Research note · Temporal Market Structure Observatory v0.1

The Market Never Sleeps. The Protection Stack Must Not Either.

Twenty-three-hour equity trading is becoming an operating system, not a slogan. The public question is no longer only whether investors can trade overnight. It is whether every hour receives measurable execution quality, complete market data, clearing assurance, supervision, and recoverability.

July 24, 2026 Zeyuan Li (Amy Li) Founder & Independent Researcher, W-Axis Lab Methodology v0.1

The migration has entered implementation. On July 23, the U.S. Securities and Exchange Commission announced a September 17 roundtable on preparations for 24-hour trading. One month earlier, the Commission approved extended operating hours for the CTA/CQ and UTP securities information processors, with extended operation planned to begin December 6, 2026. The approved schedule begins at 9:00 p.m. Eastern on Sunday, runs through 8:00 p.m. Friday, and preserves a one-hour technical pause from 8:00 to 9:00 p.m. Monday through Thursday.

The National Securities Clearing Corporation has also received approval to support extended trade capture and clearing. Nasdaq, NYSE Arca, Cboe EDGX, 24X, and existing overnight alternative trading systems are moving different pieces of the market toward a common destination.

But an extended clock is not the same thing as an extended protection stack. The current Limit Up-Limit Down Plan applies during regular trading hours. Public execution-quality reporting is only now being modernized. The Consolidated Audit Trail records order lifecycles but does not identify whether legally separate firms depend on the same AI model, data source, or risk module.

The Temporal Market Structure Observatory begins with a narrower promise: measure the market hour by hour, distinguish structural weakness from episodic shock, and make readiness a testable condition rather than a calendar date.

Measurement architecture

Eight metrics for one continuous market

The base observation unit is one security over a 15-minute interval, aggregated to an hourly public view. Each result should be shown both equally weighted across securities and weighted by trading value, so a few liquid mega-cap stocks cannot hide tail risk elsewhere.

Benchmark A

Protection parity

Compare each hour with the same security's prior 20-day median from 10:00 a.m. to 3:30 p.m. ET. This asks whether overnight protection approaches a stable daytime reference.

Benchmark B

Same-hour shock

Compare each interval with the same clock hour over the prior 20 comparable days. This asks whether tonight is abnormal relative to its own temporal regime.

Data label

Never hide the source

Every value should be marked public, proprietary, regulator-only, firm-reported, or proxy. A missing measurement must appear as missing—not as zero.

01 · Publicly derivable

Time-weighted relative quoted spread

10,000 × Σ[Δt × (ask − bid) / midpoint] / ΣΔt

Calculate only when a valid two-sided quote exists. Pair it with effective spread at execution. Consolidated NBBO and a venue's local BBO must be labeled separately, especially before the extended SIP schedule becomes operative.

02 · Full-depth required

Minimum-side executable depth

MSED-10bp = median[min(bid depth, ask depth)]

Sum displayed dollar depth within ten basis points of midpoint on each side, then take the smaller side. The measure penalizes a book that looks deep in aggregate but is dangerously one-sided.

03 · Firm or regulator data

Route rejection rate

rejected route events / all route events

Publish count- and notional-weighted rates by cause: venue availability, price controls, credit limits, duplicate orders, technical errors, and stale security state. Non-execution is not a valid substitute for rejection.

04 · Mixed public data

Halts and erroneous-trade incidents

non-news pauses / 1,000 symbol-hours

busted or corrected executions / 1,000,000 executions

Report the components separately. Exclude issuer-news and investigative halts, and distinguish regular-hours LULD events from overnight venue-specific controls.

05 · Proposed shared measure

Reference-data freshness

Σ I[local version ≠ authoritative version] × Δt / ΣΔt

Measure both propagation latency and the share of system-time spent on an obsolete version of a symbol, split, dividend, minimum price increment, trading state, or other corporate action.

06 · Router-specific

Executable venue coverage

reachable valid depth / all valid market depth

A customer may see a quote without having a route to it. Weight coverage by executable depth, require a fresh quote, and publish sensitivity at 250 milliseconds, one second, and five seconds.

07 · Member or regulator data

Execution-to-clearing guarantee latency

p50 and p95(NSCC acceptance − execution)

This is not T+1 settlement time. It measures how long an executed trade remains between venue execution and NSCC validation and guarantee. Also report the share still unaccepted after 60 seconds.

08 · Proposed, not currently public

AI order-flow concentration and synchrony

AOCI = 100 × AI share × (0.5 family concentration + 0.5 synchrony)

Group automated flow by a confidential controller-family identifier that reflects common model, version, execution policy, data source, or risk module—not merely by broker or MPID. Report the three components beside the composite.

The hidden control layer

Why AI concentration is not a market-share statistic

Five legally independent firms can still behave like one actor if they share the same model, signal vendor, cloud dependency, or portfolio-risk module.

The proposed AI Order-Flow Concentration and Synchrony Index has three parts. AI share measures how much gross order-event activity is attributable to automated or AI controllers. Family concentration is a normalized HHI across confidential controller-family identifiers. Synchrony measures positive correlation in signed order-book pressure across active families using one-second buckets over a rolling five-minute window.

An event overlay—CWO-1s—asks what share of visible depth was withdrawn inside one second by at least three controller families. This distinguishes one large participant from a common-mode withdrawal across firms.

CAT currently provides the underlying order lifecycle but not the AI/controller-family label. Until a protected crosswalk exists, a public calculation based on MPIDs is only a behavioral synchrony proxy. It must not be described as measured AI activity.

The purpose is measurement, not presumption. BIS Project Logos and Federal Reserve research both treat correlated AI behavior as an empirical question that may be amplified or dampened by model diversity, incentives, and market controls.

Stress test · Simulation only

02:14 ET: a correlated-cancellation vacuum

Fictional scenario No real security, firm, venue, model provider, or market incident is described below.

All times, percentages, spreads, scores, and market reactions in this section are hypothetical values constructed to test the Observatory's measurement and control design.

02:14:00–02:14:01

The common signal

A widely used data service revises an overseas index value. Five controller families at separate firms interpret the update as higher risk. Within 700 milliseconds they withdraw 64% of displayed depth within ten basis points across four venues.

02:14:01–02:14:03

The liquidity vacuum

In this simulation, spread widens from 9 to 92 basis points, AOCI rises from 18 to 74, and CWO-1s reaches 61%. A marketable limit order sweeps the thin book and moves the hypothetical price by 3.8%.

02:14:03–02:15:00

The feedback loop

Other agents read the price jump as new information, cancel additional quotes, and send risk-reducing sell orders. Rejections rise as venue and broker price controls engage. No single firm breaches its credit limit, so firm-by-firm monitoring misses the common-mode event.

02:16–02:22

Containment and recovery

Participants enter a hypothetical constrained state: limit orders only, smaller size, independent price references, and no new risk-increasing flow. The affected controller versions are quarantined, NSCC acceptance is checked, and a staged coordinated reopening follows.

Prevent

Map common dependencies

  • Controller, model, data, cloud, and risk-module registry
  • Cross-model common-failure stress tests
  • Overnight-depth calibration of pre-trade controls
  • Independent reference data and 24×5 supervision

Detect

Observe the market, not one firm

  • AOCI and one-second cancellation withdrawal
  • Minimum-side depth and quoted spread
  • Venue coverage and reference freshness
  • Cross-port and cross-venue message aggregation

Contain

Use graduated safe states

  • Normal → constrained → reduce-only → coordinated pause
  • Preserve legitimate cancellation rights
  • Block new risk before trapping stale quotes
  • Use an unaffected reference for volatility controls

Recover

Reconstruct and publish

  • CAT lifecycle reconstruction
  • NSCC acceptance and guarantee reconciliation
  • Version quarantine and staged reopening
  • Public scorecard without exposing trading strategy

Do not

Avoid blunt cancel throttles

  • Do not force market makers to remain on stale quotes
  • Do not route around a pause into another weak venue
  • Do not treat missing data as a healthy zero
  • Do not call an MPID proxy measured AI behavior

Existing foundation

Extend current controls

  • Rule 15c3-5 market-access controls
  • FINRA supervision and best-execution reviews
  • Regulation SCI resilience and incident processes
  • CAT, SIP, NSCC, and venue event records

Institutional map

Twenty nodes, one protection stack

The map is functional, not a claim that each category is one legal entity. Its purpose is to identify who owns authoritative data, who controls an order, who approves a rule, who responds first to an incident, and who can explain the result to the public.

Rules, supervision, audit

Nodes 1–4

  1. SEC, including Trading and Markets and DERA/MIDAS
  2. FINRA, including TRFs and member supervision
  3. CAT NMS Plan / CAT LLC
  4. LULD Plan Operating Committee

Consolidated data

Nodes 5–7

  1. CTA/CQ SIP for Tapes A and B
  2. UTP SIP for Tape C
  3. DTCC enterprise and Data Services

Post-trade

Nodes 8–9

  1. NSCC for capture, validation, netting, and guarantee
  2. DTC for settlement, custody, and asset servicing

Trading venues

Nodes 10–15

  1. NYSE Group / NYSE Arca
  2. Nasdaq Stock Market
  3. Cboe equities / EDGX
  4. IEX
  5. 24X National Exchange
  6. Overnight ATS cluster, including Blue Ocean, MOON, and Bruce

Execution and public voice

Nodes 16–20

  1. Retail introducing brokers and routers
  2. Carrying, clearing, and market-access brokers
  3. Market makers and wholesalers
  4. SIFMA and its implementation working groups
  5. Investor and public-interest organizations

End-to-end path

Follow the responsibility chain

Customer → retail broker → market-access broker → exchange, ATS, or wholesaler → SIP and CAT → NSCC → DTC.

Rules, surveillance, industry coordination, and public-interest review must cover the entire chain rather than one visible interface.

Governance

Readiness should be earned hour by hour

A date can launch infrastructure. It cannot prove that every new hour is ready.

The Observatory proposes evidence-based readiness gates. Before an additional interval becomes generally available, its market-data completeness, executable depth, venue reachability, reference-data freshness, rejection rate, clearing latency, supervisory coverage, and recovery drills should remain within prospectively defined bands.

Version 0.1 does not prescribe universal thresholds before a baseline exists. Thresholds should be calibrated using at least 20 comparable sessions, published before they are applied, tested under simulated common-mode withdrawal, and evaluated separately for liquid and less-liquid securities.

Core protections should use a weakest-link rule: an excellent average spread cannot compensate for incomplete venue coverage or stale corporate-action data. Persistent failure should trigger remediation, a narrower eligible-security set, reduced hours, or rollback. Expansion should create a reversible operating permission, not an irreversible assumption of readiness.

Contribution 01

Dual temporal benchmarking

Separate the long-run protection gap from the tonight-specific shock. A single benchmark either normalizes chronic weakness or misclassifies every overnight difference as an incident.

Contribution 02

Minimum-side executable depth

Measure the thinner side of the book rather than relying on volume, aggregate depth, or a displayed best price that may support almost no executable size.

Contribution 03

Controller-family concentration

Move systemic analysis below the legal-entity layer to shared models, data, risk modules, and vendors—the hidden infrastructure that can synchronize independent firms.

Contribution 04

Evidence-based readiness gates

Turn extended-hours approval into a continuing, measurable, and reversible qualification instead of treating an implementation date as proof of protection parity.

These are proposed public operationalizations. W-Axis Lab does not claim that no prior researcher has advanced a related concept; the contribution is to assemble them into one auditable temporal protection framework.

Primary sources and methodology anchors

Evidence behind v0.1

Public record

Measure the hours we are adding—not only the access we are promising.