Adjacent interoperability
Know Your Agent (KYA): cross-network agent trust
KYA is emerging as a cross-network trust framework for identifying and continuously assessing agents in commerce; it is not currently a published harness-execution protocol.
Current status: framework first, common specification not yet published
Section titled “Current status: framework first, common specification not yet published”On 10 September 2026, Ant International, Mastercard and Visa announced that they had begun collaborating on a Know-Your-Agent (KYA) interoperability framework for agentic commerce. The stated goal is to let card networks, digital-wallet ecosystems, agent platforms and marketplaces recognize common agent trust signals and reduce duplicated onboarding and identity checks while preserving each network’s own verification and decisioning.
The announcement is meaningful interoperability work, but it is not evidence of a finalized KYA standard. The reviewed sources do not publish a common KYA wire schema, protocol version, conformance suite or mandatory cross-network implementation profile. Treat KYA here as an emerging framework/common-principles effort, not as a ratified transport or execution protocol.
What the announced KYA collaboration covers
Section titled “What the announced KYA collaboration covers”| Area | Announced role |
|---|---|
| Cross-network operator traceability | Link an agent to a validated operator, cardholder, business or organization so agent activity remains attributable. |
| Shared certification requirements | Assess agents against security and behavioral requirements intended to show that they operate as expected. |
| Continuous transaction monitoring | Combine identity and transaction signals for ongoing assessment and certification rather than relying only on one-time enrollment. |
| Network-local decisioning | Keep each participating network responsible for its own verification, risk controls and final decisions even when trust signals become more interoperable. |
That last boundary matters: recognized trust signals can reduce duplicate verification without making one network’s certification an unconditional authorization decision for another network.
The three existing mechanisms are not one protocol
Section titled “The three existing mechanisms are not one protocol”The collaboration names three already-existing technologies as the parties’ respective starting points:
| Mechanism | Current role |
|---|---|
| Visa Trusted Agent Protocol | Visa’s framework for identifying trusted commerce agents and conveying agent intent, consumer-recognition and payment information using agent-specific cryptographic signatures. Visa describes the initial specifications as applying to its network while pursuing broader interoperability. |
| Mastercard Verifiable Intent | An open, standards-based and protocol-agnostic trust layer co-developed with Google that cryptographically links identity, user intent and the resulting action. Mastercard says it is aligned with AP2 and UCP and designed to work across agentic protocols and payment networks. |
| Ant International Agentic Mobile Protocol (AMP) | An open-source agentic-payment framework for mobile interfaces. Ant’s AMP already includes its own KYA framework for agent digital identity and authorized-capability certification plus a proprietary Agent Trust Rating for dynamic risk and autonomy control. |
The 10 September collaboration does not establish that these three mechanisms already share one wire format or that one has replaced the others. It says the organizations will work toward common principles and interoperability across their KYA approaches.
KYA vs UHP
Section titled “KYA vs UHP”| Dimension | Know Your Agent interoperability | Unified Harness Protocol |
|---|---|---|
| Primary concern | Agent/operator identity, trust signals, certification and transaction-risk visibility in commerce | Portable execution against a selected complete agent harness |
| Typical boundary | Agent/platform/marketplace ↔ payment or wallet ecosystem ↔ merchant/network trust controls | Client/product ↔ UHP server ↔ harness backend |
| Core objects | Not yet published as one normative common schema | Discovery, harness/model catalogues, Responses/Tasks, Sessions, files, artifacts and events |
| Lifecycle focus | Onboarding, trust recognition, monitoring and recertification | Task creation, streaming, continuation, cancellation, session and artifact lifecycle |
| Current maturity | Cross-network collaboration/common-principles framework announced 10 Sep 2026 | Published date-versioned Draft specification 2026-08-11 plus conformance suite |
| Binding between them | None established | None established |
A UHP-served harness could in principle participate in an agentic-commerce workflow whose payment boundary uses KYA trust signals. That would be architectural composition, not a UHP extension and not evidence that KYA participants natively implement UHP.
Relation to AIP, SAIP and AEP
Section titled “Relation to AIP, SAIP and AEP”KYA should not be treated as another name for the identity and enrollment proposals already tracked by this guide:
- Agent Identity Protocol (AIP) is an ambiguous acronym used by several distinct proposals for agent identity, delegation or authorization.
- Secure AI Identity Protocol (SAIP) is an individual IETF Internet-Draft focused on signed agent identity/provenance assertions.
- Agent Enrollment Protocol (AEP) is an individual IETF Internet-Draft for service enrollment and credential bootstrap.
Those mechanisms could eventually supply inputs to a commerce trust decision, but the reviewed KYA announcement defines no standardized binding to AIP, SAIP or AEP.
Security boundary
Section titled “Security boundary”A recognized or certified agent is not automatically authorized to perform every requested action. Identity and trust evidence answer different questions from action policy, spending authority, tool permissions and sandbox restrictions. The KYA announcement itself preserves each network’s verification and decisioning, while Mastercard Verifiable Intent separately focuses on proving user authorization and intent.
For UHP deployments, KYA therefore does not replace server authentication, per-principal object scoping, harness/tool policy, credential isolation, cancellation or other controls described in Security.
What not to infer
Section titled “What not to infer”- There is no reviewed common KYA wire specification, version or conformance suite published by the three organizations yet.
- The collaboration does not prove that Visa Trusted Agent Protocol, Mastercard Verifiable Intent and Ant AMP already interoperate without adapters or policy translation.
- KYA does not change UHP
2026-08-11or the UHP conformance suite. - No reviewed source establishes a UHP↔KYA binding, HarnessRouter KYA integration or native UHP adoption by Ant International, Mastercard or Visa.
- KYA trust or certification should not be interpreted as unconditional transaction or tool authorization.
Related pages
Section titled “Related pages”- UHP vs Agent Identity Protocol (AIP)
- UHP vs Secure AI Identity Protocol (SAIP)
- Agent Enrollment Protocol (AEP)
- UHP security
- UHP ecosystem