AI & Banking
Know Your Agent: The New Verification Step Between Customer, AI Agent and Bank
Ant, Mastercard and Visa are building a know-your-agent framework. Why KYC is not enough for AI agents and what banks should take from it for mandates.
•
acceleraid Redaktion
8 min read

For decades, payments followed a simple order. A person wants to pay, the bank checks who that person is and releases the transaction. "Know your customer" was the mandatory exercise around which compliance departments, fraud systems and authentication methods were built. That order is now getting a second layer. Increasingly, it is not the customer who wants to pay but an AI agent acting on their behalf: it compares, selects, negotiates and finally triggers the payment.
Zhuoqun Bian, president of Ant Digital Technologies, summed up the shift at the Fortune Leaders Forum in Macau on 8 September 2026: "In the agent economy, you need to know your agents. Who's the agent? Who does it belong to? Who authorized it?" Her conclusion, as quoted by Fortune, was that banks will need to know their agents much more than they know their customers. The term is already set: know your agent, or KYA.
The scale explains the urgency. McKinsey estimates that AI agents could orchestrate 3 to 5 trillion US dollars of global consumer commerce by 2030, the figure Ant International cites in its announcement (PR Newswire via Yahoo Finance). This article looks at what has been on the table since 10 September, why existing checks fall short and what banks should take from it for their customer relationships.
What was agreed on 10 September
Ant International, Mastercard and Visa announced that they have begun developing an interoperable KYA framework. The goal is for card networks, digital wallets, agent platforms and marketplaces to recognise trusted AI agents across the boundaries of their respective ecosystems (Reuters). Each participant keeps its own approval and risk-management processes. The work runs through BuildFin.ai, a platform convened by the Monetary Authority of Singapore for AI solutions in financial services.
The framework brings together three existing approaches: Visa's Trusted Agent Protocol, Mastercard's Verifiable Intent and Ant International's Agentic Mobile Protocol. According to the companies' announcement, the KYA architecture rests on three building blocks:
Cross-network operator traceability: Every agent is linked to a validated operator, cardholder or business, so that its activity can be attributed unambiguously.
Shared certification requirements: Every agent is assessed against security and behavioural requirements before it counts as trusted.
Continuous transaction monitoring: Every agent is evaluated on an ongoing basis using identity and transaction signals; certification is not a one-off event.

For banks, the third point matters most. An agent that is trusted today may be compromised or behave differently tomorrow. Verification does not end at registration; it accompanies every transaction.
Why know your customer is not enough
The International Monetary Fund described the problem back in April 2026 (IMF Note 2026/004). Its core point: KYC procedures, multi-factor authentication, anti-money-laundering and fraud controls are designed around human users. When an agent acts, two things must be verified that used to coincide: the identity of the agent and the authority delegated by the customer.
There is also a fundamental conflict. AI agents are probabilistic: the same instruction can lead to different outcomes. Payment systems, by contrast, must return the same result every time. The IMF authors put it this way: "Payment rails, from card networks to real-time gross settlement (RTGS) systems, rely on predictable rules, legal certainty, and clear accountability structures to ensure trust and financial stability." Anyone connecting a probabilistic actor to deterministic infrastructure needs a layer in between that cleanly separates decision from execution.
Three layers: where the agent decides and where it does not
That separation is exactly what the IMF proposes as an organising framework. The analysis distinguishes three layers:
Intent and orchestration: The agent interprets a goal, plans, searches, compares, negotiates and translates the result into a structured instruction. This layer authorises nothing and executes nothing.
Control and authorisation: Deterministic rules decide whether a proposed action may proceed. Cryptographically verifiable mandates specify scope, limits, identity and conditions; spending limits, velocity controls, sanctions screening and dispute guardrails are added on top.
Settlement: Card clearing, instant payments and other infrastructures execute authorised instructions with legal finality. Agents have no business here.

The IMF describes the transition as a move from "click-to-pay" to "decide-to-pay": the payment is no longer triggered by the customer's individual click but by a pre-granted, bounded mandate within which the agent decides. Know your agent belongs in the second layer. That is where it is checked whether the agent is who it claims to be, whether a valid mandate exists and whether the specific action stays within its limits.
What is already live in Europe
None of this is distant. On 2 July 2026, at the Visa Payments Forum in Paris, Visa reported that AI agents in Europe are already completing purchases in live environments: they browse assortments, select products and initiate payments that consumers have explicitly authorised and that stay within defined parameters. More than 30 European issuers are involved, including Commerzbank, comdirect, Deutsche Kreditbank, ING, BBVA, Barclays, Nordea and Revolut, within the European requirements for strong customer authentication (Visa). Mastercard takes a comparable approach with Agent Pay: agentic tokens tie an agent uniquely to an individual user and protect payment credentials, so transactions can proceed without constant user involvement (Mastercard).
We described what the first production cases with Visa, BBVA and Lianlian looked like in our August article on agentic commerce. What is new since 10 September is that the three largest network operators want to merge their previously separate trust signals. For banks as issuers, this means the question is no longer whether to admit agents. The question is under which rules.
The open question: who is liable?
The biggest unresolved point is liability. Existing rules assume human intent and direct causation. When a payment is spread across account holder, agent, payment service provider, platform, model provider and system operator, the IMF finds it unclear who answers for misconduct and whether it counts as unauthorised use or user negligence.
Benson Wong, who heads digital at JPMorgan Private Bank, shifts the focus from technology to organisation. He has never come across a case in which the agent technology itself led to an undesirable outcome, he told Fortune; the problems have centred on "the operating model, the processes, and the compliance and the controls." And the consequences scale with autonomy: if an agent answers an information question wrongly, that is embarrassing. If an agentic workflow goes wrong, the impact is vastly larger.
The IMF derives concrete recommendations from this: strictly separate the agent's decisions from authorisation and settlement, use mandates with bounded scope and cryptographic proof, keep agent registries and complete logs, require human approval for high-value or high-risk transactions, and provide graduated kill switches that do not depend on a single point. Payment networks should also develop dispute and liability rules for agents, and supervisors their own KYA frameworks and real-time monitoring.
That matches what we set out in our article on the AI security control plane: a kill switch is necessary, but the real work lies in mandates, limits, logs and escalation paths that are fixed before the first deployment.
What this means for the customer relationship
Know your agent sounds like compliance. In fact, the customer relationship is decided here too. In August 2026, Deloitte surveyed almost 2,600 banking customers in the United States: 83 percent would feel anxious about an AI agent taking action on their finances without their approval, and 66 percent believe the risk of agent errors outweighs the benefits (Deloitte). Customers do not want to prevent agents; they want to control them.
That turns the mandate that the KYA framework verifies technically into a customer experience. A bank that shows its customers which agents act in their name, what scope and limits they have, which actions require confirmation and how a mandate is revoked converts an obligation into an offering. The parallel to the four questions we set out for Danske Bank's MCP pilot is no coincidence: scope of permission, acting party, confirmation step and usage signals are the same questions, this time for payments.
The difference between the familiar check and the new one fits in one overview:
Question | Know your customer | Know your agent |
|---|---|---|
Who acts? | A natural or legal person | An agent and the operator behind it |
On whose behalf? | Their own | A principal who must be verified and linked |
What is allowed? | What the account agreement and authentication permit | What a mandate with scope, limits and conditions permits |
When is it checked? | At onboarding and periodically | At registration and at every transaction |
Who is liable? | Largely settled | Open between customer, operator, bank, platform and model provider |

Two consequences follow for how banks manage customers. First, every agent mandate creates a new data trail: which agents does a customer use, for what, with what scope, with which aborted attempts? Those signals belong in the same decision logic that today evaluates channel preferences and product usage. Second, the point of contact shifts. When the agent handles the comparison, the bank reaches the customer less through offers and more through the quality of its mandate and confirmation processes. Whoever is clear and fast here stays in the consideration set of both the agent and the customer.
Five takeaways
Since 10 September 2026, Ant International, Mastercard and Visa have been developing a shared know-your-agent framework with three building blocks: operator traceability, shared certification and continuous transaction monitoring.
KYC procedures are designed for humans. With agents, the agent's identity and the customer's delegated authority must be verified separately.
The IMF separates three layers: probabilistic intent, deterministic authorisation via mandates, deterministic settlement. KYA belongs in the middle layer.
In Europe, live agent payments are already running with more than 30 issuers under strong customer authentication requirements. The liability question, by contrast, remains unresolved.
83 percent of banking customers do not want agents to act without approval. Mandate scope, confirmation steps and revocation therefore become a customer experience, not just a control obligation.
The three networks' framework is a statement of intent, not a finished standard. For banks, this is the cheapest moment to define their own requirements for mandates, evidence and customer transparency before they are dictated from outside.
Illustration: AI-generated. AI-assisted content: We use AI technologies and automated agents in the creation of our articles, including from Microsoft, Google, OpenAI, Anthropic and other providers. Topics, editorial direction and final approval remain with our team.