Written by: Boaz Sobrado, Forbes
Compiled by: AididiaoJP, Foresight News
On May 27, 2026, Robinhood launched Agentic Trading. Users can connect external models such as Claude, ChatGPT, Cursor, Grok, and Codex to their brokerage accounts, with the agent conducting research, placing orders, and rebalancing. Funds must be transferred into a separate agent account, and the agent can only operate the funds within that account. Every executed trade triggers a notification, and users can disconnect at any time.
Forbes breaks this into two layers: first, Robinhood opens up proxy-based trading; some startups also want to go further and let AI manage funds. The latter may seem like a natural extension, but legal requirements and minimum capital stand in the way. To understand this gap, you need to start with the division of interfaces, permissions, and responsibilities.
Not a robo-adviser, but a trading rail with a model built in
Agentic Trading isn’t a proprietary trading tool built by Robinhood, nor is it the assistant Cortex within the platform. Cortex mainly handles reading research reports and providing recommendations; the final trades still require user confirmation. The mode of Agentic Trading is “the model comes from the user; the platform provides the trading rails.” The connection is done through MCP: Robinhood provides the trading server address, the user completes OAuth authorization on the desktop client, and the system then guides the opening of a separate account named Agentic. Official demos show it takes about half a minute from connection to authorization.
This division of labor determines where risk is assigned. Brokers handle order routing, clearing, account isolation, and notifications; risks such as strategic misjudgments and misreading instructions are borne by the external model and the people who write the prompts. Robinhood has clearly stated that it does not control, supervise, or audit these agents. Once data leaves the brokerage environment, it enters the systems of Anthropic, OpenAI, or other model vendors. What the platform sells is a channel, not investment-advisory service.
How accounts are opened, and how wide the permissions actually are
Users must first have a Robinhood personal account in good standing. The agent account is an independent, self-directed brokerage account; it is neither an IRA nor a sub-account of the main account. How much funding the user deposits—at least in theory—is the maximum amount they can lose. The agent can’t operate the main account, bank account, or retirement account. The feature doesn’t charge extra; stocks and ETFs execute under the platform’s existing no-commission rules.
But trading permissions and data permissions aren’t separated by the same wall. Public documentation shows that even after connecting an agent, it may still be able to view account numbers, positions, balances, and history across accounts to assess concentration. In other words, the sandbox constrains trading permissions, but it doesn’t necessarily constrain what data is visible. Exposing a full asset position structure to a third-party model—versus “the agent can only lose the $1,000 deposited at most”—are two different kinds of risk.
Instructions are delivered in natural language. For example, an agent may be asked to check whether markets are open each day; when drawdown on a single stock exceeds 10%, it halves the position; and it may move cash into targets that outperform the portfolio’s mean. It can also, based on venture financing, M&A, and valuations of unlisted companies, look for directions that have not yet been priced by public markets, and test a single trade with $100. The agent can view buying power, assess sector exposure, read analyst materials, and then choose to preview or place orders, or cancel. Users can set per-trade confirmations, or have trades execute automatically within the limits. The app provides real-time updates and profit/loss information.
In the initial launch phase, the feature supports only U.S. stocks. Options, crypto assets, event contracts, futures, and prediction markets are listed as follow-on plans, with some functions gradually opening after summer. As each capability layer expands, turnover, leverage, and the risk of mistaken operations also rise. The Gold Card additionally provides a virtual card for agents to use; the limits can be customized, and you can also require per-trade confirmation, but you can’t operate the actual card number.
Robinhood’s risk warning is very explicit: you may lose all the principal in that account. This isn’t wordplay. The model may interpret “appropriately diversified” as high-frequency rotation of holdings; it may turn limit orders into market orders on earnings-night; and it may repeatedly place orders when a data source is temporarily abnormal. Notifications let users see the problem, but seeing it doesn’t mean you’ll have time to withdraw the order.
The retail side is already similar to a mini fund, but legally it’s still proprietary trading
After accounts are opened, some users name the agents and assign roles: one screens targets, one does end-of-day review, and one generates weekly reports—an outline similar to a small hedge fund. Others only invest $1,000 to test mechanical rotation: trades can run successfully, but profits are limited and the allocation process is fragile. Even on GitHub, there are experiments like “single agent, real gold—starting from $100.”
Similar isn’t the same. The money is your own, the strategy is written by you, and losses are yours to bear; there’s no public fundraising and no fiduciary duty owed to strangers. U.S. rules for investment advisers focus on three points: whether you provide recommendations regarding securities, whether you do so as a business, and whether those recommendations are tailored to a specific person’s circumstances. Giving instructions to your own sandbox still counts as proprietary trading. Once an agent continuously rebalances according to other people’s risk preferences and charges for it or raises funds for it, its appearance starts to resemble an investment adviser and fund operations.
Regulators don’t treat this as a toy. Organizations such as the SEC and FINRA have issued joint alerts about AI and investment fraud. The risk isn’t only that the model miscalculates; it also includes impersonating an investment adviser and inducing investors to hand money to an “fully automated high-yield agent.” Isolated accounts can limit the maximum loss per account, but they can’t prevent someone from packaging the sandbox as a wealth-management product for sale to others.
What startups want to buy isn’t prompt text, but three pieces of paper
The first picture is the boundary of capability. The stock sandbox and the simultaneous trading of options, crypto assets, perpetual contracts, and prediction markets are not the same risk tier. Robinhood is writing expansion into its roadmap because users want to operate all asset types from a single entry point. For client-served products, the broader the entry, the more you need suitability testing that matches the risk level—you can’t rely only on “it can be turned off.”
The second picture is responsibility attribution. The platform says the external agents aren’t managed by it; users say they only wrote a single line of natural language; and the model vendor says it only provides general tools. When all three can shift responsibility, a key signature is missing from the documents: who is responsible for net asset value, who puts customers first in conflicts of interest, and who gets compensated first after a wipeout.
The third picture is scale and custody. Personal trial funds can be routed through customer agreements; if you raise funds from the public and manage them continuously, you must follow fund or investment-adviser rules: where the money is held, how net value is calculated, how long the redemption cycle is, how fees are collected, and how related-party transactions are disclosed. MCP can reuse the rails Robinhood has already built, but the license, custody, and capital base can’t be replicated.
There’s another parallel thread. On-chain, there are already agents with wallets that can be paid for by oneself, and people are discussing turning these agents into entities that can be paused, migrated, or even tokenized. This involves another set of identity and settlement issues. (Forbes) This article’s focus is narrower: whether—within traditional brokerage workflows—agents can grow from retail plug-ins into an asset-management business.
Conclusion
What can be confirmed for now is this: placing orders can already be automated; isolated accounts can cap the maximum loss for a single trial; and notification plus disconnect mechanisms reduce the probability of “being completely invisible.” What still can’t be written on the product page is: external models can consistently beat passive portfolios, the platform will place erroneous orders for the agent, and this setup is essentially equivalent to a licensed fund.
Robinhood chooses to keep the risk perimeter within a sandbox and to push responsibility back into the account-opening agreement. If a startup moves the sandbox away or places someone else’s funds into it, then the only things left that can contain risk are the license, custody, and capital base. Without any one of those, Agentic Trading remains merely a trading tool, and “managing funds” still stays only in the headline.
