Market manipulation by machines · Part 2

When the reason cannot be read

A market offense has to be traced to a cause. The trade must be tied to the artificial price it produced, and the outcome to the person whose choice explains it. When the trader is an autonomous model, the record still shows what happened, and can still establish an artificial price. What it cannot show is why the model acted. A black box will not give up its reason. This is the second failure, the one that follows intent: the failure of causation.

Part 2 of a three-part series on market manipulation and collusion by machine actors. Part 1: When the rogue actor is itself a model. Part 3: When the evidence is a simulation.

August 9, 2026

Part 1 followed the intent a market offense requires from the machine, which has none, to the people around it. They set the reward, chose the training environment, and decided how much of the system to watch. That association works by holding a deployer to some of the following:

  1. a purpose in the reward,
  2. a foreseeable design in the training, or
  3. a failure in oversight.

For any of these, someone has to trace a line from that choice to what the model did on the tape. Tracing that line is causation, and it is the subject of this essay.

Causation in a market offense asks two different things. The first is whether the conduct caused the market effect: did these trades move the price, or merely coincide with a move that came from elsewhere. This is easily traceable from the tape, as prices, volumes, and times are always on the record. The second is why the conduct happened, and whether that reason makes it an offense and belongs to a particular person. That question the record answers for a human by other means, and cannot answer at all when the trader is a black box. This essay is about the second.

What causation asks of a market offense

Manipulation is not made out by a price that moved. It is made out by a price that was moved, and moved to create a false impression of supply and demand. The Securities Exchange Act reaches transactions that raise or depress a price for the purpose of inducing others to trade.1 The courts applying it ask whether the conduct sent a false signal about real supply and real demand rather than reflecting them.2 A large sale that drives a price down is lawful if it is a genuine sale and unlawful if its point was to paint the tape. The price move is the same in both; what differs is the reason, and the causal claim the law makes is that the reason produced the move.

The law then splits the causal question. In a private action, a plaintiff must show transaction causation, that the manipulation led them to trade, and loss causation, that it caused the loss claimed. Loss causation is treated as a form of proximate cause. The Second Circuit requires that the loss be a foreseeable result of the risk the conduct concealed, not a later, unrelated misfortune.3 Across these tests, causation is a requirement separate from intent. Proving a manipulative purpose does not, on its own, make out a completed manipulation. The conduct must actually have produced the artificial price. A purpose that moves no price may be an attempt, prohibited in its own right,4 but the completed offense needs the effect.

The unreadable model

A trading model is what is meant by a black box: its inputs and outputs are visible, its workings are not. It maps what it sees to what it does through millions of numbers tuned in training, with no stated rule connecting the two. Asked why it sold, it has no answer to give.

There are tools that try to open the box. A survey of the field groups them into methods that attribute an output to particular inputs and methods that fit a simpler, readable model to imitate the complex one.5 Each produces an explanation after the fact. Cynthia Rudin argues that these after-the-fact explanations are unreliable, and that high-stakes decisions should use models that are interpretable from the start rather than trust an explanation laid over a black box.6 What a tool of this kind yields is a plausible account of the model's action, not a demonstration of the reason behind it. Yavar Bathaee draws the line the law runs into. A weak black box may let you rank which inputs seemed to matter, though even then you may not show that any one was decisive. A strong black box yields not even that.7

For this publication the test is whether a claim can be explained in court. An after-the-fact reason for a model's action does not meet it. The other side can contest it with a different account, and a reason that can be argued either way is not proof of cause. The reason is inside the model. It is simply not legible, and the law needs it legible.

Figure 1 · causal chain · reading across for cause

THE CAUSAL CHAIN, LEFT TO RIGHT READING ACROSS ► 01 · DESIGN reward, training, oversight documented, and readable 02 · THE MODEL its internal state the reason: not legible 03 · ACTION orders, cancels, fills on the record 04 · PRICE an artificial price measurable from the tape CAUSATION GAP the why the record cannot supply LEGIBLE OPAQUE LEGIBLE LEGIBLE PART 1: WHERE INTENT WAS LOCATED The endpoints are on the record. The reasoning that connects them is not.
The chain, and the link that cannot be read. A market offense runs from a design choice, through the model, to an action on the tape and a price effect. Three of the four are legible: the deployer's documented choices, the orders and fills on the record, and the price measured against what the market would otherwise have set. The connecting reason, inside the model, is not. Where a human trader's reason is reconstructed from evidence around the trade, the model keeps its reason where the record cannot reach. Illustrative; not a specific system.

What the law does when it cannot trace a cause

When the law cannot trace a cause directly, it has settled ways of proceeding without one. Proximate cause already substitutes foreseeability for a full account of the chain. The loss-causation cases ask not for every link but whether the harm was a foreseeable consequence of the conduct. Strict and vicarious liability go further, assigning responsibility with no proof of a particular mental state or causal path. Each is a way of placing a loss when the whole story cannot be told.

For autonomous models these are the tools on the table, and each has a cost. Bathaee, having shown why intent and causation both fail against a black box, rejects the two easy answers. A transparency mandate he treats as a technological problem the law cannot simply order solved, one that tilts design and raises barriers to entry. Strict liability he treats as administrable but blunt. His own proposal is a sliding scale keyed to supervision. The more autonomous the system, and the less its operator could see and control, the more the burden shifts to that operator. Others would regulate the design directly, reaching the choices that make collusion or manipulation a foreseeable outcome rather than searching for a reason after the fact.8 The disagreement is real. Foreseeability can under-deter where harm was not foreseeable, and over-deter where it was merely unlucky. Strict liability can chill legitimate model-building. Design rules ask a regulator to know in advance which designs are dangerous.

What they share is the move Part 1 ended on. The reason the law cannot read in the machine, it looks for in the person: in what the deployer could foresee, could see, and could stop. Causation, like intent, relocates from the trader to the deployer.

Governing the action instead of reading the mind

There is a further response, and it does not require reading the model at all. If the reason inside the model cannot be made legible, the action coming out of it can still be governed before it takes effect. In July 2026 the Monetary Authority of Singapore, with a group of banks and payment firms, published Safeguards for Agentic Finance at Runtime, a proposed industry framework, not a rule, built for this.9 It places a governance layer between the agent and the market. Every action the agent proposes is checked, before execution, against an explicit machine-readable statement of what it is authorized to do, and is then allowed, escalated to a person, or refused. Each decision is recorded.

This shifts the question the essay has been circling. It stops asking why the model acted and asks instead whether the action was authorized, and it records the answer at the moment of the act. The reason inside the model stays unreadable, but the mandate, the check, and the log are on the record. The reconstruction the law could not perform on the model's reasoning is performed instead on its authority to act. A trade proposed outside the mandate is stopped at the boundary, and the record shows that it was stopped.

This does not open the black box, and it does not claim to. It cannot tell whether an authorized action was taken for a good reason or a bad one, which is the intent problem of Part 1 in a new place. What it can do is narrow what an autonomous agent is permitted to do and leave a legible record when it acts, so that the two things Parts 1 and 2 relocate the inquiry onto, the deployer's control and the agent's authority, are written down rather than inferred.

Where the reconstruction moves

None of this makes the trade record useless. It still proves what was done, and can still establish that a price was artificial. It still holds the deployer's documented choices: the reward that was set, the environment that was chosen, the oversight that was kept or dropped. What it cannot hold is the model's reason, and in the emergent case, where the behavior grew from a plain instruction that no one shaped toward the result,10 the reason is the whole case.

So the reconstruction this publication is named for does not stop at the machine; it moves. It shifts from the reasoning inside the model, which cannot be read, to the authority around it, which can: what the agent was permitted to do, what it did, and what the record shows at the boundary between them. The reason stays inside the box. The account the law needs is built outside it.

Notes

Links captured and verified August 2026. Statutes, case law, and working papers are revised, amended, and superseded over time; a link that resolves at capture is not a guarantee it will still resolve, or still read the same way, later. The collusion research referenced below is experimental and simulation work: no jurisdiction has yet sanctioned purely autonomous tacit collusion.

  1. On manipulation as conduct that creates a false or artificial price, see the Securities Exchange Act, section 9(a)(2), 15 U.S.C. § 78i(a)(2), reaching transactions "raising or depressing the price of such security, for the purpose of inducing the purchase or sale of such security by others," and section 10(b), 15 U.S.C. § 78j(b), with Rule 10b-5, 17 C.F.R. § 240.10b-5: law.cornell.edu.
  2. On the elements of a market-manipulation claim, including the requirement that the conduct create a false impression of supply and demand, and the separation of transaction causation from loss causation, see ATSI Communications, Inc. v. Shaar Fund, Ltd., 493 F.3d 87 (2d Cir. 2007).
  3. On loss causation as a form of proximate cause, requiring that the loss be a foreseeable consequence of the concealed risk and not a later, independent misfortune, see Lentell v. Merrill Lynch & Co., 396 F.3d 161, 172 to 174 (2d Cir. 2005); ATSI applies this standard to manipulation claims.
  4. On attempted manipulation as a separate offense that does not require a completed price effect, see the Commodity Exchange Act, section 6(c)(1), 7 U.S.C. § 9(1), with CFTC Rule 180.1, 17 C.F.R. § 180.1, which reach an attempt to use or employ a manipulative or deceptive device, and section 9(a)(2), 7 U.S.C. § 13(a)(2), with Rule 180.2, 17 C.F.R. § 180.2, on manipulation and attempted manipulation of a price: law.cornell.edu.
  5. On the two broad families of methods for explaining opaque models, those that attribute an output to particular inputs and those that fit a simpler, readable model to imitate the complex one, see Riccardo Guidotti and others, "A Survey of Methods for Explaining Black Box Models," ACM Computing Surveys 51, no. 5 (2018), article 93: doi.org.
  6. On the unreliability of explaining black-box models after the fact, and the argument for using inherently interpretable models in high-stakes settings instead, see Cynthia Rudin, "Stop Explaining Black Box Machine Learning Models for High Stakes Decisions and Use Interpretable Models Instead," Nature Machine Intelligence 1 (2019): 206 to 215: doi.org.
  7. On the failure of causation against black-box AI, where proximate cause requires a foreseeable effect and conduct-nexus tests such as reliance require a traceable link, on the distinction between weak and strong black boxes, and on a proposed sliding scale keyed to supervision rather than to intent or cause, see Yavar Bathaee, "The Artificial Intelligence Black Box and the Failure of Intent and Causation," 31 Harvard Journal of Law & Technology 889 (2018), Parts IV to VI: jolt.law.harvard.edu.
  8. On the proposal to reach collusion-facilitating designs directly rather than search for an agreement or a reason after the fact, see Joseph E. Harrington, Jr., "Developing Competition Law for Collusion by Autonomous Artificial Agents," Journal of Competition Law & Economics 14, no. 3 (2018): 331 to 363: academic.oup.com.
  9. On a runtime governance layer that checks each proposed agent action against an explicit, machine-readable statement of its authority before execution, resolving it to allow, escalate, or refuse, and recording the decision, see Monetary Authority of Singapore, "Safeguards for Agentic Finance at Runtime (SAFR)," industry white paper, version 1.0 (July 2026): mas.gov.sg. The paper states that it does not constitute regulatory guidance or supervisory expectations.
  10. On reinforcement-learning traders that sustain collusion without agreement, communication, or intent, the emergent case in which no one shaped the behavior toward the result, see Winston Wei Dou, Itay Goldstein, and Yan Ji, "AI-Powered Trading, Algorithmic Collusion, and Price Efficiency," National Bureau of Economic Research Working Paper 34054 (2025): nber.org.

The research, law, and runtime-governance proposals described here are current to August 2026 and continue to change as the interpretability literature grows and as regulators and market-abuse authorities take up the question of autonomous agents.

Responses from readers

This website does not host open comments. Verified responses are published here at the editor's discretion. Submit a response to editorial@tradesreconstructed.com.