# The Confirmation Step Checks the Order, Not the Trader
> At least ten brokers and vendors connected AI assistants to live accounts this year. The safeguards check the order and the money. None checks the trader.
**Published:** 2026-09-28  
**Reading time:** 12 min read  
**Tags:** ai-order-entry, brokers, prop-firms, behavioural-risk, revenge-trading, industry
In the first half of 2026 at least ten brokers and platform vendors connected AI assistants to live client accounts, and several let the assistant draft or send orders. Every launch that lets the assistant trade builds the same kind of safeguard, and on the human-approved tier it is a confirmation step: the assistant reads the order back and waits for a yes, on the autonomous tier the agent is walled into a sub-account, and none of them can move money. Each of those checks the order or the money. None checks the trader. A trader sixty seconds past an unplanned loss can now re-enter with a sentence and a yes, and where the vendor logs a source flag the firm's record will show, for the first time, how the order was placed, and still nothing about the state of the person who confirmed it. This is for the operator deciding whether to switch AI order entry on, and what to ask the vendor first. Coaching, not financial advice.

## What shipped this year

The decision is on the desk at brokers and prop firms alike: whether a client may place an order from the AI assistant they already use. By one industry count, at least ten retail brokers and platform vendors had wired AI agents into live client accounts by June 2026, and the list has grown since. A platform vendor that serves brokers and prop firms released order placement from inside a chat in September. A listed UK broker connected its UK CFD accounts to an assistant the same month, read-only, after another broker's Australian business had done the same in May. At least one prop firm now offers its funded traders a read-only connection to their account data, rules and payout status.

The launches sort into three tiers. Read-only, where the assistant can see the account and answer questions about it. Human-approved, where the assistant drafts an order and the client signs it off. Autonomous, where the agent trades on its own inside a walled sub-account. Across every launch in that count, one rule held: no agent can deposit, withdraw or move client money.

Give the engineering its due before anything else. The vendor release read for this post ships turned off. The broker switches it on per brand and chooses who receives it by client group, trading terms, country or a manual allowlist. Each connection is bound to one account and secured with a token the trader controls. The assistant answers only about the connected account and the broker's own instruments, and declines requests for advice, recommendations or predictions. On prop accounts, an order placed through the assistant goes through the same risk engine as any other and respects the challenge and daily-loss limits. Nobody here is being careless. This is how you would build it.

## The confirmation step everyone built

On the human-approved tier, the one the vendor release describes, one control sits in front of every order. The assistant restates it and waits. In the vendor's own words, it reads back "the instrument, direction, size, order type, price, stops and margin effect", and there is "nothing executed until they explicitly say yes". On the autonomous tier the control is the wall around the money: the agent trades a sub-account it cannot fund or empty. The answer engine's own reply, asked whether a chatbot can trade an account, describes the first of these and nothing else: a manual review and confirmation step, there to protect the funds.

Be precise about what that step protects, because it protects it well. A readback confirms that the order is the order the trader meant. It catches a misheard size, a wrong direction, a stop on the wrong side of the price. The allowlist confirms the account is one the broker chose to enable. The instruction set tells the assistant not to suggest the trade. The funds rule confirms the money stays where it was. Four checks, and every one of them is a check on the order or the account.

## Every check on this path is a check on the order

Nothing on the path asks whether this trader should be placing an order at all, and nothing on it is built to. The yes is the only input the path has from the person, and a yes from a trader sixty seconds past an unplanned loss arrives in the same form as a yes from a trader working a plan.

Discentra's working definition of a [revenge trade](/glossary/revenge-trading) is a re-entry within sixty seconds of a closed loss at a larger size. That is a Discentra working definition, labelled as one, and it is [the rule our own engine runs](/use-cases/reduce-revenge-trading). A readback fits inside sixty seconds with time to spare. For a trader who has already decided, the readback is the last step, and it takes as long as the word yes.

The length of the path from impulse to live order is what changed this year. On a terminal it ran through a ticket: open the instrument, set the size, place the stop, click. On the human-approved tier it runs through a sentence and a word, with no terminal open and the approval given inside the assistant's own app. Every delay on that path was a firm's choice, as [the post on retention latency](/blog/the-negotiable-delay) argued, and this one has been chosen down to a syllable. The [window between a trigger and the next trade](/glossary/intervention-window) did not get longer to match.

None of this is an argument against the feature. A client who already uses an assistant for research will use it for orders somewhere, and a broker that offers the path inside its own platform at least sees the order. The argument is narrower: the safeguard the industry converged on is a safeguard for the order, and the industry has not yet built one for the trader.

## The question the survey did not ask

A listed UK broker surveyed 8,506 of its own Australian clients, and the trade press reported the results in September. Just under half, 48.6%, use AI to support investment decisions, 33.1% occasionally and 15.6% regularly. Fewer than a third, 29.4%, trust its market insights. The most common uses were research and education; fewer used it to generate trade ideas. And the survey did not ask whether clients would let AI place trades.

Read the sample carefully. 8,116 of the respondents were clients of the broker's share-investing platform and 390 were CFD clients, so this is an investor sample, and the trust question covered AI-generated market insights only. Read it for what it is: the one client survey we found asked about research, and the order was not on the questionnaire.

The product wave answered the second question anyway. That is a sequencing observation. A firm that ships the feature its clients already use elsewhere is doing what a firm does, and the survey's own respondents were using the tools before anyone asked them about it. It means the industry is designing the yes for a client whose own survey never asked how they intend to use it, and the gap between use and trust in the one sample we found runs to nineteen points.

## The new field

The wave also created something a retention desk has never had. For the first time an order carries a label saying how it was placed. In the vendor release read for this post, every AI-originated order is logged to the CRM with its own source flag, so risk and compliance can tell it from a manual order. One vendor has learned to record the provenance of an order; the second question below asks whether yours has.

That is a useful field, and it is a field about the order. The same event feed that carries the flag carries the three things a firm can read about the trader, the [behavioural triggers](/glossary/behavioural-trigger) it already logs: how long after the last closed loss the next order arrived, whether the size moved against the last position, and how many trades the session has produced, the pattern the glossary files under [overtrading](/glossary/overtrading). Those are [the triggers a broker's own data already exposes](/blog/behavioural-triggers-every-broker-should-monitor), and the flag adds a comparison to them that did not exist before: AI-originated re-entries against manual ones, on the same three measures, from the same feed.

State the limit. Those are inferences from actions. The feed records what the trader did and when, and nothing about why, and [a firm's behavioural record is already wrong in two directions](/blog/retention-data-wrong-two-directions) before any assistant enters it. The flag changes one thing, which is when the firm chooses to look. The field is worth more the earlier it is read: at month end it feeds a report, and before the next order it can send someone to the trader, and that timing is the whole difference between [retention tooling that acts after the fact](/blog/the-intervention-gap) and [a layer that acts inside the window](/trader-retention-software).

## Five questions before switching it on

The decision to enable AI order entry belongs to the firm, and this post takes no view on it. It takes a view on what to ask first.

- Which client groups, countries and account terms can we exclude, and is it off by default?
- Is every AI-originated order flagged in the CRM, and can we export by that flag?
- What is the median time between a client's last closed loss and an AI-originated re-entry, and who reads it before the next order?
- Does anything reach the client between the loss and the yes that is not another number? The content of that something, and [why it never says stop](/blog/the-coaching-call-never-says-stop), is its own question.
- Does the assistant refuse advice, predictions and position sizing, and is the refusal logged?

Most vendors answer the first two well, because they are questions about the order. The last three are questions about the trader, and they are the ones to ask twice.

The state of the trader who placed the order is still the field nobody keeps.

## Sources and notes

- **The industry count and the three tiers** (at least 10 retail brokers and platform vendors wired AI agents into live client accounts between January and June 2026; launches sorted into read-only, human-approved and autonomous tiers; no launch reviewed lets an agent deposit, withdraw or move client money): Finance Magnates Intelligence, reported in Finance Magnates, 8 June 2026, "[Claude Powers Nine of Ten Broker AI Agents That Now Trade Live Accounts](https://www.financemagnates.com/forex/analysis/claude-powers-nine-of-ten-broker-ai-agents-that-now-trade-live-accounts/)". An outlet's own study and a floor, not a census; it covers the first half of the year, so the September launches described above fall outside it.
- **The vendor release** (the readback, the yes, the token bound to one account, enablement by group, trading terms, country or allowlist, the source flag, the prop-account risk engine and limits, the refusal of advice, recommendations or predictions): a platform vendor's announcement dated 16 September 2026, published through FinanceWire and carried by [Investegate](https://www.investegate.co.uk/announcement/fnw/financewire-news--fnews/leverate-launches-mcp-for-traders-to-connect-/9775549), FX News Group and Finance Magnates. A vendor describing its own product. The vendor is not named in the body; the release is linked so the wording can be checked.
- **The read-only launches** (a listed UK broker's UK CFD accounts connected read-only in September 2026, spread betting accounts not yet supported; another broker's Australian business putting a read-only CFD assistant into the same assistant's app store in May 2026): Finance Magnates, 24 September 2026, "[CMC Markets Follows IG Australia Into ChatGPT as Rivals Let AI Place Trades](https://www.financemagnates.com/forex/products/cmc-markets-follows-ig-australia-into-chatgpt-as-rivals-let-ai-place-trades/)". Trade-press reporting of the launches.
- **The client survey** (8,506 respondents, 8,116 share-investing clients and 390 CFD clients; 48.6% use AI to support investment decisions, 33.1% occasionally and 15.6% regularly; 29.4% trust its market insights; research and education the most common uses; the survey did not ask whether clients would allow AI to place trades): the broker's own survey, reported by Finance Magnates, 21 September 2026, "[Brokers Add AI Execution Tools, but Only 29% of CMC Markets Clients Trust Its Insights](https://www.financemagnates.com/forex/brokers-add-ai-execution-tools-but-only-29-of-cmc-markets-clients-trust-its-insights/)", and by Australian Associated Press. Self-reported, one broker's own clients, an investor sample, survey date not stated; the nineteen-point gap between use and trust is Discentra's arithmetic. The broker's own publication of the survey was not located at the time of writing.
- **The answer engine's reply** (a manual review and confirmation step, there to protect the funds): the AI-generated answers a major search engine returned to three queries about AI assistants placing trades, read 25 September 2026. An observation of what the engine says, not a source of fact.
- **The prop-firm connector** (a read-only connection for funded traders to their account, payouts, performance and trading rules; it cannot place trades or move funds): one prop firm's own product page for its assistant connector, read 25 September 2026. The firm is not named in the body.
- **The sixty-second re-entry rule and the intervention window**: Discentra's own working definitions, labelled as such above and in the glossary. Not published findings.
- **No firm, vendor, platform or AI model is named in the body.** The linked articles name them. Nothing here is a view on any firm's decision to offer or withhold AI order entry.
## Frequently asked questions

### What does the confirmation step in AI order placement protect?

It checks the order. Before anything reaches the market, the assistant reads back the instrument, direction, size, order type, price, stops and margin effect and waits for the trader to say yes. That confirms the order is the one the trader meant, on a permitted instrument, in an authorised account, with the money where it was. It is a good design for what it covers. It does not cover the state of the person saying yes. A yes given a minute after an unplanned loss reads the same as a yes given from a plan, and nothing on the order path is built to tell them apart.

### Can a trader revenge trade through an AI assistant?

Nothing on the order path prevents it. Discentra's working definition of a revenge trade is a re-entry within sixty seconds of a closed loss at a larger size, and a readback and a yes fit inside that window with time to spare. The assistant is instructed to decline advice, recommendations and predictions. That keeps it from suggesting the trade. Noticing that the trader has just taken a loss is not among its instructions. The signals that mark a revenge trade, time since the last close, size against the last position, trades in the session, sit in the same event feed the order comes from. Whether anyone reads them before the next order is the firm's choice. Coaching, not financial advice.

### What should a broker or prop firm ask a vendor before enabling AI order entry?

Five things, in this order. First, the client groups, countries and account terms that can be excluded, and whether the feature is off by default. Second, whether every AI-originated order is flagged in the CRM and can be exported by that flag. Third, the median time between a client's last closed loss and an AI-originated re-entry, and who reads it before the next order. Fourth, whether anything reaches the client between the loss and the yes that is not another number. Fifth, whether the assistant refuses advice, predictions and position sizing, with the refusal logged. Vendors tend to answer the first two well because they are questions about the order. The last three are about the trader, and those are the ones to press on.

### Does an AI-originated order flag help with behavioural risk?

It helps more than it was built to. The flag exists so risk and compliance teams can tell an assistant-placed order from a manual one, and it does that. Read alongside the rest of the event feed, it also lets a firm compare AI-originated re-entries with manual ones on the three things that mark a behavioural trigger: time since the last closed loss, size against the previous position, and trades per session. Where the flag exists, that comparison costs nothing to run. The limit is that these are inferences from actions; the feed records what the trader did, never why. Read at month end it becomes a report. Read before the next order it becomes a reason to reach the trader. Coaching, not financial advice.


---

This is a Markdown mirror of [https://discentra.ai/blog/the-confirmation-step-checks-the-order-not-the-trader](https://discentra.ai/blog/the-confirmation-step-checks-the-order-not-the-trader). Generated for LLM citation. © Discentra Ltd. Coaching, not financial advice.
