Know Your Agent (KYA)
What Is Know Your Agent (KYA)?
How Does Know Your Agent (KYA) Work?
- Verify the principal. Identify the person or business responsible for the agent.
- Register and assess the agent. Give the agent a distinct digital identity and record its owner, purpose, capabilities, software version, and operating environment.
- Define authority. Specify which systems, data, tools, and transactions the agent may access.
- Authenticate requests. Check the agent’s identity, permissions, and delegated authority before allowing an action.
- Monitor and revoke. Log agent activity, identify suspicious behavior, and suspend or revoke access when necessary.
What Information Can a KYA Record Contain?
- The agent’s unique identifier and cryptographic credentials
- Its developer, owner, or controlling organization
- The verified person or business on whose behalf it acts
- Model, software, configuration, and version information
- Approved tools, APIs, data sources, and destinations
- Delegated permissions and evidence of user consent
- Credential expiration, suspension, and revocation status
FAQ
How Is KYA Different from KYC?
KYC focuses on identifying customers and assessing the risks associated with those relationships. KYA focuses on software agents that access systems, call APIs, or perform actions on behalf of people or businesses. KYA may rely on KYC or KYB to verify the responsible principal, but the agent still needs its own credentials, permissions, monitoring, and revocation controls.
How Does an AI Agent Prove Its Identity?
An AI agent may authenticate using cryptographic keys, certificates, signed tokens, workload identities, or other machine credentials. The receiving system checks whether the credential is valid, trusted, and linked to the registered agent. It must then separately determine whether the agent is authorized to perform the requested action.
Does KYA Replace Identity Verification for People?
No. A person or business may still need to complete identity verification, KYC, or KYB before authorizing an agent. KYA links the agent’s distinct digital identity and permissions to that verified principal. Human identity evidence should remain separate from the credentials used by the software agent.
Does KYA Guarantee That an AI Agent Is Safe?
No. KYA helps establish which agent is acting, who is responsible for it, and what it is permitted to do. An identified and authorized agent can still produce incorrect outputs, follow malicious instructions, or misuse connected tools. Runtime monitoring, secure tool design, limited permissions, and human oversight remain necessary.
When Should an AI Agent Be Reverified?
An agent may require reverification when its owner, publisher, model, software version, configuration, capabilities, or permissions change. Credential expiration, unusual activity, new tool access, security incidents, or increased transaction limits may also trigger a review. A materially changed agent should not automatically inherit the trust assigned to an earlier version.