Skip to main content
Incident intelligence/SS-IR-027CASE FILE OPEN
Symbolic editorial illustration for SS-IR-027SERVANTSTACK // INCIDENT INTELLIGENCEFORENSIC IMAGE // VERIFIED FRAME
SS-IR-027 // INCIDENT REPORTOfficial finding

Citigroup

A Fat-Finger Basket the Algorithm Happily Sold, Wiping About 300B Off European Markets

EXECUTIVE BRIEF

On May 2, 2022, a Citigroup Global Markets trader in London tried to sell a 58 million USD basket of equities.

FAILURE CHAINTRACE COMPLETE
  1. 01TRIGGEROn May 2, 2022, a Citigroup Global Markets trader in London tried to sell a 58 million USD basket of equities.
  2. 02MACHINE ACTIONAutonomous actor
  3. 03MISSING GATERisk-based SME approval before execution
  4. 04IMPACTPhysical safety
01 // INCIDENT SUMMARY

The short version

On May 2, 2022, a Citigroup Global Markets trader in London tried to sell a 58 million USD basket of equities.

02 // KEY FACTS

Case telemetry

INCIDENT
SS-IR-027
DATE
May 2, 2022
SYSTEM
Citigroup
LOCATION / SCOPE
Europe (London desk; OMX Stockholm and other European exchanges)
EVIDENCE
Official finding
AI ROLE
Autonomous actor
HARM
Physical safety
SOURCES
3 cited records
03ENTRY POINT // WHAT HAPPENED

The event

On May 2, 2022, a Citigroup Global Markets trader in London tried to sell a 58 million USD basket of equities. Instead of entering 58 million into the Notional field, the trader entered it into the Quantity field, creating a basket worth roughly 444 billion USD (about 58 million units of the MSCI Europe ex-UK index). Citi internal controls blocked 255 billion USD of the order but failed to hard-block the rest. The remaining 189 billion USD was passed to a trading algorithm that began slicing it into orders to be sold across the trading day. About 1.4 billion USD in equities was actually executed across European exchanges before the trader managed to cancel. The mass sell-off triggered a brief flash crash: the OMX Stockholm 30 Index dropped nearly 8 percent in five minutes, and roughly EUR 300 billion (about 300B+ USD) in market value evaporated at the peak. In May 2024, UK regulators fined Citi a combined GBP 61.6 million (about 78.4 million USD): GBP 27.8 million from the Financial Conduct Authority and GBP 33.9 million from the Bank of England Prudential Regulation Authority (reduced from a headline GBP 48.4 million for settlement).

04CAUSAL TRACE // AI'S ACTUAL ROLE

What the machine did

The trade-execution algorithm was the amplifier that turned a single keystroke into a market event. There was no hard block to reject an obviously absurd 444 billion USD basket in its entirety, and the system let the human override the one pop-up alert that fired by clicking past it. Once the order cleared that soft warning, the algorithm did exactly what it was built to do: it accepted the basket without any independent sanity check on size, began fragmenting and routing 189 billion USD of sell orders into live European markets, and executed at machine speed with zero human approval gate between the trader clicking OK and shares hitting the tape. The automation had no notion that a 444 billion USD order from a desk that meant to sell 58 million USD was self-evidently wrong. It optimized for filling the order, not for asking whether the order should exist.

Autonomous actorAutomation was a causal participant—not a decorative label for the system around it.
05BLAST RADIUS // CONSEQUENCES

Where the failure landed

A brief but violent European flash crash: the OMX Stockholm 30 fell about 8 percent in five minutes and roughly EUR 300 billion in market value was momentarily wiped across European indices on May 2, 2022. Roughly 1.4 billion USD of Citi own erroneous sells were executed before cancellation. Two years later, in May 2024, the FCA and PRA fined Citigroup Global Markets a combined GBP 61.6 million (about 78.4 million USD), with regulators specifically faulting the absence of a hard block and the ability to override the pop-up alert. The PRA also noted it had repeatedly pressed Citi to strengthen its trading controls between 2018 and 2022. Reputational damage and renewed scrutiny of fat-finger risk and automated order controls across the industry followed.

06 // EVIDENCE STATUS

Official finding

Supported by a court, regulator, inquiry, or other official record cited below.

SOURCE RECORD UPDATED 2026-07-09

07 // SOURCE LEDGER

3 cited records

  1. 01
  2. 02
  3. 03
08CONTROL FAILURE // MISSING GOVERNANCE

Risk-based SME approval before execution

The failure pattern in this case: High-stakes output had no accountable checkpoint.

09INTERVENTION POINT // HUMAN IN THE MIDDLE

The moment the path could change

The appropriate subject-matter expert reviews the evidence, exceptions, and affected people before the output becomes action.

AI PROPOSESHUMAN OWNS THE DECISIONSYSTEM EXECUTES
10CONTROL DEPLOYMENT // AUTHORITYGATE

Risk routing · named approval · audit trail

AuthorityGate Operational Resilience framework requires a hard, non-overridable change-validation gate on any order whose notional or quantity exceeds a desk pre-approved envelope. Under AuthorityGate, an order about 7,600x the intended size (444B USD vs. 58M USD) crosses a magnitude threshold that cannot be cleared by a single trader clicking past a pop-up. It is routed to a human SME validation gate -- a second qualified markets supervisor who must independently confirm size, notional-vs-quantity field mapping, and intent before any portion reaches the execution algorithm. Critically, AuthorityGate treats the algorithm as downstream of human sign-off, not parallel to it: no slice of a flagged basket is released to routing until the SME approves, so a self-evidently wrong 444 billion USD basket is held at the gate rather than partially executed across live exchanges. The override that defeated Citi only control would itself be a logged, dual-authorization action -- not a one-click dismissal.

RELEVANT KEYSTONE CONTROLHuman-in-the-Loop ValidationHow high-risk actions route to a named subject-matter expert who owns the go or no-go decision.
12 // THE ALTERNATIVE

Autonomy is a design choice.

See the operating model that keeps AI useful while preserving human authority at consequential moments.

Compare AgenticAI and AugmentedAI →