Know Your Agent (KYA) verifies an AI agent’s identity, scopes what it may do, and ties every autonomous action back to a named human who can be held accountable when something goes wrong.
Sixty-eight percent of organisations cannot clearly separate an action taken by a person from an action taken by an AI agent, according to a Cloud Security Alliance survey of 228 IT and security professionals published in March 2026. That gap matters because agents are already opening accounts, moving money and pulling records inside production systems, so most organisations running them cannot say which human authorised any given action. Know Your Agent is the framework built to close that gap. The mistake most teams make is treating it as a credentialing exercise, when what they really should be focusing on is attribution.
What is Know Your Agent (KYA)?
Know Your Agent (KYA) is a risk-based framework for verifying an AI agent’s identity, defining what that agent is permitted to do, and tracing every action it takes back to a named human or organisation that carries responsibility for it. An AI agent, in this context, is a software system that plans and acts toward a goal with limited human supervision, rather than a chatbot that only answers a user’s questions.
How KYA extends KYC and KYB
KYA borrows its logic from two controls compliance teams already run. Know Your Customer (KYC) answers who this person is, and Know Your Business (KYB) answers who owns and controls this company. Know Your Agent verification asks a third question, which is who authorised this software to act and what were they allowed to authorise?
What actually counts as an agent identity
An agent identity is a distinct credential that belongs to the agent itself. That distinction sounds academic until you look at what organisations do in practice. In the same Cloud Security Alliance survey, 52% run agents on workload identities, 43% rely on shared service accounts, and 31% let agents operate under a human user’s identity. In that last group, the agent’s actions are indistinguishable from the person’s in every log the organisation keeps, which is a problem. How that credential gets authenticated day to day is covered in our breakdown of the agent verification process in practice.
Why AI agent verification became urgent in 2026
Agent deployment moved faster than the controls around it. Gartner predicted in August 2025 that 40% of enterprise applications would embed task-specific AI agents by the end of 2026, up from under 5% when the forecast was published. Growth on that scale leaves no realistic window to design governance first, so most organisations are retrofitting it now.
The visibility picture is worse than the adoption numbers suggest. A second Cloud Security Alliance survey, published in April 2026 across 418 respondents, found that 82% had discovered AI agents running in their infrastructure that they did not know about, and 65% had an agent-related incident in the previous twelve months. Those incidents produced data exposure for 61%, operational disruption for 43%, and direct financial loss for 35%, which is why agent governance stopped being a theoretical exercise. This shift is already visible in specific compliance workflows, including how agentic AI is changing AML compliance
How does Know Your Agent work?
KYA verification runs as four checks that build on each other, and an agent programme is only as strong as the weakest one.
| Layer | What it proves | What breaks without it |
| Registration | The agent exists as a known entity with an owner and a purpose | Shadow agents run unrecorded and outlive their purpose |
| Authentication | The agent presenting the credential is the registered one | Stolen or replayed credentials grant machine access to sensitive APIs |
| Authorisation | The action falls inside the agent’s approved scope, value and time window | Over-privileged agents cause systemic damage the moment they are compromised |
| Attribution | A named, verified human sanctioned this specific action | No audit trail, no responsible party, and no way to revoke |
How does KYA differ from KYC?
KYC verifies a person once at onboarding and re-checks them at risk triggers, whereas KYA verifies a non-human actor continuously because agents never stop working. The table below sets out where the two controls diverge in practice.
| Comparison | KYC | KYA |
| Subject | A natural person | A software agent acting for a person or company |
| Core question | Who is this customer | Who authorised this software, and to do what |
| Trigger | Onboarding, plus periodic and event-driven review | Registration, then every action the agent takes |
| Evidence | Documents, biometrics, authoritative database checks | Credentials, scope policy, signed action logs |
| Cadence | Point in time, refreshed on a schedule | Continuous, at machine speed |
| Revocation | Close or restrict the account | Revoke the credential and the sponsoring human’s authority |
| Failure mode | An impostor passes onboarding | An authorised agent acts far outside what its sponsor intended |
The agent accountability ladder
The five rungs below will help you assess your agent verification flow:
- Unmanaged: The agent runs on a person’s own login. Thirty-one percent of organisations allow this for at least some agents, so those actions cannot be separated from human ones after the fact.
- Credentialed: The agent holds its own identity, registered against an owner and a purpose. The 82% who found unknown agents, and the 21% who have a formal decommissioning process, show how thin this rung still is.
- Scoped: Permissions are bounded by action type, value and time. Nearly three quarters of respondents, 74%, said agents often receive more access than they need.
- Attributed: Every action resolves to a named human sponsor in the log. This is the rung the 68% attribution gap describes, and the one auditors will ask about first.
- Re-attested: Before a high-risk action, the sponsoring human is re-verified in real time rather than assumed present. Only 11% of organisations automatically block an agent action that exceeds its scope, so almost nobody is here yet.

Is KYA a regulatory requirement in 2026?
No jurisdiction has enacted a standalone Know Your Agent mandate, and any vendor telling you otherwise is selling ahead of the law. What exists instead is a set of frameworks converging on the same requirement, which is that a human stays accountable for what an agent does.
Singapore moved early. The Infocomm Media Development Authority launched its Model AI Governance Framework for Agentic AI at the World Economic Forum in January 2026. The framework is guidance rather than binding law.
In the United States, the National Institute of Standards and Technology has a concept paper out for review on software and AI agent identity and authorization through its National Cybersecurity Center of Excellence. The paper treats agents as identifiable non-human entities with their own credential lifecycles and auditable, non-repudiable action trails, which is the same architecture KYA describes.
In the European Union, the AI Act’s Article 50 transparency rules require that people are informed when they are interacting with an AI system rather than a person.
The practical read for a compliance lead is that KYA is not an obligation yet.
Frequently Asked Questions
What does Know Your Agent (KYA) mean?
Know Your Agent means verifying an AI agent's identity, bounding what it is permitted to do, and linking every action it takes to a named human or organisation that answers for it. KYA applies KYC logic to software that acts on its own.
Who is accountable when an AI agent causes a loss?
The organisation that deployed the agent, and the individual who authorised its actions, remain accountable. No current framework transfers liability to the agent or its vendor, which is why regulators will ask for attribution back to a named human.
















