Article 4 min

The Future of Agentic Commerce: Scaling Trust With Know Your Agent (KYA)

August 25, 2025  


A new age of AI is here.

AI agents are ushering in a new era of innovation, defining a bold new chapter in  c-commerce. From booking trips to filling shopping carts, AI agents are learning from their environments, collecting data and performing tasks autonomously on behalf of a user. 

Yet, while agent-led commerce is rapidly advancing, the infrastructure to verify these agents hasn’t kept pace. Ecosystem players – such as merchants, platforms and consumers – still lack a fast, secure and privacy-safe way to verify the legitimacy of an agent’s origin, or whether the agent is truly acting with the user’s consent.

The challenge is clear: How do merchants keep AI agents honest as they move through the digital economy? And how do consumers trust that agents aren’t acting fraudulently on their behalf?

The key to closing the gap lies in identity.

Introducing Know Your Agent (KYA)

In our report, co-written with global payments and billing platform, PayOS, we offer both a perspective and a solution for the agentic era: Know Your Agent (KYA).

KYA is a new identity layer designed for agent-led digital interactions, bringing trust and compliance to agentic commerce without compromising speed or user experience. 

This isn’t just technical infrastructure – it’s a real-time trust layer that quietly safeguards the ecosystem while letting everything move at machine speed.

As PYMNTS CEO Karen Webster noted in a recent interview with Trulioo CEO Vicky Bindra, agentic AI is “perhaps the most significant change in how consumers and merchants engage in shopping behavior that we’ve seen in a very long time.”

KYA lets software take the lead, while keeping humans in control.

Inside the KYA Engine

Just as border security continuously evaluates travelers, agentic commerce requires infrastructure that can assess an agent’s integrity, origin and intent before clearing it to move autonomously in the digital economy on a user’s behalf.

At the heart of the KYA framework is a “Digital Agent Passport” (DAP), a lightweight, tamper-proof token that unlocks trust for agent-led commerce.

KYA follows five core steps to ensure trust and integrity at every stage of an agent’s lifecycle:

  1. 1. Verify the Agent Developer: Confirms the agent originates from a legitimate, vetted business entity
  2. 2. Lock the Agent Code: Ensures only approved, untampered code can operate
  3. 3. Capture User Permission: Provides proof of ongoing user consent
  4. 4. Issue a Digital Agent Passport: Signals that an agent is verified, trusted and in good standing
  5. 5. Ongoing Lookup: Continuously checks agent status to detect risk and prevent fraud in real time

KYA is not a one-time check – it’s a living system. Every agent remains under continuous scrutiny, with its behavior, risk profile and authorization status updated in real time. If an agent’s code changes, consent is revoked or suspicious activity arises, the system reacts immediately.

KYA in Action

As agents enter the digital economy, KYA is becoming top-of-mind for forward-looking organizations committed to secure, identity-first wanting agentic interactions. 

Trulioo recently collaborated with Worldpay, a global leader in payment technology, to introduce new safeguards for AI-powered agent-led commerce.

Worldpay will empower merchants to leverage the KYA framework, enabling them to trust shopping agents by validating consumer intent and the authority granted to those agents. This innovation will help merchants grow sales while safeguarding against fraud and unauthorized purchases.

“Agentic commerce has significant potential, but it can only scale with trust built in from the start,” said Vicky Bindra, Trulioo CEO. “With Worldpay, we’re laying the foundation for a more secure and accountable digital ecosystem – one where AI agents can operate transparently, and consumers stay in control.”

The collaboration will help merchants and platforms:

  • Unlock new experiences, from smarter checkout flows to real-time fraud detection, without sacrificing safety or visibility
  • Introduce smart controls to distinguish verified agents from malicious bots
  • Deliver measurable benefits across the entire ecosystem, including reduced fraud, smarter agent detection and improved checkout conversion
  • Give consumers confidence that AI agents are acting with proper permission
  • Establish a shared trust layer that supports innovation and meets regulatory standards

Why It Matters: A New Standard for Digital Trust

As AI-powered interactions rise to the forefront of commerce, trust and identity are crucial to maintaining integrity for consumers, merchants and the entire ecosystem. That means building an identity infrastructure that keeps pace with innovation.

KYA is that infrastructure.

And as the digital economy accelerates, KYA ensures trust moves just as fast. By anchoring agent behavior to verified identity, user consent and continuous oversight, it lays the foundation for a future where AI doesn’t erode trust, but scales it.

White Paper

Know Your Agent (KYA): An Identity Framework for Trusted Agentic Commerce

Get ready for the future of agentic commerce with Know Your Agent (KYA).

Frequently Asked Questions

Learn more about Know Your Agent (KYA).

Know Your Agent (KYA) is an identity verification layer for agent-led digital interactions. It builds trust, confirms origin, and reduces risks from AI agent decision-making by ensuring every AI or digital agent is legitimate, authorized, and operating with verified user consent.

With KYA, Trulioo and PayOS verify the developer’s identity, lock source code, capture user consent, issue a Digital Agent Passport (DAP), and validate each agent action. This secure process keeps AI agents trusted, compliant, and accountable.

Merchants, platforms, and consumers often lack a fast, reliable way to authenticate AI agents. Without KYA, it’s hard to confirm an agent’s legitimacy or authorization. Verification reduces fraud, supports regulatory compliance, and ensures trusted AI interactions.