Truth API: US and UK compliance
For a US-only desk, Truth Social’s new paid API looks like a latency play. For a desk with UK exposure, that framing is risky. A US trader facing the insider trading question can hang his hat on two independent defenses. A UK trader gets one, and it’s the harder one to prove.
The Product
Truth API delivers posts from prominent Truth Social accounts to paying customers in milliseconds, reportedly priced at $60,000–$100,000 a month, marketed to HFT and algorithmic desks. Trump’s posts in particular are well-established to be market-moving. Say Trump posts at 12:00:00.000; the public site shows it at 12:00:00.005; the API delivers it at 12:00:00.010: this is a latency advantage, not necessarily an exclusivity advantage.
Context in the US Market
Truth API is not the first potentially market-moving API released by a media company. X and Reddit have offered (arguably) similar data feeds for years. And while not disclosed via API, in 2024, the Bureau of Labor Statistics shared non-public data on inflation calculations with Wall Street “super users.” But Truth API is unusual in that the company is owned by the same individual making the potentially market-moving posts (which generate company revenue), and who happens to be the president.
The US: Two Ways Out
US law is built around property: was the information non-public and did using it breach a duty owed to whoever it belonged to. That structure hands a trader two separate defenses, either one sufficient on its own.
Defense one: it was already public. If the post went live on Truth Social’s site before the API delivered it, the customer received the same information everyone else could see, just faster. Timing alone can carry the day.
Defense two: even if it wasn’t public, no duty attached. Under the misappropriation theory, liability requires a breach of a duty of trust or confidence. The Securities and Exchange Commission’s Rule 10b5-2 spells out the relationships that create one. A hedge fund that’s simply a paying API subscriber, with no other tie to Trump or TMTG, likely owes no such duty. That’s why “we just paid for lower latency” has real legal footing, much like co-location fees or direct feeds versus the SIP. Even in the API-first scenario, a trader can win by showing no relationship of trust existed. Time will tell whether compliance teams find themselves reconstructing when a post appeared in the API versus on the website, but until they do, they have a second line of defense behind the first.
The UK: One Way Out, and It’s the Hard One
The UK’s Market Abuse Regulation (MAR) prohibits dealing, attempting to deal, or inducing another to deal while possessing inside information. It does not ask how the information was obtained or what relationship of trust existed. Defense two, the duty-based one, doesn't exist under UK law at all. A UK trader relying on Truth API is left with exactly one argument: the information was already public when they traded.
The 2016 Mark Taylor case shows why the duty-based defense is a non-starter in the UK. A financial adviser received a merger-price update by internal email sent to him by mistake, followed by an email telling all staff not to act on it. He ignored that instruction and traded anyway and was fined and banned for it. But the instruction he disobeyed isn’t what made him liable. He owed no duty of confidence to the merger parties or their counterparty and had no relationship to the source beyond having accidentally received it. Under the US framework, an absence of duty would have been at least a compelling argument. Under MAR, it was irrelevant. Possession plus use was enough on its own.
That leaves the “it was already public” defense to do all the work, and it could be harder to make out than it sounds. It isn’t enough to believe the public post came first; UK enforcement runs on reconstruction, not assurances. It wants timestamps and logs showing, to the millisecond, that the website update preceded every trade. For a product whose entire value proposition is shaving milliseconds off delivery, that’s exactly the record most firms won’t have. A UK trader who can't produce it is left arguing possession and use on the FCA’s terms, with no fallback.
The Takeaway for Global Compliance
A single API event can produce two very different postures. A US trader who loses the timing argument can still win on duty. A UK trader who loses the timing argument has nothing left. Diligence should reflect that asymmetry: for UK-facing traders, the only thing standing between “lawful subscriber” and “market abuse” is a millisecond-level record of when each post went public. Compliance teams should focus on getting proper assurances from Truth Social regarding the timing of the API. They should also consider building that timing record now, instead of after the FCA comes knocking.
©2026 Glacier Network LLC d/b/a Glacier Risk (“Glacier”). This post has been prepared by Glacier for informational purposes and is not legal, tax, or investment advice. This post is not intended to create, and receipt of it does not constitute, a lawyer-client relationship.