If ChatGPT can buy stocks for you
—After Scalable Capital opened its securities account interface, how should the responsibilities of AI, securities firms, and investors be redefined?
(Image caption) The founding team of Scalable Capital poses for a photo at their Munich office. This digital brokerage, which has obtained a banking license from the European Central Bank, recently opened its securities account interface to ChatGPT, Claude, and Grok.
A new entry point for securities accounts
German digital bank Scalable Capital recently announced that customers can now connect their investment accounts to AI assistants such as ChatGPT, Claude, and Grok that support the Model Context Protocol (MCP). According to Scalable's public information, after authorization, the AI can read investment portfolios, analyze holdings, query market data, generate price alerts, prepare savings plans, and assist in creating or adjusting securities orders.
This service is called Agentic Investing by Scalable. It still retains a very important point of human control: each securities transaction requires the client's confirmation before it can be executed; deposits and withdrawals can only be completed through Scalable's own app or website.
What I care about more is this boundary.
Scalable hasn't completely handed over securities accounts to AI, but it has allowed third-party AI assistants to access account interfaces that were previously exclusive to banks and brokerages. From this moment on, the question financial institutions need to answer is no longer just whether AI can analyze stocks, but how the chain of responsibility for financial services should be redefined as AI gradually gets involved in data reading, investment judgment, and trade preparation.
For the past decade or so, competition in fintech has primarily taken place on mobile apps. Robinhood, Revolut, Scalable, and a host of digital brokerages brought bank counters and trading terminals to mobile phones, lowering the barriers to account opening and trading. Now, this entry point is beginning to change: users may not necessarily open a brokerage app first; they might open an AI assistant first, which then uses the AI to access services provided by the bank or brokerage.
This change may seem like just a step in the interface, but it actually touches on one of the most core assets of the financial industry: the customer entry point.
What exactly does Scalable offer?
To determine the institutional weight of this matter, the product itself must first be clearly explained.
According to publicly available information, Scalable was founded in 2014 and currently serves over one million clients. Its platform boasts one of the largest asset sizes among European digital brokerages and has obtained a banking license from the European Central Bank, subject to regulation by BaFin and the German central bank. Its business encompasses financial services including stocks, ETFs, derivatives, digital assets, asset management, savings, and credit.
The core of this open platform is a set of MCP and CLI interfaces. MCP was originally proposed by Anthropic and can be understood as a standardized protocol that allows AI models to establish connections with external software and data sources after obtaining user authorization.
Traditionally, when an investor asks ChatGPT, "Is my portfolio too risky?", the model doesn't know what assets the user actually holds. With a Scalable account, the AI can access relevant holdings data within authorized limits, analyze industry and regional concentration, summarize portfolio-related news, organize trading history, and even help users prepare new orders using natural language.
Scalable offers quite specific use cases. Users can ask the AI to generate a news summary based on their holdings every morning, compare their own portfolio with a model portfolio, or calculate how much money should be invested each month to reach a certain asset goal after several years. When it comes to actual transactions, the system will still return order information and legal documents to the user for confirmation.
This design means that Scalable currently offers analytical and transaction preparation capabilities, rather than fully autonomous asset management privileges.
(Image caption) Scalable Capital's Agentic Investing interface shows that users can use natural language to request the generation of a portfolio tree diagram, and a third-party AI assistant has been added to the account view that was originally exclusive to brokerage firms.
Transaction confirmation is becoming the boundary of responsibility.
In its public statement, Scalable emphasizes that its external AI applications are operated independently by third parties, and the outputs, suggestions, and trading instructions generated by the AI do not represent investment advice provided by Scalable itself. The core of this arrangement is to separate the bank's own financial service responsibilities from the outputs of the third-party model.
This distinction is very important under the current European regulatory system.
MiFID II has specific requirements for personalized investment advice. When financial institutions provide personal recommendations, they typically need to understand the client's investment experience, financial situation, loss tolerance, investment goals, and risk appetite before determining whether a particular product is suitable for that client.
If a client makes their own decisions and then requests a brokerage firm to execute the trade, regulatory obligations fall under a different framework. Certain products and services may involve appropriateness assessments, while some execution-only transactions are subject to different requirements.
The real complexity arose after third-party AI was involved.
Suppose a client requests Claude to analyze their retirement account. After reviewing the holdings, Claude recommends reducing holdings in technology ETFs and prepares two orders: one for selling and one for buying. The client then clicks to confirm.
In this process, investment decisions are generated by the model, but the trades are completed within a regulated brokerage system. Scalable may claim that it only provides accounts and trade execution, while the model company may claim that it provides general-purpose AI tools, and the user is the party who actively authorizes and personally confirms the transaction.
Under the existing rules, these roles cannot be simply categorized into a single class.
I believe this is one of the most noteworthy institutional issues for Agentic Finance to observe in the future: how will regulatory classifications apply when the previously relatively clear boundaries between investment advice, execution-only, appropriateness, and discretionary portfolio management are crossed by an AI assistant that can read data, generate suggestions, and prepare orders?
Natural language introduces new transaction risks.
Traditional brokerage interfaces require investors to operate according to the format of the financial market.
Users need to select assets, the direction of the transaction, the quantity, the order type, and then confirm the price and fees. While this process isn't very intuitive, it has one advantage: many key decisions need to be explicitly input.
The AI Agent translates these operations back into human natural language.
"Help me make the combination a bit more conservative."
For an average person, this statement is easy to understand. However, for a system that needs to generate actual trading plans, it involves a large number of judgments that are not yet clearly defined: whether the risk refers to volatility, maximum drawdown, industry concentration, or single stock exposure; how much should be reduced; which assets to sell; what alternatives to buy; and how to handle the adjusted tax consequences.
If the model interprets a vague instruction too aggressively, the risk may no longer be just pressing the wrong transaction button, but may lie at the semantic level.
This is especially important in AI finance.
Financial markets are inherently rife with vague goals. Some want to "play it safe," others want to "not miss out on tech stocks," and still others hope to "retire in five years." These are not simple machine instructions, but investment objectives that require consideration of risk tolerance, time horizon, and family financial situation.
Scalable currently requires clients to provide final confirmation for each transaction, effectively retaining a crucial point of accountability. As long as this confirmation remains in place, users still have the opportunity to re-examine the AI's understanding of their intent before the transaction is actually executed.
The situation will be different if agents gain greater autonomy in the future.
(Image caption) Investors use ChatGPT on a laptop. The article points out that in the future, customers may not necessarily open a brokerage app first, but may instead access bank and brokerage services through a general AI assistant.
Investment data began leaking from brokerage firms' offices.
Beyond transaction liability, data is another institutional issue that emerged earlier.
Investment accounts can reveal an individual's earning capacity, wealth size, risk appetite, retirement plans, company holdings, and family financial situation. This information was previously primarily stored within the systems of banks and brokerage firms.
When users actively authorize third-party AI to access their accounts, the flow of data begins to become more complex.
Scalable controls the securities account and trading system, the model company controls the AI service, and the user controls whether to grant authorization. As for who is the data controller and who is the processor in each specific data processing stage, or whether there is a joint controller relationship, it depends on the purpose of data processing, contractual arrangements, and actual technical processes, and cannot be generalized.
The GDPR provides an existing institutional framework.
It requires companies to explain how personal data is processed, for what purpose, and for how long it is retained, and also sets additional requirements for profiling and certain automated decision-making scenarios. When an AI assistant simultaneously possesses chat logs, lifestyle information, and investment account data, financial information can be incorporated into a far more complete personal profile than that of a traditional brokerage firm.
This capability is both valuable and raises the bar for governance.
An investor might want AI to know their age, income, retirement date, and family burdens, as this would allow the model to provide more useful analysis. However, the more complete the data, the clearer the responsibilities regarding authorization, storage, deletion, and reuse need to be.
For financial services, trust is never just about whether the money has been stolen, but also about who sees the most private financial information and what it is ultimately used for.
The AI Act is merely an overlay of regulations.
The EU AI Act adds a new legal framework for AI governance, but it does not redefine all financial services responsibilities.
The AI Act classifies certain financial uses as high-risk, such as certain credit scores and specific risk assessments in health and life insurance. Securities investment advice is not simply categorized as a whole.
Therefore, Agentic Investing is currently still primarily governed by existing financial laws.
MiFID II addresses investment advice, trade execution, and suitability issues; GDPR addresses personal data; and existing requirements for cybersecurity, business continuity, third-party risk management, and consumer protection for financial institutions remain in place. The AI Act further adds model governance, transparency, and other obligations on top of these frameworks.
This layered regulation will bring new compliance costs.
A seemingly simple AI-assisted transaction may simultaneously involve model output, securities service classification, customer information, transaction records, external technology providers, and user authorization. Regulation hasn't disappeared; it simply needs to navigate more technological and legal interfaces.
For large banks, this is why opening up an agent interface can be much more difficult than launching an internal AI chatbot.
Banks can keep their self-developed AI tools entirely within their own governance framework. Once a third-party agent is integrated, responsibility needs to be distributed across companies.
(Image caption) Frankfurt Stock Exchange trading floor. Even if orders are prepared by AI, securities transactions must still be completed within a regulated market and brokerage execution system, and confirmed by the client.
The issues in the US tend to lean more towards brokerage firm responsibility.
Scalable's case occurred in Germany, but the United States is likely to face the same type of problem.
A significant amount of personal wealth in the United States already resides in digital brokerage accounts, including 401(k), IRA, regular brokerage accounts, and various retirement assets. Schwab, Fidelity, Robinhood, Interactive Brokers, and major banks are all using different forms of AI tools, albeit with varying degrees of openness.
If these institutions allow third-party AI to directly read portfolios and prepare trades in the future, the starting point for US regulatory analysis will likely remain existing securities rules, rather than creating a completely separate AI system.
In 2024, FINRA reminded its member institutions regarding the use of generative AI that existing oversight, record-keeping, communication, accuracy, and compliance obligations remain in effect. This is a general regulatory principle, not a specific rule for Scalable or Agentic Investing, but it provides a fairly clear direction: financial institutions cannot simply delegate their existing responsibilities to models simply because they are using AI.
US securities regulation has long adopted a technology-neutral approach.
If the AI is deployed by the securities firm itself, the responsibility is relatively easy to trace.
The issue becomes more complex if the model is a third-party service chosen by the client. The brokerage firm might only be responsible for data access and trade execution, while the AI company provides the model, and the client actively authorizes it. Determining who is responsible for which part of the process, and when, will likely depend on specific facts and contractual arrangements.
This is also where the Scalable case is of reference value to the US market.
Customer access rights are beginning to change
The competition in fintech over the past decade has superficially focused on commissions, product variety, and app experience, but at a deeper level, it has always revolved around the customer entry point.
Whoever controls the interface that users open every day has the opportunity to offer them more financial products.
Scalable's decision to open its Agent interface represents an acceptance of a new possibility: the first layer of interaction between customers and financial institutions may not necessarily occur within the bank's own app.
This kind of shift in entry points has occurred in other industries before.
Many hotels still have rooms and service capabilities, but a significant portion of customer relationships are controlled by Booking and Expedia; news organizations still produce content, but search and social platforms have long controlled traffic entry points.
The underlying service providers haven't disappeared, but who controls the entry point will affect customer relationships, distribution rights, and pricing power.
Whether the financial industry will end up in the same situation is not yet possible, as there is insufficient evidence to draw a conclusion.
But Scalable's actions at least indicate that some financial institutions are willing to accept third-party AI standing between themselves and their customers.
This is a strategic choice with long-term significance.
MCP transforms banks into callable services.
Instead of developing dedicated connections for a single AI model, Scalable uses standardized interfaces like MCP.
This may be more important than a single product feature.
If financial institutions provide capabilities such as account inquiries, portfolio analysis, and order preparation through standard interfaces, AI assistants can call these functions within the authorized scope, without each financial institution needing to redevelop and fully integrate them for each model company.
It is too early to say whether MCP will eventually become the mainstream standard in the financial industry.
However, standardized interfaces themselves will bring about a new kind of competition.
In the future, financial institutions may not only need to improve their own apps, but also need to ensure that their products and services can be correctly understood and used by AI assistants.
This will redefine some of the capabilities of banks and brokerages as infrastructure.
Users submit their needs, AI is responsible for combining and understanding them, and financial institutions are responsible for providing regulated accounts, products, and trading capabilities.
For GFM's Web4 and RWA research, this is also a direction worth tracking in the long term: the competition in digital financial infrastructure is extending from whether assets are on-chain to whether agents can securely access assets and accounts.
(Image caption) European Central Bank headquarters in Frankfurt. Scalable's agentic investing has not escaped existing financial regulations; MiFID II, GDPR, and banking licensing obligations still form the underlying institutional framework for the division of responsibilities.
The next step is authorization, not just transactions.
Scalable still requires investors to confirm each transaction.
This arrangement allows many responsibilities to remain within the traditional financial framework.
If agent technology continues to develop, the real challenge in the future will lie in the issue of continuous licensing.
For example, a user might request the AI to automatically adjust the tech stock allocation back to 35% within the next six months, provided that the tech stock allocation exceeds 40%; or authorize the AI to manage the account according to a retirement plan, without requiring further confirmation as long as each transaction does not exceed a certain amount.
This arrangement is not entirely unfamiliar in traditional finance.
Portfolio managers, discretionary accounts, and algorithmic trading already involve ongoing licensing. The difference lies in the fact that general-purpose AI agents may bring capabilities originally offered primarily to professional investment management clients to the larger market of ordinary investors.
At this stage, the core issue the financial system needs to address is permission architecture.
To what extent should authorization be specified? Which assets can be traded? What are the single transaction and daily limits? Under what circumstances is reconfirmation required? Does the original authorization remain valid after a model change? How is agent privileges immediately terminated if the account holder dies, becomes incapacitated, or the account is stolen?
These questions are closer to financial infrastructure than "Can AI pick stocks?"
I believe that this layer is likely the key factor that will determine whether Agentic Finance can enter the realm of large-scale personal wealth management.
AI lowers the barrier to entry, but also amplifies misjudgments.
AI entering investment accounts has real value for ordinary families.
Someone who previously couldn't understand fund fees, duration, or asset allocation can now ask questions directly in natural language; an American investor can ask if their 401(k) is overly concentrated in tech stocks, or let AI organize the asset allocation in their IRA, or analyze which stocks might be suitable for tax-loss harvesting.
This ability could potentially lower the barrier to financial literacy.
At the same time, it also brings new risks.
A young investor seeing AI write "moderate risk" may not know what assumptions the model used; a retiree seeing a well-written asset allocation plan may also interpret it as professionally responsible investment advice.
Language models are very good at explaining complex things clearly, but many questions in financial markets do not have definite answers.
Models can analyze historical data, calculate volatility, and compile company financial statements, but they cannot guarantee future market outcomes.
Therefore, even after AI lowers the operational threshold, financial literacy will not become unimportant.
Instead, investors need to understand the limitations of the model's capabilities.
Scalable chose to keep AI outside the walls.
Scalable had already incorporated AI features into its platform. By opening up the MCP interface, the company has chosen to allow external AI assistants to directly access financial services within authorized limits, rather than confining all AI capabilities to its own app.
This is a representative strategic choice.
Large financial institutions may not adopt the same approach in the future. Some banks may open up more interfaces, while others may only allow their own AI systems to handle high-risk financial operations.
Reality is more likely a hybrid model.
Low-risk queries, analysis, and data processing can be made available to external agents; transactions, withdrawals, credit, and other high-risk activities should be subject to more internal controls.
The extent to which different financial institutions open up may become a key competitive differentiator in the coming years.
The value of Scalable lies in the fact that it brought this problem to the forefront of the market ahead of time.
A slight shift in financial access
Online trading moved the securities market to computers, and smartphones put brokerages in people's pockets. Agentic investing brings even more subtle changes, allowing the financial system to begin accepting natural language as a new operational interface.
Scalable currently retains control over accounts, custody, trade execution, and oversight, and users must verify every transaction. Third-party AIs only receive a limited set of permissions.
However, once the entry point is opened, the roles of financial institutions and AI platforms will gradually need to be redefined.
For banks and securities firms, one of the most important issues in the future may no longer be how to make their apps better, but rather which financial capabilities can be opened up to agents, which must remain in a controlled environment, and how to maintain clarity in customer relationships and legal responsibilities after opening them up.
For investors, the issue is more straightforward.
When an AI can read your retirement account, analyze your investment portfolio, and prepare your next order, the convenience is easy to understand.
The real questions that the system needs to answer next are authority, responsibility, data, and trust.
If one day that "confirmation" no longer requires a human click, the financial market will need to know in advance where the responsibility lies.
Disclaimer
This article is based on publicly available information for financial and institutional research and is for informational purposes only. It does not constitute any investment, legal, or trading advice. The relevant functions, regulatory responsibilities, and risk boundaries shall be subject to the official rules and terms of service.