When Your AI Agent Is the Customer, Who Does the Bank Ask?
Photo: N43 and Hermes AIAI agents are moving from recommending purchases to executing them — up to $5 trillion of commerce by 2030 on some projections. Banks built KYC on the assumption that a human shows up. The industry is now racing to build Know-Your-Agent, and the deeper question is who is responsible when your AI agent spends your money.
Hero photo: Customer service counter, Commonwealth Bank, Brisbane, 1953 — Queensland Newspapers Pty Ltd, State Library of Queensland, Wikimedia Commons, public domain.
01 The customer is no longer a person
AI agents are graduating from recommending purchases to executing them — opening accounts, initiating payments, and completing transactions on behalf of users. Analysts project agents could orchestrate $3 trillion to $5 trillion of global consumer commerce by 2030. Every one of those transactions arrives at a bank or card network from software, not a person — and the entire identity infrastructure of finance was built on the assumption that a human being shows up.
N43 Policy Analysis, September 19, 2026. This is an analytical scenario based on current reporting and records, not a prediction; the $3-5 trillion figure is an industry projection, and the standards described are in active development, not final.
The industry's answer has a name: Know Your Agent — KYA, the successor discipline to KYC. This is the story of what banks do when the account holder is a process.
02 Why KYC breaks on software
KYC is a point-in-time exercise: verify identity once at onboarding, then monitor for material changes. That architecture assumes the customer's identity and behavior are stable facts. An agent's authority to act is not a stable fact — it is a permission that can be granted, scoped, or revoked in the time it takes to call an API, and the entity directing the agent at 3 p.m. may not be the one that provisioned it at 9 a.m. A compliance framework built on periodic re-verification cannot govern something that changes state continuously.
Agentic AI inside banks is already transforming the other side of KYC — Fenergo reports 82% of financial institutions already use AI to automate labor-intensive KYC and AML processes, with agents completing onboarding reviews in hours and resolving up to 50% of screening hits. But automating the bank's checks is the easy half. The hard half is verifying the customer's agent when it comes knocking — the compliance literature is blunt that KYA is not a feature of KYC but a new discipline built from scratch.
03 The standards race is already crowded
The infrastructure is being assembled fast. In April 2026 the FIDO Alliance launched agentic authentication and payments working groups, seeded with Google's Agent Payments Protocol (AP2) and Mastercard's Verifiable Intent. AP2 defines “mandates” — cryptographically signed credentials capturing what a user authorized an agent to do, from checkout conditions to payment limits. Verifiable Intent binds the user's biometric, passkey-grade identity to the instructions and the resulting transaction, so any party can verify who approved what without seeing everything.
Then the networks converged. On September 9, Ant International, Mastercard, and Visa began collaborating on Know-Your-Agent interoperability — a framework to make each network's agent-verification signals (Visa's Trusted Agent Protocol, Mastercard's Verifiable Intent, Ant's Agentic Mobile Protocol) recognizable across ecosystems, built on principles including cross-network operator traceability, shared certification requirements, and continuous transaction monitoring, under the Monetary Authority of Singapore's BuildFin.ai platform. FIDO's working groups are chaired by CVS Health, Google, OpenAI, Mastercard, and Visa — the entire payments and AI stack is in the room.
04 What a bank actually has to verify now
Under the emerging architecture, a bank facing an agent-initiated transaction needs to resolve three questions no traditional KYC file answers. First: is this really the customer's agent? — agent identity and certification, the KYA core. Second: what was the agent actually authorized to do? — scope, amount limits, instrument constraints, expiry, all carried in the mandate. Third: is the transaction within those bounds right now? — continuous monitoring, because authority granted this morning may have been revoked at lunch.
The good news is that the cryptographic machinery makes these questions answerable: mandates are tamper-evident, intent is verifiable by issuers and networks independently, and selective disclosure lets each party see only what it needs. The bad news is that none of this is standardized yet — three networks running three protocols toward interoperability is a truce, not a system, and a bank building agent support today is betting on specs that will shift under it.
05 The deeper question: who is responsible when your AI agent spends your money?
Here is the question the standards do not answer. Suppose your agent buys something outside what you meant — it took your “find me a cheap flight” as license to book first class, or a prompt-injected web page redirected its shopping mandate, or a compromised agent platform spent your saved mandate. The cryptographic record will show you authorized something. Was that something this? Today's dispute rules, consumer-protection law, and liability chains all assume a human clicked “buy.” When the click is a signed object from a third-party agent platform, the liability chain — user, agent vendor, merchant, network, issuing bank — has no settled order.
The industry's implicit answer is that authorization must be bounded and provable: mandates carry explicit limits, agents never hold raw credentials, and revocation is instant. That constrains how badly an agent can overspend your money. But bounded authority is not allocated liability. The first generation of agentic-fraud disputes — and regulators like MAS convening BuildFin.ai suggest they see this coming — will write those rules case by case, and the banks that waited for clarity will discover it was written against them.
06 The verdict
The verified facts: FIDO Alliance stood up agentic authentication and payments working groups in April 2026 built on Google's AP2 and Mastercard's Verifiable Intent; Ant International, Mastercard, and Visa began Know-Your-Agent interoperability work on September 9 under Singapore's BuildFin.ai; agent-driven consumer commerce is projected at $3-5 trillion by 2030; compliance practitioners are explicit that KYA is a new discipline, not an extension of KYC.
The stakes: identity is the foundation of every financial-control law on the books — AML, sanctions, consumer protection, dispute resolution. If the know-your-customer assumption breaks quietly under agent-driven transactions, it breaks for the entire control stack built on top of it. The standards arriving now decide whether that break is orderly or discovered in a fraud report.
The bottom line: banks spent fifty years perfecting the verification of humans. The next five will decide whether they can verify software acting for humans — and the part still missing is not identity or cryptography. It is the answer to one question: when your agent spends your money wrongly, who pays? Whoever the industry does not decide today, a court will decide later.
Source video: “Automating Know Your Customer Document Verification with Amazon Quick” — Amazon Quick, 2026-02-11, 1755 views observed at publication. Independently researched by N43 and Hermes AI.
References
- FIDO Alliance — FIDO Alliance to develop standards for trusted AI agent interactions (April 28, 2026)
- FIDO Alliance — Building the trust layer for agentic payments with AP2 and Verifiable Intent
- Business Wire — Ant International, Mastercard and Visa initiate Know-Your-Agent interoperability (September 9, 2026)
- Unite.AI — KYC was built for humans — now we need Know Your Agent
- Moody's — AI agents for KYC and AML investigations (April 2026)
- IBM — Agentic AI is rewriting KYC and AML in banking (July 10, 2026)
- Hero photo — Queensland Newspapers Pty Ltd / State Library of Queensland, Wikimedia Commons, public domain
By N43 and Hermes AI for DutyStation News.