150,000 Agentic Accounts, 30 Million Tool Calls A Day, And An Off Switch For Human Approval: The Architecture Behind Robinhood Agents, And How To Build The Controls It Leaves To You
Robinhood has turned the retail brokerage into an agent platform. Since opening its MCP servers to outside agents on 27 May, more than 150,000 customers have opened dedicated agentic accounts and agents now call Robinhood's tools about 30 million times a day. At HOOD Summit on 30 September it went further: in-app Robinhood Agents that a customer names, funds and connects to a model from OpenAI or other labs, which then analyse markets, build strategies and trade - with manual approval on by default but switchable off for fully autonomous execution; 'Loops', standing instructions executed around the clock, coming soon; paid 'Agent Apps' data feeds from eleven partners; crypto perpetuals at up to 10x; and 24/7 equities in early 2027. The Bank of England's deputy governor has already warned that agents like these could amplify volatility in stress. Robinhood's own terms say it does not monitor or audit agent behaviour and customers bear every loss. That makes the platform architecture - account isolation, tool surface, approval modes, the strategy and backtest gate, limits and the chart that shows what the agent did - the whole product. Here is how we would build it, in code.
AlchmAI Engineering17 min read
150,000+
Customers who have opened agentic trading accounts since Robinhood opened its MCP servers to agents on 27 May
30M / day
Times agents call Robinhood's tools daily, per the company at HOOD Summit on 30 September
Default: on
Manual trade approval in Robinhood Agents - adjustable at any time, including fully autonomous execution
11
Partner data feeds launching as paid 'Agent Apps', from Nasdaq and SpotGamma to Unusual Whales, with one-month trials
Robinhood's two agent launches, four months apart, are the clearest blueprint yet of what a retail agent platform looks like. In May it opened MCP servers so any outside agent - Claude, a Cursor session, a custom bot - could trade a dedicated agentic account funded only with deposited money, with a real-time activity feed, push notifications per trade, trade previews, fraud review and one-tap disconnect. At HOOD Summit in Houston on 30 September it added its own: Robinhood Agents, set up in three steps - name the agent, open its account, connect a model - with OpenAI's GPT-Luna free through year-end and other labs' models available, manual approval of trades on by default and switchable off, 'Loops' for standing instructions executed 24/7 coming soon, and a marketplace of eleven paid data feeds the agent can draw on. Alongside: crypto perpetual futures at up to 10x leverage, Cboe KPI-based earnings contracts, 4x intraday margin and 24/7 weekend equities in early 2027 pending approval. 'Whether you're an expert or are just getting started with AI, you're at a disadvantage if you're not using Robinhood,' said product VP Abhishek Fatehpuria.
The numbers show it is not a demo: 150,000 agentic accounts and roughly 30 million tool calls a day. The caveats show where responsibility sits. Robinhood says agents can make errors, misinterpret instructions and behave unexpectedly; that it does not monitor or audit third-party agents; and that customers bear all losses and must review account activity themselves. The Bank of England's deputy governor Sarah Breeden has warned that agents of this kind could amplify market volatility in periods of stress. In other words, the platform supplies the rails and some good defaults; the controls that make an agent safe for a given customer are the platform architecture itself, and much of it is left to whoever builds on top.
1. Account Isolation And A Propose-Only Tool Surface
export interface AgentAccount {
id: string;
ownerId: string;
agentId: string; // one agent per account; the agent's identity, not the owner's
fundedMinor: number; // only what the owner deposited is ever reachable
mode: "approve_each" | "approve_above" | "autonomous";
approveAboveMinor?: number; // used when mode === "approve_above"
limits: { maxPositionNotionalMinor: number; maxDailyLossMinor: number; maxLeverage: number; instruments: Set<string> };
status: "active" | "paused" | "disconnected";
}
// The agent's MCP tool set. Reads are free; the only write is a proposal.
export const AGENT_TOOLS = [
"get_quotes", "get_option_chain", "get_positions", "get_activity", "get_strategy_results",
"propose_order", // returns a proposal id; execution happens in the gateway
"propose_strategy", // a strategy spec to be backtested and approved, not run
] as const;
// Deliberately absent: place_order, change_limits, set_mode, add_funds, connect_data_feed.The agent cannot place an order, change its own limits, switch its own approval mode or move money. It can only propose, and the owner - or a policy the owner set in the app, under their own authentication - decides. That single design choice is what keeps 'autonomous' meaning 'autonomous within limits I set' rather than 'unsupervised'.
2. Approval Modes That Degrade Safely
type Verdict = { action: "execute" } | { action: "ask_owner"; reason: string } | { action: "reject"; reason: string };
export function approvalVerdict(acct: AgentAccount, p: OrderProposal, state: AccountState): Verdict {
// Hard limits first; no mode can override them.
const notional = p.qty * p.limitPrice;
if (!acct.limits.instruments.has(p.instrumentType)) return { action: "reject", reason: "instrument not enabled for this agent" };
if (state.positionNotionalMinor + notional > acct.limits.maxPositionNotionalMinor) return { action: "reject", reason: "position limit" };
if (state.realisedLossTodayMinor + state.unrealisedLossMinor > acct.limits.maxDailyLossMinor) return { action: "reject", reason: "daily loss limit reached - agent paused" };
if (p.leverage > acct.limits.maxLeverage) return { action: "reject", reason: "leverage above limit" };
if (state.marketStress) return { action: "ask_owner", reason: "volatility circuit: approvals required during stress" }; // the Breeden point
switch (acct.mode) {
case "approve_each": return { action: "ask_owner", reason: "approve-each mode" };
case "approve_above": return notional > (acct.approveAboveMinor ?? 0) ? { action: "ask_owner", reason: "above approval threshold" } : { action: "execute" };
case "autonomous": return { action: "execute" };
}
}
// marketStress is set by the platform, not the agent: e.g. index move > 3% intraday, or VIX above a level,
// or the instrument halted/reopened in the last 15 minutes. When the market is disorderly, every agent asks.- Autonomous mode exists, but only inside hard limits the owner set under their own login, and it falls back to asking during stress. That answers the central-bank concern directly: agents that all stop asking at the same moment are the amplifier; agents that all start asking are not.
- A daily-loss limit pauses the agent rather than just rejecting one order. An agent that keeps proposing after a bad day is the pattern that empties accounts.
- Every verdict is logged with the limits and state it was evaluated against - the record the owner, the broker and a regulator will each want.
3. Strategies Must Pass A Gate Before They Run
Robinhood's own examples - rebalancing for concentration, thematic monitoring, backtesting and deploying a mean-reversion strategy - are all strategies, not single trades. A strategy the agent wrote should be treated like code the agent wrote: declared in a constrained specification, backtested with costs, checked against limits, and approved by the owner before 'Loops'-style standing execution begins.
from dataclasses import dataclass
@dataclass(frozen=True)
class StrategySpec:
name: str
universe: list # instruments; must be a subset of the account's enabled instruments
signal: str # from an ENUM of supported signals, e.g. "zscore_mean_reversion", "sma_cross"
params: dict # bounded per signal type
rebalance: str # "daily" | "weekly" | "on_signal"
max_position_pct: float # of account funding
stop_loss_pct: float
GATES = {"min_sharpe": 0.8, "max_drawdown_pct": 15.0, "min_trades": 40, "min_years": 3, "max_turnover_pct_per_day": 50.0}
def gate(spec: StrategySpec, acct, backtest) -> dict:
failures = []
if not set(spec.universe) <= acct.limits.instruments: failures.append("universe outside enabled instruments")
if spec.max_position_pct * acct.funded_minor > acct.limits.max_position_notional_minor: failures.append("position size above limit")
r = backtest.run(spec, years=5, costs=True, slippage_bps=5) # realistic costs, out-of-sample split
if r.years < GATES["min_years"]: failures.append("insufficient history")
if r.trades < GATES["min_trades"]: failures.append("too few trades to judge")
if r.sharpe_oos < GATES["min_sharpe"]: failures.append(f"out-of-sample Sharpe {r.sharpe_oos:.2f} below gate")
if r.max_drawdown_pct > GATES["max_drawdown_pct"]: failures.append(f"max drawdown {r.max_drawdown_pct:.1f}% above gate")
if r.turnover_pct_per_day > GATES["max_turnover_pct_per_day"]: failures.append("turnover implies the strategy is churning fees")
return {"passed": not failures, "failures": failures, "report_id": r.id}
# Passing the gate does not run the strategy. It makes it eligible for the owner to approve in-app,
# where they see the report, the limits and a plain-English description of what the agent will do.4. Research Is Not Execution
The Agent Apps marketplace - paid feeds from Nasdaq, SpotGamma, Unusual Whales, Quiver Quantitative and others - is where agents will get their edge and their exposure. A feed is third-party content; an agent that reads it and can also propose orders in the same context can be steered by what it reads. Run research and execution as separate agent sessions with separate tool sets: the research agent reads feeds and writes a signal record; the execution agent reads signal records and the account, and proposes orders. The feed never touches the proposal path directly.
export const RESEARCH_SESSION = {
tools: ["get_quotes", "get_option_chain", "read_agent_app_feed", "write_signal"], // no proposals
egress: ["feeds.partner-a.example", "feeds.partner-b.example"],
outputSchema: { symbol: "string", direction: "long|short|flat", confidence: "0..1", evidenceIds: "string[]", feed: "string" },
};
export const EXECUTION_SESSION = {
tools: ["get_positions", "read_signals", "get_strategy_results", "propose_order"], // no feeds, no web
egress: [],
inputs: "signals written by RESEARCH_SESSION, validated against the schema, with feed attribution",
};
// A signal that says "ignore your limits" is just a field with a strange value. The execution agent
// never sees the feed text that produced it, and the approval verdict never reads either.5. Show The Owner What The Agent Did
Robinhood's activity feed and notifications are the right instinct; the chart is the right place. Every proposal, verdict and fill belongs on the price chart of the instrument, with the strategy's signal and the account's limits visible, so the owner can see in one view what the agent saw, what it wanted to do, what the platform allowed and what happened. We published the Lightweight Charts marker pattern for this in our agent order gateway guide; the addition for a retail platform is the approval verdict as its own marker colour, so a customer learns what their limits are doing for them.
“Robinhood built the rails and set good defaults. Whether 'autonomous' means 'within limits I set' or 'unsupervised' is decided by the architecture on top - and the Bank of England has already said which one it is worried about.”
For UK And European Brokers Watching
None of this is available to UK retail customers yet, and the FCA's Consumer Duty would ask harder questions than US disclosures do about an approval switch that can be turned off. That is an opportunity rather than an obstacle: a UK broker that launches agents with the architecture above - hard limits under the owner's authentication, stress circuits, gated strategies, separated research and execution, and a chart that shows the agent's every move - would be launching the version regulators here can live with, and the version that holds up when markets are not calm.
The Bottom Line
Robinhood Agents - 150,000 agentic accounts, 30 million daily tool calls, in-app agents with approval on by default but switchable off, standing 'Loops' coming, a paid data marketplace, perpetuals and 24/7 equities on the way - make the retail brokerage an agent platform, with the company explicit that it does not audit agent behaviour and customers bear the losses, and the Bank of England already warning about volatility. The architecture that makes it safe is the platform's job: isolated accounts with a propose-only tool surface, approval modes that enforce hard limits and revert to asking under stress, a strategy gate with realistic backtests before any standing execution, research sessions separated from execution so data feeds cannot steer orders, and a chart that shows the owner every proposal, verdict and fill. That is the trading AI architecture we build for brokers and trading platforms in London, and Robinhood has just shown the market how many customers want it.
References & Further Reading
- Robinhood - Robinhood puts the power of hedge funds in every trader's pocket (HOOD Summit 2026, 30 September). robinhood.com/us/en/newsroom/hood-summit-2026
- Robinhood - Robinhood is now open to agents (27 May 2026). robinhood.com/us/en/newsroom/robinhood-is-now-open-to-agents
- Yahoo Finance - Robinhood unveils in-app AI agents that can trade on customers' behalf. finance.yahoo.com/technology/ai/articles/robinhood-unveils-app-ai-agents-094550758.html
- GuruFocus - Robinhood unveils AI-powered trading agents and 24/7 weekend trading at HOOD Summit 2026. gurufocus.com/news/9103285/robinhood-unveils-aipowered-trading-agents-and-247-weekend-trading-at-hood-summit-2026
- StockBrokers.com - Best brokers for AI trading agents in 2026: MCP tested. stockbrokers.com/guides/ai-agent-brokers
- TradingView - Lightweight Charts: how to add series markers. tradingview.github.io/lightweight-charts/tutorials/how_to/series-markers
- FCA - Consumer Duty. fca.org.uk/firms/consumer-duty
AlchmAI Engineering
Engineering, London
Written by the AlchmAI engineering team in Mayfair, London. We build trading platforms, real-time charts, market data pipelines and AI features for brokers, prop firms and fintech teams. The Playbook is where we explain how we approach these systems, with code you can run and sources you can check.
Code in this guide is illustrative and supplied without warranty. Review and test it before production use. Nothing here is investment advice. Important information