19 Sep 2026, Sat

‘Know your agent’: Banks face a new compliance challenge as AI agents shop and pay on their own | Fortune

For decades, "Know Your Customer" (KYC) has been a cornerstone of financial compliance, a rigorous framework designed to verify the identity of clients, assess their risk profiles, and prevent illicit activities such as money laundering, terrorist financing, and fraud. Banks and financial institutions have invested billions in sophisticated systems, processes, and human capital to meet these stringent requirements, mandated by regulators worldwide. KYC protocols involve everything from collecting personal identification documents and proof of address to scrutinizing transaction histories and conducting enhanced due diligence for high-risk clients. It is a labor-intensive, data-driven endeavor aimed at establishing trust and ensuring the integrity of the financial system by understanding the human actors within it.

However, the rapid ascent of AI agents introduces an entirely new dimension to this compliance paradigm. "From the financial institutions’ perspective, when we initiate a transaction, we have to do the KYC," Bian explained. "In the agent economy, you need to know your agents. Who’s the agent? Who does it belong to? Who authorized it?" Her questions cut to the heart of the matter: how do you apply principles designed for human entities to autonomous software programs that can initiate, negotiate, and execute complex financial transactions with minimal human oversight?

The "agent economy" is not a futuristic concept; it is rapidly taking shape. These AI agents, often powered by advanced machine learning and natural language processing, are capable of understanding user intent, accessing vast amounts of data, making decisions, and interacting with various digital services on behalf of individuals or businesses. They can schedule appointments, manage investments, compare prices, execute trades, and even negotiate contracts. According to a January report from McKinsey, these intelligent agents could orchestrate as much as an astonishing $5 trillion in global consumer spending by 2030. This projection underscores the transformative potential of agentic commerce, where AI-driven entities become pivotal intermediaries in economic activity, reshaping how consumers and businesses interact with goods and services.

This exponential growth, while promising unprecedented efficiency and personalization, also presents formidable challenges to the existing financial infrastructure. As Bian pointed out, "Looking forward, all the infrastructure needs to be rebuilt or enhanced for agents." The current global financial architecture – from payment rails and clearing systems to fraud detection algorithms and regulatory reporting mechanisms – was predominantly designed for human-initiated and human-verified transactions. These systems rely on clear human accountability, predictable rule sets, and established legal frameworks that define rights and responsibilities. The introduction of autonomous, often self-learning, agents necessitates a fundamental rethinking of these foundational elements.

Recognizing the urgency of this impending challenge, key industry players are already moving to address it. On September 6, just days before Bian’s warning, Ant International, Ant Group’s global payments arm, announced a significant collaboration with industry giants Mastercard and Visa. This partnership aims to develop a "know your agent" (KYA) interoperability framework. The objective is to enable various financial ecosystems – including card networks, digital wallets, and online marketplaces – to reliably recognize and authenticate trusted AI agents across different platforms. This interoperability is crucial because agents, by their nature, are expected to operate seamlessly across multiple services and providers. Without a standardized way to verify their legitimacy and operational parameters, the risk of fraud, system manipulation, and compliance breaches escalates dramatically. The companies will channel their efforts through BuildFin.ai, an industry platform convened by the Monetary Authority of Singapore (MAS), the city-state’s central bank, known for its proactive approach to fintech innovation and regulation. MAS’s involvement lends significant weight to the initiative, signaling a collaborative push from both industry and regulators to proactively shape the future of agentic commerce.

The inherent nature of AI agents poses a particular dilemma for financial systems. As an April note from the International Monetary Fund (IMF) observed, AI agents are "probabilistic and adaptive," meaning that the same input or prompt can yield different outputs or decisions over time. This adaptability, while a hallmark of advanced AI, stands in stark contrast to the fundamental requirement of payment systems, which "must return the same answer every time." The IMF authors highlighted this critical divergence: "Payment rails, from card networks to real-time gross settlement (RTGS) systems, rely on predictable rules, legal certainty, and clear accountability structures to ensure trust and financial stability."

The probabilistic nature of AI agents introduces ambiguity into a domain that demands absolute certainty. How can a financial institution ensure legal certainty when an agent’s decision-making process is not entirely deterministic? Who is accountable when an autonomous agent, acting within its programmed parameters, makes an erroneous or detrimental financial decision? Is it the developer of the agent, the owner who deployed it, the platform hosting it, or the end-user on whose behalf it acted? These questions expose a gaping void in current legal and regulatory frameworks, which are ill-equipped to handle the distributed and often opaque accountability structures of advanced AI systems. The imperative for "explainable AI" (XAI) – the ability to understand and interpret how an AI model arrived at a particular decision – becomes not just a technological desideratum but a foundational requirement for regulatory compliance and trust in the agent economy.

Beyond the technological and theoretical challenges, financial institutions must also contend with their own internal readiness. Benson Wong, managing director and head of digital at JPMorgan Private Bank, highlighted that the core issue often lies not with the AI technology itself, but with its integration and governance. "I personally have never come across a situation where the technology of an agent failed us—or rather, led to an undesirable outcome," Wong stated. "It’s always around the operating model, the processes, and the compliance and the controls." This perspective underscores that even the most sophisticated AI agents can become liabilities if deployed within inadequate operational frameworks. Financial institutions need to establish robust governance structures, clear oversight mechanisms, comprehensive risk assessments, and rigorous testing protocols specifically designed for autonomous agents. This includes defining the scope of an agent’s authority, implementing kill switches, ensuring audit trails, and establishing human-in-the-loop interventions for critical decisions.

Wong further elaborated on the escalating cost of errors as agent autonomy increases. "If you ask an agent…an information-seeking question and [it answers] wrongly, it’s not good, but you have an embarrassing moment," he explained. This might involve an AI assistant providing incorrect market data or a flawed summary of a financial report. While undesirable, the direct financial impact is often contained. However, the scenario shifts dramatically when agents are empowered with "agentic workflows"—the ability to execute actions autonomously. "If you don’t get agentic workflows correct, there are vastly scaled impacts."

Consider the difference: an agent incorrectly informing a client about a stock price might lead to minor inconvenience. But an agent incorrectly executing a high-frequency trade, initiating an unauthorized cross-border payment, or mismanaging a portfolio based on flawed algorithms could result in catastrophic financial losses, severe regulatory penalties, reputational damage, and even systemic instability. The cost of a simple informational error pales in comparison to the potential fallout from an autonomous agent making a significant, incorrect financial decision. This demands an unprecedented level of scrutiny, validation, and control over the agents operating within the financial ecosystem.

The journey towards a robust "know your agent" framework will be multifaceted, involving collaboration between financial institutions, technology providers, regulators, and legal experts. It will necessitate the development of new standards for agent identity, authentication, authorization, and auditability. It will also require establishing clear liability models and developing robust incident response plans tailored to the unique challenges posed by autonomous systems. The goal is not to stifle innovation but to ensure that the benefits of the agent economy can be realized responsibly and securely.

In conclusion, Zhuoqun Bian’s assertion that "You need to know your agents much more than you know your customers" is not an exaggeration but a profound truth for the evolving financial landscape. The higher autonomy, potential for scaled impact, and probabilistic nature of AI agents demand an even more rigorous approach to identity, risk, and accountability than that applied to human customers. As AI agents move from assisting humans to actively participating in and orchestrating financial transactions, establishing comprehensive "know your agent" protocols will not merely be a compliance hurdle but a fundamental requirement for maintaining trust, ensuring stability, and unlocking the full potential of the digital economy. The future of finance depends on it.

Leave a Reply

Your email address will not be published. Required fields are marked *