In September 2026, three payment networks that don’t normally coordinate announced a Know Your Agent (KYA) interoperability framework, so cards, wallets and agent platforms can recognise the same agent across networks. Agent identity has stopped being a feature race and become a coordination problem. It sits inside the wider AI agent wallets and the agentic commerce landscape.
Agentic commerce has shipped its technical rails faster than its accountability rails. Agents can now transact, and identity standards can verify which agent is acting, but none can tell you who absorbs the loss when that agent buys the wrong thing. By the end you’ll know what KYA verifies, how the three standards differ, and how to map your own exposure before delegating spend.
What is a Know Your Agent (KYA) framework, and why are Visa, Mastercard and Ant International building one?
Know Your Agent is the agent-economy counterpart to KYC. Where KYC verifies a human customer, KYA verifies an AI agent is known and accountable before money moves, binding its requests to a registered operator and an authorised user. The timing differs: KYC checks a human once, while KYA repeats checks during operation, because an agent can be compromised later.
The framework exists because agentic commerce had no trust layer: merchants couldn’t verify which agent was transacting or on whose authority. The September 2026 announcement was the first coordinated fix, built on three pillars: cross-network operator traceability, shared certification, and continuous transaction monitoring.
KYA is a framework of principles, not a single protocol, sitting one layer above the individual payment standards and inside the wider trust layer in agentic commerce. So KYA and Visa’s Trusted Agent Protocol aren’t rivals: KYA is the umbrella, Trusted Agent Protocol one implementation, converging at the framework level even as they compete at the rail level.
Visa’s Trusted Agent Protocol vs Mastercard’s Agent Pay vs Ant’s Agentic Mobile Protocol: how do they compare?
Beneath the shared framework sit three standards that approach agent identity and authentication differently and don’t interoperate by default. The axis that matters: where identity sits in the payment flow.
Visa’s Trusted Agent Protocol went live in October 2025 with twelve launch partners, attaching signed HTTP headers to every request and resolving them against a centralised directory. Visa can revoke a compromised operator in minutes, but is also the single point of trust for that directory.
Mastercard’s Agent Pay folds the agent-identity claim into the network token so the issuer sees which operator acted. Any merchant that accepts Mastercard tokens accepts Agent Pay with no new integration, but the claim only travels on Mastercard rails. The Agent Pay for Machines (AP4M) variant extends the model to machine-to-machine payments.
Ant International’s Agentic Mobile Protocol is the mobile-first, open-sourced third option. Ant International is also a Visa launch partner, backing its own standard while shipping someone else’s.
Across all three, four questions separate them: who verifies the agent, where the proof travels, how consent is represented, and which network each targets. Visa runs a central directory, Mastercard defers to the issuer and the network token, and Ant leans on a mobile-first operator model. No standard has won, and none interoperates by default. That fragmentation is what KYA exists to bridge. We covered the mechanics of how agents are identified across these rails here.
Why is trust, not capability, the hardest part of agentic commerce?
But a bridged identity layer only tells you who acted. It leaves the harder question open: who pays?
Capability has outrun accountability. The rails settle purchases, but nobody has codified who absorbs the loss when one is wrong.
That’s the liability vacuum, and it has two layers. There’s no clean chargeback reason code for an “agent error”, and no cryptographic proof of which operator made the request, so liability defaults to the merchant, and in practice the loss walks into your dispute team. 93% of merchants say AI or agent providers should bear that loss, while only 28% will expose their full product range.
The regulatory layer doesn’t help. The Electronic Fund Transfer Act and Regulation E were written for human-initiated transactions, and the CFPB and Federal Reserve have not weighed in; the UK’s Financial Services AI Adoption Plan names liability, consent and fraud uncertainty as material barriers. Only 23% of consumers trust agents to spend their money, and NewtonX frames it as a $385 billion liability vacuum towards a fifth of e-commerce.
Federal Reserve Governor Christopher Waller called trust a “market-structure problem”, and Adyen argues that until we answer who is liable when a machine acts as proxy, trust cannot be established. That’s the question we examined in whether the trust gap is holding adoption back.
How do I map and assess my liability exposure before adopting agentic commerce?
Since no standard today reallocates loss, work out your business’s exposure before you delegate spend. It’s a what-to-assess question, and four dimensions matter.
The first thing to weigh is the scope of delegated authority: what the agent may spend, and on whose consent. Consent runs on OAuth-style delegated authorisation, where a token names the agent as actor and you as subject within a limited scope. A tightly scoped, revocable credential is the difference between “book domestic travel up to $2,000 a month” and a vague “travel permissions”.
Next, cross-network operator traceability and continuous transaction monitoring: can you identify the operator behind every request, and is every action observed in near-real time? These are KYA’s own pillars, so hold any framework to these two tests rather than letting it verify an agent once and go quiet.
Finally, documentation: the record of every action, because when a dispute arrives you want proof of which operator acted. American Express’s Agent Purchase Protection is the only network attempt to address the loss directly, and it’s conditional, so the trail you keep is what you’ll argue from. Read the specs yourself: Visa’s Trusted Agent Protocol specification is public on GitHub and Mastercard’s Agent Pay has developer documentation, with EMVCo’s draft as the cross-network reference, though it still leaves non-fraud liability unresolved.
As Worldpay puts it, who bears the loss in a dispute is still undecided. The limit you put on delegated authority is the idea we explored around scoping credentials to limit that liability.
Here’s where the standards race lands. KYA verifies who the agent is, and the three rails differ only on where identity sits in the flow. A verified agent is not an accountable agent.
The question to ask is what authority you’re delegating, whether you can trace it, and who pays when it’s wrong. Until a reason code exists for agent error, mapping delegated-authority scope, traceability, monitoring and documentation is the only accountability that exists.
Regulators are beginning to name the gap, but noticing is not codifying, and you shouldn’t wait. For how identity, wallets and rails fit together, see the agentic commerce landscape.
Frequently Asked Questions
Is Know Your Agent just KYC rebranded for AI?
No. KYC verifies that a human customer is who they claim to be, while Know Your Agent verifies that an autonomous agent is registered to an accountable operator and acting on a specific user’s authority. It is the agent-identity counterpart to KYC, adding a second question KYC never had to ask: on whose authority is this agent acting, right now?
Will one agent identity standard eventually win?
Unlikely in the near term. Visa’s Trusted Agent Protocol, Mastercard’s Agent Pay and Ant’s Agentic Mobile Protocol answer the same question differently and are not interoperable by default, so fragmentation persists at the rail level even as the KYA framework converges on shared principles. Treat the standards race as ongoing rather than settled.
What happens if my AI agent makes a purchase I did not authorise?
Today nobody has codified the answer. There is no clean chargeback reason code for an agent error, and no network reallocates the loss, so disputes often default to the merchant or fall on you. A signed header or network token proves which agent acted, not who absorbs the loss.
Does Visa’s Trusted Agent Protocol protect me if my agent buys the wrong thing?
No. Trusted Agent Protocol verifies which agent is acting, resolving signed request headers against a centralised directory of known agents, but it shifts no loss. It reduces uncertainty about identity, not accountability for a bad purchase. The same is true of Mastercard’s Agent Pay.
How is an AI agent actually identified during a payment?
It depends on the rail. Visa’s Trusted Agent Protocol attaches RFC 9421-signed HTTP headers to each agent request and resolves them against a directory. Mastercard’s Agent Pay embeds agent identity into the network token of the card transaction itself, while Ant’s standard is mobile-first. Where identity sits in the flow is the key difference.
Who is liable when an AI agent pays incorrectly?
No one has been formally assigned the loss. Survey evidence shows 93% of merchants expect AI and agent providers to bear it, while regulators have stayed largely silent, leaving a liability vacuum. Until a network introduces a reason code or reallocates loss, liability defaults to whoever the dispute process lands on, usually the merchant.
Can my AI agent spend money without my permission?
Not if the consent model works as designed. Agent authority is meant to run on delegated authorisation, similar to OAuth, where you approve a defined scope and can revoke it. Your exposure equals the scope you delegate, so a tightly scoped, revocable credential limits what the agent can spend without you.
What is the difference between verifying the agent and verifying the user?
Verifying the agent answers “who is this?”, while verifying the user answers “on whose authority?”. Know Your Agent composes both, binding a registered operator and an authorised user to each request before settlement. Identity standards that stop at the agent leave the authority question open, which is exactly the gap the liability vacuum sits in.
What is Agent Pay for Machines (AP4M)?
It is Mastercard’s machine-to-machine variant of Agent Pay. The standard Agent Pay route covers an agent transacting on a consumer’s behalf by folding agent identity into the network token, while AP4M extends that identity model to payments where one machine pays another directly, with no human in the loop at the point of sale.
Is agentic commerce safe enough to use now?
Capability has outrun accountability, so safety depends on how you delegate. Agents can complete purchases today, but no standard reallocates loss and disputes remain unresolved. The practical safeguard is to map your exposure first: limit delegated authority, demand cross-network traceability, monitor transactions continuously, and keep documentation of every action.
How do I revoke an AI agent’s payment authority?
Revocation depends on the consent model underwriting the credential. OAuth-style delegated authorisation lets you withdraw a token or its scope centrally, but some rails embed identity in the transaction token itself, which can make instant revocation harder. Before delegating, confirm how the framework revokes authority and how quickly that takes effect.
Does the September 2026 KYA announcement mean the networks have stopped competing?
No. The KYA interoperability framework is a layer of shared principles, and it sits above three rails that still compete on where identity sits in the flow. Convergence at the framework level and competition at the rail level are happening at the same time. Ant International, for instance, backs its own protocol while also being a Visa Trusted Agent Protocol launch partner.