Back to blog
KYI11 min read

Know Your Intent (KYI): Agents Have an Identity Layer. They Have No Intent Layer.

Know Your Intent (KYI) verifies what an AI agent is about to do, not just who it is. Why KYA repeats KYC, and why agents still have no equivalent of KYT.

Parth Chaudhary
Parth Chaudhary
Know Your Intent (KYI): Agents Have an Identity Layer. They Have No Intent Layer.

Know Your Intent (KYI) is the practice of checking, before an AI agent acts, that the action it proposes sits inside an authority a human actually granted, and producing a record of that decision that someone outside the transaction can verify. Know Your Agent (KYA) answers who the agent is. Know Your Intent answers what it is permitted to do right now, and proves the answer afterwards.

The two are not substitutes. The agent ecosystem in 2026 has spent most of its compliance effort on the first one and almost none on the second, and it is repeating a mistake financial services already made once.

The four-box problem

Financial services took roughly thirty years to work out that identity and action are separate controls.

Who is this party?What is this specific action?
HumansKYC (Know Your Customer)KYT (Know Your Transaction)
AgentsKYA (Know Your Agent)vacant

Three of those boxes are occupied. KYC has a naming statute and a compliance deadline. KYT has a rule that made transaction monitoring software mandatory. KYA has a fast-growing body of vendor products, verification services and industry commentary, and at least a dozen serious companies publishing on it.

The fourth box is empty. That box is Know Your Intent.

Why the fourth box matters more than the third

Identity verification does not stop a bad transaction. It tells you whose transaction it was.

That is not a criticism of KYC. It is what KYC was designed to do, and it is a precondition for everything downstream. But the reason banks bought transaction monitoring on top of it is that knowing a customer's name tells you nothing about whether this particular wire, on this particular Tuesday, to this particular counterparty, should be allowed to complete.

KYA has the same shape and the same limit. A verified agent identity tells you which agent acted, who operates it, and which principal it claims to act for. It tells you nothing about whether the specific action in front of you, right now, is inside the authority that principal actually granted.

An agent with a perfect, cryptographically attested identity can still delete the wrong records, email the wrong list, or place forty wrong orders in ninety seconds. Its identity will be flawless in every single one of those log lines.

What KYT actually did, and why the agent stack has not copied it

The useful part of KYT was never the monitoring. It was three structural changes, and they are the blueprint for KYI.

It moved the control from onboarding to runtime. KYC happens once, at the start of a relationship. KYT happens on every transaction, at the moment of the transaction. Agents act thousands of times per relationship. A control that fires once at registration is the wrong shape for them.

It made the decision machine-checkable. A monitoring rule is an artifact, not a judgment call. It can be versioned, tested and shown to an examiner.

It attached the decision to a named human. This is the part most people miss. New York's Part 504, adopted 30 June 2016 and effective 1 January 2017, was the first rule anywhere to explicitly mandate transaction monitoring software. But its real innovation was requiring a named board member or senior officer to personally certify, annually, that the program was adequate. That converted transaction monitoring from a budget line into a career risk, which is why the category grew the way it did.

There is no equivalent for agents. There is no artifact that says "here is the authority this principal granted, here is the action the agent proposed, here is the decision, and here is a signature you can check without asking us."

The pain points, specifically

This is not an abstract gap. Here is what is actually broken today.

1. The mandate is a sentence, not an artifact. "Book me a reasonable hotel" is an instruction to a model. It is not a machine-checkable authority. When the agent books something the user would not have approved, there is nothing to compare the action against, because the authority never existed in a form anything could check.

2. The record is held by the party being checked. A mandate has to live somewhere. Today the candidates are the payment network, the acquirer, or the company operating the agent. Each is a competent custodian. None is a disinterested one, because each has a commercial relationship with the outcome being recorded. This is the same reason a company does not audit its own books, and it is the single most under-discussed structural problem in the space.

3. Denials are invisible. Ask any auditor what they test and they will tell you: not whether a control was documented, but whether it was operating. The artifact that proves a control operated is the denial. The agent tried something, the check stopped it, and here is the evidence. Almost nothing in the current landscape produces this. Policy engines make decisions and discard them. Payment intent standards document approvals and say nothing about refusals. Observability tools record what happened, not provable non-events.

4. Every shipped intent standard is a purchase standard. The serious work on agent mandates so far, including Google's AP2 with its cryptographically signed Mandate primitive, and Mastercard's Verifiable Intent, is built around buying things. But most consequential agent actions are not payments. Deleting a record. Granting access. Changing a configuration. Sending a message to a customer list. Filing a document. Those actions have no rail, which means the parties who own rails structurally cannot cover them.

5. Nobody has published a liability rule. Google's AP2 specification explicitly hands adjudication to "the network adjudicator (e.g., Card Network)." The card networks have published nothing. Worldpay stated flatly on 30 July 2026 that no liability shift exists yet, and that allocation among issuer, acquirer, agent platform and merchant is still being negotiated in real time. The evidence layer is being standardised. The decision layer is vacant.

6. The baseline is worse than people assume. The Reserve Bank of India's FREE-AI committee report, published 13 August 2025, surveyed regulated entities on their AI practices and found that only 18% maintained audit logs, and only 21% monitored for model drift. That is a central bank measuring the state of AI record-keeping before agents were transacting at any scale.

7. Speed removes the human failsafe. A person placing a wrong order notices within minutes. An agent operating on a bad rule does not notice at all, and neither does anyone else, until a reconciliation runs. The window between a misauthorised action and its discovery is the entire exposure, and agents compress everything in that window except the discovery.

Three institutions described KYI in six months. None of them built it

The strongest evidence that this is a real category is that regulators arrived at the same specification independently, without coordinating, and without a vendor prompting them.

The IMF, April 2026. IMF Note 2026/004, by Davidovic and Tourpe, prescribes "digitally signed mandates specifying scope, limits, actor identity, and permitted conditions," plus activity logs and audit trails. It argues that authorization has to move from transaction-level to, in its words, "structural and mandate based."

The Monetary Authority of Singapore, 3 July 2026. MAS published SAFR, Safeguards for Agentic Finance at Runtime, with industry. It calls for "a governance checkpoint between every agent decision and its execution to ensure that no agentic action reaches execution without having been declared, authorised, and assessed." And it names the shift precisely: "the control point therefore migrates from human sign-off to machine-checkable policy enforced at runtime, with a verified, recorded checkpoint standing where an approver used to stand."

HM Treasury, 14 July 2026. The UK payments consultation, open until 6 October 2026, explicitly asks who bears responsibility for faulty code, incorrect data, or an AI agent acting outside its mandate. It asks. It does not answer.

None of these is binding. That is the point, not a weakness in the argument. Every compliance category that became an industry started as a non-binding paper years before the rule with a date on it.

How long this takes, and why it will be faster

Both previous cycles are a matter of public record, and both compressed.

KYC. The Bank Secrecy Act passed 26 October 1970 and contained no identity verification requirement. Nobody bought KYC software in 1971. The naming law was PATRIOT Act section 326, on 26 October 2001. The Customer Identification Program final rule landed 9 May 2003, with a compliance deadline of 1 October 2003. Statute to naming law: thirty-three years. Naming law to deadline: twenty-four months.

KYT. The Annunzio-Wylie AML Act of 1992 created suspicious activity reporting. NYDFS Part 504 was adopted 30 June 2016 and took effect 1 January 2017, with the first annual certification due 15 April 2018. Statute to naming rule: twenty-five years. Adoption to effective: six months.

Thirty-three years became twenty-five. Twenty-four months became six. Roughly twelve years to universal adoption became roughly seven.

The compression is not luck. Each cycle reuses the machinery of the last one: the buying centre exists, the budget line exists, and the person who signs the certification already has a title. KYI is not creating a compliance function. It is adding a row to one that already has a signatory.

What Know Your Intent actually requires

Three primitives. All three, or none of it works.

The mandate. A signed, versioned, machine-readable statement of what a principal authorised: scope, limits, conditions, expiry. Not a prompt. Not a chat log. An artifact that exists independently of the agent and can be shown to someone who was not there.

The hard problem here is honest and worth naming. If a model converts "book me a reasonable hotel" into a machine policy, the trust problem has not been removed. It has been moved from the agent to the translator, and then cryptographically signed. The signature now certifies an interpretation rather than an instruction. The only defensible answer is that the human confirms the structure rather than the sentence, and it is the confirmation that gets signed. The model translates. It never decides.

The gate. A check that runs between the agent's decision and its execution, every time, and returns allow or deny before anything happens. This part is no longer differentiated and anyone claiming it as a moat is behind. Microsoft's Agent Governance Toolkit shipped 2 April 2026 under an MIT licence, framework agnostic, intercepting agent actions before execution at under 0.1ms at p99. AWS followed with Cedar-based, default-deny agent policies on 6 August 2026 under Apache 2.0. Pre-execution interception is table stakes as of Q2 2026.

The receipt. A record of the decision, covering both allows and denials, that a third party can verify without access to the operator's systems. This is the part almost nobody has built, and it is the part that decides whether any of it is worth anything. A log that only its author can vouch for is not evidence. It is a claim.

What KYI is not

Being precise here matters, because three adjacent things get confused with it constantly.

It is not a payment standard. AP2, Verifiable Intent, ACP, x402 and the rest are rails and message formats. KYI is a decision and an evidence artifact that sits above whichever rail is used, and applies equally to actions that use no rail at all.

It is not a policy engine. Cedar, Cerbos, OpenFGA, Oso and Permit are all excellent, and all of them start from a policy an engineer already wrote. The unsolved half is the translation from a human's plain-language grant of authority into a signed, checkable artifact, and then the durable proof of what was decided against it.

It is not observability. Tracing tells you what an agent did. It does not tell you what the agent was permitted to do, and it cannot prove what the agent was stopped from doing.

And it is not a regulatory requirement yet. No jurisdiction mandates it. KYA is not mandated either, despite how some vendor material reads: it is industry terminology, not a rule with a date. Anyone telling you otherwise is selling something. The honest framing is that three public institutions have now described the requirement without any of them writing it into law, which is roughly where transaction monitoring sat in the years before Part 504.

What does KYI stand for?

Worth disambiguating, because the three letters are contested.

In compliance and identity contexts, KYI has historically been used for Know Your Investor, a screening product several identity vendors sell, and occasionally for Know Your Intermediary. There is also a live US trademark application for "Know Your Inference (KYI)," filed 5 December 2024 in Class 042.

In the context of AI agents and agentic commerce, KYI means Know Your Intent: verifying an agent's proposed action against a signed mandate before execution, and producing independently verifiable evidence of the decision.

Because the acronym is contested, the full phrase is the load-bearing term. Use "Know Your Intent" and treat KYI as shorthand only after the phrase has been established.

Frequently asked questions

What is Know Your Intent (KYI)?

Know Your Intent is a control that verifies an AI agent's proposed action against a signed, machine-readable mandate before the action executes, and produces a verifiable record of the allow or deny decision. It is the action-level control that sits alongside agent identity verification, in the same way transaction monitoring sits alongside customer identity verification.

How is KYI different from KYA (Know Your Agent)?

KYA establishes who an agent is, who operates it, and which principal it acts for. It is an onboarding control. KYI establishes whether a specific action is inside the authority that principal granted. It is a runtime control that fires on every action. KYA without KYI is KYC without KYT.

Why is agent identity not enough for compliance?

Because identity attributes an action, it does not authorise one. A verified agent can still take an action nobody approved, and the identity record will be perfectly accurate for that action. Auditors test whether a control was operating, and the artifact that demonstrates operation is a decision record, not an identity credential.

Who holds the record of what an AI agent was authorised to do?

Today, usually the payment network, the acquirer, or the company operating the agent. All three have a commercial interest in the outcome being recorded. Independence of the evidence is a structural property, not a marketing posture, and it is the open question in the category.

Is Know Your Intent a regulatory requirement?

Not yet, in any jurisdiction. The IMF (April 2026), the Monetary Authority of Singapore (July 2026) and HM Treasury (July 2026) have all described the requirement in non-binding publications. Both KYC and KYT existed as recommendations for decades before a rule with a compliance date created the industry.

What does a KYI receipt contain?

At minimum: a reference to the mandate version in force, the action the agent proposed, the decision, the policy that produced it, a timestamp, and a signature that can be checked without access to the systems of the party that issued it. Coverage of denials, not just approvals, is what separates evidence from a marketing log.

Where this goes next

The measured position is unusual and worth stating plainly: as of mid-2026, roughly 3% of transactions involve an AI agent in any capacity, while 89% of merchants report actively preparing for agentic commerce (Checkout.com, 9 June 2026). Meanwhile the major agent payment protocols, AP2, UCP, ACP, Agent Pay and Visa TAP, have published no production volume between them.

That gap is the whole window. The infrastructure decisions being made right now, before volume arrives, are the ones that will be extremely expensive to revisit afterwards, and the one that matters most is whether the record of what an agent was allowed to do is held by a party with money in the transaction.

Abstraxn builds the authorization layer: mandate, gate, receipt. It never holds funds, never holds keys, and never sits in the payment path, which is a deliberate design constraint rather than a gap in the product. Evidence produced by a party with a stake in the outcome is not evidence, and that constraint is the only way the receipt is worth anything to the person reading it two years later.

Identity told the industry who acted. Intent is what tells it whether the action should have happened at all.


Sources referenced in this article: IMF Note 2026/004 (April 2026); MAS SAFR, Safeguards for Agentic Finance at Runtime (3 July 2026); HM Treasury payments consultation (14 July 2026, closes 6 October 2026); RBI FREE-AI Committee Report (13 August 2025); NYDFS Part 504 (adopted 30 June 2016, effective 1 January 2017); USA PATRIOT Act s.326 and the CIP final rule (2001 to 2003); Microsoft Agent Governance Toolkit (2 April 2026); AWS agent policies (6 August 2026); Google AP2 specification; Worldpay commentary (30 July 2026); Checkout.com agentic commerce research (9 June 2026).

About the Author

Parth Chaudhary

Parth Chaudhary

Solution Architect

Parth Chaudhary is a Solution Architect at Antier, the team behind Abstraxn. He currently works at the intersection of account abstraction and agentic AI infrastructure, consistently shipping wallets, paymasters, identity primitives, and policy guardrails for autonomous agents in production. Find out more at abstraxn.com or easily spin up an agent at dashboard.abstraxn.com.