Can You Trust AI With Your Money? A Framework
AI is about to become the default place retail investors ask what to do with their money. Before you hand any tool that power, run it through six tests. Here is the framework, and where the honest failure modes are.

The question is no longer if, it is which
Deloitte's Center for Financial Services projects that generative AI could become the leading source of retail investment advice as soon as 2027, reaching roughly 78% usage by 2028. That is not a distant forecast. It means the tool you pick this year is likely the one shaping your portfolio decisions for the rest of the decade.
So the useful question is not whether you can trust AI with your money in the abstract. It is which specific tool earns that trust, and how you would know. The last generation of automation set a low bar. Fortune reported in March 2026 that robo-advisors are now regarded as a generic, incremental feature at best, the kind of thing that slots you into one of about twenty baskets of ETFs from a questionnaire. The new wave, built on large language models, is far more capable and therefore far more consequential to get wrong.
This is a framework for evaluating any AI investing tool, whether it calls itself a copilot, an agent, or AI for investing. Six tests. Each one has a clean pass or fail signal, and each one has a real failure mode worth naming out loud.
1. Custody: who is actually holding the money
Start here, because nothing else matters if you get it wrong. Custody is the question of who legally holds your assets and who can move them. A tool can be brilliant at analysis and still be a catastrophic place to keep your money if it takes custody and cuts corners on segregation, insurance, or solvency.
The safe pattern is non-custodial. Your cash and securities stay at your existing bank, brokerage, or exchange, under your name, covered by the same SIPC or FDIC protections you already have. The AI connects through read and trade permissions but never holds the balance. Ask directly: if this company vanished tomorrow, where is my money? If the answer is anywhere other than at my own broker, that is a concentration of risk you are taking on top of market risk.
This is the design Tengu uses. It connects to your accounts to see your whole net worth across banks, brokerages, and crypto, but it never takes custody. You keep your broker. The failure mode to watch for is the opposite: a shiny interface that quietly becomes the custodian, so that a startup's operational discipline now stands between you and your savings.
2. Consent: does it move without asking
The single most important line in any AI investing product is the boundary between what it can propose and what it can do. A tool that surfaces ideas is an analyst. A tool that executes trades on its own is a discretionary manager, and that is a fundamentally different level of trust and a different regulatory reality.
The consent test is simple. Before any trade reaches your broker, does a human approve it? Consent-first design means the AI does the work, finds an opportunity, explains it, proposes the specific move, and then waits. You approve, or you do not. Tengu follows this find, explain, propose, route sequence and routes the order to your broker only the moment you approve, where that broker supports it.
The honest complication is agentic trading, where you deliberately let an agent act inside limits so it can respond faster than you can click. That can be legitimate and useful, but it only counts as real consent if the limits are yours, set in advance, and revocable instantly. Which brings us to two more tests.
3. Citations: can it show its work in plain English
Language models are fluent, and fluency is dangerous. A system can produce a confident, well-written rationale for a trade that is subtly wrong, built on a stale price, a misread filing, or a fact it simply invented. The industry term for that last one is hallucination, and in a chatbot it is an annoyance. In a tool touching your money it is a loss.
The defense is grounding. A trustworthy tool tells you why it is proposing something in plain English, and it ties that reasoning to specific, checkable inputs: this position, this account, this price at this time, this tax lot. You should be able to read the explanation and independently verify the facts it rests on. If the reasoning is a black box, or if it is all narrative and no numbers, you cannot catch the error before it costs you.
The test: pick any single recommendation and ask the tool to justify it. If you get a paragraph of market-sounding prose with no traceable figures, treat it as marketing, not analysis. If you get a claim you can check against your own statements, that is a system built to be caught when it is wrong.
4. Limits: what stops it from ruining your week
Every serious autonomous system has a floor beneath which it cannot fall, set by the operator, not the machine. In investing those limits are concrete and you should be able to name yours: maximum size per trade, maximum drawdown before the system stands down, the universe of assets it is allowed to touch, and a kill switch that halts everything instantly.
This is where the agentic model earns its keep or fails. When you hire an AI agent to invest inside limits you set, the limits are the whole safety architecture. Tengu's agentic trading is built around exactly these controls, a cap per trade, a drawdown limit, a defined universe, and a kill switch you hold, so autonomy never means unbounded.
The failure mode is subtle: limits that exist in the marketing but are not truly enforced in the execution path, or a kill switch that pauses new ideas but not orders already in flight. Test it before you fund it. Set a tight limit, trigger the boundary, and confirm the system actually stops. A control you have never exercised is a control you do not know you have.
5. Auditability: can you reconstruct every decision later
Trust is not only about the moment of the trade. It is about whether, three months later, you can reconstruct what happened and why. Auditability means a durable, timestamped record: what the AI proposed, what it based that on, what you approved, what actually filled at your broker, and how the two reconcile.
This matters for two unglamorous reasons. First, taxes. Cross-account tax-loss harvesting, one of the highest-value things an AI can do for you, only works if it can prove which lot was sold, when, and what replaced it. Second, accountability. When something goes wrong, and eventually something will, an audit trail is the difference between a diagnosable mistake and an unexplained loss you can neither understand nor dispute.
The test: ask whether you can export a full history of proposals, approvals, and fills. A tool that cannot show you its own past is asking you to trust it on faith, and faith is not a control.
6. Track record: attributable, or just a backtest
Track record is the test people reach for first and the one most easily faked. A backtest is a hypothesis dressed as history. It shows how a strategy would have done on data it was often tuned against, which is why almost every backtest looks good and most live results do not. Academic work on LLM agents in investment management, including recent ACM and arXiv papers, keeps landing on the same caution: apparent skill in simulation frequently fails to survive contact with real markets, real costs, and real slippage.
The credible signal is a live, attributable record. Real money, real fills, over a real period that includes at least one bad stretch. Be actively suspicious of any single dazzling number. A tool that leads with a headline Sharpe ratio or a promised return is selling, not disclosing. In the United States, individualized promises of performance are also a compliance red flag, and their absence is a sign of a serious operator, not a timid one.
Weigh track record last, not first. A tool can pass this test and still fail custody or consent, and no historical curve is worth handing over control of your assets.
Putting the six together
Run any AI investing tool through all six and a clear picture emerges. Custody and consent are the non-negotiables. Get those wrong and the rest is decoration. Citations and auditability are how you catch mistakes, before and after. Limits are how you bound the damage when autonomy is in play. Track record is the tiebreaker, useful only once the other five hold.
The version of AI worth trusting is not the one that promises to manage your money for you. It is the one that works across your accounts, finds what you would have missed, explains it in language you can check, proposes the move, and then waits for you to say yes. You keep your broker, you keep the kill switch, and you keep the final decision. That is the standard Tengu is built to, and it is a fair standard to hold every tool to, including ours.
Key takeaways
- Custody and consent are the two non-negotiable tests: your money should stay at your own broker, and no trade should reach it without your approval.
- Demand plain-English reasoning tied to checkable facts. Confident, ungrounded narratives are how language models cost you money.
- In agentic setups, the safety is entirely in the limits you set: max per trade, max drawdown, allowed universe, and a kill switch you can actually trigger.
- Auditability, a timestamped record of proposal, approval, and fill, is what makes both taxes and accountability possible after the fact.
- Trust a live, attributable track record over any backtest, and treat any promised return or single dazzling Sharpe number as a red flag.
Frequently asked questions
Is it safe to let AI invest my money automatically?
It can be, but only with real controls. Automated or agentic investing is reasonable when the AI acts inside limits you set in advance: a cap per trade, a drawdown limit, a defined universe, and a kill switch you hold. The risk comes from tools that execute without enforced limits or take custody of your funds, so favor designs that keep your money at your own broker and let you halt everything instantly.
What is the difference between an AI that proposes trades and one that executes them?
A tool that proposes is an analyst: it finds and explains opportunities and waits for your approval before anything reaches your broker. A tool that executes on its own is discretionary and carries a higher bar of trust and regulation. Consent-first tools like Tengu propose and route only after you approve, so you keep the final decision on every move.
Can AI hallucinate a financial recommendation?
Yes. Language models can produce confident, well-written rationales built on stale, misread, or invented facts. The defense is grounding: the tool should tie its reasoning to specific, checkable inputs like your actual positions, prices, and tax lots, so you can verify a recommendation before acting on it rather than trusting the prose.
Does the wash-sale rule apply to AI tax-loss harvesting?
Yes. IRS Section 1091 disallows a loss if you buy a substantially identical security within 30 days before or after the sale, a 61-day window in total. Good AI harvesting tracks lots across all your accounts, including a spouse's and IRAs, to avoid triggering it, though crypto is treated as property, so the rule does not currently apply to it.
How do I evaluate an AI investing tool before trusting it?
Run it through six tests: custody (your money stays at your broker), consent (you approve every move), citations (reasoning tied to checkable facts), limits (enforced caps and a kill switch), auditability (an exportable record of proposals, approvals, and fills), and track record (live and attributable, not a backtest). Custody and consent are non-negotiable; the rest tell you how well you can catch and bound mistakes.