Leadership1 publisher2 min readPublished
AI buying agents strain the ongoing checks behind KYC and AML
KYC checks built for a passport holder cannot re-verify AI buying agents, ITPro argues, as Visa, Mastercard and PayPal complete thousands of agent transactions. The gap is widest in the ongoing checks that keep confirming who the customer is.
The Board Room · Leadership desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Retuning bot rules for session velocity, device consistency and transaction cadence tells a firm whether activity looks suspicious, but not whether the agent is authorised.
- Most businesses are bolting identity and fraud controls onto systems built to keep automation out, and in agent commerce the only feedback from that friction is lost revenue.
- The article expects thousands of agents acting across channels for different people, companies, wallets and platforms, too many to label one at a time as good or bad.
- Mature banking, financial services and insurance firms are already worried, the article says, while most smaller firms have not started the conversation.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- constraint Document and face re-checks are unavailable once an agent is transacting, so ongoing due diligence on agent-led activity has to test the grant of authority itself, and current controls were not built for that.
- decision Fraud teams own the question of whether traffic looks suspicious and compliance owns the question of permissions, so firms must decide who checks an agent's authority before either side retunes its rules.
- exposure Firms adopting agents as a productivity tool take on delegated-authority risk that nobody is assigned to monitor, because most clients do not yet treat agent commerce as a compliance problem.
Ongoing due diligence is the part of the identity model that fails first. A person is still somewhere in the chain. In the article's software example, a customer lets an AI agent buy on their behalf [7]. The rules then require continuous monitoring after that first check, according to the piece [4], and an agent cannot be re-verified mid-transaction because there is no one there to re-verify [3]. The article defines real monitoring as continuously asking whether a customer's identity, risk profile, authority and credentials are still valid at the moment a business relies on them [12].
The article shifts the question from the person to the permission. Agents sit between the customer and the transaction, it says, "carrying what is effectively the badge of the person who sent them" [13]. For compliance, the question becomes "whose authority is this agent carrying, and is that authority still real?" [14]. The article argues identity should never be treated as static: names and addresses change, and immigration, residency and professional status can be granted or withdrawn [8]. It applies the same test to an agent's permissions and asks whether they are still valid [6].
The trade-off for operators is between blocking agent traffic and accepting transactions the business cannot attribute. Loosen the bot rules and you get the article's software case. The payment clears and the behavioural data is clean. Yet the business has no idea who authorised the agent, what it was allowed to buy, or whether it has drifted into renewing licences nobody approved [7].
A skeptic would say the piece is written for channel partners and makes a sales case for "trust infrastructure, not tooling" [17]. That is a fair caution about the remedy. I think the diagnosis holds anyway, because it rests on how the checks are built. They are built around a document and a face, and an agent has neither [3]. The article does not put a figure on agent-related fraud or compliance losses. Its evidence of scale is the payment networks' activity [2].
This quarter's decision is what evidence of delegated authority a firm will accept. In the article's sequence, that comes after mapping the bot controls a client already runs [11]. The effects show up later, in ongoing monitoring. The piece lists the open questions there as which automated interactions to trust, what evidence that trust requires, and how delegated authority is monitored over time [10].
What to watch
- Regulator guidance on how ongoing KYC and AML monitoring applies to purchases an AI agent initiates on a customer's behalf.
- Whether Visa, Mastercard or PayPal give sellers a way to check, per transaction, who authorised an agent and within what limits.