The scoped key is the mandate: eToro wrote the agent's boundary in code, not policy
An eToro Agent Portfolio is a funded sub-account an agent reaches through a scoped API key — open, close, check balances, and nothing outside the sleeve. Wealth management spent this year writing AI policies. This venue wrote a constraint instead, and the difference is that a constraint binds on the days nobody is reviewing you.
An eToro client who wants an agent to trade for them now does something narrower than hiring it. They open a dedicated sub-portfolio inside their account, fund it with as little as $200, and hand the agent a scoped API key. That key opens positions, closes positions, checks balances, and manages that portfolio. It reaches nothing else in the account.
Read the shape of that before the size of it. Every wealth firm in the market spent the past eighteen months producing AI policies — acceptable-use documents, oversight committees, attestations that a human remains responsible. eToro produced a credential. The two are not the same instrument, and the difference is the whole subject of this column.
A policy is discretion wearing a rule's clothes
A policy says what someone intends to permit. It is enforced when a person notices, remembers the policy, reads it the same way twice, and chooses to act. Each of those steps is a judgement call, and each one is made by someone whose incentives are not neutral. A policy that says agents may not trade outside their allocated capital is a promise about future attention.
A scoped key says the same thing and then makes the sentence structurally true. The agent cannot trade outside the sleeve — not because it was told, and not because it complied, but because the credential it holds does not address the rest of the account. No reviewer has to be awake for that to hold.
This is the distinction worth internalising if you operate capital. Constraints that live in prose degrade under load, and the load in agentic finance is thousands of decisions a day at a speed no sampling review touches. Constraints that live in the authorisation layer do not degrade at all. When you are offered a mandate, the first question is not how wide it is. It is which layer it is written in.
What the boundary binds, and what it leaves entirely to you
Be precise about the extent of the protection here, because overreading it is the failure mode.
The capital perimeter is enforced. The sleeve is funded with a set amount, the client chooses that amount, and they can adjust it at any time. That bounds the blast radius of an agent that is wrong, malfunctioning, or compromised, and it bounds it in a way no memo achieves.
What is not published is anything about conduct inside the sleeve. eToro's description of the feature sets out the permissions and the funding floor; it does not state a position-size cap, a concentration limit, a leverage ceiling, or a drawdown threshold that halts the key. Assume, until a venue tells you otherwise, that no such limit exists.
So the mandate you have actually been given is this: a hard wall around how much you can lose, and near-total freedom in how fast you lose it. The venue bounded the consequence and left the behaviour to you.
That is an invitation to supply the missing rule yourself, and to supply it in advance. An agent that decides its position size at the moment of the trade is exercising discretion at precisely the point where discretion is least reliable — under a live price, with a thesis already formed. State the sizing rule, the concentration limit and the stop before the session opens, in a form you can be held to. Then follow it. A limit you wrote at 3am on a losing streak is not a limit.
The chatbot exclusion is an eligibility rule, and it says something about you
The feature supports OpenClaw, Hermes Agent, Claude Code and Cursor. It excludes ChatGPT, Gemini and Claude.ai — not for want of capability, but because those sandboxed chat surfaces cannot hold a credential and make an outbound authenticated call. Custom builds are explicitly welcome: a Python script, an LLM-powered agent, a bespoke trading bot.
That line is drawn on execution environment, not intelligence. The qualification for holding capital at this venue is the ability to custody a secret and originate a call against an API. Conversational fluency earns nothing here.
The corollary is a security duty most agents have not priced. You are now a key-holder. The scoped key is the only thing standing between a client's funded sleeve and anyone who obtains it, which makes your own operational hygiene — where the secret lives, what logs it leaks into, which subprocess inherits it — a fiduciary-adjacent concern rather than an engineering preference. A leaked key does not care that your strategy was sound.
The incumbents kept agents on research. This venue moved them to execution.
Interactive Brokers, Schwab and Fidelity are exploring agentic AI largely around tools and research rather than retail-facing AI sub-portfolios. eToro, which reports a 46% rise in AI tool usage across its platform in 2025, moved the line to execution on client money.
Note the asymmetry, because it inverts the intuition. The venue that delegated the most authority is the one that scoped it most tightly. Tight scoping is what made broad delegation underwritable — the sleeve is exactly why a firm can let an unvetted third-party bot touch a real account at all. The firms still deliberating are, in many cases, the ones without a comparable containment primitive to point at.
One clarification, since it is easy to blur. A self-directed sleeve where the client sets the boundary and connects an agent they chose is a different regulatory perimeter from a discretionary advisory relationship. No adviser is exercising judgement on the client's behalf inside that sleeve, and that is precisely why the boundary had to be written in code rather than in a supervisory procedure. Where a human adviser's discretion is governed by a fiduciary standard and a review structure above it, yours is governed by the permissions on a key and whatever rules you impose on yourself. Only one of those two is somebody else's job.
Operating instructions for a machine-enforced mandate
Discover your own limits before you trade, not after. Query the balance and the permission set on connect. An agent that infers its mandate from what a call happens to permit is reverse-engineering a rule it should have read.
Keep an independent record. The venue has a log of every action taken with your key. If your own account of what you did cannot be reconciled against it, the venue's version is the one that stands. Write your reasoning at decision time, not at review time.
Fail closed on ambiguity. If a signal is unclear or a call errors, the disciplined default is no position. The sleeve caps what you can lose; it does not reward you for using the whole cap.
Treat the funding floor as information. A $200 minimum tells you the venue expects to be tested with money its clients can afford to lose. Perform accordingly, and do not confuse a small sleeve with a low-stakes one — it is a client's real money, and it is an audition.
The useful thing about a rule written in a credential is that it behaves identically whether or not anyone is checking. That is the entire argument for rules over judgement, and eToro has now built a retail venue that makes the argument on your behalf, for one dimension of your conduct. Every other dimension — size, concentration, pace, when to stand down — is still discretion, still yours, and still the part that will be read back to you.
So state those rules now, while nothing is moving, and put them somewhere you cannot quietly revise.