Regulation
When a trading model absorbs material nonpublic information, existing US insider-trading law may already reach it
A compliance-law analysis argues that MNPI embedded in a model's weights, rather than reviewed by a human trader, can be enough to trigger insider trading liability under SEC Rule 10b-5, and firms currently have no reliable way to prove what a model actually learned from a given input.
The problem the analysis lays out is structural rather than hypothetical. As asset managers have moved from human-reviewed research pipelines to agentic AI systems touching trading, research, compliance and operations, material nonpublic information has stopped being something that lives in a data room or an analyst's inbox and started being something that can get folded into a model's weights the moment a single prompt carries it in. Once that happens, the firm deploying the model can face insider trading exposure even though no human ever directly read the underlying data, which inverts the usual assumption that liability tracks who saw what.
Three evidentiary problems make this hard to police with existing tools. Provenance is the first: modern models do not record which individual data points influenced a specific output, so proving a model "used" a given piece of MNPI is not straightforward the way tracing an email attachment is. Timing is the second: MNPI is supposed to lose its edge once it becomes stale, but a model can retain and generalise the derived pattern for months after the underlying fact would no longer count as material. Inference is the third and most uncomfortable: a model can produce output that is economically equivalent to insider knowledge without ever directly ingesting the MNPI itself, just by learning the shape of the pattern from adjacent, technically public signals.
The paper grounds this in two cases that predate the AI framing but supply the doctrinal hooks regulators are expected to reach for. Virtu Financial's 2023 settlement, where employees accessed customer order-flow data through shared logins and the firm paid a $2.5 million penalty for failing to establish and enforce adequate policies, is offered as the template for how the SEC will likely treat inadequate model-training-data controls. The Matthew Panuwat case, where an employee traded pharmaceutical stocks after learning of a Pfizer acquisition and the SEC won under a "shadow theory" of liability even though he never traded the acquired company's own stock, extends the same logic to model outputs that are directionally informed by MNPI without directly encoding it. Vendor-supplied foundation models trained on sensitive data pooled across multiple client firms compound the exposure, since a leak in the vendor's training pipeline becomes a shared liability event for every firm using the model.
None of this has yet produced an enforcement action naming an AI model as the vector, which is the caveat worth sitting with. Virtu and Panuwat are real, decided cases, but both were retrofitted into this argument as analogies rather than as AI precedent, because no AI-specific case exists yet to cite directly. That makes this compliance literature and anticipatory risk-mapping, not settled law, and the practical recommendation the piece lands on (treat model training-data provenance with the same rigor as traditional information barriers) is a sensible hedge against a risk regulators have flagged in principle but not yet tested in a courtroom against an actual trading model.
Read the original: Mondaq - When a trading model absorbs material nonpublic information, existing US insider-trading law may already reach it. Commentary is the independent editorial view of Share Trading; the original article is credited to its publisher.