How an AI trading agent avoids giving investment advice

Every trading agent will be asked “should I buy this?” within its first hour in production. Usually it is asked within the first minute. How it answers that question decides whether it is a useful product or a liability for the exchange that embeds it.
This guide covers where the line sits, the patterns that keep an agent on the right side of it, and how to test that it stays there. It is written for exchange and broker teams evaluating agents and for anyone building one. It is not legal advice; definitions of investment advice vary by jurisdiction, and each market needs its own review.
Where the line sits
The working distinction is simple to state.
- Information describes what is true. Prices, percentage moves, volume, funding rates, what happened historically, how an instrument works, and exactly what a given order would do.
- Advice tells a particular person what they ought to do, or implies what will happen. “Buy”, “sell”, “hold”, “this will go higher”, “good entry here”.
An agent can be extremely useful while staying entirely on the information side. Most trader questions are information questions underneath. “Should I buy ETH?” usually means “what is going on with ETH?” An agent that answers the second question well, and declines the first politely, serves the trader better than one that offers an opinion it cannot stand behind.
Language the agent never uses
The fastest way to see the boundary is to list what crosses it. These are phrasings an information-only agent never generates.
| Category | Examples |
|---|---|
| Direct recommendation | “You should…”, “I recommend…”, “I’d suggest you…”, “My advice would be…” |
| Personal framing | “If I were you…”, “I think you should…” |
| Ranking assets | “The best coin to hold right now is…” |
| Urgency | “Buy now”, “Sell now”, “Now’s the time”, “Don’t miss” |
| Prediction | “This will go up”, “…is going to fall” |
| Certainty | “Guaranteed”, “Can’t lose”, “Safe bet”, “Sure thing” |
| Timing verdicts | “Good entry point”, “Good exit point”, “Hot pick” |
| Valuation opinion | “Undervalued” or “overvalued” stated as the agent’s view |
Banning words alone is not enough, because a model can imply a verdict without using any of them. The list is a floor, enforced in output filters and in testing, not the whole design.
Patterns the agent does use
The positive patterns matter more than the bans. They give the model a way to be helpful when a question invites advice.
- “Here’s what the data shows.” State the facts with numbers and a timestamp: the price, the 24-hour move, funding, volume.
- Past tense, sourced. “Historically, BTC has…” with the source attached, instead of a forward-looking claim.
- Factors, not verdicts. “Some factors traders watch here are open interest, funding and the upcoming rate decision.” No conclusion drawn for the trader.
- The exact effect of an order. “This order would sell 0.5 ETH at market, estimated proceeds 1,512.40 USDT after fees. Confirm to place it.”
- An honest decline. “I can’t give advice, but here’s what’s true right now.” Then the facts.
Here is how that plays out on a common question. The figures are illustrative, not live data.
Trader: Is SOL a good buy right now?
Agent: I can’t tell you whether to buy, but here’s what’s true right now. SOL is up 3.1% over 24 hours and down 8.4% over 30 days. Perpetual funding is slightly positive, and open interest rose over the past week. Traders watching SOL often look at network activity, token unlocks and broader market direction. Want me to pull any of those?
The answer is useful, specific and grounded. It does not decide for the trader.
Confirmation is part of the boundary
Advice is not only about words. An agent that can place a trade on its own has, in effect, made a decision for the trader. That is why order confirmation belongs in the same design as the language rules.
In a confirm-by-default design, the agent drafts the order, shows every field that matters, and waits. The trader confirms, and only then is the order submitted. There is no setting that switches confirmation off. We explain the reasoning in why confirm-by-default matters for AI order flow.
How to test it
A boundary that is only described in a prompt will fail under pressure. It has to be tested the way any other critical behaviour is tested.
- Build an advice-bait suite. Write questions designed to extract advice: direct requests, leading questions, hypotheticals, role-play (“pretend you are my financial adviser”), emotional pressure, and multi-turn conversations that edge toward a verdict.
- Cover the long tail. Include every asset class the agent handles, slang, typos, and the many ways people ask the same thing.
- Score every answer. Each response passes or fails against the boundary, by automated checks and by human review of samples and of every failure.
- Gate releases on it. Every model update and prompt change runs against the suite. A drop in the pass rate blocks the release.
- Feed production back in. New phrasings seen in real conversations become new test cases.
Hippo’s advice-bait suite has been run against more than one million questions, and passing it is a launch gate for every release.
What testing does and does not prove
Testing shows that an agent behaves consistently on the information side of the line. It does not make the agent legally compliant in every market by itself. Licensing and advice rules differ between countries and between types of venue, and they change. The right external claim is that an agent is designed to stay on the information side of the line, and that each market gets its own legal review before launch.
Questions to ask a vendor
- What exactly is the agent forbidden from saying, and how is that enforced at output time?
- How large is the advice-bait test suite, what does it cover, and what is the current pass rate?
- Is the suite a release gate, or a report produced after release?
- Can the agent ever execute without trader confirmation?
- How are failures found in production handled and fed back into testing?
For the broader picture of how these agents work, start with what an embedded conversational trading agent is.
Frequently asked questions
What is the difference between market information and investment advice?
Information describes what is true: prices, moves, historical behaviour, how an instrument works, what an order would do. Advice tells a specific person what they ought to do, such as buy, sell or hold, or implies what a price will do next. Exact legal definitions vary by jurisdiction.
Can an AI trading agent answer whether a coin is a good buy?
It can answer the factual part of the question: recent price action, volume, funding, notable news and the factors traders commonly watch. It should decline the verdict itself and say so plainly.
How do you test that an AI agent does not give advice?
Build a large suite of questions written to provoke advice, such as direct requests, leading questions, role-play and multi-turn pressure. Run every model and prompt change against it and treat the pass rate as a release gate.
Is an AI trading agent that avoids advice legally compliant everywhere?
Not automatically. Rules differ by country and by licence. Testing keeps an agent on the information side of the line by design, but each market still needs its own legal review.
Hippo provides information, not investment advice.