Public MCP trading makes third-party AI agents a KYA brokerage mandate test
The August 1 KYA signal is that a brokerage MCP endpoint can let a third-party AI agent view account data and place trades on behalf of a user. Once an AI assistant can cross from portfolio conversation into order placement, Know Your Agent needs a reviewable mandate file that ties the customer, agent, account, data export, trade authority, security controls, audit trail, and jurisdiction limits together.
Daily signal: Discord tech-intel channel 1468032405695627386 was readable for the last 24 hours and surfaced AI-agent, model-control, and security-evaluation items, including "Investigating three real-world incidents in our cybersecurity evaluations." Because the Discord lead was not a verified finance source, web fallback and source verification were used. Web search found Public's MCP trading page, Imperva's MCP server security analysis, Circle Agent Stack coverage, MoonPay PayBox authorization coverage, and crypto trading-agent market analysis. These are product, security, and market-structure signals, not formal Know Your Agent adoption by a regulator, exchange, bank, broker-dealer, or payment scheme.
Why this matters for KYA
Public's MCP trading page describes a Model Context Protocol server that lets a user connect a third-party AI agent to a Public brokerage account. Its disclosures say the AI agent may view account data and place trades on the user's behalf, that trades may be executed without direct input on each transaction, and that orders submitted through the MCP server are deemed authorized by the user. The page also says Public supports account analysis, stock research, money movement visibility, automations, and asset classes including US-listed stocks, ETFs, options, crypto, and bonds.
That is a practical KYA threshold. Traditional brokerage controls can identify the customer and account. API controls can authenticate a token. But neither answer the whole agent question: which third-party AI provider processed the account data, what strategy or prompt authorized the trade, whether the mandate allowed options or crypto, how the user changed or revoked permissions, and how a reviewer reconstructs the path from prompt to order.
Imperva's MCP security analysis reinforces the same risk from the infrastructure side. A remote MCP server is an authenticated API endpoint that exposes tools capable of real actions, so it needs endpoint security, bot protection, API controls, prompt and tool-response guardrails, least-privilege scopes, read-only defaults before write access, and complete tool-call logs. For brokerage and crypto execution, those security controls become KYA evidence.
Screenshot-ready KYA compliance comparison table
| KYA dimension | Weak brokerage-agent posture | KYA-ready MCP trading posture | Evidence reviewers should expect |
|---|---|---|---|
| Operator identity | The brokerage knows the customer account, but the third-party AI agent, provider infrastructure, model runtime, and responsible operator are not linked in one record. | The KYA file links customer, brokerage account, AI provider, agent instance, model/runtime, MCP client, API token, and accountable human or business operator. | Customer KYC reference, account ID, agent ID, provider name, model/runtime version, MCP client ID, token owner, control owner, support and escalation path. |
| Agent mandate | The user gives broad natural-language authority such as "rebalance" or "buy if SPY is above a moving average" without enforceable asset, strategy, risk, or approval boundaries. | The mandate defines allowed asset classes, strategy templates, order types, concentration limits, options eligibility, crypto eligibility, human approval thresholds, and stop conditions. | Mandate text, prompt or policy hash, account scope, allowed strategy list, denied action list, risk limits, approval mode, revocation record. |
| Wallet and custody | Cash, crypto, transfer visibility, and trading authority are exposed through the same agent connection, with little separation between data access and capital movement. | Data visibility, order proposal, order placement, cash movement, crypto movement, withdrawals, and custody actions are separately permissioned and logged. | Permission matrix, account and wallet inventory, cash-transfer scope, crypto custody provider, withdrawal block, order-placement scope, settlement and confirmation records. |
| Tool and venue access | The MCP server and brokerage API expose account data, market data, preflight, order placement, order replacement, and cancellation without request-level policy proof. | Every MCP method, API endpoint, asset class, venue, order type, preflight result, replacement, and cancellation is authorized at request level and tied to the mandate. | MCP schema, API endpoint log, preflight response, order ticket, venue or asset-class policy decision, blocked-call log, token scope, third-party provider terms snapshot. |
| Audit trail | Trade confirmations exist, but the prompt, model plan, external data, account context, policy check, MCP call, order preflight, and final order are not stitched together. | The audit trail links prompt, user approval state, model plan, data pulled, policy decision, MCP request, preflight, order placement, confirmation, and post-trade review. | Trace ID, prompt hash, account-data export record, plan record, policy decision, order preflight, order ID, confirmation, cancellation/replacement log, reviewer note. |
| Security and abuse | The system assumes the third-party AI agent will not misuse account data, follow malicious tool output, overtrade, drift beyond the strategy, or expose credentials. | Controls inspect tool responses as untrusted input, rate-limit abnormal order flow, detect prompt injection, constrain OAuth/API scopes, block mandate drift, and alert on account-data exfiltration. | Prompt-injection alert, tool-response scan, API anomaly, overtrading alert, least-privilege token, blocked-action reason, incident response record, user notification. |
| Jurisdiction fit | The agent treats brokerage, crypto, options, bonds, third-party AI processing, and data sharing as one global user preference problem. | The KYA file maps customer eligibility, product eligibility, market jurisdiction, broker-dealer disclosures, crypto provider role, AI-provider data location, and complaint or dispute route. | Jurisdiction matrix, product eligibility check, disclosure receipt, FINRA/SIPC broker-dealer reference, crypto provider reference, data-processing terms, complaint path. |
The compliance lesson
Public's disclosure makes the mandate issue explicit: a third-party AI agent connected through MCP can place trades and those trades are treated as authorized by the user. That may be commercially clear, but compliance teams still need operational evidence that the agent acted within a specific mandate, not merely that the user once connected an AI platform.
This is especially important where the same connection supports account analytics, conditional orders, options, crypto, bonds, and API documentation for read and write access. A KYA-ready control design should avoid a single broad "AI access" permission. It should distinguish view-only analysis, research, draft order creation, preflight, order submission, replacement, cancellation, cash workflows, crypto custody actions, and recurring automation.
Circle Agent Stack and MoonPay PayBox show the adjacent payment side of the same pattern: agent-readable services, x402 payment flows, wallet controls, passkey approvals, autonomous spending within limits, and noncustodial crypto rails. The common control problem is not whether the agent is "smart." It is whether the operator can prove the agent's authority at the moment it touched money, data, or a venue.
Practical KYA checklist
- Create a separate KYA profile for every third-party AI agent or MCP client connected to a brokerage, exchange, wallet, or payment account.
- Separate account-data visibility from trading authority, options authority, crypto authority, cash movement, withdrawal, and recurring automation.
- Require request-level evidence for every MCP method and brokerage API endpoint, including preflight, order placement, replacement, cancellation, and account-data export.
- Bind prompts, model plans, policy checks, API scopes, trade confirmations, and user notifications into one traceable order record.
- Inspect tool responses as untrusted input and monitor for prompt injection, mandate drift, abnormal order flow, credential misuse, and account-data exfiltration.
- State the caveat clearly: Public, Imperva, Circle, MoonPay, and crypto trading-agent coverage are product, security, and market signals, not enacted KYA rules.
Bottom line
Public's MCP trading integration turns third-party AI agents into a brokerage mandate test for Know Your Agent. When a conversational assistant can see account data and place trades, the compliance file needs to identify the operator, bind the mandate, separate capital permissions, govern tool and venue access, preserve a prompt-to-order audit trail, stop abuse, and prove the setup fits the customer's jurisdiction and product eligibility.
Sources reviewed: Discord tech-intel channel 1468032405695627386 for the last 24 hours; Public MCP trading page and brokerage API documentation; Imperva MCP server security analysis; CoinTrust coverage of Circle Agent Stack; CoinInsider coverage of MoonPay PayBox; Crypto Economy analysis of AI trading agents. These are product, security, market-structure, and infrastructure signals, not formal Know Your Agent adoption by a regulator, exchange, bank, broker-dealer, or payment scheme.