For decades, one of the central rules of modern finance has been simple: Know Your Customer. Banks want to know who you are before opening an account, exchanges want to know who is moving money, and regulators want to know who stands behind a transaction. But we are now entering an economy in which the actor conducting the transaction may no longer be a person at all.
Artificial intelligence is moving from systems that advise us to systems that act for us. Today, an AI may help compare airline tickets; tomorrow, it may buy the ticket, reserve the hotel, purchase insurance, pay for the trip and hire another AI to complete part of the task. Once machines begin acting economically on our behalf, a new question appears: Who knows your agent?
I call this emerging requirement Know Your Agent, or KYA. If my AI agent tries to buy a $900 airline ticket, the airline needs to know more than my identity. It needs to know that the agent really represents me, that I authorized the purchase, how much it may spend, what it is allowed to buy and whether that authorization is still valid.
The key issue is therefore not simply identity, but identity plus authority. A useful future architecture may be: KYC the human, KYB the business, KYA the agent and KYT the transaction. Together, these layers can establish who is acting, for whom, under what authority and with what consequences.
Importantly, solutions are already emerging. Experian has introduced an Agent Trust framework that connects verified people to the AI agents acting on their behalf, while Skyfire and the KYAPay initiative are working on protocols that allow agents to present identity, authorization and payment information. These systems are early, but they show that KYA is already becoming a commercial infrastructure problem rather than merely a theoretical one.
Blockchain-based solutions are also developing. The cheqd network is building decentralized identity and verifiable credential infrastructure that can allow agents to prove who they are, who controls them and what permissions they possess. Ethereum’s ERC-8004 standard takes another approach by creating persistent agent identities, reputation records and validation mechanisms that can follow an agent across an ecosystem.
Virtuals Protocol is beginning to connect these ideas to an actual agent economy. Its Agent Commerce Protocol incorporates agent identity, reputation and machine-to-machine transactions, while ERC-8004 identities can help establish which agent is participating. The different systems need not compete; one may provide credentials, another identity, another reputation and another the payment layer.
Imagine telling your AI: “Book me a hotel in New York for three nights, but spend no more than $1,200.” Your agent could carry a digital credential showing that it represents you and is authorized to spend up to that amount on accommodation. The hotel’s AI could verify the credential, negotiate with your agent and complete the transaction without either side needing a human to intervene.
The really important change comes when agents begin hiring other agents. Your personal AI might hire a tax agent, which purchases financial data from another agent and rents computing capacity from another. We then have machines employing machines, paying machines and evaluating machines, creating an economy that operates at machine speed.
That means trust must also operate at machine speed. Traditional systems based on uploading passports, answering security questions and waiting for manual approval were designed for humans. KYA will need to be continuous, programmable and cryptographically verifiable.
It must also be proportional to the task. An AI buying a $20 book should not need the same authorization as an AI transferring $1 million, and a delivery robot entering an apartment building should not require the same credentials as an autonomous drone approaching an airport. The future will therefore require an ecosystem of identities, credentials, permissions, reputations and audit trails rather than one universal AI identity.
The problem becomes even more important when AI moves into the physical world. A delivery robot arriving at a secured building may need to prove who sent it, what it is carrying, where it is allowed to go and how long its authorization lasts. The same logic will apply to autonomous vehicles, industrial robots, drones and eventually humanoid machines.
Regulators should therefore begin thinking not only about how to regulate AI models, but how to regulate AI actors. If an AI merely recommends a stock, accountability is relatively straightforward; if it independently buys the stock, borrows money and hires another agent, responsibility becomes more complicated. A robust KYA system would at least create a verifiable record showing which agent acted, whom it represented and what authority it possessed.
There is also a strategic opportunity here for technologically advanced countries such as Israel. Israel cannot compete with the United States or China simply by building the largest AI models, but it has unusual strengths in cybersecurity, cryptography, fintech, digital identity and autonomous systems. Building the trust infrastructure for billions of future AI agents could therefore be an area where Israel plays a role far greater than its size.
Prof. Ilan Alon Photo: CourtesyThe first chapter of the AI revolution was about whether machines could generate intelligent answers. The second is about whether machines can act independently in the economy. The third will be about whether we can trust them when they do.
For decades, the financial system has asked one basic question: Do you know your customer? The autonomous economy will require another question alongside it. Who knows your agent, and how do they know?
- Prof. Ilan Alon is a professor of Economics and Business at Ariel University (Israel) and the University of Agder (Norway)





