You Approve Every Move: Consent-First AI

The most capable investing agent is not the one that acts without you. It is the one that finds, explains, proposes, and waits for your yes.

Marcus Feldman
Head of Research
22 Jun 2026
8 min read
You Approve Every Move: Consent-First AI

Why control, not capability, is now the deciding question

AI is about to become how most people invest. Deloitte's Center for Financial Services projects that generative AI could become the leading source of retail investment advice around 2027, with usage climbing toward 78 percent by 2028. That is not a distant forecast. It is the next two budget cycles.

When a technology moves that fast, the interesting debate stops being whether AI can pick investments and starts being who holds the wheel when it does. An agent that reasons across your accounts and routes trades is powerful. The same agent acting without your sign-off is a liability wearing a nice interface. The design choice that separates the two is consent.

Consent-first means the software finds and proposes, and you decide. It is non-custodial, so you keep your own accounts, your own broker, and your own money. The agent never has the standing to move a dollar on its own. That single constraint is what makes real reach responsible.

What a robo-advisor does, and the four things it cannot

To see why consent matters, look at what came before. A traditional robo-advisor is a questionnaire plus a rebalancer. You answer a few questions about age and risk tolerance, the system slots you into one of roughly twenty pre-built ETF baskets, and a static rule nudges the weights back to target on a schedule. That was genuinely useful in 2015. It automated the boring part of index investing and cut fees.

But it is narrow by design. Fortune, writing in March 2026, described legacy robo-advice as a generic, incremental feature at best. It sees one account in isolation. It cannot read the 10-K, react to a filing, notice that a concentrated stock position is dragging your whole picture, or coordinate a tax move across a brokerage and an IRA at once. It follows a rule, not your situation.

The gap is not intelligence. It is scope and reaction time. A rules engine cannot answer a plain-English question about your own portfolio, and it cannot plan around a life event like buying a home or exercising options.

The progression from chatbot to copilot to agent

The research frontier maps a clear progression: chatbot, then copilot, then agent. Work from the World Economic Forum and academic groups, including the arXiv paper 'Robo-Advisors Beyond Automation' and ACM research on LLM agents for investment management, describes AI that can reason, plan, and act rather than just retrieve answers.

An agent does things a robo-advisor cannot. It analyzes behavior, not just risk scores. It adapts risk as your life changes. It answers questions in natural language. It reasons about individual securities instead of only ETF baskets. It runs scenarios such as a concentrated position or a home down payment, and it optimizes tax across accounts as news and filings land.

Concretely, an investing agent works in four verbs. It finds opportunities across every account you connect. It explains each one in plain English so you understand the why. It proposes the specific move. Then it routes that move to your broker where supported, the moment you approve. Tengu is built around exactly this loop: find, propose, route, with your approval as the gate on the last step.

The five failure modes autonomy introduces

More capability is not free. A serious treatment of agentic investing has to name the failure modes instead of hiding them. Five are worth stating plainly.

Accountability: when an autonomous system acts, who answers for the outcome. The WEF calls this the autonomy accountability gap, where institutions deploy systems that act on their own while the accountability framework lags behind. Hallucination: a language model can state a wrong number or invent a fact with total confidence, and fragmented data makes it worse. Over-trading: an eager optimizer can churn a portfolio, generating costs and taxes that erase its own edge. Regulation: the rules for autonomous financial action are still being written, and they will not be gentle. Trust: people will not, and should not, hand a black box the keys to their savings.

These are real. Any vendor that waves them away is selling you the risk along with the product.

How approval, citations, limits, and a kill switch answer each risk

The reassuring finding is that the same governance controls institutions adopt for their own agents map directly onto a consumer product. The WEF's guidance for financial institutions names the safeguards: human oversight, action logging, real-time auditing, kill switches, and human override. Consent-first investing is those safeguards, pointed at you instead of a compliance desk.

Approval answers accountability. Because you sign off on every move, the decision is provably yours, and the agent's job is to make it well-informed rather than to make it for you. Citations answer hallucination. When each proposal shows its sources, the filing, the price, the tax lot, you can check the reasoning before you commit, and a fabricated claim has nowhere to hide. Limits answer over-trading. You set a maximum per trade, a drawdown ceiling, and an allowed universe, so an agent cannot churn or wander outside its lane. The kill switch answers trust. You hold it, and it stops everything instantly.

Non-custodial architecture ties it together. Your money stays in your accounts at your broker. The agent has reach to propose and, where supported, to route on your yes, but never the custody to act alone.

How to delegate with bounded autonomy instead of blind faith

Consent-first does not mean you must click approve on every rebalance forever. The mature version lets you delegate deliberately. You can hire an AI agent to invest on its own inside a box you define: a cap per trade, a maximum drawdown, a specific universe of assets. Inside that box it acts. Outside it, it cannot. And the kill switch stays in your hand the entire time.

That is the difference between delegation and abdication. Black-box autonomy asks you to trust an outcome you cannot inspect. Bounded autonomy asks you to set the rules once, watch the log, and keep the power to stop. One is a leap of faith. The other is a contract you wrote.

Why whole-net-worth reach is the real unlock

The strongest argument for the agent model is not a single clever trade. It is that an agent can see your whole net worth at once, across banks, brokerages, and crypto, instead of one silo. That vantage point enables things no single-account tool can do.

The clearest example is cross-account tax-loss harvesting. Harvesting a loss in one brokerage while an identical or similar position sits in another can trigger the wash-sale rule and quietly undo the benefit. Only an agent that sees every account at the same time can harvest cleanly and coordinate across them. That capability is impossible for a siloed robo-advisor by construction, and it is only responsible when it runs on consent-first rails. This is educational, not individualized tax advice, so confirm specifics with a professional.

Reach is what makes an agent worth having. Consent is what makes reach safe to grant. You do not have to choose between a capable agent and staying in control. The whole point of consent-first design is that the most capable arrangement is also the one where you approve every move.

Key takeaways

  • Deloitte projects generative AI could become retail investors' leading source of investment advice around 2027, reaching roughly 78 percent usage by 2028.
  • Legacy robo-advisors slot you into about twenty pre-built ETF baskets from a questionnaire and rebalance on static rules; an agent finds, explains, proposes, and routes across all your accounts.
  • Autonomy adds real risks: accountability gaps, hallucination, over-trading, regulation, and trust. Consent-first design answers each with approval, citations, limits, and a kill switch.
  • Non-custodial means your money stays in your own accounts and broker; the agent proposes and routes only on your yes, and never moves money alone.
  • Seeing every account at once unlocks capabilities like cross-account tax-loss harvesting that siloed robo-advisors cannot do.

Frequently asked questions

What does non-custodial AI investing mean?

Non-custodial means the AI never takes possession of your money, so you keep your own accounts and broker. The agent can find opportunities, explain them, and route a trade to your broker where supported, but only after you approve it. It cannot move funds on its own.

How is an AI investing agent different from a robo-advisor?

A robo-advisor puts you in one of about twenty pre-built ETF baskets from a questionnaire and rebalances on static rules, seeing one account in isolation. An agent reasons across all your connected accounts, answers plain-English questions, analyzes individual securities, runs scenarios, and reacts to news and filings, proposing specific moves for your approval.

What is a kill switch in agentic trading?

A kill switch is a control you hold that immediately halts all agent activity. Combined with per-trade limits, a drawdown ceiling, and a defined universe of allowed assets, it lets you grant an agent bounded autonomy while keeping the power to stop everything instantly.

Does consent-first AI execute trades at brokers like Robinhood or Schwab automatically?

No. Consent-first tools propose a move and you approve it, and the trade is routed only where that broker is supported. The design deliberately keeps you as the gate on every execution rather than acting automatically on your behalf.

Why is seeing all my accounts important for tax-loss harvesting?

Harvesting a loss in one account while a similar position sits in another can trigger the wash-sale rule and cancel the benefit. Only an agent that sees every account at once can coordinate the harvest cleanly. This is general education, not individualized tax advice.

← All articles
Tengu
Miami, Florida
September 4, 4:43 AM

Newsletter

© 2026 Tengu. All rights reserved.Privacy & cookiesTerms & conditions
Built by Tengu