Start Free Trial
Home/Regulations/MiFID II (EU Markets in Financial Instruments Directive) — Regulatory Reference
Regulatory Reference
Financial Services Global / EU high

MiFID II (EU Markets in Financial Instruments Directive) — Regulatory Reference

Investment services transparency, best execution — audit trail and cross-border data access controls for EU operations.

Key Provisions
  • Directive 2014/65/EU and Regulation (EU) 600/2014 (MiFIR)
  • Best execution obligations (Article 27) — execution policy and monitoring
  • Record-keeping (Article 16) — five-year retention of orders and transactions
  • Algorithmic trading (Article 17) — system risk controls and notification to competent authority
How AutoPIL Enforces It
  • Algorithmic trading agents registered with role and policy binding in the agent registry
  • Audit chain provides Article 16 record-keeping for AI-influenced order decisions
  • Cross-border restrictions enforce EU data residency where required
Audit LogPolicy EngineSensitivity LabelsAgent RegistryLineage
AutoPIL Policy IDs
FS-MIFID2-A16-001MiFID II Order Record Retention
FS-MIFID2-A17-001Algorithmic Trading Agent Registry
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does MiFID II require for AI agents involved in algorithmic trading?
MiFID II Article 17 requires investment firms using algorithmic trading systems to implement effective system and risk controls, maintain pre- and post-trade risk limits, and notify competent authorities before deploying such systems. For AI agents executing or influencing order decisions, this means each agent must be registered, its behavior bounded by defined policies, and every action logged with sufficient detail to reconstruct decisions. AutoPIL's agent registry maps each trading agent to a policy binding (policy ID `FS-MIFID2-A17-001`), ensuring only registered agents with approved access scopes can reach order-relevant data sources before executing.
What are MiFID II's record-keeping requirements for AI-influenced order decisions?
Article 16 of MiFID II requires investment firms to retain records of all orders and transactions for a minimum of five years. Where AI agents influence or initiate order decisions — selecting instruments, triggering execution, or enriching order flow — those decisions must be traceable and reproducible. AutoPIL writes a tamper-evident, cryptographically chained audit record for every policy evaluation: which agent requested access, which data source, what policy governed the decision, and whether access was allowed or denied. Policy ID `FS-MIFID2-A16-001` maps directly to this retention obligation. These records satisfy regulators requiring reconstruction of AI-influenced trading decisions.
How does MiFID II's best execution obligation apply to AI-driven investment workflows?
Article 27 of MiFID II requires firms to take all sufficient steps to obtain the best possible result for clients when executing orders, and to monitor execution quality against their stated policy. When AI agents assist in execution decisions — analyzing market data, selecting venues, or routing orders — those agents are effectively part of the execution process. Best execution compliance requires that the data those agents access is governed, logged, and auditable. AutoPIL enforces which data sources an agent can access for a given task, preventing unregistered agents from reaching execution-relevant data and providing the audit trail regulators need to review how decisions were made.
How does AutoPIL help with MiFID II compliance for cross-border EU operations?
MiFID II applies to investment services provided within the EU, and firms operating cross-border must ensure that data handling and decision processes comply with EU requirements, including data residency expectations for certain categories. AutoPIL's source registry tags each data source with sensitivity level, jurisdiction, and owner. Policies can restrict agent access to EU-resident data sources only, block cross-border data flows that violate residency requirements, and log every access attempt. This means firms running AI agents across geographic boundaries have an enforceable, auditable control layer rather than relying on manual process controls to maintain MiFID II compliance.
What are the enforcement risks for firms that deploy AI agents without MiFID II-compliant audit trails?
ESMA and national competent authorities (NCAs) can impose supervisory measures, public censure, and fines for Article 16 and Article 17 violations. For systematic failures in record-keeping or algorithmic trading controls, fines can reach up to 5 million EUR or 10% of total annual turnover for legal persons, whichever is higher, under MiFID II's sanction framework. More practically, firms that cannot reconstruct AI-influenced order decisions during a regulatory investigation face heightened supervisory scrutiny and potential withdrawal of authorization. The inability to demonstrate which agent made which data access decision, and under what policy, is the specific gap regulators have begun probing as algorithmic and AI-driven trading grows.
Covered Industries

MiFID II applies to investment firms, trading venues, and data reporting services operating within the EU or serving EU clients. As AI agents take on roles in algorithmic trading, order routing, and investment research, the directive's record-keeping and system control requirements extend directly to how those agents access and act on financial data.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries