Market manipulation by machines · Part 1
When the rogue actor is itself a model
Market manipulation and collusion are intent offenses: what the law forbids is not the pattern a trade leaves on the tape but the purpose behind it, the agreement, the intent to mislead, the design to move a price. When the trader is an autonomous model that reaches the same pattern on the tape while lacking the purpose or agreement behind it, the prohibition still describes the harm exactly and finds nothing it can call the offense.
Part 1 of a three-part series on market manipulation and collusion by machine actors. Part 2: When the reason cannot be read. Part 3: When the evidence is a simulation.
August 9, 2026
Two of the offenses at the center of market-abuse law are defined by the state of mind behind a trade, not by what the trade does. Market manipulation punishes a purpose: the intent to mislead, or to push a price away from what supply and demand would set.1 Collusion punishes an agreement: a meeting of minds to restrain competition. In both, the conduct visible on the tape is not the offense. The offense is the reason for the conduct. Until now, the law has inferred that reason from the behavior of people; with autonomous systems, the debate is how that interpretation must change.
An autonomous trading model, a system that learns its own strategy by trial and error rather than following written rules, can arrive at the prohibited pattern with no purpose and no agreement behind it. This essay discusses where the intent requirement lives in the law, how a machine can reach the pattern without the mind, and what a court or regulator would look for.
The proof is intent, not the pattern
Let us consider manipulation. A canceled order is not an offense. Markets run on canceled orders: quotes are placed and pulled continuously as prices move and information arrives. What separates lawful cancellation from the manipulative kind is the reason for it, not the cancellation. United States law writes this straight into the Commodity Exchange Act, which defines spoofing as bidding or offering "with the intent to cancel the bid or offer before execution," and the Commodity Futures Trading Commission reads that provision to require intent, a scienter (acting with knowledge of wrongdoing) beyond mere recklessness.2 The same sequence of orders is either a legitimate change of mind or a federal offense depending entirely on a state of mind fixed at the moment the order was placed. An earlier essay made the general version of the point: the metrics a surveillance program runs describe behavior, not intent, and a high ratio is not a crime.
Collusion draws the same line in a different place. Section 1 of the Sherman Act reaches a "contract, combination ... or conspiracy" in restraint of trade: it requires concerted action, an agreement. Firms that independently read the same market signal and independently settle on the same price are acting lawfully. This parallel conduct alone does not establish the agreement the statute demands.3 What the law forbids is tacit collusion sustained by mutual monitoring and retaliation: I hold my price because I expect you to punish me if I cut it, and you expect the same of me. On the tape, lawful parallel conduct and unlawful tacit collusion can look identical. What separates them, once again, is whether a coordinating mind stands behind the pattern.
Collusion and cooperation: can autonomous systems create a cartel?
The difficulty arrives when the trader is a reinforcement-learning system. Such a system is given a measure of success to make as large as possible, usually some measure of profit, which engineers call its reward. It is not told how to trade. It is left to discover for itself, through trial and error, the strategy that earns the most reward. Recent research shows that systems built this way can learn to collude.
In a 2025 study, Dou, Goldstein, and Ji replaced the informed speculators in a market model with AI-powered traders running reinforcement-learning algorithms and found that they "autonomously sustain collusive supra-competitive profits without agreement, communication, or intent."4 The collusion is held together not by a pact but by a price-trigger discipline. The agents restrain their own trading, and a deviation that moves the price past a threshold provokes a reversion to competitive trading. After that reversion, cooperation resumes. What emerges is the outcome a cartel produces, prices held above the level competition would set, without any of the acts that make a cartel unlawful: no meeting, no communication, no agreement to hold back.
This is not an artifact of one model or one market. In a widely used economic model of price competition, Calvano and colleagues found that reinforcement-learning algorithms "consistently learn to charge supracompetitive prices, without communicating with one another," sustained by "collusive strategies with a finite phase of punishment followed by a gradual return to cooperation," and stressed that the algorithms "are not designed or instructed to collude": they reach the strategy by trial and error alone.5 The worry does not fade as the technology improves; the authors note it may grow. Nor is it confined to bespoke systems built by quantitative traders. Pricing agents built on a consumer large language model reach the same supracompetitive prices, and the degree of collusion shifts with small changes in the wording of their instructions.6
One caution matters here. Reacting to what rivals do is not the offense. Every competent trading system, human or machine, reads the market and adapts to it. Working out what other participants are doing from prices and volumes is the ordinary business of trading. It is not a sign of wrongdoing. The research points to something narrower. The concern is that a model can learn a pattern of mutual restraint: each holds back to keep prices high, and any rival that breaks ranks is met with a spell of aggressive competition. That restraint is what holds prices above the level competition would set. A model that simply adapts is responding to the market as it finds it. A model running the collusive strategy is using its rivals' likely reactions as a lever, rewarding restraint and punishing defection over many rounds of trading. On the tape, the two look alike. The intent requirement was what separated them, and with an autonomous model that requirement has nothing to attach to.
There are two cases here, and only one is hard. In the first, a deployer deliberately designs the reward so that the model learns restraint, or sets up the training environment to the same end. Intent has then re-entered the system through the human hand. The design encodes the purpose, and the law reaches it in the ordinary way, no differently from people who colluded through software. The hard case is the emergent one, where the collusive behavior grows out of a plain instruction to maximize profit, with no one having sought it or specified it. In that case there is no agreement anywhere to point to, and no purpose that a prosecutor could put before a court. The conduct sits on the tape; the two things the law must prove to make it an offense are missing. As the economist Joseph Harrington has argued, collusion by software that chooses its own pricing rules without human intervention is not, on the current doctrine, a violation of Section 1 of the Sherman Act.7
What does the law seek
For an autonomous model, what can the law seek? The model has no mind, so intent cannot be read from it directly. The alternative is to look past the model to the system around it, and to the person who built and released it. A trading model is a series of design choices rather than a single decision, and some of those choices are where a court or regulator would look to find, or fail to find, a purpose. Four of them matter (see figure).
The first is the objective, the reward the model is told to make as large as possible. This is the closest the system comes to a place where the law can locate intent. If the reward is defined over beating specific counterparties, or over holding a spread wide, the design encodes a purpose a court can read. If it is defined only over ordinary profit and the collusive pattern emerges anyway, the reward is silent on intent, and this is the emergent case. So the first thing the design shows is whether a purpose was specified, or simply arrived.
The second is the training regime, the environment the model was trained in. The question here is not whether the model learns from its rivals, because every model does that. It is whether the model was trained by playing against the same rivals again and again, rivals that adapt and that remember enough of the past to reward restraint and punish anyone who breaks ranks. Those are the conditions under which mutual restraint becomes the strategy the model settles on, rather than something it stumbles into once. Setting up those conditions is not a purpose to collude. It is a choice to build an environment in which collusion is the likely result, and the law can treat that choice the way it treats foreseeability. This is the substance of the proposal, advanced by Harrington and others, to reach collusion-facilitating designs directly rather than hunt for an agreement that was never made.
The third is oversight. Did the deployer keep the ability to see what the model was doing, and to stop it? Were there guardrails on what the model could observe of its rivals? Was its memory kept short, so that punishment strategies could not stabilize? Was supra-competitive behavior penalized in the objective? And are these measures reliable? Not dependably: they work against the thing the model is for, since much of what suppresses the collusive outcome also blunts the model's ordinary ability to read the market. Even so, they matter to the law. Their absence does not prove the model meant anything, but it does show what the deployer could have seen, could have prevented, and chose to leave open. The guardrail question does not restore the machine's intent. It moves the inquiry to the deployer's supervision, where the doctrines of failure to supervise and willful blindness already operate.
The fourth is the audit trail: the training logs, the saved versions of the model, the record of what its reward was set to and how it arrived at its strategy. This is what can be reconstructed after the fact, and it is where the design works against the law. To read a purpose off the reward, a foreseeable design off the training, or a supervisory failure off the guardrails, a regulator needs that record to exist and to be readable. An opaque model may keep no such record, or none that anyone can interpret. The attribution is strongest, then, where the system is well documented, and weakest in the emergent case, which tends to be the least documented of all.
Figure 1 · system architecture · reading down for intent
Two limits apply. The attribution above works best where a purpose was specified and the system was set up to record it. In the purely emergent case the design is at its cleanest and the intent hardest to find, and that is where the inquiry has the least to work with. The phenomenon itself, for all the consistency of the experimental results, has not been tested where it would matter most. No jurisdiction has sanctioned purely autonomous tacit collusion, and economists remain divided over how robust it is in real, noisy markets as against the controlled settings where it has been shown.
The next wall
So the intent-based offense does not vanish when the trader is a model; it moves. The mind the law cannot find in the machine, it looks for instead in the person who set the reward, chose the training environment, and decided how much of the system to leave unwatched. The prohibition still describes the harm exactly; what it reaches for now is the deployer rather than the trader.
But that shift depends on one thing, and that thing is the subject of the second essay. To attribute anything up the chain, whether a purpose, a foreseeable design, or a supervisory failure, a regulator has to be able to reconstruct why the model acted as it did. When the model is a black box, that reconstruction is what fails. It is the second of the two failures Yavar Bathaee named, alongside the failure of intent this essay has traced: the failure of causation.8 Part 2, When the reason cannot be read, takes it up.
Notes
Links captured and verified August 2026. Working papers, statutes, and case law are revised, amended, and superseded over time; a link that resolves correctly at capture is not a guarantee it will still resolve, or still read the same way, when read later. The collusion findings below are drawn from experimental and simulation research: no jurisdiction has yet sanctioned purely autonomous tacit collusion, and the economic literature remains divided on how robust it is in live markets.
- On the intent element of price manipulation, see the Securities Exchange Act, section 9(a)(2), 15 U.S.C. § 78i(a)(2), which prohibits a series of transactions "raising or depressing the price of such security, for the purpose of inducing the purchase or sale of such security by others," and section 10(b), 15 U.S.C. § 78j(b), with Rule 10b-5, 17 C.F.R. § 240.10b-5, the general prohibition on manipulative or deceptive devices, which the Supreme Court has read to require scienter (Ernst & Ernst v. Hochfelder, 425 U.S. 185 (1976)): law.cornell.edu. The Commodity Exchange Act carries parallel manipulation provisions; on its spoofing provision, see the next note. ↩
- On the intent element of spoofing, see the Commodity Exchange Act, section 4c(a)(5)(C), 7 U.S.C. § 6c(a)(5)(C), added by the Dodd-Frank Act (2010): spoofing is "bidding or offering with the intent to cancel the bid or offer before execution": law.cornell.edu. The Commodity Futures Trading Commission interprets a violation to require intent, or scienter, beyond recklessness. ↩
- On the requirement of concerted action, see the Sherman Act, section 1, 15 U.S.C. § 1, reaching a "contract, combination ... or conspiracy" in restraint of trade: law.cornell.edu. On parallel conduct being insufficient without more to establish an agreement, see Bell Atlantic Corp. v. Twombly, 550 U.S. 544 (2007). ↩
- On reinforcement-learning speculators that sustain collusion without agreement, communication, or intent, and the price-trigger strategies that hold it together, see Winston Wei Dou, Itay Goldstein, and Yan Ji, "AI-Powered Trading, Algorithmic Collusion, and Price Efficiency," National Bureau of Economic Research Working Paper 34054 (2025): nber.org. ↩
- On Q-learning pricing algorithms that learn supracompetitive prices, sustained by a finite punishment phase and a gradual return to cooperation, without being designed or instructed to collude, see Emilio Calvano, Giacomo Calzolari, Vincenzo Denicolò, and Sergio Pastorello, "Artificial Intelligence, Algorithmic Pricing, and Collusion," American Economic Review 110, no. 10 (2020): 3267 to 3297: aeaweb.org. ↩
- On pricing agents built on a consumer large language model reaching supracompetitive prices, with the degree shifting on the wording of their instructions, see Sara Fish, Yannai A. Gonczarowski, and Ran I. Shorrer, "Algorithmic Collusion by Large Language Models," arXiv:2404.00806 (2024): arxiv.org. ↩
- On the argument that collusion by software choosing pricing rules without human intervention is not a violation of Section 1, and the proposal to reach collusion-facilitating designs directly, see Joseph E. Harrington, Jr., "Developing Competition Law for Collusion by Autonomous Artificial Agents," Journal of Competition Law & Economics 14, no. 3 (2018): 331 to 363: academic.oup.com. ↩
- On the black box breaking the two elements on which liability rests, intent and causation, see Yavar Bathaee, "The Artificial Intelligence Black Box and the Failure of Intent and Causation," 31 Harvard Journal of Law & Technology 889 (2018): jolt.law.harvard.edu. Part IV treats the failure of causation, the subject of Part 2. ↩
The research and law described here are current to August 2026 and continue to change as the experimental literature grows and as competition and market-abuse authorities take up the question of autonomous agents.
Responses from readers
This website does not host open comments. Verified responses are published here at the editor's discretion. Submit a response to editorial@tradesreconstructed.com.
