Scalable Capital's new Agentic Investing service makes for a dramatic headline: clients can connect outside AI assistants to a bank account and use natural language to analyse portfolios, create savings plans or place trades. Yet the most consequential part of the design is the point where the conversation stops. Before execution, Scalable requires the client to approve a referenced transaction after receiving the same cost information and product documents used in its own app.
That boundary determines whether an AI assistant is mainly a new interface or an ungoverned portfolio manager. Scalable's launch announcement says its MCP server and command-line interface connect external applications to the broker, while authentication, permissions, trade confirmation and post-trade records remain with Scalable. The arrangement does not remove risk. It relocates the highest-risk moment from model output to client authorisation.
The model stops before the regulated action
The service has four layers. An outside model interprets a request. Scalable's interface exposes permitted account functions and data. The customer reviews a proposed action. Scalable then executes and records the approved order. Treating those layers as one autonomous agent obscures who controls each step.
Scalable says customers can trade, establish savings plans, manage watchlists and set price alerts. They log in with Scalable credentials and complete two-factor authentication initially and at regular intervals. Agentic Investing can be deactivated, and existing account or role permissions continue to apply. Deposits and withdrawals remain available only in the broker's web and mobile applications. That last restriction is a meaningful containment measure: an erroneous trade can change market exposure, but the interface cannot directly send cash to a new external destination.
The external model nevertheless shapes the decision. It can choose what to show, frame alternatives and convert an ambiguous prompt into a proposed instrument, quantity and timing. Scalable states that AI-generated outputs and recommendations come from the third party, not from Scalable, and do not constitute its investment advice. That disclosure clarifies the intended boundary; it cannot by itself ensure that every user understands or behaves according to it.
A confirmation reference turns a prompt into an instruction
Scalable says pre-trade cost information or a Key Information Document is provided before each securities transaction. The information receives an individual reference and must be explicitly confirmed. Customers then receive normal push notifications, trade confirmations and mailbox messages. The reference joins the conversational request to a specific, reviewable order.
This is more than a generic consent button. A natural-language command such as "reduce my risk" is not executable until it becomes defined securities, amounts and order terms. Showing that object to the customer creates a moment for correction and an audit trail. It also helps distinguish model preparation from the client's specific instruction.
The counterargument is behavioural. People routinely approve dense prompts without reading them, and a confident conversational answer can create more momentum than a conventional order ticket. Confirmation may become a rubber stamp. Good design therefore depends on whether the final screen highlights material differences from the user's words, total cost, leverage, concentration and instrument complexity, rather than merely reproducing required documents. Scalable's announcement establishes explicit approval; it does not provide outcome data on how carefully customers use it.
Portfolio data travels before money does
Execution is only half the risk. To produce useful analysis, the outside assistant may receive holdings, watchlists, market data and account context. Scalable's product page warns that third-party AI applications operate independently and that data transmission is at the user's risk. Revocable access and role permissions reduce exposure, but the practical protection depends on scope: which fields are shared, how long tokens live, what the third party retains and whether read access can be separated from trading authority.
Europe's Digital Operational Resilience Act provides an EU framework for ICT risk in financial entities and oversight of designated critical third-party providers. It would be an overreach to infer from the launch alone that every connected assistant falls into that designation. The relevant investor inference is narrower: external interfaces expand the systems and failure modes that a bank must monitor, even when the external model is not the regulated executor.
The strongest operational controls would be visible in permission granularity, short-lived authorisations, comprehensive logs and a fast kill switch. The most useful public metrics would include failed authentication, revoked connections, confirmation mismatches and incidents caused by stale or incomplete account data.
Best execution survives the new interface
Once Scalable receives a client order, the route by which the customer composed it does not erase execution duties. MiFID II requires investment firms to take sufficient steps to obtain the best possible result, considering price, costs, speed, likelihood of execution and settlement, size and nature. A specific client instruction can narrow how that duty applies, but the broker still needs an execution policy, fair handling and records.
ESMA's statement on AI in investment services focuses on firms using AI in their own services. It warns about bias, opaque decisions, overreliance, privacy and security, and says MiFID duties remain relevant. Scalable's architecture appears designed to keep third-party model output outside its advice layer while preserving regulated execution inside. Whether supervisors accept that line in every interaction will depend on actual conduct, integrations and marketing, not only contractual wording.
The incident trail will be the adoption metric
The commercial upside is clear. Scalable can meet clients in the interface they already use while keeping custody and execution on its platform. Natural language may reduce navigation costs and increase engagement without requiring Scalable to build every assistant. The MCP standard also lowers integration cost across model providers.
But trading volume alone would be a poor measure of success. More activity can reflect convenience, overtrading or mistakes. A stronger scorecard would include confirmation-abandonment rates, corrected orders, complaints, reversals where available, security incidents and the share of users who choose read-only access. Evidence that customers catch discrepancies at confirmation and that permissions are routinely limited would strengthen the thesis. Repeated model-to-ticket mismatches, privacy complaints or users treating third-party output as Scalable advice would weaken it.
The product is not an AI that owns the account. It is a controlled conversion from conversation to instruction. Scalable's advantage will depend less on which model sounds smartest than on whether that conversion remains specific, revocable and auditable when real money is at stake.