Know Your Agent Is Not Agent Control | Elacity
The card networks want to verify the AI agents that spend your money. Know Your Agent confirms who is acting. It never bounds what the agent can do, or who holds its key.
Know Your Agent Tells You Who Is Spending. Not What It Can Do.
Soon an AI agent will hold something that can move your money without waking you. The card networks have a plan for that moment, and the plan is a name tag.
Checking the machine's identity confirms who is at the counter. It says nothing about how much that visitor can take, for how long, or whether you can stop it once its hand is already in your account. Identity is not authority, and the gap between them is exactly where your money sits.
What Know Your Agent actually does
On September 10, 2026, Ant International, Visa, and Mastercard said they will build a shared standard to identify, verify, and monitor the AI agents that book, shop, and pay for people. The group calls the framework Know Your Agent, and it is what it sounds like: the identity check banks run on you, pointed at software. The companies project that AI agents will move three to five trillion dollars of consumer commerce by 2030, which is why three rivals suddenly agree on anything.
Each already runs its own version. Visa has its Trusted Agent Protocol, Mastercard has Verifiable Intent, and Ant has its Agentic Mobile Protocol. Know Your Agent stitches them together so an agent cleared by one network works across the others without registering again. Under the hood, Visa's protocol has the agent prove itself by signing each request, which the merchant validates against the agent's public key. The agent carries a credential; the network confirms the credential is genuine.
There is no published technical specification, no named governance body, and no implementation timeline yet. What exists is the shape of the answer, and the shape is the tell.
Identity is the easy half
Verification is real progress, and that deserves to be said plainly. A signed request from a known agent beats an anonymous bot draining a checkout. Fraud that runs on impersonation gets harder. If the choice were Know Your Agent or nothing, take Know Your Agent.
But identity answers one question, who is acting, and leaves the dangerous one untouched: what can this actor do once it is inside? A verified agent with a standing credential and broad reach is still an agent that can be tricked, hijacked by a poisoned instruction, or simply told to do too much. The badge does not shrink the blast radius. It only confirms whose badge went off. We made this same point when a stored secret turned out not to be an identity at all.
A spending cap gets waved around as the safeguard here, but a spending limit is not a safety model when the agent still holds the authority and the key. Every era of computing has repeated the error in a new costume: grant a process broad power because you trust the identity behind it, then learn the identity was borrowed. Naming the actor was never the fix. Bounding the action is.
Verification also builds the honeypot
A framework that links every agent to a real entity and tracks its behavior over time is, by construction, a database of who is doing what with their money. It is a surveillance record and a breach target in one object, held by the very networks whose customer data already leaks. Solving trust by centralizing it rebuilds the thing that keeps failing: one place worth attacking, one operator worth compelling, one lock everyone else has to depend on.
Move the boundary to what it can touch
The better question is not whether an agent is who it claims to be. It is what the agent can touch, for how long, and whether you can stop it mid-action. That shift, from identity to bounded capability, is the whole game, and it changes what you build. It is the layer Elacity is built for, and three mechanisms carry it.
- Keys used, never owned. An agent can sign or pay for you while the secret exists in the clear for only a split second, inside a sealed sandbox, welded to that one transaction, then wiped. Copy the agent and you copy nothing reusable, because there is no stored key left to steal.
- One gate for humans and agents. There is no separate surveillance layer watching machines differently from people. A human and an agent pass through the same capability model, where every permission is narrow, expiring, revocable, and fails closed. Revoke a grant and the action stops in flight.
- Audit you hold. The record of what your agent did lives with you, not in a shared corporate registry that becomes the next breach headline. Owning the log is owning the accountability.
Visa let strangers transact without trusting each other; Elacity lets humans and AI agents compute together without surrendering their keys.
The honest edge
The hard primitive is already real: a key an agent can use but never see. The consumer agent layer around it, the wallet and the autonomous approve-or-kill loop, is still being built, and it is fair to hold us to that line. This is trust-minimized, not magic. The point is only that surrender should not be the price of letting a machine act for you.
Know Your Agent will ship, and you should probably let it check the badge. Just do not mistake a verified spender for a bounded one, or a registry an operator holds for control you hold. Follow Elacity on X for how the ownership layer for the agent economy takes shape.