0
LLM calls in the
real-time tick loop
Human
Trader approves every order
before it reaches the market
100%
Of scores, recommendations
& fills logged for replay
Deterministic
Risk engine validates
before the trader decides

AI judgment is valuable — AI authority is dangerous

The desk wanted an LLM's reasoning about event risk, discipline, and rule conflicts — but a hallucinating or slow model anywhere near live execution is a catastrophic risk. Three problems had to be solved together.

AI power without AI risk

LLMs are compelling for trading judgment, but a model that hallucinates, stalls, or simply makes a poor call cannot be allowed near live orders. The desk needed the reasoning without ever surrendering control to it.

Correlated exposure across the complex

MES, SPY, and SPX are all bets on the same index. Per-instrument limits let an unintended 3× S&P position hide across three symbols — including through options delta, 0DTE gamma, and pin risk near expiry.

Explainability & auditability

Every decision had to be reconstructable — what the model saw, what the LLM advised, and why a trade was taken or blocked — for both discipline (replaying losing days) and a defensible answer to AI-governance risks like OWASP “excessive agency.”

Separate the signal, the reasoning, and the authority

A layered AWS-native architecture where a deterministic quant core scores every bar, a governed agent reasons only at decision points, and the engine's recommendation clears deterministic risk before a human trader gives the final approval — always.

Deterministic quant core

Real-time bars and features flow through the quant stack; a SageMaker-hosted signal model (Chronos-2, benchmarked against XGBoost / LightGBM) scores each 5-minute close. Hard risk — daily stop, max size, kill switch, news lockouts — is deterministic and always enforceable.

Governed agentic reasoning layer

Only when a setup crosses a confidence threshold is a Bedrock agent (AgentCore + Strands + Guardrails) invoked — advisory only. It gathers evidence through least-privilege tools and cited RAG over the trade journal and an external market-intelligence store, then returns a structured approve / defer / size-down / reject with rationale.

Portfolio risk, then the trader's call

A deterministic portfolio risk engine on EKS converts every position — options included, via delta — into net S&P delta-equivalent exposure and caps it at the portfolio level. What clears risk is a recommendation, not an order: a human trader reviews it and gives the final approval before anything reaches the broker.

End-to-end flow
Ingest ticks Build bars Compute features Score · SageMaker Threshold? Reason · Bedrock agent Recommend Risk engine · Deterministic Trader review & approve Execute · Broker Journal & replay
Built AWS-native — SageMaker for signals, Bedrock AgentCore / Strands with Guardrails for governed reasoning, EKS for the risk and execution control plane, a human trader in the loop approving every order, and S3 + replay stores so every score, recommendation, and fill is durable and auditable.

Judgment from AI, authority from deterministic risk

The platform's outcomes are architectural guarantees, not hopeful metrics — safety, auditability, and control that hold even when the AI fails, times out, or is simply wrong.

Safety
0 in loop
The LLM only advises after a signal crosses a threshold — never in the tick-by-tick execution path.
Auditability
100%
Every model score, LLM rationale, and risk decision is persisted and replayable bar by bar.
Risk
Net-delta
Options-aware portfolio limits cap correlated S&P exposure across MES, SPY, and SPX.
Reasoning
Cited
RAG-grounded, schema-validated recommendations — the agent reasons over evidence it can cite, or it defers.
Instruments
3-in-1
New symbols are added by configuration, not service rewrites.
Authority
Human + rules
Hard limits screen every recommendation; a trader gives the final approval before any order reaches the market.

Safe by design

The agent runs only after the signal crosses a threshold, its output is advisory, deterministic risk applies hard limits, and a human trader approves every order before it reaches the market — layered defense against LLM “excessive agency.”

Explainable and replayable

Every score, rationale, and risk decision is persisted, so losing sessions can be replayed bar by bar and trading discipline improved over time.

Extensible without new risk

Config-driven instrument abstraction and multi-agent orchestration let the platform grow from MES to the full S&P complex without touching the safety core.

We got the judgment of an LLM without ever handing it the keys — the engine recommends, deterministic risk screens it, and a trader makes the final call — and every decision is on the record.
Platform outcome · Quantitative trading engagement

Putting AI near high-stakes decisions?

Blue Avanti designs agentic AI systems where deterministic controls keep final authority and every decision is auditable. Start with a free discovery call.

No sales deck — just a conversation