Algorithmic Trading and the EU AI Act: Testing Energy Models Against REMIT

0
12

Automated trading is becoming standard across European power and gas markets. Forecasting systems process weather, generation schedules, grid constraints, storage levels, and order-book movements before recommending or placing trades on day-ahead and intraday markets.

For technology firms and trading desks outside Europe, this creates a cross-border compliance problem. A model developed abroad and deployed by an EU market participant can still fall within European rules on AI, algorithmic trading, market integrity, and outsourcing.

The EU AI Act entered into force in 2024 and applies through a staged timetable. Most provisions become applicable from 2 August 2026, while separate obligations already apply to prohibited practices, AI literacy, and general-purpose AI models.

This is where legal and technical teams combine AI, Tech Compliance & Infrastructure in Energy with REMIT and MiFID II analysis. The objective is to determine what the system does, which entity controls it, and how its market behaviour will be monitored.

Why One Model May Trigger Several Rulebooks

The AI Act uses a risk-based structure. Classification turns on the system’s intended purpose and deployment context rather than the mere use of machine learning.

A model that forecasts day-ahead electricity prices for a human trader may fall outside the high-risk categories. The position can change if the same system becomes a safety component in the management or operation of critical infrastructure, including the supply of gas or electricity. The legal assessment must distinguish forecasting, automated order execution, portfolio optimisation, balancing, and grid control.

The software developer may be a provider under the AI Act, while the trading firm acts as deployer. Material modification or a change of intended purpose may shift those responsibilities.

REMIT and MiFID II examine the trading activity itself. A system can sit outside the AI Act’s high-risk categories and still require market-abuse controls, algorithm notifications, testing, and records.

REMIT II and False Market Signals

Revised REMIT introduced specific obligations for algorithmic trading and direct electronic access in wholesale energy markets. Market participants using algorithmic trading must notify ACER and the relevant national regulatory authority under Article 5a.

ACER treats spoofing and layering as potential forms of manipulation. These practices involve entering non-genuine orders that create false or misleading signals about supply, demand, or price, often while executing genuine trades on the opposite side of the order book.

A poorly calibrated algorithm may repeatedly place and cancel orders, react too aggressively to shallow liquidity, or create an artificial impression of demand.

Regulators will examine orders, cancellations, executions, market conditions, and internal controls. Firms must be able to explain why the strategy behaved as it did and show that effective safeguards were in place.

Controls Required Before Deployment

A defensive compliance file should exist before the model enters a live market. It should include:

  • a documented description of the model’s intended purpose and regulatory classification;
  • version control for code, parameters, training data, and material changes;
  • pre-trade limits for price, volume, message frequency, and position exposure;
  • testing against illiquid markets, volatility, stale data, and failed connections;
  • real-time monitoring, escalation procedures, and a functional kill switch;
  • time-sequenced records linking model signals to orders and executions.

Controls should be reviewed after retraining, a major data-source change, or a modification to execution logic. A series of small recalibrations can materially change behaviour.

For firms subject to MiFID II algorithmic-trading rules, outsourcing does not transfer regulatory responsibility to the software vendor. Contracts must give the trading firm access to technical information, testing evidence, logs, and support required to demonstrate compliance.

What a Defensive Legal Opinion Should Cover

A legal opinion should avoid broad labels such as “low-risk AI” without analysis. It should map the system’s actual function and establish the legal basis for classification.

The review should identify whether the software generates forecasts, determines order parameters, executes transactions, manages direct electronic access, or controls part of an energy network. It should then analyse the AI Act, REMIT, MiFID II, exchange rules, and national supervision.

The opinion should define responsibilities between developer, deployer, investment firm, market participant, and infrastructure provider. An EU trading firm may remain responsible for controls even when a foreign vendor retains the source code.

A useful opinion ends with operational conditions, such as human approval, deployment limits, validation procedures, notification requirements, or restrictions on certain venues and products.

Protecting Algorithms While Preserving Oversight

Trading firms often treat source code, model weights, data pipelines, and execution logic as core intellectual property. Regulatory access and customer oversight can create tension with confidentiality.

Cross-border licence agreements should define ownership of background IP, improvements, model outputs, and customised components. They should also establish audit access without giving the customer unrestricted rights to copy or reuse the technology.

Relevant provisions may cover secure code review, source-code escrow, cybersecurity duties, data location, regulatory support, service continuity, subcontractors, and access to logs.

The commercial goal is to preserve proprietary value while giving the regulated trading firm enough visibility to meet its obligations.

Compliance Continues After Launch

Algorithmic risk develops after deployment. Market structure changes, new products are added, data quality shifts, and models are retrained. A classification completed during procurement can become outdated within months.

Trading firms should maintain joint governance involving technology, compliance, legal, risk, and market operations. Every material change should be assessed for its effect on AI Act classification, REMIT conduct risk, MiFID II controls, and contractual responsibilities.

When an exchange, regulator, or clearing member asks why a model generated a particular pattern, the firm should be able to reconstruct the decision path and show the controls surrounding it.

Automated energy trading can improve forecasting and execution. Its commercial value depends on disciplined deployment. In European markets, model performance and legal accountability now develop side by side.