Skip to main content
Abstract AI assistant connection to a brokerage order system with a human approval gate

Scalable brings broker actions to AI assistants through MCP, with an approval gate

Scalable Capital's Agentic Investing exposes portfolio and order tools through MCP. Clients must approve trades, but the external-assistant boundary still matters.

Published

28 Aug 2026

Reading Time

4 min read

Share this article:

Contents

The Next Web reported on August 25, 2026, that Scalable Capital had opened its investment platform to outside AI assistants. The implementation is more specific than a chatbot that merely summarizes a portfolio: Scalable exposes broker functions through the Model Context Protocol, or MCP, while keeping final order approval inside its own control flow.

What Agentic Investing exposes

Scalable's launch announcement says clients can connect assistants including ChatGPT, Claude and Grok, then use natural-language requests for market search, portfolio analysis, watchlists, price alerts, savings plans and trades. Scalable calls itself the first European bank to open this range of functions to major external assistants; that is a company claim, not an independently verified market ranking.

The technical setup page identifies the connection as an MCP server. A client activates MCP access under Profile and Security, then adds Scalable's server address to a compatible assistant. MCP gives the assistant a structured way to discover and call tools instead of trying to operate a website by guessing at screen elements. Different assistant providers may restrict some functions under their own policies.

Scalable says users can deactivate access, monitor activity in its app or website, and must approve trades and savings plans before execution. It also says agents cannot handle payments. Those boundaries are important: the assistant can prepare an action, but a separate confirmation is intended to stop an unreviewed prompt from becoming a completed order.

Approval is a control, not a complete safety model

A confirmation step reduces risk only when it presents the essential facts clearly. A useful order review should make instrument identity, direction, quantity, order type, limit conditions, estimated cost and account visible before approval. If the final screen is vague, users can still confirm an action they did not intend. Scalable's public materials state that approval is required but do not document every confirmation-screen field or failure mode.

External assistants introduce other boundaries. Scalable's own disclosure says third-party AI applications operate independently and outside its control, that data transmission is at the user's risk, and that it does not guarantee AI output accuracy. The page also says AI-generated output or transactions do not constitute investment advice or recommendations from Scalable.

That allocation of responsibility does not remove technical risks. An assistant can misunderstand an ambiguous instruction, use stale context or be influenced by untrusted text it reads. Credential scope, session expiry, revocation, rate limits and audit logs matter because an MCP connection is a privileged interface, not just a read-only feed. The public launch pages do not provide a security architecture or independent assessment, so it would be unsupported to claim that any specific vulnerability exists or that the system eliminates these classes of risk.

The regulatory boundary

The European Securities and Markets Authority has said firms using AI in retail investment services must still meet relevant MiFID II obligations and act in clients' best interests. ESMA highlights risks including bias, poor data quality, opaque decision-making, overreliance, privacy and security. It also stresses that management remains responsible when AI-based tools are used.

This makes the line between execution and advice significant. A user giving a specific order is different from an assistant generating a personalized recommendation and then preparing that order. Scalable positions external output as third-party content rather than its advice, but actual regulatory treatment can depend on the service, interaction and jurisdiction. The public announcement does not resolve every such case.

What the launch proves and what it does not

The integration proves that a European broker can expose meaningful account actions through a standard agent interface while retaining an approval gate. The Next Web reports that Scalable serves more than one million clients and manages over €60 billion, which gives the experiment material scale if adoption follows. The article also reports that Scalable has not demonstrated that using AI improves investment returns.

The important evidence will be operational: adoption rates, rejected or corrected orders, incident reporting, revocation effectiveness, support outcomes and whether users understand what they are approving. Independent security review and clearer disclosure of data flows would also help.

For now, Agentic Investing is best understood as a new interface to a regulated broker, not an autonomous portfolio manager. Natural language can simplify navigation, but human approval, scoped access and the broker's execution controls remain the parts that turn a convenient prompt into a financial action.

Sources and methodology

This analysis uses the original TNW report, Scalable's announcement and MCP setup page, and ESMA's AI guidance. It does not provide investment advice or evaluate any security defect as confirmed.

Tags:

#Scalable Capital #MCP #AI assistants #fintech #brokerage #agentic investing

11

views

0

shares

0

likes

Related Articles