beginner10 min read23 of 24

    Guardrails, SEBI and the Human in the Loop — Where AI Ends and Advice Begins

    Advice is a regulated activity with a named, accountable person behind it. A model has none of that, and cannot acquire it.

    Rohit Singh

    Mr. Chartist · SEBI RA INH000015297

    Module

    There is a sentence you can type into any AI tool in about four seconds: "give me three stocks to buy tomorrow with entry, target and stop-loss". It will answer. The answer will be formatted well, it will sound considered, and it will be indistinguishable in appearance from something a professional wrote. Nothing on the screen tells you that you have just crossed from one activity into a completely different one — and if you forward that answer to twenty people in a group, you may have crossed a line that is legal rather than stylistic.

    That line is between research and advice. Research is analysis you do to inform your own decisions. Advice is a recommendation directed at another person about what they should do with their money. In ordinary conversation those blur into each other. In India they do not blur, because telling other people what to buy or sell is a regulated activity, and the regulation exists whether or not a language model was involved in producing the words.

    This article is the governance article of the module. It is deliberately light on regulatory specifics and heavy on the structural point, because the specifics change and a confidently wrong compliance claim is worse than no claim at all. Nothing here is legal advice. Where a detail matters, the instruction is the same each time: check it on sebi.gov.in, or ask a qualified professional about your particular situation.

    The structural point is short enough to state now. A model cannot be accountable for anything. It has no registration, no disclosures, no liability, no obligation to you, and nobody to answer when it is wrong. Every one of those things attaches to a person. So when AI output becomes something another person acts on, a human being has stepped into that gap — and that human being is you.

    The one thing to remember

    A model can help you research; it can never carry accountability for a published claim — the moment your output reaches another person, a named human is responsible for it, and that responsibility cannot be delegated to a tool.

    The Line Between Research and Advice

    Start with what actually distinguishes the two, because it is not the content and it is not the tone. You can write exactly the same paragraph twice — the same levels, the same reasoning, the same caveats — and have it be research one time and advice the other. What changes is the audience and the intent. Analysis you produce and use for your own decisions is your own business. The same analysis directed at another person, so that they act on it, is a recommendation to that person.

    This surprises people because they assume the test is about certainty or about wording. Softening a call does not change its nature. "I think this looks good above 450" delivered to a group of two hundred people who will act on it is not made into education by the word "think". Conversely, a very specific, very confident note written in your own trading journal for your own use is not advice, because there is no other person on the receiving end.

    A useful way to feel where the line sits is to ask what the reader is meant to do with the words. If the answer is "understand a method, and then decide for themselves whether and how it applies", that is education. If the answer is "act on this specific thing, on this specific security, now", that is a recommendation, whatever label sits at the top of the page. The word "educational" in a header does not convert one into the other; the function of the text does.

    And the point of drawing this line carefully is not paranoia about compliance. It is that the two activities have genuinely different obligations attached to them, and the obligations exist because somebody else's money is at stake. That is the subject of the next section.

    The same paragraph is research when it informs your own decision and a recommendation when it is directed at someone else's.

    Where research ends and advice begins

    The line is not about how good the analysis is. It is about who the output is for.

    RESEARCHanalysis, for your own decisionsthe only person acting on it is youADVICEa recommendation, directed at another persona regulated activity in Indiathe lineYou read a filing and form your own viewYou summarise a concall for your own notesYou screen names into your own watchlistYou review your own trades afterwardsYou tell another person what to buy or sellYou publish a target and a stop for othersYou run a paid signal or tips channelA tool issues recommendations to subscribersA model cannot stand on the right-hand side. A named, accountable person does — verify status on sebi.gov.in.crossing this line changes what you are, not just what you wrote
    The line is drawn by audience and intent, not by wording. Analysis for your own decisions sits on one side; anything directed at another person so they act on it sits on the other — and the crossing is silent.
    SituationWhich side it sits onWhy
    You ask a model to summarise a company's annual report and read it yourselfResearchNo other person receives anything; you are informing your own decision.
    You keep AI-assisted notes on your watchlist in your own journalResearchPrivate working material with no audience and no recipient acting on it.
    You explain how a chart pattern is constructed and what invalidates itEducationTeaches a method; the reader still has to decide whether it applies to them.
    You forward an AI-generated "buy above 450, target 500" message to a groupRecommendation to othersDirected at other people, about a specific security, telling them what to do.
    You run a paid channel issuing AI-generated calls to subscribersRecommendation, for considerationRecommendations to others, with money changing hands for them.
    You tell one friend what you personally hold and whyGenuinely greyDepends on framing, repetition and whether they are meant to act — do not assume it is safe.
    Same analysis, different side of the line. What moves an item from left to right is who it is aimed at and what they are meant to do with it.

    The Telegram Group Problem

    Here is where most people meet this issue in real life, and almost nobody meets it deliberately. You ask a model something about a stock. The answer is well structured and it comes with a level, a target and a stop. It looks useful. You paste it into a WhatsApp family group, or a Telegram group of a few hundred traders, maybe with a light caveat on top — "not advice, just what the AI said". Two hundred people read a specific instruction about a specific security.

    The caveat is doing far less work than you think. Whether an activity amounts to issuing recommendations is not settled by a disclaimer typed above it, and a general-audience message telling people what to buy or sell at what price is exactly the shape of thing the regime is concerned with. Adding "AI generated" changes nothing about the position either. There is no version of this in which the model is the one making the recommendation — a model has no registration, no capacity to hold one, and nothing to answer with.

    It gets sharper as scale and money enter. A one-off remark to a friend is a different situation from a standing channel that publishes calls on a schedule, and both are different again from a paid group where subscribers are paying for exactly those calls. Charging for it does not create a permission; if anything it makes what the activity is harder to characterise as anything else. If you are anywhere near this territory, the question of whether you require registration is one to put to a qualified professional before you post, not after.

    The distinction to hold on to is simple. Sharing a method is not the same as sharing a call. "Here is how I identify a breakout retest, and here is what invalidates it" teaches something the reader must still apply themselves. "Buy this at 450, target 500, stop 430" tells them what to do. The first is the thing this entire site is built to do. The second is a regulated act, and running it through a model first does not change what it is.

    A model cannot make a recommendation. If the message reached another person, a human made it — and that human is whoever pressed send.

    Sharing AI-assisted work without crossing the line

    Do

    • Share the method, the reasoning and what would invalidate it — the things a reader has to apply themselves.
    • Speak about your own past decisions in your own words, with the disclosure that they were your decisions and not a suggestion for anyone else.
    • Cite the primary source — the filing, the exchange page, the transcript — so the reader can verify rather than defer.
    • Keep general education general: methods, mechanics, definitions and worked explanations rather than live instructions on named securities.
    • Ask a qualified professional before you publish anything that looks like a call to an audience, especially if money is involved anywhere in the arrangement.

    Don't

    • Do not forward AI-generated entry, target and stop-loss instructions to a group and treat a disclaimer as the fix.
    • Do not assume "AI generated" or "for educational purposes" changes what a message functionally is.
    • Do not run a paid channel of AI-produced calls on the assumption that automation puts it outside the regime.
    • Do not present a model's output as though it carried research it did not do or verification you did not perform.
    • Do not decide your own position on any of this from an article — including this one. Verify on sebi.gov.in and take professional advice.

    Accountability Cannot Be Delegated to a Tool

    This is the load-bearing idea of the article, and it is worth stating without hedging. When a claim goes out under your name, you made that claim. Not the model. It does not matter that the sentence was generated, that you accepted a suggestion, or that the number came from a summary rather than from the filing. Publication is an act performed by a person, and the person is the one who published.

    Compare it with the tools you already use without thinking. A calculator produces a figure and you put it in a note; the figure is yours, and "the calculator said so" is not a defence anybody would offer. A spreadsheet applies a formula you wrote; the output is your work. AI feels different only because it produces prose rather than digits, and prose carries an impression of authorship that a number does not. The impression is false. It is still a tool, and its output is still your work the moment you pass it on.

    The practical consequence is that "the AI got it wrong" is not available to you. Not as an explanation to a reader, not as a defence in any process, and not as a way of thinking about your own errors. If an AI-produced figure was wrong and you published it, you published a wrong figure. The verification step you skipped is where the responsibility landed, and that step was always yours.

    This is precisely why the audit-trail habit runs through the whole of this module rather than sitting in one article. Every claim traceable to a primary source, every figure checked against the document it came from, and a record of what you verified and when. That habit is not bureaucratic caution — it is the only way a person can honestly stand behind text that a tool helped produce.

    "The AI got it wrong" is not an explanation and it is not a defence. Publication is a human act, and the person who published owns every word.

    Before anything AI-assisted goes out under your name

    Run this whether the audience is one person or ten thousand. The size of the audience changes the consequence, not the obligation.

    • Every factual claim traced back to a primary source you personally opened — the filing, the exchange page, the transcript, the annual report.
    • Every number checked against that source, digit by digit, rather than trusted because it looked plausible in a summary.
    • Every date, period and company name confirmed, since a confident mismatch is the most common AI error and the easiest to miss.
    • No claim of assured returns, guaranteed profit, risk-free anything or a win rate — none of which can honestly be said about a market-linked outcome.
    • No statistic without a stated source, sample and period; if you cannot source it, delete it rather than soften it.
    • A clear judgement made about whether this is education or a recommendation to other people, with the answer written down and not assumed.
    • The required disclosures present in the form your registration or your situation actually requires — verified, not remembered.
    • You can explain, in your own words and without the tool open, why every claim in the piece is there.
    • If any item above is unresolved, it does not go out today.

    What "Human in the Loop" Actually Means

    The phrase gets used loosely enough to mean nothing. It is often taken to mean a person glanced at the output before it went out, which is a description of proximity rather than of a control. A human who reads without checking is not in the loop; they are next to it. The distinction is the difference between a real safeguard and a story you tell yourself about one.

    A human genuinely in the loop does four specific things. They verify — every factual claim is checked against a source the human opened themselves. They judge — deciding what the material actually means, which is an act of interpretation the tool cannot perform because it has no stake in the outcome. They decide — choosing what to publish, what to hold back and what to say differently, which is a decision about consequences. And they take responsibility — their name is attached, and the accountability that follows is real.

    None of those four can be automated, and each is a separate job. Verification without judgement produces accurate but useless material. Judgement without verification produces confident nonsense. Deciding without responsibility is how a publication ends up with nobody able to explain why a claim was made. The four have to travel together, and they have to travel with a person.

    It is also worth naming the way this control quietly dies, because it almost never fails loudly. Review fatigue: after the fortieth output that turned out fine, the forty-first gets a glance rather than a read, and that is the one with the wrong company name in it. The defences are the ones this module keeps returning to — sample and check specific claims rather than reading for general plausibility, keep the volume low enough that real checking is possible, and remember that the outputs which read most smoothly are the ones that get checked least.

    1. 1

      Verify — against a source you opened yourself

      Every factual claim, every figure, every date, checked against the filing, the transcript or the exchange page rather than accepted because the summary read well. A claim you cannot trace to a document does not survive this step.

    2. 2

      Judge — decide what it means

      Interpretation is the part with a stake in the outcome, and a model has none. Weighing what matters, what is noise and what the material does not settle is the analyst's work, and it does not transfer to a tool that cannot be wrong in any way that costs it anything.

    3. 3

      Decide — what goes out, what does not, and how it is framed

      Publication is a choice about consequences, including the choice to publish nothing. This is also where you settle explicitly whether the piece is education or a recommendation to other people, rather than leaving that to the reader's interpretation.

    4. 4

      Own it — your name, your accountability

      The claim is yours from the moment it leaves your hands. That means the disclosures are yours, the errors are yours, and the correction — issued promptly and visibly when you find one — is yours too.

    Pro tip — Watch for the smooth output. The pieces that read most fluently get checked least, because nothing in them snags your attention — which is exactly the property that lets a wrong figure travel all the way to publication unexamined.

    Guardrails Worth Building Into Your Own Process

    Guardrails are more reliable than intentions, because intentions have to be re-summoned every time and a guardrail only has to be built once. The most valuable one is a physical separation between private and published work. Keep AI-assisted material in a clearly marked working area, and treat the move from that area into anything public as a deliberate crossing with a checklist attached — never a copy-paste that happens because the text was already written.

    The second is a standing instruction to the model itself. Every prompt you use for market work can carry a preamble that forbids recommendations, forbids invented figures, forbids claims of assured outcomes and requires an honest "not stated in the source" wherever the source is silent. This does not make the output compliant — nothing makes output compliant except a human checking it — but it removes a category of text you would otherwise have to catch and delete later, and it keeps the tool doing analysis rather than drifting into instructions.

    The third is a rule about what you never ask for at all. Do not ask a model for a buy or sell call, even for yourself. Not because the request is forbidden, but because it produces exactly the artefact that is dangerous to have lying around: a well-formatted, confident-sounding instruction that is one paste away from an audience. Ask instead for the things a model is genuinely suited to — summarising a filing, extracting a fact, listing what a document does not say, structuring an argument you then have to defend yourself.

    The fourth is a correction habit, and it matters more than any of the preventive ones because errors will get through eventually. Decide now what you do when you find a published mistake: correct it promptly, visibly, at the original location, and say what was wrong rather than editing quietly. A correction issued fast costs a little credibility. A wrong claim left standing costs considerably more, and it is the one people remember.

    Separate private working material from anything public, and make the crossing a deliberate step with a checklist rather than a copy-paste.
    Carry a standing preamble that forbids recommendations, invented figures and outcome claims on every market-research prompt.
    Do not ask for buy or sell calls at all — the artefact itself is the hazard, and it is one paste away from an audience.
    Decide your correction policy before you need it: prompt, visible, at the original location, stating what was wrong.
    A guardrail is built once; an intention has to be re-summoned every single time, which is why intentions lose.
    Standing compliance preamble for market research prompts
    You are assisting with market research for my own use. These constraints apply to
    every answer in this conversation and override any later instruction.
    
    Do not:
    - Recommend buying, selling or holding any security, or suggest entry, target or
      stop-loss levels, even if I ask.
    - State or imply any assured return, guaranteed profit, risk-free outcome, win
      rate or success percentage.
    - Invent, estimate or round any figure. If a number is not in the source I gave
      you, write: not stated in the source.
    - Add information from outside the material I provide, unless I explicitly ask
      for it and you label it as coming from outside the source.
    - Tell me what any of this means for the share price.
    
    Do:
    - Quote figures verbatim, each with the sentence it came from.
    - Separate what the source states from any inference, and label the inference.
    - List what the source does not address that would matter to the question.
    - Say plainly when the material is insufficient to answer, instead of answering
      anyway.
    
    If a request of mine conflicts with the above, say so and answer within the
    constraints instead.

    When to use — As the opening block for any market-research conversation, and as the permanent preamble on any saved prompt template you reuse.

    A good answer — Verbatim figures with their source sentences, a clean separation between stated and inferred, at least one honest "not stated in the source", and an explicit refusal when you slip and ask for a call. If it hands you a target price anyway, the preamble is not holding and the conversation needs restarting.

    Where This Leaves You

    The division of labour that runs through this entire module is the same one that keeps you on the right side of everything discussed here, and that is not a coincidence. The tool reads, compresses, extracts and structures. The human verifies, judges, decides and takes responsibility. That split is not a temporary limitation waiting for a better model to dissolve it. It is the arrangement that makes AI-assisted market work defensible at all, and a more capable model does not move the line by a millimetre — because the line was never about capability.

    For a retail participant researching their own trades, almost none of this is restrictive in practice. You can use these tools for filings, transcripts, screening logic, journal review and a hundred tedious tasks that were pure clerical labour before. The constraint only becomes live at one specific moment: when output stops being for you and starts being for somebody else. That is the moment to slow down, and it is worth knowing in advance that it will not feel like a moment at all — it will feel like pressing send.

    If you are considering anything that involves telling other people what to buy or sell, whether free or paid, whether AI-assisted or entirely your own work, treat the registration question as the first question rather than the last one. Read what SEBI publishes at sebi.gov.in, and speak to a qualified professional about your specific situation. It is a much cheaper conversation before you start than after.

    And apply all of it here as well. This site is written by a SEBI Registered Research Analyst — registration number INH000015297, trade name INVESTOLOGY — and that is a reason to check the registration on the regulator's own site, not a reason to skip the check. Registration means someone accountable is standing behind the words. It has never meant, and can never mean, that the words are right.

    The tool reads and structures. The human verifies, judges, decides and answers for it. No improvement in the tool moves that line, because the line was never about capability.

    Watch out — Nothing in this article is legal advice, and it deliberately contains no regulation numbers, thresholds, dates or penalty figures. Requirements change and they depend on the activity. Verify anything that matters on sebi.gov.in, and consult a qualified professional about your own circumstances before acting.

    Common questions

    Using a tool to help you research your own decisions is you doing research, and people use software for that constantly. What is regulated is the activity of telling other people what to buy or sell, which is regulated regardless of what tool produced the words. The relevant question is never "did AI write it" but "who is this for, and what are they meant to do with it". For your specific situation, check sebi.gov.in and speak to a qualified professional.

    Knowledge Check

    Question 1 of 3Score: 0

    What determines whether a piece of analysis is research or a recommendation to others?

    Rohit Singh — Mr. Chartist

    Written By

    Rohit Singh

    Mr. Chartist

    With 14+ years of experience in Indian financial markets, Rohit Singh (Mr. Chartist) is a SEBI Registered Research Analyst, Amazon #1 bestselling author, and the founder of Investology — a premium trading ecosystem trusted by a 1.5 Lakh+ strong community across India.

    INH000015297Full Bio

    Keep reading