Visa, Mastercard and Ant International Want AI Shopping Agents Traced Back to a Real Person or Business
Know Your Agent (KYA) is the set of checks a payment network uses to decide whether an AI agent is trustworthy and authorised before it completes a transaction, and on 9 September 2026 Ant International, Mastercard and Visa said they had begun work on making those checks interoperable across card and wallet networks. The first of the three components they named is operator traceability: every agent linked to a validated operator, cardholder, business or organisation.
That component makes the collaboration as much an identity story as a payments one. Before a network can attribute an agent's purchase to someone, somebody has to have established who that someone is. This post sets out what was announced, what each component asks for, and where a credential layer can add to the controls the networks are building.
Key takeaways
- Ant International, Mastercard and Visa have begun collaboration on an interoperable Know-Your-Agent framework, according to a joint release distributed via Business Wire on 9 September 2026.
- The work centres on three components: cross-network operator traceability, shared certification requirements and continuous transaction monitoring.
- Each network keeps its own verification and decisioning processes. The aim is common principles, so trust signals can be recognised across networks.
- The three firms will collaborate through BuildFin.ai, an industry platform convened by the Monetary Authority of Singapore, building on the SAFR framework.
- The release cites a McKinsey projection that AI agents could orchestrate US$3 trillion to US$5 trillion of global consumer commerce by 2030.
What was announced
The three organisations said they have "begun collaboration" on a KYA interoperability framework designed to help card networks, digital wallet ecosystems, agent platforms and marketplaces streamline agent onboarding and identification across networks. The framework is to be based on shared principles "while preserving each network's own verification and decisioning processes".
Each firm already runs its own protocol for agent transactions: Visa's Trusted Agent Protocol, Mastercard Verifiable Intent and Ant International's Agentic Mobile Protocol. According to the release, they "will now explore opportunities to work towards common principles". The release does not publish a technical specification or a timeline, so this is best read as the start of joint work rather than a finished standard.
The stated benefit is practical. Agents that meet common trust signals would not have to repeat the same identity checks with every network, which the firms say reduces integration complexity and "duplicative agent identity verification efforts" while keeping risk controls in place. For agent platforms, that should mean faster time to market and lower integration cost.
The collaboration builds on the Safeguards for Agentic Finance at Runtime (SAFR) framework, a white paper the Monetary Authority of Singapore released in July 2026 that sets out runtime checkpoints to keep AI agents within mandates and risk limits. The three firms will work through BuildFin.ai to advance common approaches to agent verification, accountability and risk management across payment ecosystems in Singapore.
Senior executives from all three firms were quoted. Mastercard's Chief Digital Officer, Pablo Fourez, said interoperability gives merchants, platforms, wallets and issuers "a consistent way to recognise trusted agents, verify that actions reflect the user's intent, and preserve accountability across the transaction". Ant International's Chief Innovation Officer, Jiang-Ming Yang, said the industry will draw on richer signals, including capabilities, behaviour, execution performance and risk data.
The three components
| Component | What the release says | The question it answers |
|---|---|---|
| Cross-network operator traceability | Each agent is linked to a validated operator, cardholder, or business or organisation, enabling clear attribution of agent activity | Who is behind this agent? |
| Shared certification requirements | Each agent is assessed against security and behavioural requirements to ensure it operates as expected | Is this agent built and behaving to an agreed standard? |
| Continuous transaction monitoring | Each agent is continuously monitored and evaluated using identity and transaction-related signals, supporting ongoing assessment and certification | Is this agent still behaving as expected, transaction by transaction? |
Two of the three components are about the agent itself: how it was built, and how it behaves over time. Only the first reaches past the software to the party responsible for it. That is also the component that depends most on information the payment networks do not always generate themselves.
Why agentic commerce runs on agentic identity
Linking an agent to a "validated" operator presumes the operator has been validated somewhere. For a cardholder, that validation usually already exists: the issuing bank carried out customer due diligence when it opened the account. For a business deploying agents, it may sit with an acquirer, a platform or a licensed onboarding provider. In each case, the fact the network needs was established upstream, by someone else.
Traceability therefore breaks into four steps that are easy to blur:
- Establishing the principal. A regulated or trusted party confirms the person or business exists and has passed its checks.
- Binding the agent to the principal. The agent carries something a network can check to confirm it acts for that principal.
- Bounding what the agent may do. The binding says which tasks, spending limits and time window the principal approved.
- Withdrawing authority. The principal can end the delegation, and the network can see that it has ended.
The first step is identity work that banks and licensed providers already do well. Steps two to four are where agent commerce introduces something new: a way for the principal's established identity and approval to travel with the agent, across networks, without each network re-collecting the principal's personal data. Mastercard's own framing of Verifiable Intent, checking "that actions reflect the user's intent", points at the same gap from the transaction side.
We looked at the broader KYA concept, and how it differs from traditional KYC, in our Know Your Agent guide. The market context is covered in our analysis of agentic payments and the agent economy.
Where agentic identity credentials fit
The networks' components describe what a network needs to know. A credential layer can supply some of the inputs, from parties that already hold them, while the networks keep their own decisioning. The table below sets out that division as we see it.
| KYA component | What the networks provide | What a credential layer can add |
|---|---|---|
| Cross-network operator traceability | Their own onboarding of cardholders, merchants and agent platforms, and the rules for attributing agent activity | A reusable credential, issued by a bank or licensed provider that already checked the principal, which the agent can present so a network confirms "this agent acts for a principal who passed KYC" without receiving the underlying documents |
| Shared certification requirements | Security and behavioural standards, testing and certification of agents | A signed statement of the scope the principal approved (tasks, limits, expiry), so certified behaviour can be checked against what the user actually authorised |
| Continuous transaction monitoring | Transaction and identity signals, fraud models, ongoing assessment | A check at transaction time that the delegation is still live and has not been withdrawn, adding a revocation signal to existing monitoring |
None of this replaces a network's own checks, certification or monitoring. A credential answers a narrow question: has a trusted party already established this fact, and has the principal approved sharing it? The network still decides what to do with the answer.
AIR Identity, built by Moca Network, works on both sides of that exchange. Trusted issuers, such as banks, fintechs, platforms and licensed KYC partners, issue reusable, user-held credentials from checks they have already run, for example passed KYC, residency or account tenure, and earn a network fee when partners verify them. Verifiers request proof of just the fact they need and receive a yes or no answer through zero-knowledge proofs, with the user's consent, keeping data custody minimal. For merchants and agent platforms, that means accepting agent-initiated sign-ups and orders from principals who already hold the credentials required, instead of paying for traffic that never qualifies.
AIR extends those credentials to AI agents. An agent can prove who it acts for and what it is authorised to do, under a mandate the user approved, limited to specific tasks, set to expire, and withdrawable by the user at any time. AIR is not a payment rail or a card network, and it does not certify agent software. It sits beneath the payment layer, at the point where a person or business is established and their approval is expressed. Our CEO set out the reasoning in why AI agents need provable identity, and we covered a related approach from the infrastructure side in our note on agent identity wallets.
Our read
We welcome this collaboration. Three large networks agreeing to work towards common agent trust principles, rather than asking every agent platform to satisfy three unrelated regimes, is good for merchants, for developers and for the people on whose behalf agents act. Running the work through an MAS-convened platform also keeps a regulator close to it from the start.
Operator traceability is the part to watch. As the principles take shape, the useful question is not only how networks certify agents, but how they recognise that a principal has already been established by a trusted party, and how that principal's approval and its limits reach the point of sale. Controls here will need continual review as agent capabilities and fraud patterns change, and a credential layer is one input among several.
Frequently asked questions
What is the Know Your Agent framework from Visa, Mastercard and Ant International?
It is an interoperability collaboration announced on 9 September 2026 to align Know-Your-Agent practices across card and wallet networks. It centres on operator traceability, shared certification requirements and continuous transaction monitoring, while each network keeps its own verification and decisioning processes.
What is agentic identity, and why does agentic commerce need it?
Agentic identity is the set of proofs that establishes who an AI agent is, which person or business it acts for, and what it is authorised to do. Agentic commerce, where agents shop, book and pay, depends on it: without a provable link to an operator and an approved mandate, a merchant or payment network cannot attribute an action, apply limits or resolve a dispute.
Which protocols does the KYA collaboration build on?
The release names Visa's Trusted Agent Protocol, Mastercard Verifiable Intent and Ant International's Agentic Mobile Protocol. The three firms said they will explore opportunities to work towards common principles across them, and will collaborate through BuildFin.ai, building on MAS's SAFR framework.
How do payment networks verify AI agents?
Under the announced approach, networks link each agent to a validated operator, cardholder or organisation, assess it against security and behavioural requirements, and monitor it continuously using identity and transaction signals. The goal is for trust signals recognised by one network to be recognised by others.
How can an AI agent prove who it acts for?
An agent can present a credential issued by a trusted party that already checked its principal, together with a record of the task, limits and expiry the principal approved. With AIR Identity, the verifier receives a yes or no proof of that relationship, with consent, rather than the principal's documents.
Does a credential layer replace KYA checks by payment networks?
No. Networks remain responsible for onboarding, certification and monitoring, and for their own decisions. A credential layer adds an input: proof that a principal was already established by a trusted issuer and that the agent's delegation is current. Each verifier decides whether that proof meets its requirements.
Building agent payments that need to know who an agent acts for? See how AIR Identity works, or partner with us to grow your business.
Sources
- Business Wire: Ant International, Mastercard and Visa Initiate Collaboration on Know-Your-Agent Interoperability to Scale Agentic Commerce (9 September 2026)
- Investing News Network: full text of the joint release
- PYMNTS: Visa and Mastercard team with Ant on Know Your Agent framework
- McKinsey: The automation curve in agentic commerce
- Retail Banker International: Singaporean regulator outlines safety guardrails for financial AI agents (July 2026)
Partner with AIR
AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.
Partner with us to grow your business.
AIR is built by Moca Network, the identity network of Animoca Brands.

.png)