several less obvious exposures follow from that:
Investment adviser registration. Depending on how a bot is used — particularly if operated for others — a business or individual may need to register with the SEC. If the trading involves derivatives or futures, CFTC jurisdiction may also be triggered.
Money transmission. Analysts have raised the possibility that autonomous agents conducting financial transactions at scale could constitute unregistered money services businesses.
VASP obligations. FATF guidance on virtual assets addresses algorithmic entities and requires member states to extend VASP AML obligations to entities facilitating transfers on behalf of customers — a definition that arguably reaches autonomous agent infrastructure operators.
Operational resilience. An agent depending on third-party models and cloud-hosted tooling sits squarely inside ICT third-party risk regimes.
A payment or trading agent using stablecoins, third-party models and cloud infrastructure cannot be governed under one regulatory lens alone. It touches AI rules, crypto rules, outsourcing rules and AML rules simultaneously.
Where the regulators are heading
The CFTC established an Innovation Task Force in early 2026 whose mandate explicitly spans blockchain and cryptocurrencies, AI and autonomous systems, and prediction markets — indicating regulators are examining how automation and market design interact, not just how assets are labelled.
The White House released a National Policy Framework for AI in March 2026 supporting regulation through existing agencies rather than new AI-specific legislation.
The Financial Stability Board identified AI-related vulnerabilities including third-party dependency, service provider concentration, market correlation, cyber and model risk, and has consulted on sound practices for organisation-wide AI governance.
Across Asia the picture stays fragmented, from highly restrictive positions in mainland China to licensing-based regimes in Hong Kong and Singapore.
The direction of travel is regulation through existing agencies applying existing rules, rather than a bespoke autonomous-trading statute. That is faster, but it leaves the "persons and firms" ambiguity unresolved — which means it will most likely be settled by an enforcement action rather than a rulemaking.
What this means if you are building
Trading your own funds with your own agent is legal in the major markets. You are the operator and the decision-maker in law, regardless of how autonomous the system feels.
Operating for others changes everything. Managing third-party money or offering a trading agent as a service can pull you into adviser registration, licensing and supervision obligations.
Build the audit trail first. Every framework above — 15c3-5, MiFID II, the AI Act, MiCA — converges on logging, documentation and the ability to explain a decision afterwards. If you cannot reconstruct why the agent acted, you cannot satisfy any of them.
Keep a human-legible kill switch. Interruption mechanisms are expected in adjacent domains such as algorithmic trading, and their absence is conspicuous.
Constrain the strategy space, not just the spend. Position limits stop losses; strategy constraints stop your agent discovering market abuse on its own.
Do not overstate the AI. AI washing is enforced against, and marketing copy is evidence.
The bottom line
Can AI agents trade crypto without human approval? Technically yes, and people are doing it today with their own funds and their own API keys.
But the framing of the question is slightly wrong. Financial regulation does not really ask whether a human approved each trade. It asks who is responsible for the system, whether that person maintained adequate controls, and whether the resulting conduct was lawful. On all three, the answer is the same whether a person clicked confirm or a model did.
That is why Binance built a confirmation step it may not have strictly needed, and why the sensible design pattern everywhere is the same: let the agent decide, and let something deterministic — and attributable — authorise and settle.
The agent can trade. It cannot be responsible. Until the law invents a category for a decision nobody made, that gap is filled by you.
Important
This article is general information about a developing regulatory area. It is NOT legal, regulatory, investment or tax advice, and it is not a substitute for qualified counsel in your jurisdiction. Rules differ significantly by country and by activity, and several frameworks referenced are in transition. Whether any particular arrangement triggers registration, licensing or supervisory obligations depends entirely on specific facts. Automated trading carries substantial risk including total loss. Anyone deploying trading agents — particularly on behalf of others — should take specific legal advice before doing so.
Sources
SEC, FINRA, CFTC and FATF rules and guidance, MiFID II, MiCA, DORA and EU AI Act materials, Financial Stability Board publications on AI in finance, published academic surveys of agentic AI regulation and agentic commerce security, plus analysis from Aurum Law, Blockchain Council and company announcements from Binance and Coinbase.
Bitnxt tracks exchanges, trading infrastructure and licensed service providers across the US, UK, EU and UAE. Explore the directory at bitnxt.io.

.jpg)
