At the end of May 2026, the International Organisation of Securities Commissions (IOSCO) published its 'Supervisory Toolkit for AI and Capital Markets'. IOSCO advises regulators across the world's major capital markets, so the terms it uses tend to show up in national rulebooks and supervisory questions within a year or two.
That matters for any regulated trading firm running AI on live workflows today, whether or not a regulator has asked about it yet. The EU AI Act already requires human oversight to be built into high-risk AI systems. IOSCO's toolkit gives supervisors a concrete way to check that oversight is real, not just written down.
This is the second piece to come out of that Smarter Markets appearance. The first, Chat, data, AI, governance: the four pillars reshaping trading desks, sets out the wider argument; this one goes deeper on the governance piece specifically.
Four reference points, not a vague standard
IOSCO's toolkit sets out four levels of human oversight and expects supervisors to work out which one a firm's AI deployment actually sits at, rather than take a firm's word for it. Our own autonomy slider is built around the same four points, because they're the ones I kept coming back to in conversations with clients and compliance teams before IOSCO's paper existed:
-
Human-in-control. A person decides everything. AI plays no active role.
-
Human-in-the-loop. AI acts. A person approves at each gate before anything moves forward.
-
Human-on-the-loop. AI runs the workflow. A person monitors it and can step in if something looks wrong.
-
Human-out-of-the-loop. AI acts independently, without a person reviewing it in real time.
If a firm can't say, workflow by workflow, which of these four levels it's operating at, that's the gap a supervisor will find first.
Where most firms actually sit
No large financial institution is running agents human-out-of-the-loop on live trading risk, and I don't expect that to change soon: the money at stake is still too high for firms to hand execution over completely. Forward-thinking regulated firms we talk to sit somewhere between human-in-the-loop and human-on-the-loop, approving the steps that matter most and monitoring the rest closely enough to step in if something goes wrong.
Workflows furthest along the slider, typically post-trade processes in the current environment, tend to sit at human-on-the-loop: the trade has already happened, so the financial risk of an error is lower than during execution. That matches what IOSCO's toolkit expects supervisors to look for: lower-risk, higher-volume processes moving first, with position and money at stake going last.
Why the position isn't fixed
Autonomy isn't a single decision a firm makes once, and IOSCO's toolkit reinforces that. It moves according to the task: the complexity involved, the amount of money on the line, whether a four-eyes check applies, and the level of accuracy the workflow can tolerate. What a firm needs is an audit trail that shows, workflow by workflow, why a given task sits where it does, and what happens when accuracy drops below the threshold that workflow requires.
What this means for your firm
IOSCO's paper guides regulators. It doesn't set rules for firms directly. But guidance to regulators tends to turn into questions for firms soon enough. A firm that can point to a documented level of human oversight for each of its AI-driven workflows, with accuracy thresholds and checkpoints named, will have an easier supervisory conversation than one that can't.
I've set out how we map these four levels to specific trading workflows on our autonomy slider page, if you want to see it against your own.