Scalable Capital Lets ChatGPT Execute Trades on European Retail Brokerage Accounts

A trader works on the floor of the New York Stock Exchange during morning trading on August 24, 2026 in New York City.
Heather Diehl/NYSE

Europe’s first ECB-licensed bank crossed a line on Tuesday that no European financial institution had previously crossed: it turned a general-purpose AI chatbot into a live trade executor on a regulated retail brokerage account. Scalable Capital, the Munich-based neobroker managing more than €60 billion (approximately $69.9 billion) for more than one million customers across six European countries, launched “Agentic Investing” — a feature that hands the keys to customer portfolios directly to ChatGPT, Claude, or Grok via the Model Context Protocol (MCP).

The distinction matters: this is not a robo-advisor executing a pre-programmed allocation strategy, and it is not an algorithmic trading system running rules a compliance team approved. It is an external large language model — one that also answers questions about pizza recipes — receiving natural-language instructions and translating them into live buy and sell orders in a regulated financial account. For a reader with a Scalable Capital account, activating Agentic Investing means granting an AI application that operates entirely outside Scalable Capital’s control the technical ability to modify your portfolio.

What ChatGPT Can Now Do With Your Portfolio

The feature set available from launch is substantial. A Scalable Capital customer who connects their account to ChatGPT can instruct it in plain English to execute trades, establish savings plans (Scalable’s equivalent of recurring investment orders), manage watchlists, set price alerts, and conduct searches across stocks, ETFs, and derivatives. Free real-time quotes, historical price data, and curated market news come bundled at no additional cost.

The practical use cases Scalable Capital described in its official launch announcement illustrate just how broad the scope is. A customer might ask their AI to create a personalized daily newsletter based on their holdings, sent every market morning at 7:00 a.m. They could ask it to compare their portfolio against the All-Weather Portfolio published on justETF, or instruct it to calculate the monthly savings rate needed to reach €25,000 (approximately $29,135) in ten years at a 7% annual return — and then automatically prepare the corresponding savings plan for confirmation. Adjusting a pending limit order, exporting transaction histories as CSV files, or generating a fully interactive portfolio dashboard with annotated buy/sell points and a live news ticker are all within scope.

The feature also integrates with “Scalable Insights,” the company’s existing AI analytics layer, giving agents access to portfolio diversification health checks, scenario analyses, sector and geographic breakdowns, and risk assessments.

How MCP Turns a Chatbot Into a Brokerage Terminal

The technical architecture behind Agentic Investing is straightforward in concept and significant in implication. Scalable Capital provides two integration routes: an MCP server for cloud-based AI assistants, and a CLI (command-line interface) application installable directly on a user’s device for privacy-conscious users who prefer to run local AI models.

MCP — the Model Context Protocol — was developed by Anthropic and released publicly in November 2024 as an open standard for connecting AI assistants to external tools, data sources, and systems. Before MCP, connecting an AI model to a business system required custom integration code for every model-system pair. MCP solved this with a single standardized interface — engineers have compared it to USB-C, in that any MCP-compliant AI can talk to any MCP-compliant service without bespoke connector code. OpenAI adopted the standard in March 2025; Google followed in April 2025. In December 2025, Anthropic donated the protocol to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded with OpenAI and Block.

When a Scalable Capital customer connects their account to Claude or ChatGPT via MCP, the AI model gains access to a set of “tools” — standardized function definitions — that map to Scalable’s brokerage API. Asking “Buy 10 shares of Siemens” triggers a tool call; the tool call hits Scalable’s systems; Scalable returns a confirmation request to the user; the user confirms; the trade executes. The MCP server itself runs on Scalable’s infrastructure. The AI model runs on OpenAI’s, Anthropic’s, or xAI’s infrastructure. The two communicate over JSON-RPC 2.0.

Notably, an independent developer had already built an unofficial, read-only MCP connector on top of Scalable Capital’s existing CLI tool earlier this year, allowing users to query portfolios through Claude. That grassroots validation appears to have accelerated the official launch.

What MiFID II Says About an AI Executing Your Orders

The regulatory picture is less tidy than the feature launch. The EU’s Markets in Financial Instruments Directive (MiFID II) defines “algorithmic trading” as trading in financial instruments where a computer algorithm automatically determines individual parameters of orders — and ESMA’s February 2026 supervisory briefing clarified that even where a human intervenes in the trading process, if a computer algorithm determines any individual parameter of an order, that constitutes algorithmic trading.

MiFID II’s algorithmic trading regime — which predates widespread AI use — imposes governance requirements, pre-trade controls, annual self-assessment obligations, and stress-testing frameworks on firms whose systems meet that definition. ESMA’s February briefing explicitly addressed AI: while MiFID II and its implementing regulation RTS 6 do not specifically mention AI, ESMA stated that investment firms using AI in trading workflows must consider AI in self-assessments and align with the EU AI Act (Regulation 2024/1689). The briefing was non-binding but represented a clear statement of supervisory expectations.

Scalable Capital’s legal architecture navigates this carefully. The company’s terms explicitly state that Scalable CLI and MCP serve as technical interfaces to external AI applications; that those applications operate independently and outside Scalable’s control; and that AI-generated outputs do not constitute investment advice from Scalable Capital. Every trade requires explicit user confirmation. Regulatory pre-trade disclosures — ex-ante cost information and Key Information Documents — are served automatically before any securities transaction, each assigned a unique reference that must be individually confirmed.

The practical effect: Scalable Capital has designed a system in which the AI is an execution layer and the human investor is the decision-maker on paper. Whether regulators will accept that framing as AI agents grow more autonomous remains an open question that ESMA’s ongoing monitoring of market and technological developments is specifically designed to answer.

The Security Risk the Launch Materials Do Not Emphasize

There is a documented security vulnerability class specific to MCP-connected AI agents that neither Scalable Capital’s press release nor most coverage of agentic trading addresses: prompt injection.

In an MCP-connected financial account, the AI agent processes not just the user’s instructions but also the outputs of any tool it calls — market data, news feeds, document contents, portfolio summaries. An attacker who can control any text the AI reads can embed adversarial instructions in that text. A news item seeded with hidden instructions, a document containing embedded commands, or a maliciously crafted market data response could in principle cause a connected AI agent to issue trade instructions the user never authorized. Security researchers, including Invariant Labs, HiddenLayer, and the Cloud Security Alliance, have documented this as a structurally novel attack class — one for which there is no direct equivalent in classical brokerage security. The US National Security Agency published MCP security design guidance in May 2026. A peer-reviewed MDPI study identified tool poisoning as the most prevalent and impactful client-side vulnerability in MCP implementations — embedding malicious instructions in tool metadata to manipulate connected AI agents.

Scalable Capital’s architecture reduces but does not eliminate this risk. The mandatory confirmation step for every trade means a successfully injected prompt would still need to produce a confirmation a user accepts. Two-factor authentication creates a barrier at the connection level. But the structural vulnerability is a property of MCP itself, not of Scalable Capital’s implementation specifically.

Veeam’s security research team wrote in February 2026: “In MCP-enabled environments, prompt injection can move beyond incorrect answers and influence real tool usage, which is why approvals, least privilege, and strong auditability matter.”

For users activating Agentic Investing: the risk is real but currently theoretical in the absence of documented attacks. The mitigation is not to avoid the feature but to keep it connected only to trusted AI assistants and to never ask a connected AI agent to process documents or data from unknown sources.

Europe’s Pattern: Scalable Is Not Alone

Scalable Capital called itself the first European bank to offer this capability — and the ECB-licensed bank qualifier is accurate. But the broader European pattern reflects a market in motion. Vienna-based Bitpanda, a crypto and multi-asset broker, launched its own MCP server for Fusion on August 5, 2026, bringing agentic trading to its platform for the first time. Bitpanda’s implementation routes trades through aggregated liquidity from more than twelve global venues; it targets professional traders rather than retail investors and does not hold a full ECB banking license.

In the US market, the pattern is further ahead. Robinhood launched Agentic Trading in May 2026 and by the end of Q2 had attracted nearly 100,000 accounts with more than $100 million in assets under custody. eToro’s Tori AI assistant had executed more than 500,000 trades during its first year and been adopted by more than one-third of its club members. Public.com branded itself “Agentic Brokerage” in March 2026, though its approach uses proprietary AI operating inside the platform rather than external LLMs.

What Podzuweit Called a First Step

Speaking to Reuters, Scalable Capital co-CEO Erik Podzuweit was measured about what Tuesday’s launch represents. “A lot of people might still be hesitant to let ChatGPT look at their portfolio, manage their portfolio,” he acknowledged in a Reuters interview. He described Agentic Investing as a “first step” before deeper in-app AI integration — suggesting the current MCP/external-model architecture is a transitional form, not the end state.

The end state Podzuweit described is an AI layer woven directly into Scalable’s own product, not bolted on via external assistants. That architecture would give Scalable Capital more control over what the AI can and cannot do — and likely more regulatory clarity about where responsibility for AI-generated instructions falls.

For now, the external-model architecture is how they prove the concept. Scalable Capital holds more than €60 billion (approximately $69.9 billion) in assets across Germany, Austria, France, Italy, Spain, and the Netherlands. With over 800 employees across Munich, Berlin, Vienna, and Milan, it operates its own retail-focused stock exchange — the European Investor Exchange — and holds a full banking license from the European Central Bank. The feature is live today for all customers; setup instructions are available at scalable.capital/agentic-investing.

Currency conversions in this article are approximate, based on exchange rates at time of publication and subject to change.

Frequently Asked QuestionsWhat exactly does Scalable Capital’s Agentic Investing let AI do to my account?

Once you activate the feature and authenticate with your Scalable credentials and two-factor verification, a connected AI assistant — ChatGPT, Claude, or Grok — can execute trades, set up savings plans, manage your watchlist, adjust limit orders, set price alerts, and export transaction data, all on your behalf. Every trade and savings plan requires your explicit confirmation before it executes. Deposits and withdrawals remain available only through the web and app, not through AI agents. The AI operates outside Scalable Capital’s control, and any instructions it generates are the investor’s own responsibility.

Is letting an AI execute trades on my account secure, and what is prompt injection?

The short answer is: more secure than it sounds, but not risk-free. Scalable has built layered safeguards — mandatory 2FA, per-trade confirmation, real-time activity monitoring, and a single-toggle kill switch. The structural risk is prompt injection: if you ask a connected AI agent to process external content (a news article, a document, a market feed), maliciously crafted content in that data could in principle embed instructions causing the AI to issue trade orders you never authorized. Security researchers including Invariant Labs and the Cloud Security Alliance have documented this as a property of MCP itself, not of any specific implementation. To minimize exposure: only connect AI assistants from established providers, and do not ask a financially-connected agent to process documents from unknown sources.

How is this different from a robo-advisor?

A robo-advisor runs a purpose-built algorithm inside a financial platform, approved by compliance teams, executing predetermined allocation logic. Agentic Investing connects an external general-purpose large language model — the same AI you use for writing or research — to your live brokerage account via MCP. The AI is not running a pre-approved strategy; it is translating your natural-language instructions into brokerage API calls in real time. The difference matters because the AI’s behavior is probabilistic and context-dependent, not deterministic, and because it operates outside the financial institution’s control in a way a robo-advisor does not.

What does Europe’s financial regulator say about AI-executed trades?

ESMA — the European Securities and Markets Authority — published a supervisory briefing on February 26, 2026 clarifying that where a computer algorithm automatically determines any individual parameter of an order, that constitutes “algorithmic trading” under MiFID II, regardless of human involvement at other stages. The briefing addressed AI in algorithmic trading directly and stated firms must consider AI’s influence in their annual self-assessments. It is non-binding, and regulators have not yet taken enforcement action on AI-agent brokerage accounts specifically — but the supervisory framework is actively developing, and Scalable Capital’s architecture, which assigns liability to the third-party AI provider and the investor rather than to itself, has not yet been stress-tested against that framework.