The Typology Files

AI & Compliance

Identity Was Never the Hard Part of Agent Payments

By April this year every major payment network had shipped or unveiled a Know Your Agent primitive, so that a merchant can cryptographically verify which AI agent is asking before a transaction settles. It is a good answer to a question that was never the hard one.

By Thomas Geater· 4 August 2026 · 9 min read

The industry has converged on an answer to autonomous AI agents making payments, and the answer is called Know Your Agent. Give every agent a cryptographically secured identity. Let a merchant, processor or fraud system confirm before a transaction settles that the thing making the request is a registered, accountable entity rather than an anonymous bot wearing a costume, and then add authorisation scope, revocation, audit trails, governance dashboards where mandates and limits are managed centrally. By April of this year every major payment network had shipped or unveiled a primitive along these lines. The name echoes Know Your Customer deliberately, and the echo is doing a lot of work.

Sound engineering. Real problem. Easy half of the question.

Identity was never the part of this that was going to break. Financial services is extremely good at identity — verifying that a counterparty is who it claims to be is a solved problem with thirty years of infrastructure behind it, and extending that infrastructure to non-human actors is an incremental engineering exercise. What agentic payments threaten is quieter and much harder to retrofit: the behavioural baseline that every transaction monitoring system in the world is built on.

What monitoring actually does

Strip a monitoring estate down to its logic and it does one thing. It holds a model of what this customer’s activity is expected to look like — amounts, frequencies, counterparties, geographies, times of day, the shape of a normal month — and it fires when observed behaviour departs from that model far enough to be worth a human’s attention.

Everything else is refinement. Peer group analysis refines the expectation by comparing the customer to similar customers. Scenario libraries encode the departures that historically indicated something. Machine learning layers refine which departures are worth surfacing at all. But underneath every layer sits one load-bearing assumption: that the customer’s past behaviour predicts the customer’s future behaviour, because it is the same person doing it.

An agent transacting on a customer’s behalf breaks that by construction.

It does not spend the way its principal spends. Different latency, different granularity, different tolerance for repetition. Where a person consolidates — one weekly shop, one monthly subscription, one transfer when they remember — an agent optimises, and optimisation looks like more transactions, smaller, more frequent, spread across more counterparties, executed at whatever hour the price happened to be best. None of that is suspicious. All of it is a departure from the baseline. Point a monitoring estate tuned on human behaviour at agent behaviour and it will generate alerts describing a change in pattern with an entirely innocent cause, at volume, indefinitely.

So the firm widens the tolerances for customers who have delegated to an agent. Obvious response. Also where the risk enters, because a widened tolerance is widened for everybody who can reach it. Once an institution has decided that this account is expected to show high-frequency, low-value, geographically diverse activity, structuring — which hid inside human accounts for decades — has been handed a legitimate cover story at the level of the model rather than the level of the transaction.

The typology follows the velocity

The laundering risk in agentic finance is speed and volume, not sophistication.

Agents can execute large numbers of micropayments across many sites and many chains faster than compliance engines can monitor them, and that sentence contains the whole problem. The binding constraint is the review cycle, not the detection logic. A monitoring system that batches overnight and hands analysts a queue in the morning runs on a cadence designed for human transaction velocity. Placement and layering conducted at machine speed never has to defeat the rules. It only has to finish before anybody reads them.

Three adjacent mechanisms are worth naming, because they change what an investigation looks like rather than merely making it faster. Agents are vulnerable to prompt injection, where a malicious instruction buried in content the agent processes causes it to act against its principal’s interest, which in payments means redirecting funds to an attacker’s account. Malicious agents can impersonate legitimate trusted services inside agent discovery layers. Agents holding wallet access can exceed their intended scope and make repeated irreversible payments on-chain.

Read those as a financial crime analyst rather than a security engineer and something uncomfortable surfaces. Each one produces a transaction that is, at the moment of execution, properly authenticated and correctly attributed to a legitimate agent acting for a legitimate customer.

Know Your Agent passes all three. The identity layer confirms exactly what it was built to confirm. The money still leaves.

The objection: this is just a standing order with better marketing

The strongest argument against everything above is that automated payments are not new. Direct debits, standing orders, recurring card mandates and card-on-file arrangements have executed without a human present for decades, the monitoring estate absorbed all of them without conceptual crisis, and plenty of firms already hold accounts where most activity is machine-initiated. So why is this different?

Discretion. And UK payments law is where that stops being philosophical and becomes visible.

Under the Payment Services Regulations 2017, regulation 67 requires the payer to consent to a transaction, or to a series of which it forms part, in the agreed form and following the agreed procedure. A standing order fits comfortably: amount, payee and schedule are all fixed at the point of consent, and the automation executes a decision the customer already made. An agent is different in kind. It selects the counterparty. It selects the amount. It selects the timing. What the customer consented to was a delegation, and the live question on any given payment is whether it falls inside the authority delegated.

Not an academic question either. Regulations 76 and 77 allocate the loss when a transaction turns out to be unauthorised, with regulation 77 capable of imposing liability on the payer up to £35 in certain cases, or for the whole loss where there has been fraud or gross negligence. Whether those provisions bite depends first on whether the transaction was authorised under regulation 67 — so the delegation question decides who absorbs the money. Regulation 100’s strong customer authentication requirement sits awkwardly beside machine-to-machine execution, where how the user’s authority gets verified and recorded is precisely the unresolved part. The regulations do contemplate transactions initiated on behalf of a payer, which at least gives the framework somewhere to stand. Standing somewhere is a long way from having an answer.

The Treasury consultation closes on 6 October 2026, and its central question is whether the consent, authentication and liability rules need to adapt for agentic payments. Note what that says about the present. A UK firm processing agent-initiated payments today is operating inside a framework the government is actively asking whether it still fits.

Not a reason to panic. A reason to write your assumptions down now, because you will be asked to justify them later, and “the vendor said it was compliant” has never once worked.

Where Know Your Agent does earn its place

None of this makes KYA a bad idea. It makes it a necessary component mistaken for a sufficient one.

Cryptographic agent identity gives an investigation the one thing it would otherwise entirely lack, which is attribution. Without it, agent-initiated activity is indistinguishable from account takeover, and a firm staring at a burst of unusual payments has no way to separate delegated authority from compromise. With it, an analyst can establish which agent acted, under whose mandate, within what scope, and whether that scope was exceeded. Revocation matters for the same reason cancelling a card matters. Audit trails matter because a suspicious activity report has to describe what happened, and “the customer’s software did it” is not a narrative that survives review — I have written elsewhere about what makes a SAR narrative defensible, and every requirement on that list gets harder when the acting party is not a person.

So KYA is the foundation, and the building still has to go up on top of it. That building is a monitoring model that knows the difference between a customer and a customer’s agent, holds separate expectations for each, and does not quietly widen its tolerances to make the alerts stop.

What to actually ask

If your firm is anywhere near this, and if it offers consumer payments it will be within eighteen months, put three questions to whoever owns the monitoring estate. None of them need a technical background.

Can we tell, in the data, which transactions were agent-initiated? Not in principle. In the actual fields the monitoring system reads. If that flag doesn’t exist or isn’t populated, every model assumption downstream is being applied to a population it was not built for, and nobody can see it happening.

When a customer delegates to an agent, what happens to their baseline? If the answer is that the model relearns from the new activity, the firm has automated the business of normalising whatever the agent does — including whatever an attacker makes it do.

And who signs off the widened thresholds? The Nationwide finding, where a threshold was set high enough to suppress the alerts that should have been investigated, is the closest thing the sector has to a worked example of how this fails. It required no agent, no model, no AI of any kind. It required somebody to set a number and nobody to own it.

The technology is new. That particular failure is not.

Agentic AITransaction MonitoringPayment Services RegulationsKYCAI & Compliance

Written by

Thomas Geater

I write The Typology Files, on financial-crime compliance and what generative and agentic AI are doing to it. BSc Business Management with Finance, University of Brighton. I work independently and take on advisory and writing engagements.

New pieces by email

One email when something new goes up

No schedule, no digest, no marketing. A piece goes up roughly every couple of weeks and you get one line and a link. Your address is stored by the form handler and used for nothing else. Unsubscribe by replying once.