Should You Let a General AI Agent Trade for You? 5 Risks to Know First

AI agents can now browse, write code and run it for you. So it was only a matter of time before people started asking general assistants such as Grok, Meta’s Muse or the open-source OpenClaw to build a trading bot and let it run. It feels like magic: describe an idea in a chat, and a few minutes later a script is placing orders.

General assistants are very good at many things. Running your money unattended is not one of them. This post covers what actually happens when you ask a general AI agent to build a trading bot, the five ways it tends to go wrong, and how to use AI for trading without those risks.

What a General Agent Does When You Ask for a Trading Bot

Ask a general agent to “build me a bot that buys when RSI drops below 30” and it does what it does for any task. It writes a script, asks for your exchange API keys, and runs the script wherever it can: your laptop, a cheap cloud server, or its own sandbox. Some agents decide each trade in the chat itself, reading the market and calling the exchange as they go.

Either way, three things are true. The strategy was never tested. Your keys now live wherever the agent put them. And the bot only runs while that machine, session or subscription keeps running.

Risk 1: Your Exchange Keys End Up Where You Can’t See Them

To place orders, the bot needs your exchange API keys. A general agent usually puts them in a file next to the script, often as plain text, or passes them to a third-party “skill” that knows how to talk to your exchange.

This is not a theoretical problem. Security researchers found more than 30,000 OpenClaw installations exposed on the internet, most of them open to authentication bypass and giving access to the API credentials stored inside. A supply-chain campaign dubbed ClawHavoc planted hundreds of malicious skills on OpenClaw’s marketplace, many disguised as crypto trading tools, that requested exchange keys and sent them to attackers (IBM X-Force, Hive Security).

Even without an attacker, keys copied into chat logs, scripts and cloud folders are keys you no longer control.

Risk 2: Nothing Gets Tested Before Real Money

A general agent trades today’s best guess. It does not run your rules against years of history first, and it does not check whether the rules still work on data they were not tuned on.

That matters because almost any idea looks good on the stretch of market it was invented on. Researchers Bailey and López de Prado showed how easily a strategy can be fitted to noise, a problem known as backtest overfitting. Without a backtest and an out-of-sample check, you find out whether the idea works by losing or making real money.

Risk 3: The Bot Stops When Its Machine Does

A script on your laptop stops when the laptop sleeps. A script on a cheap server stops when the server restarts, the token expires or an error goes unhandled. An agent that trades from its own session stops when the session ends.

The dangerous part is what is left behind. The bot bought, then went quiet, and nothing is watching the open position. “It bought but never sold” is one of the most common ways these experiments end, and you usually discover it from your balance, not from an alert.

Risk 4: The Same Market Can Get a Different Decision

Language models are built to produce varied, natural answers. Ask the same question twice and you can get two different responses. That is fine in a conversation. It is a problem for an entry rule.

If an agent decides each trade in the moment, you cannot say what it will do next time the same setup appears, and you cannot test it, because there is no fixed rule to test.

Risk 5: Bugs Nobody Reviewed

Agent-written code ships without review. A wrong order size, a loop that re-submits orders, or a stop-loss that never triggers looks fine until the market finds it. In one widely reported case, an autonomous agent built on OpenClaw crashed, lost track of its own wallet and, while trying to send a small donation, transferred about 5% of a token’s entire supply, worth hundreds of thousands of dollars at the time (CCN).

Where General AI Agents Do Help

None of this means AI has no place in trading. General assistants are excellent at explaining indicators, researching an idea, summarising news and turning a vague thought into clear rules. Some broker integrations also take a careful approach. Grok’s connection to Interactive Brokers, for example, drafts orders but requires you to confirm every one before it is sent (Basenor).

The problem starts when the same assistant is asked to hold your keys, skip testing and run unattended.

A Safer Way to Use AI for Trading

Split the job in two. Let the AI do what it is good at, and let a dedicated trading engine do the rest:

  1. Use AI to turn the idea into fixed rules. Entry, exit, position size, timeframe. Rules you can read and that behave the same way every time.
  2. Backtest the rules on years of data, including fees and slippage.
  3. Check them on data they have never seen with walk-forward testing, so you know whether the edge survives outside the sample.
  4. Keep your exchange keys away from the AI. Store them with the platform that executes orders, not in a script or a chat.
  5. Run the strategy on infrastructure built to stay up, with stop-loss and take-profit handled by the engine, so exits still happen if the AI is offline.

How Arrow Algo Handles It

Arrow Algo was built around that split. You describe your idea to Artemis, our AI copilot, or connect your own AI such as Claude, ChatGPT or Grok through our MCP server, and the idea becomes a strategy made of fixed, readable blocks.

From there:

You stay in control: you decide what goes live, and you can stop a strategy at any time.

A Quick Checklist Before Any AI Touches Your Money

If you cannot answer all five, the bot is not ready for real money.

Arrow Algo is software for building, testing and running trading strategies. It does not provide financial advice. Backtests are simulations on historical data, and past results do not guarantee future results. Trading involves risk.