Since 25 August 2026, customers of Scalable Capital have been able to connect their brokerage account to ChatGPT, Claude or Grok. According to the Munich bank's press release, access runs through two interfaces: a server built on the Model Context Protocol (MCP), the open standard through which language models call tools and data, and an open-source command-line application, the Scalable CLI. Once connected, the model may read account information, prepare orders, set up savings plans and price alerts; deposits and withdrawals, the same release says, remain reserved for web and app. On that basis Scalable calls itself the first bank in Europe to open its platform to all major AI assistants.

Public debate has since concentrated on two questions: whether the portfolio data end up with OpenAI, and whether the model confuses euros with percentages. Both are fair, and both skip the question that matters to compliance and operations: who is giving investment advice when a model the customer has connected derives a buy recommendation from that customer's portfolio data, and Scalable then executes the order? Scalable's answer is in the press release: nobody, or at any rate not Scalable. The statement holds as a matter of supervisory law, which is why it has consequences. The advisory step sits outside the perimeter, the execution step stays inside, and the threshold between the two has become a parameter in Scalable's own interface: the official CLI carries a flag called --accept-unsuitable, with which the statutory warning ahead of an inappropriate order is acknowledged by machine.

What follows alleges no breach of law, by Scalable, OpenAI, Anthropic or xAI. It describes where supervision ends under current law, what the bank keeps and what it hands over. Whether a language model's recommendation amounts to investment advice requiring authorisation had been decided by no court and no authority at the time of writing on 4 September 2026; the question stays open here and is named as open. Where a statement is my own reading rather than a citation, the text says so at that point.

In brief

What: Scalable Capital's “Agentic Investing”, live since 25 August 2026: brokerage account access for ChatGPT (OpenAI), Claude (Anthropic) and Grok through a cloud MCP server and an open-source CLI (Apache 2.0 licence) on the customer's own machine

Who: Scalable Capital Bank GmbH, Munich; by its own account a CRR credit institution licensed by the ECB since 10 September 2025 and supervised by BaFin and the Bundesbank, with more than one million customers and more than €60bn on the platform

For whom: retail customers who switch the feature on themselves (profile, security, Agentic Investing), with two-factor authentication when connecting and at regular intervals; every order is released with pre-trade information, a reference and explicit confirmation

Legal basis: section 63 (10) WpHG (appropriateness test) and section 63 (11) WpHG (execution-only, “at the initiative of the client”), Art. 25 (3) and (4) MiFID II with recital 85; not section 64 (3) WpHG (suitability), because Scalable gives no investment advice

Status: no statement from BaFin or ESMA on the case by 4 September 2026; in the Mills Review from 6 July 2026 the FCA recommended a review of the regulatory perimeter for general-purpose language models within three to six months

The agent on the account has predecessors, the banking licence behind it does not

The claim to be the first bank in Europe is narrowly built, and within that narrowness it holds. Robinhood, according to its own newsroom, launched Agentic Trading in beta on 27 May 2026, initially for stocks only, with its own MCP servers and a dedicated account. Public.com, according to its own MCP page, runs a server with order execution for ChatGPT, Claude and Perplexity; the Mills Review by the UK Financial Conduct Authority (FCA) names both US brokers on 6 July 2026 as examples of customers connecting their own agents. Bitpanda, according to the FAZ, has offered a key-based connection for Claude and ChatGPT since early August, but it is not a bank: it is a crypto-asset service provider authorised by Austria's Financial Market Authority under the Markets in Crypto-Assets Regulation (MiCA). Scalable, by contrast, has according to its newsroom been a credit institution licensed by the European Central Bank since 10 September 2025; the first anniversary of that licence fell six days before this text appeared.

1 of 4 PROVIDERS IS A BANK Brokerage account access for third-party AI agents, May to August 2026 BANK · ECB LICENCE BROKER, CRYPTO PLATFORM DATE ONLY APPROXIMATE MAY JUN JUL AUG SEP 2026 ROBINHOOD 27 May Broker-dealer, US PUBLIC.COM before 6 July Broker-dealer, US BITPANDA early August MiCA CASP, AT · not a bank SCALABLE CAPITAL 25 August CRR credit institution, DE
Four providers opened the brokerage account to third-party AI agents between 27 May and 25 August 2026: Robinhood and Public.com (broker-dealers, US), Bitpanda (crypto-asset service provider with MiCA authorisation, Austria) and Scalable Capital, the only ECB-licensed credit institution among them. Public.com's date is documented only as an upper bound, Bitpanda's only as "early August". Sources: Robinhood newsroom, 27 May 2026; FCA, The Mills Review, 6 July 2026, p. 36; FAZ, 25 August 2026; Scalable Capital newsroom, 25 August 2026; as of 4 September 2026.

So the act of a customer handing a language model the key to the brokerage account has predecessors: in the US since May, in Vienna since August. What has none is access under a banking licence, and therefore under the second Markets in Financial Instruments Directive (MiFID II), a regime in which the execution side carries duties of its own. Erik Podzuweit, founder and co-CEO, told Reuters the move was “a first step”; many people, he said, would still hesitate to let ChatGPT look at their portfolio. Alexander Seipp, Chief Product Officer, told Fortune there is no partnership with OpenAI or Anthropic: “This is really a standalone offering”. The first sentence concedes the uncertainty; the second settles the question of whose name the model speaks in: nobody's.

Execution stays inside, with every duty intact

Anyone hoping to accuse Scalable of sidestepping supervision will find little in the documents. The press release describes the same sequence for every order as in web and app: pre-trade cost information or the key information document comes first, and “This pre-trade information is assigned an individual reference and must be explicitly confirmed”. The CLI README describes the two-step structure as a design principle, “Buy and sell flows are intentionally two-step”. Payments are excluded. On the execution side, an order placed through an agent is therefore an order like any other.

That is the strongest version of Scalable's position, and it is correct. The bank has given up no duty on the execution side; it has opened a further input channel, much as the app once arrived alongside the browser. What the sequence does not do is say anything about where the proposal the customer confirms came from. The bank executes what the customer releases. What the customer releases, someone else proposed.

The appropriateness warning has become a parameter

German securities law knows two tests for the retail client, and public discussion usually names the wrong one. The suitability test under section 64 (3) of the Securities Trading Act (WpHG) asks about knowledge, financial circumstances and investment objectives and applies only to investment advice and portfolio management; Scalable, on its own account, provides neither. For every other service, section 63 (10) WpHG requires the appropriateness test: the firm gathers the client's knowledge and experience and, if it considers the requested instrument inappropriate for that client, must issue a warning under sentence 3, in standardised form if it wishes under sentence 6. Section 63 (11) WpHG exempts execution-only business: for non-complex instruments such as listed shares the test falls away, provided the transaction is carried out “at the initiative of the client”.

Now the README. For the purchase of an instrument Scalable classifies as inappropriate for the customer, the README states: “If phase 1 explicitly requires unsuitable acknowledgement for the buy order, --accept-unsuitable confirms that you are aware of the risks and still want to proceed.” The flag says “unsuitable”, the language of the suitability test; legally it acknowledges the warning under section 63 (10) sentence 3 WpHG. The misnomer is forgivable; the mechanism is what carries weight: the standardised warning the legislator placed as the last hurdle before buying a certificate or a warrant is a command-line argument that a language model can set. On the safeguards the customer can configure, permitted and blocked security identifiers, a maximum amount per order, the README adds: “These controls are enforced locally by the CLI only. They do not change your account permissions or backend trading permissions.” Whether the MCP server carries the same acknowledgement cannot be checked without a customer login.

Why does Scalable's construction hold nonetheless? The answer sits in recital 85 of MiFID II, and it describes the gap at the same time. According to the recital, a service is to be treated as provided at the client's initiative unless the client demands it in response to a personalised communication from or on behalf of the firm that invites or is intended to influence the client to buy a specific financial instrument. A language model the customer has connected is neither the investment firm nor its agent. The order therefore remains at the client's initiative and the execution-only exemption applies; that is my reading, not a finding by any authority. It does show what the construction rests on: the personalised invitation to buy, against which the recital was meant to protect the client, now comes from a third party outside the perimeter, built on the portfolio data Scalable hands out through the MCP server.

The recommendation meets the definition of advice, only the provider is missing

Under section 2 (8) no. 10 WpHG, investment advice is the giving of personal recommendations on transactions in specific financial instruments, provided the recommendation rests on a review of the investor's personal circumstances or is presented as suitable for that investor. BaFin's guidance note on investment advice, in its February 2025 version, draws the line to mere information as follows: a recommendation is absent where the provider merely explains the client's existing holdings without making “konkrete Vorschläge zur Änderung der Zusammensetzung dieses Vermögens”, concrete proposals to change the composition of those assets. According to the same note it is enough that the provider attributably creates the appearance of having taken the investor's personal circumstances into account. A model that reads the entire portfolio and proposes a reallocation meets every one of those elements.

What the guidance note does not say is who the provider is in that case. It knows firms and people; a language model appears nowhere in it, nor does the question whether an agent acting in the customer's name is that customer's “representative” within the definition. The model vendors have answered in their own rules, just not for this case. According to OpenAI's usage policies from 29 October 2025, the company prohibits the “automation of high-stakes decisions in sensitive areas without human review”, explicitly including financial activities. Anthropic's usage policy from 15 September 2025, according to its published text, lists investment advice as a high-risk use case and requires that “a qualified professional in that field must review the content or decision prior to dissemination or finalization”; the clause is aimed at the developer who builds Claude into a product, not at a customer running a private connector. Scalable's confirmation step meets the letter of both policies and misses their purpose, on my reading: the human doing the reviewing is the customer.

Anyone looking for case law finds silence. Urs Böckelmann, a lawyer at drrp, told Cash. in an interview published on 16 June 2026 that no court decisions or judicial guidance on the use of AI in financial distribution were yet known to the firm, and that final responsibility remained with the intermediary or adviser. He was speaking about advisers who use AI as a tool. In Scalable's case there is no adviser. The final responsibility Urs Böckelmann has in mind lands on nobody here.

The liability formula comes from the US, the testing regime does not

Scalable's disclaimer was not invented in Munich. Robinhood wrote on 27 May 2026: “Robinhood does not control, supervise, monitor, recommend, or audit these AI agents.” Public.com uses the identical formula, word for word, on its MCP page. Scalable's English product page condenses it: “Scalable does not review or monitor your AI agent and does not provide investment advice. Your AI agent's responses and actions are subject exclusively to the terms of the respective provider. You bear the risks of investing.” The formula comes from US self-directed brokerage, where the suitability obligation attaches to a broker's recommendation and pure execution business knows no appropriateness test. It has been carried into a regime that prescribes that test on the execution side.

How far such a disclaimer reaches, Germany's Federal Court of Justice has already decided for the analogous case, on 19 March 2013 under case number XI ZR 431/11: a direct bank offered execution-only, and a third party, the Accessio Wertpapierhandelshaus, had given the advice. According to the first headnote, no implied advisory contract arises with a bank that expressly offers execution-only alone, and advisory errors by a third party the investor engaged are as a rule not attributed to the bank under section 278 of the Civil Code. The second headnote states the limit: a liability-backed duty to warn may nonetheless exist as an ancillary duty of the execution-only service, in the court's wording, “wenn die kundenfernere Direktbank die tatsächliche Fehlberatung des Kunden bei dem in Auftrag gegebenen Wertpapiergeschäft entweder positiv kennt oder wenn diese Fehlberatung aufgrund massiver Verdachtsmomente objektiv evident ist”, that is, where the more distant direct bank either positively knows of the client's actual mis-advice or that mis-advice is objectively evident from strong indications. Under the third headnote the investor bears the burden of proof.

The analogy suggests itself: Scalable is the direct bank, the model is the advising third party, and the disclaimer on the product page mirrors the first headnote almost verbatim. The analogy has a fault line. The third party in 2013 was an authorised investment services firm; the headnote speaks of the staggered involvement of several such firms. A language model is none, and no court has decided whether the duty to warn narrows or widens when the third party is not regulated at all. What is certain is only the direction of the incentives: a duty to warn that turns on knowledge or evidence does not, for now, touch a bank that declares it does not look. Whether it stays that way is the open question of this article.

PSD2 settled the same scenario for payment accounts, with a licence and mandatory liability

The practice of third parties reaching into a customer's account with the customer's consent and triggering instructions there has been regulated in European financial law for years, just not for securities accounts. The second Payment Services Directive (PSD2, Directive (EU) 2015/2366) fitted third-party access to payment accounts with three components, all of which the MCP account access lacks. First, the licence category: whoever retrieves account data or initiates payments needs authorisation as an account information or payment initiation service provider, in Germany under section 1 (1) sentence 2 nos. 7 and 8 of the Payment Services Supervision Act (ZAG). Second, the interface, which the institution provides and whose users it knows. Third, mandatory liability: under Art. 73 PSD2 the institution refunds an unauthorised payment transaction without any inquiry into fault; under Art. 74 the customer bears the loss only in cases of gross negligence or intent.

The MCP account access has the interface and the consent. The licence category is missing, because OpenAI, Anthropic and xAI are not investment services firms; the mandatory liability is missing, because access runs through the three providers' consumer contracts, whose terms Scalable's notice declares to be the governing ones. Bitpanda, with its key and permission levels, sits closer to the PSD2 logic than Scalable with OAuth, two-factor authentication and per-order confirmation, yet it is there that co-founder Christian Trummer, in the FAZ, puts the construction more honestly than any disclaimer: “Das können wir technisch gar nicht kontrollieren, was der Agent macht und was die Anweisungen im Prompt waren.” Technically, he says, they cannot control what the agent does or what the prompt instructed.

The industry answered this question once before, about a decade ago, with the opposite answer. The robo-advisers of the past decade, Scalable itself began as one of them in 2014, were the authorised investment firms. According to BaFin's consumer page, robo-advice can legally take the form of investment advice, portfolio management, contract brokerage or investment brokerage, in every case an activity requiring authorisation. The robot of 2014 was licensed. The robots of 2026 are not, and Scalable hands them the key. The Financial Data Access Regulation (FiDA), whose trilogue was still open according to a non-paper from 6 April 2026, would create a licence category for securities data, as described elsewhere; it regulates data access, not the recommendation.

Supervisors are not asleep: they have set themselves a date

Neither BaFin nor ESMA had issued a statement on Scalable's opening by 4 September 2026; the search covered both authorities' press pages and the bank's newsroom. What does exist points elsewhere. ESMA's statement from 30 May 2024 holds that firms' decisions remain the responsibility of their management bodies, “irrespective of whether those decisions are taken by people or AI-based tools”; it has in mind firms' staff using ChatGPT, not their customers. BaFin, in its Risks in Focus 2026, names a “growing risk of homogeneous investment behaviour based on identical or similar recommendations from the models” and says it already supervises AI systems under existing law; market surveillance under the German AI Market Surveillance Act has applied since 29 July 2026, as described here.

London has gone furthest. On 6 July 2026 the FCA published the Mills Review, 147 pages, led by its Executive Director Sheldon Mills at the request of the FCA Board, which makes it the regulator questioning itself rather than an external review. The review reports that around 26% of UK adults trust general-purpose tools such as ChatGPT, Claude or Gemini for financial advice, “despite limited awareness that formal routes to recourse will not apply”, and that one in five is already open to AI making decisions for them. The review frames this as a competition problem: regulated firms face conduct rules while platforms and model providers exert similar influence without equivalent obligations, an “uneven playing field”.

For regulators, this blurs the perimeter. Under an activity-based approach, general-purpose tools could shape financial decisions and competition without clear oversight. Whether this influence falls inside or outside the perimeter will shape how competition and consumer protection work in practice. Sheldon Mills, Executive Director, Financial Conduct Authority, The Mills Review, 6 July 2026, p. 8

The review's first priority recommendation is that the FCA should secure and adapt the perimeter for AI-mediated retail financial services and, to that end, launch a review of general-purpose language models outside the perimeter “within three to six months of the date of this report”, which puts it between October 2026 and January 2027. The review names what an agent acting for a consumer needs at a minimum: valid instructions, “structured and verifiable mandates (scope, limits and revocation)” and a link to the principal's identity. That is the UK, and the review is a recommendation to the FCA's own board, not a legal act. The perimeter question, though, reads exactly the same under MiFID II, and the Retail Investment Strategy, due for a plenary vote in the European Parliament in November 2026, was politically agreed in December 2025, half a year before the first broker opened its agent access. Singapore, as described elsewhere, has answered the question with expectations rather than obligations. The date the FCA has set itself is the only one in the calendar on this question.

Recommendations

1. Map your own perimeter before a customer moves it

Now: for every customer interface that a third-party system can drive, record which WpHG duty attaches to which step: where information ends and recommendation begins, where section 63 (10) applies and where the exemption in subsection 11 does. An institution that draws that map only when a customer connects a community-built server no longer draws the perimeter itself.

2. Keep the appropriateness warning server-side, not as a parameter

Before any agent interface: the warning under section 63 (10) sentence 3 WpHG and its acknowledgement belong on the institution's side, with timestamp, session identifier and channel marker, and so do limits such as a maximum amount per order. A safeguard that, in the words of Scalable's README, works “locally by the CLI only” is invisible to internal audit. Tagging agent sessions as such costs little and is what makes patterns visible in the first place.

3. Operationalise the duty to warn from the Federal Court ruling instead of explaining it away

In compliance planning: the second headnote in XI ZR 431/11 ties liability to knowledge or objective evidence of mis-advice. An institution that recognises agent orders can recognise evidence: clusters of orders in inappropriate instruments from the same agent session, identical reallocations across many customers of the kind BaFin describes as homogeneity risk. Whoever measures that knows when the duty to warn bites. Whoever declares that they do not look is relying on a court accepting the declaration.

4. Do not import the US formula unexamined

When drafting the customer notice: “We do not review or monitor your agent” comes from a regime with no appropriateness test. Under MiFID II the notice should state what the institution continues to provide (pre-trade information, reference, confirmation, appropriateness warning) and what it does not: the flow of data to the model provider, which, according to the Handelsblatt comparison portal and Finanztip, cannot be reversed by disconnecting. A customer who reads that decides on an informed basis. One who reads only the formula decides as if in the US.

Glossary

Model Context Protocol (MCP): an open standard Anthropic published in November 2024 and handed to the Linux Foundation in December 2025; it describes how a language model calls external tools and data sources. For an institution, running its own MCP server means that any assistant the customer uses can operate the same interface without the institution knowing which assistant it is.

Appropriateness versus suitability test: the suitability test (section 64 (3) WpHG) asks about knowledge, wealth and investment objectives and applies only to advice and portfolio management. The appropriateness test (section 63 (10) WpHG) asks only about knowledge and experience and ends in a warning the client may override. For an execution business, that warning is the only hurdle the law still puts up.

Execution-only: pure execution business under section 63 (11) WpHG, in which even the appropriateness test falls away, provided the instrument is not complex and the client took the initiative. Under recital 85 of MiFID II, a client who sends an order through an agent is acting on their own initiative as long as the invitation did not come from the firm.

Regulatory perimeter: the boundary within which an activity requires authorisation and is subject to conduct rules. Whoever gives a personal buy recommendation stands inside; a model provider whose model produces the same recommendation on the customer's instruction remains outside as matters currently stand, and only the FCA is so far examining whether that remains so.

Account information service provider: the PSD2 licence category for third parties that retrieve account data with the customer's consent. It is the yardstick: for payment accounts the EU fitted third-party access with authorisation and mandatory liability, for securities accounts neither exists yet.