What is Know Your Agent (KYA), and how can financial institutions solve for it?

A practical guide for financial institutions and fintechs to verifying AI agents, from detection and delegation to the controls that keep them in bounds

Know Your Agent (KYA) is a verification framework for establishing the identity, authorization, and accountability of AI agents that act on behalf of customers or businesses when interacting with financial institutions. Think of the AI assistant that pays down a credit card balance twice a month, moves money into savings accounts, or acts as a personal shopper and price tracker. As AI agents increasingly open accounts, initiate transactions, and access sensitive customer data, traditional identity verification built for a human at a keyboard is falling short. For financial institutions and fintechs, the question is shifting from "is this a bot?" to "what should this agent be allowed to do, for whom, and right now?"

This guide covers what Know Your Agent means for compliance officers, risk strategists, and fintech builders: how it differs from Know Your Customer (KYC) and Know Your Business (KYB), when KYA comes into play, and how to build agent verification controls that fit existing regulatory guidance without creating unnecessary friction for the customers who use agents.

What is Know Your Agent (KYA)?

Know Your Agent (KYA) is the process of verifying and managing the identities of non-human agents (bots, AI systems, and automated processes) acting on behalf of customers or businesses. The framework extends traditional identity verification principles to agentic entities whose permissions can shift across sessions and tasks.

An agent isn't a new identity to verify from scratch. It's a delegation from a customer you already know. That changes the job. As Tommy Nicholas, Alloy's CEO and co-founder, put it in his look at AI trends reshaping financial services, the questions become: who authorized this action, what is this agent allowed to do, and should it be allowed to do it right now?

Verifying a human is hard enough (ask anyone who has chased a synthetic identity). Verifying an agent adds a second layer: you have to know the human customer, the agent acting for them, and how the two connect.

The rise of agentic commerce has exposed real gaps in legacy identity and fraud tech stacks. Traditional verification assumes a human is present and relies on signals like biometrics, behavioral detection, or device recognition. Agents work differently. They may be authorized for narrow tasks in one session and broader tasks in another, which demands dynamic entitlements and session-aware decisioning that legacy systems were never built to handle.

Alloy CEO Tommy Nicholas noted in a recent blog that many of the financial services leaders he speaks with feel unprepared. Customers are feeling cautious too. A Gartner survey cited in Mastercard's August Signals report found that only 10% of consumers would let an agent complete a purchase on its own, even though 74% are open to agents handling specific tasks when asked. 

Customers will give agents more authority as they come to trust the guardrails, and the institutions that can show those guardrails work will earn that trust first.

A successful login also proves less than it used to. Authenticating a customer at the time of login doesn’t have to mean you extend unconditional trust. An agent can pass every credential check and still be talked into something its owner never asked for, for example, by instructions hidden on a webpage it visits.

KYA gives institutions a structured way to handle this at login and at every interaction after it: confirming the agent's identity, tracing its authorization back to a responsible human or business, enforcing limits on what it can do, and checking whether its behavior still makes sense.

KYC vs. KYA: understanding the key differences

The core difference comes down to what is being verified. KYC verifies people. KYA verifies agents and the people they act for, and an agent's permissions change with each session, task, or principal.

KYC is a well-established regulatory requirement: financial institutions must verify individual customers before establishing a business relationship. KYB extends that logic to corporate entities, their ownership structures, and beneficial owners. Both frameworks assume a relatively stable identity that can be verified once and monitored over time.

Agents do not fit that model. The same agent might be cleared to check balances on Monday and asked to pay a new vendor on Tuesday.

Chart in line know your agent

 

The first question in any session becomes: is this the customer, or an agent acting as an intermediary for them? If it's an agent, the institution needs to know who it represents and what authority it holds.

Risk-based authentication underpins effective KYA by letting institutions calibrate verification requirements to the customer or agent's risk profile, the sensitivity of the requested action, and the context of the session. A bank might be comfortable letting an agent read balances but not initiate a wire transfer. Routine requests flow through while risky ones get a step-up check that requires a human to intervene.

When does KYA apply to financial institutions?

KYA comes into play whenever an AI agent accesses customer accounts, initiates transactions, or acts on behalf of another person or business within a financial institution's systems.

KYA is not yet officially regulated as a distinct, standardized regulatory framework like KYC and AML obligations. But existing banking guidance provides a foundation for it. Joint FFIEC guidance, also issued by the Federal Reserve, on authentication and access to financial institution services sets an expectation for non-human access that could extend to agents: institutions are responsible for appropriate controls over customer information and transaction capabilities, regardless of whether access comes from a human customer or an agent acting on their behalf.

Several scenarios raise KYA questions:

AI agents performing autonomous actions 

When an AI agent opens an account, initiates a payment, or accesses customer data, the institution must verify the agent's identity, confirm its authorization, and establish accountability back to a responsible principal.

Consumer agents in digital banking

Customers are already connecting personal AI assistants to their accounts, mostly for read-only insights today. As they ask those agents to move money, every agent-initiated action needs a clear, traceable link back to the person who authorized it.

Third-party integrations and API access 

Partners, vendors, and platforms connecting to financial institution systems through APIs may deploy agents that require KYA controls.

Delegated authority scenarios 

When customers grant power of attorney, authorize family members to manage accounts, or delegate transaction authority to financial advisors, institutions must verify the scope and validity of that delegation. Financial institutions already know how to do this for people. KYA applies the same logic to software that acts at machine speed.

The fraud risks of inadequate agent verification are concrete. Without KYA controls, bad actors can exploit agent access channels by compromising a legitimate agent, deploying unauthorized AI agents that bypass traditional authentication, or pairing agent access with classic account takeover (ATO) tactics like SIM swapping. Static checks don't slow a compromised agent down much, either. If it holds valid credentials, it can get past a one-time passcode faster than any fraud team can react. Unlimited access for an agent means unlimited access for whoever compromises it. 

Three ways AI agents access financial accounts

How an agent connects to a financial institution shapes what the institution can see and how much risk the agent carries. Most agent activity today falls into one of three access models.

Local browser and computer use 

The customer hands an agent their login credentials, and the agent operates the banking website or app the way a person would, clicking, typing, and navigating. Anthropic's computer use is one example. To the institution, that session can look almost identical to the customer's own. Device and behavioral signals can help flag agent activity, but attributing the activity to a particular authorized agent is difficult. 

Access through an intermediary

The agent connects through an intermediary, often a Model Context Protocol (MCP) server, which is the standard way many AI agents plug into outside tools. The customer authenticates once through an open banking connection, and from then on the agent acts through API calls. The institution’s visibility into the agent depends on how the intermediary passes along identity and authorization information. 

Direct, first-party agent connections

A financial firm can expose its own APIs or MCP servers for agent connections. The institution has greater control over how agents authenticate and what they can access.

The key question is the same across all three methods: can the financial institution distinguish the agent from the customer, and determine what the agent is authorized to do right now?

Core components of a KYA framework

Verifying agents requires a multi-layered approach: detect the agent and who it belongs to, validate its authority, restrict it to what it's permitted to do, and watch how it behaves for the whole session.

Detection and identity

Start by detecting that an agent is present at all. Then validate a digital identity, confirm the deployment source, and verify cryptographic credentials or tokens that establish authenticity. Agent detection is still maturing, so treat it as one signal among many rather than a single gate.

Authorization chain validation 

Authorization chain validation traces the agent's authority back to a responsible principal. Who authorized this agent to act? What scope was granted? Is that authorization still valid? For AI agents, this may involve checking a signed agent credential or similar token that documents permissions and the principal the agent represents.

Behavioral baselining 

Learn what normal looks like for the agent, separately from its human. An agent that checks balances every morning and suddenly tries to add a new payee at 3 a.m. deserves a closer look, even if its credentials are valid.

Scope enforcement 

Scope enforcement keeps agents within their authorized limits. An AI agent cleared to view account balances should not be able to initiate wire transfers. An AI agent authorized to schedule payments should not be able to modify account ownership. Set programmable boundaries on what an agent can spend, on what, and for how long. Dynamic entitlements and session-aware decisioning let institutions enforce these boundaries in real time.

Human in the loop for high-risk actions 

When an agent tries something high-risk, bring in a person. This includes logging all agent activities, flagging anomalous behavior for review, and enabling human intervention when agents exceed their authorized scope or encounter edge cases. Agent assist tools can route those moments to your team with the context they need to decide quickly.

Identity verification across the customer lifecycle provides foundational capabilities that extend to agent verification. The same principles of data validation, behavioral monitoring, and risk assessment apply, adapted for the unique characteristics of agent identities.

Evaluating KYA solutions: a framework for compliance and risk teams

Fraud and risk teams should evaluate KYA solutions against three core criteria: integration flexibility, dynamic authorization capabilities, and audit and accountability features.

Integration flexibility determines whether a KYA solution can connect with existing identity verification tools, fraud detection systems, and authentication infrastructure. Look for two things. First, an orchestration layer that unifies multiple verification tools into one workflow. Agent identity signals will come from many places (card networks, agent platforms, and your own session data), so the ability to pull them together matters more than any single signal. Second, a solution that complements your existing tech stack, including your CIAM, instead of forcing a rip-and-replace. 

Dynamic, risk-based authentication capabilities past the point of login are essential because agent permissions are not static. Solutions must support session-aware decisioning that evaluates agent entitlements in real time based on context: the specific action requested, the customer involved, the risk profile of the customer or agent, and any changes in the agent's authorization status since the session began. When high risk is detected, trigger a challenge commensurate to the amount of risk presented instead of simply allow/blocking. 

Audit and accountability features ensure that every agent action is logged, traceable, and attributable to both the agent and its principal. Risk teams need audit trails that document what agents did, when they did it, what authorization they held, and who bears responsibility. These records are essential for regulatory examinations, fraud investigations, and internal controls.

Implement KYA with confidence using Alloy

Alloy approaches KYA as an extension of risk-based authentication. An agent is another actor in a session, so the infrastructure that helps you know your customers can help you understand the agents acting for them.

With Alloy, financial institutions and fintechs can manage customer, session, and authorized agent risk together:

  • Orchestrate identity, device, behavioral, and agent signals from our network of 270+ data partners in a single workflow.
  • Make session-aware decisions about behavior after login, in addition to identity at the door.
  • Dynamically respond to risk: monitor, restrict, step up to document and selfie verification, or route to a human as an agent's risk score climbs.

Agent standards are still taking shape, and we're building alongside the institutions working through them. More than 900 financial institutions and fintechs already trust Alloy to accelerate onboarding, stop fraud, and scale compliance across the customer lifecycle. KYA is the next place that work goes.

Dive deeper

FAQs

Know Your Agent (KYA) is a verification framework for establishing the identity, authorization, and accountability of AI agents that interact with financial institutions on behalf of customers or businesses. It matters because traditional identity verification was designed for human users, not for AI agents that autonomously open accounts, initiate transactions, and access sensitive data. KYA answers three questions: who authorized this action, what is this agent allowed to do, and should it be allowed to do it right now? Financial institutions without KYA controls face increased fraud exposure, regulatory scrutiny, and operational risk as agentic commerce expands.

KYC verifies individual human customers, KYB verifies business entities and their ownership structures, and KYA verifies agents acting on behalf of those customers or businesses. An agent isn't a new identity. It's a delegation from an existing one. That's why their permissions and authorization scope may change by session, task, or principal, requiring continuous validation rather than one-time verification. KYA also establishes the principal-agent relationship, confirming who authorized the agent and what actions it is permitted to perform.

A KYA verification process checks five core elements: the agent's identity (confirming the agent is who or what it claims to be), authorization (validating that a legitimate principal granted the agent permission to act), principal accountability (establishing who bears responsibility for the agent's actions), scope (enforcing boundaries on what specific actions the agent can perform in the current session or context), and behavior (whether the agent's activity still matches what its owner would expect). For AI agents, this may include validating cryptographic credentials or signed agent credentials that document permissions.

KYA is not yet a codified regulatory requirement in the way that KYC and AML obligations are mandated by law. However, existing regulatory guidance from the FFIEC and Federal Reserve on authentication and access control establishes risk-based expectations that reasonably apply to any entity (human or automated) accessing financial institution systems and customer data. Institutions should treat KYA as an emerging best practice that aligns with current regulatory principles, positions them for future requirements as agentic commerce grows, and protects their customers and themselves from fraud.

Financial institutions can implement KYA without operational disruption by using orchestration platforms that integrate with existing authentication and verification infrastructure rather than replacing it. Risk-based approaches allow institutions to apply appropriate verification intensity based on the agent's risk profile and the sensitivity of the requested action, avoiding unnecessary friction for low-risk interactions. Let an agent check a balance without a hitch, and save the step-up for a new payee or a large transfer. Testing workflow changes before deployment helps teams measure impact on approval rates and customer experience before new rules go live.

Without KYA controls, financial institutions face risks including unauthorized access to customer accounts through compromised agent credentials, manipulation that turns a legitimate agent against its owner, fraudulent AI agents impersonating legitimate services, and an inability to establish accountability when agent actions result in losses or compliance violations. The lack of audit trails for agent activities also creates regulatory examination risk, as institutions may be unable to demonstrate appropriate access controls over customer data and transaction capabilities.

The term KYA is mostly used for AI agents. Human intermediaries, like customer service agents, financial advisors, and people holding power of attorney, are the older version of the same problem. Financial institutions already verify them through employment credentials, role-based access controls, and documented authority. KYA borrows that logic and applies it to software that acts at machine speed and can change what it's doing mid-session. The principles (identity, authorization, principal accountability, and scope) carry over. What's new is how often you have to check them.

See what you’re missing

First, we’ll learn about your needs, answer your questions, and then see how Alloy can help.
Back