CapitalRegistry

Writing

Who Stands Behind the Agent

When the other side of a transaction is a piece of software acting for someone, the oldest question in the market does not go away. It acquires another layer, and the answer has to be kept where machines can read it.

August 28, 2026

The question before the agent

For as long as institutional markets have existed, the hardest fact to establish about a transaction has been the identity of the other side. Not the name on the confirmation, which is a label, but the entity that bears the obligation, the capital that stands behind it, and the people whose judgment moves it. That question was difficult when every participant was a human being working for a regulated firm. Ownership trees obscured it. Booking vehicles and affiliates multiplied the names that pointed at a smaller number of true actors. People changed firms and carried relationships with them. The market answered the question imperfectly and continuously, because the structures never stopped moving.

It is worth stating how much rested on the assumption that the counterparty was a person acting for an institution. A trader had a desk, a firm, a supervisor, a licence, and a name that could be looked up. The institution had a balance sheet, a regulator, and a register entry. When something went wrong, the chain from the action to the accountable party was short and legible: a person, employed by an entity, capitalized by a parent. Every control in the market, from onboarding to margin to dispute, was built along that chain.

The chain is now acquiring a link that is neither a person nor an institution.

The agent arrives

An agent, in the sense that now matters, is software that perceives a situation, reasons about it, and takes an action in the world without a human composing each step. In markets the action might be a quote, an order, a payment instruction, a request for a price, a decision to lend or to borrow a security against collateral, or the negotiation of terms with another agent that is doing the same on behalf of someone else. The near-term shape of this, according to the more careful academic work on the subject, is bounded autonomy: agents operating as supervised co-pilots and constrained execution modules within human-led processes, with human approval reserved for decisions of high materiality, low reversibility, or serious legal consequence. That is a sober forecast and it is probably correct. It is also a forecast about the inside of the firm. From the outside, from the vantage point of the counterparty, the distinction is far less visible. A request for a price arrives. An order is placed. A payment settles. Whether a person or a process originated the instruction is not printed on it.

The change is already observable at the retail edge, where a large brokerage this spring permitted third-party agents to place trades on customer accounts through an open integration standard. The supervisory questions that followed were immediate and remain unresolved: who is the supervised person when the agent is not a registered representative, how best execution is judged when the decision logic is opaque, and to which of several parties liability attaches when an outcome is disputed. Institutional markets will meet the same questions at larger scale and with more at stake, because the institutional counterparty was never a single account but a structure, and the agent will act somewhere inside that structure.

There is a second observation that matters more for the long run. When agents transact with agents, transactions multiply. A function that once required a phone call and a relationship can be performed many times an hour between systems that have never met. The boundaries across which work passes grow more numerous, and every boundary raises the prior question before price or settlement can be considered. The counterparty problem does not shrink in an agentic market. It compounds.

Does an agent have an identity?

The plain legal answer is no, and it is worth being precise about why, because the precision is where the practical consequences live.

An agent has no legal personality. It cannot own property, hold capital, be sued, or be licensed. Law reached this position long before the current generation of software. The American statute that gave electronic signatures their force at the turn of the century already contemplated “electronic agents” and provided that a contract may not be denied effect solely because its formation involved one, so long as the agent’s action is legally attributable to the person to be bound. The operative word is attributable. The agent is not a party. It is a channel through which a party acts, and the doctrine that governs it is the ordinary law of agency: actual authority, express or implied, granted by a principal; apparent authority, where a counterparty reasonably believes the agent is authorized; and vicarious responsibility that runs to the principal for acts within the scope of what was granted. Recent legislation has closed the obvious escape, with at least one American state now providing that a defendant may not assert as a defence that the AI autonomously caused the harm. Regulators of the securities industry have said the same thing in their own register: outputs that influence advice or decisions must be reviewed, explainable, challengeable, and traceable to a responsible person.

So the agent’s identity is not a property of the agent. It is a chain. The agent acts for a deployer, the deployer is a legal entity, the entity sits in an ownership tree, the tree is capitalized somewhere, and somewhere in the structure there is a person who granted the authority and a person who will answer for it. The question “who is this agent” resolves, in every case that matters, into the question the market has always asked: who stands behind it, and how far does their authority reach.

That is the same question. It is not the same difficulty. The four forces that obscured identity before, ownership, vehicles, affiliates, and people, now operate on a fifth: delegation. An institution that presented many faces through its affiliates can present many more through its agents, each one acting under a scope of authority that is not printed on the instruction it sends. A counterparty who could once assume that a message from a desk carried the desk’s authority can no longer assume that a message from a process carries any particular authority at all. Whether the agent was permitted to do what it did becomes a fact about the agent’s principal, and it becomes a fact that the counterparty needs before the transaction, not after it.

Recourse, leverage, and the borrowing agent

Can an agent borrow a security? It can send the instruction. It cannot bear the obligation. The obligation lands on a legal entity, and which entity it lands on is the whole question. The agent that negotiated the loan may have been deployed by a manager on behalf of a fund, booked through an affiliate, under a delegation that permitted some transactions and not others. If the collateral is called and the position is contested, the recourse runs along the chain of attribution, and every ambiguity in that chain becomes a dispute about identity. Did the agent act within its authority? Whose authority? Which entity’s capital secures the obligation, and what stands behind that entity if it cannot perform?

Leverage makes the problem sharper because leverage is a claim on capital, and an agent has none. A position opened by an agent is recourse against whoever authorized it, to the extent they authorized it, and against nothing if they did not. The counterparty that extends credit to an agent is extending credit to a principal it must be able to name. In the old market, the name was resolved at onboarding and then assumed to hold. In an agentic market, the same institution may field a population of agents whose scopes differ, change, and are revoked, and the fact that an instruction came from one of them tells the counterparty little about which delegation is in force. Onboarding a firm no longer settles who, within the firm, is speaking.

There is a further layer that the academic literature has identified and that practitioners have been slower to notice. Many agents share the same underlying models, the same data feeds, the same vendors. A paper published this spring on agent architectures in financial markets argues that systemic implications depend less on the intelligence of any one model than on how agent architectures are distributed, coupled, and governed, and warns that if a large number of agents depend on similar components, failures in those components may propagate across the system. Correlated agents produce correlated actions, and correlated actions produce herding, liquidity withdrawal, and amplified volatility. The counterparty that faces an agent is therefore exposed not only to the principal behind it but to the infrastructure beneath it. What model is on the other side, and how many other agents in the market share it, becomes a counterparty fact in its own right. The market has never had to resolve identity at that layer before.

What the regulator is asking for

Europe’s approach to this arrived first and is instructive because of what it is not. The European Union’s Artificial Intelligence Act is a product-safety regime. It is not a privacy regime, and firms that prepare for it as though it were the data-protection law of the previous decade are preparing for the wrong thing. The distinction that lawyers advising the sector keep returning to is the one between a provider, which places an AI system on the market, and a deployer, which uses one under its own authority. Most financial institutions are deployers. The two roles carry different obligations, and knowing which side of the line an institution sits on for each system it runs determines its entire approach. The transparency obligations for both roles have applied since August of this year, with a short grace period to December for systems already in service, and the heavier obligations on high-risk systems follow in the years after. The sector’s own supervisors are converging on the same demand in their own vocabulary: an inventory of what is running, a documented scope for what it may do, controls around the third parties on which it depends, and a human accountable for the result.

Read together, these regimes are asking for something the market will recognize. They are asking for a register. Not of firms this time, but of systems: which agent exists, who deployed it, in what role, under what scope, and which named person answers for it. Every obligation in the Act and in the supervisory toolkits resolves to a record of that shape, kept current and available to the parties who rely on it. The regulator has, in effect, discovered the counterparty problem from the inside of the firm and prescribed the institutional form that markets have always used to solve it.

The identifier reaches for the agent

The organizations that maintain the market’s identifiers have seen the same thing and begun to move. The body that governs the Legal Entity Identifier now states plainly that when an agent commits an organization to an obligation, the interaction appears ordinary from the outside while the accountability behind it remains unclear, and that adoption at scale will be hard for enterprises and regulators to support without a way to establish which organization deployed the agent, who authorized it, and whether its actions fell within the authority granted. Its answer is to extend the verifiable form of the identifier so that a counterparty can computationally confirm the identity, authority, and role of a person or a system acting on behalf of a legal entity. A prototype demonstrated at the end of last year let a customer on a call verify, in real time, that the agent speaking was in fact deployed by the firm it claimed to represent.

This is the right shape of tool and it deserves to succeed. It is also, once again, the coordinate rather than the map. A credential that binds an agent to a legal entity fixes one point precisely: this agent, this entity, this role. It does not tell the counterparty where that entity sits in its tree, which parent capitalizes it, which affiliates and vehicles it operates through, whether the entity itself has been acquired or renamed since the credential was cut, or which people direct it now. The identifier resolves the leaf. The market needs the tree, and it needs the tree kept true while everything in it moves.

The scale of the problem has also changed. Affiliates and vehicles multiplied names in the tens or hundreds per institution, over years. Agents are created in an afternoon, scoped by configuration, and retired without ceremony. An identity layer that resolves agents to entities will face a population that turns over faster than any population the market has had to record, on top of an entity population that was already decaying faster than most records could heal. Maintenance, always the register’s central discipline, becomes the whole of the difficulty.

The register in an agentic market

The conclusion is not that the counterparty question dissolves. It is that the question survives every change in who is asking it, and that the change now under way makes the answer both more necessary and more consumed.

More necessary, because delegation adds a layer of indirection to every transaction and multiplies the number of transactions. Each agent on the other side of a trade is a pointer into a structure, and the structure is the thing that bears the risk. A market in which participants cannot resolve the pointer is a market that has lost track of its own exposures, which is the condition a previous crisis revealed and the reason the identifier system exists at all. The agent does not change that lesson. It repeats it at higher frequency.

More consumed, because the parties reading the record will increasingly be machines. An agent that is about to face another agent needs to resolve its counterparty before it acts, not after, and it needs to do so at the speed at which it acts. It cannot call a relationship manager. It cannot wait for onboarding. It needs a common record it can query, that answers who is behind this agent, in what capacity, within what authority, backed by what capital, and that answers the same way to every party who asks. A record of that kind is not a private map assembled inside each firm, because every private map would differ and every difference would be a dispute. It is the market’s oldest institution in its newest form: a canonical register, kept by a steward no participant controls, resolving the name to the entity, the entity to the structure, the structure to the people, and now the agent to all of them.

None of this is a new argument. It is the argument this series has made from its first essay, encountering a new reason to be true. The name on the contract was never the identity. The agent behind the instruction is not the identity either. Both are labels pointing into a structure that has to be resolved, and the resolution has to be maintained, and the maintained resolution has to be available to strangers, human or otherwise, who need to transact at a distance. Capital Registry holds that seat. It is kept from New York, patiently and early in its life by design, because the record a market navigates by is earned slowly and kept only by being true, and because the market that is coming will read it more often than any market before it.

Return to the register