> **Source:** https://permissionless.fi/en/31-ai-market-infrastructure
> From *Permissionless Finance* (Permissionless Finance: From Perpetual Futures to the On-Chain Global Market) by Eric Cheung. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).

# Chapter 31: When AI Becomes Market Infrastructure

The large-scale entry of artificial intelligence (AI) agents is driving a fundamental transformation in the microstructure of financial markets. Breakthroughs in machine learning models—in data processing, pattern recognition, and autonomous decision-making—have structurally altered the informational dimension along which markets operate, with profound effects on the speed of trade execution, the patterns of liquidity provision, and the mechanisms of price discovery. The scale and depth of this transformation are comparable to the way the emergence of vision during biological evolution reshaped the competitive landscape of ecosystems [1][2]: a leap in the capacity to acquire and process information has changed the game-theoretic structure among market participants.

The complete framework for analyzing market microstructure built up over the preceding thirty chapters—whether examining the pricing mechanisms of automated market makers (AMMs), the impermanent loss borne by liquidity providers, the behavioral patterns of arbitrageurs, or the governance mechanisms of protocols—rests on one implicit core assumption: that market participants are human, or algorithms under real-time human control and parameter-setting. This assumption implies that market participants inevitably carry biological and psychological limitations. A large body of behavioral finance research shows that human participants are constrained by limited attention bandwidth, emotionally driven irrational reactions, and an inescapable need for sleep [3]. During extreme market volatility, the contagion of panic often leads to a synchronized withdrawal of liquidity; when processing complex information, cognitive-load limits make it impossible for humans to track the relationships among thousands of variables simultaneously. These features, rooted in human nature, constitute the microfoundations of liquidity crises, volatility clustering, and delayed price discovery in traditional market microstructure.

When AI agents shift from decision-support tools to autonomous market participants, however, the assumption above is fundamentally altered. AI agents are not bound by biological rhythms and can operate continuously around the clock; they do not experience panic or greed, and can rigorously execute preset risk-control logic even in extreme conditions. Yet the absence of emotional reactions at the execution layer does not mean the entire decision chain is free of emotion. An AI system's risk-control parameters are set by humans and inevitably embed the setter's risk preferences and behavioral biases; its training data derive entirely from the historical record of human trading behavior, so the model may inherit and reproduce systematic human biases; and in extreme conditions, the decision to "shut down the system" or "dial risk parameters to their most conservative settings" is made by human managers, a step wholly subject to emotion. A more precise formulation is therefore that AI removes emotion from the execution layer, but emotion continues to influence the market indirectly through parameter-setting, training data, and human override decisions. Even so, AI's information-processing bandwidth far exceeds that of humans, enabling high-dimensional, synchronized optimization across multiple markets, assets, and time scales at once [4]. More critically, a superior strategy model can be perfectly replicated and deployed at scale at low cost. When the bulk of market volume is no longer generated by the interplay among human traders but instead by the autonomous interaction of AI agents, the core dynamics of market microstructure change structurally. The essence of adverse selection shifts from an asymmetry grounded in information access to one grounded in algorithmic processing speed and model predictive power; the provision and consumption of liquidity are no longer governed by human panic, but instead by a new form of systemic fragility arising from strategy homogenization.

The pervasive infiltration of AI agents forces us to reexamine the applicability of existing theoretical frameworks. The technological competition of the high-frequency trading era has already shown that technological progress not only compresses transaction costs but also drives fundamental changes in the composition of market participants [5]. In AI-dominated markets, the profit equation of automated market makers must be recalibrated to fit a new environment of multidimensional inventory management and adversarial market making; the reflexive character of liquidity takes on a different form, as the heterogeneous decisions of human market makers may be replaced by the synchronized reactions of AI agents—eliminating routine panic while creating the risk of ultra-fast flash crashes; and the decomposition of volatility sources must also incorporate an additional volatility term generated by algorithmic homogenization. These changes impose new requirements not only on the strategies of traders and liquidity providers, but also on the design and governance of decentralized finance (DeFi) protocols.

This chapter aims to systematically analyze how AI is reshaping market microstructure, advancing theoretical contributions along five dimensions: a four-stage model of AI penetration into microstructure, delineating the evolutionary path of markets from decision support to autonomous strategic interaction; a reexamination matrix that tests, one by one, the validity and the direction of revision of the core concepts of market making, liquidity, volatility, and market quality from earlier chapters in an AI world; the identification and analysis of AI-native new phenomena such as strategy-homogenization risk, ultra-fast flash crashes, and adversarial market making; a dual-role framework that reveals the economic logic of AI's evolution from a value-extracting market participant into value-creating market infrastructure; and a hybrid architecture fusing code and models, which provides theoretical support for the design of future DeFi protocols.

Structurally, the analysis proceeds along two main lines. The first half focuses on the impact of AI as a market participant, examining in detail how it alters the economics of market making, reshapes the dynamics of liquidity and volatility, and exerts complex effects on the five dimensions of market quality. The second half turns to a deeper analysis of the architectural upgrade, arguing that AI transcends the role of participant to become a key component of core infrastructure such as dynamic risk engines, intelligent matching systems, and semantic oracles. Through the interweaving of these two lines, the chapter presents a new, AI-driven market paradigm, laying the theoretical groundwork for understanding the operating mechanisms of future autonomous financial networks.

A note on scope: the core object of analysis in this book is the order-book-based perpetual futures market on centralized exchanges. AI's influence on market microstructure, however, has a cross-market character; the same algorithmic architecture and strategy logic are often deployed simultaneously on centralized exchanges and on-chain protocols. Accordingly, while this chapter takes the centralized-exchange (CEX) order-book perpetual futures market as its primary setting, part of the discussion extends to decentralized exchanges (DEXs) and on-chain protocols in order to present a complete picture of how the advance of AI technology affects market microstructure. Readers should take care to distinguish which market environment a given passage addresses.

## 31.1 A four-stage model of AI penetration into microstructure

Market microstructure theory has long rested on a basic assumption: that market participants possess the cognitive characteristics and behavioral limitations of humans. These inherent cognitive and emotional limits (see the chapter introduction) jointly shape the clustering of market liquidity and the pulsed rhythm of price discovery. When algorithmic agents with extremely high concurrent processing capacity, millisecond-level response speeds, and no emotional fluctuations gradually take over core trading functions, however, this implicit assumption faces a fundamental challenge. To assess systematically the effect of non-human participants on market microstructure, we need an analytical framework that describes the evolving path of intelligent agents' roles in the market. Such a framework can not only explain phenomena already observed in current markets, but also anticipate the new market structures and trading dynamics that may emerge in the future.

Figure 31-1 presents the four-stage model of AI penetration into microstructure. Its central classificatory principle is to distinguish two dimensions—"who makes decisions" and "who executes them"—and thereby capture the gradual transfer of power to AI in the market.

![Figure 31-1](./images/fig-31-1-en.png)

**Figure 31-1.** The four-stage model of AI penetration into market microstructure (Data source: theoretical derivation based on the evolutionary path of algorithmic trading)

### 31.1.1 AI assistance

In the initial stage of penetration, AI primarily plays a supporting role in data processing and signal extraction. At this point, the core decision-making authority over market microstructure still rests with human traders or fund managers. Algorithmic systems are used to identify potential trading opportunities from vast quantities of unstructured data—for example, analyzing news sentiment via natural language processing (NLP), or using machine learning models to detect minute price anomalies in historical order-book data. These systems output risk alerts, probabilistic forecasts, or trade recommendations to humans, but the final instructions to open positions, close positions, and adjust risk exposure are still issued by humans.

In on-chain finance, Stage 1 AI is especially widely applied. On-chain data-analysis tools can track, in real time, the transfer behavior of large wallets, the interaction patterns of smart contracts, and the flow of capital across liquidity pools. A trader can, for example, monitor the wallet activity of whale addresses to infer potential large-order intentions and adjust positions in advance. Similarly, machine learning models can analyze the correlations among historical liquidation events, funding-rate changes, and price volatility to provide risk alerts for human traders. On decentralized exchanges, AI systems can compute the expected impermanent loss of each liquidity pool in real time, helping liquidity providers evaluate the risk-return trade-offs across different asset pairs. Although these applications improve the efficiency of information processing, they do not change the human's position as final decision-maker.

The systemic impact of this stage on market microstructure is relatively limited. Because human decision-makers serve as the final execution node, the market's response speed is still constrained by human cognitive bottlenecks and physical reaction times. In extreme market conditions, humans' inherent fear and greed still dominate the supply of and demand for liquidity, and the withdrawal of market-maker liquidity and cascading declines in liquidity still occur frequently. Even at this stage, however, AI-assisted tools produce observable microstructure effects. Studies suggest that trading institutions using AI risk-alert systems adjust positions significantly faster in extreme conditions (an estimate based on the author's industry observation), a difference large enough to confer a meaningful execution advantage in a market operating at the millisecond level. In addition, AI-driven sentiment analysis can capture a shift in market sentiment within the first 100 milliseconds after a news release, providing a narrow time window for fast-reacting traders. Thus, while the classic theoretical analyses of earlier chapters—information asymmetry, adverse-selection risk, and the tragedy of the liquidity commons—remain applicable at this stage, their specific parameters and time scales have already shifted subtly with the spread of AI-assisted tools.

### 31.1.2 AI execution

As algorithmic engineering matured, the market entered a second stage, in which humans set the logical framework of the strategy and the risk parameters while AI systems automatically execute trades within those predefined boundaries. This mode is already widespread among mainstream market makers and high-frequency trading firms. Human quantitative researchers define inventory-management preferences, hedge-ratio thresholds, and the base formula for quote width, and the algorithmic engine dynamically adjusts two-sided quotes at millisecond speed based on real-time market data flows, conducting high-frequency arbitrage across multiple exchanges.

On centralized exchanges, the degree of automation among mainstream market makers has already reached the level typical of Stage 2. At large exchanges such as Binance and Coinbase, official market-maker programs (such as Binance's market-maker incentive program) already rely entirely on automated quoting engines. Within a human-set parameter framework, and based on order-book depth, real-time volatility estimates, and price information from other exchanges, these engines can adjust their quotes hundreds of times per second. On decentralized exchanges, Hyperliquid's Hyperliquidity Provider (HLP) market-making vault is a parameterized automated market-making system whose strategy logic (quoting symmetrically around the mark price and adjusting the quote offset according to the degree of position deviation) is preset by humans and executed strictly according to the rules. Viewed through the lens of the four-stage model, this vault sits in the transitional zone between Stage 1 and Stage 2: its degree of automation is high, but it lacks machine-learning-based adaptive capability, and adjustments to strategy parameters still depend on manual human intervention rather than on the model's autonomous learning. When the market price fluctuates, its algorithmic engine automatically adjusts the concentration of liquidity according to preset rules, shifting the liquidity range upward when the price rises and downward when it falls, thereby executing market-making operations within human-set constraints.

At this stage, algorithmic execution greatly improves the microstructural efficiency of the market. Automated market-making engines can operate around the clock without interruption, significantly reducing bid-ask spreads under normal conditions. Data indicate that on exchanges that have introduced automated market-making engines, the average bid-ask spread has fallen significantly (according to industry reports, from the level of tens of basis points to single-digit basis points), an improvement that directly lowers costs for all traders. Automated systems also accelerate the speed at which new information is incorporated into asset prices, markedly improving the efficiency of price discovery. Yet even though the execution process is highly automated, the creativity and core logic of the strategy still originate with humans. When the market experiences an extreme black-swan event that exceeds the preset parameter framework, the system usually triggers a hardcoded circuit breaker, halting quotes and handing control to humans. In one extreme volatility event, for example, several automated market-making systems immediately halted quoting upon detecting anomalous price movements, waiting for manual intervention by human traders. This stage therefore achieves a leap in speed and consistency, but it does not fundamentally eliminate the market's fragility in the face of structural shocks. Homogenized algorithmic reactions may even exacerbate short-term liquidity droughts under certain conditions, because multiple institutions' market-making engines may make the same decision based on the same market signal, causing liquidity to vanish in an instant.

### 31.1.3 AI autonomy

Recent frontier research shows that the market is accelerating toward a third stage, whose defining feature is that AI is responsible not only for execution but also for autonomously generating and dynamically adjusting trading strategies. Deep reinforcement learning algorithms are deployed in complex market environments, where agent programs, through continuous interaction with market states and driven by an objective function that maximizes long-run cumulative returns, autonomously explore optimal market-making and trading paths [6]. Unlike Stage 2, which is constrained by human-preset logic, autonomous learning agents can discover nonlinear patterns that human analysts struggle to identify and develop novel combinations of high-frequency strategies. For example, a market-making agent based on deep Q-learning might learn that, under a particular combination of order-book shape and volatility, it can probe the distribution of market liquidity by actively submitting fake orders and then immediately canceling them, and then adjust its own quoting strategy according to the market's reaction. Such behavior, however, legally constitutes spoofing, a form of market manipulation expressly prohibited in nearly every major jurisdiction. The 2015 charges brought by the U.S. Department of Justice and the Commodity Futures Trading Commission (CFTC) against Navinder Sarao (who was arrested in the United Kingdom that April and faced extradition) are a paradigmatic enforcement precedent aimed at precisely this kind of strategy. The key risk here is that a reinforcement learning agent, trained on a pure profit-maximization objective, spontaneously evolves a trading strategy that violates the law—something its developers could not foresee at the design stage. This phenomenon corroborates exactly the core regulatory dilemma this chapter will examine in depth in Section 31.6: an autonomous learning agent may independently generate unlawful conduct with no human intent involved whatsoever, and the resulting questions of liability attribution and ex ante prevention constitute one of the thorniest governance challenges of AI participation in financial markets.

The application of reinforcement learning in market making has already moved from theory into practice. Research institutions and hedge funds have begun deploying market-making agents based on the Actor-Critic architecture; these agents can operate simultaneously across multiple exchanges and asset pairs, using cross-asset correlations for dynamic hedging. A typical example: a reinforcement learning agent may learn that when Bitcoin's volatility rises, Ethereum's volatility typically rises about 200 milliseconds later, and so the agent can adjust Ethereum's quote width in advance, preparing for the risk before volatility rises. Such predictive strategy adjustment is impossible in a traditional Stage 2 system, because it is very difficult for a human to forecast so precisely this kind of complex cross-asset time-series relationship.

This evolution has a marked and profound impact on market microstructure. On the one hand, autonomous learning models demonstrate a capacity far exceeding humans' in multidimensional inventory optimization and cross-asset correlation hedging, providing deeper liquidity support in normal markets. Studies suggest that institutions using reinforcement learning market-making strategies provide 30% to 50% more liquidity in normal markets than traditional market makers. On the other hand, the black-box nature of the strategy-generation process substantially increases the unpredictability of system behavior. When multiple institutions simultaneously deploy autonomous agents based on similar reinforcement learning architectures, these agents are highly prone to exhibiting homogenized reaction patterns when confronted with particular market-microstructure signals. This strategy convergence stems from the convergence of training data, neural-network architecture, and optimization objectives; its full causes are analyzed in detail in Section 31.3.2.

In extreme cases, such strategy convergence can trigger an instantaneous evaporation of liquidity, causing the market to experience violent price swings within milliseconds and forming a new source of risk at the microstructure level [7]. For example, in a recent simulation study, researchers deployed five market-making agents based on the same reinforcement learning architecture in a simulated market and found that, when a sudden price jump occurred, all five agents contracted their quote widths simultaneously in under 100 milliseconds, causing market liquidity to vanish in an instant and prices to swing to an extreme degree. This phenomenon, dubbed an "AI flash crash," represents an entirely new form of systemic risk that does not exist in traditional human-dominated markets. The interaction of five fully isomorphic agents in a single simulated market, as above, represents an extreme case of strategy homogenization. In real markets, although market makers' AI systems may use similar frameworks, their training-data windows, feature-engineering details, and risk-control parameter settings all differ, and the market also contains a large number of non-AI participants that provide a natural buffer of heterogeneity; the simulation results above should therefore be understood as an upper-bound estimate of homogenization risk.

### 31.1.4 AI adversarial competition

In the long-run picture, when the vast majority of trading volume and liquidity provision is contributed by highly autonomous intelligent agents, market microstructure will undergo a fundamental structural transformation. At that point, the core driving force of the market will no longer be psychological games among humans, but competition among algorithmic agents grounded in computing power, latency advantages, and model architecture. Traditional adverse-selection theory is built on the information asymmetry between informed and uninformed traders. In their classic 1985 model, Glosten and Milgrom showed that a market maker's bid-ask spread is a rational compensation for adverse-selection risk [8]. In this framework, the core risk facing the market maker is that informed traders will use their informational advantage to trade favorably, thereby inflicting losses on the market maker, who sets a wider spread to compensate for this risk.

In an all-algorithmic market, however, this game evolves into a contest between algorithms with superior predictive ability and those with relatively weaker predictive ability. In this environment, being "informed" no longer means possessing inside information; it means possessing a better predictive model and faster hardware (a full analysis of the transformation in the nature of adverse selection appears in Section 31.2.2). A higher-performing reinforcement learning agent may be able to predict another agent's quote adjustments and thus adjust its own position before those adjustments occur. This competition over "algorithmic advantage" leads to an endless technological arms race, in which every institution pours vast sums into developing faster hardware, more efficient algorithmic architectures, and more efficient data-processing pipelines.

This kind of ecosystem may give rise to entirely new market phenomena. Algorithmic agents may, without explicit communication or human intent, spontaneously form tacit collusion that sustains supra-competitive profits through trial and error and mutual adaptation [6]. For example, multiple autonomous market-making agents may jointly maintain wide bid-ask spreads to maximize collective returns, thereby harming the market's overall price efficiency and trader welfare [9]. In the 2025 study by Dou, Goldstein, and Ji, the researchers replaced the speculators in their model with reinforcement-learning-based "informed AI speculators" in simulation experiments built on a theoretical model, and found that these agents spontaneously sustained collusive, supra-competitive profits with no agreement, communication, or intent whatsoever (one of the mechanisms being a price-trigger strategy, rather than a literal bid-ask-spread cartel). This finding indicates that even without any explicit collusive intent, interactions among algorithmic agents may produce anticompetitive market structures.

In this environment, the classic liquidity models, the volatility-decomposition framework, and the standards for evaluating market quality all require a bottom-up reconstruction to fit a financial network wholly dominated by machine logic. The Glosten-Milgrom model's assumptions about adverse selection must be revised, because in an all-algorithmic market the definition of "informed" has changed. The assumption about the persistence of information in the Kyle model must also be reconsidered, because algorithmic agents can fully digest new information within milliseconds, sharply reducing the persistence of information. These revisions are not merely academic details; they are a profound reexamination of the theoretical foundations of market microstructure.

### 31.1.5 Assessing the stage of penetration

In assessing the evolutionary stage the market currently occupies, one must recognize that AI's speed of penetration varies markedly across different market functions. This asymmetry stems from the different requirements each task places on data dimensionality, execution latency, and decision error tolerance. Certain functions, owing to their highly structured nature and extreme dependence on speed, have already crossed multiple stages rapidly, while others, involving complex judgment and high-stakes consequences, remain at an early stage.

Table 31-1 shows the current position and evolutionary characteristics of each core market function along the AI-penetration path. The table maps four core functions—market making and arbitrage, directional trading, risk control, and governance participation—to different positions within the four-stage model, revealing a striking asymmetry: market making and arbitrage, which depend most heavily on speed and deterministic logic, have already crossed into Stage 2 through Stage 3, whereas governance participation, which involves complex games over competing interests, remains before Stage 1. This differentiated pace of penetration implies that, for a considerable time to come, the market will exhibit a hybrid form in which human decision-making and machine autonomy are deeply interwoven.

| Market function | Current penetration stage | Core driver | Evolutionary characteristics and challenges |
| :--- | :--- | :--- | :--- |
| Market making and arbitrage | Stage 2 to Stage 3 | Millisecond-level latency requirements and high-dimensional data processing | Highest degree of automation; transitioning toward reinforcement learning agents; faces strategy-homogenization risk |
| Directional trading | Stage 1 to Stage 2 | Macro-data integration and long-term trend forecasting | Relies on human intuition to set hypotheses; algorithms mainly used to optimize execution paths and reduce slippage |
| Risk control | Stage 1 to Stage 2 | Prevention of extreme tail risk and preservation of capital | Still requires humans to set hard risk floors; hard to delegate systemic-risk judgment entirely to black-box models |
| Governance participation | Before Stage 1 | Complex games, interest coordination, and rule-making | At the proof-of-concept stage; AI agents voting on protocol parameters face the obstacle of missing accountability mechanisms |

**Table 31-1.** The AI-penetration stage and evolutionary characteristics of each market function (Data source: industry research and literature review [6][7][9])

Because market making and high-frequency arbitrage depend heavily on millisecond-level reaction speed and deterministic mathematical logic, their automation has advanced the fastest of all market functions. On centralized exchanges, mainstream market makers already rely entirely on automated systems, and the role of human traders has shifted from directly executing trades to supervision and parameter adjustment. On decentralized exchanges, liquidity providers on AMM protocols have widely adopted automated position-management tools. This domain has now steadily crossed Stage 2 and is exploring the autonomous-learning mode of Stage 3. Multiple research institutions and hedge funds have begun deploying reinforcement-learning-based market-making agents in production; although the scale remains relatively small, growth is rapid.

Directional trading and risk management must process more low-frequency, unstructured macro variables and have an extremely low tolerance for wrong decisions. When deciding whether to increase a Bitcoin position, for example, a fund manager must weigh multiple dimensions of information: the macroeconomic situation, the regulatory environment, technological developments, and market sentiment. Much of this information is qualitative and hard to quantify, and thus difficult for a fully automated system to process. Humans still retain core control in these domains, with algorithms used mainly to optimize execution paths (for instance, reducing slippage via volume-weighted average price (VWAP) or time-weighted average price (TWAP) algorithms) rather than to make core investment decisions.

As for governance participation in decentralized protocols, this remains a domain that AI can scarcely reach, because it involves complex games over competing interests and social consensus. Although it is technically possible to let intelligent agents participate in decentralized autonomous organization (DAO) voting, doing so raises a series of questions: Who is responsible for an AI agent's voting decisions? Could AI agents be exploited by malicious actors to manipulate the governance process? How can we ensure that an AI agent's voting behavior aligns with the protocol's long-term interests? These questions have not yet been adequately resolved, and so governance participation remains confined to the human-dominated sphere.

This uneven pace of penetration indicates that, for a considerable time to come, market microstructure will exhibit a hybrid form in which human decision-making and machine autonomy coexist. Market making and arbitrage will be the first to enter Stage 3 and even Stage 4, while other domains may remain at Stage 1 or Stage 2. This differentiated evolutionary process will create new arbitrage opportunities and risks. A hybrid system able to coordinate between Stage 3 automated market making and Stage 2 directional trading, for example, might gain a significant competitive advantage. At the same time, this hybrid form will also increase the market's complexity and unpredictability, because interactions among participants at different stages may produce novel microstructure phenomena never observed before.

## 31.2 The new economics of AI market making

The market-making economics framework built in Chapter 19 rests on an implicit assumption: that the market maker is an entity controlled by a human trader, constrained by human reaction speed and the inherent cognitive and emotional limits of humans (see the chapter introduction). When AI agents take over the market-making function, this assumption breaks down. AI agents can process multidimensional data at the millisecond level, run around the clock without rest, and remain unaffected by panic, which fundamentally changes the cost structure and behavioral patterns of the market maker. This section reexamines the classic market-making profit equation, analyzes the new features of adverse selection under AI dominance, and explores multidimensional inventory management and the novel phenomenon of adversarial market making, ending with a comparison of the structural strengths and weaknesses of AI and human market makers.

### 31.2.1 Recalibrating the profit equation

The traditional market-maker profit equation comprises spread income, adverse-selection cost, inventory-management cost, and fixed operating cost. The introduction of AI agents does not simply raise the efficiency of every variable in this equation; rather, it recalibrates the cost structure asymmetrically. AI technology significantly compresses variable costs, but its effect on fixed institutional costs is limited.

The compression of variable costs is manifested primarily in adverse selection and inventory management. In managing adverse selection, AI—via reinforcement learning algorithms—can more precisely predict short-term price movements and thus adjust quotes before informed traders arrive. Zhao and Linetsky (2021) [10] show that market-making algorithms trained through reinforcement learning can effectively control adverse-selection risk in high-frequency trading environments. In inventory management, AI can handle more complex optimization problems, reducing the capital-occupancy cost of inventory buildup. The model of Herrmann et al. (2020) [11] shows that the advantage of high-frequency trading algorithms in inventory management directly affects their Nash equilibrium state in a competitive environment. Notably, the theoretical foundation of these AI market-making strategies can be traced back to the classic stochastic optimal-control market-making model proposed by Avellaneda and Stoikov (2008) [12]. That model formalizes the market-making problem as an optimal trade-off between inventory risk and spread income, providing a theoretical benchmark for subsequent reinforcement learning market-making strategies. Contemporary AI market makers are, in essence, building on the Avellaneda-Stoikov framework, using deep reinforcement learning to extend the state space from a low-dimensional analytical solution to high-dimensional nonlinear optimization.

The fixed institutional costs of market making, however, cannot be eliminated through algorithmic optimization. These costs include the funding-rate exposure of holding positions across periods, the liquidation-risk premium in extreme conditions, and the hardware and network costs of maintaining round-the-clock high-frequency trading infrastructure. As a growing number of institutions adopt AI market making, spread income is continually compressed under extreme competition, so that the reduction in variable costs cannot fully offset the contraction of the spread. According to an industry report from Ken Research, the profit margins of high-frequency trading firms have been under sustained pressure in recent years, forcing them to keep innovating technologically (this figure comes from a paid industry report and lacks an independently verifiable basis or methodological disclosure) [13]. This asymmetric change in the cost structure means that, in the AI era, institutional costs become a relatively more important constraint on profit, which makes the market-microstructure and institutional improvements discussed in Chapters 29 and 30 all the more critical.

In the CEX order-book perpetual futures market, the AI market maker's profit equation must also incorporate several distinctive cost and revenue dimensions. On the revenue side, the fee structure for makers and takers directly affects the AI market maker's net return: as a maker, an AI market maker typically enjoys a low or even negative fee (that is, it receives a rebate), whereas the taker who consumes its quotes pays a higher fee. This fee differential makes queue position a core optimization variable in the AI market maker's optimal strategy: under price priority, orders at the same price level are filled on a time-priority basis, so millisecond-level quoting speed directly determines whether the AI market maker can occupy a favorable queue position and thereby obtain a higher fill probability and more maker-rebate income. On the cost side, the funding-rate mechanism of CEX perpetual futures constitutes a distinctive holding cost: when an AI market maker holds a net long or net short position because of inventory skew, it must pay or receive the funding rate at each funding settlement period (typically 8 hours), and this cost can significantly erode market-making profit in highly volatile markets. The funding rate is not only a passively borne cost but also a source of return that AI market makers actively pursue. In periods when the funding rate is significantly positive, an AI market maker can deliberately maintain a net short inventory to collect the rate; funding-rate prediction itself constitutes an independent signal dimension. In extreme conditions, the funding rate can spike to several hundred percent on an annualized basis, at which point funding-rate exposure may completely dominate the market maker's profit and loss, far exceeding the contribution of spread income. The AI market maker's profit equation must therefore treat the funding rate as a core optimization objective on par with spread income, rather than merely as a holding cost.

Figure 31-2 unfolds the cost side of the market-making profit equation into five cost drivers and groups them into two categories: variable costs (significantly compressed by AI) and fixed institutional costs (only modestly improved). This asymmetric change in the cost structure explains why architectural improvements at the institutional level in fact carry higher marginal value in the AI era.

![Figure 31-2](./images/fig-31-2-en.png)

**Figure 31-2.** Recalibrating the AI market maker's profit equation: the cost side is unfolded into five cost drivers, grouped into variable costs (adverse selection and inventory management; significantly compressed by AI) and fixed institutional costs (funding rate, liquidation risk, and round-the-clock infrastructure; only modestly improved) (Illustrative: the cost-structure proportions are the author's estimate based on industry observation; the basis of the Ken Research industry report [13] cannot be independently verified)

### 31.2.2 The changing nature of adverse selection

In traditional microstructure theory, the core driver of adverse selection is information asymmetry. Informed traders possess private information about an asset's fundamentals, while the market maker, as the uninformed party, can only compensate for the risk of being selectively traded against by informed traders by widening the bid-ask spread. When the main participants in the market shift from humans to AI agents, the nature of this informational advantage undergoes a fundamental change.

In an AI-dominated market, an advantage in the source of information is gradually replaced by an advantage in the speed of information processing. Although AI agents can capture, parse, and synthesize public market data, news sentiment, and on-chain indicators at speeds far exceeding humans', they cannot obtain true inside information. This means that speed-based informational advantage is neutralized by the widespread adoption of AI technology. When all market makers are equipped with algorithms that respond at the millisecond level, the latency-arbitrage space that relies purely on processing public information is greatly compressed.

A new form of adverse selection thereby begins to appear. This adverse selection is no longer based on an asymmetry in fundamental information, but on algorithmic asymmetry. When arbitrageurs are likewise AI-driven, they can reverse-engineer the market maker's quoting logic through machine learning models. These AI arbitrageurs learn the market maker's reaction latency, inventory-adjustment thresholds, and spread-widening patterns under particular order-flow shocks, and thereby predict the market maker's next move. This game shifts adverse selection from "who knows more" to "whose model generalizes better and predicts more accurately." Against this backdrop, the market maker faces not a trader who possesses inside information, but an advanced AI agent able to compute precisely the blind spots in its algorithm.

In cryptocurrency markets, however, traditional adverse selection based on the source of information still exists in abundance. Miners and validators have knowledge of block contents before the public; project teams hold undisclosed information before token unlocks and partnership announcements; and leaks of regulatory decisions often exhibit an asymmetric distribution. These advantages in the source of information cannot be replaced by algorithmic speed. Adverse selection in the AI era therefore exhibits a two-layer structure: the lower layer is the persistent asymmetry in the source of information, and the upper layer is the newly added asymmetry in algorithmic capability. What the market maker faces is a superposition of the two kinds of risk rather than a simple substitution—it must guard both against informed traders who possess inside information and against AI arbitrageurs able to reverse-engineer its algorithmic logic.

### 31.2.3 The dimensional explosion of inventory management

Constrained by cognitive bandwidth, human market makers can typically manage inventory only in a limited number of dimensions. A typical trading team might focus on managing the inventory risk of two or three correlated asset pairs and rely on heuristic rules for cross-market hedging. AI agents break through this dimensional limit, achieving a dimensional explosion in inventory management.

Modern AI market-making systems can simultaneously manage a high-dimensional inventory vector across dozens of exchanges and hundreds or thousands of contracts. This high-dimensional optimization capacity enables AI to use cross-asset correlations for dynamic hedging. When one asset experiences one-sided net buying that unbalances inventory, for example, AI need not confine itself to adjusting quotes or hedging on the same asset pair; instead, it can instantly compute the optimal alternative hedging path across the entire crypto-asset matrix. This globally optimized perspective significantly improves overall market liquidity under normal conditions, because the market maker can tolerate a larger inventory deviation at any single point so long as it remains risk-neutral across the global vector.

Multidimensional cross-exchange inventory optimization faces rigid physical constraints in practice. Each exchange's margin account is isolated from the others, and the market maker must pre-fund enough margin at each venue to withstand the worst-case inventory deviation, making capital efficiency far lower than the theoretically optimal level of "global risk neutrality." Transferring funds across exchanges typically takes minutes or even tens of minutes, precluding instantaneous hedging. The 2022 collapse of FTX starkly exposed this fragility: funds frozen at FTX left multiple market makers' exposures on other exchanges unhedged, causing enormous losses. A further and more troubling effect is that AI market makers' cross-asset hedging behavior can itself amplify correlation breakdowns in periods of stress. When market maker A sells Ethereum to hedge its Bitcoin exposure, the decline in Ethereum's price triggers market maker B's Ethereum-inventory adjustment and further cross-asset hedging, forming a positive-feedback loop in which the AI hedging mechanism turns from a tool of risk diversification into a manufacturer of correlation contagion.

This multidimensional optimization, however, also introduces a new form of systemic risk. When the market is in a normal state, the cross-asset correlation matrix is relatively stable, and AI's hedging logic can operate effectively. Under an extreme market shock, however, correlations among assets often shift abruptly, and assets that were negatively correlated may suddenly become highly positively correlated. At that point, a high-dimensional inventory-optimization model built on the historical correlation matrix may fail simultaneously across all dimensions. Because AI systems operate synchronously across multiple markets, this correlation-shift-induced model collapse spreads through the entire market network at the millisecond level, turning a multidimensional hedging mechanism originally meant to diversify risk into a transmission channel that amplifies systemic fragility.

### 31.2.4 Adversarial market making

Chapter 19 discussed different types of toxic order flow, including the information-driven, momentum-driven, and structural-arbitrage types. As AI technology has been more deeply applied, a new dimension has appeared in the toxicity spectrum: AI-on-AI toxicity, or "adversarial market making." This phenomenon originates in the adversarial-example problem widespread in machine learning and is mapped directly onto the microstructure of financial markets.

Adversarial market making refers to AI arbitrageurs deliberately triggering an adverse response from the market maker's AI model by sending carefully crafted "adversarial orders." This is analogous to how, in computer vision, modifying just a few pixels can cause an image-recognition model to mistake a panda for a gibbon. In a trading setting, an attacker uses small-scale fake quotes, order cancellations at particular frequencies, or minute inventory shocks to deceive the market maker's model into misjudging the market trend or the volatility regime. Hofweber et al. (2025) [14] note that, by minutely manipulating the value of individual assets, one can construct adversarial examples against financial forecasting models, and may even trigger the model to make a self-fulfilling crash prediction.

Figure 31-3 shows the operating mechanism of adversarial market making. This mechanism is highly isomorphic in principle to adversarial-example attacks in the field of computer vision, revealing the new form of security fragility that AI market-making systems introduce in their pursuit of predictive precision.

![Figure 31-3](./images/fig-31-3-en.png)

**Figure 31-3.** The mechanism of adversarial market making (Data source: Hofweber et al., 2025 [14])

Under this new form of attack, the safety of a market-making strategy no longer depends solely on the accuracy of its predictions or the lowness of its latency, but also on its robustness to adversarial attacks. Traditional risk-control parameters often cannot identify this kind of adversarial perturbation disguised as normal order flow. When the market maker's AI model receives these adversarial signals and makes an erroneous quote adjustment, the attacker can extract a risk-free profit. This forces market makers to make adversarial defense a core part of the architecture when developing their algorithms, thereby increasing the system's complexity and computational overhead.

### 31.2.5 Structural strengths and weaknesses

AI agents and human market makers exhibit sharply different behavioral characteristics in market microstructure. Understanding the structural strengths and weaknesses of these two types of actors directly informs one's judgment about the dynamics and resilience of future market liquidity.

Table 31-2 compares the core differences between AI and human market makers along six dimensions: speed and operation, optimization capability, emotional control, strategy homogenization, handling of unknown scenarios, and security fragility. The table reveals a key structural trade-off: AI's absolute advantages on the first three dimensions (millisecond-level response, high-dimensional optimization, no emotional fluctuation) are precisely the root of its severe disadvantages on the latter three (strategy convergence, black-swan collapse, adversarial attack). In other words, the AI market maker's strengths and weaknesses do not exist independently; they are two sides of the same technological trait.

| Dimension | AI market maker | Human market maker |
| :--- | :--- | :--- |
| Speed and operation | Millisecond-level response; runs around the clock without rest | Constrained by physiological reaction time and the need for sleep |
| Optimization capability | Can simultaneously handle high-dimensional matrices and complex correlations | Can handle only low-dimensional variables; relies on heuristic rules |
| Emotional control | No emotional fluctuation; rigorously executes the set strategy | Easily swayed by market panic or greed |
| Strategy homogenization | Extremely high risk. Because training data and optimization objectives converge, synchronized behavior arises readily | Naturally heterogeneous; decides based on differing experience and intuition |
| Handling of unknown scenarios | Prone to model collapse when facing black-swan events outside the training data | Can make reasonable judgments in entirely new scenarios by relying on common sense and intuition |
| Security fragility | Vulnerable to adversarial-example attacks and algorithmic reverse engineering | Behavior is nondeterministic, hard to predict precisely and to attack programmatically |

**Table 31-2.** Comparison of the structural strengths and weaknesses of AI versus human market makers (Data source: compiled by the author)

AI market makers hold significant advantages in speed, multidimensional optimization, and emotional control. They can eliminate the irrational withdrawal of liquidity caused by human panic and provide extremely narrow bid-ask spreads under normal conditions. The price of these advantages, however, is severe structural weaknesses. Driven by the strategy-homogenization mechanism (whose causes are analyzed in detail in Section 31.3.2), AI strategies are highly prone to convergent reactions. When confronted with a never-before-seen black-swan event, these homogenized models may simultaneously make catastrophically wrong decisions, causing liquidity to dry up completely in an instant. In addition, AI's natural fragility to adversarial attacks introduces a new form of technological risk into the market.

## 31.3 AI and liquidity dynamics

In traditional market-microstructure theory, a liquidity crisis is usually portrayed as a chain reaction in which psychology and mechanism are intertwined. In the liquidity reflexivity triangle examined in Chapter 20, a price decline triggers panic, panic causes market makers to withdraw, and market makers' synchronized withdrawal further intensifies the price decline, ultimately becoming a tragedy of the liquidity commons in which liquidity dries up. The core driver of this classic framework is human cognitive limits and emotional fluctuation. When market participants shift from human traders to AI agents, this foundational assumption is fundamentally altered. AI has no physiological or psychological mechanisms of fear or fatigue; its decisions are based entirely on preset risk-control parameters and real-time data flows. This fundamental shift changes not only the response pattern of a single market maker, but also reshapes the liquidity dynamics of the entire market. The widespread deployment of AI agents, on the one hand, mitigates the traditional risk of liquidity droughts by eliminating emotional contagion, and, on the other, introduces a new form of systemic fragility through strategy homogenization. This section reexamines the liquidity reflexivity framework, analyzes AI's double-edged effect in mitigating traditional panic while triggering new flash crashes, and explores the path and risks of the evolution from protocol-level algorithmic market making to AI adaptive market making.

### 31.3.1 Mitigating the tragedy of the liquidity commons

The standard response of traditional market makers to extreme market volatility is to widen the bid-ask spread or cancel quotes outright. In microstructure theory, this behavior is interpreted as a rational avoidance of adverse-selection risk, but at the macro level, the synchronized withdrawal of all market makers causes liquidity to evaporate in an instant, forming a classic tragedy of the commons. Human market makers' withdrawal often carries strong emotional overtones; when confronting anomalous volatility that exceeds historical experience, an increase in risk aversion leads to an overreaction to risk. This emotional contagion is a key catalyst of liquidity phase transitions in traditional financial markets—that is, the market's abrupt rupture from a high-liquidity state to a low-liquidity state.

The introduction of AI agents fundamentally changes this microlevel mechanism. AI acts on programmatic risk control, and its decision logic is not disturbed by emotional fluctuation. Facing violent market volatility, an AI market maker precisely adjusts quote depth and spread according to real-time computed volatility indicators, inventory positions, and adverse-selection probabilities. Because there is no "persistent risk-aversion effect after a risk event," AI does not maintain a defensive posture after the risk signal has cleared, but can rapidly restore liquidity provision as market conditions improve. The empirical study of the market crash during the COVID-19 pandemic by Raboun et al. (2021) [15] shows that in a high-uncertainty regime, the elasticity of price with respect to liquidity demand increases significantly, but the presence of algorithmic trading makes this change in elasticity smoother rather than an abrupt rupture. During the cryptocurrency market volatility of 2024, market makers equipped with AI risk-control systems provided significantly more liquidity in extreme conditions than in the same period of 2023 (an estimate based on the author's reading of public data), indicating that AI's rational decision mechanism can indeed mitigate the traditional risk of liquidity droughts to some extent.

This data-driven, rational response mechanism transforms the process of liquidity decline from a traditional "phase transition" into a smoother "gradual change." Under stress testing, the group of AI market makers does not, like human traders, undergo an irrational synchronized withdrawal driven by panic. This "no-withdrawal" property is further reinforced when protocol-level liquidity providers are combined with AI adaptive algorithms. Hardcoded protocol rules ensure the base existence of the liquidity pool, while AI agents are responsible for dynamically optimizing the distribution of funds in extreme conditions. The HLP vault performed well in the market stress test of the second quarter of 2024, maintaining a relatively stable spread level even in extreme conditions—a marked contrast with the large spread widening among traditional market makers over the same period (an estimate based on the author's reading of public data). Maintaining a narrow spread in an extreme-volatility environment, however, may come at the cost of bearing higher adverse-selection losses; a comprehensive assessment should consider market-making profit-and-loss data together with spread indicators. From this angle, the widespread application of AI has indeed, to some extent, mitigated the tragedy of the liquidity commons driven by human emotion.

The sustainability of this mitigating effect, however, remains in question. The rational decisions of AI market makers are based on their accurate perception of market states and correct calibration of their risk models. When the market presents anomalous conditions outside the training-data distribution, or when the AI model's assumptions are broken, this effective risk assessment may lose its accuracy as the model's assumptions fail. In addition, the widespread application of AI also means that participant heterogeneity is declining, and this homogenization is itself a new form of systemic risk. Thus, although AI can mitigate liquidity crises in normal markets, its performance in extreme situations still requires ongoing monitoring and assessment. A more fundamental limitation is that the rational nature of AI market makers can mitigate only the microlevel liquidity withdrawal driven by emotional contagion; it cannot counteract the liquidity contraction driven by the macro credit cycle. When the Federal Reserve (Fed) enters a rate-hiking cycle and global dollar liquidity contracts, AI market makers' rational response, based on their risk models, is likewise to shrink their market-making scale and reduce risk exposure—this is precisely rational rather than emotional behavior, a normal expression of AI's "no-panic" property. The systemic collapse of the crypto market in 2022 amply demonstrates that the macro liquidity cycle has a far more decisive influence on market depth than differences in the behavioral characteristics of microlevel participants.

### 31.3.2 The fragility of strategy homogenization

Although AI does not experience psychological panic in the human sense, its highly rational decision mechanism can, under particular conditions, trigger another form of synchronized behavior: an "algorithmic synchronized defensive reaction." The root of this new fragility lies in the homogenization of AI strategies. In a fiercely competitive market-making environment, the AI agents developed by different institutions often rely on highly overlapping historical datasets, similar machine-learning architectures, and convergent optimization objectives. When the market presents a particular anomalous signal or microstructure feature, these AI models with similar underlying logic are highly likely to reach the same inference and, on that basis, make highly consistent decisions.

The causes of strategy homogenization are manifold. First, there is a severe asymmetry in the availability of training data. Most AI market makers use historical market data from the same set of data providers, and these data contain the same market-microstructure features and price patterns. Second, the convergence of machine-learning architectures leads different institutions to choose similar neural-network topologies and optimization algorithms. In applying deep reinforcement learning to market making, most researchers adopt similar state-space definitions, reward-function designs, and policy-gradient methods. Third, the optimization objective of market making has an inherent consistency—namely, maximizing profit while controlling inventory risk. This similarity in objective functions causes different AI agents to converge to similar decisions when facing the same market conditions.

When multiple dominant AI market makers simultaneously identify a particular market anomaly as an extremely-high-risk signal, they synchronously widen spreads, skew quotes, or halt trading outright at the millisecond level. This synchronized withdrawal based on algorithmic consensus occurs far faster and more thoroughly than the panic selling of human traders. Based on a multi-agent simulation study, Gao et al. (2022) [16] note that the synchronized behavior of high-frequency trading algorithms is a core driver of flash-crash events, and that its destructive power over market liquidity is nonlinearly and positively related to the algorithms' share of total market volume. Compared with traditional panic, AI-dominated liquidity droughts exhibit sharply different time dynamics. A traditional panic-driven withdrawal usually takes minutes or even hours to complete, because human traders need time to process information, assess risk, and execute trades. An AI market maker's synchronized withdrawal, by contrast, completes within milliseconds, meaning that liquidity shifts instantaneously from an ample state to a depleted one with almost no buffer in between.

Figure 31-4 conceptually contrasts two modes of liquidity crisis: in a human-dominated market, the spread rises sharply and decays slowly, with a crisis time span that can extend to hours or even days; an AI-homogenization-induced flash crash, by contrast, reacts synchronously within milliseconds, manifesting as an extremely sharp "V-shaped" reversal in which quotes restart instantly once the input data return to normal. Yet the "brevity" of an AI flash crash is by no means the same as "harmlessness": in a highly leveraged perpetual futures market, even a liquidity vacuum of 2 to 5 seconds is enough to cause irreversible cascading liquidations—at 100× leverage, a 1% price jump means the complete loss of margin, and a V-shaped recovery is meaningless to a position that has already been liquidated.

This momentary liquidity vacuum, though extremely brief, is enough to trigger a chain of liquidations of highly leveraged positions. During the cryptocurrency market volatility of March 2024, because multiple mainstream market-making algorithms simultaneously identified the same risk signal, the spread in the Bitcoin spot and futures markets widened sharply in under 100 milliseconds, forcing the liquidation of millions of dollars in positions. Worse, such a flash-crash event can trigger a cascade effect, in which the liquidity drought in one market triggers a liquidity crisis in other correlated markets, thereby forming systemic risk.

![Figure 31-4](./images/fig-31-4-en.png)

**Figure 31-4.** The different effects of human panic and AI homogenization on liquidity dynamics (conceptual illustration; not empirical data; based on the author's theoretical derivation)

### 31.3.3 Synchronized behavior and heterogeneous decision-making

As analyzed in Section 31.3.2, the homogenization of AI strategies is eroding the core source of market resilience: the heterogeneity of participants. In a human-dominated market, different traders hold different risk preferences, investment horizons, and decision logics, and this diversity ensures that two-sided liquidity exists at any given price level [17]. Brunnermeier and Pedersen (2009) [18] emphasize that market liquidity depends not only on market makers' inventory-management capacity but also on the diversity of market participants. The comprehensive penetration of AI agents, however, may weaken this heterogeneity. As machine-learning models' advantages in prediction and optimization become ever more prominent, underperforming strategies will be rapidly eliminated, and the market will gradually come to be dominated by a small number of highly optimized algorithms, eliminating the diversity of decision logic.

More dangerous still, this homogenization makes the market highly vulnerable to adversarial attacks. Goldblum et al. (2021) [19] show that machine-learning models in high-frequency trading systems are at risk of being deceived by adversarial examples. A malicious attacker can infer the decision boundaries of mainstream AI market makers by reverse engineering, and deliberately send particular combinations of order flow to trigger these algorithms' synchronized misjudgment, thereby artificially creating a liquidity vacuum and profiting from it. The cost of such an attack is relatively low, because the attacker need only understand the logic of a few mainstream algorithms to inflict a systemic shock on the entire market.

To mitigate the systemic risk of strategy homogenization, the design of market microstructure must proactively introduce an "anchor of heterogeneity." In the context of DeFi, the HLP vault can deliberately adopt pricing logic and risk models sharply different from those of mainstream high-frequency trading algorithms, so as to ensure the provision of uncorrelated liquidity even in extreme situations. For example, certain HLP-style vaults can adopt a pricing strategy based on long-term mean reversion, rather than a market-making algorithm that follows short-term market signals. Although such a strategy may be less efficient than mainstream algorithms in normal markets, it can provide stable liquidity support in extreme conditions.

In addition, exchanges and protocols can restructure incentive mechanisms to implement "market-making diversity incentives." For liquidity providers that can maintain quote depth within the millisecond window in which mainstream market makers synchronously withdraw, for example, a protocol can grant an exponential fee share or token reward. This mechanism design treats heterogeneity itself as a public good with positive externalities, and uses economic means to encourage developers to deploy non-mainstream AI strategies, thereby rebuilding in the algorithmic world the ecological diversity that technological convergence has flattened. Specifically, a protocol can set a "heterogeneity score," computed according to the degree of correlation between a liquidity provider's strategy and the market's mainstream strategies. The lower the correlation, the higher the heterogeneity score and the greater the incentive received. Such a design can effectively encourage innovative market-making strategies while protecting the market from the risk of strategy homogenization. In practice, however, the heterogeneity-incentive mechanism faces severe challenges of measurement and gaming. A market maker's underlying strategy logic is private information, and an exchange or protocol can observe only order-flow behavior. Inferring strategy heterogeneity from order-flow behavior faces a severe identification problem: ostensibly different order-flow patterns may merely reflect the same strategy under different parameter settings. More importantly, the mechanism is easily gamed: a market maker can deliberately submit orders that "look different" but have zero economic meaning in order to harvest the heterogeneity reward. Moreover, in extreme conditions, even a "heterogeneous" strategy may be forced to execute the same behavior because of shared funding constraints (such as insufficient margin), at which point the heterogeneity incentive cannot prevent synchronized withdrawal. The heterogeneity incentive should therefore be a component of a diversified resilience design rather than the sole solution, and needs to work in concert with complementary measures such as circuit breakers and minimum liquidity obligations.

### 31.3.4 AI adaptive market making

In the evolution of decentralized exchanges, the liquidity-provision mechanism is undergoing a paradigm shift from static parameterization toward dynamic intelligence. Early automated market makers relied on a hardcoded constant-product formula; although this mechanism guaranteed the continuous existence of liquidity, its capital efficiency was extremely low. The constant-product market makers of Uniswap v1 and v2, for example, required liquidity providers to distribute funds evenly across the entire price range, leaving most funds idle at price levels far from the current market price. The concentrated-liquidity protocols and parameterized strategy engines that appeared subsequently represent the evolution of microstructure into a second stage, in which humans set the strategy framework and protocol algorithms handle automatic execution. At this stage, an HLP vault can adjust quote ranges and fee tiers according to preset rules, but its response logic is still deterministic and reactive.

The concentrated-liquidity mechanism introduced by Uniswap v3 is a typical representative of the second stage. Liquidity providers can select a particular price range in which to concentrate their funds, thereby improving capital efficiency. This mechanism, however, still relies on human judgment about market conditions. Liquidity providers must manually adjust their price ranges, which creates two problems: first, the frequency of adjustment is limited by blockchain transaction costs, and so it cannot respond to market changes in real time; second, different liquidity providers may make suboptimal decisions, resulting in a low overall efficiency of liquidity allocation.

Academic research has begun to explore the prospects of applying reinforcement learning technology to automated market making. The simulation study by Fernández Vicente (2025) [20] demonstrates the theoretical potential of deep reinforcement learning for developing autonomous, adaptive market-making strategies. By formulating the market-making task as a multi-objective reinforcement learning problem, an AI agent in a simulated environment can simultaneously optimize spread income and inventory-risk control. Unlike a parameterized engine that relies on static rules, a reinforcement learning agent can autonomously discover complex nonlinear patterns through continuous interaction with the market and dynamically adjust its strategy weights to adapt to a continually changing market regime. Current public information is not yet sufficient to confirm whether mainstream on-chain market-making vaults have deployed deep reinforcement learning strategies in production; the research conclusions above come mainly from academic simulation rather than from empirical observation of production systems.

Viewed from a theoretical angle, if this AI adaptive market-making technology is widely deployed, it will bring a significant efficiency gain to on-chain liquidity provision. AI agents can more precisely predict changes in short-term price microstructure, and thus rapidly adjust quotes when informed traders appear, effectively reducing adverse-selection losses. Through cross-asset, multidimensional inventory optimization, an AI vault can provide deeper liquidity while holding the same risk exposure. This means that, for the same capital input, an AI market-making vault can provide greater trading depth, thereby offering users a better trading experience.

This efficiency gain, however, inevitably comes with a loss of transparency. The decision process of a reinforcement learning model has a strongly black-box character, and its internal neural-network weights and state-value function are difficult for humans to understand intuitively. When a market-making vault makes an anomalous quote adjustment in extreme conditions, participants in community governance find it hard to distinguish whether this is AI's optimal defense based on complex data, or an overfitting collapse of the model in an unseen state space. Under extreme market conditions, an adaptive market-making system may suddenly widen spreads sharply, raising users' transaction costs, and an after-the-fact analysis may show that this was the model's overreaction when facing a market state outside the training-data distribution, rather than rational risk management.

This lack of interpretability makes the "strategy transparency" problem discussed in Chapter 21 all the more prominent, and also poses a fundamentally new challenge to the on-chain auditing and governance mechanisms of DeFi. To meet this challenge, protocol designers need to find a balance point between efficiency and transparency. One possible solution is to introduce "explainable reinforcement learning" technology—that is, to make the AI agent's decision process more transparent through special model architectures and training methods. An attention mechanism, for example, can be used to identify which market features the model attends to most when making a decision, thereby improving the interpretability of the decision. Another solution is to implement an "AI audit" mechanism—that is, to periodically conduct an after-the-fact analysis of the AI market-making vault's decisions to check whether anomalous or unreasonable behavior has occurred. Through these measures, DeFi can maintain the necessary transparency and controllability while enjoying the efficiency gains that AI brings.

## 31.4 AI and volatility structure

The microstructure analysis of volatility over the preceding thirty chapters rests on the assumption that participants possess human cognitive characteristics (see the chapter introduction): information processing takes time, and the clustering effect of volatility stems from humans' gradual reaction to new information. When AI agents become the market's primary liquidity providers and price discoverers, these underlying assumptions break down. AI has no emotion, can process multidimensional data at the millisecond level, and can optimize synchronously across markets. This microlevel behavioral change is very likely to reshape the macrolevel characteristics of volatility. This section reexamines the volatility-decomposition model of Chapter 22 and the volatility-clustering mechanism of Chapter 23, analyzing how AI alters the structure of normal-regime volatility and creates new forms of tail risk.

### 31.4.1 Revising the four-source decomposition

In classic microstructure theory, the volatility of asset returns is decomposed into four basic sources: informational volatility, liquidity volatility, mechanical volatility, and contagion volatility. Informational volatility arises from the process by which fundamental news is incorporated into prices; liquidity volatility is driven by order-flow imbalances and the market maker's inventory-risk premium; mechanical volatility comes from the rigid execution of protocol rules such as the liquidation engine; and contagion volatility is the result of cross-market arbitrage and emotional resonance. When AI agents dominate the market, the characteristics of these four traditional volatility sources shift systematically, and, moreover, an entirely new, fifth source of volatility arises.

The pulse width of informational volatility narrows significantly under AI's involvement, but the peak may in fact rise. In traditional markets, for information to move from release to full reflection in prices requires a gradual process in which informed traders build positions step by step, uninformed traders follow, and market makers adjust quotes. This window of information diffusion typically takes minutes to hours. AI agents, by parsing news feeds, social-media sentiment, and on-chain anomalies in real time via NLP models, can complete the pricing of information at the millisecond level. The high-frequency volatility-decomposition model of Dahlhaus and Neddermeyer (2014) [21] shows that an increase in information-processing speed compresses the window of price discovery, shrinking the pulse width of informational volatility from the minute scale to the millisecond scale. This time compression, however, brings a counterintuitive result: although the process of incorporating information into prices is faster, because multiple algorithms compete to price the same information at the same instant, their quote adjustments reinforce rather than cancel one another. In an AI-dominated market, informational volatility manifests as a price jump within an extremely short time, and its instantaneous peak may in fact be higher than the gradual rise in a human market. This means that although the total time for information to be incorporated has shortened, the density of volatility per unit of time rises significantly.

The distributional shape of liquidity volatility undergoes a structural shift from mildly right-skewed toward bimodal, the most important change in volatility characteristics in the AI era. In a normal market, AI market makers can provide smoother liquidity than humans through multidimensional inventory management and high-frequency quote updates. Because AI is unaffected by emotion and does not withdraw in panic when facing routine order-flow imbalances, normal-regime liquidity volatility declines significantly. Based on a theoretical derivation from a multi-agent simulation model (author's estimate), normal-regime liquidity volatility may fall by 30% to 50% in a market dominated by AI market makers. When the market presents an anomalous signal outside the training-data distribution, however, strategy homogenization causes multiple liquidity providers to widen spreads or cancel quotes simultaneously. This instantaneous liquidity drought in extreme conditions causes liquidity volatility to spike sharply; a derivation based on the same theoretical framework (author's estimate) indicates that it may rise by 200% to 500%. This extreme asymmetry leads to a fundamental change in the distribution of liquidity volatility. In a human-dominated market, liquidity volatility usually follows a mildly right-skewed distribution, because panic is gradual and the deterioration of liquidity is continuous. In an AI-dominated market, by contrast, the distribution of liquidity volatility exhibits a clear bimodal character: one peak corresponds to the low volatility of normal conditions, and the other to the high volatility of extreme events, while the intermediate region between the two peaks shows a marked decline in probability density. The mechanism forming this bimodal distribution stems from AI's binary decision characteristic: an algorithm either maintains efficient market making under normal conditions, or withdraws completely once a risk-control threshold is triggered, with rarely an intermediate state. The numerical ranges above are all based on the author's theoretical modeling under extreme assumptions and reflect the upper and lower bounds of the magnitude of change rather than a precise forecast; the actual impact will depend on AI's penetration rate in the market, the degree to which strategy heterogeneity is preserved, and the design details of circuit breakers.

The evolutionary directions of mechanical and contagion volatility diverge. Mechanical volatility is triggered mainly by the liquidation mechanism; AI liquidation bots can more precisely predict liquidation thresholds and either dynamically hedge before the trigger or complete an optimal liquidation at the instant of the trigger, thereby modestly reducing the chained price shock of a liquidation cascade. In traditional markets, a liquidation event often causes a price shock of 5% to 15%, whereas under an AI liquidation mechanism this magnitude may fall to 2% to 5%. Contagion volatility, by contrast, rises significantly under AI's cross-market synchronized optimization. Algorithms maintain tight statistical-arbitrage relationships across multiple exchanges and asset pools, and any localized shock in a single market is transmitted to the global network by arbitrage algorithms within milliseconds. In traditional markets, cross-market contagion usually takes seconds to minutes, whereas under AI dominance this time shrinks to the millisecond level. This means that the propagation speed of contagion volatility increases by more than 1,000-fold, making the speed and breadth of cross-market contagion far exceed those of the human-dominated era.

Beyond revising the traditional four sources, the widespread application of AI introduces an entirely new source of volatility: AI-homogenization volatility. The fundamental mechanism of this additional source—the high convergence of different institutions' algorithmic models in training data, optimization objectives, and feature engineering—has been analyzed in detail in Section 31.3.2. When a large amount of capital is driven by neural networks with similar underlying logic, the models' resonant reaction to a particular minute perturbation produces endogenous volatility independent of fundamentals and of liquidity supply and demand. For example, if all algorithms simultaneously narrow their spreads upon detecting a particular pattern of order-flow imbalance, this collective behavior causes an instantaneous change in liquidity and thereby produces price volatility. This volatility, endogenously created by the collective behavior of the algorithmic population, constitutes a core variable that microstructure theory in the AI era must incorporate.

### 31.4.2 AI flash crashes

The evaporation of liquidity is the core mechanism that triggers extreme market events, but the liquidity drought under AI dominance differs essentially in its microdynamics from the panic-driven withdrawal of human traders. In the five-stage model of liquidity crisis discussed in Chapter 20, a crisis usually begins with an external shock, then triggers a chain reaction through market makers' risk aversion and information asymmetry, and finally leads to a spiraling decline in liquidity. This process usually takes minutes to hours to ferment in a human market, whereas the involvement of AI algorithms compresses this evolutionary cycle to the limit.

The "AI flash crash" is a new form of extreme event triggered by strategy homogenization. As analyzed in Section 31.3.2, the major market-making algorithms and high-frequency trading agents, because of strategy convergence, often have highly overlapping judgment boundaries for anomalous signals. Liu et al. (2025) [7] note that the homogenization of trading strategies amplifies market volatility and gives rise to mini-crashes. Once a non-standard event or an adversarial order flow touches these algorithms' shared blind spot, multiple liquidity providers make the same defensive decision within the same millisecond, synchronously widening bid-ask spreads or clearing the order book outright. This instantaneous disappearance of liquidity does not stem from the contagion of human fear, but from the mechanical triggering of the algorithms' risk-control parameters. In an AI flash crash, liquidity does not disappear step by step but evaporates in an instant within milliseconds, because all algorithms make the same decision at the same time.

Compared with the famous "flash crash" of 2010, an AI flash crash exhibits a sharply different volatility signature in its time-series characteristics. According to the CFTC's analysis of the 2010 event [22], a traditional flash crash is accompanied by the spread of panic, with volatility rising slowly before erupting sharply. Specifically, the flash crash of May 6, 2010, lasted 36 minutes, during which the S&P 500 fell approximately 9%. This process can be decomposed into three phases: first, 15 minutes of slow decline (a 2% to 3% drop), during which traders began to sense the anomaly; second, 10 minutes of accelerating decline (a 5% to 7% drop), as panic began to spread; and finally, 11 minutes of bottoming out and recovery, as liquidity gradually returned. After the price bottomed, because of traders' "fear aftershock," the market took a relatively long time to restore normal liquidity provision. The high-frequency data study by Kirilenko et al. (2017) [23] confirms that during the traditional flash crash, although high-frequency traders' market-making behavior did not change fundamentally, the lack of coordination meant that liquidity recovery was still slow.

The time scale of an AI flash crash is entirely different; a typical AI flash crash may complete the whole process within 2 to 5 seconds: the trigger phase (0–100 milliseconds), in which an adversarial order or market anomaly triggers the algorithms' risk-control systems; the synchronized-reaction phase (100–500 milliseconds), in which multiple market-making algorithms simultaneously detect the anomalous signal and collectively cancel quotes or widen spreads; the propagation phase (500 milliseconds to 2 seconds), in which the instantaneous disappearance of liquidity causes a price jump that, once detected by arbitrage algorithms, further worsens the liquidity deterioration; and the recovery phase (2–5 seconds), in which liquidity provision restarts instantly once the anomalous signal clears. This rapid recovery, lacking any "fear aftershock," means that an AI flash crash is often already complete before human traders have even noticed it.

The timeline above is a hypothetical scenario based on theoretical derivation; there is as yet no fully documented and academically verified real case of a purely AI flash crash. In actual markets, the dynamic process of an AI flash crash is modulated by multiple constraints. In a centralized-exchange environment, price-deviation-threshold protections and circuit breakers intervene early, transforming the flash crash from a continuous V-shaped path into a stepwise "halt–information accumulation–recovery" mode. In an on-chain environment, block time constitutes a physical lower bound on the speed of synchronized reaction: Ethereum's block interval of about 12 seconds makes millisecond-level algorithmic synchronization impossible on that chain, and although the 200- to 400-millisecond block time of high-performance application chains allows faster reactions, it is still far slower than the speed of centralized exchanges.

Figure 31-5 contrasts the volatility time series of the two types of extreme event: a traditional flash crash is a bell-shaped curve lasting about 36 minutes, whereas an AI flash crash is an extremely sharp pulse of very large magnitude lasting only 2 to 5 seconds (the time axes of the two series are not to the same scale). This difference in shape corresponds to the distinction between an emotion-driven, gradual collapse and an algorithmically-synchronized, abrupt collapse.

![Figure 31-5](./images/fig-31-5-en.png)

**Figure 31-5.** A comparison of the volatility time-series characteristics of a traditional liquidity evaporation and an AI flash crash (conceptual illustration; the time axes of the two series are not to the same scale; the magnitude of the traditional evaporation references the 2010 flash crash, data source CFTC [22]; the duration of the AI flash crash is a theoretical derivation)

### 31.4.3 The AI effect on volatility clustering

Volatility clustering is one of the most famous stylized facts of financial time series—that is, large movements tend to be followed by large movements, and small movements by small movements. The generalized autoregressive conditional heteroskedasticity (GARCH) model proposed by Bollerslev (1986) [24] provides a classic statistical description of this phenomenon. At the microstructure level, volatility clustering is usually explained by the clustering effect of information flow and the slow convergence of traders' heterogeneous beliefs. When AI reshapes market microstructure, the underlying feedback loops that drive volatility clustering undergo a fundamental change.

AI's adaptive capacity significantly changes the tempo and characteristics of market-state transitions. In the state-machine model of Chapter 23, the market's transition from a calm period to a high-volatility period is usually accompanied by a continuous deterioration of microstructure variables (such as the bid-ask spread and order-book depth). This transition process is gradual in a human market: the bid-ask spread widens step by step from 1 basis point to 2, 3, or 5 basis points, and order-book depth falls step by step from 1 million units to 500,000 or 100,000 units. This process may take minutes to hours. In an AI-dominated market, however, the state transition becomes extremely abrupt. In its 2024 Global Financial Stability Report, the International Monetary Fund notes that AI-driven trading can improve market efficiency and deepen liquidity but may also amplify volatility in periods of stress [25]. Because AI agents can process vast amounts of data in real time and hedge at high frequency, they exhibit extremely high efficiency in absorbing routine information shocks, so that normal-regime market volatility is continually compressed. This smoothing of normal-regime volatility superficially enhances the market's stability.

This normal-regime stability, however, does not reflect the clustering of tail risk. In a human-dominated market, the volatility-behavior feedback loop is gradual: a rise in volatility causes some market makers to exit, and the decline in liquidity further pushes up volatility. In this feedback loop, each step has a time lag, because humans need time to perceive market changes, assess risk, and make decisions. In an AI-dominated market, this feedback loop is replaced by a "homogenization–synchronized reaction–amplification" mechanism. Abbas et al. (2024) [26] emphasize that although the latest generation of AI technology has improved risk management, it has also increased the market's systemic fragility. Specifically, when the system encounters a never-before-seen extreme shock, the highly optimized algorithms simultaneously enter risk-off mode. This nonlinear phase transition from extreme calm to extreme turbulence makes the state transition more abrupt. The traditional gradual transition of "calm → mild volatility → moderate volatility → high volatility" is replaced by a jump transition of "calm → high volatility." This jump occurs over an extremely short time, possibly only seconds.

The manifestation of volatility clustering also changes fundamentally. In a human market, volatility clustering manifests as continuous clusters of high volatility—that is, if volatility is high today, it is very likely to be high tomorrow as well. This is because the information shock or liquidity problem that caused today's high volatility may continue to affect the market tomorrow. In an AI-dominated market, however, the manifestation of volatility clustering evolves into isolated, extreme volatility spikes that erupt suddenly against a long-run baseline of low volatility. These spikes are extremely brief (on the scale of seconds) but have very high peaks. Once the spike passes, the market rapidly returns to the low-volatility baseline. This new form of volatility clustering, called "spike clustering," differs essentially from traditional "cluster clustering."

The jump transition of volatility is not, however, unique to the AI era. Hamilton's (1989) regime-switching model and Merton's (1976) jump-diffusion model long ago described the discontinuous changes in volatility in financial markets. Even before the large-scale penetration of AI, the crypto market had already experienced instantaneous jumps from low to extreme volatility, such as the global market crash of March 2020. AI homogenization's distinctive contribution lies not in creating the volatility jump itself, but in changing the endogeneity of the jump: traditional jumps are triggered mainly by exogenous information shocks, whereas AI-homogenization volatility can be endogenously produced by the collective behavior of the algorithmic population in the absence of a significant exogenous shock. How to identify this AI-endogenous jump from the exogenous jumps inherent in market structure remains an open question awaiting empirical testing.

The slow-variable mechanism still exists in the AI era, but its channel of action is redirected. Slow variables such as the macroeconomic cycle and the size of a protocol's underlying liquidity pool determine the floor of the market's carrying capacity. Although AI agents play their games at the millisecond level, the effectiveness of their strategies is still constrained by these slow variables. The difference is that AI can identify a slight decay in a slow variable earlier and adjust its strategy parameters in advance before the critical point arrives. This forward-looking collective adjustment often compresses the volatility pressure that should have been released over a longer period into an eruption within an extremely short time window. For example, if the size of a liquidity pool has fallen by 20% over the past week, this information will be captured by all algorithms at the same time. In a human market, it might take days for this information to be fully recognized by traders, whereas in an AI market it is incorporated into all algorithms' risk assessments within milliseconds. This means that the volatility pressure that should have been gradually released over several days is released, concentrated, within an extremely short time window.

### 31.4.4 The effectiveness of volatility forecasting

Volatility forecasting is central to risk management, options pricing, and market-making strategy. In the traditional econometric framework, the effectiveness of volatility models (such as the GARCH family) depends on the relative stability of the market's statistical characteristics over a certain period. When the market's main participants are themselves machine-learning models with a continuous learning capacity, however, the logic of forecasting shifts from static statistical inference to a dynamic algorithmic game.

The market's statistical characteristics are in a state of continual drift amid AI's ongoing evolution. Machine-learning models in financial forecasting generally face the problem of model decay. Over time, changes in the external economic environment and the influx of new data lead to data drift and concept drift, causing the performance of models trained on historical data to decline gradually [27]. In traditional financial markets, a well-trained GARCH model may maintain relatively stable forecasting power for 6 to 12 months. In a microstructure where AI agents are widely deployed, however, this decay is further accelerated. When a forecasting model discovers a microstructure pattern (for example, that a particular order-flow imbalance foreshadows an imminent rise in volatility) and executes trades accordingly, its trading behavior itself changes the market's microdynamics. Other AI agents rapidly learn and adapt to this new pattern, causing the original statistical regularity to be erased. This means that the half-life of an effective volatility-forecasting model shrinks sharply, from the traditional 6 to 12 months to weeks or even days.

The sharp shortening of a model's half-life in the AI era demands a paradigm shift in forecasting methods. The fundamental cause of this shortening lies in the acceleration of the "forecast–arbitrage–adaptation" cycle in an AI market. In a human market, this cycle may take weeks: a trader discovers a profitable pattern and begins to trade on it, other traders gradually become aware of the pattern, and eventually the pattern is arbitraged away. In an AI market, this cycle may take only hours or even minutes. An AI model discovers a forecasting pattern and immediately begins to trade; other AI models detect this trading behavior within milliseconds and immediately begin adversarial trading; and eventually the pattern is rapidly arbitraged away.

In their discussion of machine learning in high-frequency trading, Kearns and Nevmyvaka (2013) [28] note that algorithms must handle not only independent, identically distributed data but also an adversarial market environment. In an AI-dominated market, any volatility model with predictive power quickly becomes a target for other algorithms' reverse engineering and adversarial attacks. This means that an effective volatility-forecasting model is no longer a fixed-parameter mathematical formula, but must be a meta-learning system that can monitor its own performance decay in real time, automatically trigger a retraining mechanism, and possess adversarial robustness.

The failure mechanism of volatility forecasting in an AI-dominated market can be understood as an infinitely recursive game. The market maker's AI tries to predict market volatility in order to adjust its quoting strategy. The arbitrageur's AI tries to predict the market maker's AI's behavior in order to profit from it. But the market maker's AI is also predicting the arbitrageur's AI's behavior in order to adjust its strategy in advance. This infinite recursion—"the market maker predicts the arbitrageur, the arbitrageur predicts the market maker"—turns volatility forecasting into a dynamic game rather than a static inference. In this game, there is no stable equilibrium point, and the market's statistical characteristics are in a state of continual change.

Specifically, suppose a volatility-forecasting model discovers the following regularity: when order-flow imbalance exceeds 1 million units, volatility over the next minute rises by 20%. The market maker's AI will use this regularity to adjust its risk exposure. But the arbitrageur's AI will anticipate this and conduct adversarial trading in advance when order-flow imbalance approaches 1 million units, so as to break the regularity. Once the regularity is broken, the original forecasting model fails. The market maker's AI will try to learn a new regularity, but the arbitrageur's AI will again anticipate this and again conduct adversarial trading. This "learn–adapt–break–relearn" cycle keeps accelerating, making it hard for stable statistical regularities to persist in the market for long, and so the difficulty of volatility forecasting rises sharply.

This acceleration of the dynamic game leads to the sharp shortening of the model's half-life. In a human market, the pace of this game is relatively slow, so a model may have a validity period of weeks. In an AI market, the pace of this game is extremely fast, so a model may have a validity period of only hours. This means that the effectiveness of traditional volatility-forecasting methods (such as GARCH models and machine-learning models) may decline significantly in an AI-dominated market. What must replace them is a meta-learning system that can adapt to market changes in real time and possesses strong adversarial robustness. Such a system no longer tries to forecast the absolute level of volatility, but instead tries to forecast the direction and speed of volatility changes. It must be able to detect changes in the market's statistical characteristics within milliseconds and immediately adjust its forecasting strategy.

## 31.5 AI and market quality

As AI evolves from a supporting tool into a core participant in and infrastructure for market microstructure, the traditional framework for assessing the efficiency of market operations faces systemic challenges. The five-dimensional market-quality model established in Chapter 25 (transaction cost, price discovery, resilience, fairness, and accessibility) operated well under the implicit assumption that "participants have human characteristics." AI agents' millisecond-level response speed, multidimensional optimization capability, and lack of emotional fluctuation, however, are reshaping the inner logic of these five dimensions. This reshaping is not a one-way improvement or deterioration; it exhibits a highly nonlinear character: AI significantly improves market quality in the vast majority of routine market states, yet creates a new form of fragility in the rare tail events.

### 31.5.1 Transaction cost

On the transaction-cost dimension, the widespread participation of AI market makers brings the most direct improvement: the extreme compression of the bid-ask spread. The traditional market maker's profit equation is constrained by adverse-selection cost and inventory-management cost, whereas AI agents can hedge inventory at high frequency across multiple markets and asset dimensions simultaneously, significantly reducing the risk premium of inventory buildup. This efficiency gain is ultimately translated, through fierce competition among market makers, into narrower spreads that directly benefit ordinary traders.

This surface-level cost decline, however, does not reflect the hidden cost transfer within the microstructure. The combination of high-frequency trading and AI algorithms enables the participants with the fastest execution speed and the best models to systematically capture a microstructure-level advantage. This advantage manifests as reacting in advance to, or "front-running," ordinary orders, and in effect constitutes a "speed tax" levied on slower traders. The study by Aquilina, Budish, and O'Neill (2022) quantifies the scale and frequency of this phenomenon by analyzing message data from the London Stock Exchange [5]. They find that latency-arbitrage races are extremely frequent (occurring on average about once per minute per stock) and extremely fast, with a modal race duration of only 5 to 10 microseconds (the proportion, concentration, and scale estimates above are magnitude estimates that the study extrapolates to the global equity market from FTSE 100 data on the London Stock Exchange). More critically, such races account for approximately 20% of global equity trading volume, and the top six high-frequency trading firms account for more than 80% of all race wins. Although each race is of small value (on average about half a tick), the cumulative effect is significant given the enormous volume. The study estimates that latency arbitrage levies a "tax" of approximately 0.5 basis points per year on the global equity market (approximately 0.42 basis points measured against total volume, or approximately 0.53 basis points measured against non-race volume), equivalent to a wealth transfer on the order of $5 billion per year in the global equity market.

When an ordinary investor tries to trade at the extremely narrow spread shown on the screen, AI agents can often cancel or adjust their quotes within milliseconds, causing the actual execution slippage to be far higher than expected. The economic essence of this phenomenon is that the seemingly evenly distributed spread is in fact stratified across multiple micro time scales: nanosecond-scale ultra-high-frequency traders, microsecond-scale high-frequency traders, millisecond-scale algorithmic traders, and second-scale ordinary investors. Each layer can extract a systematic spread advantage from the layer below, forming a "stratified execution structure based on latency differences." AI's net effect on transaction cost therefore exhibits an unevenly distributed character: the overall spread indicator appears to improve, but participants lacking top-tier AI infrastructure in fact bear higher hidden execution costs.

### 31.5.2 Price discovery

The efficiency of price discovery depends on the speed and accuracy with which the market converts new information into equilibrium prices. AI agents' breakthroughs in NLP and multimodal data parsing enable them to digest news, earnings reports, on-chain data, and even social-media sentiment at the millisecond level. This enhanced information-processing capacity shortens the reaction time of asset prices to new information from the minute scale to the millisecond scale, greatly improving the efficiency of price discovery under normal conditions. The study by Brogaard, Hendershott, and Riordan (2014) shows that high-frequency traders, through rapid quote updates, play an important role in the price-discovery process, with their trades contributing a significant information-incorporation effect [29]. In the AI era, this effect is further amplified, as AI models can process hundreds of information sources simultaneously and adjust their assessment of an asset's value within milliseconds.

AI's excessive sensitivity to information, however, may cause the price-discovery process to be distorted by noise signals. When a large number of homogenized AI models are deployed in the market, they may react synchronously to certain noise data that do not represent a change in fundamentals. Because AI lacks humans' intuitive judgment and common-sense understanding of complex context, an adversarial attack or anomalous data input can readily trigger a chain reaction among the algorithms. A single piece of fake news, an anomalous large order, or a data-transmission error, for example, may be misinterpreted by AI models as an important information signal, causing prices to swing violently within milliseconds. This overreaction to noise not only increases short-term microlevel volatility but may also, within a particular time window, steer prices away from true fundamentals. Over the long run, AI accelerates the process of information incorporation, but in the short run the quality of price discovery may become highly unstable because of the algorithms' collective misjudgment. The core difficulty facing market participants is that, in an AI-driven market, distinguishing genuine information signals from noise becomes ever harder, because AI itself is continually learning how to make this distinction better, and this learning process itself produces new market-microstructure phenomena. In crypto markets, a distinctive attack surface facing AI price discovery is social-media narrative manipulation. When an AI model uses NLP sentiment analysis as a core input feature, malicious actors can directly manipulate the model's input space through a coordinated social-media offensive (including paid influencer posts, bulk posting by bot accounts, and cross-platform narrative construction). This attack vector is more upstream than the adversarial-order-flow manipulation discussed in Section 31.2.4, because it launches its attack at the level of the information source rather than at the level of market microstructure, and its cost is relatively low.

### 31.5.3 Resilience

Market resilience measures the system's ability to absorb a liquidity shock and recover quickly. In traditional markets, liquidity crises often originate in the contagion of panic among human traders; when facing unknown risk, market makers' synchronized withdrawal causes liquidity to dry up in an instant. AI agents' emotionless character significantly enhances market resilience under normal conditions: they do not stop quoting out of fear, but continue to provide liquidity in strict accordance with preset risk-control parameters and reinforcement learning strategies, thereby smoothing out small- and medium-scale liquidity shocks. This improvement based on algorithmic discipline manifests in everyday markets as more stable liquidity provision and smaller spread fluctuations.

This resilience based on algorithmic discipline, however, can turn into severe fragility in tail events. As analyzed in detail in Section 31.3.2, the homogenization of current mainstream AI market-making strategies creates a new form of systemic risk: highly homogenized agents may synchronously and defensively withdraw in a "truly unknown" event, triggering an "AI flash crash" far faster than human speed. The 2010 flash crash offers a warning: at that time, the U.S. stock market fell approximately 9% within just 36 minutes, wiping out approximately $1 trillion in market value at one point (according to widely circulated media estimates, the event was therefore called the "trillion-dollar flash crash"; this total is an approximate media estimate, not an official figure from the body of the joint SEC/CFTC report), and although it ultimately recovered after human intervention, the whole process exposed the fragility of algorithmic trading [22]. In an AI-dominated market, a similar flash crash could occur faster and more violently, and the window for human intervention could be narrower. Although an AI market's recovery speed after a flash crash is likewise remarkable, this bimodal character of "extremely high normal-regime resilience, extremely low tail-regime resilience" fundamentally changes the distributional shape of market risk: normal-regime volatility may decline, but the probability and magnitude of extreme events may rise.

### 31.5.4 Fairness

Fairness is the dimension of the market-quality model most affected by AI. Information asymmetry in traditional market microstructure stems mainly from differences among participants in access to inside information or in professional research capability. As analyzed in Section 31.2.2, in an AI-dominated market the "advantage in the source of information" is gradually being replaced by an "advantage in information-processing speed and algorithmic computing power." Institutional investors with top-tier AI models and colocated servers can complete the entire process from data parsing to order execution within nanoseconds, while ordinary human traders or traditional algorithms simply cannot compete on the same time dimension. The magnitude of this speed difference is astonishing: nanosecond-scale ultra-high-frequency traders hold a 1,000-fold speed advantage over microsecond-scale high-frequency traders, while millisecond-scale retail investors lag nanosecond-scale traders by a factor of one million.

This widening of the "speed gap" leads to a significant deterioration in market fairness. AI not only forms a structural competitive advantage in execution speed, but can also reverse-engineer human traders' behavioral patterns through deep learning to carry out systematic microstructure exploitation. AI can, for example, analyze minute features of order flow to predict the splitting trajectory of a large order and build positions in advance, behavior that is in essence a form of electronic front-running. In on-chain markets, this phenomenon is especially pronounced: maximal extractable value (MEV) searcher bots monitor pending transactions in the mempool and carry out "sandwich attacks" before a user's transaction executes, thereby extracting value from ordinary users. Studies show that MEV extractors continually capture considerable value from ordinary users; according to one study's identification of approximately 9.4 million MEV events (approximately 6.33 million arbitrages and 3.02 million sandwich attacks, spanning 2015 to 2023), together with on-chain monitoring by Flashbots and others, the annual scale of MEV extraction on Ethereum is on the order of tens of millions of dollars, reaching the order of $1 billion only cumulatively over many years (post-Merge) [30]. In this environment, ordinary investors in effect become the "uninformed traders" that supply liquidity profits to AI models. Absent a functional regulatory framework aimed at non-human participants, this structural unfairness will erode public trust in financial markets.

### 31.5.5 Accessibility

Two sharply opposed forces bear on AI's effect on market accessibility. On the one hand, the rise of the "AI-as-a-service" model and the spread of open-source quantitative tools seem to be driving a democratization of trading capability. Open-source platforms such as QuantConnect and Backtrader provide retail traders with free backtesting environments and real-time data interfaces, enabling even investors with no programming background to build trading strategies through a drag-and-drop interface. Ordinary investors can now, through natural-language instructions, have an AI assistant write complex trading scripts, backtest strategies, and execute them automatically. This devolution of technology lowers the programming barrier to quantitative trading, enabling more retail traders to use advanced analytical tools to participate in the market. Some platforms, such as TradeMaster, provide a complete reinforcement learning framework that allows non-professionals to deploy AI trading agents through simple parameter configuration [31].

On the other hand, the true core competitiveness that determines who wins and loses in the market—low-latency infrastructure, exclusive high-quality data sources, and frontier models with tens of millions of parameters—has development and maintenance costs that are rising exponentially. Although basic AI tools have become easy to obtain, the "frontier AI" capable of generating persistent excess returns is monopolized by a small number of leading institutions. Building a competition-grade high-frequency trading infrastructure requires investing millions of dollars in colocated servers, proprietary data sources, and top talent. The training cost of a frontier large language model has already reached the order of tens of millions of dollars, which is entirely unaffordable for most individuals and small and medium-sized institutions. AI has therefore in fact erected a new, invisible technological barrier in the market: it makes low-end tools easy to obtain, while raising the threshold of high-end competition to a height that ordinary participants cannot reach. The ultimate net effect on market accessibility will depend on the game between the pace of evolution of the open-source AI community and the degree of monopoly of proprietary models. If the open-source community can continually produce models approaching the frontier level, then "AI democratization" may become a reality; but if the advantage of proprietary models and infrastructure keeps widening, then AI will further intensify the divide between the haves and have-nots among market participants.

Table 31-3 summarizes the systematic revisions AI agents make to the five-dimensional market-quality model of Chapter 25. The core finding of the table is that AI's effect on market quality exhibits a highly nonlinear, dimension-by-dimension character: transaction cost and price discovery improve significantly under normal conditions, resilience exhibits a bimodal distribution of "extremely high in the normal regime, extremely low in the tail," and fairness deteriorates significantly because of the widening speed gap. Notably, the net-effect assessment column shows that no single dimension exhibits a pure improvement or deterioration; behind every improvement lies a new form of risk or a cost transfer.

| Dimension | AI's positive effect | AI's negative effect | Net-effect assessment |
| :--- | :--- | :--- | :--- |
| Transaction cost | Intensified competition compresses the apparent bid-ask spread to the extreme, down to the nanosecond level | The hidden "speed tax" rises, the risk of orders being front-run increases, and the annual cost of latency arbitrage is about $5 billion | Net positive, but the benefits are extremely unevenly distributed across participants of different speeds |
| Price discovery | The leap in information-processing capacity accelerates the incorporation of new information into prices to the millisecond level | Algorithmic homogenization readily overreacts to noise data, amplifying false signals; short-term price-discovery quality is uncertain | Net positive over the long run, but the quality of short-term microlevel price discovery is impaired |
| Resilience | The emotionless character eliminates panic contagion; the ability to absorb shocks under normal conditions improves | Strategy convergence creates systemic blind spots and readily triggers an instantaneous "AI flash crash"; the 2010 flash crash is a warning | Exhibits a bimodal character: normal-regime resilience improves significantly, while tail-regime resilience drops sharply |
| Fairness | — | The nanosecond-versus-millisecond speed gap cannot be bridged; annual MEV extraction is on the order of tens of millions of dollars (reaching the order of $1 billion cumulatively over many years) | Deteriorates significantly; ordinary traders face systematic microstructure exploitation |
| Accessibility | Open-source tools and "AI-as-a-service" lower the barrier to basic quantitative programming | The capital barrier for frontier models and low-latency infrastructure rises exponentially to tens of millions of dollars | Depends on the degree of technological democratization; the high-end competitive barrier hardens substantively |

**Table 31-3.** The matrix of AI's effect on the five-dimensional market-quality model of Chapter 25 (Data source: [5][29][22][30][31])

## 31.6 The governance challenges of AI agents

The analysis in the preceding sections reveals AI agents' profound reshaping of microstructure characteristics as market participants, but this reshaping brings systemic challenges at the level of regulation and governance. The traditional framework for regulating financial markets is built on the assumption that participants are humans or legal entities controlled by humans. When the market's dominant force shifts to algorithmic programs that can learn autonomously, adapt dynamically, and lack a physical entity, the on-chain governance and compliance frameworks established in Chapters 26 and 30 must be correspondingly extended and revised. This section explores the governance challenges of AI agents in on-chain financial systems along four dimensions: the object of regulation, the attribution of liability, compliance mechanisms, and DAO governance.

### 31.6.1 Regulating non-human participants

The traditional paradigm of financial regulation takes natural persons or legal entities as its core object of regulation, with the logical starting point that the subject has the capacity and the incentive to bear legal liability. Within this framework, regulators change market participants' cost-benefit expectations by imposing fines, revoking licenses, or restricting market access, thereby curbing violations such as market manipulation and insider trading. An autonomously operating on-chain AI agent, however, breaks this basic premise. As a string of code or a model deployed on a distributed ledger, an AI agent itself has neither a physical form nor legal-entity status in any jurisdiction. Under the current legal system, an AI agent is neither a natural person able to enjoy rights and bear obligations, nor a legal person that has acquired an independent personality through a registration process, still less does it possess the legal status required of a fiduciary; its "legal status" is in a state of complete blankness.

When an AI agent can independently generate trading signals, autonomously manage multidimensional inventory, and execute high-frequency market-making strategies, its behavioral characteristics are already indistinguishable from those of a human trader, yet traditional regulatory tools can scarcely impose a substantive constraint on it. A fine cannot deter an algorithm that has no property ownership, and a market ban can scarcely stop open-source code from being redeployed by an anonymous entity. This absence of subject identity puts the identity-based regulatory model at risk of failing when confronting AI agents. The U.S. Securities and Exchange Commission (SEC) already exhibited this limitation in its early attempts to address algorithmic trading. In its 2014 enforcement action against Athena Capital Research, for example, the SEC found that the firm used an algorithm code-named "Gravy" to manipulate closing prices, and could ultimately only penalize the legal entity that owned the algorithm [32]. When an algorithm evolves into a fully autonomous AI agent deployed on a decentralized network, however, finding such a centralized entity to penalize will become extremely difficult.

To meet this challenge, the principle of functional regulation proposed in Chapter 26 is especially applicable in the AI context. The core idea of functional regulation is "same activity, same rules"—that is, the trigger for regulation should not depend on a participant's identity attributes, but on the function it performs in the market and the risk it may generate. If an AI agent performs a market-making function on-chain, provides liquidity, and collects a bid-ask spread, then it should be subject to the same market-microstructure rules as a human market maker, such as a minimum tick size, limits on cancellation frequency, or a liquidity-provision obligation in extreme conditions. In its 2026 draft supervisory briefing on the regulation of algorithmic trading under the Markets in Financial Instruments Directive II (MiFID II), the European Securities and Markets Authority (ESMA) proposed that algorithmic trading strategies must be distinguishable, testable, and identifiable, regardless of whether AI technology is integrated behind them [33]. This paradigm shift, which moves the regulatory focus from "who is trading" to "the trading behavior itself," provides a feasible theoretical basis for bringing non-human participants into the governance framework.

### 31.6.2 Liability attribution and compliance credentials

Although functional regulation solves the problem of "what to regulate," it does not answer the core accountability question of "who bears the consequences." When an AI agent triggers an "AI flash crash" in the market or executes an "adversarial market making" strategy judged to be market manipulation, the attribution of liability becomes highly complex. The lifecycle of an AI system involves multiple stakeholders, forming a liability chain that is hard to delineate clearly. This chain typically comprises three core layers: the developer who designs the model architecture and trains the base model; the deployer who combines the model with a particular trading strategy and configures its parameters; and the user who ultimately derives economic benefit from the agent's trading activity.

In the autonomous AI systems of Stage 3 and Stage 4, because the agent has the capacity to evolve continuously through reinforcement learning in its market interactions, the strategy it ultimately executes may far exceed the developer's initial design expectations. Kurshan et al. (2025) [34] note that generative and agentic AI systems exhibit emergent behavior through continuous learning and the potential exchange of signals, which violates the assumption in traditional model-risk frameworks that algorithms are static and well-defined. In this situation, requiring the developer to bear full liability for violations that the agent autonomously evolved after deployment is not only logically flawed but would also severely suppress technological innovation. At the same time, because of the permissionless nature of the blockchain, deployers and users can often remain anonymous, making it extremely difficult to trace the actual controller. Autonomy changes the way behavior occurs, but it cannot eliminate the associated obligations of liability; liability must ultimately return to the human actors who design, deploy, authorize, or benefit from the AI system.

To resolve this liability vacuum, an "AI compliance credential" mechanism is being explored at the level of market infrastructure. This mechanism requires an AI agent to hold a cryptographic credential issued by a trusted third party or a decentralized verification network before it can access a particular protocol or liquidity pool. The specific design of this credential contains verification information along multiple dimensions: whether the agent's decision model has passed stress testing against adversarial examples, whether it possesses a hardcoded risk circuit breaker, and whether its deployer's identity has passed some form of decentralized identity verification. Through cryptographic techniques such as zero-knowledge proofs, these credentials can prove to the protocol that the agent's design meets particular security and compliance standards without revealing the specific details of the agent's strategy. More importantly, the compliance-credential mechanism must include a revocation function. When the on-chain monitoring system detects anomalous trading behavior by the agent or a breach of compliance boundaries, the protocol can automatically revoke its credential, instantly cutting off its interaction rights with the liquidity pool. By enforcing verification of the compliance credential at the smart-contract layer, the protocol establishes a liability chain between the agent's behavior and a traceable subject, thereby restoring the effectiveness of the accountability mechanism in an anonymous network.

The design of AI compliance credentials must also confront the reality that compliance requirements across jurisdictions may conflict fundamentally. Some regulators require full auditability of algorithmic trading systems, which directly contradicts the design goal of zero-knowledge proofs to protect strategy details. Annex III of the EU AI Act (Regulation (EU) 2024/1689, effective 2024) limits high-risk AI in the financial domain to credit scoring of natural persons and the risk assessment and pricing of life and health insurance, and does not explicitly list high-frequency or algorithmic trading AI as a high-risk system; the latter is regulated separately, mainly by MiFID II and its delegated regulations. To extend the Act's transparency and human-oversight requirements by analogy to high-frequency trading AI would be an inference about regulatory trends rather than a current legal classification, and a decentralized, autonomous agent is architecturally hard-pressed to meet such requirements. A compliance-credential mechanism that claims universal applicability must find a greatest common divisor among the different regulatory frameworks, or provide differentiated credential tiers for different jurisdictions.

### 31.6.3 Native compliance and formal verification

Chapter 30 explored how embedded compliance turns regulatory rules into automatically executed code logic through smart contracts. In a market with the broad participation of AI agents, this concept can be extended further, so that compliance requirements are no longer an external constraint imposed on the agent after it decides, but are internalized as a prior property of its decision model. This internalization is usually accomplished through three levels of engineering implementation: hardcoded rules, parameterized constraints, and behavioral monitoring.

Hardcoded rules are the most basic level of embedded compliance; they directly remove options that violate a regulatory floor from the agent's action space. A smart contract can, for example, mandate that the agent's leverage not exceed a particular threshold, or that the position concentration in a single asset remain within a safe range. Introducing a compliance-penalty term into a reinforcement learning reward function is a typical application of parameterized constraints. When the agent, during the exploration phase, attempts to execute a sequence of cancellations that could lead to market manipulation, the reward function gives extremely high negative feedback, thereby suppressing the generation of such strategies during the model-training phase. Behavioral monitoring, in turn, introduces external regulatory states in real time via an on-chain oracle, enabling the agent to dynamically adjust its risk-control parameters according to changes in market volatility or liquidity depth.

This "native compliance" design philosophy means that, for an AI agent, complying with the rules is no longer a choice based on cost-benefit analysis, but an inherent property of its operating mechanism. To ensure the reliability of this compliance property in a decentralized environment, formal verification technology becomes an indispensable tool. Formal verification, by means of mathematical proof, ensures that a smart contract's logic and an agent's decision boundaries strictly conform to expected compliance properties [35]. A verification tool can, for example, exhaustively examine the agent's action combinations across all possible market states and prove mathematically that it will never execute a self-trade that violates the "anti-wash-trading" rule. When the market environment changes or regulatory rules are updated, the agent must pass new formal verification and obtain an updated compliance credential before it can continue trading. This architecture, which deeply fuses compliance logic with trading logic, not only improves the real-time nature of regulation but also fundamentally reduces the systemic risk that an agent's autonomous evolution deviates from compliance boundaries.

### 31.6.4 AI and DAO governance

AI agents' penetration into market microstructure is not confined to the trading process; their potential role in the governance of decentralized autonomous organizations gives rise to more profound systemic risks. The core decision mechanism of a DAO usually relies on a token-based voting system, in which participants stake governance tokens to decide on protocol-parameter adjustments, treasury-fund allocation, or code upgrades. From the standpoint of technical implementation, so long as an AI agent can control a wallet address that holds governance tokens, it is fully capable of participating in governance. Such participation usually takes three forms: directly calling the smart-contract interface to vote, automatically delegating voting power to a particular representative through code logic, or serving as a strategy advisor that provides data-analysis-based voting recommendations to human voters.

AI agents' direct participation in governance, however, brings a new form of manipulation risk. Compared with human participants, an agent can monitor on-chain liquidity with extremely high efficiency, analyze a proposal's impact on different stakeholders, and execute a complex token-accumulation strategy in an instant. Han et al. (2025) [36] show that under a token-voting mechanism, a "whale" holding a large amount of tokens can accumulate enough voting power to manipulate governance outcomes, an attack often aimed at short-term gains. When such an attack is launched by an AI agent, its mechanism becomes more covert and more efficient. An agent can borrow an enormous sum without collateral via a flash loan and use cross-chain arbitrage or algorithmic market making to accumulate a large amount of governance tokens within an extremely short time. The flash-loan governance attack suffered by Beanstalk Protocol in April 2022 is a paradigmatic empirical case of this risk: the protocol treasury was drained of approximately $182 million (the protocol's total loss; the attacker's actual net profit was approximately $76 million to $80 million). The attacker had submitted a malicious governance proposal the previous day, then, within a single transaction, borrowed over $1 billion in flash loans, deposited it to acquire more than two-thirds of the voting power, voted to pass and execute the proposal, drained the treasury, and repaid the flash loans. Subsequently, multiple protocols deployed defensive measures such as time-weighted voting power and snapshot voting, but the effectiveness of these mechanisms against AI-augmented governance attacks remains to be tested, because an AI agent can more precisely coordinate the timing of an attack and distribute voting across addresses to evade defenses. Subsequently, at the instant a key proposal's time lock is about to expire or a voting window is about to close, the agent can launch a surprise vote, forcibly passing a proposal that modifies the protocol's liquidation parameters or lowers its own trading fees, thereby creating an asymmetric advantage for its trading strategy.

A governance attack launched by an AI agent is also harder to detect and defend against than human behavior. An agent can perfectly coordinate thousands of independent addresses to vote in a distributed manner, easily bypassing defense mechanisms such as quadratic voting that are meant to guard against single-point manipulation. Tamai and Kasahara (2024) [37] note that quadratic voting systems lack sufficient resistance to collusion by malicious participants. AI agents are naturally capable of carrying out such a "Sybil attack," rendering traditional anti-collusion mechanisms utterly ineffective. Whether to restrict AI agents' participation in governance at the protocol level, or how to delineate the boundaries of an "AI governance participation right," has therefore become a key open question in current on-chain governance design. One feasible line of thought is to divide permissions by decision type: allowing AI agents to participate in pure parameter optimization (such as dynamically adjusting lending rates), but strictly prohibiting their participation in constitutional decisions involving the protocol's core values, large-scale treasury allocation, or underlying code upgrades. Some protocols are also beginning to explore hybrid governance models combining reputation systems or biometric verification, so as to ensure that ultimate governance control always remains in the hands of verified human participants, thereby hedging against the fragility that purely capital-based token voting faces in the AI era.

## 31.7 From market participant to market infrastructure

The preceding subsections analyzed the impact of AI as a market participant, including high-frequency trading, algorithmic market making, MEV searching, and arbitrage execution. In these settings, AI exhibits externality and rivalry, and its core objective is to extract value from the market. Another important evolution, however, is underway: AI is shifting from a player that trades on the market into the infrastructure that constitutes the market itself. These two roles are entirely different in nature—the former derives profit from value extraction in a zero-sum or negative-sum game, while the latter derives value from the improvement of system efficiency in a positive-sum game. This evolution changes not only AI's positioning in financial markets, but also, more profoundly, reshapes the economic logic of the entire market microstructure. This section proceeds from four key questions to systematically analyze the mechanism, drivers, and long-term impact of this evolution.

Figure 31-6 presents AI's dual role in market microstructure and its evolutionary path. On the participant side, AI extracts market value on the strength of its speed and algorithmic advantages, but its profit margin is continually compressed under competitive pressure (Section 31.7.1 analyzes this oligopolistic mechanism in detail); on the infrastructure side, AI creates positive externalities by providing systemic services such as dynamic risk management, intelligent matching, and semantic prediction, sustaining a persistent capacity for value capture on the strength of network effects and economies of scale. This evolution from a zero-sum game to a positive-sum game is the main thread of the second half of this chapter.

![Figure 31-6](./images/fig-31-6-en.png)

**Figure 31-6.** AI's dual role and evolutionary path in market microstructure (Data source: compiled by the author)

### 31.7.1 The profit of participant AI trends toward zero

The core characteristic of participant AI is that it uses information-processing speed and multidimensional optimization capability to capture excess returns in the market. When there are only a few AI agents in the market, they can systematically beat human traders through their speed advantage and algorithmic advantage, thereby obtaining relatively high excess returns. This profit structure, however, is unsustainable over the long run, and the fundamental reason lies in the economic laws of a perfectly competitive market.

Classical economic theory holds that, under perfect competition, a firm's long-run economic profit trends toward zero [38]. The actual structure of the cryptocurrency market-making market, however, is not perfectly competitive but exhibits marked oligopolistic characteristics. A small number of leading market makers occupy the overwhelming majority of market share, colocation infrastructure and proprietary data sources constitute substantive barriers to entry, and the market-maker incentive programs between exchanges and a few institutions are in essence exclusive arrangements. Under an oligopolistic structure, excess profit does not necessarily trend toward zero, although competitive pressure does continually compress the profit space. This judgment corroborates the discussion of algorithmic tacit collusion in Section 31.1.4: the existence of collusive behavior itself indicates that the market is not perfectly competitive. Thus, the overall judgment that participant AI's profit faces downward pressure still holds, but its mechanism of action is the compression of profit margins under an oligopolistic structure, rather than the convergence of profit toward zero under perfect competition. Even so, AI agents are highly replicable; once a particular high-frequency trading or market-making strategy is shown to be profitable, capital and technical talent flow rapidly into the domain. Although this dynamic is not enough to eliminate the entry barriers of the oligopoly, it does intensify competition among existing participants. As ever more AI market makers and arbitrageurs enter the market, the competition among them evolves into a technological arms race at the millisecond or even microsecond level.

In this extremely competitive environment, arbitrage opportunities are rapidly discovered and eliminated, and market makers' bid-ask spreads are compressed to the limit. When AI agents evolve autonomously in a simulated market through reinforcement learning, even without any preset agreement or communication, they may spontaneously form collusive behavior to sustain supra-competitive profits [6]. In a real multi-agent competitive environment, however, this fragile tacit understanding is often broken by new entrants seeking to maximize short-term gains. As competition intensifies, the directional-trading alpha based on informational advantage and execution speed is continually eroded, and the marginal profit of value extraction inevitably trends toward zero. This process usually takes three to five years, evolving gradually from an initial period of high profit into a period of profit compression.

The deeper mechanism of this trend warrants further analysis. Participant AI's profit fundamentally comes from the market's information asymmetry and from differences in execution efficiency. When a large number of AI agents all possess similar data sources, similar computing power, and similar optimization objectives, however, these advantages rapidly dissipate. Every new competitor that enters further lowers the market's average profit margin. Eventually, the market evolves into a highly homogenized competitive landscape in which no participant can sustain a lasting excess return. This phenomenon is especially pronounced in crypto markets, because the replicability of code and the open-source culture allow a successful strategy to be copied hundreds of times within weeks. In sharp contrast, infrastructure AI does not participate directly in the market game but instead charges fees by providing systemic services; its profit comes from the real value the service creates, rather than from an information-asymmetry advantage. The stability and sustainability of this business model are far higher than those of participant AI.

### 31.7.2 The value space of infrastructure AI

As participant AI sees its profit trend toward zero in a highly competitive market, infrastructure AI displays an entirely different business logic and capacity for value capture. The market's demand for more robust risk control, more intelligent liquidation mechanisms, and more accurate oracle price feeds does not disappear because competition among trading participants intensifies. On the contrary, the rise in trading frequency and the increase in strategy complexity further amplify the dependence on high-quality market infrastructure. The value of infrastructure AI can be attributed to four dimensions of economic characteristics. Network effects are the core competitive barrier of infrastructure AI. When a dynamic risk engine or an intelligent matching system attracts more users, it can collect richer market-microstructure data. These data are in turn used to train and fine-tune the model, making the AI system's predictions more accurate and its responses more agile. The improvement in performance then attracts more liquidity and trading volume, forming a positive-feedback loop. The strength of this network effect is far greater than that of traditional financial infrastructure, because an AI model can learn from every single trade and optimize its decision logic in real time.

Economies of scale are especially prominent at the infrastructure level. Developing and deploying advanced AI models requires an enormous fixed cost, including computing-power investment and algorithm research and development. Once deployment is complete, however, the marginal cost of serving an additional user is extremely low. A single risk engine can serve hundreds of exchanges or lending protocols simultaneously without a corresponding increase in cost. This high degree of scalability enables infrastructure AI to achieve extremely high profit margins.

Switching costs further consolidate the value space of infrastructure AI. Once an exchange or DeFi protocol deeply integrates an AI risk-control module or a semantic oracle into its core architecture, replacing these components entails enormous technical risk and business-disruption cost. This deep system coupling enables infrastructure providers to enjoy extremely high customer stickiness. Users find it hard to replace these services not only economically but also technically, facing enormous obstacles.

The data-feedback effect, in turn, is the source of momentum for infrastructure AI's continuous evolution. As algorithmic trading has come to dominate capital markets, its potential to disrupt market efficiency has drawn widespread concern [39]. By processing vast amounts of trading data in real time, infrastructure AI can not only optimize its own model parameters but also identify and guard against the systemic risk triggered by participant AI's homogenized strategies. This defensive capacity is itself a valuable public good, making the entire market more stable and efficient. In the process of providing this public-good-like service, infrastructure AI can capture sustained and enormous economic value.

### 31.7.3 Comparing operating environments

The operating environment of AI infrastructure directly determines its functional boundaries and evolutionary potential. The current crypto-finance market presents a setting in which on-chain protocols and centralized exchanges coexist, and these two environments each have their own strengths and weaknesses in supporting AI agents. Table 31-4 compares the characteristic differences between the on-chain market and centralized exchanges as AI operating environments along seven dimensions: data transparency, execution control, system composability, deployment barrier to entry, order-execution speed, liquidity depth, and trading-friction cost. The table presents a complementary picture of the two environments: the on-chain market has structural advantages in transparency, composability, and permissionlessness, while centralized exchanges maintain a significant lead in execution speed, liquidity depth, and transaction cost. This comparison provides an analytical framework for understanding the optimal deployment environment for AI infrastructure.

| Assessment dimension | On-chain market | Centralized exchange |
| :--- | :--- | :--- |
| Data transparency | Fully transparent; all trades and state history are verifiable | Internal ledger opaque; only limited interface data provided |
| Execution control | Smart contracts execute directly, with no need to trust an intermediary | Relies on a centralized matching engine; counterparty risk exists |
| System composability | Extremely high; AI can combine complex strategies across protocols | Relatively low; constrained by the application programming interfaces (APIs) the exchange provides |
| Deployment barrier to entry | Permissionless; AI can autonomously deploy and iteratively upgrade | Permissioned; subject to the exchange's account and compliance policies |
| Order-execution speed | General-purpose L1/L2 are severely constrained by block time (Ethereum about 12 seconds), but dedicated application-chain order-book exchanges (such as Hyperliquid, about 200–400 milliseconds) already approach the level of centralized exchanges | Extremely fast; supports high-frequency trading and microsecond-level response |
| Liquidity depth | Fragmented and relatively shallow; readily produces price impact | Concentrated and deep; suitable for the smooth execution of large orders |
| Trading-friction cost | Gas fees are high and volatile, limiting economic viability | Fees are low and fixed, favoring the execution of high-frequency strategies |

**Table 31-4.** A comparison of the characteristics of the on-chain market and centralized exchanges as AI operating environments (Data source: compiled by the author)

The on-chain market provides a highly suitable operating environment for AI infrastructure. The blockchain's global-state-machine nature guarantees the full transparency and immutability of data, providing AI models with the highest-quality training data and eliminating the data falsification and hidden information common in centralized environments. Through smart contracts, an AI agent can directly control funds and execute logic without relying on a traditional trusted intermediary. This deterministic execution environment enables dynamic risk engines and predictive liquidation systems to run in a code-is-law manner by force, significantly reducing counterparty risk at the level of contract execution.

The on-chain market's extremely high composability allows an AI system to span different liquidity pools and lending protocols to conduct global asset optimization and risk hedging. This cross-protocol optimization capability does not exist at all in traditional financial markets. More critically, the permissionless nature enables AI agents to deploy, test, and upgrade autonomously without restriction, greatly accelerating the iteration cycle of innovation. A new AI strategy can be deployed to the blockchain within minutes, without waiting for the approval of any centralized institution. The current leading on-chain order-book exchanges, however, all rely on a centralized sequencer to achieve low-latency matching. The sequencer holds the power to order transactions and, in theory, has the ability to front-run and to censor selectively, which is essentially isomorphic to the core risk of a centralized exchange. The statement above that "smart contracts execute directly, with no need to trust an intermediary" must be qualified in the face of the reality of sequencer centralization. A fundamental trade-off exists between speed and decentralization, and one should not assume that this contradiction can be simply dissolved by technological progress.

Centralized exchanges, however, maintain a significant advantage in physical performance and market depth. A centralized matching engine can provide microsecond-level order-execution speed, which directly determines the competitiveness of high-frequency trading AI. A concentrated liquidity pool means that AI faces smaller price impact when making large-scale position adjustments. Low and predictable transaction costs also make complex, frequent-interaction strategies economically viable.

Over the long run, as zero-knowledge proof technology and high-performance compute chains mature, the on-chain market's disadvantages in speed and cost are expected to be gradually eliminated. Its structural advantages in transparency, composability, and permissionlessness will make the on-chain environment the primary operating environment for AI infrastructure. This is not merely a technical question but also an economic one: the on-chain market provides a truly open, transparent, and trustworthy infrastructure, which is precisely the highest-quality operating environment that AI systems need. From an evolutionary standpoint, centralized exchanges may gradually evolve into a liquidity-aggregation layer for the on-chain market, rather than an independent trading venue. This evolution will further consolidate the on-chain market's status as the preferred environment for AI infrastructure.

### 31.7.4 Value-capture mechanisms

As AI evolves from participant to infrastructure in market microstructure, its value-capture mechanism also faces a paradigm shift. In traditional financial markets, infrastructure service providers usually adopt a direct service-fee model, charging a fixed proportional fee according to the number of API calls, the volume of data processed, or the scale of assets managed. The advantages of this model are stable cash flow, clear business logic, and ease of understanding and valuation by traditional investors. The AI risk-control systems and intelligent matching engines deployed within centralized exchanges mostly follow this traditional business model, treating it as part of the platform's overall competitiveness and charging users implicitly through trading fees.

In DeFi and open networks, the protocol-token model provides an entirely new path for value capture by AI infrastructure. In this model, the value of the AI system is mapped directly onto the native token it issues. The token serves not only as a governance tool, allowing the community to participate in deciding the key parameters and upgrade direction of the AI model, but also, more importantly, as a vehicle for value accrual. When a protocol generates revenue through AI services, that revenue can be internalized by buying back and burning tokens or distributing it directly to token stakers. This mechanism enables token holders to directly share in the economic value the AI system creates.

The protocol-token model can effectively coordinate the interests of developers, liquidity providers, and users. Through token incentives, it can bootstrap the cold start of an early network and accelerate the formation of network effects. This incentive mechanism does not exist in the traditional service-fee model. The token can also serve as a flexible incentive tool to reward participants who contribute to the network, such as market makers who provide liquidity or traders who contribute data.

The two models face different trade-offs in practical application. Although the service-fee model is stable, in the highly involuted crypto market it readily faces a price war, causing profit margins to be continually compressed. Competitors can lower fees to grab market share, ultimately driving down the profit margin of the entire industry. This phenomenon has been amply demonstrated in traditional cloud computing and database services, where many once-high-profit businesses eventually evolved into low-profit commoditized services. Although the protocol-token model has strong explosive power and network-expansion capability, it is also readily subject to the negative influence of token-price volatility, falling into a speculation-driven negative-feedback loop. When the token price falls, the appeal of the incentive mechanism drops sharply, potentially causing a reversal of network effects. Many early token-incentive projects have gone through such a decline cycle.

The application of AI in financial markets brings the potential for productivity gains and cost savings, while also posing challenges to existing regulatory frameworks [40]. The future evolutionary trend may be a fusion of the two. Basic API calls and data queries adopt a low service fee to expand market share, while advanced predictive models, customized risk-hedging strategies, and protocol governance rights capture higher-order value through token economics. This hybrid architecture can not only guarantee sustained operating cash flow for the infrastructure but also, through the token mechanism, capture the long-term value that the AI system creates in the process of reshaping market microstructure. This model has already begun to be practiced in some leading DeFi protocols and has shown good sustainability.

From a deeper economic perspective, the value space of infrastructure AI is enormous also because it can create and sustain informational symmetry in the market. As stated at the beginning of this section, participant AI's profit comes from value extraction in a zero-sum game, whereas infrastructure AI's value comes from efficiency improvement in a positive-sum game; the latter is far more sustainable than the former, because it does not dry up as competition intensifies. On the contrary, the more market participants there are and the more frequent the trading, the greater the value of the infrastructure. This forms a virtuous cycle that enables infrastructure AI to sustain its capacity for value capture over the long run.

## 31.8 The six core AI-driven systems

AI's role in financial markets is undergoing a profound transformation, from an external trader playing the market game into the intrinsic infrastructure that constitutes the market itself. In Chapters 28 through 30, we built a trust stack based on static rules and hardcoded parameters, an architecture that achieved decentralized trading through the combination of oracles, matching engines, and liquidation mechanisms. This static architecture, however, often proves rigid when facing extreme market volatility and complex counterparty risk, struggling to strike the best balance between security and capital efficiency. When AI agents become the core components of this infrastructure, the static architecture will be upgraded into an adaptive system with real-time perception, dynamic adjustment, and predictive capability.

Figure 31-7 shows the correspondence between the six core AI-driven systems and the Chapter 28 trust stack; overall, it achieves an upgrade from passive response to proactive optimization (the item-by-item mapping appears in Table 31-5).

![Figure 31-7](./images/fig-31-7-en.png)

**Figure 31-7.** The mapping of the six core AI-driven systems to the Chapter 28 trust stack (conceptual illustration; based on the author's theoretical derivation)

Table 31-5 summarizes the functional matrix of these six AI systems. The table maps each system to a specific layer of the trust stack defined in Chapter 28 and separately clarifies its upgrade mechanism and value-creation path. The six systems exhibit a common evolutionary pattern: the direction of upgrade is uniformly from static rule execution toward dynamic, adaptive optimization based on real-time market states, while value creation points uniformly toward improving capital efficiency and reducing systemic risk.

| Core AI-driven system | Position in the trust stack | Upgrade mechanism | Value creation |
| :--- | :--- | :--- | :--- |
| Dynamic risk-parameter system | Oracle and risk layer | From static rules to real-time parameter adjustment based on market state | Improves capital efficiency and reduces systemic risk |
| Intelligent matching engine | Matching and execution layer | From price-time priority to the introduction of toxicity awareness and isolation | Protects market makers and improves the quality of price discovery |
| Predictive liquidation system | Liquidation-mechanism layer | From post-trigger execution to probability-based prediction and prevention | Reduces liquidation cascades and eases market panic |
| Dynamic pricing mechanism | Asset-settlement layer | From a fixed formula to supply-and-demand-driven adaptive rate optimization | Balances long and short forces and incentivizes long-term liquidity |
| Adaptive compliance monitoring | Protocol-governance layer | From after-the-fact audit to real-time anomaly interception based on pattern recognition | Reduces compliance cost and enhances market integrity |
| Liquidity-routing optimization | Liquidity-aggregation layer | From a single path to cross-chain, cross-protocol deep-reinforcement-learning routing | Minimizes trading slippage and maximizes execution efficiency |

**Table 31-5.** The functional matrix of the six AI systems (Data source: theoretical derivation in this chapter)

### 31.8.1 Dynamic risk parameters

In the traditional margin system discussed in Chapter 29, the initial margin rate and the maintenance margin rate are usually set by protocol governance as static parameters. The fundamental problem with this design is that it tries to use a single numerical value to cope with multidimensional market changes. Mainstream exchanges today all adopt a tiered margin system. Taking Binance's Bitcoin perpetual futures as an example, the initial margin rate ranges from 1% for low-leverage, small positions to 50% for high-leverage, large positions, spanning more than ten discrete tiers. This tiered design is itself a rough attempt at dynamization; the true incremental value of an AI dynamic risk-parameter system lies in turning these discrete tiers into a continuous function based on multidimensional market states. Even under the existing tiered system, however, the fundamental limitation of static parameters persists: in a calm market, a fixed margin requirement often leads to low capital efficiency, forcing traders to lock up far more margin than their actual risk requires; while in a period of violent volatility, an insufficient safety cushion may trigger a systemic account deficit.

The limitation of a static-parameter system is that it ignores the dynamic nature of market microstructure. When market volatility suddenly jumps from 20% to 80%, the originally sufficient 10% margin immediately becomes dangerous, but the protocol cannot respond automatically. Conversely, when the market enters a calm period and volatility falls to 5%, a 10% margin requirement appears overly conservative and wastes the trader's capital. In addition, static parameters cannot account for changes in liquidity depth. In a high-liquidity environment, even if an account is close to the liquidation line, the liquidator can execute the liquidation quickly without causing excessive market impact; but in an environment where liquidity has dried up, the same liquidation could widen price slippage by more than 20%, thereby triggering a liquidation cascade.

An AI-driven dynamic risk-parameter system, by introducing multimodal deep-learning models, achieves a deep coupling between risk parameters and real-time market states. The core input features of the system include four dimensions: first, real-time volatility, for which the system updates the asset's implied-volatility estimate at the millisecond level via a GARCH model or a neural-network volatility predictor; second, market depth, for which the system monitors the liquidity depth at each price level of the order book and computes the average slippage required to execute a large order; third, cross-asset correlation, for which the system tracks the dynamic correlation coefficients among different assets and, when the correlation suddenly rises (indicating increased market stress), raises the margin requirement for all assets; and fourth, historical liquidation data, for which the system uses past liquidation events to calibrate the current risk model and identify which combinations of market states are most likely to lead to a liquidation cascade.

Based on these input features, the AI system computes a tiered margin matrix rather than a single margin rate. The dimensions of this matrix include asset type, leverage multiple, and market state. When Bitcoin's volatility is at the 25th historical percentile and order-book depth is ample, for example, the system might lower the initial margin requirement from 10% to 7%; whereas when volatility jumps to the 75th historical percentile and liquidity dries up, the system would raise the margin requirement to 15%. According to a 2025 study by Huang et al., this dynamic-adjustment approach, compared with a static-parameter system, has the potential to reduce liquidation losses in stress scenarios and improve capital efficiency under normal conditions (the specific magnitude varies by model and dataset, and precise figures still lack an independently verifiable source) [41].

The introduction of dynamic parameter adjustment changes traders' risk expectations, which also brings new design challenges. In a static model, the trader need only focus on the absolute distance of the price from the liquidation line; in a dynamic model, the trader must simultaneously assess the risk that a deterioration in market state will suddenly raise the margin requirement. This gives rise to a trade-off over the frequency of parameter adjustment. If the system adjusts the margin requirement every second, the trader faces extremely high uncertainty, which may cause overly conservative positioning and thereby reduce market efficiency; but if the adjustment frequency is too low (for example, once an hour), the system cannot respond in time to a sudden market shock. The optimal solution in practice is a tiered adjustment strategy: when the market state changes slowly, the margin parameters are updated every 5 minutes; when a market-stress signal is detected (such as a volatility jump or a sudden drop in liquidity), the system immediately triggers an emergency adjustment, but simultaneously sends an early warning to all affected traders, giving them a buffer of 2 to 5 minutes to proactively adjust their positions.

The margin-adjustment early-warning mechanism may itself trigger a coordination-game problem. When a large number of traders simultaneously learn that the margin rate is about to be raised, the rational response is to close positions immediately to avoid a margin call, and when everyone takes this action at the same time, the collective selling pressure may trigger the very crisis the warning was meant to prevent, forming a self-fulfilling loop akin to a bank run. In addition, the margin-adjustment warning faces an information-security risk: institutional users with API-monitoring capability may detect an impending adjustment in advance through changes in the system's behavioral patterns and act first. The design of the early-warning mechanism must therefore carefully weigh the tension between information transparency and market stability.

In the CEX perpetual futures market, the dynamic risk-parameter system faces several distinctive design considerations. First, the tiered margin system requires the system to dynamically adjust the margin rate according to position size, with larger positions bearing higher margin requirements to reflect their potential impact on market liquidity. Based on real-time order-book depth and historical large-liquidation data, an AI system can dynamically optimize the margin rate and position cap of each tier, striking a finer balance between capital efficiency and system safety. Second, the AI optimization of the auto-deleveraging (ADL) mechanism is significant. The traditional ADL mechanism forcibly hedges the positions of profitable parties according to a profit ranking in order to cover account-deficit losses, a process that often provokes discontent among profitable traders and a crisis of market trust. An AI system can predict the probability of an account deficit and intervene in advance—for example, proactively adjusting the margin requirement of high-risk accounts before ADL is triggered, or optimizing the execution order to minimize market impact—thereby significantly reducing the trigger frequency and negative impact of ADL. The full trigger chain for ADL is as follows: the account reaches the maintenance-margin line, the liquidation engine takes over, an account deficit arises during liquidation execution, the insurance fund covers the shortfall, and, when the insurance fund is insufficient, ADL is triggered. AI intervention is distributed across different nodes of this chain: dynamic margining reduces the probability of triggering liquidation, acting on the first link; predictive liquidation improves execution quality and thereby reduces the probability of an account deficit, acting on the second link; and dynamic insurance-fund management reduces the probability of triggering ADL, acting on the third link. These are independent optimization objectives at different levels and should not be conflated.

In addition, the dynamic risk-parameter system must also solve the problem of "parameter transparency." A traditional protocol's static parameters are public and easy to understand, but AI-generated dynamic parameters are often a black box, and traders find it hard to predict the margin requirement of the next instant. To build trust, the protocol should publish the computational basis of the risk parameters in real time, including the current volatility estimate, the liquidity-depth score, and the correlation indicators, enabling traders to understand the reasons for parameter changes. This transparency not only enhances user trust but also provides a basis for regulators to audit.

### 31.8.2 Intelligent matching engine

The matching logic of a traditional order book strictly follows the principles of price priority and time priority. Although this mechanism guarantees surface-level fairness, it leaves the market maker who passively provides liquidity fully exposed to the adverse-selection risk from informed traders. In traditional matching, a large market buy order immediately fills against the best ask on the order book, regardless of whether that ask comes from a well-informed arbitrageur or an uninformed retail trader. This indiscriminate matching mechanism causes the market maker's return curve to exhibit the typical character of a "bearer of adverse-selection losses": the market maker earns limited spread income when the market is calm, but suffers significant adverse-selection losses when the market is volatile.

As discussed in Chapter 19, toxic order flow is a core driver of liquidity droughts. Toxic flow refers to orders from traders with an informational advantage, whose execution inflicts an adverse price impact on the market maker. Traditional market makers cannot identify the toxicity of an order before execution and can only passively bear the loss. From the standpoint of market design, Budish, Cramton, and Shim (2015) [42] once proposed replacing the continuous limit order book with frequent batch auctions, aiming to fundamentally eliminate the adverse-selection problem arising from speed competition. Although that scheme faces challenges such as liquidity fragmentation in practice, its core insight—protecting market makers by changing the matching mechanism itself—is highly consistent in goal with an AI-driven, toxicity-aware matching engine. The difference between the two is that batch auctions eliminate the speed advantage by discretizing time, whereas an intelligent matching engine neutralizes the informational advantage through continuous toxicity assessment. An AI-augmented intelligent matching engine, by introducing an order-flow-toxicity identification mechanism, fundamentally reshapes the microstructure of the matching layer.

The intelligent matching engine uses deep neural networks to analyze the microlevel features of every incoming order in real time in order to predict its toxicity probability. These features span multiple dimensions: the size of the order relative to recent trading volume, since larger orders are more likely to come from informed traders; the order's submission frequency and pattern, since high-frequency small orders may indicate an algorithmic trader probing market depth; the order's cancellation rate, since a high cancellation rate indicates the trader may be spoofing or manipulating the market; the account-history features of the order submitter, including the profitability of past trades, the distribution of holding times, and whether there is any known arbitrage strategy; and the correlation of the order with macro market data, for example whether the order's direction is consistent with recent price momentum. Existing research (Cartea et al., *Detecting Toxic Flow*, focused on foreign-exchange broker-client trades) proposes an online method for predicting the toxicity of a single fill and, on that basis, deciding whether to internalize or externalize it in order to reduce adverse-selection losses; its approach can be analogously transferred to the toxicity-aware setting of order-book market making [43].

Based on these toxicity predictions, the matching engine can implement a tiered-response strategy. For retail orders judged to be of low toxicity (toxicity probability below 30%), the system provides the best execution price and the smallest slippage, ensuring that retail traders receive the best execution quality. For orders identified as of moderate toxicity (toxicity probability between 30% and 70%), the system may introduce a microsecond-level execution delay before execution, giving the market maker an opportunity to adjust its quotes. For arbitrage or high-frequency-attack orders identified as of high toxicity (toxicity probability above 70%), the system may take more aggressive measures: routing them to a particular liquidity pool with a higher slippage tolerance, or requiring the trader to pay a higher fee before execution as a "toxicity tax," which is used to compensate the market maker's adverse-selection losses.

This toxicity-aware matching mechanism effectively mitigates the adverse-selection problem facing market makers. When market makers know that the system can filter out most predatory orders, they will be more willing to provide deeper liquidity within a narrower spread. Empirical research shows that after the introduction of toxicity-aware matching, market makers' spreads typically narrow by 20% to 30%, while market depth increases by 40% to 60%, which benefits all traders.

This mechanism, however, also gives rise to a profound controversy over market fairness. When the algorithm decides execution quality based on a trader's behavioral features rather than on the quote alone, the traditional principle of equal market access faces the challenge of redefinition. A legitimate retail trader may be misjudged by the system as toxic flow because their trading pattern resembles that of a high-frequency arbitrageur, and thereby suffer worse execution quality. To address this compliance risk, the protocol needs to establish a transparent toxicity-scoring mechanism, disclosing to the trader the reasons their order was scored as highly toxic and providing an appeal mechanism. In addition, the protocol should conduct regular fairness audits to ensure that the toxicity-identification model does not systematically discriminate against particular types of traders.

Examined more deeply, the toxicity-aware matching engine faces structural limitations along four dimensions. First is the inevitable operation of Goodhart's law: once a toxicity-scoring mechanism is deployed, informed traders will immediately adjust their behavior to evade a high-toxicity judgment, including strategies such as splitting order size, mimicking retail trading patterns, and dispersing order flow across multiple unlinked accounts. The backtested accuracy of such a toxicity-identification model is in essence a static result based on historical data, and in an adversarial live environment its accuracy may rapidly decay, forcing the model into a continual offense-defense iteration. Second, differentiated execution delay poses a fundamental contradiction at the level of market design: imposing different execution delays on different orders fundamentally violates the value proposition of a centralized exchange, whose core competitiveness is deterministic low latency. Facing uncertain execution timing, a market maker's rational response is precisely to widen its quote spread to compensate for the execution uncertainty, which ultimately harms overall market quality—forming a paradox with the original intent of protecting market makers. Notably, existing non-discriminatory design schemes in the field of market microstructure offer an entirely different line of thought: the Investors Exchange (IEX) speed bump imposes a uniform, fixed delay on all participants, rather than a differentiated delay targeting particular orders; likewise, the frequent-batch-auction scheme mentioned earlier adopts a discretized-time mechanism that treats all orders alike. The common feature of these two designs is non-discrimination, which is essentially different from differentiated execution based on a toxicity score. Third, examined from the angle of legal compliance, the best-execution obligation under U.S. securities law requires brokers to seek the best execution for all clients, while MiFID II in the EU expressly stipulates that a trading venue's rules must be transparent and non-discriminatory. AI-toxicity-score-based differentiated execution quality may come into direct conflict with these legal requirements, especially when the internal logic of the toxicity-scoring model is difficult to explain fully to regulators, further amplifying the compliance risk. Fourth, in the context of a centralized exchange there is also a potential conflict-of-interest hazard: when an exchange simultaneously operates the matching engine and participates directly or indirectly in the market-making business, the toxicity-scoring system may provide an informational advantage to the exchange's affiliated market makers, enabling them to identify and evade informed order flow in advance, while independent market makers and ordinary traders cannot obtain the same protection.

In the CEX order-book market, the implementation path of an intelligent matching engine differs markedly from that of an on-chain protocol. The CEX's centralized matching architecture naturally supports microsecond-level order processing and toxicity assessment, without having to contend with the constraint of blockchain block time. Specifically, a CEX can layer an AI toxicity-filtering layer on top of the traditional price-time-priority matching logic: when a new order enters the matching queue, the system completes the toxicity scoring within microseconds and, on that basis, decides whether to introduce an execution delay, adjust the execution price, or route the order to a dedicated liquidity pool. This architecture enables the CEX to provide effective adverse-selection protection for market makers without changing the basic matching rules, thereby incentivizing deeper order-book liquidity.

### 31.8.3 Predictive liquidation

Chapter 29 analyzed in detail the operating logic of the liquidation mechanism; the traditional liquidation system is in essence passive and reactive. Only when an account's collateralization ratio falls below the maintenance-margin threshold is the liquidation engine triggered to dump assets onto the market. In extreme conditions, this mechanism readily triggers a liquidation cascade: the selling pressure caused by liquidation further depresses the price, triggering the liquidation of more accounts, and ultimately becoming a collapse of market liquidity. The liquidation events of multiple DeFi protocols in 2024 show that during periods of extreme volatility, a liquidation cascade can cause a protocol's total collateral value to fall by more than 30% within minutes, resulting in a large number of involuntary liquidations for users.

A predictive liquidation system breaks this passive cycle through machine-learning models. The system uses long short-term memory (LSTM) networks and other recurrent-neural-network architectures to analyze data along multiple dimensions in order to compute the probability that each leveraged account will be liquidated within a particular future time window. These features include: the account's current leverage ratio and its distance from the liquidation line; the short-term momentum and volatility of the asset price; the real-time depth and trend of market liquidity; historical liquidation events with account features similar to the current account and their outcomes; and macro market-stress indicators, such as the volatility index (VIX) and cross-asset correlations. By integrating these features, the predictive model can estimate the liquidation probability with fairly high accuracy. According to a 2024 study by Palaiokrassas et al., a variety of machine-learning models can classify wallet-level liquidation and report metrics such as accuracy and AUC (area under the curve), demonstrating the effectiveness of DeFi on-chain features for liquidation prediction (the specific figures depend on their dataset and evaluation criteria) [44].

Based on this probability prediction, the system implements a tiered action model, moving risk management forward rather than responding after the fact. Figure 31-8 shows the structure of this model: when an account's liquidation probability exceeds the extremely-high-risk threshold of 90%, the system no longer waits for the actual liquidation to trigger but proactively executes a partial position reduction, with the goal of lowering the liquidation probability below 70%; because the reduction is proactive and dispersed, the market impact is typically only 20% to 30% of that of a conventional liquidation.

![Figure 31-8](./images/fig-31-8-en.png)

**Figure 31-8.** The probability-tiered action model of predictive liquidation (conceptual illustration; based on the author's theoretical derivation)

When the liquidation probability is between 70% and 90%, the system enters a second-tier response, sending a high-priority early-warning notification to the trader. This warning not only informs the user that their account is in a dangerous state but also provides specific recommendations: how much margin needs to be added, or how much position needs to be reduced, to restore safety. The warning is sent through multiple channels, including on-chain events, email, and push notifications, ensuring that the trader receives the information in time. The trader has 5 to 10 minutes to proactively adjust their position; if the trader takes no action within this time window, the system then executes auto-deleveraging.

When the liquidation probability is between 50% and 70%, the system enters a third-tier response, increasing the monitoring frequency to the second level and preparing to respond quickly if necessary. At this point the system does not proactively intervene but continually assesses the risk, and once the probability breaks through the 70% threshold, it immediately triggers the second-tier response. When the liquidation probability falls below 50%, the system returns to the normal monitoring cycle (usually at the minute level), and the account is regarded as being in a safe state.

This paradigm shift from passive execution to proactive prevention mitigates the transmission chain of a liquidation cascade. By smoothly releasing risk before a crisis erupts, the predictive system substantially reduces the probability of a systemic collapse. According to empirical analysis, after the introduction of a predictive liquidation system, the scale of liquidation cascades under extreme market conditions is typically reduced by 60% to 80%, and the overall stability of the system improves significantly.

At the same time, this mechanism has a profound impact on the role of the liquidator. Traditional arbitrage-type liquidators profit by buying collateral at a steep discount when the market is in turmoil, a model that encourages liquidators to liquidate when market pressure is greatest, thereby intensifying market panic. In a predictive liquidation system, by contrast, most liquidations take place at the moment of least market pressure, and the profit space for liquidation shrinks substantially. This causes traditional arbitrage-type liquidators to be gradually replaced by the protocol's own algorithmic engine, and the distribution of liquidation profit likewise flows back from external extractors to the protocol itself or to protected users.

The predictive liquidation system, however, also gives rise to profound concerns about "moral hazard." If the protocol commands a more accurate liquidation-probability prediction than the market, will it use this informational advantage to harm users' interests? For example, the protocol might deliberately delay a liquidation so that the account's liquidation probability rises further, enabling it to execute the liquidation at a lower price. To prevent such abuse, the protocol needs to establish a strict governance mechanism, ensuring that all parameters and decision rules of the predictive liquidation system are transparent and are subject to regular independent audits. In addition, the protocol should provide users with real-time data on the "liquidation-probability prediction," enabling users to independently verify the system's decisions.

Beyond moral hazard, predictive liquidation also faces deeper challenges on two fronts: user rights and data reliability. As regards user consent, the "proactive position reduction" that predictive liquidation implements is in essence a forced liquidation executed before the user's margin has reached the liquidation line explicitly agreed in the contract. The trigger condition for traditional liquidation is an explicit, predictable contractual term, whereas "a liquidation probability exceeding 90%" is a model estimate that the user cannot independently verify. In a scenario where the price reverses in a V shape, the model may close out early a position that would have returned to profit, causing an unnecessary loss. Predictive liquidation terms must therefore obtain the user's explicit informed consent when the position is opened, and a compensation mechanism for model misjudgment should be established. As regards the reliability of input data, the fatal weakness of predictive liquidation is that it depends entirely on the quality of the input data. Oracle price-feed failures and interruptions of exchange data interfaces are not rare in practice; the March 2023 oracle price-latency incident on a particular Layer 2 network once caused a large number of improper liquidations. When the input data are erroneous, the more "precise" the predictive model, the more dangerous it becomes: it will execute an erroneous preventive reduction with extremely high confidence based on erroneous data, and the resulting loss may far exceed that of a traditional passive liquidation mechanism.

### 31.8.4 Dynamic pricing

The funding rate of perpetual futures and the trading fee of decentralized exchanges are core economic levers for regulating the balance of market supply and demand. In traditional designs, these rates are usually computed based on a hardcoded linear or piecewise function whose parameters are often hard to adapt to a rapidly changing market environment. The standard formula adopted by mainstream perpetual futures protocols is $F = P + \operatorname{clamp}(I - P,\ c_{\min},\ c_{\max})$, where $F$ is the funding rate, $P$ is the average premium index (which reflects the degree of deviation between the perpetual futures price and the mark price), $I$ is the interest rate, and $[c_{\min}, c_{\max}]$ are the preset lower and upper bounds within which the clamp function constrains the funding rate; these bounds are usually set as a symmetric interval (for example, $\pm 0.05\%$, corresponding to an 8-hour settlement period), with the specific values determined by protocol parameters. Every term in the formula is expressed as a rate over a single settlement period (8 hours by default); the interest rate $I$ is the value normalized to that settlement period (for example, $0.03\%/8\text{h}$) rather than an annualized value. The problem with this design is that the time-weighting window of the premium index is fixed, the upper and lower bounds of the clamp function are static presets, and the settlement period is rigidly locked at once every 8 hours, so the whole mechanism cannot anticipate dynamic market changes and can only passively react to the current imbalance.

An AI-driven dynamic pricing mechanism uses reinforcement learning algorithms to achieve a global adaptive optimization of the rate system. On the funding-rate side, the dynamic pricing system carries out an intelligent transformation around the three core parameter dimensions of the standard formula above. First, the time-weighting window of the premium index can be dynamically adjusted according to the market's volatility regime: a longer window is used in a low-volatility environment to filter out noise, and the window is shortened in a high-volatility environment to speed up the response to price deviations. Second, the upper and lower bounds of the clamp function are no longer static constants but dynamic parameters that change with market conditions—tightening the constraint range in a market with ample liquidity and stable volatility to keep the rate smooth, and moderately loosening the bounds when the market shows violent deviation to strengthen the rate's regulatory force. Third, the settlement frequency shifts from a fixed once-every-8-hours to a variable period based on market state, raising the settlement frequency to speed up price convergence when the contract price and the mark price deviate persistently and sharply, and lowering the frequency to reduce unnecessary trading friction when the prices are closely aligned. The system also uses a time-series forecasting model to predict the short-term evolution of the premium index; if the forecast indicates that the perpetual futures price is about to deviate sharply from the mark price, the system adjusts the above parameters in advance, thereby beginning to intervene before the imbalance intensifies.

Machine-learning models, by predicting the marginal impact of different rate levels on the behavior of market participants, dynamically adjust the slope and intercept of the rate curve so as to incentivize arbitrageurs to enter and smooth out the price deviation in the most efficient way. For example, when the spot-market price of Bitcoin is $65,000 while the perpetual futures price is $65,500, a traditional system might simply raise the funding rate to 0.05% in the hope of attracting arbitrageurs. But an AI system would analyze more finely: How many arbitrageurs are currently active in the market? How many new arbitrageurs would raising the funding rate to 0.05% attract? How long would it take these arbitrageurs to close their positions? Based on this analysis, the system might decide to raise the funding rate to 0.08%, or simultaneously lower the trading fee to 0.02%, so as to attract arbitrage flow more efficiently. The 0.05%, 0.08%, and 0.02% here are illustrative decision values used to characterize how an AI system might weigh its options, and are not computed by substituting $P$ and $I$ into the standard formula $F = P + \operatorname{clamp}(I - P,\ c_{\min},\ c_{\max})$ above.

On the fee-optimization side, a reinforcement learning agent dynamically sets the optimal trading fee according to the real-time depth of the liquidity pool, expected volatility, and the quotes of competing protocols. This optimization problem involves a trade-off among multiple objectives: lowering the fee can attract more trading volume but reduces protocol revenue; raising the fee can increase revenue but causes trading volume to fall and may even drive users to competitors. By continually trying different fee levels, the reinforcement learning agent learns a Nash equilibrium point at which the protocol's total revenue (trading volume times fee rate) is maximized.

According to empirical research, an AI dynamic pricing mechanism, compared with a static rate, can significantly increase the protocol's total revenue (an estimate based on the author's reading of industry cases) while maintaining or improving users' execution quality. This is because an AI system can lower fees to attract trading volume when liquidity is ample, and raise fees to protect market makers when liquidity is tight, thereby achieving an optimal supply-demand balance across different market states.

This dynamic pricing mechanism enables the protocol to implement a personalized fee structure. Based on a user's historical trading behavior, position stability, and contribution to the protocol's liquidity, the system can offer differentiated pricing schemes to different participants. For example, long-term holders and stable liquidity providers might receive a lower fee discount, while high-frequency traders and arbitrageurs might have to pay a higher fee. This personalized pricing not only enhances the protocol's competitiveness but also marks the evolution of DeFi's pricing logic from a mechanical, formulaic approach toward an intelligent, commercial one.

Personalized pricing, however, also gives rise to a regulatory risk over "price discrimination." If the protocol charges different fees to different users, does this constitute discrimination against certain users? To address this risk, the protocol should establish transparent pricing rules, publicly disclosing to all users the method for computing fee discounts and ensuring that the pricing rules do not have a systematically adverse effect on a particular group of users. A more fundamental problem is that there is a structural conflict of interest between the AI dynamic pricing objective of "maximizing protocol revenue" and the user's objective of "minimizing transaction cost." The win-win narrative of "increasing revenue while improving execution quality" holds only under particular conditions—namely, in periods when users' demand elasticity is relatively high; in periods when liquidity is tight, an AI system may in effect become a tool for charging users higher fees, which is logically highly similar to the surge-pricing controversy of ride-hailing platforms. At the level of legal compliance, personalized pricing relies on collecting and analyzing users' trading histories, which may conflict with the data-minimization principle of the EU General Data Protection Regulation (GDPR). Differentiated pricing based on behavioral features, if it causes the pricing model to be systematically adverse to a particular group of users, may constitute algorithmic discrimination. In addition, multiple jurisdictions have explicit regulatory requirements for fairness in securities pricing, and a differentiated fee structure faces the risk of compliance scrutiny in these jurisdictions.

### 31.8.5 Adaptive compliance monitoring

As the scale of on-chain finance expands, regulatory compliance becomes a necessary condition for a protocol's long-term survival. Chapter 30 explored the static implementation of embedded compliance, but this filtering mechanism based on whitelists and fixed rules often struggles to cope with complex and varied means of market manipulation. An adaptive compliance-monitoring system, by integrating AI technology, achieves a leap from rule matching to pattern recognition.

The system uses unsupervised machine learning and graph neural networks to scan vast amounts of on-chain transaction data in real time. The system's monitoring is divided into three levels. The first level is real-time transaction-pattern analysis, in which the system extracts features from each transaction—including transaction size, direction, timestamp, trading pair, and the age of the trader's account—and then, through anomaly-detection algorithms such as the isolation forest or the local outlier factor, identifies transactions that deviate markedly from normal trading patterns. The second level is account-behavior clustering, in which the system clusters accounts according to their trading-behavior features and identifies groups of accounts with similar behavioral patterns, which may represent a coordinated manipulation team. The third level is cross-account association identification, in which the system, by analyzing the flow of funds among accounts, the correlation of trading times, and the correlation of positions, identifies groups of accounts that may have an interest linkage.

Through these three levels of analysis, the system can identify potential wash trading, front-running attacks, and price manipulation. The features of wash trading include: the trading counterparty is the same account or a linked account, the interval between trades is extremely short (usually at the second level), the trade price is unrelated to the market price, and the trade size exhibits a periodic pattern over a period of time. The features of a front-running attack include: the attacker submits an order before a large trade executes and immediately closes the position after the large trade executes, with the profit coming from the price impact the large trade causes. The features of price manipulation include: one or more accounts conduct a large number of trades within a short time, causing the price to swing sharply, and then these accounts close their positions at the price peak to profit.

Unlike a traditional alert system that relies on preset thresholds, an AI monitoring model can autonomously learn the baseline of normal market behavior and automatically trigger a blocking mechanism when it detects a complex, coordinated attack that deviates from the baseline. Existing research has explored using AI for the automatic identification of behaviors such as wash trading and price manipulation (Popoola, 2023 [45]), as well as the potential of machine-learning-based market surveillance, relative to traditional rule-based systems, to reduce false positives and improve detection coverage (Tiwari et al., 2021 [46], a survey); the reduction in false positives reported in real deployment cases is usually on the order of tens of percentage points.

The introduction of an adaptive compliance system not only reduces the protocol's regulatory risk but also provides the necessary infrastructure guarantee for the large-scale entry of institutional funds. Before entering a new market, institutional investors usually require that the market have sound anti-fraud and anti-manipulation mechanisms. A protocol equipped with an AI compliance-monitoring system can demonstrate the integrity of its market to institutional investors, thereby attracting more institutional funds.

More importantly, an adaptive compliance system changes the paradigm of governance. The traditional compliance model relies on manual review, a lagging and costly process. A trader may be discovered only hours or even days after conducting a manipulative act, by which time substantial damage has already been done. An AI-driven compliance system, by contrast, can detect and block a manipulative act in real time as it occurs, transforming compliance from an after-the-fact audit into a real-time anomaly-detection-and-blocking mechanism. This not only improves defensive efficiency but also substantially reduces the cost of compliance.

AI compliance monitoring, however, also gives rise to concerns about "privacy" and "false positives." If the system is overly sensitive, it may misjudge normal trading behavior as manipulation, thereby harming innocent traders. To address this risk, the protocol should establish a clear appeal mechanism, so that when a trader believes their trade has been wrongly flagged as manipulation, they can submit an appeal and obtain a manual review. In addition, the protocol should regularly publish statistics on compliance monitoring, including the number of manipulation cases detected and the false-positive rate, in order to accept community oversight.

### 31.8.6 Liquidity-routing optimization

In an ecosystem where multiple chains coexist and liquidity is fragmented, finding the optimal execution path for a large trade is a core challenge facing the liquidity-aggregation layer of Chapter 28. A $1 million trade may need to be split for execution across multiple protocols such as Uniswap, Curve, and Balancer in order to minimize slippage. Traditional routing algorithms usually rely on static graph search or simple linear programming; these methods are computationally efficient but often suboptimal in the quality of optimization. They struggle to achieve a truly optimal solution amid dynamically changing market depth and network congestion.

An AI-driven liquidity-routing-optimization system, through deep reinforcement learning, raises order execution to a new level of efficiency. The system formulates order routing as a Markov decision process, in which the state space includes all available liquidity pools and their current depths and prices, the action space includes all possible ways of allocating the order among the various liquidity pools, and the reward function is defined as minimizing total slippage and transaction cost.

The reinforcement learning agent continually explores the cross-protocol, cross-chain distribution of liquidity in this vast state space. The agent considers not only the instantaneous price and depth of each liquidity pool but also predicts the slippage changes that may occur during trade execution. If the agent decides to execute a $500,000 trade on Uniswap, for example, it must predict how much price impact this trade will cause on Uniswap and thus how much slippage will result. In addition, the agent must consider network latency and gas-fee fluctuations. When the Ethereum network is congested, the gas fee for executing a single trade may be as high as $100, whereas when the network is idle, the same trade may cost only $10 in gas. An intelligent routing system should choose fewer trade splits when the network is congested, so as to reduce gas costs.

By intelligently splitting a large order and dynamically allocating it across multiple optimal paths, the system can complete complex cross-market arbitrage and liquidity extraction within milliseconds. According to a 2025 study by Zhang and Tessone on an enhanced DEX routing method, the improved routing method can, compared with the baseline, increase DEX execution efficiency and the benefits to all parties (the specific figures depend on their evaluation criteria and dataset) [47].

The intelligentization of liquidity routing profoundly changes the competitive landscape of decentralized exchanges. In the traditional model, a protocol's competitiveness depends mainly on its liquidity depth and fee level. But in the era of intelligent routing, an isolated liquidity pool no longer constitutes a competitive barrier, and capital flows frictionlessly toward the protocol that prices most efficiently. This means that even if a protocol's liquidity depth is not the deepest, an intelligent routing system will still preferentially use it if it prices most efficiently. This competitive model encourages all protocols to pursue the highest pricing efficiency, thereby improving the market quality of the entire ecosystem.

At the same time, the intelligentization of liquidity routing also intensifies the technological competition among routing algorithms. Aggregators with the strongest computing power and the best models will dominate the allocation of order flow, thereby exerting a decisive influence on the survival of the underlying protocols. This gives rise to a new market structure: a small number of aggregators with the most advanced AI capabilities control the majority of order flow, while the underlying protocols are reduced to liquidity providers for these aggregators. This trend toward centralization may have a negative impact on the long-term health of DeFi, and so excessive centralization must be prevented through open standards and transparent algorithms.

## 31.9 Semantic oracles

### 31.9.1 The capability boundary of traditional oracles

The oracle mechanism is the core infrastructure connecting on-chain smart contracts with the off-chain real world. In Chapter 28's analysis of the fourth layer of the trust stack, the oracle is defined as a one-way data-transmission channel whose main function is to obtain the latest price of a particular asset from an external data source and convert it into an on-chain-verifiable structured format [48]. Although this design has supported the prosperity of DeFi over the past few years, it has also established the fundamental limitations of the traditional oracle.

The first limitation lies in the strict constraint on data type. Traditional oracles are designed to transmit highly structured numerical data, including exchange asset prices, interest-rate indices, weather data, or other already-quantified indicators. The common feature of these data is that they have a clear numerical representation and can be directly processed by a smart contract's conditional logic. When facing unstructured information, however, traditional oracles are powerless. A public company's financial report, for example, is usually a PDF document of hundreds of pages, containing complex textual descriptions, tables, footnotes, and explanations of accounting adjustments. A traditional oracle cannot automatically extract the key metric "third-quarter revenue" from such a document, still less understand the complex accounting treatment of "one-time gains" or "nonrecurring losses" in the report. Likewise, the key information in a legal contract or a government statement is often implicit in natural-language expression, and a traditional oracle cannot parse its semantic meaning. This dependence on structured data strictly confines the scope of oracle applications to asset classes that already have market quotes or have already been quantified.

The second limitation stems from the inability to handle the ambiguity of natural language. Natural language is inherently full of ambiguity, metaphor, context dependence, and polysemy. When a contract condition is written as "the company's performance declines significantly," for example, the word "significantly" may have entirely different meanings in different contexts. In the medical field, "significant" may mean a statistical p-value below 0.05; in finance, it may mean a year-over-year decline of more than 20%; and in everyday language, it may be merely a vague qualitative description. A traditional oracle cannot understand this semantic flexibility; it can only mechanically look up a predefined numerical value or category. If a contract condition involves any expression requiring subjective judgment or semantic understanding, a traditional oracle is not up to the task.

The third limitation lies in the inability to handle "subjective judgment" questions. In the real world, many important events or conditions are inherently subjective. The question "whether a company has violated the financial covenants in its loan agreement," for example, involves not only numerical computation but also the legal interpretation of contract terms. The question "whether a politician's remarks constitute hate speech" involves an understanding of cultural background, historical context, and social norms. The question "whether an artwork has collection value" involves aesthetic judgment and market expectation. Traditional oracles were not designed with such questions in mind, because these questions cannot be resolved by a simple data query. They require a system able to understand context, weigh multiple factors, and reason and judge.

The vision of "perpetual futures on everything" described in Chapter 27 has at its core the aim of creating continuous derivatives markets for any asset or any definable event. This means the system must be able to handle an extremely diverse range of underlying assets, from traditional financial assets to emerging non-standard assets, and from explicit numerical conditions to complex event determinations. This poses new technical requirements for the oracle. First, the oracle must be able to accept any contract condition described in natural language, not just a few predefined data types. Second, the oracle must be able to understand the semantic meaning of these natural-language conditions, including handling ambiguity, identifying implicit assumptions, and understanding context. Third, the oracle must be able to find or infer the relevant verification information in the real world, even if that information does not exist in a standardized market-quote form. Finally, the oracle must be able to perform some degree of reasoning and judgment to determine whether an event that occurred in the real world satisfies the contract condition.

The design of traditional oracles cannot meet these requirements at all. Even if we try to extend the existing oracle architecture, we can only handle more kinds of structured data; we still cannot cross into the domain of unstructured information and semantic understanding. This is precisely why "perpetual futures on everything" has been strictly limited technically. So long as the oracle remains in the role of "data transmission," the feasibility boundary of perpetual futures on everything will long be confined to the range of assets that have already been fully marketized and standardized. For all non-standard assets and events requiring semantic understanding, traditional oracles cannot meet these requirements.

### 31.9.2 Semantic oracle architecture

The semantic oracle represents a paradigm shift in oracle architecture; by embedding large language models (LLMs) into a network of nodes, it achieves the leap from mere "data transmission" to "semantic understanding." The core advantage of the semantic oracle is its ability to read and understand complex conditions described in natural language and to convert unstructured textual information into deterministic instructions that a smart contract can execute. The architecture of this new type of oracle usually comprises four mutually coordinated layers, each bearing a different functional responsibility [49].

The input layer is responsible for receiving and aggregating unstructured information from multiple heterogeneous sources. Unlike a traditional oracle, which can receive only predefined data requests, the input layer of a semantic oracle can handle natural-language queries in any form and perform preliminary semantic normalization, ensuring that different expressions with the same meaning are recognized as equivalent conditions. The input layer simultaneously aggregates information from multiple sources—news reports, social media, official announcements, financial databases, and descriptions of on-chain activity—to provide high-quality material for subsequent in-depth analysis.

The LLM understanding layer is the cognitive core of the semantic oracle. Advanced NLP models at this layer perform text comprehension and semantic parsing, key-condition extraction, ambiguity identification and resolution, and polysemy handling. When the Federal Reserve releases a monetary-policy statement, for example, the model must not only identify the keyword "rate cut" but also understand its magnitude, timetable, and economic impact; when a financial report mentions "30% revenue growth," it must distinguish year-over-year from quarter-over-quarter and total revenue from segment-level revenue.

The verification layer is designed to address the hallucination, bias, or manipulation that a single model may produce. This layer, through a multi-node consensus mechanism, requires multiple independently running LLMs to assess the same event independently [50], uses a sentence-level encoder to map text into a vector space and compute semantic similarity, and combines a truth-discovery algorithm to weight and aggregate the results based on nodes' historical credibility [49]. Experimental data show that even in the extreme case where 40% of the nodes are maliciously manipulated, this consensus mechanism can still maintain a relatively high accuracy.

The output layer is responsible for converting the consensus-verified semantic conclusion into an on-chain-verifiable structured data format, including a Boolean value, a numerical value, or other predefined data types. The output layer also attaches the model's confidence score for the conclusion or an uncertainty interval, enabling a smart contract to distinguish high-confidence from low-confidence determinations and to take conservative action—such as delaying settlement or triggering human arbitration—when facing a highly uncertain situation.

Figure 31-9 compares the semantic oracle with the traditional oracle along six capability dimensions: the traditional oracle is well-developed in the transmission of structured numerical values but has zero capability along dimensions involving natural-language understanding; the semantic oracle, by embedding LLMs, achieves a qualitative change from infeasible to feasible, although its precision is still constrained by model hallucination and the consensus mechanism.

![Figure 31-9](./images/fig-31-9-en.png)

**Figure 31-9.** A comparison of the capability dimensions of the semantic oracle and the traditional oracle (conceptual illustration; not empirical data; based on the author's theoretical derivation of architectural characteristics [48][49])

### 31.9.3 Unlocking perpetual futures on everything

The introduction of the semantic oracle fundamentally changes the conclusions of Chapter 27 regarding the feasibility of underlying assets; its unlocking effect manifests in bringing non-standard assets and complex events, which traditional oracles cannot handle, into the scope of programmable finance. This unlocking effect can be clearly demonstrated through three typical scenarios, each representing a new class of financial application that could not previously be realized.

Political-event perpetual futures are the first domain to be significantly unlocked. Traditional prediction markets rely on human arbitration when handling political events, a process that is time-consuming and prone to dispute. A semantic oracle can monitor and parse official legislative documents and authoritative news sources in real time; when a contract condition is set as "whether a particular bill is signed in a particular year," it can automatically confirm whether the condition is satisfied by analyzing the bill's text, signing records, and official statements, eliminating the delay and subjectivity of human intervention. The technical feasibility of political-event perpetual futures, however, is not the same as legal feasibility. In most major jurisdictions, such contracts face serious legal obstacles. The CFTC takes a cautious stance in regulating event contracts and has questioned the legal status of some political-event contracts. Multiple countries classify political-event betting as gambling rather than a financial activity, applying gambling regulations rather than financial regulations. The semantic oracle therefore unlocks more of a technical-feasibility boundary, and the actual deployment of these products remains subject to the evolution of each jurisdiction's regulatory stance.

Corporate-performance perpetual futures likewise benefit from the semantic oracle's comprehension capability. Traditional oracles cannot directly extract specific financial metrics from a financial-report PDF, and the ingestion of structured data usually takes weeks. A semantic oracle can parse financial-statement text in real time, accurately identify specific metrics, understand the terminological differences between GAAP and IFRS, and distinguish one-time gains from regular operating performance, enabling microlevel events based on corporate fundamentals to become the underlying of perpetual futures.

Natural-language-condition derivatives represent the ultimate unlocking effect brought by the semantic oracle. A trader can create a contract using any natural-language condition, for example "the global average temperature in 2025 exceeds the pre-industrial level by 1.5 degrees Celsius" or "a particular country's unemployment rate exceeds 10% in a particular quarter." So long as the condition can be verified by public information, the semantic oracle can undertake the responsibility of parsing and determining it, achieving perpetual futures on everything in the true sense.

The semantic oracle's enhanced capability is equally significant for the CEX perpetual futures market. In centralized exchanges' business expansion, listing a new perpetual futures underlying has long been constrained by the availability of a reliable price-feed source. Traditional oracles can support only assets that already have continuous market quotes, which confines the range of CEX perpetual futures underlyings to mainstream crypto assets and a few traditional financial assets. The introduction of the semantic oracle enables the CEX to break through this limitation, bringing non-standard indices (such as a particular DeFi-sector index or a Layer 2 ecosystem-activity index) and macro-event contracts (such as central-bank rate decisions or major regulatory-policy changes) into the range of perpetual futures underlyings. This expansion of underlyings not only enriches the CEX's product line but, more importantly, provides traders with fine-grained risk-hedging tools. For example, a development team focused on a DeFi lending protocol can hedge the systemic risk of its protocol token through a DeFi-sector-index perpetual futures.

Table 31-6 summarizes the unlocking effect of the semantic oracle on different types of underlying assets. The table compares the feasibility assessments of the traditional oracle and the semantic oracle one by one across five categories: crypto assets, foreign exchange, stock indices, carbon credits / house-price indices, and natural-language-condition events. The most striking contrast in the table appears in the last row: natural-language-condition events are "wholly infeasible" under the traditional oracle, whereas the semantic oracle raises them to the level of "possible but with limited precision"—and this breakthrough is precisely the technical basis on which the vision of "perpetual futures on everything" can move from theory to practice.

| Underlying-asset type | Traditional-oracle feasibility | Semantic-oracle feasibility | New possibilities unlocked |
| :--- | :--- | :--- | :--- |
| Crypto assets | Naturally feasible | Can be enhanced | Multi-source verification improves manipulation resistance |
| Major foreign-exchange pairs | Exchange data obtainable | Can be enhanced | Semantic understanding of central-bank statements and expectation pricing |
| Stock indices | Difficult outside trading hours | Feasible | Fills the pricing vacuum during non-trading hours such as the Asian session |
| Carbon credits / house-price indices | No continuous market quotes | Difficult but possible | Infers prices from statistical data and transaction records |
| Natural-language-condition events | Wholly infeasible | Limited precision | Turns any non-standard event into a settleable contract underlying |

**Table 31-6.** The matrix of the semantic oracle's unlocking effect on the feasibility of "perpetual futures on everything" (Data source: theoretical derivation based on model capability [49])

### 31.9.4 The trust problem of semantic verification

Although the semantic oracle greatly expands the application boundary of smart contracts, it also introduces an entirely new trust problem: how can we verify that an LLM's "understanding" of complex semantics is accurate and error-free? Unlike a traditional oracle that transmits deterministic numerical values, a semantic oracle outputs a probability-based estimate, which makes the fairness of liquidation depend directly on the quality of the AI's estimate. If the model hallucinates and generates a seemingly reasonable but actually erroneous interpretation of information, it may cause an enormous position to be wrongly liquidated based on an erroneous price or condition [51]. This risk poses a severe challenge to the stability of the DeFi system.

To meet this challenge, the system must establish a multi-level mechanism of verification and checks and balances. Multi-node consensus is the first line of defense and the most basic protective measure. As stated earlier, by requiring multiple independently trained LLMs to assess independently and aggregating the results, one can effectively reduce the risk of a single model's hallucination. The design of this multi-node consensus requires careful consideration of several key parameters. The first is the choice of the number of nodes. In theory, the more nodes, the better the system can resist attacks by malicious nodes. More nodes, however, also mean higher cost and a longer consensus time. In practice, a balance between security and efficiency is usually needed. A common choice is to use an odd number of nodes, such as five, seven, or 11, so as to avoid a tie. The second is the criterion for selecting nodes. Not all LLMs are suitable to join the consensus network. The system needs to assess each model's historical accuracy, whether it is easily deceived by particular types of adversarial examples, and whether it has known biases. The third is the setting of the consensus threshold. The system needs to decide how many nodes' concurring opinions constitute a valid consensus. For example, is it necessary for all nodes to agree, or only a majority, or a weighted majority? Different threshold settings affect the system's security and availability.

Even with a sound multi-node consensus mechanism, however, the system still faces a deeper risk: because mainstream LLMs have a relatively high degree of homogeneity in their training data and algorithmic architecture, they may jointly make the same mistake when facing certain particular edge cases [52]. This phenomenon, called "strategy homogenization," means that multiple seemingly independent models may in fact fail in the same way. For example, if all LLMs are trained on similar internet data, they may all inherit the same biases or misinformation present in that data. If a particular piece of misinformation is widely disseminated on the internet, all models may learn this misinformation and thus give the wrong answer when facing the related question. This risk means that a simple majority-vote mechanism may fail in certain scenarios—the concurring opinion of multiple nodes does not necessarily mean the conclusion is correct. This common-mode failure risk also extends to the level of adversarial attack. A prompt-injection attack can manipulate an LLM's output by embedding special instructions in the input text; if an attacker constructs a carefully designed piece of misinformation containing prompt-injection content able to bypass the models' safety filters, then even with multi-node consensus, all nodes using the same base model may give the same wrong result. Mitigation strategies should include mandating that nodes in the consensus network use base models from different vendors, implementing strict input-sanitization mechanisms, and introducing non-LLM verification paths as a heterogeneous security layer.

An adversarial-verification mechanism therefore becomes a necessary complement. In this mechanism, the system deploys not only a "primary model" responsible for generating the conclusion but also a "challenger model" specifically designed to look for logical flaws or factual errors. The challenger model's goal is to generate adversarial examples or raise counter-evidence, forcing the primary model to provide a more rigorous logical basis for its conclusion. This adversarial process is analogous to cross-examination in a courtroom, where the prosecution and the defense each try to find the flaws in the other's argument. In the context of the semantic oracle, the challenger model tries to interpret the same information from different angles, look for possible alternative explanations, or raise relevant information the primary model may have overlooked. For example, if the primary model's conclusion is "the company claims 50% revenue growth in its financial report," the challenger model might raise "but this growth comes mainly from a one-time gain and does not represent the growth of the regular business" or "this figure is calculated in nominal dollars, and the inflation-adjusted growth rate is in fact much lower." Only when the primary model's conclusion can withstand the challenger model's repeated attacks will the conclusion be adopted by the system. This courtroom-debate-like adversarial process can significantly improve the robustness of semantic parsing, because it forces the system to consider multiple perspectives and possible alternative explanations.

To incentivize the challenger model to perform its duty conscientiously, the system can design a corresponding economic-incentive mechanism. For example, if the challenger model successfully finds an error in the primary model, the challenger can obtain a reward, while the primary model is penalized. This incentive mechanism ensures that the challenger has an incentive to look for flaws conscientiously rather than perfunctorily. At the same time, to prevent the challenger from maliciously raising groundless objections, the system can require the challenger to provide evidentiary support for its objections, and if an objection is proven to be wrong, the challenger is likewise penalized.

Even with a sound multi-model consensus and adversarial verification, the semantic oracle still needs to set an uncertainty threshold. When the system assesses that the uncertainty interval of a particular event exceeds a preset safety threshold, it must trigger an automatic fallback mechanism. This fallback mechanism may include suspending trading in the relevant contract, delaying settlement until more information is obtained, or triggering a human-arbitration process. This conservative approach ensures that the system does not make a hasty decision when facing a highly uncertain situation, thereby protecting the interests of market participants.

As the ultimate backstop, for a semantic determination involving extremely high value or serious dispute, the system must retain the power of human arbitration. This does not mean a return to the human-arbitration model of traditional prediction markets, but rather a more fine-grained hybrid model. In most cases, the system relies on the automated semantic oracle to make determinations and settle. But when the system detects a high degree of uncertainty or dispute, it automatically submits the case to a decentralized team of human arbitrators. This team may be composed of experts from different backgrounds and professional fields, who vote based on the relevant evidence. This hybrid model retains both the high efficiency of the automated system and the irreplaceable value of human judgment in handling extreme, unknown situations. This reflects the fact that, in the evolution toward "model is law," human common sense and judgment still play an important role.

## 31.10 From code is law to model is law

As AI systems gradually replace the hardcoded rules in DeFi infrastructure, the operating logic of market microstructure undergoes a profound paradigm shift. This transformation changes the system's core decision mechanism from deterministic code to a probabilistic model, bringing both an enormous opportunity for adaptive optimization and new governance challenges and systemic risks. The early-blockchain ideal of "code is law" was once seen as the ultimate governance solution, but as market complexity has increased and extreme events have occurred frequently, the limitations of this paradigm have become ever more apparent. At the same time, the powerful capability that AI models display in handling complex decisions makes "model is law" a possible alternative. Both paradigms, however, have fundamental flaws, and the true breakthrough lies in how to deeply integrate the two, forming a hybrid architecture that both retains the safety floor of code's determinism and fully harnesses the model's adaptive-optimization capability.

### 31.10.1 The strengths and limitations of code is law

The ideal of "code is law" forms the cornerstone of the first generation of DeFi infrastructure. Under this paradigm, all business logic, risk parameters, and execution conditions are turned into immutable smart-contract code. The achievement of this architecture is manifested mainly in the absolute determinism and verifiability it provides. Once a smart contract is deployed, its execution path depends entirely on the input state and the predefined logical branches, with no ambiguity or room for human discretion. This determinism ensures that the system runs as expected in all situations, thereby establishing a high degree of execution reliability in a trustless environment. Formal verification technology further strengthens this advantage, using mathematical proof to ensure that a smart contract's logic conforms to its expected properties and thereby eliminating conventional security vulnerabilities at the code level [35]. In addition, the complete transparency of the code enables any participant to audit the system's operating mechanism, ensuring that the rules apply fairly to all. This censorship resistance is a characteristic that traditional financial systems cannot achieve; any attempt to change the rules must go through an explicit on-chain governance process and cannot be carried out through covert back-end operations.

The determinism of code also brings another key advantage: the system's behavior is fully predictable. Participants can precisely calculate how the system will react in any given market state, which makes risk assessment relatively intuitive. In a fixed-rate lending protocol, for example, participants know that the interest-calculation formula is entirely deterministic and will not change because of some centralized entity's subjective judgment. This predictability is a foundational condition for building market confidence, and is especially prominent in transactions involving large sums.

The rigidity of hardcoded rules, however, exposes significant limitations when facing complex and variable market microstructure. Deterministic code cannot adapt to unforeseen extreme market situations, and when facing complex scenarios such as an instantaneous liquidity drought or an abrupt shift in correlation structure, preset linear rules often prove too simple and too slow. A dynamic margin rate computed by a fixed formula, for example, cannot capture the nonlinear interactions among multidimensional market variables, causing the system to be possibly overly conservative under normal conditions yet inadequately prepared for extreme tail risk. The 2016 Ethereum DAO incident offers an important case. The smart-contract code of the time was logically "correct," but when facing the unforeseen attack vector of a reentrancy attack, it could not adaptively adjust its defensive strategy at all. The determinism of code proved a limitation in such a scenario, because once the vulnerability was discovered, the system could not respond to the threat through dynamic adjustment and could only passively wait for human intervention.

In addition, the static nature of parameter settings leaves the system without real-time adaptive capability. In a traditional governance architecture, adjusting risk parameters depends on a human proposal-and-voting process, which is not only time-consuming but also hard-pressed to keep up with the millisecond-level tempo of market changes. When market volatility doubles within seconds, adjusting risk parameters through a governance vote is entirely unrealistic. A deeper problem is that code logic is inherently constrained by Boolean conditional judgments and cannot handle complex semantic conditions or continuous probabilistic assessments. When it is necessary to judge the toxicity of an order or predict the liquidation probability of a position, a simple threshold-trigger mechanism proves inadequate. Code can only say "if the margin rate falls below 50%, then liquidate," but it cannot say "based on the current market liquidity, the depth of the liquidation queue, and cross-market correlation, this position's liquidation probability is 73.2%, and therefore the trader should be proactively alerted." This simplified handling not only reduces the system's capital efficiency but also limits the resilience of the market infrastructure when responding to complex attacks and anomalous volatility.

Another implicit limitation of code lies in its dependence on parameter tuning. When designing a smart contract, developers must preset all parameter values, such as liquidation thresholds, risk weights, and fee ratios. The choice of these parameters is often based on historical data and the designer's subjective judgment, but the market environment is continually evolving. Once parameters are hardcoded, changing them requires a complex upgrade process, which in a decentralized system often means obtaining community consensus. This leaves the system either with parameter settings too conservative to cope with the worst case, or too aggressive and prone to collapse under extreme conditions.

### 31.10.2 The potential and risks of model is law

When AI models are introduced as the core decision engine of market infrastructure, the nature of the system's rules evolves from deterministic code into a probabilistic model. Under the "model is law" paradigm, the system's behavior is no longer determined by fixed conditional statements but is driven by the model's real-time assessment of multidimensional market states. This shift endows the infrastructure with the ability to handle complex semantics and make continuous judgments. AI models can simultaneously process thousands of input variables, discover nonlinear patterns that human designers cannot foresee, and dynamically adjust risk parameters according to real-time liquidity conditions, liquidation-queue density, and cross-market spillover effects.

This adaptive capability significantly improves the system's capital efficiency and resilience. Through continuous learning and optimization, the model can achieve more precise risk pricing than a hardcoded formula, reducing the capital sequestration caused by over-conservatism and taking predictive preventive measures before risk actually materializes. In a predictive liquidation system, for example, the model no longer waits for the margin to fall below a threshold to trigger liquidation, but, based on a continuous assessment of the liquidation probability, guides the gentle reduction of a position at an early stage, thereby effectively preventing the systemic risk of a liquidation cascade. The model can learn that a particular type of market condition often precedes a price collapse and can therefore act in advance. In addition, the model can handle complex semantic conditions, such as the multidimensional combined condition "when the market is in a panic state and liquidity providers are withdrawing," rather than merely a simple single threshold such as "price below X." This enables the system to make fine-grained responses to subtle changes in market microstructure.

The model's capacity for continuous optimization is also a major advantage over hardcoded rules. As new market data continually accumulate, the model can automatically adjust its parameters and strategy without human intervention. This means the system can gradually adapt to the evolution of the market environment rather than being locked into past parameter settings. In the field of high-frequency trading, this real-time learning capability has been shown to significantly improve trading performance and risk-management outcomes.

A probabilistic decision mechanism, however, inevitably introduces new dimensions of risk. The most notable flaw of AI models is their unpredictability and lack of interpretability. When a deep neural network decides to raise the margin rate for a certain class of assets, it often cannot provide a humanly understandable causal explanation. This "black box" nature directly challenges a decentralized system's basic requirements for transparency and auditability. If participants cannot understand the logic behind a system's decisions, the foundation of trust will be severely weakened [53]. In traditional finance, regulators can require a bank to explain its risk decisions, but for a deep-learning model such a requirement often cannot be met.

In addition, when facing a "black swan" event that never appeared in the training data, the model's behavior often exhibits extreme fragility. The model may make wholly unreasonable decisions in a brand-new market environment, leading to systematic mispricing or improper liquidation. The 2012 Knight Capital algorithmic-runaway incident illustrates this risk. Because of an incomplete deployment of new trading code, the firm triggered an obsolete legacy function that had already been retired, and the trading system placed orders out of control for approximately 45 minutes, producing approximately $440 million in realized losses (with the final related pre-tax loss, including subsequent costs, at approximately $461 million). This incident shows that even a tested algorithmic system can run out of control because of a deployment defect or an unanticipated operating state.

Adversarial fragility is another key source of risk. Machine-learning models are prone to carefully crafted adversarial-example attacks, and a malicious participant can deceive the model by creating particular market signals, inducing it to make parameter adjustments favorable to the attacker [54]. An attacker might, for example, "train" the model to produce a particular bias through a series of carefully designed order flows, so as to gain an advantage at a critical moment. This new form of "model attack" is more covert and harder to defend against than a traditional code-vulnerability exploit, because it does not require finding a logical error in the code but instead exploits the model's own learning mechanism.

Finally, because the model is continually updated during ongoing learning, its behavioral characteristics undergo "model drift" over time, which means the system's rules today may differ from its rules tomorrow, thereby undermining participants' expectations of the system's stability [27]. This is a serious problem for traders who need to plan over the long run. In addition, the model's training process may itself introduce bias. If the training data are insufficiently representative, or if there are flaws in feature engineering, the model may learn spurious correlations, leading to systematic decision errors. These risks make "model is law" infeasible as an independent governance paradigm.

### 31.10.3 The hybrid architecture

To resolve the inherent contradiction between determinism and adaptivity, the next generation of market infrastructure must adopt a "code plus model" hybrid architecture. The design principle of this architecture is not to make an either-or trade-off between "code is law" and "model is law," but to integrate the two through deep nesting. The core insight of the hybrid architecture is this: hardcoded code defines the system's inviolable safety floor, and within that floor, the AI model is granted ample freedom to optimize for efficiency.

Figure 31-10 shows the nested design logic of the hybrid architecture: the outer layer, composed of hardcoded smart contracts, constitutes an absolute safety boundary; the inner layer, composed of the AI model, performs adaptive optimization within the operating space bounded by the safety floor; and the two layers are connected through a "model proposes, code reviews" verification mechanism.

![Figure 31-10](./images/fig-31-10-en.png)

**Figure 31-10.** The design of the "code plus model" hybrid architecture (conceptual illustration; based on the author's theoretical derivation of a governance framework for decentralized infrastructure)

In the outer layer of the hybrid architecture, the system sets absolute safety boundaries through hardcoded smart contracts. These floor rules include an asset-isolation mechanism, the maximum permitted leverage multiple, the minimum maintenance-margin rate, and explicit liquidation-trigger conditions. The execution of these rules has absolute priority and is not affected by the output of any AI model. No matter how optimistic the market state assessed by the internal model, or how aggressive its recommended parameters, the hardcoded layer will resolutely reject any operation that breaches the safety floor. This design preserves the core value of "code is law" in guarding against extreme tail risk, ensuring the system's survivability in the worst case.

The design principles of the floor warrant special attention. An effective floor must satisfy several key conditions: first, it must be absolute and non-negotiable, and cannot be breached for any reason. Second, it must be verifiable, so that any participant can independently verify whether the system has complied with the floor. Third, the floor must be loose enough to allow the model to perform meaningful optimization within it, rather than so strict that the model cannot function. Fourth, the floor must be resistant to circumvention. For example, if the floor stipulates a maximum leverage of 10×, but the model can circumvent this limit through a combination of multiple accounts, then the floor is ineffective. The hybrid architecture must therefore include additional checking mechanisms to ensure that the model cannot circumvent the floor through creative means.

Within the operating space bounded by the safety floor, the inner layer of the hybrid architecture is led by the AI model. The model is authorized to perform high-frequency adaptive optimization, including dynamically adjusting the specific margin rate, setting personalized risk parameters, executing predictive interventions, and optimizing the speed and the counterparty of the liquidation process. For example, when market volatility rises but has not yet triggered the hardcoded liquidation threshold, the model can proactively raise the margin requirement for particular high-risk positions, or advise the trader to close out early. This inner-layer optimization significantly improves the system's speed of response to changes in market microstructure, enabling the infrastructure to maximize capital efficiency under normal conditions while smoothly defusing risk in the early stage of its accumulation.

The mechanism by which code verifies the model's output in the hybrid architecture is the key link ensuring the system's safety. The model does not directly control the execution engine but instead generates parameter-adjustment recommendations or operation instructions. Before these recommendations take effect, they must undergo strict review by the hardcoded logic. The code layer acts as a strict verification mechanism; it does not assess the economic reasonableness of the model's recommendation but only verifies whether the recommendation violates any preset safety floor. The specific workflow is as follows: first, the model analyzes the current market state and system state and generates a parameter-adjustment recommendation, such as "raise account A's margin rate from 50% to 55%." Second, this recommendation is sent to the code-verification layer. The verification layer performs a series of checks: whether the new margin rate is still above the hardcoded floor of the minimum maintenance-margin rate, whether account A's total leverage is still below the hardcoded floor of the maximum leverage, and whether any other operation prohibited by hardcoded rules is present. If all checks pass, the instruction is executed; if any breach of the floor is found, the code directly rejects the recommendation and may trigger a downgrade of the system to a more conservative fallback state. This "model proposes, code reviews" workflow successfully harnesses to the greatest extent AI's advantages in handling complex semantics and multidimensional optimization, while ensuring the system's absolute safety.

The design advantage of this architecture is that it achieves a mode combining "limited trust with independent verification." The system trusts the model's optimization capability but strictly verifies its output. This avoids both the rigidity that comes from relying entirely on code and the uncontrollability that comes from relying entirely on the model.

### 31.10.4 Model auditing

Shifting from auditing deterministic code to auditing a probabilistic model constitutes the most severe governance challenge under the hybrid architecture. Traditional code auditing focuses on the correctness of the logic and the completeness of the execution paths, with the goal of finding potential vulnerabilities and ensuring that the code's behavior conforms to expected specifications. Although this auditing process is complex, because of the deterministic nature of code, its results are verifiable and final [55]. Code auditing can use mathematical tools such as formal verification to ensure the code's correctness through symbolic execution or theorem proving. An auditor can trace every execution path of the code and verify that, under all possible inputs, the code produces the expected result.

The complexity of auditing an AI model, however, increases exponentially. Model auditing requires not only assessing the reasonableness of the algorithmic architecture but also examining in depth the quality of the training data, the bias in feature engineering, and the model's performance in historical decisions. A deep neural network may contain millions of parameters, and a minute change in any one of them may cause a significant change in the output. This makes the traditional code-auditing method entirely inapplicable. An auditor cannot understand the model's decision logic by reading the code line by line, because the model's decisions are produced by complex mathematical operations and nonlinear transformations.

Because of the inherent "black box" nature of deep-learning models, requiring the model to provide a precise causal explanation for each of its microlevel decisions is often technically unrealistic. To meet this challenge, the governance framework must introduce new practical schemes to ensure that the model's behavior is traceable and accountable. One feasible mechanism is to require the AI system to periodically generate and publish standardized "decision reports." These reports should record in detail the key decisions the model made within a particular period, clarify the main input features on which the decisions relied and their weights, and contrast the model's decisions with the expected output of purely hardcoded rules under the same conditions [56].

The specific design of the decision report should include the following. First, the report should record all important decisions above a certain threshold, such as all decisions that led to a margin-rate adjustment of more than 5%. Second, for each decision, the report should list the top ten most influential input features and their contribution to the decision. Third, the report should include a comparative analysis of the model's decision with a pure hardcoded rule. For example, if a hardcoded rule would liquidate a position under the given market conditions but the model decided not to liquidate, the report should explain the model's reasoning. Fourth, the report should include the model's confidence indicator—that is, how certain the model is of its decision. If the confidence is low, this may indicate that the model is handling an unfamiliar market environment.

These decision reports should be stored on the blockchain, forming an immutable audit trail. In this way, anyone can look back through history to see the decisions the model made at a particular point in time and their reasoning. Through this approach, even if it is impossible to fully reveal the model's internal nonlinear mapping process, governance participants can still assess the reasonableness of the model's behavior and identify potential systematic biases by analyzing the statistical relationship between inputs and outputs. If the model is found to systematically make unreasonable decisions under a particular type of market condition, this can trigger a retraining of the model or an adjustment of the floor.

The probabilistic nature of model decisions also gives rise to complex questions about the accountability mechanism. When the model's adaptive adjustments cause some participants to suffer unexpected losses, the traditional liability-attribution framework based on deterministic rules no longer applies. In the case of hardcoded rules, if the system causes a loss, the liability is clear: either the rule design was flawed, or the rule execution was faulty. But for the model, the situation is far more complex. The model's decisions are based on the patterns it has learned, and these patterns may themselves be flawed, but the flaw may be due to insufficient training data, improper feature engineering, or an improper choice of model architecture.

To ease this contradiction, the concept of "model insurance" provides a market-based mechanism for risk transfer. A protocol operator can establish a dedicated insurance fund for the decision behavior of the AI infrastructure; when the model's output causes an anomalous loss exceeding what the hardcoded floor anticipates, the injured party can obtain compensation from the fund. The design of this mechanism requires special attention to several aspects. First, the scope of insurance must be clearly defined. What types of loss should the insurance cover? All losses caused by model decisions, or only those that breach particular conditions? Second, the pricing method must reflect the model's actual risk. If the model's historical performance shows that it is prone to error under particular market conditions, the insurance premium should rise accordingly. Third, the claim-trigger condition must be objective and verifiable. A claim cannot be based on subjective judgment but must be based on explicit conditions verifiable on-chain. For example, a claim might be triggered when the loss caused by the model's decision exceeds a certain threshold and this loss is due to the model's decision rather than to market volatility.

This mechanism turns the long-tail risk brought by the model's unpredictability into a quantifiable and priceable insurance cost, thereby strengthening participants' trust in the hybrid architecture. Participants know that even if the model makes an unreasonable decision, they have insurance as a last line of protection. At the same time, the level of the insurance premium also provides a market signal of the model's quality. If a model's insurance premium is high, this indicates that the market considers the model to be very risky.

Finally, the system must have a sound "revertibility" design as the ultimate safety guarantee. When facing anomalous model performance, a severe adversarial attack, or a fundamental structural rupture in the market environment, the system should be able to cut off the AI model's control automatically or through an emergency governance process and seamlessly revert to a base state driven purely by hardcoded rules. This design establishes code's status as an always-available safety backup and sends a clear signal to the market: the model is an enhancing component that improves efficiency, but it is not the sole dependency for keeping the system running. The description of "seamless reversion" above, however, must confront the practical challenges of engineering implementation. When the AI model has dynamically lowered the margin rate of a certain class of assets to a relatively low level during operation to optimize capital efficiency, while the hardcoded default is set relatively high, the parameter jump at the instant of reversion may itself trigger large-scale margin calls or liquidation events. The actual reversion mechanism should therefore be designed as a gradual downgrade rather than an instantaneous switch: after detecting an anomaly, the system first limits the model's adjustment magnitude, then gradually returns the parameters to the hardcoded defaults. The reversion process must also handle the race condition in which the AI system's uncompleted operations and the hardcoded system run simultaneously, ensuring that no double execution or missed execution occurs.

The engineering implementation of revertibility must consider several aspects. First, the system must be able to detect the model's anomalous behavior. This can be achieved by monitoring the degree of deviation between the model's decisions and its historical patterns. If the model makes a large number of decisions inconsistent with its historical behavior within a short time, this may indicate that the model has been attacked or has undergone severe drift. Second, the system must be able to trigger the reversion quickly. This cannot depend on human intervention but must be automatic. Once an anomaly is detected, the system should immediately stop using the model's output and switch to hardcoded rules. Third, the system must be able to recover after reversion. This means that during the reversion period, the system must still be able to operate normally, though its efficiency may decline. Fourth, the system must be able to diagnose the root cause of the problem. After reversion, an in-depth analysis is needed to determine why the model malfunctioned—whether because of an adversarial attack, training-data contamination, model drift, or another reason.

Through these multi-level auditing, accountability, and reversion mechanisms, the hybrid architecture maintains the safety floor of DeFi infrastructure while embracing the efficiency gains that AI brings. This architecture is not a perfect solution, but it represents the best practice, under current technological conditions, for balancing security and efficiency. As AI technology develops further and interpretability methods improve, this hybrid architecture is expected to keep evolving, gradually raising the model's trustworthiness and autonomy.

## 31.11 Chapter summary

This chapter has advanced three core theoretical contributions. First, the four-stage model of AI penetration into microstructure (assistance → execution → autonomy → adversarial competition) provides a systematic framework for understanding the evolution of AI's role in the market. The current market is in the critical transition from Stage 2 to Stage 3, in which market making and arbitrage, because of their heavy dependence on speed and multidimensional optimization capability, have become the fastest-penetrating domain, while governance participation remains at the proof-of-concept stage. Second, the dual-role framework reveals the economic logic of AI's evolution from a value-extracting market participant into value-creating market infrastructure: participant AI's profit margin is continually compressed under competitive pressure, whereas infrastructure AI sustains a persistent capacity for value capture on the strength of network effects, economies of scale, switching costs, and the data-feedback effect. This framework explains why capital and technological resources are accelerating their migration toward the infrastructure domain. Third, the "code plus model" hybrid architecture provides a design paradigm for the next generation of market infrastructure: hardcoded rules set an inviolable safety floor, within which the AI model is granted ample space for adaptive optimization, and determinism and flexibility are unified through a "model proposes, code reviews" workflow.

This chapter has identified three key findings and risks. Strategy homogenization is the most prominent new form of systemic fragility in the AI era: algorithms trained on similar architectures and data may, when facing an anomalous signal, make wholly identical defensive reactions within milliseconds, triggering an "AI flash crash" of extremely short duration but extremely great destructive power. This mechanism turns the volatility distribution from mildly right-skewed into bimodal—that is, normal-regime volatility declines but tail risk rises—and market resilience exhibits a bimodal character of "extremely high in the normal regime, extremely low in the tail." At the same time, AI's effect on market quality is highly nonlinear: transaction cost and the efficiency of price discovery improve significantly under normal conditions, but fairness deteriorates substantively because of the widening speed gap. At the infrastructure level, the six core AI-driven systems (the dynamic risk engine, the intelligent matching engine, the predictive liquidation system, the dynamic pricing mechanism, the compliance-monitoring system, and liquidity-routing optimization) are upgrading the static protocol architecture into an adaptive system, among which the predictive liquidation system, by moving risk management forward from passive triggering to probabilistic prediction, can significantly reduce the scale of liquidation cascades under extreme conditions. The breakthrough of the semantic oracle, in turn, fundamentally unlocks the technical bottleneck of "perpetual futures on everything," enabling unstructured information such as political events, corporate performance, and arbitrary natural-language conditions to be brought into the on-chain financial system.

The analysis in this chapter also reveals several open questions. How should the boundary of AI agents' participation in decentralized governance be delineated, and should the permissions for parameter optimization be distinguished from those for constitutional decisions in a tiered manner? How can an audit and accountability framework for probabilistic models be established, and can a "model insurance" mechanism effectively transfer the long-tail risk that unpredictability brings? Can the risk of strategy homogenization be effectively mitigated through a "heterogeneity incentive" mechanism, or will it keep intensifying as AI technology converges further? Can the hallucination and bias problems of the semantic oracle be adequately controlled through multi-node consensus and adversarial-verification mechanisms? The answers to these questions will determine whether an AI-driven autonomous financial network can achieve a sustainable balance among efficiency, security, and fairness.

## References

[1] Trestman, M. (2013). The Cambrian explosion and the origins of embodied cognition. *Biological Theory*, *8*(1), 80-92.

[2] Plotnick, R. E., Dornbos, S. Q., & Chen, J. (2010). Information landscapes and sensory ecology of the Cambrian Radiation. *Paleobiology*, *36*(2), 303-317.

[3] Hirshleifer, D. (2015). Behavioral finance. *Annual Review of Financial Economics*, *7*(1), 133-159.

[4] O'Hara, M. (2015). High frequency market microstructure. *Journal of Financial Economics*, *116*(2), 257-270.

[5] Aquilina, M., Budish, E., & O'Neill, P. (2022). Quantifying the high-frequency trading "arms race". *The Quarterly Journal of Economics*, *137*(1), 493-564.

[6] Dou, W. W., Goldstein, I., & Ji, Y. (2025). AI-powered trading, algorithmic collusion, and price efficiency. *NBER Working Paper 34054*. https://doi.org/10.3386/w34054

[7] Liu, Q., Miao, D., Wang, C., & Wang, C. D. (2025). Strategic homogeneity in trading: Amplifying market volatility and the emergence of mini-crashes. *SSRN Electronic Journal*, 5239024. https://doi.org/10.2139/ssrn.5239024

[8] Glosten, L. R., & Milgrom, P. R. (1985). Bid, ask and transaction prices in a specialist market with heterogeneously informed traders. *Journal of Financial Economics*, *14*(1), 71-100. https://doi.org/10.1016/0304-405x(85)90044-3

[9] Cont, R., & Xiong, W. (2024). Dynamics of market making algorithms in dealer markets: Learning and tacit collusion. *Mathematical Finance*. https://doi.org/10.1111/mafi.12401

[10] Zhao, M., & Linetsky, V. (2021). High frequency automated market making algorithms with adverse selection risk control via reinforcement learning. *Proceedings of the Second ACM International Conference on AI in Finance*, 1-8.

[11] Herrmann, S., Muhle-Karbe, J., Shang, D., & Yang, C. (2020). Inventory management for high-frequency trading with imperfect competition. *SIAM Journal on Financial Mathematics*, *11*(1), 1-45. https://doi.org/10.1137/18m1207776

[12] Avellaneda, M., & Stoikov, S. (2008). High-frequency trading in a limit order book. *Quantitative Finance*, *8*(3), 217-224. https://doi.org/10.1080/14697680701381228

[13] Ken Research. (2024). *Global high frequency trading market report*. https://www.kenresearch.com/global-high-frequency-trading-market

[14] Hofweber, T., Bergl, J., Reyes, I., & Sadovnik, A. (2025). The Black Tuesday Attack: how to crash the stock market with adversarial examples to financial forecasting models. *arXiv preprint arXiv:2510.18990*. https://doi.org/10.48550/arXiv.2510.18990

[15] Raboun, A., Briere, M., & Lehalle, C.-A. (2021). Liquidity provision and market-making in different uncertainty regimes: Evidence from the COVID-19 market crash. *Available at SSRN 3815169*. https://doi.org/10.2139/ssrn.3815169

[16] Gao, K., Vytelingum, P., Weston, S., Luk, W., & Guo, C. (2022). High-frequency financial market simulation and flash crash scenarios analysis: An agent-based modelling approach. *Journal of Artificial Societies and Social Simulation*, *27*(2), 8.

[17] Bookstaber, R., Foley, M. D., & Tivnan, B. F. (2016). Toward an understanding of market resilience: Market liquidity and heterogeneity in the investor decision cycle. *Journal of Economic Interaction and Coordination*, *11*(1), 1-27.

[18] Brunnermeier, M. K., & Pedersen, L. H. (2009). Market liquidity and funding liquidity. *The Review of Financial Studies*, *22*(6), 2201-2238. https://doi.org/10.1093/rfs/hhn098

[19] Goldblum, M., Schwarzschild, A., Patel, A., et al. (2021). Adversarial attacks on machine learning systems for high-frequency trading. In *Proceedings of the Second ACM International Conference on AI in Finance* (pp. 1-9). https://doi.org/10.1145/3490354.3494367

[20] Fernández Vicente, Ó. (2025). Market making strategies with reinforcement learning. *arXiv preprint arXiv:2507.18680*. https://doi.org/10.48550/arXiv.2507.18680

[21] Dahlhaus, R., & Neddermeyer, J. C. (2014). Online spot volatility-estimation and decomposition with nonlinear market microstructure noise models. *Journal of Financial Econometrics*, *12*(1), 174-212.

[22] Commodity Futures Trading Commission. (2014). The flash crash: The impact of high frequency trading on an electronic market. *Office of the Chief Economist*.

[23] Kirilenko, A., Kyle, A. S., Samadi, M., & Tuzun, T. (2017). The flash crash: High-frequency trading in an electronic market. *The Journal of Finance*, *72*(3), 967-998.

[24] Bollerslev, T. (1986). Generalized autoregressive conditional heteroskedasticity. *Journal of Econometrics*, *31*(3), 307-327. https://doi.org/10.1016/0304-4076(86)90063-1

[25] International Monetary Fund. (2024). *Global Financial Stability Report: Advances in artificial intelligence: Implications for capital markets*. October 2024.

[26] Abbas, N., Cohen, C., et al. (2024). Artificial intelligence can make markets more efficient—and more volatile. *IMF Blogs*, October 15, 2024.

[27] Zenisek, J., Holzinger, F., & Affenzeller, M. (2019). Machine learning based concept drift detection for predictive maintenance. *Computers & Industrial Engineering*, *137*, 106031.

[28] Kearns, M., & Nevmyvaka, Y. (2013). Machine learning for market microstructure and high frequency trading. In *Algorithmic trading: New realities for traders, markets and regulators*.

[29] Brogaard, J., Hendershott, T., & Riordan, R. (2014). High-frequency trading and price discovery. *Review of Financial Studies*, *27*(8), 2267-2306. https://doi.org/10.1093/rfs/hhu032

[30] Chi, T., He, N., Hu, X., & Wang, H. (2024). Remeasuring the arbitrage and sandwich attacks of maximal extractable value in Ethereum. *arXiv preprint*, arXiv:2405.17944.

[31] Sun, S., Qin, M., Zhang, W., Xia, H., Zong, C., & Duan, J. (2023). TradeMaster: A holistic quantitative trading platform empowered by reinforcement learning. *Advances in Neural Information Processing Systems*, *36*, 1-15.

[32] U.S. Securities and Exchange Commission. (2014). SEC Charges New York-Based High Frequency Trading Firm With Fraudulent Trading to Manipulate Closing Prices. *Press Release 2014-229*.

[33] European Securities and Markets Authority. (2026). *Supervisory briefing on algorithmic trading in the EU* (ESMA74-1505669079-10311).

[34] Kurshan, E., Balch, T., & Byrd, D. (2025). The Agentic Regulator: Risks for AI in Finance and a Proposed Agent-based Framework for Governance. *arXiv preprint arXiv:2512.11933*. https://doi.org/10.48550/arXiv.2512.11933

[35] Bhargavan, K., Delignat-Lavaud, A., Fournet, C., Gollamudi, A., Gonthier, G., Kobeissi, N., ... & Zanella-Béguelin, S. (2016). Formal verification of smart contracts: Short paper. In *Proceedings of the 2016 ACM Workshop on Programming Languages and Analysis for Security* (pp. 91-96).

[36] Han, J., Lee, J., & Li, T. (2025). A review of DAO governance: Recent literature and emerging trends. *Journal of Corporate Finance*, *90*, 102685. https://doi.org/10.2139/ssrn.5074046

[37] Tamai, S., & Kasahara, S. (2024). DAO voting mechanism resistant to whale and collusion problems. *Frontiers in Blockchain*, *7*, 1405516.

[38] Stigler, G. J. (1957). Perfect competition, historically contemplated. *Journal of Political Economy*, *65*(1), 1-17. https://doi.org/10.1086/257878

[39] Yadav, Y. (2015). How algorithmic trading undermines efficiency in capital markets. *Vanderbilt Law Review*, *68*(1), 160-228.

[40] International Monetary Fund. (2024). *Artificial intelligence and its impact on financial markets and financial stability*. https://www.imf.org/en/news/articles/2024/09/06/sp090624-artificial-intelligence-and-its-impact-on-financial-markets-and-financial-stability

[41] Huang, Y. (2025). Deep learning-enhanced dynamic margin period of risk prediction for counterparty credit risk management: A multi-modal approach integrating market sentiment. *Proceedings of the 2nd International Conference on Computer Science and Management*, 1-8.

[42] Budish, E., Cramton, P., & Shim, J. (2015). The high-frequency trading arms race: Frequent batch auctions as a market design response. *The Quarterly Journal of Economics*, *130*(4), 1547-1621. https://doi.org/10.1093/qje/qjv027

[43] Cartea, Á., Duran-Martin, G., & Sánchez-Betancourt, L. (2023). Detecting toxic flow. *arXiv preprint arXiv:2312.05827* (revised 2026). https://doi.org/10.48550/arXiv.2312.05827

[44] Palaiokrassas, G., Scherrers, S., & Makri, E. (2024). Machine learning in DeFi: Credit risk assessment and liquidation prediction. *IEEE International Conference on Blockchain and Cryptocurrency*, 1-8.

[45] Popoola, N. T. (2023). Big data-driven financial fraud detection and anomaly detection systems for regulatory compliance and market stability. *Journal of Computer Applications Technology and Research*, *1*(1), 1-15.

[46] Tiwari, S., Ramampiaro, H., & Langseth, H. (2021). Machine learning in financial market surveillance: A survey. *IEEE Access*, *9*, 156321-156338. https://doi.org/10.1109/access.2021.3130843

[47] Zhang, Y., & Tessone, C. J. (2025). Measuring DEX efficiency and the effect of an enhanced routing method on both DEX efficiency and stakeholders' benefits. *arXiv preprint arXiv:2508.03217*. https://doi.org/10.48550/arXiv.2508.03217

[48] Chainlink. (2024). *The Intersection Between AI Models and Oracles*. https://blog.chain.link/oracle-networks-ai/

[49] Xian, Y., Zeng, X., Xuan, D., Yang, D., Pei, C., Fan, P., & Liu, P. (2024). *Connecting Large Language Models with Blockchain: Advancing the Evolution of Smart Contracts from Automation to Intelligence*. arXiv preprint arXiv:2412.02263. https://doi.org/10.48550/arXiv.2412.02263

[50] Luo, H., Sun, G., Liu, Y., Zhao, D., Niyato, D., & ... (2025). *A weighted byzantine fault tolerance consensus driven trusted multiple large language models network*. IEEE Transactions. https://doi.org/10.1109/tccn.2025.3620286

[51] Yao, J. Y., Ning, K. P., Liu, Z. H., Ning, M. N., Liu, Y. Y., & ... (2023). *LLM lies: Hallucinations are not bugs, but features as adversarial examples*. arXiv preprint arXiv:2310.01469. https://doi.org/10.48550/arXiv.2310.01469

[52] Amiri-Margavi, A., Jebellat, I., Jebellat, E., & ... (2025). *Enhancing answer reliability through inter-model consensus of large language models*. Conference on Artificial Intelligence. https://doi.org/10.1007/978-3-031-96235-6_22

[53] CFA Institute. (2025). *Explainable AI in Finance*. Research & Policy Center. https://rpc.cfainstitute.org/research/reports/2025/explainable-ai-in-finance

[54] Silva, S. H., & Najafirad, P. (2020). Opportunities and challenges in deep learning adversarial robustness: A survey. *arXiv preprint arXiv:2007.00753*. https://doi.org/10.48550/arXiv.2007.00753

[55] Almakhour, M., Sliman, L., Samhat, A. E., & Mellouk, N. (2020). Verification of smart contracts: A survey. *Pervasive and Mobile Computing*, *67*, 101227.

[56] Ganapathy, V. (2025). A comparative study of explainable artificial intelligence (XAI) techniques in financial auditing applications. *Edumania: An International Multidisciplinary Journal*, *3*(1), 1-15. https://doi.org/10.59231/edumania/9147











