To "Know Your Agent," You'll Need to Trust Your Data

Verification, at its core, has always been about establishing that the person on the other end of the interaction is who they say they are. Standards like FATF's 40 Recommendations have codified exactly that, requiring financial institutions to verify customer identities using reliable, independent sources before any business relationship begins.
But as AI-powered agents begin to handle payments, manage customer onboarding, and execute financial decisions on someone's behalf, the “actor” initiating those actions may no longer be human. The KYC and AML regulatory infrastructure governing identity verification and risk assessment was simply not written with this new reality in mind. This challenge was at the center of the recent Payments Journal webinar featuring Memoona Anwar (Data Zoo's Chief Compliance and Innovation Officer) and Tracy Goldberg (Director of Cybersecurity at Javelin Strategy and Research), and it has major implications for how companies should be thinking about their data layers.
The Regulations Weren't Written for This
AML, KYC, and KYB rules require organizations to verify the identities of the customers and business they’re dealing with. Every piece of that framework assumes a human or legal entity at the originating end of the relationship.
KYA (Know Your Agent) is what comes next. But, as Memoona put it plainly during the webinar, the regulatory environment hasn't caught up: "Anti-money laundering laws and regulations and requirements are not ready for KYA," she said.
A recent IMF paper on agentic AI in payments makes the same point that traditional authorization mechanisms, including KYC processes and multi-factor authentication (MFA), were designed around human users who explicitly approve transactions. When payments are initiated autonomously by software agents acting under delegated authority, verifying both the identity of the agent and the intent of the underlying user becomes significantly more complex.
KYA standards will eventually be implemented. In the meantime, companies need to be thinking and building in ways that won't require starting over when those standards arrive.
Trust Is Still the Core Problem, and Data Is Still the Answer
What makes verifying an AI agent fundamentally different from verifying a person is that agents operate without a physical presence to cross-reference, a face to match, or documents to validate. That means trust has to be built from digital data alone.
In the webinar, Memoona framed it this way: "Trusting an agent means trusting the underlying data. What is the source of data? How did we verify that this agent has the authority to represent a particular human being or represent a particular system or take those particular actions?"
While the data might be different, the criteria we already use to assess data quality for human identity verification still apply in an agentic world. As Memoona described: "Is it coming from a trusted and independent source? Is it verifiable and consistent? And is it fit for the purpose it is being used for? These are the three things that we have to check."
The Risks Aren't New, But the Scale Is Different
Memoona pointed out that credential stuffing, synthetic identity fraud, and bot attacks existed well before agents. But AI has changed the scale at which they can be executed and how fast.
“Now, AI is capable of trying multiple combinations of identities and trying to break into systems at scale without human intervention,” she said.
There's a subtler issue, too. When an agent acts on a customer's behalf, the merchant or financial institution is no longer interacting directly with the end user — they're interacting with an abstraction layer. That makes intent much harder to assess. Is the action legitimate automation? A misconfigured system? A malicious actor operating through the agent? Traditional controls weren't designed to answer that question and verify identity at the same time.
For compliance teams, this is a real operational challenge. The behavioral patterns and digital footprints that currently help establish trust for human users simply don't exist yet for agents.
An Unexpected Upside for All Identity Verification
The challenge of building a KYA framework may actually end up pushing improvements to KYC that the industry has struggled to make on its own.
Tracy Goldberg raised this during the webinar, and it's an interesting way to look at it. KYC has long been constrained by siloed data, privacy barriers that prevent teams from sharing useful intelligence, and ways of working that haven't evolved fast enough. Building trust infrastructure for AI agents — which requires better data governance, cleaner sourcing, and more rigorous provenance tracking — could push organizations toward practices that strengthen the entire verification stack (not just the agentic piece of it).
That means the organizations investing in data quality and governance now to prepare for KYA are also building the foundation for better identity decisions across the board.
What to Do Before KYA Standards Exist
There’s no KYA compliance mandate yet, but that's not a reason to wait. The organizations that will be best positioned when standards do arrive are the ones already treating data source due diligence as a non-negotiable part of how they operate. Put another way, it’s not just a box to check when a regulation requires it.
At Data Zoo, that practice is built into everything we do. Before we onboard any data source for identity verification, we conduct our due diligence into how the data was collected, how it's maintained, how it's updated, and how it's verified for accuracy. We connect our clients to government databases, credit bureaus, and other primary sources across 40+ countries, because that's the only way to produce verification results that are actually defensible.
That's true for verifying humans, and it will be even more critical for verifying the agents that act on their behalf.
As Memoona put it in her conversation with Tracy, "Regardless of how advanced the technology is or the AI becomes, the limiting factor will always be trust. And trust always comes back to the quality, reliability, and the integrity of data that is being used to operationalize those agents."
In other words, prioritize the data layer, and the rest follows from there.
Watch the full webinar: Know Your Agent: Trust, Verification, and the Future of Agentic AI — featuring Memoona Anwar, Chief Compliance and Innovation Officer at Data Zoo, and Tracy Goldberg, Director of Cybersecurity at Javelin Strategy and Research
Ready to Get Started?
Learn how Data Zoo can help your business with identity verification and fraud detection.
Contact Sales