Visa, Mastercard, and Ant International are advancing the Know Your Agent (KYA) interoperability framework. The goal is not to create a unified risk control center, but to enable different payment networks to recognize shared Agent identities and trust signals while retaining their own approval and risk decisions.Article author, source: ME News
TL;DR
- Visa, Mastercard, and Ant International are advancing the Know Your Agent (KYA) interoperability framework. The goal is not to create a unified risk control center, but to enable different payment networks to recognize shared Agent identities and trust signals while retaining their own approval and risk decisions.
- The importance of this lies not in "AI also needs real-name verification," but in the payment system being asked for the first time to systematically answer three questions: Who is this Agent? Who does it represent? And what is it authorized to do? Previously, bank cards solved "how to pay," while KYA must answer "why should a machine be allowed to pay on your behalf."
- The core elements of the three-party collaboration include: tracing the operators or users behind Agents across networks, establishing shared authentication requirements, and continuously monitoring Agent transactions. In other words, KYA is more like a combination of “identity + authorization + behavioral records,” rather than just a static ID card.
- This does not mean that KYA has become a global standard. The current collaboration is still in the stage of framework exploration; what truly determines its impact will be the subsequent technical specifications, merchant integration, responsibility allocation, and whether more wallets, acquirers, and Agent platforms join.
AI agents are starting to spend; the payments industry must first address the "identity layer".
Over the past two years, Agentic Commerce has most easily been described as an experience story: a user says, “Book me the best hotel for next week in Tokyo,” and the AI completes the search, comparison, booking, and payment.
When it comes to the actual payment stage, the question immediately shifts from "Is the model smart enough?" to "Who actually decided to spend this money?"
On September 10, Ant International, Mastercard, and Visa announced the launch of a KYA interoperability initiative. Under the framework disclosed by the three parties, card networks, digital wallets, Agent platforms, and e-commerce platforms will soon be able to recognize trusted Agent signals across networks, eliminating the need to independently replicate Agent identity verification in each system.
However, an agent being recognized by another system does not automatically grant payment authorization. Each network retains its own rights to verification, approval, and risk management. The three parties have currently defined clear areas of collaboration, including cross-network operability traceability, shared authentication requirements, and ongoing transaction monitoring, and plan to further explore related approaches through BuildFin.ai, initiated by the Monetary Authority of Singapore.
This distinction is important.
Translating KYA simply as “giving an AI an ID card” may make it easier to understand, but it risks underestimating its complexity. An ID card answers “who you are,” but an agent in payments must also answer “who you represent,” “what are your authorization boundaries,” “does this action align with the original intent,” and “who is accountable if something goes wrong.”
If traditional KYC is about verifying the identities of individuals and enterprises, then KYA is more about establishing a verifiable agency relationship in the machine world.
My assessment is that the true large-scale infrastructure of Agentic Commerce will not begin with smarter shopping bots, but rather with this less glamorous layer of trust.
The reason is simple: models can make probabilistic recommendations, but payments must produce deterministic outcomes. Once money is transferred, you can't explain it away with "the model probably understood the user."
Why must you do KYC now?
The demand is no longer a concept.
McKinsey’s 2026 research estimates that, under a medium scenario, AI agents could mediate or orchestrate $3 trillion to $5 trillion in global consumer commerce transactions by 2030; in the U.S. B2C retail market alone, this could amount to nearly $900 billion to $1 trillion.
This number does not mean that all these transactions will be fully autonomously paid by AI, but it is sufficient to show that AI is moving from “influencing purchasing decisions” to “participating in transaction execution.”
Traffic changes are more intuitive.
Visa disclosed that in July 2025, traffic to U.S. retail websites generated by generative AI increased by more than 4,700% year-over-year. Prior to the launch of its Trusted Agent Protocol, it also noted that 85% of users of AI shopping tools believed AI improved their shopping experience.
The issue is that merchants typically default to blocking automated traffic as bots, since crawlers, credential stuffing, scalpers, and malicious automation all technically fall under the category of "non-human access."
When agents that shop on behalf of consumers also enter websites as machines, merchants must be able to distinguish between two types: authorized commercial agents and malicious bots that should be blocked.
Yet the psychological barrier for consumers has not disappeared.
A U.S. consumer survey released by Visa on September 9 found that only 23% of respondents were willing to trust generative AI to handle payments on their behalf; when the question was changed to whether they trusted Visa to handle agent transactions, the percentage rose to 61%.
This is, of course, Visa's own research and should not be treated as an industry-neutral statistic, but the contradiction it reveals is very real: people are increasingly willing to let AI help them choose, yet still reluctant to let AI directly handle money.
Therefore, the first commercial barrier for Agent payments is not whether there is a payment API, but whether trust can be extended from humans to machines.
Without KYA, merchants see only an automated request; with KYA, merchants have at least the opportunity to know who operates this Agent, which user or business it represents, whether it has passed security verification, whether its past behavior has been normal, and whether this operation is within authorized limits.
Why should third parties recognize each other instead of operating independently?
Visa, Mastercard, and Ant International have previously been laying the groundwork, respectively.
Visa has the Trusted Agent Protocol, focusing on enabling merchants to identify trusted agents and their commercial intent; Mastercard emphasizes verifiable user intent, permissions, and network credentials through Agent Pay and Verifiable Intent; Ant International extends agent capabilities to wallets and mobile payment scenarios via the Agentic Mobile Protocol.
The value of this collaboration among the three parties is not to create a fourth protocol, but to establish a shared "language of trust" between these systems.
If this step is implemented, the most direct benefit will be reducing the cost of repeated integrations.
Today, a payment service provider often faces different identity models, risk control fields, and integration processes when entering various card networks, wallets, and markets. If the Agent platform were to replicate this fragmented approach in the future, the larger its scale, the greater the friction would become.
The direction of interoperable KYC is to allow an Agent, after completing authentication in one system, to carry trusted signals into another system, enabling the latter to make its own risk assessment rather than starting from scratch.
Particularly noteworthy is the role of Ant International.
It is not another global card network, but a network connecting a vast number of wallets, merchants, and cross-border payment scenarios. In 2026, Ant International disclosed that its payment ecosystem connects approximately 2 billion user accounts and 150 million merchants, covering over 50 digital wallets and bank apps, as well as more than 10 national QR code payment systems.
For KYA, this means that interoperability discussions are no longer just about coordinating card networks between Visa and Mastercard, but now involve bringing cards, wallets, QR codes, and cross-border merchant networks into the same agent trust framework.
In June this year, Mastercard launched Agent Pay for Machines, further advancing agent payments toward machine-to-machine transactions, and announced that over 30 industry participants support or are piloting the service, with settlements possible across multiple rails including cards, accounts, and stablecoins.
From this, it’s clear that KYA is not just about “AI helping consumers buy a pair of shoes.”
It may ultimately cover higher-frequency, more automated scenarios such as enterprise agents purchasing software services, automatically buying computing power or data, and cross-border fund allocation.
The true watershed is the authorization and responsibility that follow "identity".
KYA can solve a fundamental issue, but it cannot eliminate all risks associated with Agent payments.
An identity-verified, registered Agent may still execute transactions the user did not intend due to prompt injection, model misjudgment, configuration errors, or excessive permissions.
Therefore, a "Trusted Agent" must not be understood as an "always correct Agent".
This is also why third parties have included “continuous transaction monitoring” in the framework.
Static authentication only confirms that an Agent passed a check at a specific point in time; what payment truly requires is dynamic trust: who it is today, who it represents right now, what its current task is, whether the amount and merchant are authorized, and whether its behavior deviates from historical patterns.
The SAFR framework released by the Monetary Authority of Singapore in July 2026 also emphasizes setting runtime governance checkpoints before agent actions are executed, ensuring that each proposed action operates within predefined authorization, policy, and risk boundaries, while maintaining an auditable record.
Only when combined with this type of runtime governance does KYA approach a complete control chain suitable for financial scenarios.
So I prefer to understand the future Agent payment system as having three layers:
The first layer is identity, confirming “who is acting”; the second layer is authorization, confirming “what it can do”; the third layer is transaction risk control, confirming “whether this one should be approved”.
KYA addresses the first layer and provides trusted signals to the next two layers. However, the final authority to deduct, reject, and assign responsibility should not disappear nor be left to the free judgment of a general AI model.
KYA could redefine value distribution in the payments industry
One of the most critical assets in today's payment networks is establishing trusted connections among consumers, merchants, and banks.
In the Agent era, the object of this "trusted connection" will include an additional category of machine entities.
Whoever can provide widely accepted agent identities, authorization credentials, and risk records has the opportunity to become the foundational trust layer for Agentic Commerce.
This is also the most significant industry implication of this collaboration.
In the past, discussions about AI business entry points often focused on who owned the strongest models or the largest chat interfaces; but as AI begins to spend money genuinely, model companies must enter the deterministic rules set by payment networks.
Payment companies may appear to be at the end of the transaction chain, but they can actually re-embed themselves upstream in the agent economy through KYA, tokens, authorization, and risk control.
Of course, this also brings new platform power issues.
If, in the future, only a few large networks define what constitutes a trustworthy Agent, KYA could shift from being a public infrastructure that reduces friction to a new barrier to entry.
Therefore, the significance of interoperability lies not only in technical efficiency but also in preventing each network from establishing isolated Agent identity silos.
The ideal state is not “the world recognizes only one AI identity,” but rather that different networks can mutually recognize necessary trusted credentials while preserving diverse authentication providers and independent risk decisions.
It's not yet time to call it a "global standard"
The most important thing to avoid in this collaboration is not to phrase “launching an interoperability framework collaboration” as “the three companies have already unified the KYA standard.”
The publicly available information still uses language exploring common principles and advancing framework collaboration; complete technical specifications, governance mechanisms, certification entities, fee structures, and a global large-scale commercial timeline have not yet been disclosed.
In other words, this is a clear-direction, high-stakes starting point—not yet the final outcome.
But the starting point itself still matters, because it shows that the payments industry has accepted a reality: AI agents will not remain merely “recommendation tools” forever.
Once it begins executing transactions on behalf of individuals and businesses, the payment system must formally incorporate machine agency into its frameworks for identity, authorization, risk management, and accountability.
The internet previously solved how people can pay online; mobile payments solved how people can pay more conveniently; Agent payment aims to solve how the payment system can still confirm that a payment reflects the user's true intent when the user is not physically present to click each time.
From this perspective, KYA is not about giving AI a pretty “ID card,” but about establishing a traceable, authorized, rejectable, and auditable economic identity for machine agents.
What truly matters is not that AI can finally make payments, but that the payments industry is beginning to seriously answer a more practical question: when machines spend money on your behalf, who has the authority to say “this payment is approved”?
References
- Ant International, Mastercard and Visa.Ant International, Mastercard and Visa initiate collaboration on know-your-agent interoperability to scale agentic commerce.. Business Wire, 2026-09-10.
- Reuters. Payment firms Visa, Mastercard and Ant International team up on AI agent trust framework. 2026-09-10.
- McKinsey & Company.The automation curve in agentic commerce.2026-01-28.
- Visa Inc.New Visa Research Finds Consumer Trust is Accelerating the Path to Agentic Commerce. 2026-09-09.
- Visa Inc.Visa Introduces Trusted Agent Protocol: An Ecosystem-Led Framework for AI Commerce. 2025-10-14.
- Mastercard.Mastercard launches Agent Pay for Machines. 2026-06-10.
- Ant International.Ant International Highlights Democratising AI and Strengthening Trust in 2025 Sustainability Report. 2026-05-11.
- Monetary Authority of Singapore.MAS Partners with Industry to Develop Safeguards for AI Agents in Finance. 2026-07-03.
