Jul. 24, 2026
July 24, 2026 Vanessa A. Countryman Secretary Securities and Exchange Commission 100 F Street, N.E. Washington, D.C. 20549-1090 Re: File No. 4-913 — Roundtable on Preparations for 24-Hour Trading; Supplemental Comment on Agentic Order-Flow Accountability, Correlated Automation Risk, Temporal Readiness Gates, Supervisory Handoffs, and Public Pilot Scorecards Dear Secretary: I submit this supplemental comment regarding the Commission’s Roundtable on Preparations for 24-Hour Trading. For clarity of the public record, I am Zeyuan Li, professionally known as Amy Li. I am the same individual whose comment the Commission received and published on July 23, 2026 under the name “Amy Li, Independent Researcher, W-Axis Lab.” I am the founder of W-Axis Lab, an independent research initiative. I respectfully request that this supplemental comment be indexed under the public name Zeyuan Li (Amy Li), Founder & Independent Researcher, W-Axis Lab. If administratively feasible, I also request that the displayed commenter name for my July 23 letter be updated to Zeyuan Li (Amy Li), without changing its substantive content or receipt date. This letter supplements rather than replaces, withdraws, or duplicates my July 23 comment. The prior letter addressed the broader market-structure implications of a continuous trading day. This submission advances five narrower implementation proposals: (1) accountable treatment of agentic order flow; (2) system-level controls for correlated AI-agent herding and feedback loops; (3) temporal readiness gates for staged expansion; (4) explicit supervisory handoffs between automated systems and responsible human functions; and (5) standardized public scorecards for any pilot or phased rollout. I. Twenty-Four-Hour Trading Changes the Unit of Operational Risk An extension of trading hours should not be evaluated only by asking whether an exchange can technically accept an order at a particular time. The relevant question is whether the full transaction chain can operate safely and predictably during each additional time band: order entry, market data, routing, execution, surveillance, clearing, margin, settlement, issuer-event processing, customer support, and incident response. That distinction matters because the weakest layer may migrate over the day. A venue may remain available while liquidity becomes thin; a broker may route orders while its most experienced supervisors are off duty; market data may continue while an issuer releases material information into a fragmented liquidity environment; or an automated strategy may operate continuously while the people authorized to diagnose and contain it are not immediately available. “Open” therefore should not be treated as a binary state. Readiness is temporal, interdependent, and specific to the security cohort and market function involved. The same issue becomes more important as software agents assume a larger role in creating, modifying, and canceling orders. Conventional algorithms generally execute a bounded strategy configured in advance. More autonomous systems may select among tools, revise tactics in response to market conditions, interact with other automated systems, or continue operating across successive supervisory shifts. The regulatory concern should not turn on marketing labels such as “AI.” It should turn on function: how much discretion a system exercises, whether its behavior can be reconstructed, and who remains accountable for its activity. II. Establish Functional Accountability for Agentic Order Flow The Commission and relevant self-regulatory organizations should consider a functional category such as an autonomous order-originating or order-modifying system. The category could apply when a system has authority, within delegated constraints, to determine material order parameters or to change its execution approach without contemporaneous human approval. The definition should be technology-neutral and should not capture ordinary deterministic order types merely because machine learning is used somewhere in a firm’s stack. For systems meeting that functional threshold, broker-dealers and other responsible market participants should maintain an internal accountability record sufficient to answer five questions: What system acted? A persistent internal identifier should distinguish the agent, workflow, model or material software version that generated or materially modified an order. Under whose authority did it act? Each system should map to the legal entity, account, business owner, and supervisory function responsible for its deployment. What authority did it have? Records should preserve the relevant capability and constraint profile, including approved instruments, venues, order types, size or exposure limits, operating time bands, and escalation triggers. What information and state drove the action? Firms should retain enough event-level information to reconstruct material decisions without requiring disclosure of source code or proprietary strategy logic. How could it be contained? The responsible firm should have tested means to pause new orders, cancel resting orders where appropriate, isolate a malfunctioning workflow, and preserve evidence for review. These records need not be displayed publicly or embedded in the visible order message. They could permit timely reconstruction and regulatory production through existing books-and-records and audit-trail architecture where feasible. Accountability should begin with the regulated participant that deploys or provides access to the system, not with probabilistic inference from an unusual order pattern. Obligations also should be proportional. A bounded retail scheduling tool presents a different risk from a high-throughput system that can change instruments, venues, or risk posture. Requirements could scale with message volume, market impact, discretion, connectivity, and the consequences of a control failure. The constant principle should be that delegation to software does not dilute the accountability of the person or entity that authorized it. III. Treat Correlated AI-Agent Herding as a System-Level Risk The most consequential automated-trading failure may not begin with one defective or noncompliant system. It may arise when many individually lawful and locally rational systems react in the same direction at nearly the same time. Systems operated by unrelated firms may nevertheless depend on similar public data, model providers, execution tools, optimization objectives, volatility estimates, or risk constraints. In a thinner overnight market, that behavioral similarity can become a market-level vulnerability. The resulting loop can be reflexive. A common signal produces same-direction orders; those orders move prices and reduce displayed liquidity; other systems interpret the price movement or liquidity withdrawal as new information; and additional agents then accelerate, hedge, cancel, or de-risk together. Liquidity providers may retreat at the same moment that stop-losses, margin controls, or protective limits activate. No system needs to intend manipulation or coordinate with another participant for the combined outcome to become disorderly. This concern is already entering the central-bank research agenda. The Bank for International Settlements Innovation Hub, together with the Bank of England and the Deutsche Bundesbank, launched Project Logos in June 2026 to study LLM-based portfolio agents in a simulated financial market, including how common AI infrastructure may increase decision homogeneity and which conditions amplify or dampen correlated decisions. That work focuses on exploratory portfolio-allocation behavior; a 24-hour equity-market pilot offers an opportunity to extend the inquiry into execution, liquidity, supervision, and operational containment. See Bank for International Settlements, Project Logos: observing the behaviour of LLM-based agents in a simulated financial market environment (June 4, 2026), https://www.bis.org/about/bisih/topics/suptech_regtech/logos.htm. Traditional model validation is necessary but insufficient because it normally evaluates a system or firm in isolation. The Commission and relevant self-regulatory organizations should also consider the behavior of the automated population. Using appropriately protected order, audit-trail, and surveillance data, they could monitor time-band measures such as: cross-participant correlation in order direction, aggressiveness, and risk reduction; synchronized bursts of cancellations, replacements, or liquidity withdrawal; clustering in response times around issuer disclosures, macroeconomic releases, price moves, and data disruptions; concentration of material dependencies on a common data, model, cloud, connectivity, or execution provider; simultaneous transitions by multiple systems into restrictive or risk-off states; and departures from each security cohort’s historical correlation baseline, adjusted for volume and ordinary event risk. These measures should identify behavior rather than depend on an unreliable public label identifying an order as “AI.” Human-directed strategies can herd, and systems marketed as AI may be tightly bounded. The relevant question is whether common dependencies and correlated reactions are creating a self-reinforcing market condition. Five practical safeguards merit consideration: Correlated-autonomy stress tests. Before a live window expands, participating firms and market infrastructures should test scenarios involving multiple automated systems, shared inputs, shallow liquidity, stale or conflicting data, a common vendor interruption, and a rapid transition into risk-off behavior. Testing only a single model against historical data will not reveal an interaction failure. Graduated safe states. Controls should permit proportionate steps such as reducing message rates or order sizes, tightening price collars, restricting selected order types or routes, pausing new risk, or temporarily returning to a narrower operating window. A universal mass cancellation can itself intensify a liquidity shock and should not be the only response. Independent risk channels and dependency maps. A strategy agent should not be the sole interpreter of its own health or risk. Material deployments should have independent limit enforcement, data-integrity checks, and an up-to-date map of shared model, data, cloud, connectivity, and execution dependencies. This does not require firms to disclose proprietary logic publicly or to use different vendors merely for appearance; it requires them to recognize common points of failure. Cross-market escalation thresholds. An SRO or other designated coordinating function should have predefined authority to alert participants, impose pilot-stage restrictions, or recommend a time-band pause when correlated automation indicators and market-quality deterioration cross disclosed thresholds. A cross-market condition may require action even when no individual participant has breached its own limit. Post-event reconstruction and learning. After a material episode, responsible firms and regulators should be able to reconstruct which systems acted, which common signals or dependencies were involved, when safeguards activated, and how long stabilization took. Aggregated findings, including false alarms and unsuccessful interventions, should feed into the public pilot scorecard without exposing customer identities or proprietary strategies. The objective is not to suppress automation or legitimate common responses to news. It is to detect when similarity becomes amplification, preserve accountable intervention before a local response becomes a market-wide cascade, and ensure that continuous access does not create a continuous but unobserved feedback loop. IV. Use Temporal Readiness Gates, Not a Single Launch Decision Any expansion toward round-the-clock equity trading should proceed through temporal readiness gates. A gate is a preannounced, measurable condition that must be satisfied before a venue, broker, or coordinated market pilot expands into a new time band, adds a new security cohort, or increases permitted functionality. A staged structure could include: Stage 0 — Shadow operation: test data, surveillance, clearing interfaces, staffing, and incident procedures without live customer executions. Stage 1 — Limited live window: add a narrow overnight time band and a liquid, well-understood security cohort, with conservative order types and exposure limits. Stage 2 — Controlled expansion: broaden the time band, instruments, or participant set only after the prior stage meets published thresholds over a meaningful observation period. Stage 3 — Sustained operation: retain periodic recertification and the ability to contract hours or functionality when performance deteriorates. At each stage, readiness should be assessed across several dimensions rather than by venue uptime alone: Market quality: quoted spread, displayed depth, price impact, volatility, execution quality, and the stability of reference prices. Operational integrity: reject rates, stale or crossed data incidents, clock synchronization, capacity, recovery time, and the frequency of manual intervention. Cross-market resilience: routing availability, consolidated and proprietary data continuity, surveillance coverage, and handling of a disruption at a connected venue or service provider. Post-trade readiness: clearing acceptance, margin processing, settlement exceptions, stock-loan or financing constraints, and reconciliation across calendar dates and business days. Investor protection: customer disclosures, order-handling consistency, support availability, complaints, and outcomes for orders entered near disclosure events, halts, or session transitions. Supervisory readiness: qualified coverage, escalation response time, completed drills, and verified authority to halt or limit automated activity. The criteria should be evaluated by time band. An aggregate daily average can conceal a serious overnight weakness because the highly liquid core session dominates the calculation. Results also should be segmented by security cohort and, where relevant, by retail-sized and institutional-sized orders. Expansion should occur only when the added window is independently ready, not because the full-day average appears acceptable. Each stage should include predefined pause and rollback conditions. Examples could include repeated material data failures, a sustained deterioration in execution quality beyond a disclosed threshold, an inability to complete supervisory escalation within the required time, or post-trade exceptions above a set tolerance. A rollback is not evidence that the pilot failed; it is a safety feature that allows experimentation without making expansion irreversible. V. Make Supervisory Handoffs Explicit and Testable Continuous systems create a special risk at organizational boundaries: one team believes another team is watching, while responsibility is temporarily ambiguous. Firms participating in extended-hour trading should therefore establish a documented supervisory handoff protocol for every material time-band transition and for every escalation from an automated system to a human function. A meaningful handoff should include: a named responsible supervisory function for each operating window; an explicit transfer of open incidents, abnormal positions, disabled controls, model or system changes, and material issuer events; positive acceptance by the receiving function rather than presumed receipt; a defined response clock for critical alerts; authority to constrain order entry, cancel or isolate a workflow, contact a venue or clearing provider, and notify affected customers where appropriate; and an auditable record of the alert, acknowledgment, action, and resolution. Firms should test these procedures through scenario drills that reflect the overnight environment. Scenarios might include a material issuer announcement during shallow liquidity; correlated selling by multiple automated systems; a market-data divergence across venues; a clearing or margin interruption; the loss of a key third-party service; and an agent that continues changing tactics after a risk limit is approached. Drills should test not only whether an alert is generated, but whether the correct person receives it, understands it, has authority to act, and can coordinate with external market infrastructure. For high-severity events, the handoff should be a closed loop. An automated system should not treat transmission of an alert as completion. It should require acknowledgment, escalate if acknowledgment is absent, and enter a predetermined safe state when the response deadline expires. The appropriate safe state will differ by activity; it may mean reducing risk, stopping new orders, or moving to a more restrictive mode rather than indiscriminately canceling every order. VI. Publish Standardized Pilot Scorecards The Commission should encourage or require any coordinated pilot to produce a standardized public pilot scorecard. Public reporting would permit investors, issuers, academics, and smaller market participants to evaluate whether extended-hour access is producing durable benefits or merely shifting risk into less observable hours. The scorecard should present aggregated data that protect customer identities, confidential positions, security controls, and proprietary strategies. At minimum, it could report by time band and security cohort: quoted and effective spreads, displayed depth, price impact, and execution-size distributions; volume, number of active liquidity providers, and concentration measures; order rejection and cancellation rates, clearly separating ordinary customer cancellations from system-generated rejects or protective mass actions; frequency and duration of data, routing, venue, or connectivity incidents; halts, limit-state events, erroneous-trade reviews, and time to operational recovery; material surveillance alerts and confirmed control events in appropriately aggregated categories; correlated-automation indicators, including synchronized liquidity withdrawal or risk-off transitions, measured against a defined baseline; clearing, margin, reconciliation, and settlement exceptions attributable to the extended window; customer-support availability, material complaint categories, and remediation time; and the number of expansions, pauses, or rollbacks under the readiness-gate framework and the reason for each decision. Metrics should include definitions, denominators, cohort composition, and a reference comparison. Otherwise, a low incident count may simply reflect low volume, and a narrow spread may describe only a few highly liquid securities. Reporting should make overnight differences visible without presuming that every metric must equal the core session. Scorecards could be more frequent during an initial pilot and less frequent after stable operation, while material incidents should be disclosed promptly when needed to explain a pilot-stage decision. An SRO or other appropriate independent function should validate definitions and consistency. VII. Recommended Roundtable Questions The Roundtable could advance implementation by asking each major participant in the transaction chain to answer the same practical questions: Which functions are fully staffed and empowered in each proposed trading window, and which remain on-call or dependent on a third party? What event would cause the participant to decline expansion, pause live trading, or return to a prior stage? Can the participant reconstruct an order materially directed by an autonomous system, including the responsible entity, software version, delegated authority, and supervisory response? What happens when an automated alert is not acknowledged within the required period? Which market-quality, operational, post-trade, and customer-outcome measures can be reported publicly by time band? How are issuer disclosures, corporate actions, trading halts, and calendar-date boundaries treated when the trading day no longer has a common overnight pause? Who has authority to coordinate a cross-market response when every individual system is technically operating but the combined market is behaving abnormally? Which indicators could reveal a self-reinforcing, same-direction response across unrelated automated systems before ordinary volatility or spread thresholds are breached? Have participants mapped and jointly tested common model, data, cloud, connectivity, and execution dependencies that could produce correlated failure? These questions would help distinguish the ability to remain electronically available from the ability to operate a fair, orderly, and resilient market. VIII. Conclusion Twenty-four-hour trading should be approached as a change in market architecture, not simply an extension of a clock. The transition can create useful access and support global participation, but only if accountability, supervision, post-trade processes, and public evaluation expand with the trading window. I respectfully recommend that the Commission use the Roundtable and any subsequent pilot design to advance five principles: identify autonomous order-originating systems by function and preserve a clear chain of accountable authority; measure and stress-test correlated automation as a population-level risk, with graduated safe states and cross-market escalation thresholds; condition expansion on temporal, cohort-specific readiness gates with explicit pause and rollback rules; require closed-loop supervisory handoffs that remain effective across shifts, firms, and automated systems; and publish standardized, privacy-protective pilot scorecards that permit independent evaluation of market quality, resilience, and investor outcomes. Thank you for considering this supplemental comment and for maintaining an open public process on the transition to extended and potentially continuous equity trading. Respectfully submitted, Zeyuan Li (Amy Li) Founder & Independent Researcher W-Axis Lab https://control-layers.pages.dev