From KYC to KYA, Is It Time to Give AI Agents Their Own 'ID Cards'?

marsbitPublished on 2026-05-10Last updated on 2026-05-10

Abstract

Titled "From KYC to KYA: Is It Time to Issue 'Identity Cards' for AI Agents?", this article discusses the emerging concept of Know Your Agent (KYA) as AI agents become increasingly autonomous. In Agent-to-Agent (A2A) scenarios, where agents execute contracts, payments, and trades without human intervention, the lack of a shared identity standard creates risks like unauthorized transactions, fraud, and accountability gaps. KYA acts as a trust layer to verify an agent's origin, authority, and accountability. The need for KYA is most critical outside centralized platforms (like Google or Coinbase), such as in decentralized exchanges (DEX), A2A payments, and merchant payments. Several key players are building KYA infrastructure: - **ERC-8004**: A proposed Ethereum standard that issues a unique AgentID as an NFT, building on-chain identity, reputation, and validation systems. - **Visa TAP**: Visa's solution issues agent identity credentials, with transactions verified via triple signatures (legitimacy, delegator, payment method). - **Trulioo**: Extends its KYC/KYB compliance infrastructure using a Digital Passport for Agents (DAP), issued after verifying both the developer and user, and refreshed per transaction. - **Sumsub**: Focuses on post-issuance real-time verification, detecting agent anomalies during transactions using its existing compliance systems. Regulatory bodies are also acting. The EU AI Act mandates operator identification in logs for high-risk AI systems, the US...

Authored by: Tiger Research

Compiled by: AididiaoJP, Foresight News

The era of AI agents is accelerating, and alongside it, concerns about the uncontrolled creation and behavior of agents are growing. Know Your Agent (KYA) systems, which assign identities to agents and regulate their behavior, are receiving increasing attention. Why is a KYA identity infrastructure needed? Which companies are building it?

Summary

  • AI agents have entered an era of autonomously executing contracts, payments, and transactions, but there are currently no shared standards to verify "who this agent is." In Agent-to-Agent (A2A) scenarios, KYA is gaining more focus than KYC.
  • KYA is not needed in all scenarios. Within centralized platforms (Google, OpenAI, Coinbase), existing KYC is sufficient. Where KYA truly becomes important is in scenarios where independently deployed autonomous agents interact with DEXs, A2A payments, and merchant payments.
  • The KYA standards race has begun:
  • ERC-8004: Issues AgentIDs on top of NFTs, building an on-chain system for identity, reputation, and verification.
  • Visa TAP: Visa issues identity credentials for agents, verified through TAP's triple signature (legitimacy, delegator, payment method).
  • Trulioo: Adopts the SSL CA model, with DPAs issuing DAPs.
  • Sumsub: Layers a KYA system on top of its own compliance system.

Regulatory action has begun at the national level. The EU's AI Act requires high-risk AI system behavior logs to include operator identity. The US NIST has listed agent identity management as a priority standard area. Singapore has released the world's first national-level AI agent governance framework. Just as the 2019 FATF Travel Rule determined which crypto exchanges survived, whether one possesses KYA infrastructure will determine who enters the next market cycle.

Why is KYA Emerging Now?

KYC: The Layer That Reshaped Finance

  • Before 1989, global finance lacked a unified identity standard. This gap made it difficult to track drug money and illicit funds.
  • After the FATF was founded in 1989, KYC became a mandatory requirement in finance, blocking illicit funds at the entry point.

Without Agent Identity, Systems Regress

  • AI agents execute contracts, payments, and transactions without human involvement, but currently, it's impossible to verify "who it is."
  • In A2A environments, accountability becomes blurred, dispute risks increase, and users are exposed to fraud patterns like money laundering.

The Role and Response of KYA (Know Your Agent)

  • KYA (Know Your Agent) is a trust layer that pre-verifies an agent's origin, permissions, and accountability framework.
  • Unverified agents bring three major risks simultaneously: unauthorized transactions, fraud, and accountability gaps.

The Manifestation of KYA's Necessity

KYA is Needed at Every Level

  • Within centralized platforms, user KYC + platform accountability is sufficient. In interoperable scenarios outside platforms, KYA becomes crucial for verifying an agent's specific actions and safety.
  • Within a country (inside a platform), one ID (KYC) is enough to move freely. But once crossing borders (outside a platform), the environment changes, and entry review (KYA) of purpose and trust is needed.

Market Players

ERC-8004: NFT-Based Agent Identity

  • ERC-8004 adds an identity layer on top of ERC-721, minting an NFT as a unique ID for each agent.
  • It also adds three on-chain registries (Identity, Reputation, Validation), serving as identity, reputation board, and verification record respectively.

Two Markets Built by Ethereum Standards, a Third is Coming

  • ERC-20 (Token Issuance Standard): Before standardization, every token needed brand-new code. After ERC-20, most major assets were issued on it.
  • ERC-721 (NFT Standard): CryptoPunks, BAYC, ENS built the NFT market itself upon it. As blockchain integration accelerates in the agent era.
  • ERC-8004 will play the same standardizing role for Agents.

Visa TAP: Authentication on the Visa Rail

Visa issues identity credentials (Agent Intent) to agents, akin to an identity card. Without a key, transactions cannot occur. Keys are issued only after Visa pre-approval. Every transaction is signed and submitted to the merchant.

The merchant receives three signatures, not one: Visa approval, delegator, payment method, all confirmed simultaneously.

Visa: A Strategy to Pull Every Transaction into the Visa Network

  • Just as Visa previously captured payment rails, it is now encapsulating the agent era.
  • Through Visa Intelligent Commerce (VIC), Visa offers a solution bundle that packages KYA with payments.
  • If agent payments still use the card rail, and this bundle becomes the default option, then Visa's market share can remain stable even through the transition.

Trulioo: Extending KYC-Era Verification Infrastructure

  • Trulioo is a compliance operator on the global KYC/KYB rail and is expanding its verification stack to KYA.
  • DPAs play the role of SSL-CAs. Unlike SSL (domain only), DPAs verify developer KYB and user KYC before issuing a DAP.
  • Banks and fintechs legally require human and business identity. As agents enter finance, Trulioo's KYC/KYB position will be further solidified.

DAP, an Agent's Digital Passport, Refreshed with Each Transaction

  • DAP is an agent's digital passport. A DPA verifies the developer (KYB) and user (KYC), packages both into a token, and grants it to the agent.
  • Unlike a paper passport, it is a live token, refreshed and re-verified with every transaction. Once delegation is revoked or anomalies are detected, the DAP is invalidated immediately.
  • KYA is not a one-time verification. Trust must be reconfirmed with every transaction.

Sumsub (AI Agent Verification): Detecting Agent Anomalies

  • Sumsub's approach is: whenever an agent attempts an anomalous transaction, re-verify the currently active human identity.
  • It leverages its verification systems from its compliance business since 2015 to detect agent anomalies more accurately.

Operators with Technology to Address New Threats of the AI Era

  • Other KYA players focus on one-time pre-transaction identity verification. Sumsub focuses on real-time verification post-issuance.
  • As agent permissions expand, anomaly detection becomes crucial; as fraud scales with technology, Sumsub's real-time verification stack gains attention.

Proactive Regulatory Positioning, Shaping Entry Rules

The Gap Caused by the FATF Travel Rule May Recur with KYA

After the 2019 FATF Travel Rule, VASPs diverged based on their ability to bear KYC/AML infrastructure costs. Peers like CryptoBridge and Deribit, unable to afford it, either shut down or moved to less regulated regions.

The EU, Singapore, and the US are already vying for leadership. KYA will become a core layer of the agent era.

KYA Will Differentiate by Market Segment, Not a Single Winner

The real variable in the standards race is not technology, but combinations. Mainstream players have entered the collaboration and combination phase. In the future, who pairs with which merchants, payment networks, and KYC customer bases will determine the leader in each segment.

The market will not have a single winner; it will differentiate by market segment.

Related Questions

QWhat is KYA (Know Your Agent), and why is it emerging as an important concept in the AI agent era?

AKYA (Know Your Agent) is a system designed to verify the identity, authority, and accountability of AI agents, especially in scenarios where they operate autonomously without direct human oversight. It is emerging as a crucial trust layer due to the rise of AI agents that autonomously execute contracts, payments, and transactions. In these Agent-to-Agent (A2A) environments, there is currently no shared standard to verify 'who the agent is,' leading to increased risks like unauthorized transactions, fraud, and accountability gaps. KYA addresses these risks by establishing a trust infrastructure for pre-verifying an agent's source, permissions, and purpose.

QWhat are some key standards and solutions being developed for KYA?

ASeveral standards and solutions are being developed for KYA. Notable examples include: 1) **ERC-8004**: An Ethereum-based standard that uses NFTs (ERC-721) as unique AgentIDs and adds on-chain registries for identity, reputation, and validation. 2) **Visa TAP (Triple Authorization Protocol)**: Visa's solution that issues identity credentials (Agent Intent) to agents and requires triple signatures (from Visa, the delegator, and the payment method) for transaction approval. 3) **Trulioo's DAP**: Extends their KYC/KYB infrastructure to issue a dynamic Digital Agent Passport (DAP) that is re-validated per transaction. 4) **Sumsub (AI Agent Verification)**: Focuses on post-issuance, real-time verification of agents to detect and prevent abnormal behavior using their existing compliance stack.

QIn what scenarios is KYA most necessary, according to the article?

AAccording to the article, KYA is most necessary outside of centralized, walled-garden platforms (like Google, OpenAI, or Coinbase), where traditional user KYC and platform accountability are sufficient. KYA becomes critical in scenarios involving independent, autonomously deployed agents interacting across platforms, particularly in: 1) **Agent-to-Agent (A2A) transactions** (e.g., payments between agents). 2) **Accessing decentralized exchanges (DEXs)**. 3) **Making payments to merchants**. These represent interoperable environments where a lack of agent identity verification creates significant operational and financial risks.

QHow are governments and regulatory bodies responding to the need for AI agent identity management?

AGovernments and regulatory bodies are beginning to act on AI agent governance, effectively pushing the need for KYA infrastructure. Key actions include: 1) **The EU AI Act**: Requires operators of high-risk AI systems to be identifiable in activity logs. 2) **US NIST**: Has prioritized AI agent identity management as a key standard-setting area. 3) **Singapore**: Released the world's first national-level AI governance framework specifically for agents. The article draws a parallel to the 2019 FATF Travel Rule, suggesting that the ability to implement compliant KYA systems will be a determining factor for which entities can participate in the next phase of the AI agent market.

QWhy does the article suggest the KYA market will be segmented, with no single winner?

AThe article suggests the KYA market will be segmented because the key variable for success is not just technology, but the combination and integration of solutions with existing business ecosystems. Major players are entering a 'cooperation-combination' phase. The future market leader in each segment will be determined by which KYA provider successfully partners with which merchants, payment networks (like Visa's approach), and existing KYC customer bases. Therefore, different KYA standards and solutions (e.g., ERC-8004 for the crypto-native ecosystem, Visa TAP for card-based commerce) are likely to dominate different application areas, leading to a fragmented market rather than a single universal winner.

Related Reads

The Midlife Crisis of Crypto GPs: No PMF, No Next Check from LPs

The article "The Midlife Crisis of Crypto GPs: No PMF, No Next LP Check" analyzes the shifting crypto fundraising landscape. It argues the era of selling grand visions to LPs is over; GPs must now offer products with clear Product-Market Fit (PMF). The author categorizes crypto fundraising products into three types: Primary (VC funds), Liquid (trading strategies), and CeFi/DeFi Native Yield. This summary focuses on the Primary market. Key points include: * **Market Shift:** LPs are impatient, demand immediate returns, and are skeptical of future promises. The "easy money" narrative has faded. * **GP Value Erosion:** LP learning curves have shortened (aided by AI), reducing the value of a GP's basic "crypto knowledge." Superior judgment is now rare. * **Weakened LP Motivations:** Traditional reasons for LPs to invest in crypto VC funds (capturing industry beta, gaining access, leveraging GP judgment) have weakened due to new products like ETFs and increased LP sophistication. * **Surviving in Primary:** The primary market will likely persist for: 1) large funds in endowment mandates treating it as a lottery ticket, 2) family offices/HNWIs using proprietary capital, 3) a few funds with proven recent outperformance, and 4) funds with strong ecosystem "deal-making" capabilities. * **Conclusion:** For most GPs, rebuilding trust requires starting over in a niche, demonstrating alpha-generating ability, or providing concrete value/services to LPs.

marsbit21m ago

The Midlife Crisis of Crypto GPs: No PMF, No Next Check from LPs

marsbit21m ago

Crypto GPs' Midlife Crisis: No PMF, No LP's Next Check

The article "The Midlife Crisis of Crypto GPs: No PMF, No LP's Next Check" analyzes the shifting crypto fundraising landscape. It argues that the era of LPs funding vague "vision" is over; GPs must now offer products with clear Product-Market Fit (PMF) to secure capital. The market has matured. LPs, disillusioned by the last cycle's failures and wary of long lock-up periods, now demand tangible, near-term returns rather than speculative narratives. The proliferation of accessible crypto ETFs and other liquid products has reduced the need for VC blind pools as an entry point. The author categorizes crypto fundraising products into three types: Primary (VC funds, with blind pools or clear pipelines), Liquid (alpha/beta, directional/market-neutral strategies), and CeFi/DeFi Native Yield (crypto-specific mechanisms like staking, farming). Focusing on the Primary market, the piece details why traditional LP rationales for investing in crypto VCs have weakened: easier beta access via ETFs, diminished "access" and "judgement" premiums as LPs build internal teams, and a widespread lack of proven superior returns from GPs. Ultimately, only specific players are likely to remain at the primary VC table: large funds with access to patient endowment capital, family offices/HNWIs investing proprietary capital, the few funds with demonstrable excess returns from the last cycle, and those with clear "deal-making" or ecosystem resource advantages. For others, the path forward is to rebuild trust by proving alpha-generation capability in a niche or providing concrete, valuable services.

链捕手46m ago

Crypto GPs' Midlife Crisis: No PMF, No LP's Next Check

链捕手46m ago

The Age of Decoupling Has Arrived: Bitcoin is No Longer the Sole Compass of Crypto

The era of the cryptocurrency market moving in lockstep with Bitcoin is ending, as the industry splits into two distinct asset categories: endogenous and exogenous. Endogenous assets, like Bitcoin, derive value purely from the crypto market's cycles. Their narratives swing between being "interstellar money" in bull markets and "digital collectibles" in bear markets. Exogenous assets, however, are nominally crypto but operate with independent value drivers. Examples include: * **Venice:** An AI inference service using tokens for payments; its consumer-AI business model is decoupled from crypto price swings. * **Figure:** A fintech lender using blockchain to speed up loan approvals; its core value is in credit, not crypto. * **Stablecoin firms like BVNK:** Acquired by traditional finance giants (Mastercard, Stripe), their growth is tied to payment infrastructure, not market cycles. Hybrid projects like **Hyperliquid** (a decentralized exchange) show a shift, with a growing share of non-crypto trading (e.g., prediction markets). This divergence is fundamental. Endogenous assets remain highly correlated to Bitcoin, similar to gold miners to gold. Exogenous assets are evolving to have their own fundamentals, like the weak correlation between gold and the S&P 500. This changes investment analysis. Evaluating exogenous assets requires traditional fundamental research—assessing user bases, unit economics, and moats—more akin to fintech investing than charting Bitcoin. Promising exogenous sectors include: on-chain exchanges/brokers, AI-crypto fusion, privacy-focused digital banks, lending (institutional/private credit), stablecoins/real-world asset tokenization, payment rails, and non-financial crypto-consumer products. Currently, investing via equity is often safer than via tokens, as token value accrual mechanisms need further regulatory and industry development (e.g., the CLARITY Act). Nonetheless, the core trend is clear: crypto market drivers are diversifying from a single factor (Bitcoin) to multiple fundamentals, ending the era of uniform market moves.

marsbit1h ago

The Age of Decoupling Has Arrived: Bitcoin is No Longer the Sole Compass of Crypto

marsbit1h ago

Trading

Spot
Futures

Hot Articles

How to Buy ID

Welcome to HTX.com! We've made purchasing SPACE ID (ID) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy SPACE ID (ID) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your SPACE ID (ID)After purchasing your SPACE ID (ID), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade SPACE ID (ID)Easily trade SPACE ID (ID) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

2.9k Total ViewsPublished 2024.03.29Updated 2026.06.01

How to Buy ID

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ID (ID) are presented below.

活动图片