
Summary
Visa, Mastercard and Ant International are working on a shared Know-Your-Agent framework to identify, certify and monitor AI agents that make purchases or payment decisions on behalf of users.
Why AI agents create a new payments identity problem
Visa, Mastercard and Ant International have begun working on a shared Know-Your-Agent, or KYA, framework for artificial intelligence agents that make purchases on behalf of users. The initiative is intended to help card networks, digital wallets, agent platforms and marketplaces identify and onboard agents across networks.
The announcement addresses a problem that is becoming more important as payment systems move beyond direct human interaction. In a conventional card transaction, the main actors are relatively familiar: a cardholder, an issuer, an acquirer, a merchant and the relevant payment network. An AI agent introduces another layer. The software may interpret a user’s request, select a service, interact with a merchant and initiate a payment without the user manually completing every step.
That creates questions that ordinary customer or account identification does not fully answer. Who operates the agent? Which person, company or account holder does it represent? What authority was it given? Did it act within that authority? If the agent makes a mistake or is manipulated, which participant is responsible?
KYA treats the agent as a separately identifiable participant in the payment process rather than merely an automated interface connected to an existing account.
Three proposed layers of control
The companies identified three areas of work for the framework.
The first is operator traceability across networks. Each agent would be linked to a validated operator, cardholder or business. This linkage could give payment participants a clearer record of who stands behind an agent and make it easier to investigate disputes or suspicious activity. However, traceability alone does not prove that a particular action was properly authorized. A system still needs to determine whether the agent stayed within its assigned permissions and whether the user understood the scope of those permissions.
The second area is shared certification. Under the proposal, agents would be assessed against security and behavioral requirements. Security criteria could relate to the way an agent is operated, how its credentials are protected and how it connects to payment infrastructure. Behavioral criteria would address whether it acts for its stated purpose and follows its assigned limits.
The details remain open. Different platforms may define an agent’s capabilities, data access and degree of autonomy in different ways. A certification that is meaningful for a shopping assistant may not be sufficient for an agent that can interact with several financial or commercial services. The eventual framework will therefore need to distinguish between identity, technical security, delegated authority and the risk of a particular action.
The third area is continuous monitoring. Rather than treating onboarding as a one-time approval, the companies said they would explore monitoring agents through identity and transaction signals. This reflects the fact that an agent may operate over time, call external tools and interact with multiple services.
Continuous monitoring also introduces its own governance questions. Payment networks will need to consider which signals can be shared, how false positives are managed and how monitoring can be conducted without creating unnecessary exposure of personal or commercially sensitive information.
Common principles, not yet a single protocol
Visa, Mastercard and Ant International already have their own protocols for agent payments: Visa’s Trusted Agent Protocol, Mastercard Verifiable Intent and Ant International’s Agentic Mobile Protocol. The new collaboration is not described as an immediate replacement of those systems. Instead, the companies said they would explore ways to work toward common principles.
That distinction matters. An AI agent may need to move among payment networks, wallets, merchant platforms and agent service providers. If each participant uses a completely different identity format, authorization model and risk signal, cross-network activity may require repeated checks or fail altogether. On the other hand, unrestricted data sharing could increase privacy risks and magnify the effect of an error in one system.
A shared framework is therefore more likely, at least initially, to consist of interoperable principles, certification requirements and methods for exchanging selected information. It does not necessarily mean that the three companies will operate a single shared database. The source announcement states that each network will keep its own verification and decision-making processes. Interoperability, in other words, is not the same as centralized decision-making.
Singapore provides a regulatory and operational setting
The work will run through BuildFin.ai, a platform convened by the Monetary Authority of Singapore. It builds on the regulator’s Safeguards for Agentic Finance at Runtime, or SAFR, framework and covers payment ecosystems in Singapore.
A regulator-convened setting gives the initiative an opportunity to move beyond a purely conceptual discussion. The risks created by autonomous or semi-autonomous agents do not arise only when an agent is first registered. They can emerge while a task is being executed. An agent might encounter manipulated web content, an instruction designed to override the user’s intent, a service that requests excessive permissions or a series of actions that becomes materially different from the original request.
Runtime safeguards therefore need to address how an agent interprets authority, confirms intent, handles exceptions and records its decisions. They also need to define when an action should be paused or escalated for additional review.
The information released so far does not specify the technical standards that will be adopted, nor does it provide a timetable for implementation. Results from a Singapore-focused payment ecosystem may not transfer directly to other jurisdictions. Rules on data protection, consumer responsibility, electronic identification and payment authorization vary significantly across markets.
Implications for wallets and institutional infrastructure
For digital wallets, institutional custody providers and other payment infrastructure operators, agent identity could become an additional control layer alongside customer due diligence and transaction monitoring. Systems may need to distinguish among the account holder, the agent operator, a specific agent instance and the merchant receiving payment. They may also need to retain records of an agent’s permissions, certification status and execution history.
That does not automatically mean a wallet or custodian would be responsible for every decision made by an agent. Rather, the initiative highlights the need to define responsibility among users, developers, operators, wallets and payment networks. Practical questions could include how agent credentials are isolated and rotated, when an action requires additional confirmation, how long execution records should be retained and how relevant information can be exchanged during a dispute without unnecessarily exposing sensitive data.
Standardized identity and permission formats could reduce integration friction if agents eventually operate across several networks. But standardization would not remove the need for institution-specific controls. An agent’s certification would not, by itself, demonstrate that every action is appropriate or compliant with a wallet operator’s policies, customer relationship, geographic restrictions or risk framework.
The opportunity and the unresolved risks
The announcement cites a McKinsey projection that AI agents could orchestrate between $3 trillion and $5 trillion in global consumer commerce by 2030. That projection helps explain why payments companies are addressing agent identity in advance, but it is not a guarantee of adoption. The pace of deployment will also depend on consumer trust, merchant acceptance, liability rules, fraud losses and regulatory approval.
KYA can help answer who operates an agent and which user or business it represents. It cannot, by itself, resolve every problem involving user intent or system security. An agent may be correctly linked to its operator yet misunderstand a request. It may hold a valid certification yet be influenced by malicious instructions or a compromised external tool. Agent identity, proof of user intent, permission management, transaction authorization and dispute remedies will therefore need to work as connected control layers rather than as a single identity label.
For now, the collaboration remains an exploration of common principles among three companies with existing agent-payment protocols. Its significance is that major payment participants are treating AI-agent identity as infrastructure rather than as a narrow product feature. Whether the initiative develops into broadly reusable standards will depend on how effectively future testing balances interoperability, privacy, security and clear accountability.
The underlying shift is straightforward: once software agents begin acting on behalf of users in commercial environments, payment systems may need to expand the traditional question of “know your customer” into a parallel question—“know your agent.”
Source: link