In January 2025, the SEC fined Two Sigma $90 million. The charge wasn’t about a “bad trade.” It was about failure to supervise under the Investment Advisers Act of 1940.
A senior researcher made unauthorized changes to 14 trading models. It took the firm two years to notice. By then, clients had lost $165 million. In September 2025, the DOJ criminally charged that researcher with wire fraud and securities fraud. He faces 20 years.
The lesson is brutal: Returning the money didn’t stop the enforcement. The SEC’s position is that if you cannot prove deterministic supervision of your models, you are liable.
Today, every fund is moving to LLM-based trading. They are using Claude or GPT-4 to reason, but they are leaving a massive gap between that reasoning and the actual execution. I call this the Supervision Gap.
The New (Unsupervised) Workflow
The old way of staring at Bloomberg terminals is dead. The new flow looks like this:
Human chats with LLM → LLM reasons → LLM calls MCP tool → API executes
The research side is solved. AI can summarize a 200-page SEC filing in seconds. But the execution side is terrifying. LLMs are probabilistic. They don’t follow fixed rules; they reason. And when they reason, they hallucinate.
I’ve seen this: An LLM is told to buy $1,000 of ETH. It tries to place a market order without a limit price. On a volatile pair, that’s a suicide mission. The AI thinks it’s fine. The API accepts it. The firm loses.
The Regulatory Reality: SEC 2026 Priorities
This isn’t theoretical. The SEC’s 2026 Examination Priorities make it clear: AI oversight is now embedded in every examination category. Examiners aren’t asking if you use AI; they are asking for evidence of governed data access and execution.
FINRA’s 2026 report specifically flags “autonomous AI agents” as a novel risk category requiring “auditability controls and scope limitations.”
If your “supervision” is just a PDF policy on a shelf, you have already failed.
The Rules Two Sigma Broke (And Their EU Equivalents)
1. Investment Advisers Act §206(2) — Fiduciary Duty / Anti-Fraud
What the SEC charged: Two Sigma breached their fiduciary duty by failing to reasonably address known vulnerabilities in their investment models. The unauthorized changes caused client harm.
EU Equivalent: EU AI Act Article 14 — Human Oversight of High-Risk AI Systems. Requires that high-risk AI can be effectively overseen by humans, with the ability to override or interrupt outputs.
How Agent Provost closes it: The deterministic circuit breaker enforces hard risk limits. Even if a model is tampered with, no trade executes outside approved parameters. The human-in-the-loop model ensures a human authorizes every execution.
2. Investment Advisers Act Rule 206(4)-7 — Written Compliance Policies
What the SEC charged: Two Sigma failed to enforce their own written policies. They had a formal model approval process (PAM), but vulnerabilities in the parameter database allowed a researcher to bypass it for two years.
EU Equivalent: EU AI Act Article 17 — Quality Management System. Requires deployers to establish and document a quality management system including risk management, data governance, and technical documentation throughout the AI lifecycle.
How Agent Provost closes it: rules.json IS the written compliance policy — encoded as executable code. It is enforced deterministically by the LuaJIT engine. No human can “forget” to enforce it. No one can “look the other way.” The rules execute on every single request.
3. Investment Advisers Act §203(e)(6) — Supervisory Failures
What the SEC charged: Two Sigma failed to supervise their personnel. Unauthorized changes to 14 live-trading models went undetected for nearly two years. Employees only noticed when they saw “higher-than-expected correlations” between models.
EU Equivalent: MiFID II RTS 6 — Algorithmic Trading Record-Keeping. Requires firms to maintain records of algo decisions for 5 years, submit strategy descriptions to competent authorities, and demonstrate that compliance staff can technically review algo processes.
How Agent Provost closes it: Every blocked trade generates a PROVOST_INTERVENTION log with provost_user (who), provost_machine (what system), provost_request_id (correlation ID), and the exact request_body JSON. The pattern of one user’s models violating risk parameters would have been visible in days — not two years.
4. SEC Rule 204-2 — Books and Records Retention
What the SEC charged: Two Sigma could not produce complete, tamper-proof records of what their models were doing during the period of unauthorized changes.
EU Equivalent: EU AI Act Article 12 — Logging Requirements. Requires automatic logging of events relevant to identifying risks and ensuring traceability throughout the AI system’s lifecycle. Logs must be kept for the appropriate duration based on the system’s purpose.
How Agent Provost closes it: Fluent Bit captures every request and response body as structured JSON and streams it to S3 Object Lock in COMPLIANCE mode. This is true WORM (Write Once Read Many) storage. No one — not the researcher, not an admin, not even the root AWS account — can delete or alter these logs until the retention period expires. Configurable for 3, 5, or 7 years.
5. SEC Rule 21F-17(a) — Whistleblower Protection
What the SEC charged: Two Sigma’s separation agreements required departing employees to represent they had not filed governmental complaints. Nearly 300 employees signed these agreements.
EU Equivalent: EU Whistleblower Directive 2019/1937 — Protection of persons reporting on breaches of Union law.
How Agent Provost closes it: This rule is about employment contracts, not technology. But Agent Provost’s immutable audit trail supports whistleblowers — if an employee reports suspicious model behavior, the WORM logs provide tamper-proof evidence that cannot be retroactively altered or deleted by the firm.
6. FINRA Rule 3110 — Supervision
What FINRA requires: Member firms must establish and maintain a system to supervise the activities of associated persons that is reasonably designed to achieve compliance with securities laws and FINRA rules.
EU Equivalent: DORA — Digital Operational Resilience Act. Requires ICT incident reporting within 4 hours, third-party risk management, and operational resilience testing for critical functions.
How Agent Provost closes it: The two-hop proxy architecture captures both the LLM-to-MCP communication (intent) and the MCP-to-API communication (execution). Supervisors get end-to-end traceability — they can see what the AI decided, what it tried to do, and what actually happened.
7. SEC Rule 15c3-5 — Market Access Rule
What the SEC requires: Brokers and dealers with market access must establish risk management controls and supervisory procedures designed to manage financial and regulatory risks, including pre-trade capital thresholds, credit limits, and erroneous order filters.
EU Equivalent: MiFID II Article 17 — Algorithmic Trading Controls. Requires investment firms engaged in algorithmic trading to have effective systems and risk controls, including pre-trade controls and kill switches.
How Agent Provost closes it: The LuaJIT rules engine enforces pre-trade risk checks at wire speed — max_trade_size, max_trade_notional, cumulative_trade_notional, symbol_order_cooldown, allowed_tickers. Every check runs in sub-milliseconds before the order reaches the broker API. The kill switch can hard-block all trading instantly.
Summary Table of rules you need to follow!
| SEC Rule Broken | What It Requires | EU Equivalent | How Agent Provost Closes It |
|---|---|---|---|
| §206(2) Fiduciary Duty | Act in client’s best interest | EU AI Act Art. 14 (Human Oversight) | Deterministic circuit breaker blocks trades outside approved parameters |
| Rule 206(4)-7 Compliance Policies | Written policies to prevent violations | EU AI Act Art. 17 (Quality Mgmt) | rules.json = policy as executable code, enforced on every request |
| §203(e)(6) Supervision | Supervise personnel activities | MiFID II RTS 6 (Algo Record-Keeping) | Every action logged with user ID, machine ID, request body — visible in days |
| Rule 204-2 Books & Records | Retain records 3-5 years | EU AI Act Art. 12 (Logging) | Fluent Bit → S3 Object Lock COMPLIANCE mode = true WORM, tamper-proof |
| FINRA 3110 Supervision | Supervise all business activities | DORA (Operational Resilience) | Two-hop proxy captures both intent (LLM→MCP) and execution (MCP→API) |
| Rule 15c3-5 Market Access | Pre-trade risk controls | MiFID II Art. 17 (Algo Controls) | LuaJIT engine enforces pre-trade checks in sub-milliseconds + kill switch |
How Agent Provost Closes the Gap
Agent Provost doesn’t sit inside the model. It sits in the data path—between the model’s output and the broker’s API. It is a deterministic firewall for probabilistic engines.
Here is how the Agent Provost rules engine (written in LuaJIT) would have stopped the Two Sigma failure:
- cumulative_trade_notional: Tracks rolling exposure per user/machine. If a researcher’s modified model starts concentrating trades beyond limits, the proxy hard-blocks the trade with a
403 PROVOST_INTERVENTION. - max_trade_size: Blocks any single trade exceeding a share quantity cap.
- symbol_order_cooldown: Prevents “frequency” failures by blocking repeat orders for the same symbol within a time window.
- allowed_tickers: In “draconian mode,” it blocks any ticker not explicitly on the approved list.
- Immutable Audit Trail: Every blocked attempt is logged with the user’s identity, the machine ID, and the exact JSON payload. These logs go to S3 Object Lock in COMPLIANCE mode. They cannot be deleted or altered—not even by the person who wrote the code.
In the Two Sigma case, the pattern would have been visible in days, not two years.
The Human-in-the-Loop Model
The only SEC-compliant path forward is Human-in-the-Loop:
- Human uses AI to research.
- Human decides to buy and tells the AI to execute.
- Agent Provost checks the rules, allows or blocks, and logs everything immutably.
The human makes the decision. The AI is the reasoning engine. Agent Provost is the System of Record.
Deploy Deterministic Governance
The market isn’t waiting. LLM-based trading is happening now. The execution side is the bottleneck because of the Supervision Gap.
Agent Provost removes that bottleneck. It inspects every JSON payload, enforces hard risk rules in sub-milliseconds, and creates a tamper-proof ledger for regulators.
Deploy Agent Provost on AWS Marketplace
View the Architecture on GitHub
Learn more at FloatingCloud.io
