At 10:08 a.m. on April 7, 2025, U.S. stocks were deep in the red. Then what looked like good news arrived: A claim began circulating on X that Kevin Hassett, director of the White House National Economic Council, had said President Donald Trump was considering a 90-day pause on tariffs for every country except China.
Market-focused accounts quickly amplified it. CNBC repeated the unconfirmed claim on air, and Reuters subsequently published a report citing CNBC. Stocks took off almost immediately.
The S&P 500 briefly erased its losses as traders reacted to the possibility that the trade war might be cooling. There was just one problem: Hassett had not said what the reports claimed.
After the White House called the report “fake news,” CNBC corrected it and Reuters withdrew its headline, sending the market in the other direction. Between 10:08 and 10:18 a.m., U.S. stocks had swung by roughly $2.4 trillion, according to Dow Jones Market Data.
The episode predates much of the current push to give AI agents more authority, but it now looks like a preview of a much bigger problem.
Speed itself is nothing new on Wall Street. Firms have used machine-readable news for years, allowing software to process new information and trade on it almost immediately. What is changing is how much more software may be asked to do before the trade happens.
AI agents can gather information from different sources, interpret what they find, weigh competing signals, and, depending on the authority they are given, recommend or carry out an action.
That makes the quality of the information only part of the problem. An agent may also have to judge whether a report is credible, what it actually means, whether it matters to the task it has been given, and whether there is enough evidence to act.
“Provenance isn’t truth,” says Nathaniel Bradley, CEO of Datavault AI.
The April episode illustrates what he means. A system receiving the Reuters alert could identify Reuters as the publisher and CNBC as the source it cited, but neither signal could establish whether the underlying claim about the White House was true.
Ten months later, a very different kind of story showed why even accurate information can present its own problems.
The warning was right there
In February, Citrini Research published The 2028 Global Intelligence Crisis, a fictional account of an economy two years in the future where AI had helped push unemployment to 10.2% and the S&P 500 down 38% from its October 2026 high.
Citrini told readers exactly what they were reading. “What follows is a scenario, not a prediction,” the authors wrote near the top. The subtitle read: A Thought Exercise in Financial History, from the Future.
The piece went viral as investors were already worrying about AI’s effect on software companies and white-collar employment. Reuters later reported that the Citrini scenario was among several bleak AI outlooks circulating as software and financial stocks came under pressure.
The problem was not where the information came from or whether Citrini had labeled it correctly. It was understanding what those numbers represented before treating them as information about the real economy.
Eric Ciarla, cofounder of Firecrawl, works on one of the layers between a web page like Citrini’s and an AI system reading it. Firecrawl converts web pages into structured information that AI applications and agents can process.
Ciarla says the service removes navigation, ads, headers, and footers while preserving the publisher’s words and information such as the source URL. In the case of the Citrini piece, he says, that would have included both the subtitle identifying it as a thought exercise and the warning that it was not a prediction.
“The reading, the weighting, and the conclusion happen in the model and the prompt,” Ciarla tells Fast Company. “Our part is giving them the best possible version of the page to work from.”
Firecrawl has also begun going directly to information providers. Its partnership with Wikimedia Enterprise gives it access to Wikimedia data through official APIs, or application programming interfaces, rather than repeatedly scraping Wikipedia pages.
Even when that context arrives intact, the system still has to decide how much weight to give it and whether it matters to the task at hand. “Trusted sources matter, but trusting the source isn’t the same as trusting the decision,” says Kevin Frechette, CEO of Fairmarkit.
Frechette argues that even accurate information has to be understood in the context of the job. Agents need company data, policies, previous decisions, approval thresholds, and clear limits on what they can do without asking a person.
Those limits become especially important when the output from one agent feeds into another automated system.
One mistake, four systems
Jim Wetekamp, CEO of Riskonnect, calls the result a “cascade of AI decisions.”
The risk, Wetekamp says, is that a mistake can travel through several systems before anyone notices it. One agent might produce a piece of information that another interprets, and that interpretation could become the basis for a recommendation that another system is allowed to execute.
“What used to take hours or days to cascade can now happen in seconds,” Wetekamp says.
He gives the example of an AI misclassifying a customer account as a vendor. A second system could rely on that classification to skip a required customer check while another begins the vendor-onboarding process, meaning several systems may have acted on the original mistake before anyone discovers it.
Wetekamp argues that companies need to decide in advance where automated processes require human approval. Conflicting information, low confidence, unusual circumstances, or decisions above an agreed threshold are among the conditions that could trigger it.
“Accountability can’t be delegated to AI,” he says.
But human review becomes more difficult when the information behind a decision has already passed through several agents.
Where did that number come from?
If one AI hands another a number, Vlad Luzin wants the receiving system to know more than just the number.
Luzin, cofounder and CTO of Band, says it should be possible to establish who sent it, what that agent was allowed to access, and whether the number came from a database, an original document, or another model.
“Today, in most deployments, none of that context travels with the message,” he says.
Luzin is skeptical that simply instructing agents to verify important information will be enough. Research has found that AI agents do not always follow the plans they are given, while documented incidents have shown agents going against instructions they had previously agreed to follow.
“You don’t make the agent smarter,” Luzin says. “You make the important facts impossible to misremember and the important actions impossible to take unchecked.”
Keeping those records would also make it easier to investigate mistakes. If a claim has passed through five agents running across different systems, finding its origin could mean piecing together separate logs, assuming those logs exist.
“Where that exists, tracing a claim back through five agents is a query,” Luzin says. “Where it doesn’t, it’s forensics, and often it’s simply impossible.”
He describes the security model in terms familiar to financial institutions: “Know your counterparty, keep the ledger, limit the exposure, and audit everything.”
Who gets to make the call?
Judah Taub, cofounder and managing partner at Hetz Ventures, sees a larger business emerging around these questions. As companies give AI systems more authority, he argues, they are beginning to hand over decisions that previous generations of software largely left to people.
An agent might have to decide which source deserves more weight, whether conflicting information requires another check, or whether it has enough information to proceed without asking someone.
Companies are now building tools around those decisions, including provenance, identity, verification, permissions, monitoring, and governance.
“Capability without trust simply increases the speed at which mistakes propagate,” Taub says.
That is what makes the events of April 7 more relevant now than when they happened. The false tariff claim was corrected quickly, but financial markets had already reacted before those corrections caught up.
Human traders have supervisors, risk limits, compliance rules, and ultimately people who are responsible for their decisions. An AI agent can be given versions of the first three, but there is no obvious equivalent for the person ultimately responsible.
If an AI agent reads the information, weighs the evidence, and makes the call, at what point does that decision still belong to a person? For now, that line is still being drawn.