Pluang Brings AI Agents to Indonesia’s Booming Retail Trading, with ‘Human in the Loop’

The platform is launching agentic trading in Indonesia, using models like ChatGPT to assemble trades while requiring human approval for final execution.

Magnific

Opinions expressed by Entrepreneur contributors are their own.

You're reading Entrepreneur Asia Pacific, an international franchise of Entrepreneur Media.

Indonesian multi-asset investment platform Pluang is testing a service that integrates artificial intelligence agents directly into regulated trading accounts. The move comes as brokerages globally split over how much execution authority to delegate to machines.

The service, called Pluang Agentic Trading, is being rolled out through limited early access. It utilises Anthropic’s Model Context Protocol (MCP), an open standard designed to connect AI systems with external data and software tools. Instead of a user copying portfolio details into a chatbot, MCP gives authorised models like ChatGPT, Claude and Gemini a structured route into the brokerage architecture.

An agent can analyse holdings, balances, transaction history and live prices to prepare buy and sell orders across five asset classes: Indonesian equities, US stocks, crypto, crypto futures and digital gold. US stock options and mutual funds remain excluded from the agent channel for now.

However, Pluang keeps a strict human checkpoint at the execution gate. An agent can monitor markets and assemble orders, but every transaction requires explicit, manual approval from the investor before execution.

Where Pluang Draws the Line on AI Trading

Pluang’s agentic trading model lets AI agents analyse portfolios, monitor markets and prepare orders through an MCP connection, while its own infrastructure controls account permissions and transaction limits. The key boundary comes at execution: the investor must manually approve every trade.

FINANCIAL INFRASTRUCTURE

[ ChatGPT / Claude / Gemini ] 
|
v
      [ AI AGENT VIA MCP ]
      – Analyses portfolio
      – Monitors markets
      – Prepares trade orders
              |
              v
    [ PLUANG SECURITY LAYER ]
      – Enforces spending caps
      – Keeps account credentials
        from third-party AI providers
      – Issues single-use order tokens

             |
              v
       [ HUMAN CHECKPOINT ]
       Investor must manually
       approve final execution
              |
              v
 [ TRADE EXECUTION ]

Timing is critical for Southeast Asia’s largest economy. Indonesia’s retail investment sector is rapidly expanding. The country witnessed 30.06 Mn capital market investors at the end of July, representing a 47.63% surge since the start of 2026, according to data from its Financial Services Authority (OJK). In July alone, the market added 1.10 Mn investors.

Pluang’s rollout lands as the global brokerage industry tests vastly different approaches to a fundamental question: once an AI agent gains access to a financial account, how much autonomy should it hold?

As of now, there are three distinct operational models:

Full Delegation (Robinhood): Its dedicated agentic account allows third-party AI agents to execute trades automatically on a customer’s behalf, explicitly warning users that orders may be placed without their direct input or real-time consent.

Conditional Automation (Public): Investors pre-approve an agent and define specific strategic parameters. When it is live, the agent executes trades autonomously whenever those predefined market conditions are met.

Human-in-the-Loop (Interactive Brokers & Pluang): Interactive brokers similarly utilises an MCP-based AI integration to let investors research portfolios and generate trade instructions, but mandates that clients manually review and submit every order.

To limit operational and security risks, Pluang is enforcing server-side spending caps on a per-order, daily and asset-class basis, although exact limits have not been disclosed. Users do not share account credentials with third-party AI providers, and fund withdrawals through an agent are blocked.

In a bid to defend against prompt-injection attacks, external data read by an agent is treated strictly as information instead of executable instructions. Each prepared order also carries a time-limited, single-use token to prevent duplicate execution.

Yet, technical guardrails do not eliminate the thorniest legal question: liability when an AI misunderstands a legitimate instruction.

Pluang distinguishes between standard investment risk — where an agent accurately executes a user-requested strategy that subsequently loses money — and genuine misexecution, where the agent misinterprets an instruction or performs an unauthorised action.

In cases of misexecution, users must report the trade for manual review. Pluang has not yet published a formal policy setting out who bears liability for AI misexecution or a dedicated process for resolving such disputes. For now, these cases are reviewed individually.

The regulatory framework reflects this ambiguity. Pluang’s agentic layer is not a licensed investment product but merely an access channel. Underlying trades are routed through existing entities supervised by the OJK or the commodity futures regulator, Bappebti (short for Badan Pengawas Perdagangan Berjangka Komoditi).

In 2023, the OJK and fintech industry bodies released guidance demanding that AI-based applications do no harm. But technology is advancing faster than regulatory frameworks. As global brokerages allow AI deeper access to financial markets, the key question will no longer be whether machines can trade, but how much of our decision-making we are willing to give up. And finally, who will be responsible for financial losses when algorithms misinterpret human intent?

Indonesian multi-asset investment platform Pluang is testing a service that integrates artificial intelligence agents directly into regulated trading accounts. The move comes as brokerages globally split over how much execution authority to delegate to machines.

The service, called Pluang Agentic Trading, is being rolled out through limited early access. It utilises Anthropic’s Model Context Protocol (MCP), an open standard designed to connect AI systems with external data and software tools. Instead of a user copying portfolio details into a chatbot, MCP gives authorised models like ChatGPT, Claude and Gemini a structured route into the brokerage architecture.

An agent can analyse holdings, balances, transaction history and live prices to prepare buy and sell orders across five asset classes: Indonesian equities, US stocks, crypto, crypto futures and digital gold. US stock options and mutual funds remain excluded from the agent channel for now.

Related Content