Who Answers for the Black Box? Algorithmic Trading, Regulation 16C, and SEBI’s March Towards Ethical AI
Contents
I. Introduction
The Securities and Exchange Board of India (“SEBI”) has constructed an increasingly detailed regulatory architecture for algorithmic trading, beginning with its broad guidelines of March 2012. SEBI defined in the 2012 guidelines that ‘Any order that is generated using automated execution logic shall be known as algorithmic trading’.
Recently, SEBI formalised the relationship between Brokers and Algo providers as one of principal and agent for API-based trading and, most significantly, distinguished between ‘White-box’ and ‘Black-box’ algorithms in the February 2025 Circular for safer participation of retail investors, and the insertion of Regulation 16C into the SEBI (Intermediaries) Regulations, 2008.
The circular has sparked discussions about whether a disclosure-based audit check has now reached its limits and whether there is a liability-without-control problem that must be addressed. This study argues that the recent additions are insufficient to tackle the problem of intrinsic opacity that machine learning, particularly deep neural networks and large language models, has now introduced to the market.
II. The Evolution of Algorithmic Trading and Broker Regulation in India
SEBI has always taken decisive steps to fulfil its statutory duty as per Section 11 of the SEBI Act, 1992. The 2012 circular aimed to regulate and develop technological integration rather than prohibiting it. It required that algorithm orders be routed through Broker servers equipped with proper risk-control mechanisms. It instructed exchanges to construct frameworks capable of absorbing the algorithmic load while maintaining consistent response times across all Broker participants. SEBI introduced a regime designed to deter the order-flooding behaviour that hat could arise from high-frequency automated strategies, marking a shift from the previous manual paradigm.
The current regulations represent the emergence of a new phase of cognitive governance, defined by the unrecoverable and unknown logic of Black-box algos. The half-yearly system audit mandated in 2013 assumed that the auditor could determine whether the requirements were met or not through access. However, the sudden maturation of generative AIs and Large Language Models goes beyond earlier applications by market participants, introducing new risks.
Previously, SEBI viewed the algorithm as a fast and tireless agent whose appetite for the order book had to be limited by speed restrictions, permission gates, and audit logs. The risks it sought to mitigate were of market destabilization caused by a malfunctioning or aggressive algorithm placing orders too quickly, too large, or too many. SEBI did not, and could not at that time, anticipate that the danger might instead lie in cognition, that the logic by which an algorithm decided to place a particular order might itself become unknowable and therefore, a threat to the presumption that all orders can be inspected and audited.
III. Arrival of Advancing Machine Learning and APIs in Algorithmic Trading
It is important to understand that the transformation of quantitative finance over the past decade is, at bottom, a transformation of what counts as data. The traditional inputs of quantitative analysis were structured and numeric. Examples include historical prices and volumes, company fundamentals such as earnings, balance-sheet ratios, and dividend records, and macroeconomic indicators such as interest rates and inflation.
However, the contemporary frontier lies in what practitioners term ‘alternative data.’ This category includes unstructured, high-dimensional sources that can be indirect indicators of the value of securities. It may involve written data, such as news articles, regulatory findings, and social media sentiments, as well as visual data, such as candlestick patterns. It also covers newly available statistical data such as geolocation build-outs, web traffic statistics, and point-of-sale data. Machine learning models analyse these varied datasets and convert them into signals that help predict economic activity and market movements.
The increase in alternative data has led to the widespread use of machine learning, especially deep neural networks, in quantitative finance. A deep neural network is a type of AI model made up of many interconnected layers that process information. It contains a large number of parameters, often in millions or billions for the largest language models. Their values are adjusted during extensive data training to minimise predictive error. These models identify complex relationships within massive datasets and detect patterns and investment opportunities that traditional models and human analysts may overlook.
However, these models also face significant legal and operational challenges, as they are often Black-box systems. In contrast to linear models, where the logic behind a prediction is clearly explained, deep neural networks are Black-Boxes and do not reveal how they arrive at a particular decision. The information in Black-Box models is processed through millions or billions of interconnected parameters, making the decision-making process too complex to translate into simple human explanations. Therefore, the logic becomes invisible even to the developers themselves. This algorithmic opacity is a serious threat to transparency and regulatory compliance in financial decision-making because disclosure of the model does not provide the logic behind a prediction.
IV. The Black-box and the Impossible License
The Brokers face a complex licensing and registration regime, as it is not a one-time event but a continuing status subject to dynamic executive rule-making and subordinate legislation. This acts as a lever by which exchanges and regulatory bodies continuously govern Broker conduct. The February 2025 Circular for safer participation adds a classification that is, for present purposes, decisive. It distinguishes between ‘White-box’ and ‘Black-box’ algorithms.
Following the distinction, for White-box algos which follow an explainable AI model, the circular asks for very little beyond the general regime. But for Black-box Algos where the logic is not known to the user and is not replicable, the Algo provider under Clause V must:
- Register as a Research Analyst, maintain a detailed research report for each Black-box algorithm, and confirm to the respective stock exchange that such a report has been kept; and
- On any change to the logic governing the algorithm, treat it as a fresh algorithm, re-register it, and prepare a new research report.
SEBI understands that interpretability needs to be a regulatory category. It is remarkable, as very few regulators have posited a trading algorithm’s explainability into a category with duties tied to its various levels of opacity. This is alongside the construction of a principal-agent relationship, ensuring that a licensed, solvent intermediary is accountable for any liability arising from algorithmic actions. The circular also includes an intelligent piece of regulatory gap-filling. The circular, while mentioning under Clause III that “while algo providers shall not be regulated by SEBI”, still allows SEBI to retain the supervisory authority by mandating that such Black-box Algo providers become Research Analysts. Thus, creating a sanctionable framework under SEBI, with the power to penalise a Research Analyst’s actions in case of default under Section 32 of the Research Analyst Regulations, 2014.
The regulatory response to the Black-box, such as reporting and re-registration, presupposes two assumptions about the model’s interpretability and its stationary application.
The Circular stipulates that the Black-box Algo provider shall register as a Research Analyst and maintain detailed research reports; but the requirement is impossible to satisfy in good faith. A verbatim reading of the clause reveals that the report should consist of the logic of the Black-box algorithm. When the logic behind a prediction cannot be revealed, the report will instead consist of the model’s architecture, training data, and intended behaviour, which are indeed valuable disclosures. However, they are not disclosures of the decision-making logic; rather, they seek to explain the Black-box model from outside. The threat is that the aim of transparency through documentation will not address opacity but instead lead to black-and-white compliance without actual comprehension, and may provide a false sense of security to the retail investors it seeks to protect.
Another difficulty arises from the requirement to re-register whenever there is any change in the logic. While this aims to ensure that the registered model is the one actually deployed, it puts service brokers in a difficult position. Even if interpretability wasn’t an issue, this assumes that the logic is static and that a single algorithm behaves similarly across different data sets over time. Most machine-learning models are adaptive; they periodically retrain on fresh data to reduce the probability of an error. The logic enters a state of constant, incremental change, with no stable cognition to register, even though the underlying code may still be the same. The licensing consequence is that adaptive models would now require fresh registration more or less constantly. Furthermore, the realistic outcome would more likely be either the burden of constantly deploying due to a constantly changing logic or providers treating periodic data training as the same algorithm even though the logic has changed, and thus building a passage around the requirement.
V. Ethical Governance and Sole Public Liability of the Principal
At the core of governance lies a fiduciary duty that requires investment professionals, Brokers, and financial institutions to act in the absolute best interests of their clients. This duty is non-negotiable under the Code of Ethics and Standards of Professional Conduct of the CFA Institute. However, fiduciaries cannot reasonably demonstrate prudence or due diligence if they cannot explain why an algorithm system made a specific financial decision that resulted in a material loss for the client. The inability to articulate the logic behind an algorithm's output directly conflicts with the legal requirement to act intentionally with the informed consent of the investor.
Domestically, including 16C in the SEBI (Intermediaries) Regulations, 2008 is a potential means to support ethical governance. It regulates any person under SEBI's jurisdiction who uses AI or machine learning tools, such as Research Analysts, regardless of whether those are designed by the person themselves or procured from third-party technology service providers. That is, the deployer can be a person other than the provider. This eliminates the ambiguity that might otherwise have surrounded the question of who is responsible for an AI-driven harm. The provision aligns with the previously discussed agency characterization, that the Broker as principal is liable for the acts of the Algo provider, and reinstates the principle that a regulated entity cannot contract out of responsibilities by outsourcing the underlying function.
The hard-hitting barrier exists when the Broker who obtains a Black-box model is in the position of a principal, responsible for an agent whose conduct it cannot observe and whose reasoning it cannot reconstruct. The liability is concentrated on the party with the least ability to supervise or understand the system. The Broker may demand contractual indemnities and service-level commitments from the vendor, and prudent Brokers will do so, but private contractual allocation does not displace the public regulatory liability. The issue can be better understood by ascertaining where the tangible loss is absorbed. If the model fails, the direct losses fall on the intermediary and ultimately on the downstream investor, in which case the principal’s safety-net mechanisms may be displaced when the vendor is offshore or thinly capitalised. An ethical governance framework must properly allocate risk to achieve its end. The June 2025 consultation by SEBI proposed guidelines for the responsible use of AI and Machine Learning and invited feedback. Still, such informal discussions cannot cure the illness of a binding public law framework.
VI. Conclusion
It cannot be denied that SEBI deserves praise for one of the most detailed attempts anywhere to make the explainability of a trading algorithm a matter of securities law. India has, in the space of a single year, laid down a coherent body of AI governance with remarkable efforts such as the RBI's FREE-AI Committee Report in August 2025, MeitY's national guidelines in November 2025, and a January 2026 white paper from the Office of the Principal Scientific Adviser urging safeguards ‘by design’ across the AI lifecycle.
A market is, at bottom, a structure of trust wherein the investors commit capital on the faith that the rules are fair, that intermediaries owe and observe duties, and that when something goes wrong, someone can give a fair account of what led to such an adverse outcome. The Black-box withdraws this account, and the framework governing an unintelligible object starts regulating the stakeholders around Black-box instead of the box itself. Closing this gap in accountability and transparency does not require a blanket ban but rather a framework that balances interests with innovation.
The endnotes of this study will be forward-looking, suggesting that, firstly, a right to explanation must be created for the retail clients. Where an algorithmic system produces a materially adverse outcome for the retail client, the client should be entitled to a meaningful, plain-language explanation of the factors that drove the decision. Secondly, a corresponding obligation must be placed on the intermediary to maintain the records and the necessary explanations of the behaviour to honour that right. Additionally, this should be accompanied by a more extensive independent audit of a model’s behaviour, including bias testing, stress testing under extreme scenarios, drift detection, and validation of explanation methods, conducted by accredited auditors independent of both the intermediary and the vendor. These measures have already been adopted for high-risk AI use under other domestic and international frameworks, such as the recent European Union AI Act.
A significant ethical governance milestone can also be achieved by closing the provider-deployer accountability gap. There is a need to develop a registration or empanelment system for developers and AI vendors who supply models to regulated intermediaries. This system must include co-extensive obligations for model documentation and auditing. The task before SEBI is to ensure that the algorithmic future of the Indian market is one in which predictive power and public trust move forward together, rather than one in which the former is purchased at the silent expense of the latter. It's vital to closely monitor the upcoming situation, as it may shape the securities landscape for generations.