Know Your Agent (KYA) is the practice of establishing and verifying the identity, principal, permissions, and trust history of an autonomous AI agent before it is allowed to act.
KYC verifies the customer; KYA verifies the agent.
Why it matters
An agent is software that acts on behalf of a person or organisation, often with initiative across many steps. The service on the other side must decide, per request, whether the agent is genuine, who is accountable for it, and whether this action is within its authority. KYA is the name for doing that deliberately rather than implicitly.
It draws on established practice: digital identity assurance (NIST SP 800-63), per-request evaluation (zero trust, NIST SP 800-207), verifiable claims (W3C Verifiable Credentials), delegated authorization (OAuth), and the due-diligence mindset of KYC.
What KYA covers
- Agent identity — a verifiable identifier for the agent.
- Principal — the accountable human or organisation.
- Delegation — the explicit, scoped transfer of authority.
- Credentials — verifiable proof of identity and rights.
- Permissions — what the agent may do, up to what limits.
- Audit trail — a record of actions and their authority.
- Revocation — a fast, precise way to withdraw authority.
Common confusion
KYA is not a single ratified standard; it is an emerging umbrella term. Vendors often use it loosely. The useful test: how many of the items above does a given approach actually establish with verifiable evidence?
Related
Sources
- NIST, SP 800-63-4 — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)
- NIST, SP 800-207 — https://csrc.nist.gov/pubs/sp/800/207/final (accessed 2026-10-03)
- W3C, Verifiable Credentials Data Model v2.0 — https://www.w3.org/TR/vc-data-model-2.0/ (accessed 2026-10-03)
- IETF, draft-klrc-aiagent-auth-00 — https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-00.html (accessed 2026-10-03)
- FATF, The FATF Recommendations — https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html (accessed 2026-10-03)