Visa, Mastercard and Ant Just Agreed on How to ID an AI Shopping Agent
On September 9, 2026, Ant International, Visa, and Mastercard put out a press release announcing a "Know-Your-Agent" (KYA) interoperability framework, an agreement to make three competing AI-agent-identity protocols recognize each other's trust signals instead of forcing everyone to implement all three. The announcement leans on a stat that's easy to skim past: AI agents are projected to orchestrate $3 to $5 trillion in global consumer commerce by 2030. I run a small SaaS with a checkout page, and my first reaction wasn't excitement about interoperability. It was: how long until my payment processor asks me to prove I can tell a real AI shopping agent from a scraper pretending to be one.
What KYA actually bridges
Three payment giants each shipped their own way to say "this AI agent is legitimate." Visa built the Trusted Agent Protocol (TAP), which launched in October 2025 and already has integration partners including Adyen, Shopify, and Stripe. Mastercard built Verifiable Intent, an open-source protocol introduced in March 2026 and co-developed with Google. Ant International built the Agentic Mobile Protocol (AMP), tied into its digital wallet ecosystem, which went live in April 2026. Each protocol answers the same question (is this agent authorized to act, and is it acting on behalf of a real person) in its own incompatible way.
KYA doesn't replace any of the three. It's a set of shared principles that lets card networks, digital wallet ecosystems, agent platforms, and marketplaces recognize each other's certification instead of running separate checks. Per Ant International's chief innovation officer, Jiang-Ming Yang, the goal is for an agent that registers with one network to not need to re-register with the other two. The three companies say they'll share standard certification requirements and run continuous monitoring using identity and transaction signals to keep that certification current, built on a model called Safeguards for Agentic Finance at Runtime (SAFR), which runs through a platform convened by the Monetary Authority of Singapore.
The pitch: verify once, get trusted everywhere
The stated problem is real. If a merchant has to separately validate an agent against Visa's rules, Mastercard's rules, and Ant's rules before deciding whether to fulfill an order, that's three integrations, three sets of documentation, and three places where an agent can get flagged inconsistently. Mastercard's chief digital officer, Pablo Fourez, framed the goal as giving "merchants, platforms, wallets and issuers a consistent way to recognise trusted agents, verify that actions reflect the user's intent, and preserve accountability across the transaction." Visa's Rubail Birwadker made a similar case: without a shared trust signal, agents can't participate in commerce at scale because nobody upstream can vouch for them consistently.
That's a legitimate coordination problem, and reducing it to one shared vocabulary instead of three is a genuine improvement over the status quo, on paper.
One framework instead of three is not the same as simple
Here's where I'd push back on how this gets covered. "Three protocols became one framework" sounds like consolidation, but for a solo operator running a Shopify storefront, a subscription SaaS, or any checkout page, KYA isn't a single API you call once. It's a promise that three different backend systems will eventually agree on how to hand you a trust signal, which you'll still need to receive, interpret, and act on inside your own checkout flow. You still have to decide what happens when an order comes in from an agent with no trust signal at all, from an agent whose certification looks stale, or from a request that never announces itself as an agent in the first place and just looks like unusually fast, unusually specific browsing.
None of that logic exists yet. The framework, as announced, has no published technical specification, no governance body, and no disclosed rollout timeline. It's three companies agreeing on principles, not a standard you can integrate against this quarter.
Why the card networks are moving first
This isn't charity. Fraud liability sits with card networks and issuers, not with you, at least not yet. When a chargeback dispute lands, it's Visa's and Mastercard's rulebooks that decide who eats the loss, and an unverified AI agent placing orders (or a scraper impersonating one to test stolen cards) is exactly the kind of ambiguous transaction that turns into a liability fight. That's why the three companies are moving now instead of waiting for volume to force their hand: the fraud exposure from unverified agentic traffic accrues to them well before it accrues to a solo merchant's P&L.
For you, this is still a leading indicator, not a fire drill. The first real, concrete signal I'd point to is this: "was this order placed by a verified agent, an unverified bot, or something impersonating an agent" is moving from a hypothetical question to a field that will eventually show up in transaction metadata you're expected to check. That's worth knowing about today even though nothing about your checkout needs to change today.
The honest take
I'd be lying if I said I don't think about this at all. But the correct move right now, for almost everyone reading this, is to watch and understand, not to integrate. Frameworks like this typically take 18 to 24 months to go from a joint press release between three companies to something a small merchant can actually implement, let alone something a payment processor requires. There's no published spec yet. There's no governance body yet. There's no timeline yet. Building against a week-old agreement between three competitors who haven't even finished agreeing with each other is a good way to spend a weekend rebuilding your checkout against something that changes shape twice before it ships.
What I'd actually do: keep an eye on whether your payment processor (Stripe, Shopify Payments, whoever sits between you and the card networks) starts surfacing an agent-trust signal in transaction data, since that's the point where this becomes your problem instead of theirs. Until then, the highest-value thing you can do is understand the shape of the three underlying protocols so you're not starting from zero when your processor eventually asks you to opt in. I could be wrong about the timeline: card networks have moved faster than 18 to 24 months before when fraud losses got expensive enough, and a single bad news cycle about agent-driven fraud could compress this considerably. If that happens, the merchants who understood the framework early will have an easier time than the ones who ignored it entirely.
Author
Lukas
@lukcombinatorSources
- Ant International, Visa, Mastercard work to make agentic protocols interoperable (Biometric Update)
- Ant International, Visa, and Mastercard Agree on Agent Identity Standard. Now Comes the Hard Part. (Forkast)
- Visa and Mastercard Team With Ant on Know Your Agent Framework (PYMNTS)
- Ant International, Mastercard and Visa Initiate Collaboration on Know-Your-Agent Interoperability to Scale Agentic Commerce (Ant International)