Why It’s Time to Know Your Agent

know your agent

A business deploys an artificial intelligence agent to manage procurement. The agent queries suppliers, compares prices, issues purchase orders, and routes payments. The supplier on the other end has no way to verify whether the agent placing the order is legitimate, acting within authorized limits, or impersonating a real buyer.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    That is the operating reality of agentic commerce today. AI agents are already transacting across retail, finance, travel and enterprise procurement at speeds no human oversight loop can match. The identity infrastructure that would allow any party to verify who an agent is, what it is authorized to do, and whether it is acting within sanctioned limits does not yet exist at scale.

    A World Economic Forum article written by Johnny Ayers, CEO of identity company Socure, argues that the agent-driven economy is no longer emerging. By Black Friday 2025, AI-driven traffic to U.S. retail sites had risen 805% year over year, with agents driving over $22 billion in global online sales. The global AI agents market, valued at $5.4 billion in 2024, is projected to reach $236 billion by 2034.

    The article argues this acceleration raises a fundamental question current trust infrastructure cannot answer: When a human is not the transacting party, how do we establish identity certainty? The article frames the answer as a Know Your Agent framework, building on the Know Your Customer model established during financial globalization in the 1970s. A functional KYA framework, the article says, hinges on four capabilities: establishing who and what the agent is, confirming what it is permitted to do, maintaining accountability for every action it takes, and continuously monitoring its behavior against approved parameters.

    The article warns that without these capabilities, distinguishing between a legitimate commerce agent and a malicious bot impersonating one becomes impossible. The identity and accountability infrastructure built today, the article argues, will determine whether agentic commerce becomes a catalyst for global prosperity or a new frontier for unprecedented fraud.

    The Standards Gap the Government Is Moving to Close

    A February announcement from NIST launched the AI Agent Standards Initiative to ensure the next generation of AI agents is widely adopted with confidence, can function securely on behalf of users, and can interoperate smoothly across the digital ecosystem.

    The announcement says that while agents can now work autonomously for hours across code, calendars and commerce, their real-world utility is constrained by their ability to interact with external systems. Absent confidence in agent reliability and interoperability, NIST warns that innovators face a fragmented ecosystem and stunted adoption. The initiative advances along three pillars: industry-led development of agent standards, community-led open-source protocol development, and research in AI agent security and identity.

    Two active workstreams are already underway. NIST’s National Cybersecurity Center of Excellence published a concept paper on AI agent identity and authorization covering identification, authorization, auditing, and controls to prevent prompt injection. NIST’s Center for AI Standards and Innovation is holding sector-specific listening sessions on barriers to AI adoption in finance, healthcare and education. The announcement’s main point is that without standards for who agents are and what they are allowed to do, the agent economy cannot be trusted at scale.

    What Financial Regulators Are Demanding

    The IMF’s note on agentic payments goes further than either the WEF article or the NIST initiative in naming what regulators specifically need to require. The note argues that as AI agents shift payments from human-initiated instructions to agent-mediated decisions, traditional fraud models built on human behavioral patterns become ineffective. Agents do not behave like humans and the models trained to detect anomalous human behavior cannot reliably flag anomalous agent behavior.

    The note calls for regulators to move from Know Your Customer to Know Your Agent requirements, with mandated verifiable identities for financial bots linked to legal entities. It points to tokenized authorization mechanisms that allow agents to initiate transactions using preapproved payment methods without accessing underlying credentials, and cryptographic mandate frameworks that bind agent-initiated actions to verifiable scope, limits and permitted conditions.

    The note frames this as a critical infrastructure problem. As autonomous AI agents become integrated into financial and public systems, policymakers increasingly view them as part of critical digital infrastructure requiring robust governance and oversight.