Binance is moving AI agents from analysis into action. The crypto exchange has launched Agent OS, a platform that lets AI applications inspect markets and carry out trades for users who authorize them.
The launch brings autonomous AI into a sensitive area: managing real money. Binance, described in the source as the world's largest crypto exchange with more than 300 million registered users, is offering new access to its financial infrastructure while making user controls a central part of the setup.
What Agent OS Lets AI Agents Do
Agent OS is built for developers who want to connect AI applications and agents to Binance services. The platform combines existing Binance tools with newly introduced support for its Model Context Protocol (MCP).
The system works with tools including OpenAI's ChatGPT and Codex, Anthropic's Claude Code, and Cursor. With user authorization, those agents can access market data, view account information and execute trades.
Binance is targeting trading as one of the first use cases. Jeff Li, vice president of product at Binance, said agents could monitor markets, conduct research and risk analysis, react to signals, and autonomously place orders or execute strategies such as arbitrage.
That makes Agent OS more than a chatbot layer. It is a way for software agents to act through Binance's infrastructure after a user decides what access they should have.
The Main Control Is the User's Permission Setup
Binance is not presenting Agent OS as a system where agents receive unrestricted access. Instead, the company says the user decides what an AI agent can see and do.
"Instead of total freedom, we put the power in users' hands to give them the granular access control of what they can do through the agent," said Jeff Li, vice president of product at Binance, in an interview. "We put [the control] at the account level to protect the users' funds."
The main mechanism is a dedicated sub-account. Users can assign an agent to a sub-account and configure it for certain activities, including spot or futures trading.
Withdrawals from those sub-accounts are blocked by default, Li told TechCrunch. That design creates a sandbox around the agent's activity, limiting where the agent can operate.
Users can also decide whether an AI agent must request approval for every order or can trade autonomously after its permissions are set. Binance does not add a separate cap on how much an agent can trade or lose inside the sub-account. In practice, the amount the user moves into the sub-account becomes the limit.
Visibility Into AI Reasoning Is Limited
The risk question is not only whether an agent can trade. It is also whether Binance can understand why the agent made a specific trading decision.
Li said the reasoning happens outside Binance's systems, either on the user's computer or inside the AI application the user chooses. "We really cannot see the reasoning of what the user's action is," he said.
That means Binance can monitor the trading activity that results from an agent's actions. But the exchange has limited visibility into whether the decision came from faulty information or manipulation.
When asked about prompt-injection attacks or other compromises, Li again pointed to sub-accounts as the primary protection. Binance also said its existing security, risk-control and anti-money-laundering policies for subaccount APIs apply to Agent OS at launch.
For users, the practical takeaway is clear: permissions matter. An AI agent's access, account scope and funding level define how much room it has to operate.
Payments And On-Chain Activity Are Also Part Of The Plan
Agent OS is not limited to exchange trading. Binance is also designing it to connect agents with payments and on-chain activity.
Through Binance's x402 integration, agents can send and settle payments. The Agentic Wallet lets them interact with tokens and decentralized-finance protocols.
Unlike exchange trading through a sub-account, Agentic Wallet transactions have Binance-set daily limits. According to the company, regular swaps are capped at $50,000 a day, DeFi transactions have a default $100,000 daily limit, and x402 payments are limited to $20 a day.
Those limits create a different control structure for wallet activity than for exchange trading. In trading, Binance does not impose a separate cap on how much an agent can trade or lose within the sub-account. For Agentic Wallet activity, the company has defined daily thresholds.
Crypto Exchanges Are Opening The Door To Agentic Trading
Binance is not the only crypto exchange moving toward AI agents. Rival exchanges have also been opening infrastructure to AI applications through MCP and other developer tools.
In March, Kraken launched an open-source command-line tool with a built-in MCP server. That tool allows AI agents to take actions including spot and futures trades.
Coinbase followed in June with Coinbase for Agents, which connects AI agents directly to user accounts. It allows agents to trade, make payments and execute other financial workflows within user-set limits.
OKX also enabled agentic trading on its platform by bringing an open-source MCP toolkit earlier this year.
Li called Agent OS Binance's "first step" toward giving developers a platform for AI-powered applications that can act across crypto and traditional markets. The broader shift is toward agents that do not only answer questions, but also carry out financial tasks after users authorize them.
That shift puts the control layer under pressure. As AI agents gain access to trading systems, market data, payments and wallets, the design of permissions, sub-accounts and limits becomes central to how users manage risk.