The idea in one breath: MCP is a standard way for a model to call somebody else’s software. When a broker opens one, it is publishing a menu of operations an agent may perform on your account. The interesting part of any such announcement is never the protocol — it is which operations are on the menu, and whether placing an order is one of them.
During 2026 a series of brokers announced that AI agents could connect to trading accounts. Robinhood opened a trading server to third-party agents in May; Webull, Deriv, IG, ThinkMarkets and eToro followed with their own arrangements. The announcements share a piece of vocabulary — the Model Context Protocol — and it is worth knowing what it is before deciding what to think.
What the protocol is
MCP is an open standard for exposing tools to a model. A server declares a set of operations with typed inputs, and any compatible client can discover and call them. That is the whole idea. It is plumbing, in the same category as a well-documented API, and it carries no opinion about what the operations should be.
So "the broker opened an MCP server" tells you a connection is possible and nothing at all about what it permits. That is the question the phrase tends to obscure.
The menu is the story
The operations a broker publishes fall into rough tiers, and the boundary between them is the only part with consequences.
- Read your positions and balances. An agent that can see your account and say things about it.
- Read market data and research. Broadly the same risk as any data feed.
- Stage an order for your approval. The agent prepares, you confirm. A human remains in the loop at the only moment that costs money.
- Place an order without per-trade approval. The agent transacts. This is a different product wearing the same word.
Different venues drew that line in different places, deliberately. Some restricted their integration to read-only with no execution through the AI layer. Others permit an agent to trade on a client’s behalf. Both are defensible engineering; they are not the same offer, and a single phrase covers both in most coverage.
The supervision question
Regulators noticed. FINRA’s 2026 oversight report flagged agent-executed trading as an area needing governance around vendor risk. That is not a prohibition and should not be read as one, but it tells you the supervisory questions are live rather than settled: who is responsible for an agent’s order, what record exists of why it was placed, and what happens when the model that placed it is retired and replaced.
You are evaluating a broker’s new agent integration. Order the questions by how much the answer changes your risk — the one that changes it most first.
- 1Which model is behind the agent, and what happens to my setup when it is replaced?
- 2What are the venue’s stated limits, and who is liable when the agent is wrong?
- 3Can the agent place an order without my approval on each trade?
- 4What record is kept of why an order was placed, and can I read it afterwards?
- 5What credential does the agent hold, and can I revoke it without closing the account?
- 6What operations does the published menu actually contain, beyond the headline?
Part of Track 15 · AI & Automated Trading — see the full syllabus.
Put it on a live chart
You have done the checkpoint. The concept is worth more on a symbol you actually care about than on a teaching example — the first read is free and needs no account.
Grade a chart free