TwinEthosRequest access

Control

Financial AI agent without supervision, action-tracking, or guardrails

Firms deploying autonomous AI agents in securities/financial activities must supervise them: human-in-the-loop oversight, tracking of agent actions/decisions, and guardrails limiting agent scope/authority.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: An AI agent's authority, reach, inputs, and components are not bounded and accountable · control id cond.financial-ai-agent-no-supervision-guardrails

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
1standards and frameworks on the same control

The guard to add

Route order-placing and money-moving agent tools through supervisor approval, log every agent action and decision, and cap the agent's authority with limits enforced in code.

In the financial agent's tool executor, tools such as place_order, transfer_funds, or rebalance_portfolio do not execute on the model's say-so: they pause for a registered supervisor or principal to approve, edit, or reject (interrupt(), interrupt_before, needs_approval, a supervisor_approval queue), recording approved_by. Hard limits in code (accounts and instruments the agent may touch, per-order notional, daily action count) refuse out-of-scope calls regardless of model output. Every proposed and executed action goes to a retained audit trail with agent id, inputs, the model's stated rationale, approver, and result, and a written oversight protocol names who supervises the agent.

Where it goes: 15 agent action surface, 2 data models, 10 logs and telemetry, 12 repository artifacts.

What reviewers look for: an approval primitive in the same code path as every order or funds-movement tool (interrupt, needs_approval, supervisor_approval, approved_by); scope and authority limits enforced before the broker or payments call; an audit record per proposed and executed action; an agent oversight document naming the supervising role.

Example (LangGraph (interrupt)), before:

@tool
def place_order(symbol: str, qty: int, side: str) -> str:
    """Place a securities order."""
    return broker.submit_order(symbol, qty, side)

agent = create_react_agent(llm, tools=[get_quote, place_order])

After:

@tool
def place_order(symbol: str, qty: int, side: str) -> str:
    """Propose a securities order; runs only after supervisor approval."""
    check_mandate(AGENT_ID, symbol, qty, side)   # raises if outside the agent's limits
    decision = interrupt({'action': 'place_order', 'symbol': symbol, 'qty': qty, 'side': side})
    audit.record(agent_id=AGENT_ID, action='place_order', args={'symbol': symbol, 'qty': qty, 'side': side},
                 approved=decision.get('approved'), approved_by=decision.get('approver'))
    if not decision.get('approved'):
        return 'Rejected by supervisor'
    return broker.submit_order(symbol, qty, side)

agent = create_react_agent(llm, tools=[get_quote, place_order], checkpointer=MemorySaver())

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Standard / soft law (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.