On 30 June 2026, Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, delivered remarks titled "Agents of change" on a panel at the European Central Bank's Sintra forum. The coverage turned it into an announcement: the Bank of England is weighing a market-wide kill switch against AI-driven market collapse. The words are right. They really do appear in the script. The mood is wrong. And anyone who reads the sentence closely finds a question inside it that is far less comfortable for a trading desk than the headline.
The difference between a proposal and a research question is half the story here. The other half sits in a delegated regulation from 2018.
What: Remarks titled "Agents of change", delivered on a panel at the ECB's Sintra forum and published as a script with 29 footnotes
Who: Sarah Breeden, Deputy Governor for Financial Stability, Bank of England
When: 30 June 2026
Mood: Not an announcement. Ongoing simulation work is to examine whether guardrails are needed at all
Core: At firm level the kill switch has existed since 2018. At market level nothing exists to support one
What Sarah Breeden actually said
The sentence everything turns on reads, in the original: "That work can also explore mitigants: whether markets using AI agents are resilient enough; whether agents' objective functions could incorporate public policy objectives; and whether guardrails are needed, analogous to circuit breakers or kill switches that would limit or stop trading market-wide if faulty AI models cause market meltdown."
Kill switch, circuit breaker and market meltdown are all there, in one sentence, word for word. The press invented none of it. But the sentence opens with "that work can also explore" and poses three questions, the third of which asks whether guardrails are needed at all. This is the conditional of a research agenda, not an announcement with a timetable. "The Bank of England is introducing a kill switch" would be false. "The Bank of England has put a market-wide kill switch on the research agenda" is the story.
The risk she describes is drawn precisely: "If AI agents respond similarly to the same prompts or triggers, they could amplify volatility in stress – especially if their objectives drift from original goals or public policy objectives, in a manifestation of the misalignment problem that can arise with some AI models." No single agent runs amok. Many agents react alike, because they are built alike and see the same thing.
The switch that has been there for eight years
This is where the coverage goes wrong in a way that matters, because it implies a gap that is not there.
The delegated regulation under Article 17 of the Markets in Financial Instruments Directive (MiFID II), known in practice as RTS 6, governs the organisational requirements for algorithmic trading. Its Article 12 is headed Kill functionality. The text: "An investment firm shall be able to cancel immediately, as an emergency measure, any or all of its unexecuted orders submitted to any or all trading venues to which the investment firm is connected."
That has applied since 2018. Every investment firm running algorithms must be able to pull all its open orders at once and across every venue it touches, selectively too, by trader, desk or client. It must be able to say at any moment which algorithm is behind which order, and the compliance function needs direct access to the switch. On top of that come pre-trade price and volume limits and testing of algorithms before they go live.
So anyone asking why there is still no kill switch for AI agents is asking the wrong question. There is one. It just sits with the individual firm and stops that firm's own orders. What Sarah Breeden puts up for debate is a switch that halts trading across the market. That is where the trouble starts.
Why the market level is a different animal
A firm's emergency stop needs three things, all of which a firm has: knowledge of its own orders, the authority to cancel them, and somebody to press the button. A market-wide stop needs the same three across every participant. None of them exists.
There is no authority. Today, nobody may halt trading because of how models are behaving. Venues must calibrate their own volatility interruptions under Article 48 of MiFID II, but those stop at the edge of the venue and bite instrument by instrument.
There is no trigger logic, and that is the harder part. Every interruption in use today fires on price. On Xetra each share has a wide static corridor around the opening price and a narrow dynamic one around the last price established; when the potential execution price leaves the dynamic corridor, a volatility interruption of at least 120 seconds replaces continuous trading. In the United States, the Limit Up-Limit Down mechanism works with bands of five or ten per cent around a rolling five-minute average and pauses for five minutes once a price sits outside the band for 15 seconds. The market-wide circuit breaker on the S&P 500 bites at minus seven, minus 13 and minus 20 per cent.
An AI herding trigger would have to fire on behaviour: on the correlation between decisions, not on the price that follows them. That is not a calibration problem. It is a different measurement. Wait for the price move and you have not prevented the herd, you have merely cushioned its consequence.
One detail from the American example deserves attention. Since its overhaul after the 2010 flash crash, the market-wide circuit breaker has never once fired, not even in March 2020. An instrument that never bites is either well calibrated or useless, and the two are hard to tell apart.
What Sarah Breeden did not say
Two things have slipped in the retelling and need straightening out.
The first is the evidence. Sarah Breeden writes plainly: "In financial markets, evidence suggests that for now, trading firms mostly use autonomous AI for lower-risk operational tasks, such as research. But that could change quickly." Her footnote points to a spotlight review by the FICC Markets Standards Board. Several reports instead credited her with a survey by the Cambridge Centre for Alternative Finance, which put the share of financial firms already running agentic systems at 52 per cent, and spun that into headlines about autonomous AI traders. Neither the number nor the source appears in her script. The number is real, but it measures agentic AI anywhere across the firm, customer service and back office included, rather than autonomous trading agents. The headline inverts what the speaker said.
The second is the jurisdiction. The claim that this speech brings agentic AI into the view of financial stability supervision for the first time does not hold. The Financial Stability Board named AI-driven market correlation as one of four systemic channels back in November 2024, eighteen months before Sintra, and issued a consultation on responsible AI adoption in June 2026. Sarah Breeden herself describes work already under way: "We are experimenting with the BIS Innovation Hub and the Bundesbank on simulation methods to understand which aspects of agent design could drive herding behaviour." The topic is not new. The sharpening into a concrete, market-wide instrument is.
The counter-argument
One objection to a market-wide stop, one that Sarah Breeden does not raise in the script, has been familiar in microstructure research since the flash crash.
A circuit breaker does not prevent a wave of selling. It moves it. Traders who see a threshold approaching sell ahead of it, to get out before the pause. The literature calls this the magnet effect, and it turns a safety device into an accelerant. With an AI kill switch the problem would compound: its trigger would by definition be a pattern that many agents could spot at once. The trigger would itself become a herding signal. A device against correlation that creates correlation is no answer.
And the strongest objection to the whole story comes from the speaker herself: autonomous trading barely happens today. An article that sounds an alarm contradicts its own source. That is exactly what makes the speech worth reading. Financial stability supervision usually describes risks once they have shown up. Here it describes one before it exists, which is rare enough to take seriously.
Recommendations for practice
For trading desks, markets COOs and the control functions beside them, four areas deserve attention.
Now: The switch in RTS 6 Article 12 was designed for classical algorithms: known code, known order source. An AI agent that varies its decisions on reasoned grounds is harder to trace back to a cause when something breaks. The duty to know at any moment which algorithm stands behind which order becomes the real hurdle. Firms meeting it on paper alone will find out when it counts.
In the risk inventory: Herding arises, on Sarah Breeden's account, when agents respond alike to the same signals. In practice the cause is rarely intent. It is shared parentage: the same base model, the same vendor, the same training data. That concentration appears in no standard risk register, and it belongs in one.
Before the next supervisory meeting: Sarah Breeden asks whether agents' objective functions could carry public policy goals. That sounds academic. It is the draft of an examination question. A firm that cannot show in writing what an agent optimises for, and how a drift from that goal would be spotted, has no answer to the most obvious follow-up.
Strategically: Should a market-wide trigger ever arrive, it would hit every participant at once, whether or not your own house caused the problem. The planning question is not whether it comes, but what an unexpected market-wide halt would do to open positions, hedges and liquidity. That is a stress-test scenario, not a regulatory topic.
Keep reading – every two weeks in your inbox.
Capital markets insights, regulatory updates and AI trends. Concise, well-founded, free.
GDPR-compliant. Unsubscribe at any time.