Konubinix' opinionated web of thoughts

Know Your Agent

Fleeting

tl;dr
the sources that say KYA shape it differently; South and co-authors and the KYAPay profile both name the instance as what is identified, and that profile says agents can be « transient and ephemeral » and their claims' assurance varies dramatically.
authorship
this note is edited using Claude/default, governed by the note how to write a literature note

What this note asks

what
the subject is what « Know Your Agent » means, what problem its users say it solves, and whether an agent is the kind of thing that can be known.
scope
the subject assumes the name is in use, and the sources cited below show that it is.
scope
the note reports what the sources define and claim, and does not rank the frameworks they denote.

What KYA means

what
Sumsub gives KYA as an agent’s identity, its binding to a responsible entity, and policy enforced over every autonomous action1.
what
Experian gives it as « a framework for establishing trust in AI-driven interactions »2.
what
Grogan gives KYA not as a framework but as a class of challenge, the one an enterprise meets when it must verify a third-party agent’s capabilities3.
  • what: what he offers against it is AgentFacts, « a universal metadata standard that enables systematic agent verification through cryptographically-signed capability declarations, multi-authority validation, and dynamic permission management »4.
what
the KYAPay profile at the IETF makes KYA a token, giving the claims common to « the KYA (Know Your Agent), PAY (Payment), and KYA-PAY (combined Know Your Agent and Payment) Tokens »5.
scope
Sumsub calls it an approach, Experian a framework, Grogan a challenge and the KYAPay profile a token, and the note reports the four without reconciling them.
scope
Sumsub and Experian both sell identity verification and Grogan proposes a standard against the challenge he names, so each backs the wording it uses and not what the field settles on.
scope
the KYAPay profile is an Internet-Draft of Informational intended status, not an approved standard, and its first author gives their affiliation as Skyfire5.

The problem KYA is said to solve

what
Experian puts it as a reading problem — of an agent that initiates a transaction, « Is it a trusted assistant acting on behalf of a real customer, or a sophisticated bot attempting fraud? »6.
what
Grogan puts it as a verification problem — trust must be established « without standardized metadata or verification infrastructure »3.
what
Ant International puts it as an onboarding problem, agents being identified across networks that each keep their own decisioning7.
scope
Sumsub, Experian and Ant International sell into the remedy and Grogan proposes one, so each backs that the problem is claimed and not how large it is.

Whether an agent can be known

what
Ken Huang writes for the Cloud Security Alliance that « the transient nature of AI agents » leaves identity mechanisms built on persistent credentials inadequate8.
  • what: what he puts in its place is a token « linked to specific tasks » and carrying metadata about « the requesting system, purpose, and allowed operations »9.
what
Zhao and Zhao hold that the model and harness producing an agent’s behaviour « underspecifies a long-lived agent »10.
  • scope: they stipulate when a substrate change counts as « migration, not agent creation »11.
  • scope: they bound their own evidence, which « supports architectural substitutability, failure handling, and individual-axis feasibility, but not equal task performance, behavioral fidelity »12.
what
Menon writes that agents lose « continuity of self » when context windows overflow and conversation histories are summarized13.
scope
Menon and Zhao and Zhao address different variables, his a context window, theirs a change of model, harness or host.
what
South and co-authors put an agent on a task « spanning days or weeks », for which « IAM models based on short-lived, user-session-bound access tokens are fundamentally incompatible »14.
  • what: what they ask for instead is « a durable, delegated identity that is a first-class citizen in the IAM system, distinct from the initiating user »15.
  • what: the thing they would identify is the instance — « Each agent instance can be assigned a globally unique and verifiable identifier for accountability »16.
what
the KYAPay profile holds that agents « vary in terms of longevity »17.
  • what: they « can have stable long-running identities (such as those of a server-side confidential client), or they can be transient and ephemeral, and correspond to individual API calls or compute workloads »17.
  • what: and separately that « Because an agent can be public or confidential (as described in Section 2.1 of [RFC6749]), the level of assurance for these claims varies dramatically »18.
scope
of the five sources in this section, South and co-authors are the one to reach knowing, holding that « identifying agents will involve knowing the specific instance that took an action and the properties of that system »19.

What the protocols attach to an agent

what
Visa publishes the Trusted Agent Protocol as « a standardized, cryptographic method for an AI agent to prove its identity and associated authorization directly to merchants »20.
what
Visa says that from that signature a merchant « can verify that an agent is legitimate and has the user’s permission to act »21.
what
in AP2 the open mandates an autonomous Shopping Agent creates « MUST include the agent’s public key as a `cnf` claim »22.
  • what: AP2 also lets that agent sign for itself, the Shopping Agent « MAY now sign it using its Agent Key instead of getting approval on a Trusted Surface »23.
what
the KYAPay profile’s introduction says its framework « allows the web security ecosystem to distinguish among individual agent instances, the platforms they run on, and the human principals behind them »24.
  • what: its section 3.2.3 requires of the agent identity claim « REQUIRED - Agent name » and « REQUIRED - The public IP address of the system / agent that requested the token »25.
  • what: section 3.2 lists « hid : REQUIRED (Required for human identity use cases) - A map of human identity claims (individual or organization) »26.
  • what: sections 3.2.1 and 3.2.2 each define a « verifier », a « verified » and a « verification_id », and section 3.2.3 defines none of the three27.
  • scope: section 3.2 lists « aid : REQUIRED - Agent identity claims » and section 3.2.3 opens « The aid claim is optional »28.
scope
the Visa and the Google text say neither « KYA » nor « Know Your Agent »29.
  • scope: that is a fact about those two texts, and not about what Visa and Google hold — Visa is in the KYA collaboration Ant International announced7.
scope
Visa and Google each sell into agentic commerce, and the KYAPay profile is an Internet-Draft of Informational intended status, not an approved standard, its first author giving their affiliation as Skyfire5.
therefore
South and co-authors and the KYAPay profile both name the instance as what is identified19, 24.
  • scope: neither the Visa text nor the Google text uses the word « instance » of an agent30.

How KYAPay and the Trusted Agent Protocol say a check runs

the KYAPay profile

what
the party it puts between the others is an Identity Token Issuer, which its section 2.1.3 defines31.
what
the checks it requires of a kya token’s header and payload are in its section 4.1, every one a MUST32.
scope
those MUSTs are an Internet-Draft’s, of Informational intended status and not an approved standard5.

the Trusted Agent Protocol

what
the README heads the two mechanisms drawn below « Cryptographically Verify Agent Intent »33 and « Confirm Transaction-Specific Authorization »34, addressing merchants throughout.
scope
it is Visa’s own README and not a specification — read whole, its 98 lines carry no « MUST »35.

Who says KYA

Know Your Agent, KYA

what
« Know Your Agent », abbreviated KYA, names for an AI agent what KYC names for a customer36.
who
a McGill law academic37, the author of a paper proposing a KYA metadata standard38, a verification vendor1 and an officer of Ant International39 each use it.
scope
an officer of Mastercard uses it too, in words that reach this note through Ant International40.
what
Ant International announced on [2026-09-10 Thu] that it, Mastercard and Visa had begun collaboration on a « Know-Your-Agent (KYA) interoperability framework »7.
therefore
the name reaches past any one vendor.
scope
the vendors cited sell into the field, so each backs the name it uses and not what the field settles on.

The earliest dated uses found

what
Crossref registers « Know Your Agent: Governing AI Identity on the Agentic Web » under Tomer Jordi Chaffer, its record created [2025-03-03 Mon]37.
what
Jared James Grogan posted « AgentFacts: Universal KYA Standard for Verified AI Agent Metadata & Deployment » on [2025-06-11 Wed]38.

The report prepared for the OpenID Foundation says KYA once

what
its one use of the name is in reporting the KYAPay protocol41.
what
that report also lists « agent-centric identities » among the open questions it sets out42.
scope
it predates Ant International’s announcement by more than ten months7, 42.

Names alongside KYA

what
« Digital Agent Passport » names the credential one report puts at the centre of KYA43.
what
« Know Your Human » names, in PYMNTS’ reporting, the check that a person authorised what an agent does44.

Notes linking here


  1. Primary for the name Sumsub uses, and interested on what the field uses. « Know Your Agent (KYA) is a risk-based approach to establishing and maintaining trust in AI agents by defining their identity, binding them to responsible entities (human or organizational), and enforcing policy, oversight, and auditability across all autonomous actions. » — Alisa Abramova, Artem Popov and Arthur Tsvettsih, Sumsub ([2026-01-28 Wed]). ↩︎ ↩︎

  2. Primary for the wording Experian uses, and interested, Experian selling identity verification. « Know Your Agent is a framework for establishing trust in AI-driven interactions. » — Laura Burrows, Experian ([2026-06-03 Wed]). ↩︎

  3. Primary, the author’s own paper, and interested, its author proposing at 4 the standard this challenge calls for. « Enterprise AI deployment faces critical “Know Your Agent” (KYA) challenges where organizations must verify third-party agent capabilities and establish trust without standardized metadata or verification infrastructure. » — Jared James Grogan, arXiv:2506.13794 ([2025-06-11 Wed]). ↩︎ ↩︎ ↩︎

  4. Primary, the author’s own paper, the same as 3, and interested, its author proposing the standard. « This paper presents AgentFacts, a universal metadata standard that enables systematic agent verification through cryptographically-signed capability declarations, multi-authority validation, and dynamic permission management. » — Jared James Grogan, arXiv:2506.13794 ([2025-06-11 Wed]). ↩︎ ↩︎

  5. Primary, the profile’s own text, and interested, its first author giving their affiliation as Skyfire. « The following are claims in common, used within the KYA (Know Your Agent), PAY (Payment), and KYA-PAY (combined Know Your Agent and Payment) Tokens. » — A. Agarwal, Skyfire, and M. Jones, Self-Issued Consulting, « KYAPay Profile », draft-skyfire-kyapayprofile-01, published [2026-03-31 Tue], an Internet-Draft of Informational intended status and not an approved standard. ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  6. Primary for the wording Experian uses, and interested, Experian selling the remedy. « When an AI agent initiates a transaction, those signals become harder to interpret. Is it a trusted assistant acting on behalf of a real customer, or a sophisticated bot attempting fraud? KYA is emerging to solve exactly this problem. » — Laura Burrows, Experian ([2026-06-03 Wed]). ↩︎

  7. Primary for what Ant International announces, and secondary for what it reports of Mastercard and Visa. « Ant International, Mastercard, and Visa have begun collaboration on a Know-Your-Agent (KYA) interoperability framework, designed to help card networks, digital wallet ecosystems, agent platforms and marketplaces streamline agent onboarding and identification across networks, based on shared principles while preserving each network’s own verification and decisioning processes. » — Ant International, Shanghai/Singapore ([2026-09-10 Thu]). ↩︎ ↩︎ ↩︎ ↩︎

  8. Primary for what its author holds, and interested, the author heading a vendor in this field. « Given the transient nature of AI agents, traditional identity mechanisms based on persistent credentials are inadequate. » — Ken Huang, CEO of DistributedApps.ai, Cloud Security Alliance ([2025-03-11 Tue]). ↩︎ ↩︎

  9. Primary, same author and post as 8. « Each authentication token is linked to specific tasks and contains metadata about the requesting system, purpose, and allowed operations. » — Ken Huang, Cloud Security Alliance ([2025-03-11 Tue]). ↩︎

  10. Primary, the authors’ own paper. « That boundary is useful for one execution but underspecifies a long-lived agent that may change models, orchestration harnesses, interaction sessions, and host servers while retaining one identity, memory, and executable code lineage. » — Zhenyu Zhao and Roy Zhao, arXiv:2609.00546 ([2026-09-01 Tue]). ↩︎ ↩︎ ↩︎

  11. Primary, same paper as 10, and a condition its authors stipulate rather than a finding they report. « changing either replaceable layer is migration, not agent creation, when an authorized protocol preserves attributable lineage and transfers continuation authority within a governed deployment boundary. » — Zhenyu Zhao and Roy Zhao, arXiv:2609.00546 ([2026-09-01 Tue]). ↩︎

  12. Primary, the same paper as 10, its pdf downloaded and searched rather than read through a fetch. « Together, the evidence supports architectural substitutability, failure handling, and individual-axis feasibility, but not equal task performance, behavioral fidelity, latency, cost, or controlled combined migration. » — Zhenyu Zhao and Roy Zhao, arXiv:2609.00546 ([2026-09-01 Tue]). ↩︎

  13. Primary, the author’s own paper. « Modern AI agents suffer from a fundamental identity problem: when context windows overflow and conversation histories are summarized, agents experience catastrophic forgetting – losing not just information, but continuity of self. » — Prahlad G. Menon, arXiv:2604.09588 ([2026-03-02 Mon]). ↩︎

  14. Primary, the same report as 42, its pdf downloaded and searched rather than read through a fetch. « An enterprise process agent, for example, might be assigned to onboard a new employee–a workflow spanning days or weeks. » and « IAM models based on short-lived, user-session-bound access tokens are fundamentally incompatible with this pattern. » — Tobin South and twenty co-authors, arXiv:2510.25819 ([2025-10-29 Wed]). ↩︎ ↩︎ ↩︎ ↩︎

  15. Primary, the same report as 14. « The agent requires a durable, delegated identity that is a first-class citizen in the IAM system, distinct from the initiating user, allowing it to authenticate independently over extended periods. » — Tobin South and twenty co-authors, arXiv:2510.25819 ([2025-10-29 Wed]). ↩︎

  16. Primary, the same report as 14. « Each agent instance can be assigned a globally unique and verifiable identifier for accountability, using schemes like DIDs or others currently being standardized. » — Tobin South and twenty co-authors, arXiv:2510.25819 ([2025-10-29 Wed]). ↩︎

  17. Primary, the same draft as 5. Section 2.1, under « Agent Identity »: « Agents also vary in terms of longevity – they can have stable long-running identities (such as those of a server-side confidential client), or they can be transient and ephemeral, and correspond to individual API calls or compute workloads. » — A. Agarwal and M. Jones, draft-skyfire-kyapayprofile-01 ([2026-03-31 Tue]). ↩︎ ↩︎ ↩︎

  18. Primary, the same draft as 5, the sentence preceding the one at 17, with the two before it so that « these claims » resolves. « Agent Identity: A unique identifier and a set of claims describing an agent. Grouped into the aid claim for convenience. Because an agent can be public or confidential (as described in Section 2.1 of [RFC6749]), the level of assurance for these claims varies dramatically. » — A. Agarwal and M. Jones, draft-skyfire-kyapayprofile-01 ([2026-03-31 Tue]). ↩︎

  19. Primary, the same report as 14. « More generally, identifying agents [4] will involve knowing the specific instance that took an action and the properties of that system. » — Tobin South and twenty co-authors, arXiv:2510.25819 ([2025-10-29 Wed]). ↩︎ ↩︎

  20. Primary, Visa’s own repository, and interested, Visa selling into agentic commerce. « Visa’s Trusted Agent Protocol provides a standardized, cryptographic method for an AI agent to prove its identity and associated authorization directly to merchants. » — Visa, trusted-agent-protocol. The README carries no version or date; read [2026-09-16 Wed]↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  21. Primary, the same README as 20, and interested. « By presenting a secure digital signature with every interaction, a merchant can verify that an agent is legitimate and has the user’s permission to act. » — Visa, trusted-agent-protocol, read [2026-09-16 Wed]↩︎

  22. Primary, the protocol’s own specification, and interested, Google selling into agentic commerce. « When a Shopping Agent needs to operate autonomously, it will create open Checkout and Payment Mandate Content and have these authorized by the Trusted Surface. These MUST include the agent’s public key as a `cnf` claim. » — Google, Agentic Payment Protocol (v0.2). The page carries no publication or revision date; read [2026-09-16 Wed]↩︎ ↩︎ ↩︎ ↩︎

  23. Primary, the same specification as 22, and interested. « the Shopping Agent MAY now sign it using its Agent Key instead of getting approval on a Trusted Surface. » — Google, Agentic Payment Protocol (v0.2), read [2026-09-16 Wed]↩︎

  24. Primary, the same draft as 5, and interested. « KYA tokens provide a layered, verified, and extensible identity stack specifically engineered for autonomous agents. This framework allows the web security ecosystem to distinguish among individual agent instances, the platforms they run on, and the human principals behind them. » — A. Agarwal and M. Jones, draft-skyfire-kyapayprofile-01 ([2026-03-31 Tue]). ↩︎ ↩︎ ↩︎

  25. Primary, the same draft as 5, and interested. Section 3.2.3, « Agent Identity aid Sub-Claims », opens « The aid claim is optional. If present, it contains the following sub-claims. » and gives « name : REQUIRED - Agent name. The name should reflect the business purpose of the agent. » and « creation_ip : REQUIRED - The public IP address of the system / agent that requested the token. Its value is a string containing the public IPv4 or IPv6 address from where the token request originated. It MUST be captured directly from the token request. » — A. Agarwal and M. Jones, draft-skyfire-kyapayprofile-01 ([2026-03-31 Tue]). ↩︎

  26. Primary, the same draft as 5. Section 3.2: « hid : REQUIRED (Required for human identity use cases) - A map of human identity claims (individual or organization). » — A. Agarwal and M. Jones, draft-skyfire-kyapayprofile-01 ([2026-03-31 Tue]). ↩︎

  27. Primary, the same draft as 5. Sections 3.2.1, « hid - Human Identity Sub-Claims », and 3.2.2, « Agent Platform Identity apd Sub-Claims », each define « verifier : OPTIONAL - URL of the Identity Verifier », « verified : OPTIONAL - Boolean Verification status. True if verified, otherwise false. » and « verification_id : OPTIONAL - Verification identifier. » Section 3.2.3, « Agent Identity aid Sub-Claims », defines three sub-claims — name, creation_ip and source_ips — and none of those. All three sections read in full. — A. Agarwal and M. Jones, draft-skyfire-kyapayprofile-01 ([2026-03-31 Tue]). ↩︎

  28. Primary, the same draft as 5. Section 3.2 lists « aid : REQUIRED - Agent identity claims. »; section 3.2.3 opens « The aid claim is optional. » — A. Agarwal and M. Jones, draft-skyfire-kyapayprofile-01 ([2026-03-31 Tue]). ↩︎

  29. Primary, the two texts themselves, the same as 20 and 22. A search of the Trusted Agent Protocol README and of the AP2 specification (v0.2) for « KYA » and « Know Your Agent » returns no occurrence in either; both read [2026-09-16 Wed]↩︎

  30. Primary, the two texts themselves, the same as 20 and 22. A search of the Trusted Agent Protocol README returns no occurrence of « instance »; the AP2 specification (v0.2) has one, « verifying that the Payment Credential shared by the Credential Provider has been authorized to pay for this Checkout instance », which is a checkout and not an agent; both read [2026-09-16 Wed]↩︎

  31. Primary, the same draft as 5. Section 2.1.3: « Identity Token Issuer: A trusted neutral entity that conducts Know Your Customer (KYC) and Know Your Business (KYB) (for organizations) verifications. It is responsible for issuing cryptographically signed kya tokens that attest to the identity of the Principal, Agent, and Agent Platform, for both Buyers and Sellers. » — A. Agarwal and M. Jones, draft-skyfire-kyapayprofile-01 ([2026-03-31 Tue]). ↩︎

  32. Primary, the same draft as 5. Section 4.1.1 requires of the header « alg - JWTs MUST be signed using allowed JWA algorithms (currently, ES256 ). », « kid - The kid claim MUST be present, and set to a valid Key ID discoverable via the issuer’s (payload iss claim) JWK Set. » and « typ - The typ header parameter value MUST be one of: kya+jwt , pay+jwt , or kya-pay+jwt . » Section 4.1.2 requires of the payload « Verify JWT Signature - Valid JWTs MUST be signed with a valid key belonging To the token’s issuer ( iss claim) », « Validate iss Claim - Ensure that the token is signed by the expected valid issuer. », « Validate the exp Claim - The verifier MUST validate that the token has not expired, within the verifier’s clock drift tolerance. », « Validate the iat Claim - The verifier MUST validate that the token was issued in the past, within the verifier’s clock drift tolerance. », « Validate the jti Claim - Ensure that the jti claim is present, and is a UUID. », « Validate the aud Claim - Ensure that the aud identifies the recipient as the intended audience. » and « Validate the env Claim - Ensure that the Environment claim is set to an expected and use case appropriate value (such as production or sandbox ) ». Both sections read in full. — A. Agarwal and M. Jones, draft-skyfire-kyapayprofile-01 ([2026-03-31 Tue]). ↩︎

  33. Primary, the same README as 20, and interested, read whole on disk rather than through a fetch. « Cryptographically Verify Agent Intent: Instantly distinguish a legitimate, credentialed agent from an anonymous bot. The agent presents a secure signature that includes timestamps, a unique session identifier, key identifier, and algorithm identifier, allowing you to verify that the signature is current and prevent relays or replays. » — Visa, trusted-agent-protocol, read [2026-09-16 Wed]↩︎

  34. Primary, the same README as 20, and interested. « Confirm Transaction-Specific Authorization: Ensure the agent is authorized for the specific action it is taking (browsing or payment) as the signature is bound to your domain and the specific operation being performed. » The « your » is the merchant’s, the README addressing merchants throughout. — Visa, trusted-agent-protocol, read [2026-09-16 Wed]↩︎

  35. Primary, the same README as 20. Its 98 lines were read whole on disk and contain no occurrence of « MUST »; the document presents itself as « The Challenge », « The Solution », « Key Benefits » and a quick start for a sample implementation, not as a specification. — Visa, trusted-agent-protocol, read [2026-09-16 Wed].

     ↩︎
  36. Primary for the name Sumsub uses, and interested on what the field uses. « Like Know Your Customer (KYC), Know Your Agent frameworks establish trust and accountability for autonomous systems. » — Alisa Abramova, Artem Popov and Arthur Tsvettsih, Sumsub ([2026-01-28 Wed]). ↩︎

  37. Primary for the registration, which is all it backs: the paper itself could not be read, SSRN and PhilArchive both refusing the request. « Know Your Agent: Governing AI Identity on the Agentic Web » — Tomer Jordi Chaffer, McGill University Faculty of Law, Crossref record for DOI 10.2139/ssrn.5162127, created [2025-03-03 Mon]↩︎ ↩︎

  38. Primary, the author’s own paper. « AgentFacts: Universal KYA Standard for Verified AI Agent Metadata & Deployment » and « Enterprise AI deployment faces critical “Know Your Agent” (KYA) challenges » — Jared James Grogan, arXiv:2506.13794 ([2025-06-11 Wed]). ↩︎ ↩︎

  39. Primary, Ant International speaking in its own voice. « Interoperable KYA between card and wallet networks is critical for securing trust for our payment partners, platforms and merchants in agentic commerce, » — Jiang-Ming Yang, Chief Innovation Officer of Ant International, in the same release ([2026-09-10 Thu]). ↩︎

  40. Secondary, cited because Mastercard’s own newsroom carries no posting of this release that could be found, and its wire copy refuses the request. « Interoperability across Know-Your-Agent frameworks is essential to making agentic commerce work at scale, giving merchants, platforms, wallets and issuers a consistent way to recognise trusted agents » — Pablo Fourez, Chief Digital Officer, Mastercard, quoted in the release of Ant International ([2026-09-10 Thu]). ↩︎

  41. Primary for what that report says, which is all it is cited for here; KYAPay’s own text is cited at 5 and 24. « The protocol defines a “Know Your Agent” (KYA) process, extending traditional KYC/KYB identity verification to the agent itself. » — Tobin South and twenty co-authors, arXiv:2510.25819 ([2025-10-29 Wed]), its pdf downloaded and searched rather than read through a fetch. ↩︎ ↩︎

  42. Primary, the report’s own text, and not the foundation’s position: its Contributors section says « This report was prepared for the OpenID Foundation by Tobin South starting in April 2025 ». « ambitions for highly autonomous agents raise complex long-term questions regarding scalable access control, agent-centric identities, AI workload differentiation, and delegated authority » — Tobin South and twenty co-authors, « Identity Management for Agentic AI », arXiv:2510.25819 ([2025-10-29 Wed]). Its pdf was downloaded and searched: « Know Your Agent » occurs once and « KYA » once outside the protocol name « KYAPay », which occurs twice, all in the passage quoted at 41; and « passport » occurs once, of the IETF’s Web Bot Auth proposal — « This method acts as a “passport for agents,” using HTTP Message Signatures to attach a verifiable identity to traffic, regardless of its IP address. » ↩︎ ↩︎ ↩︎

  43. Secondary, cited because Trulioo’s own account of this credential sits in a white paper released only against a form demanding a name, a work address, a job title, a company and a country. « At the center of KYA is a Digital Agent Passport, a tamper-proof credential that holds details on each AI agent, including provenance, user binding, permission scope, real-time behavior telemetry and continuous risk scoring. » — Masha Borak, Biometric Update ([2025-08-21 Thu]). ↩︎

  44. Primary for the name PYMNTS uses. « ‘Know your human’ brings those layers together by ensuring that a real person authorized the instruction and that the agent executing it remains within that delegation. » — PYMNTS, PYMNTS ([2026-02-27 Fri]). ↩︎