On 10 September 2026, Visa, Mastercard and Ant International announced a joint initiative to develop a Know-Your-Agent interoperability framework. The aim is to help card networks, digital wallets, agent platforms and online marketplaces recognise trusted AI agents while retaining their own approval and risk-management processes.
The announcement does not mean that a universal standard has already been completed or deployed. It marks the beginning of an effort to align three existing approaches: Visa’s Trusted Agent Protocol, Mastercard’s Verifiable Intent and Ant International’s Agentic Mobile Protocol. The collaboration will take place through BuildFin.ai, an initiative convened by the Monetary Authority of Singapore to support responsible AI development in financial services.
When AI moves from recommending to acting
Digital assistants can already compare products, prepare a shopping basket or suggest a flight. Agentic commerce introduces a more sensitive step: an agent may be authorised to complete the purchase on the user’s behalf.
That shift turns an interface problem into a trust problem. A merchant needs to distinguish an agent mandated by a customer from a malicious bot. A payment provider needs to understand the mandate. An issuer or wallet must determine whether the transaction stays within the user’s limits. If the purchase is later disputed, the parties need an auditable record.
A transaction can no longer answer only one question — is the payment method valid? It must also establish which agent is acting, for whom and for which precise purpose.
Why separate protocols are not enough
Visa, Mastercard and Ant International have already developed their own building blocks. Visa’s work is designed partly to help merchants distinguish legitimate agents from unwanted bots. Mastercard focuses on making the user’s intent verifiable. Ant International has developed a mobile- and wallet-oriented protocol that includes agent registration, spending controls, passkeys and one-time payment credentials.
These approaches tackle complementary problems. But if every network, wallet, merchant and agent platform uses a separate language, an agent may need to be integrated and recognised independently in each environment. Technical costs rise, controls become difficult to compare and the user experience varies from one ecosystem to another.
The proposed Know-Your-Agent framework is intended to provide a shared recognition layer. According to the companies, it would allow participating organisations to recognise a trusted agent without giving up their own authorisation, compliance and risk decisions. Interoperability would not remove local controls; it would provide a common foundation on which those controls could operate.
What a payment system would actually need to verify
An AI agent that can make a payment cannot be treated as an ordinary automated browser. A robust architecture must link at least four elements.
1. The agent’s identity
Participants need to know which platform or provider operates the agent, how the agent was registered and whether its attributes remain valid when the transaction occurs. This technical identity does not replace customer or merchant due diligence. It adds a new digital actor to the trust chain.
2. The user’s mandate
The authorisation should define what the agent is allowed to do: the maximum amount, time period, category of goods or services, possible beneficiary and any confirmation conditions. A mandate that is too broad creates risks similar to an unlimited power of attorney. One that is too narrow removes the benefit of automation.
3. Credentials and risk controls
Merchants do not need access to the underlying payment data. Tokens or one-time credentials can reduce exposure of sensitive information. Banks and wallets must still apply fraud, authentication, sanctions and anti-money-laundering controls according to the context of each transaction.
4. Evidence and accountability
A transaction may be technically authorised and still fail to reflect the customer’s actual intent. The system therefore needs evidence of the mandate, the limits applied, the action performed and the risk decisions made. This audit trail will matter for refunds, disputes and the allocation of liability.
What the announcement does not settle
The initiative reported by Reuters does not provide a publication timetable, a final governance structure or detailed liability rules for agent platforms, merchants, wallets, acquirers, networks and issuers. It does not announce a large-scale production deployment.
Important questions remain open. Who will certify an agent? How will that status be suspended or revoked? What evidence will be accepted in a dispute? How should an ambiguous instruction or a change made after the initial consent be handled? Which data can be shared without exposing the user unnecessarily?
Know-Your-Agent should also not be confused with Know Your Customer. Identifying the agent does not release regulated institutions from identifying the relevant people and businesses, assessing the transaction and complying with local rules.
Why African payment providers should pay attention
This is not presented as an African launch. It is nevertheless relevant to markets where wallets, mobile money, super apps and cards coexist. In those environments, an agent may eventually need to interact with several payment methods, each governed by different limits, rules and liability models.
African providers should seek to prevent a standard designed mainly around cards or large international merchants from treating local wallets as an afterthought. Passkey availability, device capabilities, mobile connectivity, authentication journeys, control costs and redress mechanisms all need to work under local conditions.
Banks, fintechs and mobile-money operators therefore have an interest in following the governance of these standards before the main technical choices become fixed. Their participation can help ensure that mobile-first payments, low-bandwidth journeys and transactions involving several providers are considered from the outset.
Trust is becoming infrastructure
The significance of this initiative is not simply that an AI system may buy something for a user. That capability already exists in pilots and separate protocols. The harder task is to make delegated purchasing understandable and verifiable across ecosystems.
A reliable agentic payment must connect identity, intent, authentication, risk management and evidence. Without that chain, automation will merely accelerate transactions whose origin and accountability are difficult to explain.
Visa, Mastercard and Ant International are now trying to develop a common language. The value of the resulting framework should be measured less by the number of registered agents than by its ability to preserve user consent, operate across multiple payment rails and resolve incidents when an agent does not do exactly what the user expected.




