Back to News
News AlertWorld Money
Move Over KYC: Why India Is Building 'Know-Your-Agent'
T
Author
Tushar Shrivas
Published
September 13, 2026
Reading Time
6 MIN READ
Spread the Word

NPCI is building an AI-agent registry while Visa, Mastercard, and Ant develop KYA standards. Here's how payment networks plan to verify AI agents.
NPCI Unified Agent Protocol, AI agent registry, agentic payments, Visa Trusted Agent Protocol, Mastercard Verifiable Intent, Ant International Agentic Mobile Protocol, UPI AI agents
Move Over KYC: Why India Is Building a 'Know-Your-Agent' System for AI Payments
Banks spent decades forcing humans through Know-Your-Customer checks before they could open an account or move money. Right now, two separate groups of institutions — one in India, one spanning three global payment networks — are racing to build the equivalent check for software.
In India, the National Payments Corporation of India is developing a Unified Agent Protocol (UAP) — reported by Business Standard as early as July 2026 and confirmed by Reuters sources in September — designed to register, verify, and authorize AI agents before they can execute payments over UPI. The idea is to create a registry that can help answer one question before an agent is allowed to transact: is this software actually trusted to spend on this person's behalf? Business Recorder
Almost exactly two months later — and unconnected to India's effort — Ant International, Mastercard, and Visa announced on September 10, 2026, in São Paulo that they're jointly developing a Know-Your-Agent (KYA) interoperability framework, meant to let their three separate agent-identity systems (Visa's Trusted Agent Protocol, Mastercard's Verifiable Intent, and Ant's Agentic Mobile Protocol) recognize each other's trust signals instead of operating as walled gardens. Business Wire
Why This Is Happening Now, Not Later
The trigger is the same on both fronts: AI agents are moving from making suggestions to actually completing purchases, and the companies building the payment rails say this is projected to be enormous. Ant International, Mastercard, and Visa's own joint announcement cites projections that AI agents could orchestrate $3 trillion to $5 trillion of global consumer commerce by 2030.
That scale creates a problem the old anti-fraud playbook wasn't built for. For two decades, payment gateways tuned their fraud engines to detect and block automated scripts — bots were, by definition, the threat. Agentic commerce inverts that: a legitimate, high-value transaction might now be initiated by a piece of software rather than a human tapping a screen, and blocking all automated activity would just break the product these networks are trying to enable. IT Digest

What KYA Actually Checks
The KYA framework, as described in the companies' own joint announcement, centers on a few specific pillars: cross-network operator traceability (connecting an AI agent back to a validated human, cardholder, or business account, so there's a clear line of accountability for every transaction), shared certification requirements for assessing an agent's security and capabilities before it's trusted, and continuous transaction monitoring rather than a one-time approval. World Business Outlook
Importantly, each network keeps its own verification and decision-making process — Visa still runs its own checks, Mastercard runs its own, Ant runs its own. What KYA adds is a shared vocabulary of trust signals on top, so an agent verified on one network doesn't have to start from zero when it shows up on another. Electronic payments
India's UAP takes a related but distinct approach, built specifically around UPI's existing architecture. Rather than launching a parallel identity system, it extends two tools NPCI already runs: UPI Circle, which lets a person delegate payment authority to someone else (currently capped around ₹15,000 a month), and Reserve Pay, which lets a customer pre-block funds for future payments to a specific merchant. Under UAP, an AI agent would occupy that delegated slot instead of a human, spending against a limit the user sets once.
Startup Fortune
The Part That Isn't Built Yet
It's worth being precise about where both of these actually stand today: neither is live. Reuters' own reporting on the NPCI registry is sourced to three people involved in the discussions, none of whom could be named because they aren't authorized to speak to media — and NPCI itself has not publicly confirmed the plans. Details on final transaction limits and rollout timeline remain pending. The Ant/Visa/Mastercard KYA framework, per the companies' own announcement, is similarly described as a collaboration just beginning, without a finalized technical specification or public rollout date.
The single hardest unresolved question, on both fronts, is liability: who is actually responsible when a verified agent gets tricked — by a manipulated listing, a malicious prompt, a compromised merchant — into spending money the user never intended to spend. Reuters notes that an agent registry "would not itself resolve every risk," and that questions remain around consent, transaction limits, and who is liable when an agent behaves outside a user's instructions. Neither NPCI's protocol nor the KYA framework has published a public answer to that yet. Technode Global
Why It Matters Anyway
Even in this early, unfinished state, the direction is clear: the world's largest payment networks and India's national payments operator have independently concluded that agentic commerce needs its own version of identity verification — separate from, and layered on top of, how they verify humans today. KYC answered "who is this person." KYA is trying to answer a harder question: "who is actually responsible for what this piece of software just did with someone's money."
That question doesn't get resolved by an announcement. It gets resolved by whichever institution first proves its liability model actually holds up when an agent gets it wrong at scale.
FAQ
Are the NPCI registry and the Visa/Mastercard/Ant KYA framework the same thing?
FAQ
Is NPCI's AI agent registry live right now?
No. It's still under development, based on anonymous sourcing in Business Standard's original report, and requires RBI approval before it can launch. No public timeline has been given.
Are the NPCI registry and the Visa/Mastercard/Ant KYA framework the same thing?
No — they're separate, parallel efforts. NPCI's Unified Agent Protocol is specific to India's UPI rail. The KYA framework is a global effort among three payment networks to make their own existing agent-identity systems recognize each other.
What does KYA actually verify?
It's designed to trace an AI agent back to a validated human or business account, apply shared certification requirements before trusting an agent, and continuously monitor transactions rather than approving an agent just once.
Who's liable if a verified AI agent makes a mistaken purchase?
Neither framework has published a public answer to this yet. It remains the single largest unresolved question in both India's and the global industry's approach to agentic payments.
Tushar Shrivas
B.Tech CS@ Shri Balaji Institute of Technology & Management
I write at Metaplugs — breaking down the latest in tech, economics, and business into simple, impactful stories for everyday readers. Passionate about software testing and global finance.