Why Institutional AI Agents Need Regulated Rails

The Cambridge Centre for Alternative Finance surveyed 482 financial firms and regulators between October 2025 and January 2026. It found 52 percent of institutions piloting agentic AI or further along, with 23 percent already scaling (Cambridge Judge Business School). Almost none of that activity involves an agent committing capital to a position. The reason is not that the models cannot read an offering memorandum or price a building. It is that no venue can yet answer, for a machine, the question every market has always asked before accepting an order: on whose authority, within what limits, and can you prove it afterward?

The gate is authority, not capability

Every action in a capital market resolves to a principal. A trader acts for a desk, a desk for a firm, a firm for its clients, and each link carries a mandate, a limit and a signature. The system works because authority is legible. When a software agent submits a subscription to a private placement or instructs a transfer of a security, the same chain must hold, and today it does not.

The consumer payments industry reached this conclusion first. In April 2026 the FIDO Alliance formed an Agentic Authentication Technical Working Group to standardize how agents authenticate on behalf of a user and how delegation is bounded, building on a payments protocol contributed by Google and a verifiable-intent framework from Mastercard (FIDO Alliance). Card networks are binding an agent to a specific merchant scope and a consent record signed by the consumer's own issuer. The objects being standardized are exactly the ones capital markets need: a verified principal, a scoped mandate, an expiry, a revocation path and a record.

Capital markets carry heavier objects than a checkout. An agent buying into a tokenized commercial real estate interest is subscribing to a security under an exemption that turns on who the investor is. An agent rebalancing a treasury into tokenized gold is taking delivery of a claim on a bar in a vault. An agent instructing a distribution is moving money that belongs to someone else. Each requires that the machine's action resolve to a person or entity that has been verified, that the action falls inside a delegation that person granted, and that the delegation can be revoked and audited. None of that is a model problem. It is a rails problem.

What regulated rails supply that open ones cannot

Framed as value rather than obligation, a regulated venue gives an agent four things an open protocol does not.

The Cambridge survey found 51 percent of respondents ranking loss of human oversight among the top AI risks, and industry more worried about it than regulators, at 55 percent against 42 percent. The instinct is to put a human in every loop, which would make agents pointless. The better answer is a record. If every machine action is signed under a named delegation with explicit limits, oversight becomes something a compliance officer reads on Monday rather than something that has to happen in real time.

What a delegation has to contain

Research on agent-to-agent finance has converged on a checklist for the delegation object, and it is worth stating in full because venues will be judged on whether they support each item (arXiv, July 2026).

The principal must be verified and referenced by credential, not re-identified per action. Scope must be explicit: which asset classes, which issuers or venues, maximum ticket size, and concentration limits against the portfolio. Time must be bounded, with an expiry after which the delegation is void without anyone acting. Revocation must be immediate and must propagate before the next action, not after. Approval thresholds must exist, so that a transfer above a stated size pauses for a human signature while smaller ones proceed. And every action must carry an audit label tying it to the delegation that authorized it.

Consider a family office whose agent manages a sleeve allocated across tokenized real estate, gold and short-duration Treasury funds. The delegation might permit subscriptions into commercial real estate interests up to a stated ticket, on venues where the office has completed onboarding, with any single position capped at a share of the sleeve, and with new-issuer exposure requiring a principal's approval. The agent rebalances within those limits, every move is recorded against the delegation, and the office's quarterly review reads the log rather than reconstructing intent.

The accountability question is where the survey's findings bite. Regulators surveyed by Cambridge placed primary responsibility for agent outcomes on the regulated financial institution, at 38 percent, while industry and vendors preferred case-by-case allocation. A venue should assume it will be held to the regulator's view. That means the venue designs the delegation format and enforces it at the point of action, rather than accepting whatever authority a visiting agent asserts.

What this means for issuers and venues

For a sponsor raising capital against a building, a producing well or a data center, the arrival of agent principals changes the shape of demand rather than its source. The capital still belongs to institutions and family offices. What changes is that a growing share of their allocation decisions will be executed by software operating under delegations, and that software will route to wherever it can act with verified authority and read verified data. A sponsor whose offering lives on a venue that supports both is reachable by that flow. A sponsor whose offering lives in a PDF is not.

For venues, the market's participants are describing a competitive test. The Cambridge respondents expect agentic AI to be meaningfully achieved by 2030, at 81 percent. Between now and then the venues that win agent flow will be those that made principal, scope, expiry and record first-class objects at the point where an order is accepted. Commertize's view is that this is the same infrastructure institutions already require for their own people, made machine-readable, which is why regulated venues built on verifiable data hold the advantage over open protocols that never asked who was signing.

None of this depends on a new standard arriving. It depends on venues treating the question "on whose authority" as something to be answered by the rail rather than by trust. Markets that answer it will get the agents. Markets that do not will get the pilots.

Have an asset you're thinking about tokenizing? See how the platform works and start at commertize.com/tokenize, or contact the team and tell us what the asset is — if it isn't a fit, that is a useful answer to get in one conversation rather than three.

Have an asset you're evaluating for tokenization? Send the offering memo to deals@commertize.com or start at commertize.com/tokenize, and we will return a written tokenizability and capital-structure memo within 48 hours — free, no obligation.

Confidential review. No cost, no commitment, no calls unless it is a fit.