Credit cards arranged around a glowing digital
AI

Ant International, Visa, and Mastercard Start “Know Your Agent” Standards Work

The MAS-convened BuildFin.ai effort targets identity and authorization for AI agents initiating payments across networks.

By Elliot Marsh6 min read

Ant International has begun collaborating with Mastercard and Visa on a “know your agent” interoperability framework meant to let payment ecosystems recognize trusted AI agents across card networks, digital wallets, and marketplaces. The work is being conducted through BuildFin.ai, an industry platform convened by the Monetary Authority of Singapore, as banks confront attribution and liability questions when agents initiate transactions.

Key Takeaways

  • Ant International is working with Mastercard and Visa on a “know your agent” interoperability framework aimed at recognizing trusted AI agents across card networks, digital wallets, and marketplaces.
  • The standards effort is being run through BuildFin.ai, an industry platform convened by the Monetary Authority of Singapore.
  • Ant Digital Technologies president Zhuoqun Bian framed the compliance requirement as proving the agent’s identity, its owner, and who authorized it to transact.
  • A January McKinsey report projected AI agents could orchestrate as much as $5 trillion in global consumer spending by 2030.

Ant, Visa, and Mastercard Put “Know Your Agent” on the Standards Track

Ant International, Ant Group’s global payments arm, said it has begun collaborating with Mastercard and Visa on a “know your agent” interoperability framework designed to let card networks, digital wallets, and marketplaces recognize trusted AI agents across ecosystems.

The work is being conducted through BuildFin.ai, an industry platform convened by the Monetary Authority of Singapore (MAS). That matters because it frames “know your agent” less like a single-firm product feature and more like an attempt to standardize how agent identity and trust are expressed across multiple payment environments.

The announcement dates the effort to Sept. 6, 2026, placing it in the early phase of agentic commerce where the core question is not whether agents can click “buy,” but whether the rails can reliably decide who is acting, under what authority, and with what recourse when something goes wrong.

From KYC to Agent Identity: What Banks Say They Need to Prove

The compliance shift being pitched is straightforward: traditional KYC (know your customer) checks are built to identify the human or legal entity opening an account, while agent-driven payments introduce a second actor that can initiate actions without a human pressing the button each time.

Zhuoqun Bian, president of Ant Digital Technologies, described the new requirement at the Fortune Leaders Forum in Macau on Sept. 8. “From the financial institutions’ perspective, when we initiate a transaction, we have to do the KYC [know your customer],” she said. “In the agent economy, you need to know your agents. Who’s the agent? Who does it belong to? Who authorized it?”

In plain English, “know your agent” is a proposed compliance approach that ties three things together: the agent’s identity (which software agent is acting), ownership (which user or organization it belongs to), and authorization (what permissions were granted for this specific transaction class). The interoperability framework piece is the glue. It implies shared standards so that an agent recognized as “trusted” in one context can be recognized, authenticated, and constrained in another without bespoke integrations.

Bian also argued the constraint is structural, not cosmetic. “Looking forward, all the infrastructure needs to be rebuilt or enhanced for agents,” she said, positioning agent identity and authorization as a payments-layer problem rather than an app-layer preference.

Why Payment Rails Struggle With Probabilistic Agents

Payment systems are built around deterministic processing and clear accountability. Card networks and RTGS (real-time gross settlement) systems are designed to produce the same outcome given the same inputs, because finality, dispute handling, and systemic stability depend on predictable rules.

An April International Monetary Fund note put the mismatch in technical terms: AI agents are “probabilistic and adaptive,” meaning the same prompt can yield different answers, while payment systems must return the same answer every time. The IMF authors wrote: “Payment rails, from card networks to real-time gross settlement (RTGS) systems, rely on predictable rules, legal certainty, and clear accountability structures to ensure trust and financial stability.”

That gap is where “trusted agent” standards become more than branding. If an agent can change its plan mid-execution, or interpret a user’s intent differently across runs, the rails still need a crisp mapping from action to authorization and from authorization to liability. Without that mapping, the failure mode is not just fraud. It is operational ambiguity, where the system can process a payment but cannot cleanly explain who initiated it, who should have stopped it, and who eats the loss.

JPMorgan Private Bank’s Benson Wong framed the near-term risk surface as governance rather than model quality. “I personally have never come across a situation where the technology of an agent failed us—or rather, led to an undesirable outcome,” he said. “It’s always around the operating model, the processes, and the compliance and the controls.” He added that autonomy changes the blast radius: “If you ask an agent…an information-seeking question and [it answers] wrongly, it’s not good, but you have an embarrassing moment. If you don’t get agentic workflows correct, there are vastly scaled impacts.”

What to Monitor as “Trusted Agent” Definitions and Adoption Emerge

The collaboration announcement establishes the venue and the participants, but it does not yet specify the technical spec, enforcement model, or timeline for adoption. That leaves traders and operators with a familiar problem: the standards effort is real, but the mechanism that would make it binding is still undefined.

Concrete traction would look like published BuildFin.ai documentation that spells out how a “trusted AI agent” is identified, authenticated, and authorized across networks, including a reference architecture that can be implemented by banks, wallets, and marketplaces. Without that, “interoperability framework” remains an intent statement rather than an integration path.

Adoption signals matter as much as the spec. Named banks, wallet providers, or marketplaces committing to implement the framework through BuildFin.ai would indicate the work is moving from convening to deployment, and would start to answer whether this becomes a de facto standard or stays a pilot among large incumbents.

Liability mapping is the other missing primitive. The framework will need to clarify where responsibility sits when an AI agent initiates a transaction, whether with the user, the agent provider, the wallet, the merchant, or some combination. MAS commentary would be a separate step-change. If the regulator begins framing “know your agent” as a supervisory expectation rather than a voluntary standard, the compliance timeline compresses and the cost of non-participation rises.

My Read: Payments Standards Are Becoming the Bottleneck for Agentic Commerce

The part that decides this is not whether agents can shop, it is whether payment rails can attribute intent and authority at machine speed. Ant International working with the two largest card networks through a MAS-convened platform is the first credible sign that “know your agent” is moving from conference language into standards work that other institutions can plug into.

The threshold that matters is whether BuildFin.ai produces a spec that assigns identity, authorization, and liability in a way banks can operationalize without rewriting their control stack from scratch. If that lands and adoption expands beyond the initial parties, agentic commerce starts to look like an integration problem with a timetable, not a narrative about demos.

Sources