Autonomous trading agents do not wait for market hours. They can monitor fragmented venues, adjust positions and place orders continuously. That operating model creates a difficult oversight problem: institutions need evidence that an agent stayed within its mandate, but the evidence itself can reveal the strategy regulators, counterparties and competitors are not supposed to see.
Midnight’s September 7, 2026 blog post proposes Policy Vaults for institutional trading. The design uses zero knowledge proofs, a cryptographic method for proving that a statement is true without revealing the underlying information, to enforce risk limits and demonstrate compliance while keeping positions, balances and strategies private.
The proposed structure separates the policy from the trading logic. A Policy Vault could contain rules such as maximum exposure, permitted instruments, loss limits or reporting requirements. An AI agent would execute its strategy against live market conditions. The vault would then produce, or require, a proof that the relevant action remained within those rules.
The important distinction is between revealing a result and revealing the data used to reach it. A conventional audit might require an institution to disclose order histories, account balances or the strategy itself. A zero knowledge system can instead aim to prove a narrower statement: that a trade, position or sequence of actions satisfied a specified condition.
That privacy property is useful only if the condition is precise. “Trade safely” is not a proof statement. A workable policy needs defined inputs, thresholds and timing. It must specify which assets count toward exposure, how positions are valued, whether borrowed funds are included and what happens when market data is delayed or unavailable. The vault can prove compliance with encoded rules. It cannot repair a policy that was vague, incomplete or badly chosen.
This is where the proposal moves beyond private execution. The goal is not simply to conceal trading information. It is to create selective disclosure, in which an institution reveals the compliance fact required by a particular observer without surrendering the wider dataset. A regulator might receive evidence that a risk ceiling was respected. An internal supervisor might receive a different proof covering a broader set of controls. The trading strategy could remain outside both disclosures.
The approach also changes the shape of an audit. Instead of examining every confidential input, an auditor would need to assess the policy, the proof system and the connection between the proof and the agent’s actions. That creates a chain of dependencies. The policy must be correctly encoded. The private inputs must correspond to real positions and orders. The proof must be generated for the relevant time period. The receiving party must know which facts the proof establishes and which facts it does not.
The blog presents Policy Vaults as a response to the limits of conventional oversight in markets where automated agents operate continuously. But a proof of a constraint is not automatically proof of good governance. An agent could remain below a position limit while following a strategy that creates unacceptable operational, legal or liquidity risks. Compliance checks therefore need to cover the obligations an institution actually carries, not only the metrics that are easiest to express mathematically.
Emergency intervention is another unresolved part of the design. A system that protects strategy data cannot assume that every decision should remain private during a crisis. Institutions may need a way to halt an agent, freeze a vault, rotate an authority or disclose information under defined conditions. Those controls introduce privileged actors and governance rules. Their existence must be auditable without turning the privacy layer into a back door.
Responsibility also remains outside the proof itself. If an automated strategy breaches a rule because its market data was wrong, its policy was misconfigured or its proof was generated from incomplete inputs, the cryptography does not decide who is accountable. That question belongs to the institution’s control framework and the agreements governing the agent.
For Midnight, the proposal gives programmable privacy a more concrete financial use case than simply hiding transactions. Its test will be implementation. Institutions would need auditable policies, credible proof generation, reliable links to trading data, emergency controls and a clear assignment of responsibility when automation fails. Policy Vaults could reduce the information exposed during supervision, but they will support accountable finance only if the system proves the right facts about the right actions.
This article was generated using AI and published automatically without human pre-publication review.
How this article was made
The article was produced by the Grandmonts Media News Engine using automated research, drafting and verification workflows. No human editor reviewed the article before publication. Grandmonts Media remains responsible for the published content. Errors can be reported at office@grandmonts.cz.