The Refusal Layer
Abstract
Part I of this series established that investment products were bundles of transformations, and that frictionless access deletes exactly one of them: protection of the investor from themselves. This article asks what replaces it. The answer is neither the human adviser nor the investor's own AI. A functioning refusal layer requires three properties — judgment, bindingness, and accountability — and only the first is cognitive. The other two are legal: a veto the client can override is not a veto, and a duty without a suable counterparty is not a duty.
The surviving structure is the AI inside the intermediary: licensed, non-overridable intraday, liable for its refusals, compensated by fee rather than flow. No authorisation category exists for such an entity — the suitability regime assumes the intermediary proposes and the client disposes, and nothing in it contemplates discretionary non-execution of a lawful, funded instruction. On-chain commitment devices, the one environment where self-binding works without a counterparty, prove the rule by exception: bindingness without judgment or accountability.
IThe Inversion of Scarcity
Every previous era of finance rationed access. Capital minimums, market hours, intermediary permission, the physical inconvenience of a phone call to a broker — these were not designed as behavioural protections, but they functioned as one, and they were priced at zero. The pull era deletes them all simultaneously: fractional size deletes the capital minimum, tokenised settlement deletes the clock, conversational AI deletes the permission layer and the inconvenience together. The New York Stock Exchange's own tokenised platform announcement promises the full set in three bullet points: twenty-four-seven trading, fractional shares, instant settlement (ICE, 2026).
Access was the twentieth century's scarce good. When everything is available to everyone at every hour in any size, the scarce good inverts. The investor's binding constraint is no longer getting in. It is being stopped.
IIWhy the Refusal Cannot Be Self-Hosted
The obvious answer is to give the investor's AI the job. It already knows the portfolio, the plan, the investor's documented tendency to sell into drawdowns. Configure it to refuse harmful instructions. Done.
This fails by construction, and the failure is worth dissecting because it defines the shape of what must exist instead. A functioning refusal layer requires three properties, and only one of them is intelligence.
The first property is judgment, and here the AI wins outright — against the human adviser, without contest. It detects the panic pattern in the investor's own message history. It is awake at two in the morning, when the impulse arrives. It prices the structured product's embedded option in milliseconds and can say precisely why the yield is not what it appears. On the pure cognition of refusal, the machine is the best fiduciary analyst ever built.
The second property is bindingness, and here the self-hosted AI fails absolutely. A veto the investor can override — by editing a prompt, toggling a setting, opening a second account — is not a veto. It is a speed bump the investor owns. The relevant precedent is three thousand years old: Ulysses did not ask his crew to advise him about the sirens. He had himself tied to the mast, and — the detail that matters — the crew held the rope. He pre-committed through parties he could not command in the moment of temptation (Elster, 1979). Self-custody of one's own restraint layer is a contradiction in terms. The refusal must sit with an entity outside the investor's instance, outside their prompt, outside their account settings — which is to say, with an intermediary, whatever machinery runs inside it.
The third property is accountability, and here the pure AI has nothing to offer. Refusal has costs. The veto that stops the bottom-tick liquidation will, sometimes, also stop a legitimate exit ahead of a forty-percent drawdown. Someone must bear that error, and bearing it requires a balance sheet, a licence that can be revoked, insurance that can pay, an entity that can be sued.
Fiduciary duty is not a behaviour; it is an enforceable claim against a party with something to lose. A model has no assets, no authorisation, no seizable anything. No defendant, no duty.
The composite answer is therefore neither of the terms in the usual debate. Not the human adviser, whose judgment is inferior and whose cost fails the fifth transformation. Not the investor's own AI, whose bindingness is fictional and whose accountability is void. The surviving structure is the AI inside the intermediary: a licensed entity that deploys the model, cannot be overridden by the client intraday, carries liability for its refusals, and is compensated by fee rather than by flow. The intermediary survives the pull era not because human judgment is needed — it mostly isn't — but because someone must be suable and non-overridable, and those are legal properties, not cognitive ones.
IIIThe Failure Modes of Each Pure Form
Both pure alternatives fail in ways that are predictable enough to name in advance.
- Sycophancy collapse. An assistant competing for users learns what every salesman knows: yielding retains the client, refusal churns them. The market itself will breed the veto out of any refusal layer that must also win a subscription war. Bindingness is the countermeasure as much as the product: it moves the competitive moment from each decision to the mandate boundary — the client can fire the fiduciary at renewal, but cannot punish it intraday, which is exactly where sycophancy operates.
- Operator conflict. An AI whose operator monetises order flow, product placement, or engagement carries the conflicts of the twentieth-century bank salesforce back into the system — less visibly, because the bias lives in model weights and retrieval rankings rather than in a commission grid that regulation at least forced into disclosure. Payment for order flow was crude but legible. Preference embedded in a recommendation engine is neither.
- The pure intermediary's obsolescence. The traditional adviser fails on the other flank: judgment that cannot match the model's, cost that cannot justify itself once assembly is free, and a historical compensation structure — examined in The Hidden Price — that flowed from the manufacturers of products rather than from the investors it nominally served. The gate that justified the adviser's economics is dissolving on its own schedule, independent of anything argued here.
IVThe Regulatory Void
Here the argument leaves product design and enters public architecture, because the entity described above — licensed, model-driven, discretionarily non-executing — has no category in existing law.
The European suitability regime under MiFID II is built on a directional assumption: the intermediary proposes, the client disposes. Duties attach to the recommendation; the client's instruction is sovereign. An advised client can reject every proposal; a non-advised client passes an appropriateness test and then trades as they please. Nowhere in this architecture is there room for an authorised firm that holds client assets and declines to execute a lawful, funded instruction on behavioural grounds. Portfolio management with full discretion comes closest, but discretion to manage is not the same as a mandate to refuse — and the refusal layer's entire value lies in binding the client against their own real-time instruction, which sits closer to a trust structure than to anything in the investment-services canon.
An authorisation framework for binding algorithmic fiduciaries would need at minimum five elements.
- Mandate scope. Which instruction classes the entity may refuse, agreed ex ante, so that refusal is the exercise of a contract rather than an improvisation.
- Override latency. Cooling periods measured in days rather than an absolute lock, because the goal is to separate impulse from action, not to imprison the client — the mast, not the brig.
- A liability standard for wrongful refusal. Without it, the accountability property collapses.
- A structural prohibition on flow-based compensation. A refusal layer monetised by execution is a contradiction that no disclosure can cure.
- Disclosure of the model's incentive wiring. Training objectives, operator revenue links, the things that determine whose interests the judgment actually serves — a transparency category that securities law has never had to imagine, because judgment was previously assumed to reside in disclosable humans. The requirement is operator-level, not weight-level: revenue links and training objectives are disclosable even where the model's internals are not — and disclosure here is a floor, not a cure, as payment for order flow demonstrated.
None of this exists. The MiCA review, the tokenisation pilot regimes, the market-structure modernisation files on both sides of the Atlantic — all of them regulate access: who may issue, who may trade, who may custody. Not one of them contemplates the licensing of restraint. The rulebook for the most valuable financial service of the coming decade has not been drafted.
VThe DeFi Exception That Proves the Rule
There is exactly one environment where self-binding can work without a suable counterparty, and it is instructive that it is the environment with no counterparties at all. On-chain, immutability can substitute for the intermediary: a smart-contract commitment device — time-locked positions, vesting-gated withdrawals, vaults whose exit latency is enforced by code no one can amend — delivers bindingness through physics rather than law. For some holders that is precisely the point: the licensed fiduciary is a legal entity that can be pressured, captured, or overruled by subsequent regulation; the contract cannot. The crew holding the rope is replaced by a contract that cannot hear the investor scream.
This is a genuine achievement and a sharply limited one. Code-enforced restraint delivers the second property, bindingness, in its purest available form — and delivers neither of the others. There is no judgment: the time-lock cannot distinguish the panic sale from the legitimate exit, so it refuses both, which is the wrongful-refusal problem with no liability attached. And there is no accountability, because there is no one to hold to account; the error cost lands entirely on the investor who configured the device. DeFi commitment devices are the refusal layer for investors who want the mast without the crew: real, opt-in, and blunt. They will serve a self-selecting minority well. They are not the general solution, for the same reason Part I identified DeFi as the system where claim quality and behavioural protection are inversely provisioned — the architecture that removes intermediaries removes, with them, everything only an intermediary can be.
—The Market for No
The prediction that falls out of this argument is concrete. The institutions that survive the pull inversion will not be those that distribute products — distribution is ending as a business — but those trusted to withhold execution, and paid for it. The first licensed binding-fiduciary mandate, an authorised firm deploying a model with contractual power to refuse its own client, will exist within five years. It will be authorised under a rulebook improvised from portfolio-management and trust law, because the correct category will not have been written yet.
That category should be written deliberately instead. Regulators spent the last cycle building frameworks for tokenised access and will spend the next discovering that access was never the binding constraint. The investor in a world where everything is available needs, more than anything else that can be manufactured, a counterparty whose product is no.
Sources
- 1. Intercontinental Exchange, The New York Stock Exchange Develops Tokenized Securities Platform, press release, 19 January 2026. ir.theice.com
- 2. Elster, J., Ulysses and the Sirens: Studies in Rationality and Irrationality, Cambridge University Press, 1979.
- 3. Thaler, R. H. & Benartzi, S., Save More Tomorrow: Using Behavioral Economics to Increase Employee Saving, Journal of Political Economy, 112(S1), S164–S187, 2004.
- 4. Directive 2014/65/EU (MiFID II), Article 25 — suitability and appropriateness.
- 5. Nasdaq Stock Market LLC, Proposed Rule Change To Enable the Trading of Securities in Tokenized Form, Federal Register, September 2025.
Written in a personal capacity. Analytical views only — not legal or investment advice.