How is KYA different from KYC?

KYC checks one person, usually once, at onboarding. KYA has three answers to hold at the same time, and they can come apart: the business that operates the agent, the person the agent is acting for, and what that person authorised it to do on this occasion.

In Experian's version, KYC answers who you are and KYA answers who or what is acting for you and whether it should be trusted (Experian). Sumsub's definition is more procedural, binding each agent to a responsible person or organisation and enforcing policy, oversight and an audit trail across everything it does (Sumsub). Both companies sell verification, so read the definitions knowing that, but on the substance they agree.

KYC also never had to deal with a customer who changes overnight. An agent can have its model or its prompt swapped between Monday and Tuesday while the company that operates it keeps the same legal name, so a check passed at onboarding may describe software that no longer exists.

Where did the name come from?

It was in use in payments by the middle of 2025, first as a product feature. Skyfire launched Agent Checkout on 26 June 2025 on an open protocol it called KYAPay, in which the KYA part is a signed token carrying the verified details of the agent's owner that a service needs to open an account for it (Business Wire via Silicon UK, PYMNTS).

By July, Trulioo and the agent-infrastructure company PayOS had published a white paper stretching the name over a wider framework. At its centre is a Digital Agent Passport, a tamper-proof credential recording who built the agent, who it represents and what it may do. Independent authorities would issue, sign and revoke the passports, a role the paper suggests identity providers, payment networks or industry groups could fill (PYMNTS, Biometric Update).

What have Visa, Mastercard and Ant International agreed?

Less than the headlines suggest. The release of 9 September says the three "will now explore opportunities to work towards common principles" (the joint release). Each already runs its own protocol for agents, Visa's Trusted Agent Protocol, Mastercard's Verifiable Intent and Ant International's Agentic Mobile Protocol, and the stated aim is to streamline how agents are onboarded and identified across networks (the joint release, PYMNTS).

The work goes through BuildFin.ai, an industry platform convened by the Monetary Authority of Singapore, and builds on the regulator's Safeguards for Agentic Finance at Runtime framework (the joint release, TNGlobal). Under the first pillar each agent is linked to a validated operator, cardholder or business; under the second it is assessed against security and behaviour requirements; under the third it is monitored continuously on a mix of identity and transaction signals (the joint release, TNGlobal).

What the release does not carry is a date. It names no implementation timetable or pilot volume, and no merchants or financial institutions that will test it, while TNGlobal describes a framework under development rather than a standard already running on the three networks (the joint release, TNGlobal).

Is KYA the same as detecting an agent at checkout?

No, and the two get confused because the same protocols touch both. Detection asks whether this request really came from the agent it claims to be, which is what a signed request under Web Bot Auth or Visa's Trusted Agent Protocol proves (how merchants detect AI agents). KYA sits a step earlier and asks whether anybody has vetted the business behind that agent and what it answers for.

A request can carry a perfect signature from an agent whose operator nobody has ever checked. It passes detection and it should fail KYA.

Who runs the check, the network or the rail?

Two answers arrived within a day of each other. The card networks and Ant International are writing shared rules for the agents that touch their own networks. India's payments operator plans one register for everyone on its rail.

Reuters, citing three people involved in the discussions, reported on 10 September that the National Payments Corporation of India plans a registry to vet AI agents that make payments on the Unified Payments Interface, as part of a planned Unified Agentic Protocol (Business Recorder, reporting Reuters, RetailIntel, citing ET Small Business). NPCI did not immediately respond to Reuters (Business Recorder).

A register run by the rail means one check for every agent on UPI. Under the network model an agent that pays by Visa and by Mastercard is vetted twice, unless the interoperability the three have promised to work towards turns up.

What does KYA leave unsolved?

KYA tells you whom to ask when an agent's payment goes wrong. Who covers the loss is settled somewhere else. One of Reuters' sources said liability for wrong or unauthorised payments will need to be settled by regulation, and ET reports that the liability rules are still being defined (Business Recorder, RetailIntel). The gap is older than KYA (who is liable when an agent gets it wrong).

The other open question is the cost of the third pillar. Tracing an agent to a company happens once. Certification is a test the agent passes on a particular day, and I have watched 797 tests pass on a gate that had never read its own policy (the essay), so I would not lean hard on a pass from one day. Continuous monitoring is the pillar that catches an agent which was fine when certified and drifts later, and it is daily work somebody has to staff. The release does not say who.

What should a builder do now?

Keep one record per agent: the legal entity that operates it, the person it is acting for and the mandate it carries, and make the agent able to produce it on request. Skyfire's token already carries the owner's details and Trulioo's passport the builder, the principal and the permissions, while the networks' first pillar is tracing each agent to a validated operator. Whichever scheme wins, it will be asking for a record you can build today.