DEV Community

Codego Group
Codego Group

Posted on Originally published at news.codegotech.com

Mastercard, Visa and Ant International Unite on Know-Your-Agent Framework

Three of the most powerful names in global payments are joining forces to address one of the most consequential and underexamined risks emerging from the artificial intelligence revolution: who — or what — is actually authorizing a financial transaction. Mastercard, Visa, and Ant International are now actively exploring an interoperable Know-Your-Agent framework designed to identify AI agents and the human or corporate operators behind them before payments are permitted to proceed. The initiative signals that the payments industry is moving — with unusual speed and cooperative intent — to get ahead of a regulatory and security vacuum before it widens into a systemic problem.

The Rise of Autonomous Spending

For the better part of a decade, the financial industry has been grappling with the fraud and compliance implications of digital wallets, instant transfers, and embedded finance. Now a new variable has entered the equation at scale: artificial intelligence agents that browse, decide, negotiate, and pay on behalf of their human principals without requiring explicit human approval at the point of transaction. These agents are already operating across e-commerce platforms, travel booking services, and subscription management tools. As their capabilities expand and their adoption accelerates, the question of how payment networks verify the legitimacy of an autonomous actor — rather than a human cardholder — becomes both technically complex and commercially urgent.

The Know-Your-Agent framework being explored by the three companies attempts to answer that question systematically. Rather than applying existing Know-Your-Customer protocols directly to AI systems — a structurally awkward fit — the proposed approach would create an interoperable layer specifically designed for agent identification. Payment networks, digital wallets, agent platforms, and marketplaces would all be able to query this layer to determine whether a given AI agent is registered, who operates it, and under what authorization it is acting. The interoperability dimension is particularly significant: a fragmented ecosystem of incompatible agent registries would create loopholes that bad actors could exploit precisely at the seams between networks.

Preserving Network Sovereignty

Critically, the framework as currently conceived would not require any of the participating networks to surrender their own verification logic or decision-making authority. Each network would retain full control over its own compliance processes, risk scoring, and transaction approval mechanisms. The shared framework would function as a common identification substrate — a lingua franca for agent identity — rather than a centralized authority that overrides individual network rules. This architectural choice is not merely a diplomatic concession to three institutions with competing commercial interests; it is also a sound design principle. Centralizing verification authority for AI agent payments would create a single point of failure, both technically and regulatorily, that no sophisticated financial network should accept.

The involvement of Ant International alongside the two dominant Western card networks is particularly notable from a geopolitical and market-structure perspective. Ant's digital wallet and payments infrastructure spans much of Southeast Asia, South Asia, and beyond, giving the framework a genuinely global dimension from the outset. An AI agent operating across jurisdictions — booking a hotel in one country, paying a supplier in another, managing a subscription billed in a third — would need to be recognizable across all three networks simultaneously. Without coordination of the kind these three companies are now pursuing, cross-border AI-driven commerce could become a compliance nightmare for merchants and a fraud opportunity for malicious actors.

The Compliance Imperative

From a regulatory standpoint, the initiative arrives at a propitious moment. Regulators across the European Union, the United Kingdom, and Asia-Pacific are actively developing frameworks to govern AI systems operating in consequential domains, including financial services. The European Banking Authority and the Bank for International Settlements have both flagged the need for clearer accountability chains when automated systems execute financial decisions. A voluntary industry-led Know-Your-Agent standard — particularly one backed by institutions with the combined global reach of Mastercard, Visa, and Ant International — could meaningfully shape what mandatory regulatory requirements eventually look like, and potentially prevent a more prescriptive and operationally disruptive regulatory intervention.

There is also a consumer protection argument that deserves emphasis. When a human cardholder makes a fraudulent or erroneous payment, the dispute resolution frameworks embedded in card network rules provide a relatively well-understood path to remedy. When an AI agent makes a payment that the consumer did not intend or did not fully authorize, the liability chain becomes murky. Is the operator of the agent platform responsible? The developer of the underlying model? The merchant who accepted the payment? A Know-Your-Agent framework does not resolve these liability questions on its own, but it creates the identification and audit infrastructure without which no rational liability allocation is possible.

What This Means for the Industry

The Mastercard, Visa, and Ant International initiative should be read as a leading indicator of where the entire payments and fintech ecosystem is heading. Institutions that process, facilitate, or enable payments — whether card networks, neobanks, payment service providers, or embedded finance platforms — will need to develop agent-aware compliance infrastructure. That means not only integrating with whatever interoperable identification layer eventually emerges, but also revisiting merchant agreements, fraud liability policies, and customer authorization frameworks to account for the reality of autonomous spending. The companies that treat this as a distant future concern will find themselves architecturally unprepared when regulators move from exploration to mandate. The companies that engage now, as Mastercard, Visa, and Ant International are demonstrably doing, will have shaped the standard rather than scrambled to meet it.

Written by the editorial team — independent journalism powered by Codego Press.

Top comments (0)