Urgent.News

600+ sources. One page. See who else covered it.

Editions

AI

From KYC to KYA: how AI agents are reshaping payment risk

The next phase of digital payments may not be defined by faster checkouts or cheaper transfers, but by a more uncomfortable question: who or what is being trusted to move money? As businesses begin experimenting with AI agents that can search for suppliers, compare prices, negotiate terms, initiate payments, and reconcile invoices, the old assumptions […] The post From KYC to KYA: how AI agents…

From KYC to KYA: how AI agents are reshaping payment risk

The forthcoming era of digital payments will hinge not on swifter transactions or lower fees, but on a more pressing question: who or what is trusted to manage financial operations? As businesses start exploring AI agents capable of supplier searches, price comparisons, negotiation, payment initiation, and invoice reconciliation, traditional notions of financial oversight are being challenged.

Humans are no longer clicking every button; finance teams may not manually approve each step. In certain instances, software will act on behalf of a company, operating within predefined rules. The crux of this transformation lies within the realms of "Beyond Automation: Defining Agentic Global Payments," a report published by Sunrate and Mastercard.

Its core assertion is uncomplicated: automation alone is insufficient. To manage commercial decisions involving millions of US dollars, companies require more than just speed; they need accountability. This missing component is termed the "Trust Layer," a framework enabling businesses to authenticate an agent's identity, comprehend its authority, and track its actions.

In essence, the future of payments will not solely depend on an AI's ability to act intelligently; it will also depend on how organizations can validate that these actions were authorized, limited, and auditable.

While the past decade has seen fintech dominated by Know Your Customer (KYC) protocols, the emergence of agentic commerce introduces a new dimension of complexity. An AI agent that places an order, books travel, pays a supplier, or transfers funds across borders must not only verify the identity of the company behind it but also understand the identity and authority of the agent itself.

This is where "Know Your Agent" (KYA) comes into play. KYA is more than a mere branding initiative; it signifies a suite of controls: verifying an AI agent, defining its authority, documenting the transaction's intent, and ensuring actions remain within commercial and policy boundaries. For instance, an agent authorized to purchase office supplies should not be able to approve a substantial foreign exchange transfer.

Similarly, a procurement agent with a US$10,000 spending limit should not be able to split payments to circumvent that limit. In Southeast Asia, where many enterprises operate across diverse markets, currencies, payment methods, and compliance frameworks, this is of paramount importance. A regional startup with suppliers in Vietnam, customers in Indonesia, finance operations in Singapore, and banking connections across multiple jurisdictions would face a heightened risk environment without appropriate governance.

The three pillars of the Trust Layer are outlined as follows: credential protection, intent capture, and KYA and governance. Credential protection emphasizes the need to replace sensitive card or account details with secure digital tokens, mitigating the risks associated with compromised agents. Intent capture involves securely transmitting users' budget, preferences, constraints, and instructions alongside transactions, ensuring that an agent's actions align with approved directives.

Lastly, KYA and governance encompass the architecture responsible for verifying agent identities and establishing stringent permission boundaries, including authentication, policy enforcement, audit trails, and the ability to revoke or modify permissions as necessary. While these controls may appear technically intricate, their commercial significance is straightforward: businesses cannot entrust financial decisions to agents without the capability to subsequently explain what transpired, why it occurred, and whether it adhered to established policies.

The urgency of this transition is not merely theoretical. Gartner reports that a significant percentage of AI projects are abandoned after the proof-of-concept phase due to poor data readiness, exorbitant costs, and inadequate risk management. In the context of payments, this is particularly crucial. AI pilots often function as productivity experiments, testing whether a model can compose emails, summarize documents, or automate customer support.

However, in the payments domain, a subpar recommendation could result in time wastage, while a faulty transaction might involve real money, contravene regulations, or strain relationships with banks and suppliers. For Southeast Asian startups, this presents both a cautionary tale and an opportunity. The warning is that merely developing an intelligent agent is insufficient; a product capable of automating procurement or treasury workflows may impress during demonstrations but will face tougher scrutiny from enterprise customers before being deployed in live payment transactions.

They will inquire about transaction approval, data utilized by the agent, and the company's ability to substantiate whether the payment complied with internal policies. Moreover, they will seek clarification on how a bank or payment service provider can trace the authorization chain and manage fraudulent instructions. The opportunity lies in surpassing competitors by providing superior answers to these questions.

Rather than being the entities with the most sophisticated AI interfaces, the leading organizations in this sector will be those that masterfully merge automation with robust governance frameworks, ensuring accountability and transparency in payments.

Written by urgent.news from e27's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at e27.co →

More in AI

Ryanair Signs Five-Year Google Cloud Deal to Expand Artificial Intelligence in Airline Operations

Ireland · TECHNOLOGY Key Facts —The deal: Ryanair announced a five-year cloud partnership with Google on 12 August 2026 to deploy artificial intelligence tools across its operations.

  • Ryanair signs five-year deal with Google Cloud for AI integration.
  • Agreement focuses on Gemini Enterprise platform and Google Workspace.
  • Partnership aims to enhance resilience and efficiency for 300 million passengers by 2034.