The Brief 54
CISO Intelligence Brief
The checkpoint belongs to the model,
not to you.
Three brokers and one IDE shipped inside twenty-four hours. Together they show that the human-approval step everyone is counting on is not a control anyone configured.
Scalable Capital, the Munich broker holding more than €60 billion for over a million clients, became the first bank in Europe to open its platform to external AI assistants. ChatGPT, Claude, Grok, or anything else that speaks Model Context Protocol.
Before the security reflex fires: give Scalable credit. They did this carefully, and the brief is stronger for saying so.
What Scalable Capital actually shipped
Agentic Investing went live yesterday. Clients enable it under Profile > Security, then point an assistant at a public MCP endpoint. There is also a CLI for locally hosted models. From day one the interface carries trading, savings plans, watchlists, price alerts, native search across stocks, ETFs and derivatives, plus news, real-time quotes and historical data.
The control set, from Scalable’s own newsroom:
- Agentic access is off until enabled, and revocable at any time
- Existing account and role permissions apply unchanged
- Login plus two-factor authentication, upfront and at recurring intervals
- Orders and savings plans must be approved before they execute
- Regulatory cost disclosures and key information documents appear before every securities transaction, each with an individual reference that must be confirmed
- Payments are never handled by agents
- Push notifications, trade confirmations and mailbox messages continue as before; every action is reviewable in real time
That is a human in the loop at the moment of consequence. It is more than most enterprises currently have in front of their own agents.
Scalable is also candid about the far side of the boundary: the connected third-party AI applications operate independently and outside Scalable’s control, usage is at the client’s own risk, and outputs are not investment advice. Co-CEO Erik Podzuweit called the launch a first step. Take him at his word.
Approval is optional elsewhere, and inconsistent everywhere
It is already optional. Robinhood Agentic Trading has been live since late May. Their own product disclosure states that a customer can connect a third-party AI agent to a dedicated account to automate investment decisions and order placement, and that orders may be placed by an agent for execution without the customer’s direct input on each transaction. Trading and Banking MCP servers, documented and public. Not a roadmap item — three months in production.
Scalable’s confirmation step is a design choice made by a conservative institution entering a new category. It is not a property of the category.
And where it exists, it varies by model. Coinbase publishes order-creation testing for its own agent interface. Their findings: Claude previews the order and requests confirmation in chat. ChatGPT creates it in one turn. Claude Desktop refuses most orders the Claude web client will create, with Sonnet 4.6 the exception when the instruction carries explicit authorization. Lower-tier models sometimes create orders against the wrong product entirely, buying ETH-USD when the instruction specified ETH-USDC.
Same authorized connection. Same scoped credentials. Same instruction. Different consequence, depending on which model is answering.
Read that as a control statement rather than as a compatibility note. The confirmation behavior being treated across this market as a safety property is, in significant part, a behavior of the model rather than an enforcement of the platform. It varies by vendor, by client, and by tier. Coinbase’s own mitigation advice is telling: isolate a separate funded portfolio to limit blast radius. That is containment, not authorization.
And the model became a variable
On 24 August, Microsoft brought Bring Your Own Model to Visual Studio in Preview. Supported providers are Microsoft Foundry, OpenAI, Anthropic and Ollama, with custom URL support for OpenAI and Ollama. It works whether or not the developer is signed in to GitHub.
It is enabled by default across Community, Professional and Enterprise. The ADMX policy that would let an administrator disable it is described as arriving later, with the 18.10 GA release, alongside centralized model configuration and management.
Microsoft is being honest about the sequencing: the Preview is the developer experience, and enterprise management follows. Read the current state as a CISO rather than as a developer. For this window, a governed development environment can have its model provider changed by the person at the keyboard, to an endpoint nobody approved, with workflow, tooling and repository access entirely unchanged. The control to prevent it does not exist yet.
Why these three belong together
Stack them. If the safety behavior at the tool call is partly a function of which model is answering, and the model can be swapped by the user without a central record, then that safety behavior is not something the organization configured. It is something the organization inherited, from a vendor it did not choose, on a given Tuesday.
Identity does not fail anywhere in this. That is the part that keeps getting missed. Scalable’s client passed 2FA and their permissions are correct. The developer signed into Visual Studio with valid corporate credentials and legitimate repository access. Every credential in every one of these stories is clean.
Four things remain unestablished at the moment the action executes:
- Where the instruction originatedA valid session says who connected. It does not say whether this particular prompt came from the account holder, from a document the assistant read, or from a page it retrieved along the way.
- Which model produced itWhen the provider behind a workflow is swappable and not centrally logged, “the agent did it” is where the audit trail ends rather than where it begins.
- Whether the target is in scopeAccount access is a boundary. The specific instrument, counterparty or repository inside that boundary is not.
- What class of consequence this isReading a portfolio and liquidating a position arrive over the same authorized connection, carrying the same token.
The protocol layer states this about itself plainly. MCP’s Enterprise-Managed Authorization went stable on 18 June. It governs the connection. It explicitly does not authorize individual tool calls. In June that was an architectural footnote; yesterday a licensed bank turned it into a transaction boundary.
Model-layer provenance will not close the gap either. Anthropic has signed the EU AI Act Article 50(2) Code of Practice and marks Claude output at the model level, and its own documentation is careful to say a detected mark is a signal rather than a conclusion, and that marks can be lost through editing or format conversion. That establishes where content came from. It says nothing about whether the action carried authority.
Put these to your team this week
- Which of our systems currently expose, or plan to expose, an MCP server or equivalent tool surface to models we do not operate?
- For each of those, what happens between the authorized connection and the individual tool call? Name the control, and name who owns it — us, the platform, or the model vendor.
- Can we produce, for any single consequential action taken by an agent in the last ninety days, the model and version, the delegation path, the policy version in force, and the controls that were actually active at that moment?
- If the answer to R-03 is reconstruction from logs, how long does it take, and who signs it?
- Where in our development toolchain can a model provider be changed today without an administrative control?
If R-03 takes more than an afternoon, that is the finding. It will not improve on its own: every quarter from here adds tool surfaces, adds providers, and adds swappability.
Authenticated once is not authorized indefinitely. It was never going to be.
Software Armor runs a 20-minute Authority Path Review. We trace one consequential action in your environment from instruction origin to execution, and show you what is provable and what is merely asserted.
No preparation required.
Book the reviewSources
- Scalable Capital newsroom & Agentic Investing product page — 25 Aug 2026
- Reuters, Tom Sims — “German broker Scalable opens investment platform to major AI chatbots,” 25 Aug 2026
- Robinhood newsroom — “Robinhood is Now Open to Agents,” 27 May 2026
- Coinbase Developer Documentation — Coinbase for Agents overview, order-creation testing
- Microsoft Visual Studio Blog, Tanmayee Kamath — Bring Your Own Model, 24 Aug 2026
- Anthropic support documentation — Article 50(2) machine-readable marking
- Model Context Protocol specification — Enterprise-Managed Authorization, stable 18 Jun 2026
The CISO Intelligence Brief is published in NexusRiver on Tuesdays and Thursdays by Eric Yehle. Sentinel Shield and the Authority Path Review are products of Software Armor LLC, O’Fallon, Missouri.
TLP:AMBER — recipients may share this brief within their own organization on a need-to-know basis.