FILE 001 STATUS Open ← Back to all files
KYA

Know Your Agent: Why AI Agents Need an ID Too

Agentic AI isn't just filling out applications anymore. It's starting to show up across the entire lending relationship — and traditional KYC has no idea what to do with any of it.

Here's a question that didn't exist in fraud strategy two years ago: when a loan application comes in, who — or what — actually filled it out?

That's the easy version of the question, because it's the one that's already visible. The harder version is that "filling out the application" is just the first place an agent shows up. The same agent — or a different one, working from the same delegated authority — can just as easily be the one uploading documents mid-underwriting, responding to a stipulation request, initiating a payment, or opening a dispute six months into the loan. KYA isn't an intake control. It's a question that has to be re-askable at every point an agent, rather than a person, is the one acting.

And lending isn't even the only place this is happening. Agentic commerce — AI agents browsing, comparing, and checking out on a shopper's behalf — is running into the exact same wall at merchant checkouts right now. Different industry, same underlying question: not "is this a real customer," but "is this software actually authorized to act as one, and how far does that authorization go?"

Not metaphorically. Literally. Agentic AI can now browse a lending site, compare offers, pre-fill an application, upload documents, and answer verification questions, all with a human's authorization but without a human's hands on the keyboard. Some of this is already happening quietly at the edges of consumer finance. A lot more of it is coming, fast, because the economics are obvious: an AI agent that can shop three lenders in ninety seconds is a better customer experience than a person doing it in an afternoon.

The problem is that every fraud and compliance framework we have was built on one assumption: the entity on the other end of the transaction is a person. Know Your Customer exists to answer "is this person who they say they are?" It has no mechanism for answering "is this software acting with the authority it claims to have, on behalf of the person it claims to represent?" That's a different question, and right now, almost nobody is set up to ask it.

Why KYC alone doesn't cover this

KYC verifies a human identity at a point in time — a document, a face, a database hit. It was never designed to verify a delegated, autonomous actor that can act repeatedly, adapt its behavior, and show up under a hundred different sessions in a single afternoon. Layering standard KYC controls onto an AI agent is a bit like checking a courier's ID and assuming that also validates the shipping company, the delivery contract, and every future package they'll ever carry. It answers one question and quietly assumes away several others.

That gap is what I've been calling Know Your Agent (KYA): a parallel framework for authenticating AI agents transacting on a person's behalf, the same way KYC authenticates the person themselves.

What KYA actually asks

KYA isn't a rebrand of KYC with "AI" bolted on. It's a distinct set of questions a fraud program needs answered before it trusts an agent-submitted application:

Technically, this points toward the same identity primitives the decentralized-identity world has already been building for other use cases: Decentralized Identifiers and Verifiable Credentials, adapted here to bind an agent's actions to a specific, verified human, with an audit trail that survives the session. It's not exotic technology. It's an application most of the industry hasn't gotten around to yet.

The fraud teams that treat this as a future problem are the ones who'll be explaining it to their board as a past-tense loss.

What this means for lenders right now

You don't need a fully built KYA stack today to start protecting yourself. Three things are worth doing now:

CASE ONGOING

This is the core argument behind a paper I presented at IEEE GAISS 2026 — "The AI Agent Passport: A Fraud-First Identity Architecture for Agent-Driven Personal Loan Applications" — which goes deeper into the DID/VC architecture and the threat modeling behind it. This post is the practitioner's version: what I'd actually tell a fraud team to do on a Monday morning, not the full academic case.

Agentic AI in lending isn't a someday problem. The agents are already at the door. The question is just whether we've bothered to ask them for ID.