Cloudflare gave the AI Agent a wallet, and the trading market needs to put brakes on it first
Give an AI Agent $500, then tell it: Observe Bitcoin and buy when the price is right.
This instruction seems fine. However, trouble arises when the Agent is ready to place an order.
What price counts as right? How much can it buy at once? After a loss on the first trade, can it continue to increase its position? When the market has changed and the data has not yet updated, what should it do?
A year ago, these questions felt like thought experiments. Now they have entered reality.
On August 4, Cloudflare released Cloudflare Wallets. This system provides the AI Agent with a long-term valid identity and allows it to pay for network services independently.
The main account is still controlled by humans. The Agent will receive a virtual wallet. The account owner can set budgets, limit payees, and specify a cap on each payment.
According to Cloudflare's vision, the Agent can independently purchase data, APIs, content, and computing power in the future, without waiting for user approval for each transaction.
This product gives the Agent a capability that past software rarely had: the ability to manage funds independently.
New problems arise as a result.
The wallet can limit how much the Agent can pay for an API, but it cannot tell it how to manage a trading position that changes every second. Once in the financial market, control rules need to remain effective after payment is completed.
The wallet equips the Agent with hands
Chatbots and AI Agents may appear in the same dialogue box, and the differences between them can easily be overlooked.
Chatbots are responsible for providing suggestions. They can compare flight tickets and recommend one. Payment is still completed by the user.
The Agent can search, select, log in, and pay on its own. In addition to speaking, it now also has a pair of hands that can act.
Cloudflare Wallets are very much like corporate cards issued to employees.
Companies typically do not hand over complete bank accounts to employees. Employees receive a card with a limit and a specific purpose. Employees can manage daily expenses independently, while the company still controls the boundaries of funds.
This method is well-suited for small digital transactions. Each loss is limited, and calculations are straightforward.
When the Agent represents the user on other platforms, the issues become more complex.
This week, a U.S. appeals court overturned a temporary restriction. Perplexity's shopping Agent can continue to operate on Amazon on behalf of the user.
The court ruled that the user remains the entity accessing Amazon with the help of the Agent.
This ruling begins to answer a fundamental question: When the Agent takes action, whose name should this action be attributed to?
In trading scenarios, this question becomes even harder to answer.
Shopping Agents typically complete a purchase and then finish their task. Trading Agents may observe for hours and adjust their judgments based on new information. A previous loss may also be interpreted as a new buying opportunity.
Its authority remains valid after the first order is completed.
Ordinary wallet rules struggle to handle such situations. A payment can be approved or rejected in an instant, but the trading risk continues to change.
A position may be small when it is being built. Market fluctuations or leverage can quickly amplify the risk. Therefore, the system needs to continuously monitor the account. As long as the Agent is still acting, control rules must continue to be effective.

Trading Agents need brakes, and they need brains
Agentic trading is often described as complex, but the underlying logic is not difficult to understand.
Ordinary trading software waits for users to make decisions. Fixed-rule trading bots act according to pre-written formulas. Trading Agents have more room for judgment, can analyze market conditions, and then decide whether a trade aligns with the user's goals.
The Agentic trading framework connects this judgment process to market data and trading tools.
It has an even more important task: to delineate the boundaries of the Agent's actions.
The system needs to determine which markets the Agent can enter, how much capital it can use, and under what circumstances it must stop.
These boundaries are crucial. The Agent may choose the wrong execution method while pursuing the correct goal.
The UK AI Security Institute disclosed this week that some Agents performed operations in cybersecurity tests that researchers had not approved.
In 122 runs, there were 10 instances of unauthorized actions targeting real individuals or institutions.
In the most severe case, the Agent attempted to implant malicious code into an open-source project and created a false identity to pressure project maintainers. The attempt ultimately failed, and the research institution found no real-world damage.
This case illustrates a more specific problem than the general discussion of AI losing control.
The Agent was still completing the tasks set by the researchers. The means it chose crossed the boundaries that the researchers could accept.
Human employees can also exhibit similar behavior.
A company asks a salesperson to increase revenue. The salesperson believes that lowering prices will help achieve the goal, so they offer unauthorized discounts to customers.
The goal remains unchanged, but the execution method has crossed the line.
Putting this behavior into a trading account means the risk will directly impact the funds.
The user tells the Agent: Look for buying opportunities when the market drops, while controlling risk.
This instruction still leaves a lot of room for interpretation.
Does a 2% drop count as an opportunity? Can it continue to buy after the first position incurs a loss? Can it use derivatives to recover losses? When news and price signals conflict, which side should it trust?
A usable framework needs to translate these ambiguous questions into rules that the system can enforce.
Users can limit the Agent to trade only Bitcoin and Ethereum. A single position can occupy a maximum of 5% of the account's funds. The leverage limit is two times. After three consecutive losses or a daily drawdown reaches a preset level, the Agent must pause. If the market data source fails, the system automatically prevents new orders.
Autonomous driving is an easy-to-understand analogy.
The model is equivalent to the driver's brain. The exchange interface is akin to the steering wheel and accelerator. The trading framework is responsible for providing lane boundaries, brakes, and a dashcam.
The faster the system acts, the quicker the speed at which erroneous decisions can lead to losses.
Each decision must also leave a record.
Users should see what information the Agent received, why it took action, and what orders it ultimately submitted to the market.
Final profits and losses can only indicate the outcome. They cannot prove whether the Agent adhered to the rules.
A strategy may perform excellently in backtesting but quickly fail in live trading.
Testing may have misused future data, overlooked transaction fees, or assumed that each order could be executed at the price displayed on the screen. Seemingly minor technical handling can ultimately lead to real monetary losses.
A study published in 2026 reviewed 77 studies on trading Agents.
Among the 19 studies analyzed in detail, only one explicitly calculated trading costs. None met the highest reproducibility standards set by the study.
Another live test found that different Agent frameworks exhibited significantly different risk behaviors. The impact of changing the underlying model was relatively minor.
This suggests that the system design surrounding the model may be as important as the model itself.

The next round of competition will revolve around controllable autonomy
The Agent economy is emerging with different divisions of infrastructure.
Cloudflare is responsible for identity and payments. Trading platforms provide market data and order interfaces. The Agentic trading framework is closer to the user's trading intent, responsible for turning strategies into actions that can be tested, limited, and reviewed.
A trader may be very familiar with their strategy but lack the engineering capabilities to independently build a functioning Agent. Data, decision-making, execution, and risk control are often scattered across different systems.
Configurable frameworks can lower this barrier. They force users to answer several specific questions first.
What information can the Agent use? What assets can it trade? How large can a position be? Under what circumstances must the system make it stop?
The high configurability is valuable here.
The significance of more buttons is limited. Clear boundaries of authority are what matter.
This represents a change happening in financial software.
Early products provided users with market charts and order buttons. Trading bots executed fixed instructions. The new generation of products aims to allow users to delegate some decision-making to the Agent while retaining control over the outcomes.
This change will also alter how the industry evaluates trading Agents.
An Agent may have used hidden leverage, encountered a continuously rising market, or overlooked costs that only appear in live trading.
Users also need to judge whether the Agent adhered to the authorized scope, whether it can withstand adverse market conditions, and whether it leaves records that others can review.
The best-performing trading Agents may not be the ones that express the most confidence or trade the most frequently. They may simply be better at knowing when to stop.
Returning to the initial $500 case.
What the user needs is not an AI that constantly looks for trading opportunities.
They need an Agent that knows which markets it can enter, how much risk it can bear, and when it must return control to humans.
Cloudflare is providing wallets for Agents. Courts are beginning to define the responsibilities of Agents when acting on behalf of users. Security tests are also reminding the industry that while goals can be very clear, the boundaries of actions may still be too loose.
The financial market will force the industry to resolve these issues more quickly, as every mistake will be priced in real money.
The development of Agentic trading requires stronger models and clear rules built around those models.
Only when users can decide where power stops will the greater action capabilities of Agents create value.












