From KYC to KYA, Is It Time to Give AI Agents Their Own 'ID Cards'?

marsbitPublished on 2026-05-10Last updated on 2026-05-10

Abstract

Titled "From KYC to KYA: Is It Time to Issue 'Identity Cards' for AI Agents?", this article discusses the emerging concept of Know Your Agent (KYA) as AI agents become increasingly autonomous. In Agent-to-Agent (A2A) scenarios, where agents execute contracts, payments, and trades without human intervention, the lack of a shared identity standard creates risks like unauthorized transactions, fraud, and accountability gaps. KYA acts as a trust layer to verify an agent's origin, authority, and accountability. The need for KYA is most critical outside centralized platforms (like Google or Coinbase), such as in decentralized exchanges (DEX), A2A payments, and merchant payments. Several key players are building KYA infrastructure: - **ERC-8004**: A proposed Ethereum standard that issues a unique AgentID as an NFT, building on-chain identity, reputation, and validation systems. - **Visa TAP**: Visa's solution issues agent identity credentials, with transactions verified via triple signatures (legitimacy, delegator, payment method). - **Trulioo**: Extends its KYC/KYB compliance infrastructure using a Digital Passport for Agents (DAP), issued after verifying both the developer and user, and refreshed per transaction. - **Sumsub**: Focuses on post-issuance real-time verification, detecting agent anomalies during transactions using its existing compliance systems. Regulatory bodies are also acting. The EU AI Act mandates operator identification in logs for high-risk AI systems, the US...

Authored by: Tiger Research

Compiled by: AididiaoJP, Foresight News

The era of AI agents is accelerating, and alongside it, concerns about the uncontrolled creation and behavior of agents are growing. Know Your Agent (KYA) systems, which assign identities to agents and regulate their behavior, are receiving increasing attention. Why is a KYA identity infrastructure needed? Which companies are building it?

Summary

  • AI agents have entered an era of autonomously executing contracts, payments, and transactions, but there are currently no shared standards to verify "who this agent is." In Agent-to-Agent (A2A) scenarios, KYA is gaining more focus than KYC.
  • KYA is not needed in all scenarios. Within centralized platforms (Google, OpenAI, Coinbase), existing KYC is sufficient. Where KYA truly becomes important is in scenarios where independently deployed autonomous agents interact with DEXs, A2A payments, and merchant payments.
  • The KYA standards race has begun:
  • ERC-8004: Issues AgentIDs on top of NFTs, building an on-chain system for identity, reputation, and verification.
  • Visa TAP: Visa issues identity credentials for agents, verified through TAP's triple signature (legitimacy, delegator, payment method).
  • Trulioo: Adopts the SSL CA model, with DPAs issuing DAPs.
  • Sumsub: Layers a KYA system on top of its own compliance system.

Regulatory action has begun at the national level. The EU's AI Act requires high-risk AI system behavior logs to include operator identity. The US NIST has listed agent identity management as a priority standard area. Singapore has released the world's first national-level AI agent governance framework. Just as the 2019 FATF Travel Rule determined which crypto exchanges survived, whether one possesses KYA infrastructure will determine who enters the next market cycle.

Why is KYA Emerging Now?

KYC: The Layer That Reshaped Finance

  • Before 1989, global finance lacked a unified identity standard. This gap made it difficult to track drug money and illicit funds.
  • After the FATF was founded in 1989, KYC became a mandatory requirement in finance, blocking illicit funds at the entry point.

Without Agent Identity, Systems Regress

  • AI agents execute contracts, payments, and transactions without human involvement, but currently, it's impossible to verify "who it is."
  • In A2A environments, accountability becomes blurred, dispute risks increase, and users are exposed to fraud patterns like money laundering.

The Role and Response of KYA (Know Your Agent)

  • KYA (Know Your Agent) is a trust layer that pre-verifies an agent's origin, permissions, and accountability framework.
  • Unverified agents bring three major risks simultaneously: unauthorized transactions, fraud, and accountability gaps.

The Manifestation of KYA's Necessity

KYA is Needed at Every Level

  • Within centralized platforms, user KYC + platform accountability is sufficient. In interoperable scenarios outside platforms, KYA becomes crucial for verifying an agent's specific actions and safety.
  • Within a country (inside a platform), one ID (KYC) is enough to move freely. But once crossing borders (outside a platform), the environment changes, and entry review (KYA) of purpose and trust is needed.

Market Players

ERC-8004: NFT-Based Agent Identity

  • ERC-8004 adds an identity layer on top of ERC-721, minting an NFT as a unique ID for each agent.
  • It also adds three on-chain registries (Identity, Reputation, Validation), serving as identity, reputation board, and verification record respectively.

Two Markets Built by Ethereum Standards, a Third is Coming

  • ERC-20 (Token Issuance Standard): Before standardization, every token needed brand-new code. After ERC-20, most major assets were issued on it.
  • ERC-721 (NFT Standard): CryptoPunks, BAYC, ENS built the NFT market itself upon it. As blockchain integration accelerates in the agent era.
  • ERC-8004 will play the same standardizing role for Agents.

Visa TAP: Authentication on the Visa Rail

Visa issues identity credentials (Agent Intent) to agents, akin to an identity card. Without a key, transactions cannot occur. Keys are issued only after Visa pre-approval. Every transaction is signed and submitted to the merchant.

The merchant receives three signatures, not one: Visa approval, delegator, payment method, all confirmed simultaneously.

Visa: A Strategy to Pull Every Transaction into the Visa Network

  • Just as Visa previously captured payment rails, it is now encapsulating the agent era.
  • Through Visa Intelligent Commerce (VIC), Visa offers a solution bundle that packages KYA with payments.
  • If agent payments still use the card rail, and this bundle becomes the default option, then Visa's market share can remain stable even through the transition.

Trulioo: Extending KYC-Era Verification Infrastructure

  • Trulioo is a compliance operator on the global KYC/KYB rail and is expanding its verification stack to KYA.
  • DPAs play the role of SSL-CAs. Unlike SSL (domain only), DPAs verify developer KYB and user KYC before issuing a DAP.
  • Banks and fintechs legally require human and business identity. As agents enter finance, Trulioo's KYC/KYB position will be further solidified.

DAP, an Agent's Digital Passport, Refreshed with Each Transaction

  • DAP is an agent's digital passport. A DPA verifies the developer (KYB) and user (KYC), packages both into a token, and grants it to the agent.
  • Unlike a paper passport, it is a live token, refreshed and re-verified with every transaction. Once delegation is revoked or anomalies are detected, the DAP is invalidated immediately.
  • KYA is not a one-time verification. Trust must be reconfirmed with every transaction.

Sumsub (AI Agent Verification): Detecting Agent Anomalies

  • Sumsub's approach is: whenever an agent attempts an anomalous transaction, re-verify the currently active human identity.
  • It leverages its verification systems from its compliance business since 2015 to detect agent anomalies more accurately.

Operators with Technology to Address New Threats of the AI Era

  • Other KYA players focus on one-time pre-transaction identity verification. Sumsub focuses on real-time verification post-issuance.
  • As agent permissions expand, anomaly detection becomes crucial; as fraud scales with technology, Sumsub's real-time verification stack gains attention.

Proactive Regulatory Positioning, Shaping Entry Rules

The Gap Caused by the FATF Travel Rule May Recur with KYA

After the 2019 FATF Travel Rule, VASPs diverged based on their ability to bear KYC/AML infrastructure costs. Peers like CryptoBridge and Deribit, unable to afford it, either shut down or moved to less regulated regions.

The EU, Singapore, and the US are already vying for leadership. KYA will become a core layer of the agent era.

KYA Will Differentiate by Market Segment, Not a Single Winner

The real variable in the standards race is not technology, but combinations. Mainstream players have entered the collaboration and combination phase. In the future, who pairs with which merchants, payment networks, and KYC customer bases will determine the leader in each segment.

The market will not have a single winner; it will differentiate by market segment.

Related Questions

QWhat is KYA (Know Your Agent), and why is it emerging as an important concept in the AI agent era?

AKYA (Know Your Agent) is a system designed to verify the identity, authority, and accountability of AI agents, especially in scenarios where they operate autonomously without direct human oversight. It is emerging as a crucial trust layer due to the rise of AI agents that autonomously execute contracts, payments, and transactions. In these Agent-to-Agent (A2A) environments, there is currently no shared standard to verify 'who the agent is,' leading to increased risks like unauthorized transactions, fraud, and accountability gaps. KYA addresses these risks by establishing a trust infrastructure for pre-verifying an agent's source, permissions, and purpose.

QWhat are some key standards and solutions being developed for KYA?

ASeveral standards and solutions are being developed for KYA. Notable examples include: 1) **ERC-8004**: An Ethereum-based standard that uses NFTs (ERC-721) as unique AgentIDs and adds on-chain registries for identity, reputation, and validation. 2) **Visa TAP (Triple Authorization Protocol)**: Visa's solution that issues identity credentials (Agent Intent) to agents and requires triple signatures (from Visa, the delegator, and the payment method) for transaction approval. 3) **Trulioo's DAP**: Extends their KYC/KYB infrastructure to issue a dynamic Digital Agent Passport (DAP) that is re-validated per transaction. 4) **Sumsub (AI Agent Verification)**: Focuses on post-issuance, real-time verification of agents to detect and prevent abnormal behavior using their existing compliance stack.

QIn what scenarios is KYA most necessary, according to the article?

AAccording to the article, KYA is most necessary outside of centralized, walled-garden platforms (like Google, OpenAI, or Coinbase), where traditional user KYC and platform accountability are sufficient. KYA becomes critical in scenarios involving independent, autonomously deployed agents interacting across platforms, particularly in: 1) **Agent-to-Agent (A2A) transactions** (e.g., payments between agents). 2) **Accessing decentralized exchanges (DEXs)**. 3) **Making payments to merchants**. These represent interoperable environments where a lack of agent identity verification creates significant operational and financial risks.

QHow are governments and regulatory bodies responding to the need for AI agent identity management?

AGovernments and regulatory bodies are beginning to act on AI agent governance, effectively pushing the need for KYA infrastructure. Key actions include: 1) **The EU AI Act**: Requires operators of high-risk AI systems to be identifiable in activity logs. 2) **US NIST**: Has prioritized AI agent identity management as a key standard-setting area. 3) **Singapore**: Released the world's first national-level AI governance framework specifically for agents. The article draws a parallel to the 2019 FATF Travel Rule, suggesting that the ability to implement compliant KYA systems will be a determining factor for which entities can participate in the next phase of the AI agent market.

QWhy does the article suggest the KYA market will be segmented, with no single winner?

AThe article suggests the KYA market will be segmented because the key variable for success is not just technology, but the combination and integration of solutions with existing business ecosystems. Major players are entering a 'cooperation-combination' phase. The future market leader in each segment will be determined by which KYA provider successfully partners with which merchants, payment networks (like Visa's approach), and existing KYC customer bases. Therefore, different KYA standards and solutions (e.g., ERC-8004 for the crypto-native ecosystem, Visa TAP for card-based commerce) are likely to dominate different application areas, leading to a fragmented market rather than a single universal winner.

Related Reads

GitHub, Transfixed by AI

On the night of February 9th, GitHub suffered a major outage caused by a simple configuration change—reducing a cache refresh interval from 12 to 2 hours—that triggered a cascade of failures. This was not an isolated event, but part of a broader pattern. In early 2026, GitHub experienced at least 8 major incidents, failing to meet its promised 99.9% availability. These outages stemmed from structural issues: explosive growth in load, tight service coupling, and insufficient protection against abnormal traffic. This unprecedented load is driven by AI Agents. In 2025, GitHub handled ~1 billion commits. By 2026, weekly commits reached 275 million, projecting to ~14 billion for the year—a 14x increase. AI tools like Claude Code now contribute 4.5% of all public repository commits, with weekly submissions surging 25x in just three months. AI-generated pull requests jumped from 4 million to 17 million per month in half a year. Unlike human developers, AI Agents work continuously, generating commits at a scale that overwhelms infrastructure designed for human rhythms. The surge also shattered GitHub's business model. Copilot's flat-rate pricing, based on assisting human developers, became unsustainable as Agentic AI sessions consumed resources worth hundreds of dollars for a few dollars in fees. In response, GitHub imposed usage limits and, by June 1st, shifted to a pay-per-use "AI Credits" system. Facing this new reality, GitHub realized a 10x scaling plan was insufficient. It announced a need to *redesign* its architecture for 30x current scale—decoupling services, adding fault isolation, and improving change management to prevent cascading failures. Other platforms like Stripe and AWS are facing similar challenges with AI Agents. Fundamentally, GitHub is transitioning from a human collaboration platform to an "exhaust pipe" for automated AI workflows. Its detailed post-mortem reports aim to maintain trust during this turbulent rebuild. The February outage was not just a technical glitch, but a signal of the software industry's entry into a new, AI-driven era.

marsbit10m ago

GitHub, Transfixed by AI

marsbit10m ago

Both Suffer Massive Losses Exceeding $90 Billion, Which Is in Greater Peril: Strategy or Bitmine?

Facing massive paper losses exceeding $90 billion each amidst a sharp market downturn, "Digital Asset Treasury" (DAT) giants Strategy and Bitmine find themselves in a precarious position, but with different underlying risks. Strategy, heavily invested in Bitcoin (BTC), faces significant financial strain. Its strategy relies heavily on debt, including convertible notes and preferred stock (STRC) requiring substantial dividend payments. With its cash reserves dwindling and BTC offering no staking yield for cash flow, Strategy's high leverage makes it vulnerable. A continued price decline could force asset sales to meet obligations, potentially creating a negative feedback loop. Its market value has already fallen sharply. In contrast, Bitmine, an Ethereum (ETH) holder, appears on firmer financial ground. It primarily funds its purchases through equity offerings (like ATM programs), avoiding debt pressure. It also generates income by staking a large portion of its ETH holdings. While not immune to market drops and shareholder dilution concerns, Bitmine maintains more flexibility, recently announcing a new preferred share offering to raise further capital. The core divergence lies in their financing: Bitmine uses equity (investor money), while Strategy uses debt (borrowed money). Consequently, Bitmine currently faces less immediate liquidity pressure than Strategy, which must navigate the dual challenge of servicing debt/dividends and a declining core asset (BTC) price.

marsbit17m ago

Both Suffer Massive Losses Exceeding $90 Billion, Which Is in Greater Peril: Strategy or Bitmine?

marsbit17m ago

Where the AI Bubble Really Is: Which Layer of Players Are Naked

AI Bubble: Where It Really Is and Who's Swimming Naked This analysis dissects the AI industry not as a single entity but as a five-layer pyramid, arguing that bubbles are concentrated in specific tiers, not uniformly distributed. **Key Distinction from the 2000 Dot-com Bubble:** Unlike 2000, where companies had stock prices before revenue, today's leading AI players have massive, contract-backed revenue driving their valuations. Core infrastructure demand is real, with every GPU running at full capacity for paying customers. **The Five-Layer Pyramid & Bubble Assessment:** * **L0 (Fab/Manufacturing) & Top L4 (Leading AI Apps): NO BUBBLE.** Companies like TSMC, NVIDIA, major cloud providers (Microsoft, Google, Meta, Amazon), and top AI labs have real revenues and orders. Supply is tightly constrained by TSMC's disciplined capacity control and physical limits like power/land for data centers, preventing a supply glut. * **L1 (Memory): BATTLEGROUND.** Sky-high HBM margins could signal a new structural cycle or a classic "boom before bust." The oligopoly of three major players may enforce supply discipline, making this a high-stakes bet. * **L2 (Interconnect/Optical Modules): BUBBLE TERRITORY.** Companies like Lumentum and AAOI have seen stock surges (4-10x) far outpacing revenue growth. This hardware segment has lower physical barriers to expansion than fabs, allowing speculation. It mirrors the 2000 bubble's epicenter—optics. * **L3 (Infrastructure/"GPU Landlords"): VULNERABLE.** GPU leasing companies profit from the current compute shortage but own no long-term moat. Their business model relies on a temporary bottleneck that will ease as big tech expands and new tech (e.g., potential space-based data centers) emerges. * **L4 Long Tail (VC-backed Startups): STRONG BUBBLE SIGNALS.** VC funding concentration in AI is twice that of the 1999 peak. Many startups with little revenue use the valuation logic of successful giants to justify their own, creating high risk of a "valuation crunch" when funding dries up. **Critical Risks to Monitor:** 1. **GPU Depreciation & Accounting:** Companies extending the assumed useful life of GPUs artificially boost profits. The true economic life depends on future generational leaps from NVIDIA. 2. **"GPU Credit" & Off-Balance-Sheet Leverage:** Emerging structures where shell companies borrow to buy GPUs and lease them out (with chipmakers sometimes investing) move debt off major balance sheets. This echoes the "vendor financing" of 2000 and the securitization risks of 2008, though currently small-scale. 3. **TSMC Abandoning Caution:** If the primary supply bottleneck (TSMC's conservative capacity planning) breaks, runaway supply could trigger a bust. 4. **Algorithmic Efficiency Breakthrough:** A major leap in software efficiency could drastically reduce the need for raw compute hardware, undermining the investment thesis. **Conclusion:** The AI boom is expensive and has frothy areas, but its core is underpinned by real demand and physical supply constraints. The bubble risk is layered: most present in optical components, GPU leasing, and the long-tail startup ecosystem, while the foundational chip manufacturing and leading application layers remain relatively solid—for now.

marsbit30m ago

Where the AI Bubble Really Is: Which Layer of Players Are Naked

marsbit30m ago

Trading

Spot
Futures

Hot Articles

How to Buy ID

Welcome to HTX.com! We've made purchasing SPACE ID (ID) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy SPACE ID (ID) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your SPACE ID (ID)After purchasing your SPACE ID (ID), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade SPACE ID (ID)Easily trade SPACE ID (ID) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

2.9k Total ViewsPublished 2024.03.29Updated 2026.06.02

How to Buy ID

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ID (ID) are presented below.

活动图片