Policy
Visa and Mastercard Will Accept an Agent That Ant Already Cleared
Three companies that do not usually agree on anything announced a shared "Know Your Agent" framework in São Paulo. What they published was an intention: no specification, no governance body, no date. The hard question — who pays when a credentialed agent does the wrong thing — was not on the slide.
On September 10, in São Paulo, Ant International, Visa and Mastercard said they would build a common way to identify AI agents that spend money. They called it a Know Your Agent framework — KYA, the deliberate echo of know-your-customer — and the idea is interoperability: an agent vetted by one participant should not have to be vetted again by the next.
Jiang-Ming Yang, Ant International's chief innovation officer, put it plainly, as quoted by Forkast: "Trust is the foundation of the AI transformation. If an agent registers with Ant, they don't need to register again with Visa, Mastercard."
That sentence is the entire news. Two card networks and the operator of Alipay+ have agreed, in principle, to honor each other's homework on a question none of them has finished answering.
Three passports, one corridor
The agreement is not a new standard so much as a treaty between three existing ones. Each company arrived with its own scheme already built: Visa's Trusted Agent Protocol, Mastercard's Verifiable Intent, and Ant International's Agentic Mobile Protocol, which launched in April and has been rolling out across the Alipay+ ecosystem — ten wallets and seven acquirers, per TNGlobal.
Left alone, three protocols means every agent platform and marketplace builds three integrations, and every small merchant picks a side. The framework's stated ambition is to let each participant keep its own verification and risk controls while agreeing on shared principles for recognizing agents the others have already cleared. Its named focus areas are cross-network operator traceability, shared certification requirements, and continuous transaction monitoring.
The other two executives said versions of the same thing. Pablo Fourez, Mastercard's chief digital officer: "Interoperability across Know-Your-Agent frameworks is essential to making agentic commerce work at scale." Rubail Birwadker of Visa: "Without trusted identity and explicit permissioning, AI agents cannot participate in commerce at scale." Both quotes are via Forkast.
The number underneath all of it is McKinsey's: $3 trillion to $5 trillion of global consumer commerce orchestrated by AI agents by 2030. Treat that as a projection with a marketing job to do, not a measurement. It is, however, the figure that explains why three rivals stood on the same stage.
What was announced, and what was not
| Element | Status as of Sep 11 |
|---|---|
| Intent to interoperate | Announced, three parties |
| Underlying protocols | Three, already shipping separately |
| Technical specification | Not published |
| Governance body | Not named |
| Rollout timeline | Not disclosed |
| Liability allocation | Not addressed publicly |
Identity is the easy half
Know-your-customer works because a customer is a durable legal person who can be sued, fined or jailed, and whose identity does not change between Tuesday and Wednesday. An agent is a process. It is instantiated, it runs with a set of permissions, and the interesting question is almost never "which software is this." It is "is this software still doing what its operator told it to."
A credential answers the first question. It cannot answer the second, and the framework's own third pillar quietly concedes as much: continuous transaction monitoring is what you build when you know the credential at the door will not stay true for the length of the session.
This is not a hypothetical worry on this beat. As we reported today, a 9.4-rated flaw in a widely used agent harness let a confined agent flip its own permissions to full access with one shell command — and the system logged the change as though the human operator had made it. An agent in that state is still, by every credential it carries, the same agent. The passport is genuine. The holder has changed.
The word nobody said
Neither the announcement nor the coverage of it addressed liability. That is the question every merchant, issuer and regulator will ask second, and it is genuinely hard: when an agent that Ant credentialed and Visa accepted makes a payment its owner did not intend, the loss lands somewhere, and mutual recognition means it lands across a border between three companies' risk models.
Card networks have solved this shape of problem before — the chargeback system is, underneath, a two-decade negotiation about who eats fraud. But those rules were written after the fraud, not before it, and they took years. Announcing that credentials will be portable before deciding whose balance sheet absorbs a portable mistake is the sort of sequencing that tends to get revisited under pressure.
Where the work actually happens is worth noting: development is proceeding through BuildFin.ai, an industry platform convened by Singapore's Monetary Authority. A regulator-convened venue is a meaningfully better home for this than a press release, and it is the detail that separates this from the agent-standards announcements that have come and gone this year. It is also, so far, the only piece of governance anyone has named.
Why it matters here
Because this framework is being built for the same agents that this industry is handing wallets and exchange sessions to. The direction of travel all year has been toward autonomous software that holds value and signs for it. Identity infrastructure for that software is overdue and this is a serious attempt at it, from three parties with enough combined reach to make a de facto standard stick.
The gap to watch is between what a KYA credential proves and what people will assume it proves. It proves an agent was registered by somebody who checked something. It does not prove the agent's sandbox held, that its instructions are its owner's, or that the session that started clean is still clean. Those are different guarantees, and the announcement did not claim otherwise — but the shorthand will.
The Take
Take the announcement for what it is: three competitors agreeing to stop building three separate moats, which is real and unglamorous and better than the alternative. Then hold them to the parts they skipped. A standard is a specification, a governance body and a date; this is currently none of those, and the industry has a long record of shipping the press release and quietly abandoning the spec. The specific thing to watch for is whether the published framework distinguishes identity from control — whether a credential can be revoked mid-session, and what happens to in-flight authority when it is. If KYA ends up certifying who an agent was at registration and nothing about what it is doing now, it will have built a very expensive way to be confidently wrong.