Robinhood has allowed external AI agents to execute trades in real accounts.
Written by: Boaz Sobrado, Forbes
Translated by: AididiaoJP, Foresight News
On May 27, 2026, Robinhood launched Agentic Trading. Users can connect external models such as Claude, ChatGPT, Cursor, Grok, Codex to their brokerage accounts, allowing agents to conduct research, place orders, and rebalance. Funds must be transferred to a separate agent account, and the agent can only operate with the funds in that account. Notifications are sent for each transaction, and users can disconnect at any time.
Forbes divides this matter into two levels: Robinhood first opens up agency trading; some startups hope to further let AI manage funds. The latter seems a natural extension, but there are legal and capital requirements in between. To understand this span, one must begin with interface, permissions, and division of responsibilities.
Not a robo-advisor, but a trading track with built-in models
Agentic Trading is not a trading tool developed by Robinhood nor is it the in-platform assistant Cortex. Cortex is mainly responsible for research report reading and suggestions, and the final trade is still confirmed by the user. The model of Agentic Trading is "models brought by users, platform provides trading tracks." Connections are completed through MCP: Robinhood provides the trading server address, users complete OAuth authorization on the desktop, and the system subsequently guides the creation of an independent account named Agentic. Official demonstrations show that it takes about half a minute from connection to authorization.
This division of labor determines the allocation of risk. The brokerage is responsible for matching, clearing, account isolation, and notifications; risks related to strategy judgment and instruction misinterpretation are borne by the external model and prompt authors. Robinhood explicitly states it does not control, supervise, or audit these agents. Once data leaves the brokerage environment, it enters the systems of Anthropic, OpenAI, or other model vendors. The platform sells a channel, not advisory services.
How accounts are opened and how wide the permissions actually are
Users must first have a normally functioning personal account with Robinhood. The agent account is an independent self-brokerage account, neither an IRA nor a sub-account of the main account. The amount of funds a user transfers theoretically determines the maximum possible loss. Agents cannot operate the main account, bank account, or retirement account. This functionality is not charged separately, and stocks and ETFs execute according to the existing commission-free rules of the platform.
However, trading permissions and data permissions are not the same barrier. Public statements show that connected agents can still view account numbers, holdings, balances, and history across accounts to assess concentration. In other words, the sandbox constrains trading permissions, but may not limit the visibility of data. Exposing the entire asset holding structure to a third-party model, versus stating that "the agent can only lose the transferred $1,000," represents two different risks.
Instructions are given in natural language. For example, agents can be asked to check at market open daily, halve positions when a single stock retraces over 10%, and reallocate cash to targets outperforming the average of the portfolio; they can also search for directions that have not yet been priced by the public market based on venture financing, mergers and acquisitions, and unlisted valuations, with a $100 test order. Agents can view purchasing power, assess sector exposure, read analyst materials, and then choose to preview, directly order, or cancel orders. Users can set up confirmation for each trade or allow automatic trades within a limit. The app provides real-time updates and profit/loss information.
Initially, this feature only supports US stocks. Options, cryptocurrencies, event contracts, futures, and prediction markets have been listed for future plans, with some functionalities gradually opening up in the summer. Every expansion in capability increases the risks of turnover, leverage, and misoperation. The Gold card also provides a virtual card for agents to use, with customizable limits, and can require confirmation for each transaction, but cannot operate with a physical card number.
Robinhood's risk warning is very clear: it is possible to lose all principal in the account. This is not just a cliché. Models may interpret "appropriate diversification" as high-frequency trading, may turn limit orders into market orders on earnings night, or may repeat ordering during brief data source anomalies. Notifications can alert users to problems, but seeing an issue does not mean there's time to withdraw.
The retail end is almost like a micro fund, legally still self-operated
After accounts are opened, some users assign names and roles to agents: one screening targets, one reviewing closing positions, one generating weekly reports, resembling small hedge funds. Others may invest only $1,000 to test mechanical rotation, and while trades can be executed, profits are limited, and the allocation process is fragile. An experiment of "single agent, real money, starting from $100" even emerged on GitHub.
Similarity does not equal sameness. The funds are one's own, the strategies are written by oneself, and losses are also borne by oneself; there is no external fundraising, nor an obligation to strangers. U.S. investment advisory rules focus on three points: whether advice is provided regarding securities, whether it is done as a business, and whether it is directed at specific situations. Giving instructions to one's own sandbox still constitutes self-operation. If agents continuously adjust portfolios according to others' risk preferences and charge for it or raise funds, their appearance becomes close to that of investment advisors and fund operators.
Regulation does not view this as a toy. Organizations like the SEC and FINRA have already issued joint alerts about AI and investment fraud. The risk lies not only in models making incorrect calculations but also in impersonating advisors and inducing investors to hand over funds to "fully automated high-yield agents." Isolated accounts can limit the maximum loss for a single account but cannot prevent someone from packaging the sandbox as a financial product for external sales.
What startups want to buy is not the prompts, but three pieces of paper
The first is the capacity boundary. Trading stocks in a sandbox while simultaneously trading options, cryptocurrencies, perpetual contracts, and prediction markets does not involve the same level of risk. Robinhood is expanding this in its roadmap because users want to operate all varieties within a single entry. For client-facing products, the wider the entry, the more appropriate testing needs to match the risk level, and it cannot rely solely on the ability to "turn it off."
The second is the attribution of responsibility. The platform claims that external agents are not under its management, users say they only wrote a natural language sentence, and model vendors say they provide only general tools. When all three parties can shift responsibility, the document lacks a key signature: who is responsible for net worth, who prioritizes clients in conflict of interest situations, and who compensates first after a liquidation.
The third is scale and custody. Personal experimental funds can be governed under customer agreements; for external fundraising and ongoing management, it must comply with fund or advisory rules: where funds are stored, how net worth is calculated, what the redemption cycle is, how fees are charged, and how related transactions are disclosed. MCP can reuse the tracks already laid out by Robinhood, but licensing, custody, and capital cannot be replicated.
There is also a parallel clue. On-chain agents with wallets that can pay themselves have been seen, and some are discussing making agents pauseable, transferable, or even tokenizable entities. This involves another set of identity and clearing issues. The focus of this Forbes article is narrower: within the traditional brokerage framework, will agents grow from retail plugins into asset management businesses?
Conclusion
What is currently certain is that order entry can now be automated, isolated accounts can limit the maximum loss for a single trial, and notification and disconnection mechanisms reduce the probability of being "completely unseen." What cannot yet be recorded on product pages is: external models can consistently outperform passive portfolios, the platform will cover agents' mistakes, and this model is equivalent to that of licensed funds.
Robinhood chooses to confine risks within the sandbox and to write responsibilities back to the account opening agreement. If startups remove the sandbox and bring in other people's funds, the only remaining entities that can contain risk will be licenses, custody, and capital. Without any of the three, Agentic Trading remains just a trading tool, and “managing funds” is still just a title.
Disclaimer: This article represents only the personal views of the author and does not represent the position and views of this platform. This article is for information sharing only and does not constitute any investment advice to anyone. Any disputes between users and authors are unrelated to this platform. If the articles or images on the webpage involve infringement, please provide relevant proof of rights and identity documents and send an email to support@aicoin.com. The relevant staff of this platform will conduct an investigation.