Algorithmic systems now place a large share of the orders in equities, futures, and foreign exchange markets, and many of those systems adjust their own strategies in response to conditions their designers never explicitly programmed them to expect. When one of those systems produces a trading pattern that looks like manipulation, the law has a hard time answering a question it used to answer easily: who meant to do this?
That question sits at the center of a discussion published by The Regulatory Review on September 6, 2026, in which law professor Gina-Gail S. Fletcher argues that financial regulators should shift trading-misconduct liability away from an intent-based standard and toward a harm-based one.
Her argument holds up well against the case law regulators already have on the books. The more interesting story, in my view, is how much of that shift has already happened quietly, inside decisions courts made for other reasons.
Why "Intent" Breaks Down When a Model Is Trading
Securities fraud law was built around a person at a desk. Someone placed the order, and the law needed to find out what that person knew and meant when they placed it. That framework works fine when a human being is the one deciding to deceive the market.
It works less well when a model is deciding. A trading algorithm trained on historical price data does not "mean" to distort a price. It produces a pattern because the pattern was rewarded during training, or because it fell out of an objective function nobody wrote with that specific pattern in mind. Asking what the model intended is not just hard. It may not be a coherent question at all.
This is not limited to systems built on deep learning. Even simpler rules-based algorithms that adjust order size or timing based on live market signals can produce spoofing-like patterns without any person choosing that specific pattern in advance. The more adaptive the system, the wider the gap grows between the person who approved the strategy and the specific order that ends up looking manipulative.
A harm-based standard sidesteps that problem. Instead of asking what a trader or a system meant, it asks what the trading activity actually did: did it distort a price, create a false impression of supply or demand, or disadvantage other participants who traded against it? Those questions can be answered from trade and price data alone. They do not require reconstructing a state of mind that, in an automated system, may never have existed in the first place.
Intent-Based vs. Harm-Based: A Direct Comparison
The two standards differ in what they ask, what they require regulators to prove, and how well they hold up once the trader is a model rather than a person.
| Dimension | Intent-Based Standard | Harm-Based Standard |
|---|---|---|
| Core question | Did the trader mean to deceive or manipulate the market? | Did the trading activity distort prices or harm other participants? |
| What regulators must prove | A state of mind, often through communications, testimony, or circumstantial inference | A measurable market effect, drawn from trade and price data |
| Fit for algorithmic trading | Weak: an adaptive model has no mind to interrogate in the ordinary sense | Strong: a model's output can be measured regardless of how the model arrived at it |
| Closest existing legal example | Rule 10b-5 fraud claims, which require scienter under Ernst & Ernst v. Hochfelder, 425 U.S. 185 (1976) | Dodd-Frank's spoofing provision, 7 U.S.C. § 6c(a)(5)(C), as applied in United States v. Coscia, 866 F.3d 782 (7th Cir. 2017) |
| Main weakness | Sophisticated actors can structure conduct, or delegate it to a system, so intent stays genuinely unclear | Risks capturing conduct that caused harm without a clearly culpable actor behind it |
The Law Already Half-Believes This
Existing securities law is not starting from zero on this question, and that is the most useful part of the story.
Rule 10b-5 fraud claims under Section 10(b) of the Securities Exchange Act of 1934 have required proof of scienter since the Supreme Court decided Ernst & Ernst v. Hochfelder in 1976. That case held that a private right of action under Rule 10b-5 demands intent to deceive, manipulate, or defraud. Negligence is not enough. Fifty years later, that requirement still governs the core antifraud provision in American securities law.
Now compare that to the anti-spoofing provision Congress added through Section 747 of the Dodd-Frank Act in 2010, codified at 7 U.S.C. § 6c(a)(5)(C). It defines spoofing as bidding or offering with intent to cancel the order before execution. On paper, it still requires proof of intent.
In practice, courts have leaned on something else. In United States v. Coscia, the Seventh Circuit upheld the first criminal conviction under that provision in 2017. The court's evidence was not a confession or an email. It was the structure of the trader's own algorithm, which was built to place large orders and cancel them within milliseconds of entry.
That is a harm-based standard wearing an intent-based label. Once intent gets inferred almost entirely from what an algorithm was built to do and what it actually did in the market, the "state of mind" requirement has already been hollowed out. What is left underneath is close to a simpler question: did this system behave in a way that predictably distorts the market? Fletcher's proposal asks regulators to stop pretending otherwise and build the rule around the standard courts are already applying.
Where the Rulebook Is Still Catching Up
Fletcher also makes a point that anyone who has worked near a trading desk already knows: regulators' technological capabilities tend to lag the markets they oversee. That lag is not a knock on any particular agency. It is what happens when a regulator tries to build shared infrastructure fast enough to track a market that keeps moving underneath it.
The Consolidated Audit Trail is the clearest example. The SEC adopted Rule 613 in July 2012 to create it, and approved the CAT NMS Plan governing its build-out in November 2016. National securities exchanges and large broker-dealers began reporting order and trade data starting in 2019 and 2020.
The smallest broker-dealers, who together handle a meaningful share of order flow, did not begin reporting until 2022, a full decade after Rule 613 was adopted. That is not a system that came online quickly, and it is worth remembering the next time someone assumes regulators can already see everything the market is doing in real time.
The SEC also adopted Regulation Systems Compliance and Integrity, known as Reg SCI, in November 2014, codified at 17 CFR 242.1000 through 1007. It requires exchanges, clearing agencies, and other significant market participants to maintain adequate capacity, integrity, and security in their technology systems. Reg SCI is a genuine answer to technological risk, but it is aimed at system stability, not at the harder question underneath Fletcher's argument: how to assign liability when an algorithm's behavior looks like manipulation and no person typed the specific order.
There is an older rule that gets less attention but fits this pattern well. The SEC's Market Access Rule, Rule 15c3-5 under the Exchange Act, adopted in 2010 and codified at 17 CFR 240.15c3-5, already requires broker-dealers with market access to maintain risk management controls reasonably designed to prevent the entry of erroneous orders before those orders reach an exchange. That is harm-prevention logic, not intent-based liability. It is proof that regulators already know how to write rules that do not depend on proving what anyone meant.
A harm-based standard does not close the technology gap by itself. What it does is lower the bar for what regulators need to prove once they can see a harmful pattern, which matters a great deal while the tools for tracing that pattern back to its origin are still catching up.
The Same Gap Shows Up Outside Finance
Trading algorithms are an early, well-documented case of a broader problem: what happens to accountability once decisions that used to require a person now come out of a system trained on data rather than instructed by a rule. Hiring algorithms, content-moderation systems, and credit-underwriting models all raise a version of the same question courts have been quietly answering in spoofing cases. Can you hold a system accountable for what it does, even when nobody can point to the moment a person decided to do it?
That question also runs through why financial regulators move slowly on questions like this one in the first place. Agencies that oversee an industry often depend on that industry for the technical expertise needed to write workable rules, which creates a structural pull toward the industry's preferred framing of the problem. I have written before about how regulatory capture shapes AI governance more broadly, and the dynamic Fletcher describes in market regulation is a specific, well-documented instance of it: the people best positioned to explain how a trading algorithm works are often employed by the firms whose algorithms are under review.
What This Means for Trading Desks and Compliance Teams
If your firm builds, deploys, or oversees algorithmic trading systems, this is not an abstract legal debate. It changes what a defensible compliance program looks like.
Under an intent-based regime, a firm's strongest defense has usually been documentation: show that the algorithm was built for a legitimate purpose, that the strategy went through review, and that nobody meant harm. That documentation still matters under a harm-based regime, but it stops being sufficient on its own. The question shifts to what the system actually did in the market and whether the firm had controls in place to catch harmful patterns, regardless of what the design documents said the system was supposed to do.
The European Union is already operating on this logic. The Markets in Financial Instruments Directive II, effective January 3, 2018, requires under Article 17 that investment firms engaged in algorithmic trading maintain effective systems and risk controls. Firms must be able to cancel unexecuted orders, halt trading during unusual conditions, and prevent orders that could contribute to a disorderly market. None of that depends on what the firm intended. It depends on whether the firm had the operational capacity to prevent harm before it happened.
For a US firm watching this direction, the compliance investment worth making now falls into three categories:
- Real-time surveillance of what algorithms are actually doing in live markets, not just periodic review of what they were designed to do.
- Kill switches that can be triggered on an observed pattern, rather than waiting for confirmed proof of intent behind that pattern.
- Independent review processes that treat an algorithm's live behavior as evidence in its own right, separate from what the design documentation claims the algorithm was built to do.
A model can behave exactly as designed and still cause the kind of market harm a harm-based standard is built to catch. Firms that can only defend their intent are defending against yesterday's question.
There is a related shift worth naming directly. The compliance conversation around algorithmic trading has centered for years on explainability, on whether a firm can show a regulator why a model did what it did. That capability still matters.
But a harder question is coming to matter more: can the firm show it would have caught the harm even without a full explanation of the model's reasoning? Those are different capabilities, and firms that built only the first one have more work ahead than they may realize. That point runs through what I have argued about oversight built on proof rather than explanation in AI systems generally: showing your work is not the same as showing you would have caught the problem.
The Harder Question Underneath
Something uncomfortable sits under this whole debate, and picking harm over intent does not resolve it. If liability no longer requires a mind behind the conduct, who exactly is being held responsible, and what is the punishment actually deterring? A fine changes a firm's incentives, but intent-based fraud law was never only about deterrence. It was also about drawing a line between an accident and a wrong, and that line depends on being able to locate a wrongdoer.
Harm-based standards are honest about something algorithmic markets have made genuinely hard: finding a clear wrongdoer standing behind the wrongful act. Fletcher's proposal does not pretend that problem away. It refuses to let the difficulty of the question become an excuse for letting harmful conduct go unaddressed just because nobody can prove what a model, in any meaningful sense, intended.
I do not think that discomfort is a reason to keep the intent standard on life support. It is a reason to be honest about what a fine against a firm can and cannot do. It can change what the firm builds next quarter. It cannot tell us whether anyone actually did wrong, and pretending an intent standard still answers that question, once intent is inferred almost entirely from code, is not more honest. It is just slower to admit the same thing.
Where this goes next depends less on the strength of the legal argument, which is solid, and more on whether agencies can build the technical capacity to make a harm-based standard workable in practice. Writing the rule is the easy part. Building the surveillance infrastructure to apply it consistently is the harder project, and it is the one worth watching.
Frequently Asked Questions
What is a harm-based standard for trading misconduct? A harm-based standard asks whether trading activity actually distorted prices, created a false impression of supply or demand, or disadvantaged other market participants, regardless of what the trader or the system behind the trade meant to do. It replaces the question of intent with the question of measurable market effect.
Has a US court already inferred intent from an algorithm's design rather than direct evidence? Yes. In United States v. Coscia, 866 F.3d 782 (7th Cir. 2017), the Seventh Circuit upheld a criminal spoofing conviction under 7 U.S.C. § 6c(a)(5)(C) based largely on the structure of the trader's algorithm, which was built to place large orders and cancel them within milliseconds. The court treated the design of the system as evidence of the intent behind it.
Is the SEC likely to formally adopt a harm-based standard soon? There is no pending SEC rulemaking that formally replaces intent with harm as the liability standard for trading misconduct. Fletcher's argument is a proposal for how regulators and courts should approach the problem, not a description of an adopted rule. The Coscia precedent shows the logic already operating inside intent-based law, which is a different thing from Congress or the SEC writing a new standard into the books.
How does the EU's approach under MiFID II differ from the current US framework? MiFID II's Article 17, in effect since January 3, 2018, already requires EU investment firms engaged in algorithmic trading to maintain risk controls, including the ability to halt trading and cancel orders, regardless of intent. US securities and commodities law still centers liability for fraud and manipulation on proof of intent, even where courts have effectively inferred that intent from system design.
What should a compliance team building AI trading systems do now, regardless of how the legal standard evolves? Build the capacity to monitor what trading algorithms actually do in live markets, not just what they were designed to do, and build kill switches that trigger on observed harmful patterns rather than waiting for proof of intent. That investment holds up under either standard, because it addresses the underlying problem: a firm's own documentation of intent is no longer sufficient evidence that its system is behaving safely.
Last updated: 2026-09-26
Jared Clark
Founder, Prepare for AI
Jared Clark is the founder of Prepare for AI, a thought leadership platform exploring how AI transforms institutions, work, and society.