Know Your Agent: the only definition that matters is the regulators’

Nine months ago we argued Know Your Agent would need to become a real standard. Three regulators have now told us, in the space of nine days, roughly what that standard has to do.
Tim Williams — CEO and Cofounder — AstraSync AI
Last August we published a piece arguing that “Know Your Agent” (KYA) needed to stop being a loose label and start becoming a proper framework, the way Know Your Customer (KYC) did decades ago. That article still gets read every week, which tells us the question has not gone away. It has sharpened. (https://medium.com/@astrasyncai/know-your-agent-kya-establishing-the-standard-for-ai-agent-identity-and-trust-d0fb779fc657)
The question we hear most from financial services clients has not changed: when different vendors say “KYA,” what do they actually mean, and which interpretation maps onto the obligations we are already held to? What has changed is the volume and the source of the asking. In the last few weeks, three separate customer conversations across JAPAC have landed on it. One is a global institutional cross-asset exchange now running a proof of concept with us. Another is a top-20 global bank scoping agent interactions with its consumers. The third is a professional services firm that, until recently, did not consider itself a financial institution at all.
That last one is the tell. Australia’s AUSTRAC Tranche 2 reforms bring roughly 90,000 new reporting entities, lawyers, accountants, conveyancers and real estate professionals, into the AML/CTF regime from 1 July 2026. A whole population of firms is discovering customer due diligence obligations for the first time, at the exact moment their staff are deploying AI agents to do the work. The two timelines have collided.
The timing matters for another reason. Many organisations are setting next year’s budgets right now, and a familiar asymmetry is showing up in the numbers: large, confident line items for AI capability, sitting beside small or absent line items for AI governance. Appetite for innovation-led growth almost always runs ahead of the spend that controls its risk. The people who have to correct that imbalance are Chief Risk Officers and CISOs, and they are being asked to make sensible governance choices about a category whose own vocabulary is still contested. Understanding what KYA actually has to mean is, this quarter, a budgeting problem as much as a compliance one.
Why the question got louder
Three regulatory interventions landed within nine days of each other, and together they moved KYA from a marketing term toward an enforceable expectation.
On 30 April 2026, APRA issued its first AI-specific Letter to Industry, drawn from a targeted review of large banks, insurers and superannuation trustees. On 1 May, the cybersecurity agencies of all five Five Eyes nations jointly published “Careful Adoption of Agentic AI Services,” their first coordinated guidance on autonomous agents. On 8 May, ASIC followed with an open letter reminding every licensee that cyber resilience is a core licensing obligation, not an IT problem to delegate.
Read together, these are not three documents about cybersecurity. They are three regulators independently describing the same gap: institutions are deploying agents faster than they can govern them, and the controls built for humans and for static software do not fit autonomous actors. APRA observed that identity and access management capabilities have not yet adjusted to non-human actors such as AI agents. The Five Eyes guidance went further and specified part of the answer, stating that each agent should carry a verified, cryptographically anchored identity with short-lived credentials, and naming accountability as one of its five core risk categories.
Strip the cybersecurity framing away and what these regulators are circling is the thing we called KYA in August 2025. Who is this agent, who stands behind it, what is it allowed to do, and can you prove all of that after the fact.
Who has the most to gain from getting this right
Firms with AML obligations have the most direct exposure, so they have the most to gain from understanding where KYA is heading before it hardens into rules. An AML-regulated firm that buys an agent-governance product today, only to find it does not satisfy customer due diligence or transaction monitoring when the regulator asks, has not closed a gap. It has bought a false sense of one. For Tranche 2 entities standing up an AML program for the first time, the risk is sharper, because they are choosing tools without the institutional memory that tells a seasoned compliance officer which acronyms carry penalties and which are marketing.
The less obvious point, and the more important one, is that firms with no AML exposure at all have nearly as much to gain. Many are treating agent governance as an extension of identity and access management, a module to bolt onto the system that already governs employee logins. APRA’s letter is a direct warning against exactly that instinct, observing that many entities rely on policy and detective controls rather than enforceable technical restrictions, and that IAM has not adjusted to non-human actors. An agent is not a user with an unusual login pattern. It is an actor that can be created, copied, instructed by a third party, and pointed at systems its owner never anticipated. Governing it as an IAM add-on solves the part of the problem you can see and leaves the part you cannot.
How to think about KYA: start with the framework you already have
The most useful way to evaluate any KYA claim is to test it against the obligations that already exist, then extend.
Traditional financial crime compliance rests on a few well-defined disciplines. KYC establishes who a customer is. KYB does the same for a business. CDD is the ongoing obligation to keep that understanding current and to monitor activity, not a one-time check at onboarding. KYT, Know Your Transaction, asks whether a transaction is consistent with what you would expect and whether you can produce tamper-evident evidence of what happened and why. The FATF Travel Rule requires that verified identity about both parties travels with a transfer, so neither end of the chain is blind.
A genuine KYA framework has to map onto each of these, then extend them to cover what is new about an agent. Five questions fall out of that mapping, and they are the same five a compliance officer already asks of any customer relationship.
First, who is the customer and who is accountable? An agent is not a customer; a principal is. A real KYA approach identifies and verifies the human or legal entity that built the agent, the one that deployed it, and the one that authorised the action. Each carries accountability for a different part of what might go wrong.
Second, does due diligence continue after onboarding? A credential issued once at deployment and never updated as behaviour or ownership changes is a snapshot, not CDD. Anything that issues a passport and considers the job done is incompatible with the ongoing obligation.
Third, can identity travel with the transfer? This is the Travel Rule, extended. Between two institutions it means originator and beneficiary. In an agent context the agent’s own identity and that of its principal have to travel too, so both ends have evidence of who authorised what. A two-party envelope is no longer enough.
Fourth, can it produce KYT-grade evidence? FATF’s December 2025 horizon scan flagged autonomous agents as a vector for high-volume laundering that rules-based systems struggle to catch. The control that survives that is tamper-evident evidence captured at the level of each agent action, not just each settled transaction. Anything that cannot produce that is an operational control, not a compliance artefact.
Fifth, does it map onto the frameworks now forming? Singapore’s IMDA agentic governance framework, MAS’s FEAT principles, AUSTRAC’s reformed regime, the Five Eyes guidance and the EU AI Act are converging on the same expectations. A buyer needs to know which their chosen approach already fits, and which it will have to be ripped out to meet.
What this means outside JAPAC, and outside finance
This article leans on JAPAC examples because JAPAC regulators have been the most explicit. Singapore has published agent-specific governance guidance. Australia has produced three regulatory letters in nine days and is onboarding 90,000 new reporting entities. That makes the region a leading indicator, not an exception.
For a buyer whose regulators have not yet spoken as plainly, the lesson is not “you have time.” It is that the direction of travel is now visible, and decisions made today against a purely local and current view risk becoming rip-and-replace projects when the local regulator catches up. The cost of choosing an approach that cannot extend to CDD, the Travel Rule and accountability is not paid today. It is paid at the next regulatory letter, in migration.
The same logic applies across sectors. A firm with no AML exposure that picks an IAM-style agent control now, because that is the problem it can see, is making the local-and-current decision APRA cautioned against. The frameworks forming around financial services are the most developed, which makes them the best available preview of what general agent governance will be expected to look like everywhere else.
What KYA is claimed to be, that will not meet the test
Several categories of vendor now use “KYA” or position close to it. Each solves a real problem. None, on its public positioning, meets the full test above, and it is worth being precise about where each stops.
Some define KYA as verified payment identity for agent commerce: confirming an agent at a checkout is a pre-credentialed customer with an authorised spend limit. Real and useful at the point of purchase. Silent on ongoing due diligence, behaviour over time, or agents not transacting at the moment they are checked.
Some define it as proof that a human is present behind the agent: cryptographic attestation that a real person authorised an action. Valuable for high-sensitivity moments like signing or approval. Says nothing about who built the agent, what it may do, or how it has behaved.
Some define it as enterprise IAM extended to agents: brokering agent-to-application connections inside one organisation’s identity fabric. A genuine control for shadow AI and over-permissioned internal agents, built to operate inside a boundary rather than across organisational lines, which is exactly where the Travel Rule and counterparty accountability live. This is the IAM-add-on category APRA warned about.
Some define it as cryptographic credentials and delegation: decentralised identifiers and verifiable credentials giving an agent a tamper-evident identity. Foundational primitives, the envelope that carries verified claims, but silent on whether the entity inside it is trustworthy or acting within its authority.
Some define it as on-chain identity and reputation: registries and reputation scores for an agent-to-agent economy where counterparties share no regulator. Rich primitives for a decentralised marketplace. They do not, on their own, produce regulator-grade CDD or KYT evidence against an AML program.
The pattern is consistent. Each category answers one of the five questions well and is silent on the others. Sold under the same three letters, they leave a regulated buyer to assume a single product covers obligations that in fact sit across several of them, or outside all of them.
Where this leaves the original article, and us
The August piece argued that KYA had to combine identity, capability, authorisation, behaviour and dynamic trust, and that trust should be earned continuously rather than granted once. That core still holds. What we got wrong was the timeline. We framed regulation as something to get ahead of. In JAPAC at least, it is already here, and more specific than we expected this soon.
What we built AstraSync to do is make the full five-party trust chain, developer, owner, agent, instructor and counterparty, verifiable across organisational boundaries, with trust scores that update as behaviour changes and a tamper-evident audit record for every agent access request. In the proof of concept now running with the institutional exchange, that puts their compliance position ahead of the regulatory timeline rather than behind it: the evidence a regulator will eventually ask for is generated from day one, not retrofitted after the next letter lands. That the regulators have converged on the same requirements this quickly is, more than anything, a sign the underlying problem was real.
If you are working through what KYA means for your own obligations, in any jurisdiction and whether or not you carry AML exposure, the test in this article is a good place to start. The harder task this quarter is not picking a vendor. It is making sure the governance side of the AI budget is sized to the capability side, and that whatever it buys can extend to CDD, the Travel Rule and accountability rather than being torn out at the next regulatory letter. A CRO or CISO who can map a purchase to the five questions above can defend it to a board that wants the innovation and to a regulator that wants the control. That is the decision worth getting right, and it is gettable with the right framing rather than the right acronym.
Further reading on AstraSync
- What is Know Your Agent (KYA)?
- AI agent identity vs API keys: what changes and why
- PDLSS Permission Boundaries
This essay first appeared on Medium on 26 May 2026.

