Ant International, Visa and Mastercard announced this week that they are jointly developing Know-Your-Agent (KYA), a shared framework designed to verify which AI agent is making a purchase and whether it has permission to do so, a response to forecasts that autonomous agents could handle up to $5 trillion in consumer spending by the end of the decade.
The trust problem behind AI agent payment standards
Jiang-Ming Yang, Ant International’s chief innovation officer, put the stakes plainly in comments to CNBC: “Trust is the foundation of the AI transformation.” That’s not just a soundbite. AI systems can misfire — generating wrong information or acting on instructions the user never actually gave, and when that system also holds spending authority, a mistake stops being an inconvenience and starts being a financial one. That’s the gap this framework is trying to close before agent-led spending scales any further.
What the Know-Your-Agent framework actually does
The mechanics, according to the companies’ own joint statement, center on three things: tying an agent to a verified real-world entity, evaluating how it behaves, and tracking its activity over time. Mastercard’s Pablo Fourez said the goal is interoperability “essential to making agentic commerce work at scale” — giving every merchant and payment provider in the chain a shared way to trust that an agent’s actions actually reflect what its human owner intended, and that someone stays accountable if something goes wrong. Yang described the underlying need in similar terms, telling the companies’ statement that connecting card and wallet networks this way is “critical for securing trust” as agentic commerce grows.
The interoperability piece matters most in practice. Right now, an agent that proves who it is to one payment network would presumably need to start from scratch on every other network it touches. The three companies want that verification to carry over instead — prove it once, and the rest of the system takes your word for it.
The fine print nobody’s talking about yet
Strip away the announcement’s optimism and what’s actually been published is a framework under development, not a finished technical standard. As TechNode reported, no certification criteria or technical specification came with the announcement, and basic questions — how liability gets assigned, how a compromised agent’s credentials get revoked, how much data moves between networks, how disputes actually get resolved — remain open. There’s no public implementation timetable, no pilot volumes, and no list of merchants who’ll test it first. It’s a real commitment between three major players, but it’s a starting point, not a rollout.
Three companies, three different rails
Each partner walks into this collaboration having already spent roughly a year building its own version of the same idea. Visa’s answer, rolled out in April under the name Intelligent Commerce Connect, tries to handle the whole transaction lifecycle for an agent in one place — proving who’s paying, protecting the card number, confirming the user actually authorized it, and enforcing whatever spending limits are attached. By June, Visa had also lined up OpenAI as a partner for its agent-payments push and moved deeper into stablecoins; the company’s own disclosures put its stablecoin settlement flow through VisaNet at roughly $7 billion a year on an annualized basis around that time.
Mastercard split its work across two fronts. Agent Connect, which launched just a day before this three-way announcement, gives a merchant one plug-in point to handle everything from an agent browsing products to finalizing a purchase a customer already approved. Behind that sits Agent Pay, which uses tokens to record exactly what a shopper gave an agent permission to do — and what Fourez calls Verifiable Intent, a way of attaching proof that an agent’s actions actually match the instructions it was given.
Mastercard also built a separate rail entirely, Agent Pay for Machines, unveiled in June with more than 30 partners on board, including Ripple, Coinbase, and Stripe, aimed not at a person shopping through an agent, but at machines transacting directly with other machines, often in small, frequent amounts.
Ant International’s contribution is reach rather than infrastructure. The company links to more than 50 digital wallets through Alipay+, a wallet-interoperability network it runs for cross-border payments, concentrated in markets where mobile payment has largely replaced plastic cards. That matters because so much of global spending already flows through wallets rather than cards to begin with: Worldpay put total wallet-based spending above $13 trillion worldwide in 2025, with wallets handling 56% of e-commerce purchases and taking a 33% share of spending swiped or tapped at physical checkout counters.
Card networks and wallets are increasingly overlapping rather than competing, which is exactly why interoperability is the piece all three companies keep emphasizing — an agent moving through this landscape could plausibly touch a card rail, a wallet, and a stablecoin settlement layer within a single purchase.
Ant’s broader ecosystem is already putting a version of this in front of ordinary users. Roughly three years ago, Ant International split off from Ant Group, the Hangzhou company that still operates Alipay in mainland China, and this week Alipay rolled out an AI feature letting users set up standing purchase instructions, like ordering the same Starbucks drink every morning at a set time, with the app placing the order automatically and only prompting for payment approval when it’s ready.
CNBC reported that the same tool also supports recurring Didi ride-hailing requests. It’s a small-scale preview of the exact dynamic the KYA framework is meant to govern at larger scale: software acting repeatedly on standing permission, with a human still approving the money moving.
None of this makes agentic commerce a solved problem. It makes it a funded one, with three of the industry’s biggest names now betting that workable AI agent payment standards look like one shared trust layer, not three competing ones.