Ant International, Mastercard and Visa have begun work on a shared Know-Your-Agent framework so payment systems can recognise trusted AI agents across card and wallet networks without surrendering their own risk decisions. Announced on 10 September 2026, the collaboration is a standards effort—not a finished payment product—and will proceed through Singapore’s BuildFin.ai industry platform.

Everyone else is reporting that three payments groups agreed to collaborate; we are explaining why the difficult part is not recognising a bot once, but preserving accountable consent as that bot crosses different rails, wallets and merchant systems.

What the Know-Your-Agent framework actually proposes

The joint statement describes a common layer of trust signals for AI agents that recommend and eventually complete purchases. An agent linked to a validated operator, cardholder or organisation could carry evidence of that relationship into another participating ecosystem, reducing repeated onboarding work while leaving the receiving network free to accept, challenge or reject it.

That distinction matters. Interoperability does not mean Visa, Mastercard and Ant International will merge their identity systems. It means they intend to explore common principles that let one system understand another system’s assertions about who controls an agent, what it is certified to do and how its behaviour is being monitored.

Know-Your-Agent collaboration facts
Element Verified position on 10 September 2026
Participants Ant International, Mastercard and Visa
Purpose Cross-network AI-agent onboarding and identification
Core controls Operator traceability, certification requirements, continuous monitoring
Coordination venue BuildFin.ai, convened by the Monetary Authority of Singapore
Product status Collaboration and framework exploration; no commercial launch date disclosed

How Know-Your-Agent trust signals could travel across networksThree payment networks send operator, certification and monitoring signals into a shared recognition layer while each network keeps its own final risk decision.Portable trust, local decisionsOperator traceabilityAgent certificationOngoing monitoringRecognised trust signalsEach network still approves or declines

Why three existing protocols need a bridge

All three organisations entered the project with their own architecture. Visa has Trusted Agent Protocol, Mastercard has Verifiable Intent and Ant International has Agentic Mobile Protocol. Those approaches can each bind a transaction to an agent and a user mandate inside their own environments, but merchants and platforms face duplicated integration if every network expresses identity and consent differently.

A shared Know-Your-Agent vocabulary could make an assertion portable without making it unquestionable. In practical terms, a merchant gateway might receive a signal that an agent was registered by a known operator, passed defined security checks and remains within a permitted behavioural envelope. The gateway would still combine that signal with transaction context, fraud controls and its own policy.

This is closer to federation than a universal identity card. Federation can reduce repetitive checks, but it also requires clear rules for revocation, freshness and provenance. If an agent changes its model, tools or operator, a certification that was valid yesterday may no longer describe today’s risk.

The framework’s three control layers

Operator traceability

The first layer links an agent to a validated person or organisation. Traceability is the foundation for accountability because a merchant needs to know whose authority the software is exercising. The joint release does not say that an AI model itself becomes the legal customer; it says agent activity should remain attributable to an operator, cardholder or business.

Shared certification requirements

The second layer concerns security and behavioural expectations. Certification could give networks a common way to describe whether an agent follows a mandate, protects credentials and exposes enough evidence for a transaction to be reviewed. The partners have not published a test suite, assurance level or certificate format, so those questions remain implementation work rather than settled standards.

Continuous transaction monitoring

The third layer recognises that a one-time check is not enough. The partners say agents should be evaluated continuously using identity and transaction-related signals. That design is important because an agent can begin in a trusted state and later behave outside the pattern its operator intended, whether through a compromised tool, a changed workflow or an ambiguous instruction.

The accountability chain in an agentic paymentA user mandate passes to an identified agent, through network controls and to a merchant decision, with monitoring feeding back across the chain.Accountability must survive every handoffUser mandateIdentified agentNetwork controlsMerchant decisionContinuous monitoring and revocation feedback

What BuildFin.ai adds

The work will be advanced through BuildFin.ai, an industry platform convened by the Monetary Authority of Singapore. That connection grounds the collaboration in a broader financial-sector effort rather than leaving it as a bilateral technical experiment. The partners also say the work builds on Singapore’s Safeguards for Agentic Finance at Runtime framework.

Regulatory convening can help surface questions that product teams might otherwise postpone: who bears loss when an agent exceeds a mandate, how quickly a compromised identity must be revoked, and what evidence is retained for disputes. BuildFin.ai does not automatically answer those questions, but it creates a place where financial institutions, technology providers and researchers can test common approaches.

For India and other wallet-heavy markets, the Ant International dimension is especially relevant. Its Alipay+ network connects card alternatives and local wallets across multiple markets. A framework that recognises both card-network and wallet-network trust signals could reduce the risk that agentic commerce develops as separate regional islands.

What merchants and developers should watch

The immediate value is architectural, not consumer-facing. Platforms building shopping agents should watch whether the partners publish machine-readable claims for identity, mandate and certification; merchants should watch how those claims fit with existing bot controls, payment authentication and dispute evidence.

Developers should also separate “recognised” from “authorised.” Recognition can say that a known provider vouched for an agent. Authorisation must still establish that the user approved this purchase, at this merchant, under the relevant amount and timing limits. Treating recognition as blanket authority would recreate the very accountability gap the framework is meant to close.

The collaboration follows other agentic-payment experiments, including a Visa and Revolut passkey-based agentic payment test and PhonePe and Visa’s cardless payment tools. Those projects show individual transaction paths; the Know-Your-Agent framework addresses the common trust layer that could let more paths interoperate.

What remains unresolved

The announcement does not publish a technical specification, governance body, certification auditor, pilot merchant or deployment date. It also does not define liability when one network accepts another network’s signal and the transaction later proves unauthorised. Those omissions are normal for the opening of standards work, but they are the tests that determine whether interoperability becomes infrastructure or remains a statement of intent.

Privacy will be another constraint. Portable accountability signals must carry enough information to support risk decisions without exposing unnecessary personal or behavioural data across networks. A useful design will need selective disclosure, clear retention limits and a way to distinguish an agent’s operator from the end customer when they are not the same entity.

A practical test for the eventual specification

A future specification should let a merchant answer a short series of questions without trusting a marketing label. Who registered the agent? Which person or organisation controls it? What category of action was certified? When was the evidence issued? Has the agent’s software, operator or risk status changed since then? Which network made each assertion, and can another participant verify the assertion without receiving unrelated personal data?

Those questions suggest that the useful object is not one permanent badge. It is a bundle of time-bound, signed claims whose scope can be checked at the moment of payment. One claim might establish the agent operator, another the software version, and another the user mandate for a specific purchase. Networks could recognise the format and provenance of those claims while continuing to apply different thresholds.

Revocation has to travel as reliably as approval. If an operator loses a credential, an agent is compromised or a certification expires, every participant that previously recognised the signal needs a timely way to stop relying on it. Continuous monitoring is meaningful only when adverse information can change a transaction decision before money moves.

Dispute evidence will be equally important. A cardholder, wallet user, merchant and issuer may each see a different slice of an agentic transaction. The framework will need to preserve enough information to reconstruct the mandate and the agent’s actions without storing an unrestricted conversation transcript. That balance between auditability and data minimisation is a design requirement, not a later privacy feature.

Finally, the partners will need to define how smaller wallets, merchants and agent developers participate. An interoperable standard creates the most value when it lowers integration cost beyond the founding companies. If certification is expensive or governance remains closed, the framework could merely add another gate. Open technical documentation, test environments and proportionate assurance levels would be signs that the collaboration is becoming shared infrastructure.

The concise answer: the Know-Your-Agent framework is an attempt to let payment networks recognise common evidence about an AI agent’s operator, certification and behaviour while keeping final transaction control local. Its success will depend less on the headline partnership than on whether the three participants publish enforceable rules for consent, revocation, privacy and liability.

Frequently asked questions

What is Know-Your-Agent?

Know-Your-Agent is a proposed trust framework for identifying AI agents, linking them to validated operators and monitoring how they behave when they initiate payment activity.

Did Ant International, Mastercard and Visa launch a payment product?

No. They announced a collaboration to explore interoperable principles. No consumer product, technical specification or commercial launch date was disclosed.

Will one network control every AI agent?

No. The joint statement says each network will preserve its own verification and decisioning processes while exploring recognition of shared trust signals.

Why does the Singapore regulator matter?

The work will proceed through BuildFin.ai, which is convened by the Monetary Authority of Singapore and brings financial institutions, technology providers and researchers together around responsible AI in finance.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.