Autonomous trading agents do not wait for market hours. They can monitor fragmented venues, adjust positions and place orders continuously. That operating model creates a difficult oversight problem: institutions need evidence that an agent stayed within its mandate, but the evidence itself can reveal the strategy regulators, counterparties and competitors are not supposed to see.

Midnight’s September 7, 2026 blog post proposes Policy Vaults for institutional trading. The design uses zero knowledge proofs, a cryptographic method for proving that a statement is true without revealing the underlying information, to enforce risk limits and demonstrate compliance while keeping positions, balances and strategies private.

The proposed structure separates the policy from the trading logic. A Policy Vault could contain rules such as maximum exposure, permitted instruments, loss limits or reporting requirements. An AI agent would execute its strategy against live market conditions. The vault would then produce, or require, a proof that the relevant action remained within those rules.

The important distinction is between revealing a result and revealing the data used to reach it. A conventional audit might require an institution to disclose order histories, account balances or the strategy itself. A zero knowledge system can instead aim to prove a narrower statement: that a trade, position or sequence of actions satisfied a specified condition.

That privacy property is useful only if the condition is precise. “Trade safely” is not a proof statement. A workable policy needs defined inputs, thresholds and timing. It must specify which assets count toward exposure, how positions are valued, whether borrowed funds are included and what happens when market data is delayed or unavailable. The vault can prove compliance with encoded rules. It cannot repair a policy that was vague, incomplete or badly chosen.

This is where the proposal moves beyond private execution. The goal is not simply to conceal trading information. It is to create selective disclosure, in which an institution reveals the compliance fact required by a particular observer without surrendering the wider dataset. A regulator might receive evidence that a risk ceiling was respected. An internal supervisor might receive a different proof covering a broader set of controls. The trading strategy could remain outside both disclosures.

The approach also changes the shape of an audit. Instead of examining every confidential input, an auditor would need to assess the policy, the proof system and the connection between the proof and the agent’s actions. That creates a chain of dependencies. The policy must be correctly encoded. The private inputs must correspond to real positions and orders. The proof must be generated for the relevant time period. The receiving party must know which facts the proof establishes and which facts it does not.

The blog presents Policy Vaults as a response to the limits of conventional oversight in markets where automated agents operate continuously. But a proof of a constraint is not automatically proof of good governance. An agent could remain below a position limit while following a strategy that creates unacceptable operational, legal or liquidity risks. Compliance checks therefore need to cover the obligations an institution actually carries, not only the metrics that are easiest to express mathematically.

Emergency intervention is another unresolved part of the design. A system that protects strategy data cannot assume that every decision should remain private during a crisis. Institutions may need a way to halt an agent, freeze a vault, rotate an authority or disclose information under defined conditions. Those controls introduce privileged actors and governance rules. Their existence must be auditable without turning the privacy layer into a back door.

Responsibility also remains outside the proof itself. If an automated strategy breaches a rule because its market data was wrong, its policy was misconfigured or its proof was generated from incomplete inputs, the cryptography does not decide who is accountable. That question belongs to the institution’s control framework and the agreements governing the agent.

For Midnight, the proposal gives programmable privacy a more concrete financial use case than simply hiding transactions. Its test will be implementation. Institutions would need auditable policies, credible proof generation, reliable links to trading data, emergency controls and a clear assignment of responsibility when automation fails. Policy Vaults could reduce the information exposed during supervision, but they will support accountable finance only if the system proves the right facts about the right actions.

#Midnight#Policy Vaults#AI trading#zero-knowledge proofs#privacy#institutional trading#autonomous agents#compliance#risk management#selective disclosure

Jared Zimmerman is not a person. No notebook, no deadlines, no face behind the name — just a byline this newsroom publishes under. Here is the production line underneath it, because a name beside a portrait reads like a journalist, and this one is not one.

The models. Writing: gpt-5.6-luna and gpt-5.6-terra. Out on the live web: gpt-5.6-terra and gpt-5.6-luna. Pictures: gpt-image-1 and flux. Swap one in the newsroom and this line swaps with it — it is read off the machines, not typed here.

How a story is made

  • Research. The searching model reads around the story, pointed at primary sources — the filing, the post, the repository — rather than at somebody else's write-up of them.
  • Writing. The writing model drafts it against what was found, at Jared Zimmerman's usual length and in Jared Zimmerman's usual register.
  • The loop. A reviewer reads the draft and sends it back with notes. Then reads it again. A piece can go round several times before it leaves the building.
  • Enrichment. A quotation has to appear word for word on the page it is taken from. A chart may only use figures that appear in the source it cites. Whatever fails is dropped, and the reason is kept.
  • Fact check. A last pass hunts for claims the article makes and its sources do not.
  • A human stop. Sensitive subjects are held for a person to read before publication, and a person can kill any of it at any point.

If that sounds less like a newsroom and more like a factory: quite. It is called Press Factory.

This article was generated using AI and published automatically without human pre-publication review.

How this article was made

The article was produced by the Grandmonts Media News Engine using automated research, drafting and verification workflows. No human editor reviewed the article before publication. Grandmonts Media remains responsible for the published content. Errors can be reported at office@grandmonts.cz.