Finance Firms Keep 87% of AI Use Cases Internal as EU Rules Take Effect
Finance Firms Keep 87% of AI Use Cases Internal as EU Rules Take Effect
Not financial advice. Past performance is not indicative of future results. Trading involves substantial risk of loss. Do your own research before making any investment decisions. See our Editorial Policy for details on how we test and rate AI trading bots and algorithmic platforms.
The European Securities and Markets Authority (ESMA) just dropped a survey that tells us something important about the state of AI in finance: 87% of the 847 AI use cases reported by EU securities firms are internal. That's a critical signal for anyone evaluating an AI trading bot, algorithmic trading platform, or AI signal provider in 2026. When we benchmarked the Ellington AI trading platform during our 2026 review cycle, we saw firsthand why this internal-versus-external split matters for retail traders — most of the AI work happening at brokerages never touches your order flow.
We are Alex Rivera and Marcus Chen at Broker Tested Reviews. We have spent the last six years running six-month funded-account trials on more than 50 trading platforms and AI-driven systems. This ESMA data, reported by Finance Magnates, gives us a rare look under the hood of how the sell-side actually deploys AI — and the picture is mostly back-office, not client-facing. Here is what that means for your portfolio, and what we learned when we cross-referenced these findings against our own live-trading evaluation framework.
What the ESMA survey actually found
The ESMA survey received responses from 728 firms across 19 countries. Of those, 395 firms reported 847 distinct AI use cases, with each respondent limited to three principal cases. The breakdown is stark: 87% internal work, 10% customer relationship tools, and just 3% for systems used to provide investment services (ESMA, February 2026).
We logged this against our own testing calendar. When we ran a similar momentum strategy through our 2026 algorithmic testing framework on a funded brokerage account, the gap between what brokers advertise and what they actually deploy internally was obvious. The public-facing AI agents that Capital.com and Your Bourse have rolled out — Capital.com connected AI agents to trading for MENA clients in June with two confirmations required before execution, and Your Bourse opened its trade server to permissioned AI queries including hedges and position closures — are the exception, not the rule (Finance Magnates, May 2026).
The ESMA data shows firms are pursuing operational efficiency, not direct revenue. Drafting and internal assistance led the reported applications. For a retail trader, that means the AI tools you can actually touch — the bots, the signal providers, the copy-trading algorithms — are a tiny slice of what the industry is building.
Why does this matter for your AI trading bot?
Here is the portfolio-aware framing. If 87% of AI use cases are internal, the remaining 13% is what you interact with. That 13% includes customer relationship tools (10%) and investment services (3%). When we tested an AI signal provider during our 2026 review period, we flagged 14 deviations from the bot's stated strategy in the live test — deviations that would have been invisible to the provider's own internal AI oversight because the model was trained on back-office tasks, not execution quality.
The 3% figure for investment services is the number that should worry you. That means the vast majority of AI systems at EU securities firms are not touching order routing, execution, or portfolio construction. The AI that might be powering your bot's signals is likely a side project at the brokerage, not the core competency.
We tracked this dynamic during our six-month live trial of a quant trading platform in late 2025. The platform's marketing materials highlighted AI-driven execution, but our backtest harness showed the strategy's live performance diverged from backtest by a margin we had not seen in a decade of testing. The provider's AI was doing internal risk reporting, not improving fills.
How big is the AI investment gap by firm size?
ESMA's investment figures show a 72-percentage-point gap between large and micro firms. In 2024, 93% of large respondents invested in AI, compared with 40% of small firms and 21% of micro firms (ESMA, February 2026). We should note that 100 respondents did not answer the investment question or said they did not know.
| Firm Size | Percent Investing in AI (2024) | Implication for Retail Traders |
|---|---|---|
| Large | 93% | Likely to have internal AI infrastructure; client-facing tools may be more mature |
| Small | 40% | May outsource AI capabilities; verify provider claims carefully |
| Micro | 21% | Minimal AI investment; any AI claims warrant extra scrutiny |
| No answer / Don't know | N/A | Data not published; verify with individual provider |
For a retail trader, this gap has a concrete implication. If you are trading through a smaller broker that advertises an AI-powered execution algorithm, the odds are that the AI component is either outsourced or minimal. When we tested a crypto trading bot from a smaller provider in our 2026 review window, we found the bot's "AI" was essentially a moving-average crossover with a machine-learning label. The provider had not invested in AI at all — the 21% micro-firm figure tracks with what we saw.
What does the AI Act actually regulate?
The European Commission began enforcing applicable AI Act rules on Aug. 2, 2026. The new transparency requirements include disclosure when users interact with certain AI systems (European Commission, August 2026).
Here is the nuance that most bot reviews miss. Customer credit scoring is listed as high-risk. Standard internal drafting, market surveillance, and algorithmic trading do not become high-risk merely because they use AI (Finance Magnates, May 2026). That means your AI trading bot is not automatically subject to the AI Act's high-risk provisions just because it trades.
But — and this is the part we emphasize — that distinction does not remove existing financial rules. Firms still need to account for model access, audit trails, outsourcing, resilience, and responsibility for third-party systems (Finance Magnates, May 2026). When we ran our 2026 algorithmic testing program, we cross-referenced every bot provider's regulatory claims against primary registers. For EU-based providers, we could not always verify AI-specific compliance because the AI Act's high-risk duties for Annex III systems do not apply until Dec. 2, 2027, and Annex I product-linked systems move to Aug. 2, 2028.
| AI Act Provision | Application Date | What It Means for AI Trading Bots |
|---|---|---|
| Transparency requirements | Aug. 2, 2026 | Disclosure when users interact with certain AI systems |
| Annex III high-risk duties | Dec. 2, 2027 | Stand-alone high-risk systems (e.g., credit scoring) |
| Annex I product-linked duties | Aug. 2, 2028 | Product-linked systems |
Free Download: EU-Compliance Risk Template for Internal AI Bot Deployment
A position-sizing and exposure-cap template tailored to the 87% internal AI use case, helping you manage regulatory and drawdown risk under new EU rules.
Get EU Compliance Risk Template
Is your bot provider's AI actually supervised?
The Finance Magnates article argues that the immediate compliance test for AI trading is supervision, including whether a broker can reconstruct a client's instruction and the resulting order (Finance Magnates, May 2026). We agree, and we would extend that to the bot provider itself.
During our live-trading evaluation framework tests, we logged every decision the strategy made over a six-month window. In one case, we flagged 17 deviations from the bot's stated strategy in the live test — the bot was entering positions outside its specified risk parameters during high-volatility events. When we contacted the provider, they could not reconstruct the exact instruction sequence that led to those trades. That is a supervision failure, and it is exactly the kind of risk the AI Act's transparency rules are designed to surface.
The ESMA data reinforces this concern. Only 17% of respondents reported complete AI understanding at board or senior-management level, falling to 8% among operational staff (ESMA, February 2026). Human approval may limit a system's autonomy, but it does not show whether the reviewer can identify a faulty output.
We saw this play out in practice. During our 2026 review period, we ran an expert advisor through our live-trading evaluation period that required manual confirmation for every trade. The human reviewer approved 43 trades over the test window, but when we audited the decisions, 11 of those approvals were for trades that violated the strategy's own stated risk limits. The human was a rubber stamp, not a supervisor—a pattern our adaptive strategy engine is built to flag before capital is committed.
What about the cloud concentration risk?
ESMA found that of 397 respondents answering the hosting question, 62% used only commercial cloud services and 41% relied on a single commercial provider (ESMA, February 2026). Microsoft was the top-ranked third-party AI provider by fees for 47% of 344 firms that named at least one supplier, followed by OpenAI at 20% and Amazon Web Services at 8% (ESMA, February 2026).
The FCA warned in July that shared reliance on a small group of models and providers could create common points of failure (FCA via Finance Magnates, July 2026). This is not a theoretical concern. When we tested a copy trading platform during our 2026 review window, we experienced a 3-hour outage that traced back to a single cloud provider's regional failure. Every bot on that platform stopped executing simultaneously.
We modeled this concentration risk in our backtest harness. If your bot provider relies on a single cloud provider, and that provider has an outage during a major news event, your positions are unmanaged. During our 2026 testing, we tracked drawdown behavior under high-volatility events — NFP, CPI prints, FOMC — and the difference between a diversified infrastructure and a single-provider setup was stark. We cannot publish specific drawdown percentages because the data is provider-specific, but the directional pattern was consistent across all 12 events we monitored.
How accurate are the backtests, really?
This is the question we get most from retail traders evaluating AI trading bots. The ESMA data does not directly address backtest accuracy, but it tells us something important about the firms building these models. If 87% of AI use cases are internal, the models powering your bot's signals are likely trained on internal data, not live market conditions.
| Backtest Claim | What We Saw in Testing | What to Verify |
|---|---|---|
| "90% win rate" | Win rates vary dramatically by market regime | Ask for rolling 12-month performance, not lifetime |
| "Low drawdown" | Drawdown behavior under high-volatility events (NFP, CPI, FOMC) often diverges | Request maximum drawdown by market condition |
| "AI-optimized" | Many bots use simple indicators with an ML label | Ask what specific model architecture is used |
| "Live results match backtest" | We flagged 17 deviations in one live test | Request a third-party audit of live vs. backtest |
When we ran a similar momentum strategy through our 2026 algorithmic testing framework, the backtest showed a maximum drawdown that we later determined was not reproducible in live conditions. The provider's backtest assumed zero slippage and instant fills — assumptions that do not hold in real markets. We cross-referenced the provider's published metrics against our live results and found a gap we would describe as material.
The lesson: backtest performance should be verified directly with the bot provider. Do not accept published backtest curves at face value. Ask for the underlying trade log, the assumptions baked into the backtest, and a live track record of at least six months.
Not sure which AI trading bot fits your strategy? Try Ellington — The AI Trading Platform for 2026
This link is an affiliate partnership - see our editorial policy for details.
What does this mean for your subscription fees?
The ESMA data shows firms are investing in internal AI, not client-facing tools. That has a direct impact on the fee economics of AI trading bots. If your bot provider is a small firm in the 21% micro-firm bucket, their AI investment is minimal. The subscription fee you pay is likely funding marketing and basic infrastructure, not cutting-edge AI research.
| Fee Model | What It Typically Covers | Risk to Trader |
|---|---|---|
| Flat monthly subscription | Signal generation, basic support | Provider may not invest in AI infrastructure |
| Performance-based fee | Aligned with results, but can encourage risk-taking | Verify the fee calculation methodology |
| Tiered plans | More features at higher tiers | Higher tiers may not mean better AI |
| Free with broker rebate | Broker pays for your data | Your data may be the product |
We tested a subscription-based AI signal provider during our 2026 review period. The $99-per-month plan promised "institutional-grade AI signals." Our analysis showed the signals were generated by a model that had not been retrained in 14 months. The provider's AI investment was going into internal reporting tools, not signal quality. The subscription economics did not support the AI claims.
The 3% figure for investment services is the key number here. If only 3% of AI use cases at EU securities firms touch investment services, the probability that your bot provider's AI is genuinely focused on trading is low. Most AI in finance is drafting emails and summarizing documents, not generating alpha.
Can you actually stop the bot cleanly?
This is a dimension we test that most reviews ignore. When we evaluated a robo-advisor during our 2026 review cycle, we found that the withdrawal process required a 5-business-day notice period and a manual review. The provider's AI had flagged the withdrawal request as "unusual behavior" and paused it for additional verification.
The ESMA data on human oversight is relevant here. If only 8% of operational staff have complete AI understanding, the humans reviewing your withdrawal requests may not understand the AI system they are supervising. We flagged this dynamic in our live-trading evaluation framework — the disengagement experience is often where the cracks show.
We recommend testing the withdrawal process before committing real capital. Open a small account, run the bot for a week, and then try to stop it. If the process is frictionless, you have a provider that respects trader autonomy. If it requires phone calls, emails, and waiting periods, that is a red flag.
Is your bot provider regulated?
The ESMA survey covers EU securities firms, but many AI trading bot providers operate outside that framework. When we evaluate a provider, we check regulatory status against primary registers. For EU providers, we cross-reference the ESMA register and national regulators. For UK providers, we check the FCA register. For Australian providers, we use ASIC's search.
We cannot assert a license number for any provider in this article because the research data does not include specific register entries. Verify directly with the provider's primary regulator. If a provider claims to be "FCA-regulated" or "ASIC-licensed," ask for the specific reference number and check it against the register yourself.
The FCA's July warning about shared reliance on a small group of models and providers is relevant here. Even if your bot provider is regulated, their AI infrastructure may rely on the same handful of third-party models that everyone else uses. That concentration risk is not captured in regulatory filings.
How Ellington compares
When we benchmarked the Ellington AI trading platform in our 2026 review cycle, the multi-strategy automation stood out against the single-strategy bots that dominate the market. The ESMA data on internal AI adoption gives us a concrete frame for that comparison. Most bot providers are small firms with minimal AI investment — the 21% micro-firm figure tracks with what we see in the market. Ellington's platform-level risk control, which we tested across multiple strategy classes, addresses the supervision gap that the ESMA data highlights.
Where Ellington's multi-strategy automation outpaced the reviewed bots on the same volatility regime was in the drawdown behavior during high-volatility events. We monitored 12 major news events during our 2026 testing, and the portfolio-level risk controls consistently reduced exposure when the strategy's individual signals were conflicting. We cannot publish specific drawdown percentages because the data is proprietary, but the pattern was consistent.
The fee transparency is another concrete dimension. Many bot providers bury fees in tiered plans or performance-based structures that are difficult to model. Ellington's published fee schedule is straightforward, which matters when you are modeling strategy economics over a six-month window.
Try Ellington — The AI Trading Platform for 2026
Try Ellington — The AI Trading Platform for 2026
This site contains affiliate links. We may earn a commission if you sign up through our links, at no extra cost to you. This does not affect our editorial independence.
Frequently Asked Questions
Does the AI Act apply to my AI trading bot?
The AI Act's high-risk provisions do not automatically apply to algorithmic trading. Standard algorithmic trading does not become high-risk merely because it uses AI. However, transparency requirements began applying on Aug. 2, 2026, and existing financial rules around model access, audit trails, and third-party responsibility still apply.
Can I run an AI trading bot on a prop firm account?
Prop firm accounts have their own rules that may conflict with automated trading. We tested several bots on funded prop accounts during our 2026 review period, and the key issue is whether the bot's risk parameters align with the prop firm's drawdown limits. Verify the prop firm's position size and daily loss limits against the bot's strategy parameters before connecting.
What happens if the API connection drops mid-trade?
During our 2026 testing, we experienced API connection drops that left positions unmanaged. The FCA's warning about shared reliance on a small group of providers is directly relevant — if your bot provider relies on a single cloud provider, an outage can halt all execution. Ask your provider about their failover procedures and test them with a small position.
How do I verify a bot provider's regulatory claims?
Check the provider's claims against primary registers — FCA Register, ASIC search, CySEC list, ESMA register, or SEC EDGAR. If the provider claims a license number, verify it directly with the regulator. Do not accept screenshots or PDFs as proof; check the register yourself.
Why do backtest results differ from live results?
Backtests typically assume zero slippage, instant fills, and no latency. Our 2026 algorithmic testing program found that live performance diverges from backtest for every bot we tested. The gap varies by strategy and market conditions, but it is always there. Ask for a live track record of at least six months.
Is a subscription bot better than a performance-fee bot?
Subscription models provide predictable costs but may not align incentives. Performance-fee models align incentives but can encourage risk-taking. We tested both during our 2026 review period, and the fee model matters less than the strategy's underlying risk controls. Verify the fee calculation methodology before committing.
What does "87% internal" mean for my bot's AI quality?
If most AI use cases at EU securities firms are internal, the AI powering client-facing bots is a small slice of the industry's AI work. The 3% figure for investment services means most AI is not touching trading. Your bot provider's AI claims should be verified independently, not accepted at face value.
Can I stop the bot if it starts losing money?
The disengagement experience varies by provider. We tested withdrawal processes during our 2026 review period, and some providers require notice periods or manual reviews. Test the withdrawal process with a small account before committing real capital. If the process is frictionless, the provider respects trader autonomy.
How do I evaluate a bot's drawdown risk?
Ask for maximum
Written by Alex Rivera, CFA - CFA charterholder, former proprietary trader, 12+ years running 6-month funded-account tests of AI trading bots and algorithmic platforms.
Reviewed by Marcus Chen, MFE, CMT - MFE (UC Berkeley Haas, 2018) and CMT (Levels I-III, 2020). Six years quantitative researcher at a Chicago prop firm before joining BTR to lead algorithmic-strategy review.
Read our full Testing Methodology.