Know Your Agent (KYA) is the practice of establishing and verifying what an autonomous software agent is, who is accountable for it, what it is authorised to do, and whether it can be trusted to act — before you give it access, authority, or money.
KYA is the agent-era counterpart to Know Your Customer (KYC): KYC verifies the customer; KYA verifies the agent.
Why KYA exists
For decades, the actor on the other side of a digital transaction was either a person or a fixed piece of software. Identity practice grew around those two cases: KYC for people and companies (a regulatory anti-money-laundering duty built on customer due diligence), and machine identity for services and workloads (credentials for a process, not a principal).
Autonomous agents break that split. An agent is software, but it acts on behalf of a person or an organisation, often for many steps, with its own initiative and tool access. The service it talks to must decide, per request: is this really the agent it claims to be, who stands behind it, and is this specific action within its authority?
That decision is what KYA operationalises. The work is not one check at onboarding; it is a lifecycle — enrol, verify, authorise, monitor, and revoke.
The five questions KYA answers
- Identity — What is this agent, technically? Does it have a verifiable identifier?
- Principal — Who is legally accountable for its actions?
- Authority — What is it permitted to do, for how long, up to what limits?
- Evidence — Can it prove it is what it claims to be, and can actions be traced?
- Lifecycle — How is it onboarded, monitored, and revoked?
If you can answer all five for a given agent, you have done KYA for it. If you can answer only “it presented an API key”, you have not.
What KYA covers
KYA sits at the intersection of several established disciplines. It does not replace them; it names the gap between them.
| Layer | Question | Typical standards / practice |
|---|---|---|
| Identity | Who/what is the actor? | NIST SP 800-63 digital identity; SPIFFE workload identity |
| Principal | Who is accountable? | KYC/KYB duties; EU AI Act provider/deployer roles |
| Delegation | On whose authority does it act? | OAuth 2.0; OAuth token exchange (RFC 8693); IETF agent drafts |
| Credentials | What proves its rights? | W3C Verifiable Credentials; OID4VCI; eIDAS 2 wallets |
| Permissions | What may it do? | Scoped credentials; rich authorization requests (RFC 9396) |
| Audit | What did it do? | Log management (NIST SP 800-92); EU AI Act record-keeping |
| Revocation | How is it stopped? | Token revocation (RFC 7009); credential status lists |
Each row has mature standards; the KYA problem is joining them into one verifiable chain from principal → agent → action.
How KYA relates to neighbouring ideas
- KYC is a regulated anti-money-laundering duty to identify and verify customers (people and legal persons), per FATF Recommendation 10. KYA borrows its discipline but asks about the agent, not the customer.
- KYB (Know Your Business) is the industry label for applying due diligence to legal entities, including beneficial ownership. It tells you who the company is, not what its agent is doing.
- IAM (identity and access management) manages accounts and permissions inside your estate. It usually assumes the actor is a known employee or service; it does not, by itself, establish who is behind an external agent.
- Zero trust (NIST SP 800-207) says do not trust by network location; evaluate every request against policy. KYA supplies the identity-and-authority inputs that a zero-trust decision needs for agents.
- AI governance frameworks (e.g. NIST AI RMF, ISO/IEC 42001) set up policy and accountability. KYA is the operational identity layer those policies need at the point of access.
Where the standards are today
KYA is emerging, not settled. Several workstreams matter as of October 2026:
- W3C Verifiable Credentials Data Model 2.0 is a W3C Recommendation (May 2025). It defines the issuer/holder/verifier roles and the data model for tamper-evident claims, which agent credentials can reuse.
- IETF is actively writing OAuth extensions for agents, including an on-behalf-of authorization flow that carries the agent’s identity through consent into the access token, and drafts on AI-agent authentication and authorization.
- EU AI Act (Regulation (EU) 2024/1689) imposes transparency obligations for certain AI systems (Article 50) and, for high-risk systems, automatic event logging (Article 12).
- eIDAS 2.0 / EUDI wallets (Regulation (EU) 2024/1183) push verifiable credentials into mainstream EU identity, a likely substrate for agent credentials.
- Payments are moving fastest: protocols such as Google’s AP2 carry cryptographically signed mandates (as verifiable credentials) so an agent can prove the user’s intent to a merchant.
None of these is a complete KYA standard. Treat any vendor claim of a finished “KYA product” with care; the useful question is which of the five questions above it actually answers, and with which verifiable evidence.
Common misconceptions
- “It’s just API keys with extra steps.” API keys authenticate a caller; they do not express a principal, a scope, an expiry, or a revocable mandate. Identity is necessary but not sufficient for KYA.
- “The model is the agent.” A model is a component. The agent is the running system that holds credentials and takes actions; that system is what must be identified and limited.
- “Prompt guards are agent security.” Prompt-injection defences are valuable, but they are not identity. An attacker who impersonates a trusted agent does not need to attack the prompt.
- “KYA is a one-time onboarding check.” Authority and risk change; KYA must be continuous and revocable.
This is our working definition, written to be useful rather than authoritative. It is grounded in the primary sources listed below; where the field has no settled answer, we say so.
FAQ
Is “Know Your Agent” an official standard? No. There is no single ratified standard called KYA. The term names a real, emerging problem; the building blocks are standards such as NIST SP 800-63, W3C VC, and OAuth/IETF work.
Is KYA only for AI/LLM agents? The term is used mostly for AI agents, but the discipline applies to any delegated autonomous actor. Classic bots and RPA already needed parts of it.
Who needs to do KYA? Anyone who lets an external or semi-autonomous agent act on their systems or accounts: API and platform teams, payments and fintech, and any organisation extending KYC/AML or IAM to agents.
Is KYA a legal requirement? Not as such. Specific duties (identity proofing, transparency, record-keeping) sit in regulations such as the EU AI Act and AML rules. KYA is the practice that connects them; it is not itself a named legal obligation.
Is this legal advice? No. This is an explanation for practitioners. For compliance decisions, take professional advice.
Keep reading
- KYA vs KYC vs KYB
- Why agent identity is a new problem
- Glossary: agent identity, principal, delegation, revocation
Sources
- NIST, SP 800-63-4, Digital Identity Guidelines — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)
- NIST, SP 800-207, Zero Trust Architecture — https://csrc.nist.gov/pubs/sp/800/207/final (accessed 2026-10-03)
- W3C, Verifiable Credentials Data Model v2.0 — https://www.w3.org/TR/vc-data-model-2.0/ (accessed 2026-10-03)
- IETF, draft-klrc-aiagent-auth-00, AI Agent Authentication and Authorization — https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-00.html (accessed 2026-10-03)
- IETF, draft-oauth-ai-agents-on-behalf-of-user-02 — https://datatracker.ietf.org/doc/html/draft-oauth-ai-agents-on-behalf-of-user-02 (accessed 2026-10-03)
- European Commission, EU AI Act, Article 50 — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50 (accessed 2026-10-03)
- ISO, ISO/IEC 42001:2023, AI management systems — https://www.iso.org/standard/42001 (accessed 2026-10-03)
- FATF, The FATF Recommendations — https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html (accessed 2026-10-03)
- SPIFFE, SPIFFE Concepts — https://spiffe.io/docs/latest/spiffe-about/spiffe-concepts/ (accessed 2026-10-03)