Resource Hub | DC Payments

Know Your Agent: Getting Ready for AI That Pays on Its Own

Written by DC Payments Author | August 24, 2026

 

AI is moving from recommendation engine to authorized buyer. When software can initiate and approve a payment, identity has to evolve from knowing your customer to knowing your agent.

Agentic commerce is commerce in which an AI agent finds, selects, and pays for goods or services inside a mandate a person or business has delegated to it. Verifying that agent is a new discipline, and the industry has a name for it: KYA, or Know Your Agent. It asks who owns the agent, what it is allowed to do, and whether the payment it is requesting should go through right now.

The next checkout may not have a human at the keyboard

For years, financial institutions have framed AI as a tool that helps people work faster. It scores fraud risk, accelerates digital KYC, reads documents, and routes service requests. That is useful work, but the human stays the decision-maker. Online shopping is no different: the payment starts when a person clicks a button.

Agentic commerce breaks that assumption. The agent can search for a product, weigh competing offers, add items to a cart, begin checkout, and authorize payment. The person sets the intent and the limits; the agent executes them.

That is a categorical change, not an incremental one. It also lands on infrastructure built for a different world. Card networks, fraud engines, checkout flows, and onboarding models were all calibrated for human-initiated transactions. When the buyer is software, the question a bank or merchant has to answer changes entirely.

From KYC to KYA: know the agent before it pays

KYC answers a familiar question: do we know the customer? KYE, know your employee, extends that to the people who already hold access inside an institution. KYA asks the next one: do we know the agent acting for the customer, and should it be trusted to do this?

The distinction matters because an authenticated agent is not automatically an authorized one. A valid API key or a stored tokenized card proves only that a credential exists. It does not prove that the agent presenting it was permitted to buy this item, at this price, from this merchant, right now.

So the security question shifts. It is no longer only whether the identity was verified, but whether this particular transaction should be allowed. A customer might trust an agent to reorder office supplies up to a set amount each month, and not to open an account, wire funds, or add a new payee. KYA is what makes that boundary enforceable rather than aspirational.


Why agentic commerce needs open infrastructure to scale

The early stumbles in agentic checkout were not failures of model capability. They were failures of plumbing. The commercial stakes are large. eMarketer projects $144 billion in U.S. e-commerce originating from AI platforms by 2030, and the firms racing to build the connective layer are betting that whoever closes the infrastructure gap holds the durable position.

Research across enterprise merchants points to a consistent set of constraints:

  • Fragmented protocols across AI commerce surfaces;
  • Product data that machines cannot reliably query;
  • Checkout stacks designed for linear human flows;
  • Fraud frameworks tuned to human-initiated payments; and
  • Merchant onboarding that does not scale.

No single company closes all five.

The historical parallel is the late-1990s shift to online retail. That transition did not resolve because one merchant won. It resolved because the ecosystem agreed on interoperability in terms of transport security for trust and card network protocols for settlement. Agentic commerce faces the same shape of problem, and needs the same shape of answer.

Much of what an agent needs already has a name in banking. Permissioned data access through secure APIs, explicit consent that can be reviewed and revoked, accreditation that establishes who may participate and clear liability when something goes wrong. This is the open banking playbook. It maps almost directly onto the trust layer agent-initiated payments will require. For where that framework stands in Canada, read Open Banking in Canada: What's Taking So Long and What to Do Now.

What the agentic payments stack actually needs

Five capabilities carry that trust layer. They are listed here in the order worth building them, because each one depends on the ones above it.

Verifiable agent identity

Every agent capable of initiating a payment should carry an identity that institutions and merchants can recognize and check. That record should show who created the agent, who is accountable for it, what it was built to do, and whether its authority is still valid. This comes first because every control that follows depends on knowing which agent is acting.

Scoped, time-bound credentials

Standing privileges are the wrong default for autonomous systems. Long-lived API keys and broad service accounts should give way to credentials that are scoped to a specific task, bounded in time, and revocable the moment an owner or workflow changes.

Runtime authorization

Checking identity once, when a credential is issued, is not enough. Agents transact at machine speed, and a compromised one can move across several systems before anyone notices. High-risk actions need to be evaluated as they happen, against the consent on file, the amount, the merchant, and the surrounding risk signals. Sensitive payments and credential changes should require step-up approval. This is the layer that actually stops a bad transaction rather than documenting it afterwards.

Machine-readable data

Agents act only on what they can read. Product details, pricing, inventory, payment options, and policy rules all need to be queryable through open APIs and shared protocols. Poor or stale data produces poor agent decisions, which surface later as failed payments and disputes. Put bluntly, if AI can't parse your product data, you don't exist.

Audit trails

Regulated institutions have to be able to reconstruct what happened. A durable record should link the customer's instruction, the agent that acted, the permission it used, the rail selected, and the outcome. This is the layer most often deferred, and the most painful to retrofit once agents are already transacting.

The banking gap between experimenting and deploying

Banks are interested, but interest is not deployment. Industry research cited by Retail Banker International found 96% of banks experimenting with agentic AI while only 19% had put it into production, with most live use confined to back-office KYC and AML work rather than customer-facing money movement. The full analysis is in Unlocking success in agentic banking.

The gap is not enthusiasm. It is accountability. A bank can explain a fraud model to its regulator because a human made the final call. It cannot yet explain why an autonomous system chose one action over another, or say with confidence who is answerable when that choice goes wrong. Until that question has an institutional answer, pilots stay in the back office.

Where to start

None of this requires waiting for a finished standard. Begin by mapping where an AI agent could already initiate or influence a payment decision in your current workflows. Most institutions find more exposure than they expect, usually in procurement and payables rather than in customer-facing channels.

Consent language deserves separate attention, and it is easy to underestimate. Customers need to understand when a tool may act on their behalf and how to withdraw that permission. That wording is often harder to get right than the engineering behind it.

The goal is not to slow agentic commerce down. It is to make it safe enough to scale. The best agentic experience will feel invisible to the customer, but it cannot be invisible to risk, identity, and compliance systems.

Frequently asked questions

What does KYA, or Know Your Agent, mean?

KYA means verifying the AI agent or other non-human system involved in a transaction, rather than trusting the credential it presents. In practice it combines a verifiable agent identity, an accountable owner, scoped credentials, and a check performed at the moment the payment is requested.

How is KYA different from KYC?

KYC verifies the person or business behind an account, usually at onboarding. KYA verifies the delegated actor at the point of the transaction. KYC asks whether the identity is real; KYA asks whether this agent, with this authority, should be allowed to move money right now.

Is agentic commerce relevant to business payments today?

Yes. Business payments already rely on automation, digital wallets, embedded finance, and real-time data. As AI agents enter procurement, treasury, and payables workflows, providers need a way to verify delegated authority before funds move.

Final takeaway

Agentic commerce asks a harder question than any AI use case before it: how do you verify the buyer when the buyer is software? The institutions that answer it first will set the terms the rest of the market ends up adopting.