Prepared by
Binance Global Policy | October 2026
Steven McWhirter, Global Policy Lead
Diego Montes Serralde, Global Policy Manager
With the expert contribution of Tanveer Kalooji
Main Takeaways
Agentic AI could materially improve financial crime compliance. AI agents can analyse information across multiple systems, investigate alerts, identify relationships, monitor regulatory changes and prepare case assessments. Used responsibly, they could reduce low-value manual work and allow compliance professionals to focus on higher-risk cases and consequential decisions.
Autonomy creates a new accountability challenge. Once AI systems can use tools, delegate tasks, alter records or initiate transactions, institutions must be able to establish which agent acted, who authorised it, what mandate it held and who remains responsible for the outcome.
Know Your Agent (“KYA”) should complement, rather than replace, KYC. KYC establishes the identity and risk profile of the customer or legal entity. KYA establishes the identity, provenance, authority, permissions and operating constraints of the software acting on their behalf.
The strongest governance model separates intelligence from control. AI agents may analyse, prioritise and recommend, while consequential actions should remain subject to defined policy controls, explicit authorisation thresholds, runtime monitoring and proportionate human or institutional oversight.
Policy attention is already moving in this direction. Recent work in the UK and Singapore points to the need for clearer safeguards around agent identity, delegated authority, runtime controls and machine-to-machine authentication, particularly as agentic payments become an early test case for broader autonomous financial activity.
1. Introduction
Financial crime compliance has evolved alongside the financial system it is intended to protect. As payments became faster, financial services became more digital and markets became increasingly global, compliance functions adopted automated screening, transaction-monitoring systems, blockchain analytics and machine-learning models. Agentic artificial intelligence may represent the next stage of that evolution.
Unlike a conventional rules engine, which follows predefined instructions, or a generative AI application, which produces content in response to a prompt, an AI agent can pursue an objective through a sequence of actions. It may retrieve information from multiple systems, determine which tools to use, compare alternative courses of action and adapt its workflow as circumstances change.
In an AML context, an agent could receive a transaction-monitoring alert, review the customer profile, analyse linked accounts and wallets, consult relevant typologies, prepare an investigative chronology and recommend whether the case should be escalated. Several specialised agents could divide those tasks across identity verification, sanctions screening, blockchain tracing and case management, before presenting a consolidated assessment to a human investigator.
This could materially improve the effectiveness of compliance. It could also introduce new risks.
A compliance agent may access highly sensitive information, make inferences about customers, alter risk classifications or close alerts. An agent involved in payments may go further by selecting a route, confirming that predefined conditions have been met or initiating a transaction under delegated authority. If those systems are not properly identified, permissioned and monitored, institutions may struggle to reconstruct how an outcome was reached or determine where responsibility lies. The questions around liability, oversight and control become more acute. Once software can take autonomous or semi-autonomous steps toward a goal, rather than merely generate analysis, institutions must be able to determine whether the agent acted within its mandate, whether appropriate oversight was maintained, and who remains responsible for the outcome.
The central policy question is, therefore, how institutions and regulators can preserve identity, authority and accountability when software begins to act within the compliance and payment architecture.
This paper argues that a Know Your Agent, or KYA, framework could provide an important part of the answer. KYA would not displace KYC, customer due diligence or existing AML/CFT obligations, including applicable transaction-monitoring and payment-transparency requirements. It would provide an additional control layer for software agents by establishing who or what the agent is, which person or organisation it represents, what it is permitted to do and how its conduct can be limited, verified and, where necessary, stopped.
An AI agent should not be permitted to undertake a consequential financial or compliance action unless its identity can be authenticated, its authority is defined and appropriately bounded, and its conduct can be attributed to an accountable principal. |
2. What is Agentic AI?
Agentic AI refers to systems that can pursue an objective through a sequence of actions, rather than merely responding to a single instruction. An agent may determine which steps are required, retrieve information from different systems, use external tools and adjust its approach as new information becomes available.
Agentic AI is not necessarily a distinct model category. In practice, an agentic system may combine one or more AI models with tools, memory, orchestration, external data sources and permissions that enable it to pursue objectives and take actions.
These systems exist on a spectrum. Some operate as assistants that prepare recommendations for human approval, while others can perform defined tasks or initiate actions within the permissions they have been granted. The governance implications become more significant as an AI system moves from producing information to acting on it.
The World Economic Forum has described this development as requiring governance models that take into account an agent’s role, autonomy, authority, predictability and operational context. The United Kingdom’s Digital Regulation Cooperation Forum similarly characterises agentic AI as a shift from AI as a tool to AI as an actor that can assess goals, plan workflows and execute actions affecting real-world environments.
Safeguards should, therefore, depend on what a system is capable of doing in practice, rather than labels as an “AI agent.”
3. From compliance automation to agentic compliance
The financial sector already uses AI across fraud detection, AML monitoring, customer-risk assessment, sanctions screening and operational processes. Agentic AI builds on those capabilities by connecting separate analytical functions into adaptive workflows that can gather evidence, assess context and prepare actions for human or rules-based approval.
A. Customer due diligence and onboarding
An onboarding agent could collect information from approved sources, identify missing documents, compare records and flag inconsistencies. For legal entities, it might analyse corporate registries, ownership structures and beneficial ownership information. For individuals, it could support identity verification, sanctions screening and initial risk classification.
The institution would remain responsible for the adequacy of its customer due diligence. The value lies in reducing fragmented manual processes and directing human attention toward higher-risk or ambiguous cases.
B. Transaction monitoring and investigations
Traditional monitoring systems frequently generate high volumes of alerts based on static rules and thresholds. Agentic AI may support more contextual assessment by examining transactions against the customer’s profile, counterparties, previous behaviour and wider transaction network.
In crypto markets, an agent could combine account-level information with blockchain analytics to identify exposure to sanctioned or high-risk addresses, rapid movement through multiple wallets, cross-chain obfuscation or patterns associated with scams and laundering typologies. This direction is increasingly recognised in international AML/CFT policy. FATF’s 2026 work notes that advances in artificial intelligence, machine learning and big-data analytics have the potential to enhance blockchain analytics and other tools used to detect and monitor suspicious activity.
Once an alert is generated, an investigative agent could build a chronology, map the movement of funds from fiat on-ramps into digital assets, trace subsequent wallet activity across chains and counterparties, identify any off-ramp activity, retrieve supporting records, and draft a case narrative. A separate agent could test whether the proposed conclusion is supported by the evidence and identify contradictory information or unsupported assumptions.
This could improve the use of compliance resources by reducing administrative work and allowing investigators to focus on judgment-intensive cases. It could also improve auditability where the data sources, tool calls, intermediate findings and approvals are retained as part of a unified evidentiary record. Importantly, greater analytical capability does not remove the need for expert judgment. FATF’s 2026 work similarly emphasises that advanced blockchain analytics are most effective when combined with traditional investigative techniques and expert human assessment.
Where a report is being considered, a separate agent or control function could verify that the draft narrative is supported by source records and satisfies the institution’s escalation criteria.
Consequential decisions, including decisions to file a suspicious activity or transaction report, terminate a customer relationship or impose another material restriction, should remain subject to appropriate validation and accountable human or institutional oversight, consistent with applicable law and supervisory expectations.
C. Sanctions and adverse media monitoring
Sanctions compliance increasingly requires institutions to look beyond direct name matching and assess ownership, control, indirect exposure and geographic restrictions and links to sanctioned or high-risk activity, rather than relying on direct name matching alone.
An agent could monitor list changes, identify potentially affected customers, analyse complex ownership structures and prioritise cases according to confidence and urgency.
It could support adverse-media screening by assessing whether a result is a true customer match, whether the source is credible and current, whether the allegations are relevant to the institution’s risk appetite, and whether escalation or further due diligence is warranted.
These capabilities could allow institutions to respond more quickly to emerging threats, adverse-media developments, and changing designations, but they also introduce risks if an agent relies on inaccurate sources, weak entity resolution, outdated reporting, or unsupported inferences.
D. Regulatory change and control mapping
AML obligations evolve through legislation, regulatory rules, guidance and enforcement decisions. An AI agent could monitor relevant sources, identify amendments and map them against the firm’s policies, products and controls.
This could support more continuous compliance management and help institutions identify where monitoring scenarios, risk indicators or procedures require adjustment. Legal and compliance professionals would nevertheless need to validate interpretations, particularly where requirements are ambiguous or differ across jurisdictions.
Across these use cases, the value of agentic AI lies not merely in speed. It lies in its ability to connect fragmented information, assess activity in context and allow human expertise to be focused where judgment matters most.
Those benefits are conditional. Agents may hallucinate, misinterpret information or rely on weak sources. Investigators may defer excessively to apparently sophisticated recommendations. Models trained on historical decisions may reproduce earlier biases, while agents connected to external tools may be exposed to prompt injection, data leakage or unauthorised actions.
The objective should not, therefore, be unrestricted automation, but controlled delegation: agents may support analysis, prioritisation, and recommendation, while consequential outcomes remain subject to deterministic safeguards, documented approvals and human or institutional accountability.
The same architecture could support the controlled use of information received through public-private partnerships, including emerging typologies and risk indicators. As such information becomes more structured and machine-readable, institutions will need to ensure that agents access and use it only within defined legal, confidentiality and purpose limitations.
4. Why is KYC not enough?
KYC answers a foundational question: who is the customer? In an agentic environment, that question remains essential but is no longer sufficient.
An institution may know the customer behind an account while remaining unable to determine whether a particular instruction originated from the customer, an authorised agent, a compromised agent or a sub-agent acting beyond its mandate.
Two agents accessing the same system may also present materially different risks. One may be authorised only to retrieve information. Another may be able to modify a customer’s risk classification, close an alert or initiate a transfer.
Institutions, therefore, need to be able to determine which agent performed a particular action, who developed, deployed and operated that agent, and on whose behalf it was acting. They should also understand the scope of the agent’s mandate, including which data, systems and tools it was permitted to access, whether it could merely recommend an action or had authority to initiate or execute it, and whether it could delegate tasks to other agents.
This assessment should also extend to the limits placed on that authority, including any financial, temporal or geographic restrictions, the mechanisms available to suspend or revoke the agent’s permissions, and the identity of the natural or legal person that ultimately remains accountable for its conduct.
KYA extends beyond conventional identity and access management. Traditional access controls generally determine whether a user or service account may enter a system and perform a defined function. KYA must also establish the agent’s relationship to its principal, the purpose and limits of its mandate, any authority to delegate tasks, and the accountable party responsible for the resulting conduct. This broader context becomes essential where an agent can operate across systems, act asynchronously or exercise discretion within a delegated objective.
The OpenID Foundation has noted that agents often act indistinguishably from human users, while existing authorisation models may be insufficient for asynchronous activity, cross-domain interactions, recursive delegation and agents operating for multiple users. KYA provides a framework for addressing these gaps.
5. What is Know Your Agent (KYA)?
Know Your Agent can be understood as the process of identifying, authenticating, authorising and continuously governing an AI agent that acts within or interacts with a financial service.
KYA should not be treated as granting legal personality to software or applying conventional customer due diligence directly to a machine. The objective is operational accountability, while legal and regulatory responsibilities continue to attach to the relevant natural or legal persons. This is consistent with the broader technology-neutral approach reflected in FATF’s 2026 work, which distinguishes underlying software from the persons exercising control or performing regulated financial functions through it.
A KYA framework should establish the relationship among the different actors involved in an agent-mediated activity. This includes the agent itself, understood as the software instance performing the relevant task, and the principal, meaning the individual or legal entity on whose behalf the agent acts.
The framework should also identify the provider or deployer responsible for developing, operating, configuring or making the agent available, as well as the relying institution, such as a financial institution, VASP or payment provider, that permits the agent to access or interact with its systems. Clearly defining these roles is essential to determine the applicable permissions, responsibilities and lines of accountability.
These roles may overlap depending on how the agent is developed and used. For example, a financial institution may procure, deploy and rely on an internal AML agent itself. By contrast, a consumer-facing agent may be provided by a third-party technology company and authorised by the customer to interact with one or more financial institutions.
Regardless of the operating model, the agent should remain clearly linked to the individual or legal entity that is ultimately accountable for its actions.
In our view, a practical KYA framework could be structured around five layers.
Agent identity and provenance: Each material agent should have a distinct identity linked to its provider, deployer, responsible legal entity, software or model version, and authentication credentials. This allows institutions to attribute an action to a specific authorised agent, rather than merely confirming that a valid user or service account was accessed.
Link to an accountable principal: The agent should be linked to the individual or organisation on whose behalf it acts. While responsibilities may be allocated contractually among technology providers and regulated firms, the use of an agent should not dilute the regulated institution’s responsibility for meeting its AML/CFT obligations.
Mandate and permissions: Each agent should operate under a clearly defined mandate specifying the actions, data and tools available to it and the purposes for which they may be used. Permissions should follow the principle of least privilege and, where personal or sensitive information is involved, incorporate appropriate purpose limitation, data minimisation and access controls. They should also distinguish between the ability to analyse or recommend and the authority to make or execute consequential decisions.
Delegation and monitoring: Where agents may use sub-agents or external services, the permitted delegation chain should be defined and authenticated, with delegated authority remaining within the original mandate. Institutions should continuously monitor both the agent’s behaviour and, where it can initiate financial activity, the transactions generated through that authority. Monitoring should identify behaviour that exceeds permissions, departs from expected activity, indicates compromise or creates financial-crime risks requiring additional review.
Revocation and auditability: Institutions should be able to suspend an agent, revoke or restrict its permissions and introduce additional human approval where necessary. Material actions should remain traceable to the agent, its principal, the authority in force, the tools and data used, any human intervention and the resulting outcome.
For consequential actions, KYA should support point-of-action verification. The relevant control layer should be capable of confirming that the agent’s identity and credentials remain valid, that the proposed action falls within its current mandate and that no approval, risk or revocation condition prevents execution.
In practical terms, a minimum KYA record would allow an institution to verify the agent’s identity, the principal it represents, the party responsible for deploying it, the scope and duration of its authority, any right to delegate, its current status and the context in which it is authorised to operate. The record should support attribution and control without implying that the agent itself assumes the regulatory status or obligations of the person on whose behalf it acts. That information should accompany the agent throughout the relevant interaction and remain available for subsequent review.
As agent-mediated activity scales, elements of the KYA record should be capable of being expressed in machine-readable and, where appropriate, cryptographically verifiable form. This could allow an agent’s identity, principal, mandate, limits, delegation rights and status to be checked consistently across financial institutions and payment infrastructures.
This type of minimum record could also support emerging trust frameworks for agentic payments, where regulators and industry are beginning to consider standardised approaches to agent identity, verification and machine-to-machine authentication.
Taken together, these five layers provide the foundation for treating AI agents as identifiable, authorised and governable participants within a financial institution’s control environment. Their practical value, however, depends on how they are embedded into day-to-day compliance processes. An AML workflow provides a useful illustration of how KYA can translate these principles into operational controls, from verifying an agent’s authority at the outset to preserving human accountability for consequential decisions.
6. KYA in practice: a controlled AML workflow
In practice, an agentic AML workflow could involve specialised agents reviewing customer information, transaction behaviour, blockchain activity and sanctions exposure. Before accessing a case, each agent’s identity, mandate and permissions would be verified. Their findings could then be consolidated and independently challenged before any recommendation is accepted.
Consequential outcomes should remain subject to fixed, rules-based controls that the agent cannot override, together with appropriate human approval. The process should preserve a record of the evidence considered, its relevant provenance and permitted use, the agents and models involved, material tool calls, any human intervention and the final decision. This reflects a clear separation of functions in which agents analyse and recommend, controls enforce mandatory requirements, and accountable humans decide where the consequences are significant.
This direction is already beginning to emerge in policy and industry practice. In July 2026, the Monetary Authority of Singapore announced the Safeguards for Agentic Finance at Runtime (“SAFR”) framework, developed with industry participants under its BuildFin.ai initiative. SAFR focuses on the need for real-time safeguards where AI agents operate in financial services, including policy-bound execution, validation before action, auditability and interoperability. Its emphasis on verifying and recording an agent’s proposed actions before execution is closely aligned with the KYA approach proposed in this paper in which agents may support financial workflows, but their actions should remain bounded by identity, authority, mandate and control requirements that can be reviewed after the fact.
7. Agentic payments and the case for KYA
The need for KYA becomes more immediate where agents can transact. The IMF has described agent-mediated payments as a potential transition from “click-to-pay” toward “decide-to-pay,” in which software agents may compare options, determine whether conditions have been met and initiate financial actions under delegated authority.
This concern is increasingly reflected in central-bank thinking. In June 2026, Sarah Breeden of the Bank of England observed that agentic AI could move payments and commerce from recommendation mode, where humans still execute transactions, toward systems in which agents automate the final step. She highlighted that this raises practical questions around how users securely provide consent and authorisation to agents, how disputes and liability should be handled for erroneous or fraudulent transactions, and how authorities can avoid fragmentation as AI firms, merchants and payment systems develop their own agent-interaction protocols.
The United Kingdom’s Financial Services AI Adoption Plan points in the same direction. It identifies agentic payments as a near-term use case for autonomous financial systems and notes that these models raise uncertainty around legal accountability, liability, consent and fraud in automated payment flows. Importantly, the Plan recommends the development of a trust framework for agentic payments built around legal and liability standards, Know Your Agent protocols, and interoperable machine-to-machine authentication. This provides a useful policy signal in which KYA is not merely an internal compliance concept, but part of the broader trust infrastructure likely to be needed as agents begin to initiate or support financial transactions.
These developments create an architectural tension. AI systems are probabilistic and adaptive, while payment infrastructures depend on predictability, legal certainty and deterministic execution.
A useful model is to separate the process into three layers.
In crypto markets, programmable wallets and smart contracts may allow permissions to be expressed directly through code. A wallet could limit an agent to specified assets, approved addresses, transaction values or time periods, while requiring human approval where risk indicators or thresholds are triggered.
Before processing an agent-initiated transaction, a VASP or payment provider should be able to verify the identity and status of the agent, the principal it represents, the scope of its delegated authority and whether the transaction falls within that mandate. Existing transaction-level obligations and risk controls should continue to apply irrespective of whether an instruction originates from a person or an authorised agent. Depending on the activity, these may include sanctions screening, Travel Rule requirements, wallet-risk assessment and enhanced controls for higher-risk cross-chain or DeFi exposure.
A proportionate framework should distinguish among agents that retrieve information, recommend transactions and control or transfer value. The greater the authority and potential consequence, the stronger the identity, monitoring and approval requirements should be.
This is best understood as “bounded autonomy” in which agents may operate within clearly authorised objectives, permissions and limits, but stronger safeguards should apply as their ability to affect customers, compliance outcomes or the movement of value increases.
8. Conclusion
Agentic AI could significantly strengthen financial crime compliance. It can connect fragmented information, identify relationships across large datasets, accelerate investigations and help institutions respond more dynamically to changing risks.
The same capabilities change the control environment. Once software can select tools, delegate tasks, alter records or initiate payments, institutions need to know more than who the customer is. They must know which agent acted, who it represented, what authority it held and whether its conduct remained within that authority.
Know Your Agent offers a practical framework for answering those questions. KYA is an accountability layer for software operating within the financial system.
The future AML architecture may, therefore, be understood through three complementary lenses: (1) Know Your Customer, which establishes the identity and risk profile of an individual or legal entity; (2) Know Your Transaction, which examines how value moves, why the activity is occurring and whether it is consistent with expected behaviour; and (3) Know Your Agent, which identifies the software actor involved, the authority under which it operates, the limits of its permissions and the person or entity that remains accountable for its actions.
Together, these disciplines could provide the trust architecture required for an increasingly automated financial system. As AI agents gain greater authority to influence decisions and move value, governance should follow that authority. Greater autonomy, access and potential consequence should be matched by stronger requirements for verifiable identity, bounded permissions, auditable conduct, revocation and continuing human or institutional accountability.
