On October 19, 1987, portfolio insurance strategies did exactly what they were designed to do. They sold as markets fell. And as selling intensified, many strategies using similar dynamic-hedging logic generated further sell signals. By the close of trading, the Dow Jones Industrial Average had fallen 22.6%, the largest single-day percentage decline in its history.
Portfolio insurance was not the sole cause of Black Monday, but subsequent analysis identified it as one of the mechanisms that compounded selling into an already falling market. The algorithms had not necessarily malfunctioned. The deeper problem was the interaction between automated strategies operating simultaneously in stressed conditions.
Thirty-nine years later, the European Union is asking a related question. The EU AI Act represents the world’s most comprehensive horizontal regulatory framework for artificial intelligence. Many of its provisions now apply, although the timetable for the rules governing high-risk AI systems has recently been extended. Under changes adopted in July 2026, the requirements for stand-alone high-risk AI systems will apply from 2 December 2027, while those embedded in regulated products will follow from 2 August 2028.
For financial institutions running AI-driven execution, pricing, risk, surveillance or trading systems, the implications are significant. But firms first need to understand exactly where their systems sit within the regulatory framework.
Where trading systems actually sit
The AI Act applies a risk-based framework to AI systems. High-risk applications face the most demanding requirements, including risk management, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity.
But there is an important distinction for trading firms.
AI-based algorithmic trading is not currently designated as a high-risk use case under the AI Act. ESMA made this explicit in its February 2026 Supervisory Briefing on Algorithmic Trading in the EU. It states that while an algorithmic trading system meeting the Act’s definition of an AI system may be subject to relevant AI Act requirements, AI-based algorithmic trading is currently excluded from the scope of high-risk use cases. ESMA also notes, however, that the scope of high-risk use cases is subject to annual review.
That distinction matters. It means firms should not assume that an AI-driven execution algorithm automatically falls into the Act’s high-risk category simply because it makes autonomous trading decisions.
Equally, firms should not conclude that the AI Act is irrelevant.
Where an algorithmic trading system meets the Act’s definition of an AI system, relevant provisions may still apply depending on how that system is used. ESMA notes, for example, that AI used in algorithmic trading may potentially attract transparency obligations where it is intended to interact directly with natural persons.
More importantly, firms are already subject to extensive algorithmic-trading requirements under MiFID II and RTS 6.
The practical compliance challenge is therefore not simply:
Is my trading system high-risk under the AI Act?
It is:
Which elements of the AI Act apply to this system, how do they interact with our existing MiFID II obligations, and can we demonstrate effective governance of the system throughout its lifecycle?
The existing regulatory framework is already demanding
ESMA’s February 2026 Supervisory Briefing is important because it makes clear that the arrival of AI does not replace the existing algorithmic-trading framework.
Investment firms remain responsible for their trading algorithms regardless of whether they are developed internally or supplied by a third party.
Systems must be appropriately governed, tested and monitored. Material changes require appropriate testing. Firms must maintain clear accountability and oversight, and outsourcing cannot transfer regulatory responsibility away from the investment firm.
ESMA goes further where AI is involved. It warns that a series of apparently minor model recalibrations could accumulate over time into a material change in model output without the resulting system being properly tested.
That is particularly relevant for machine-learning systems.
A conventional algorithm may behave differently because somebody changes its code. A machine-learning system may change behaviour because its inputs, parameters, training data or learned relationships change. The governance problem therefore becomes continuous rather than episodic.
Under Article 9 of RTS 6, investment firms already have to carry out an annual self-assessment and validation process covering their algorithmic trading systems, strategies, governance and compliance arrangements. ESMA says firms and supervisors should explicitly consider the use of AI within that process.
This is arguably the most immediate regulatory issue for many FX firms. The obligation exists now.
What happens if a system is classified as high-risk?
Although AI-based algorithmic trading is not currently a designated high-risk use case, firms should still understand what the high-risk framework requires. The classification can evolve, and financial institutions may operate other AI systems that do fall within high-risk categories.
Several provisions are particularly relevant.

Article 9 — Risk Management
A documented risk-management system must be established, implemented and maintained throughout the lifecycle of a high-risk AI system.
That includes identifying reasonably foreseeable risks, evaluating those risks, adopting appropriate mitigation measures and testing systems against defined performance metrics and thresholds.
This is not a one-off model-validation exercise.
For a financial institution, the practical implication is that governance has to follow the model into production. A model that was safe when approved may behave differently when market structure, liquidity, volatility, correlations or the data on which it relies begin to change.
Article 12 — Record-keeping
High-risk AI systems must include automatic logging capabilities enabling events to be recorded throughout the system’s lifecycle.
The purpose is traceability. That does not mean that every individual trade must be accompanied by a human-readable essay explaining precisely why the AI made its decision. It does mean that firms need records sufficient to understand and investigate how the system behaved, identify relevant risks and support post-market monitoring.
For trading firms, this has obvious parallels with existing expectations around algorithm logs, order records, parameter changes and testing documentation.
Article 13 — Transparency and Provision of Information
High-risk systems must be sufficiently transparent to allow deployers to interpret their output and use it appropriately.
Providers must supply information about the system’s characteristics, capabilities and limitations so that those responsible for deploying it understand how it should — and should not — be used.
This is sometimes described loosely as an “explainability requirement”, but that phrase can be misleading. The Act does not prescribe one universal technical method for explaining every model decision. There is no requirement that every trading firm adopt SHAP, feature-attribution techniques or any other particular explainability methodology.
The appropriate level of interpretability depends on the system and its intended use. For a trading firm, the more useful questions are practical ones:
Can the people responsible for the system understand the factors that materially influence its behaviour?
Can they identify when it is operating outside the environment for which it was designed?
Can they tell when model confidence is deteriorating?
Can they reconstruct what happened after an abnormal trading event?
Those are much more meaningful questions than whether somebody can produce an elegant explanation of one isolated trade.
Article 14 — Human Oversight
For high-risk AI systems, human oversight must be designed into the operating framework.
The Act requires that appropriate human overseers are able to understand the system’s capabilities and limitations, monitor its operation, interpret its output and, where appropriate, disregard, override or reverse that output.
They must also be able to intervene in the operation of the system or stop it safely.
This does not mean that a human must approve every algorithmic trade. That would defeat much of the purpose of algorithmic execution.
It does mean that human oversight has to be effective rather than theoretical. A kill switch that exists somewhere in a manual but cannot practically be used when the system begins behaving abnormally is not meaningful control.
That principle should already be familiar to MiFID-regulated algorithmic trading firms.

The explainability problem
There is a particular challenge when machine learning enters trading.
Traditional execution algorithms are normally constructed from rules that can be examined directly:
If volatility exceeds a threshold, reduce participation.
If spreads widen, become less aggressive.
If an order reaches a defined proportion of market volume, alter the execution trajectory.
The causal chain can generally be inspected.
Machine-learning models are different. A model may combine dozens or hundreds of variables and discover relationships that were never explicitly programmed by the people operating it.
That can produce better predictions. It can also produce a governance problem.
Suppose an AI-driven execution system suddenly becomes significantly more aggressive in EUR/USD at 10:17 on a volatile morning.
The question for a compliance officer is not simply whether the trade made or lost money. They may need to know whether the behaviour reflected volatility, liquidity, order-book imbalance, historical flow, model recalibration, a data-quality problem or an interaction nobody anticipated. That is why explainability in trading should not be treated as a fashionable branch of data science. It is increasingly becoming part of operational control.
The real lesson from 1987
Black Monday is useful precisely because the systems involved did not need artificial intelligence to generate systemic consequences.
Portfolio insurance used relatively straightforward rules.
The danger came from feedback. Markets fell. Strategies responded by selling. That selling contributed to further market declines.Those declines generated further selling. AI introduces an additional dimension because some systems can adapt to changing data and discover relationships that are not explicitly coded by their designers. That does not make AI inherently dangerous. It does make governance harder.
ESMA’s warning about successive small recalibrations accumulating into a material model change goes directly to this point. A system can evolve gradually until the model running today is meaningfully different from the one originally validated. The control framework therefore has to evolve with it.
What firms should be doing now
The first step is an inventory.
Firms should know which systems in their trading and risk infrastructure potentially meet the AI Act’s definition of an AI system.
That sounds obvious.It isn’t.
Machine learning may sit inside execution algorithms, liquidity selection, smart order routing, transaction-cost analysis, market surveillance, pricing engines, risk controls, client-flow classification and vendor products whose internal architecture the investment firm does not fully control.
The second step is classification.
Do not assume every AI system is high-risk. Determine what the system actually does, how it is used, whether any specific AI Act obligations apply and how those obligations interact with MiFID II and RTS 6.
The third is ownership.
Somebody must be accountable for what the system is doing.The model may have been built by a quant team. It may have been bought from a vendor. It may run in somebody else’s cloud environment.
None of those facts removes the firm’s responsibility for the algorithmic trading activity.
ESMA is explicit on outsourcing: firms should retain ongoing visibility and access to outsourced algorithms and must have the unconditional ability to monitor, suspend or terminate algorithmic trading when necessary. Regulatory responsibility remains with the investment firm.
The fourth is change control.
Machine-learning models create a temptation to regard continual recalibration as normal operation rather than model change.
Regulators may take a different view when cumulative adjustments alter the behaviour of the system materially.
Firms need thresholds for deciding when a change requires testing, validation or renewed approval.
The fifth is evidence.
It is no longer enough to say that a system is monitored. Firms need to be able to demonstrate how.
What was tested? Who approved it? What parameters changed? What data was used? What happened when the model encountered conditions outside its normal range? Who could intervene?Was intervention technically possible? What records were retained?
Those questions should be answerable before a regulator asks them.

The penalties are real — but they need to be understood correctly
The AI Act provides for substantial administrative penalties.
The highest maximum — up to €35 million or, for undertakings, 7% of total worldwide annual turnover for the preceding financial year, whichever framework produces the applicable maximum — relates to infringements involving prohibited AI practices.
Other infringements of obligations imposed on providers, deployers and other operators can attract penalties of up to €15 million or 3% of worldwide annual turnover, subject to the detailed provisions of the Act.
Those figures are maximum penalties, not automatic fines for an algorithmic-trading compliance failure.
But they demonstrate how seriously the European Union is treating AI governance.
The deadline has moved. The problem hasn’t.
The regulatory timetable has changed.
The high-risk AI provisions that had originally been expected to apply from August 2026 have been postponed. Under the legislation adopted in July 2026, the principal requirements for stand-alone high-risk systems will apply from 2 December 2027.
For algorithmic trading firms, however, that should not be interpreted as an eighteen-month holiday.
AI-based algorithmic trading is not currently classified as a high-risk use case under the AI Act, but the classification is subject to review. More importantly, the MiFID II and RTS 6 obligations governing testing, governance, validation, oversight and control of algorithmic trading systems already apply.
The firms best prepared for whatever comes next will therefore not be those attempting to predict exactly where regulators eventually draw every classification boundary. They will be the firms that can demonstrate that they know which models they are running, what those models are allowed to do, how their behaviour is tested, who owns them, how changes are controlled, what evidence is retained and how a human can intervene when something goes wrong.
That is ultimately the issue. In 1987, the algorithms did exactly what they were designed to do.
The question the EU AI Act is asking is simpler:
Can you prove it?

