The principal is the human or organisation legally accountable for an autonomous agent’s actions. In KYA, every agent identity should resolve to exactly one accountable principal.
Why it matters
Software does not owe duties; people and organisations do. When an agent buys, files, negotiates, or deletes, the question “who is responsible?” must have an answer that is not “the model”. The principal is that answer, and it is the accountability anchor that Know Your Agent is built around.
This mirrors existing accountability concepts elsewhere:
- AI regulation already assigns roles and duties to actors such as providers and deployers of AI systems (EU AI Act). The principal is the KYA-side anchor for accountability.
- AI risk frameworks (NIST AI RMF) place accountability in governance structures, not in the system itself.
- AML/CDD regimes make an individual legally responsible for a customer relationship; KYC/KYB establish who that is.
Note the distinction between a principal and an operator: an operator runs the agent’s infrastructure, while the principal is on whose authority and account it acts. Both may need identifying, but only the principal is the accountability anchor.
What a good principal record contains
- A verified legal identity (tied to KYC/KYB where relevant).
- The scope of the agent’s authority it grants.
- A point of contact for revocation and incident response.
How it works in practice
The principal appears inside the delegation itself. In OAuth terms, the agent is the client acting “on behalf of the resource owner” — the principal — and token exchange keeps a record of who is acting and on whose behalf. That record is what lets a service, or an auditor, attribute an action to a person or company rather than to a process.
A principal is not a new kind of legal person. Where regulated activity is involved, the principal still needs KYC/KYB; KYA adds the agent layer on top. That separation is the core of KYA vs KYC vs KYB. To see how the link is asserted and checked, see How to verify an agent.
Related terms
Sources
- European Union, Regulation (EU) 2024/1689 (AI Act) (accessed 2026-10-03)
- NIST, AI 100-1, AI RMF 1.0 (accessed 2026-10-03)
- FATF, The FATF Recommendations (accessed 2026-10-03)
- ISO, ISO/IEC 42001:2023 (accessed 2026-10-03)
- IETF, RFC 6749, The OAuth 2.0 Authorization Framework (accessed 2026-10-03)
- IETF, RFC 8693, OAuth 2.0 Token Exchange (accessed 2026-10-03)
Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.