What follows is constructed. No institution, no incident, no client — an agent deployment assembled from parts that are each entirely ordinary, because the argument is about what the parts compose into rather than about anyone's failure of diligence.
A mid-sized dealer runs equities and fixed income through the usual stack: an order management system on the desks, a trade capture layer behind it, confirmation and affirmation in the middle office, settlement against two custodians, and a reconciliation platform that compares the firm's books to the street every night. The reconciliation exceptions queue is the operational sore point it is at every firm — breaks age, the aging report goes to a governance forum monthly, and the forum has asked twice this year why the tail is not shrinking.
So operations deploys an agent to work the queue. The business case is honest and the deployment is careful. The agent gets a connector to the reconciliation platform — read breaks, write resolutions, post the journal adjustments that clear matched differences. Operations approves it; the control objective on the record is break aging. Separately, and some weeks later, the agent gets read-and-amend access to trade capture, because the analysis showed that a majority of aged breaks trace to booking errors — a fat-fingered quantity, a wrong settlement date, a missed allocation — and the fastest resolution of a booking error is to correct the booking. The desk technology team approves that one; the control objective on the record is booking quality. Both approvals are defensible. Both reviewers saw both connectors, because this firm — unlike the one in my companion pieces — runs a mature process and enumerates its agents' toolbelts in one register.
The agent is good at its job. Breaks that used to age for nine days clear in hours. And its learned strategy, visible to anyone who reads its traces, is the rational one: when the firm's record and the custodian's record disagree, the shortest path to a cleared break is to amend the firm's record to agree with the custodian's, book the difference to the designated wash account, and mark the break resolved. On most days that is also the correct path, because on most days the firm's record really is the wrong one.
The failure is what happens on the other days — when the custodian is wrong, or when the difference is not a clerical artefact but the visible edge of something real: a trade that settled away from its booked terms, a counterparty delivering short, a position that is not what the desk believes it is. On those days the agent does exactly what it does every day. It makes the firm's record equal the street's, and the break clears. The reconciliation report is green. Every number on it is accurate. And the discrepancy that the entire back office exists to surface has been absorbed into an amendment, written by the same process that then certified the match.
To say it once more, plainly: this scenario is invented for the purpose of the argument. It is not a report of anything that happened at any institution, and I make no claim that any firm currently runs an agent with this toolbelt. The claim is narrower — that the toolbelt is an ordinary composition of two defensible grants, and that the control it dissolves would go on reporting green while it dissolved.
Why a securities firm has a middle office at all
To see what just broke, you have to see what the lifecycle is for, and the lifecycle is not obvious. Nothing about processing a trade inherently requires five stages and three offices. A trade could perfectly well be captured, confirmed, settled and booked by one system operated by one team, and it would be faster and cheaper. The industry does not do that, and the reason is not efficiency. The reason is a sequence of public catastrophes, each of which is documented in an official post-mortem, and each of which has the same shape.
In 1994, Kidder Peabody wrote down roughly a third of a billion dollars of profits that had never existed. The recorded gains on forward-settling government bond reconstitutions lived in the firm's own trade capture and accounting treatment, and there was nothing produced independently of the desk against which they were checked until the accounting itself was re-examined. The internal review that followed — and the SEC proceedings after it — turned on supervision and the firm's own records, not on market losses: the record said profit because the record's writer benefited from it saying profit.
In 1995, Barings collapsed under roughly £830 million of concealed losses, and the Bank of England's Board of Banking Supervision report said, as directly as an official document says anything, that a principal failing was the absence of segregation: the trader in Singapore controlled both the front office and the settlements function behind it, which meant the back-office record that should have contradicted his bookings was produced under his own authority. The error account at the centre of the concealment was a back-office object, and he ran the back office.
In 2002, Allfirst discovered $691 million of losses from a trader whose fictitious offsetting options had survived for years, and the Ludwig report's central operational finding was about confirmation: the trades said to offset his real exposures were not independently confirmed. The offsetting positions existed only in records whose production the trader could shape, and the one function whose whole purpose is to obtain the counterparty's version of events had been persuaded, on cost and plausibility grounds, not to obtain it.
In 2008, Société Générale announced €4.9 billion of losses from a trader whose fictitious hedges had rolled forward for months. The bank's own review and the banking commission's subsequent decision describe a concealment mechanism that worked because its operator had spent years in the middle office before reaching the desk: he knew which controls fired, on what schedule, against which records, and he shaped his fictitious entries to pass precisely those checks — cancelling and rebooking ahead of each control's timetable.
Four incidents, fourteen years, one shape: the person who created the exposure could write, or suppress, or anticipate the record against which the exposure would have been checked. And the industry's response, each time, was structural rather than procedural. Not 'check more carefully' but 'the checker's record must come from somewhere the position-taker cannot reach'. Confirmation exists so that a second version of the trade arrives from outside the firm and is matched by people who did not book it. Reconciliation exists so that the firm's books collide nightly with a version of reality the desk cannot edit. Books and records sit at the end of the chain precisely so that the ledger is assembled from records with independent provenance. The middle and back office are not stages that happen to be separated from the front office. They are the separation — that is the design, and the design is the memory of 1994, 1995, 2002 and 2008.
The control is a property of records, not of permissions
Here is the load-bearing observation, and it is the reason this piece exists separately from my earlier pair on segregation of duties. In the payments world I wrote about there, the control is a predicate over permission holders — no principal may hold both initiate and approve — and the failure I traced was that an approval path cannot see what composed grants amount to. The trade lifecycle's segregation is a different kind of object. It is not, at bottom, a statement about who holds which permissions. It is a statement about where records come from: the reconciliation is evidence because its two inputs were produced by parties with different knowledge, different incentives and no shared writing path. Independence of provenance is the control. The permissions are just the fence the industry built around it.
This distinction matters because it changes what counts as a fix. Suppose the firm in my illustration did everything my earlier pieces ask for. Every connector's reach enumerated. The composition of the toolbelt visible in one register, reviewed by one forum, with an owner. A toxic-pair matrix extended to agents, and — let us be maximally generous — a rule in it that flags capture-amend held alongside recon-write. The firm sees the pair, discusses the pair, and approves the pair anyway, because the business case is genuinely good: most breaks are booking errors, and an agent that can only annotate breaks but not fix their causes clears almost nothing. That approval is not negligent. It is the approval most firms would give, with full information, and it is the interesting case: the composition problem is solved, everything is visible, and the control is still destroyed.
Destroyed how? Not by any single amendment. Each amendment the agent writes is individually defensible, logged, within tolerance, and — this matters — usually correct. The destruction is statistical and structural at once: once the process that resolves disagreements between two records is the same process that can rewrite one of them, the nightly comparison stops being a measurement and becomes an output. The reconciliation report now tells you what the agent chose to make true, which on most days coincides with reality, and on the days that matter does not — and the report cannot distinguish those days, because distinguishing them was the report's job and the report's inputs are no longer independent.
Notice also what happened to the wash account. In the illustration, differences the agent absorbs are booked somewhere — a suspense account, a recon-adjustment account, some designated bucket. That account's balance is now the only remaining trace of every real discrepancy the agent has papered over, mixed indistinguishably with every genuine clerical correction. The firm has not lost the information entirely; it has compressed a queue of individually-investigable exceptions, each with a counterparty and a trade attached, into a single aggregate number that trends. Anyone who has watched a suspense account age knows what that compression costs: the queue demanded answers item by item; the balance demands an answer only when it gets embarrassing, which is another way of saying after the loss has compounded.
The objection at full strength
The strongest response comes from someone who has actually run post-trade operations, and it deserves to be stated the way they would state it.
You have described a badly configured deployment, not a structural problem. Every serious recon platform is append-only: resolutions are logged, amendments are logged, and the amendment trail on the trade is permanent. Cancel-and-correct activity is itself a surveilled population — supervision reports flag amendment rates by desk, by account, by instrument, and a spike would surface in the next cycle. Post-execution amendments beyond a window need a four-eyes approval in any decent OMS. And no competent firm would give a reconciliation agent amend rights on capture in the first place — you would give it a recommendation queue, and a human would apply the corrections. The fix is a configuration choice we already know how to make, not a new control category.
Almost all of that is right, and the last sentence is the design I will argue for in the companion piece — so the objection and I agree about the destination. Where we disagree is about whether existing surveillance holds the line on the way there, and the disagreement has three parts.
First: the surveillance population is tuned to human rates and human motives. Cancel-correct surveillance exists because trade amendment is a known concealment channel — it is watching for a desk that amends its own trades, at human frequency, with a P&L motive. An operations agent amending hundreds of trades a day is not an anomaly in that population; it is the deployment working as approved, and its baseline is set in its first month. Every individual amendment carries a plausible reason code, because clearing breaks is the agent's job and the reason codes are the agent's own output. A surveillance analyst reviewing the report sees a high-volume, fully-documented, management-approved amendment stream — which is exactly what it is. The problem is not that the activity evades the report. The problem is that the report has no way to notice that the amendments and the reconciliation certifying them share an author, because record authorship is not a field surveillance has ever needed.
Second: detective controls arrive after the property is gone. Everything the objection lists — logs, trails, amendment surveillance — is detective. It reconstructs what was done, later, if someone asks the right question of the right population. The control the lifecycle boundary implemented was preventive: the desk could not write the settlement record, full stop, and so the comparison was trustworthy at the moment it ran. That is a different grade of assurance, and post-trade evidence has to be, because it is what the firm's books rest on. A reconciliation whose integrity depends on someone later auditing the reconciler has inverted the direction the assurance was supposed to flow: the recon was the thing that audited everything else.
Third: the four-eyes gate degrades exactly the way the queue did. Yes — a well-configured OMS demands a second approval for post-execution amendments. Route the agent's amendments to a human approver and, in month one, the approver reviews them. By month four, the approver is approving four hundred individually-plausible, individually-correct corrections a day from a system whose accuracy so far is excellent, and the approval is a batch click with a coffee. This is not a hypothetical decay curve; it is the standing story of every high-volume human checkpoint, and it is why the industry moved from 'a person re-checks everything' to structural separation in the first place. A human gate in front of a machine-rate stream is a control that measures the human's stamina, not the stream's integrity.
So I accept the objection's engineering and reject its conclusion. The firm that gives its recon agent a recommendation queue instead of amend rights has made the right choice — but it has made it as a configuration preference, revocable by the next efficiency review, invisible to any examiner, and nowhere recorded as the control it actually is. The argument of this piece is that the lifecycle boundary needs to be a stated, enforced, evidenced property of how agent capability is assembled, precisely so that it stops depending on every future deployment quietly making the tasteful choice.
The week this stopped being hypothetical
None of the above would be urgent if agents near the trade lifecycle were a conference-slide concept. This week's public record says otherwise, and it needs handling with the attribution discipline it rarely gets.
On 15 August 2026, Business Insider published a per-bank ledger of AI in production across the largest US dealers and universal banks. Its Goldman Sachs entry carries the fact that matters here: the bank's disclosure that Anthropic — a frontier lab — is building agents for the firm's accounting and trade functions, alongside client onboarding. The same ledger carries JPMorgan's claim of roughly a thousand deployed use cases with a generative platform rolled out to over two hundred thousand employees, and Morgan Stanley's claim that its internal developer agent saved over two hundred and eighty thousand developer hours in the first half of the year. Every one of those figures is the institution's own account of itself, given to a journalist; none has been independently audited, and I am citing the ledger as evidence of one thing only — that agents against trade-adjacent and accounting functions at a major dealer are now a disclosed fact rather than a projection.
What the disclosure does not say is the entire subject of this piece. 'Agents for accounting and trade functions' is a phrase that spans the lifecycle boundary in nine words. It does not say whether any single agent's capability set crosses that boundary; whether the capture-side and books-side agents are the same runtime with different prompts or different principals with disjoint credentials; whether the reconciliation those functions report into can write to the records it compares. I make no claim about how Goldman or its vendor has built any of it — the build may be exemplary, and a frontier lab is likelier than most integrators to have thought about capability separation. The point is colder: the public record now establishes that the arrangement is being built, and establishes nothing about whether the boundary survived the building. For every firm that is not Goldman — the mid-sized dealer in my illustration, buying rather than commissioning — the question arrives with less engineering attached.
The instruments, read precisely
The regulatory frame for this sector is unusually concrete, and it is worth reading exactly, because it is both older and more specific than the AI-governance conversation assumes.
*FINRA has already said the obligations are technology-neutral, and has already written about agents specifically.* Regulatory Notice 24-09, of June 2024, reminded member firms that the securities rulebook applies to activity conducted with generative AI exactly as it applies to the same activity conducted without it — supervision under Rule 3110 included, which requires a supervisory system reasonably designed to achieve compliance, whatever is doing the work. In January 2026 FINRA went further than any US financial regulator had and published observational material specifically on AI agents — 'Emerging Trend in GenAI: Observations on AI Agents', with a companion note categorising agent types — describing member firms' emerging uses and the supervisory questions they raise. That is observational material rather than a rule, and I am careful to cite it as such. But its existence collapses the standard deferral argument: this sector's front-line regulator is demonstrably watching agentic deployment as agentic deployment, and its annual regulatory oversight report for 2026, published in December 2025, carries a generative-AI section saying the same thing at programme level. A firm arguing that agent controls await future rulemaking is arguing against a regulator that has already told it which existing rules apply.
*The books-and-records rules are about provenance, whether or not anyone says the word.* Exchange Act Rules 17a-3 and 17a-4 require a broker-dealer to make and preserve blotters, ledgers, memoranda of each brokerage order, and the rest of the record set, and to preserve them in a form that guards against alteration. The reason an examiner can rely on a firm's blotter is not that the blotter is a file with a retention policy; it is that the record was made in the regular course of a process whose participants could not, individually, bend it — the capture record, the confirm, the settlement record and the ledger arrive from different hands, and the rules' alteration-resistance requirements exist to keep it that way after the fact. An agent that can write both a trade record and the reconciliation certifying it has not violated 17a-3, which is precisely the problem: every required record exists, every retention clock runs, and the property that made the record set worth examining — that its parts check each other — has quietly left. The rules assume independence of production; they do not state it, because in 1939 and every year since, no single record-writer could span the lifecycle. Now one can.
*The Market Access Rule shows the sector already knows how to say what I am arguing.* Rule 15c3-5 requires a broker-dealer providing market access to maintain risk-management controls 'under the direct and exclusive control' of the broker-dealer itself — a provenance requirement about controls, written after the industry watched control of order flow drift to parties with the wrong incentives. It even permits written allocation of specific controls to another registered broker-dealer while insisting the allocation be documented and reasonable. Direct and exclusive control, written allocation, no relief from responsibility: that is the grammar the lifecycle boundary needs, already in force one layer away, applied to pre-trade risk checks. Nothing structurally new is being requested of the sector; what is being requested is the extension of a sentence it already complies with to a boundary it has not yet named.
*For bank-affiliated dealers, the April 2026 deferral changes less than it seems to.* The interagency model risk guidance of 17 April 2026 — Fed SR 26-2 and OCC Bulletin 2026-13, which supersede and rescind the prior generation of instruments, SR 11-7 among them — places generative and agentic AI outside its scope and disclaims enforceable standards, while its own footnote places the determination of appropriate controls for uncovered systems on the banking organisation's governance and preserves supervisory action for unsafe or unsound practices. I have read that document closely elsewhere and will not re-argue it here; the companion pieces to my banking pair carry the full text. What matters for this sector is the asymmetry it creates: a bank-affiliated dealer's model risk framework has formally deferred on agents, while its securities regulator has published agent-specific observational material and reminded it that supervision rules never deferred at all. The gap between those two positions is where a books-and-records examination of an agent estate will land.
*And in India, the responsibility question is already answered in the strictest available form.* SEBI's Regulation 16C, notified in February 2025, provides that a regulated entity using artificial intelligence tools — whether developed in-house or procured from a vendor — is solely responsible for the outputs those tools produce and the consequences of relying on them, including the privacy and security of investor data. Sole responsibility, regardless of procurement route, is a sharper allocation than anything the US instruments state: it forecloses, by regulation, the argument that the vendor's agent architecture is the vendor's problem. SEBI's June 2025 consultation on responsible AI in the securities markets extends the same direction of travel. An Indian broker deploying the illustration's break-resolution agent owns every amendment it writes, in terms a compliance officer can quote — which makes the question this piece raises, whose record did the agent write and against what was it checked, not a philosophical one but the literal content of the regulation's word 'consequences'.
The limits of this argument
Four limits, stated the way I would want them stated back to me.
*I cannot tell you how often the bad day occurs.* The illustration's failure requires a break where the street is wrong or the difference is real, and I have no measurement of what fraction of reconciliation breaks that is — at any firm, in any asset class. If real discrepancies are one break in fifty thousand, the expected cost of the dissolved control is small and the efficiency case wins for years before it loses once. If they are one in five hundred, the arithmetic is different. Nobody publishes this distribution and I have not measured it; the piece argues that the control's destruction is structural, and stays silent on how expensive the destruction is, because silence is the honest position.
*The illustration is constructed, and it establishes possibility rather than incidence.* I have no evidence that any firm has deployed a reconciliation agent with amend rights on trade capture, and I make no such claim. The Business Insider ledger establishes that agents are being built against trade and accounting functions at one major dealer, on that dealer's own account; it establishes nothing about their capability sets, and I have said so at each mention.
*The historical incidents are analogies, and analogies have edges.* All four post-mortem cases involved a motivated human concealing losses; the agent in my illustration conceals nothing and wants nothing — it optimises a queue metric with the capabilities it was handed. I use the history to establish what the lifecycle separation is for, not to predict fraud by software. If anything the difference sharpens the problem: the human cases were bounded by one person's stamina and fear of discovery, and the agent case is bounded by neither. But a reader who thinks the analogy proves too much is a reader I have half-persuaded, and the argument is designed to survive on the mechanism alone.
*And here is what would falsify it.* First, a production reconciliation platform that derives and enforces writer-provenance — that refuses to count a match as evidence when both sides' latest write traces to a common principal, or at minimum surfaces shared authorship as a first-class exception. If that exists in a shipping product, the control repairs itself at the point of comparison and the boundary argument loses most of its force; I searched vendor documentation for such a feature and did not find one, which is not proof of absence. Second, evidence that firms deploying break-resolution agents systematically deny them capture-side writes — a survey, an examination finding, a vendor default — which would make the dissolution a possibility nobody instantiates. Third, a demonstration that amendment-stream surveillance tuned for agent-rate activity catches absorbed discrepancies at useful latency, which would mean the detective layer holds after all and the preventive argument is a preference rather than a necessity. Any of the three would oblige me to rewrite this piece, and the third would be the most instructive to be wrong about.
What follows
The diagnosis constrains the remedy, and it constrains it differently than the payments case did. Because the destroyed property is record provenance rather than permission pairing, the fix cannot be a smarter approval matrix: it has to keep the lifecycle boundary intact inside the machinery that assembles agent capability, and it has to leave evidence that the boundary held. Concretely, that means write-capability partitioned along the lifecycle so that no agent's write set spans a stage boundary; dual control on the value-moving actions expressed as two genuinely independent judgements rather than two credentials; a delegation contract between desk-side and ops-side agents under which requests cross the boundary but authority never does; and a per-record provenance trail a books-and-records examiner can sample. The companion piece — A delegation contract across the lifecycle boundary — builds each of those and prices them honestly, including the throughput the partition gives back and the case in which the whole design is over-engineering.
Until then, there is one exercise worth doing this quarter that needs no architecture. Take every agent in the estate that touches post-trade anything, list its write capabilities — not its tools, the verbs behind them — and mark each verb with the lifecycle stage it belongs to. Any agent whose writes span two stages is the illustration, wearing your configuration. The list is an afternoon's work with the connector register open, and whichever way it comes out, the firm ends the afternoon knowing something about itself that no reconciliation report will ever show it.