Know Your Human: KYC's Agentic Payment Gap
The IMF warns AI agents making payments expose critical KYC gaps. Discover why 'Know Your Human' is now the compliance imperative for agentic commerce.

An unusual document came out of the International Monetary Fund in April 2026. Autonomous AI agents were formally identified, in IMF Note 2026/004 — How Agentic AI Will Reshape Payments — as a structural threat to the identity verification frameworks that underpin global financial systems.
KYC and multifactor authentication, the paper warned, "rely on explicit human action." That is the IMF's concern, and it is precise. The foundational assumption collapses when AI agents capable of executing payments, initiating transfers, and managing accounts act autonomously on a user's behalf. The transaction that follows may have nothing to do with the human who passed the original KYC check.
LexisNexis Risk Solutions puts numbers on a problem that is no longer theoretical. Agentic traffic — autonomous AI interactions with financial and e-commerce systems — rose 450 percent in 2025. In February 2026, Microsoft Security confirmed that 80 percent of Fortune 500 companies operate active AI agents. FIS, one of the world's largest payment processors, launched its industry-first agentic payment platform in May 2026. Deployment is already in progress. The compliance infrastructure has not caught up.
Why Traditional KYC Assumes a Human — and Where That Assumption Fails
Know Your Customer rules were written around a particular premise. A person starts a financial interaction, presents credentials, and is verified once at the point of entry. Later activity then carries implicit trust, because humans behave in recognizable, bounded ways. Anomalies are detectable. Liability is attributable.
Each of those properties is dismantled, systematically, by AI agents.
Authorize an AI agent to pay invoices, execute trades, book travel, or manage subscriptions, and the agent can fire off dozens or hundreds of transactions with no further human involvement. Regulatory thresholds that would ordinarily trigger re-verification may be crossed by any one of those transactions. Liability questions follow that existing frameworks cannot cleanly resolve.
Take a sequence of crypto asset transfers executed in rapid succession by an AI agent working under a broad authorization. Every transfer must have a traceable, verified human principal under MiCA. Travel rule data must accompany every transaction under the Transfer of Funds Regulation. The originating human, though, verified their identity at onboarding, months earlier. Their current KYC status, risk profile, and behavioral patterns are not being assessed in real time. Because no mechanism exists to interrupt them, the agentic transactions proceed.
The Biometric Update flagged this as a sector-wide shift in May 2026: financial services are being pushed toward "continuous identity" — a model where identity is not an event that happened at onboarding, but a validated state maintained throughout the customer lifecycle.
Know Your Human: A Shift in the Compliance Model
PYMNTS coined a name for the industry's response to this gap. Know Your Human (KYH) describes the compliance standard that places the verified, consenting human back at the center of every agentic transaction chain.
KYH is a layer, not a replacement for KYC. Traditional identity verification is extended to cover three specific failure modes that agentic commerce creates.
Delegated authority verification. Explicit, documented consent that specifies the scope of delegation is required by KYH when a user authorizes an AI agent to act on their behalf. Paying utility invoices below €500 per month may be in scope; executing equity purchases or initiating international wire transfers may not. Bounded, verifiable delegation is the compliance primitive that KYH introduces. Unbounded delegation is a liability gap.
Continuous validation. An agent that will act autonomously for months or years afterward makes a one-time KYC check at onboarding structurally insufficient. Ongoing confirmation is required under KYH frameworks: the verified human remains in control of the delegation, and the agent's transactions remain within the authorized behavioral envelope. The system must pause and re-verify when an agent begins transacting in ways that diverge from the human's established pattern.
Traceability for dispute resolution. A complete chain of accountability must be reconstructable from the compliance record when a transaction executed by an AI agent is disputed. Did the verified human authorize this agent? Did the specific action fall within the authorized scope? Where did the behavioral baseline diverge? Chargebacks, regulatory inquiries, and fraud investigations become legally unresolvable without this audit trail.
For a detailed look at the machine-facing side of this problem — verifying the agent's own identity and permissions — see our analysis of Know Your Agent (KYA): AI Identity Verification.
Where the Regulatory Exposure Lands
Concrete liability for payment service providers follows from this gap. Providers face "increased liability risk if they cannot validate whether a transaction has been duly authorized," Addleshaw Goddard's February 2026 analysis concluded, especially where existing frameworks "were designed around human behavior, not autonomous agents."
EU-regulated entities pick up layered exposure. PSD3 and the Payment Services Regulation wrote strong customer authentication around human-initiated actions. Whether that first human authentication covers SCA for later agentic transactions is still unresolved. The European Banking Authority has issued no guidance specific to agentic payment flows.
AMLR and MiCA state the duty more bluntly. Each transaction has to attach to a verified human principal whose risk profile is current. Architectures built for human-initiated transactions do not meet that bar once activity is autonomous and agentic.
The fraud vector sits alongside the regulatory one. Compromise an AI agent's session, or manipulate the agent's instructions through prompt injection, and an attacker can execute financial transactions that appear technically authorized — they fall within the original human delegation — while serving entirely fraudulent ends. Distinguishing legitimate agentic behavior from agentic fraud is something traditional fraud detection models built around human behavioral patterns are poorly equipped to do.
How Compliant Agentic Identity Is Structured
The identity stack has to be re-architected around delegation, not verification alone, if the Know Your Human gap is going to close.
| Dimension | Traditional KYC | Know Your Human |
|---|---|---|
| Verification moment | Single check at onboarding | Ongoing, across the agent lifecycle |
| Subject | Human identity | Human identity plus authorized agent scope |
| Authorization record | Account credential | Delegation document carrying scope constraints |
| High-risk transactions | Human re-authenticates | Agent pauses; the human re-authorizes that specific action |
| Audit trail | Session log | Transaction log tied to the delegation record |
| Anomaly detection | Human behavioral baseline | Agentic behavioral baseline inside authorized scope |
A compliant agentic identity stack has four obligations. Record the grant when authority is given — the moment a user lets an AI agent act, those bounds need the same legal precision applied to a KYC identity document. Check those bounds at execution — no agentic transaction should go through until it has been matched against the stored delegation. Keep a live behavioral model running — if activity drifts from the human's authorized pattern, re-verification should fire before the situation escalates. Emit a continuous audit trail — each agentic action should map back to the human authorization that allowed it.
Confirming who a human is is only part of it. Continuous, traceable accountability of every action taken in their name is the rest — and that is the architecture Joinble's AI Agents were built to support.
For a closer look at how multi-agent systems handle compliance decisions without human intervention, see Agentic KYC: How Autonomous AI Agents Are Replacing Manual Compliance Reviews.
Timeline: Moving Ahead of Formal Guidance
The IMF published its warning in April 2026. FIS launched its agentic payment platform in May 2026. Banks across Europe are being enrolled in Visa's agentic commerce infrastructure. The deployment cycle sits ahead of the regulatory guidance cycle by a margin that is growing, not shrinking.
Build Know Your Human infrastructure proactively — before the EBA issues SCA guidance for agentic flows, before ESMA clarifies MiCA obligations for AI-initiated transfers, before the first enforcement action establishes liability precedent — and the remediation burden will be significantly lower than it will be for organizations that wait.
KYC compliance history offers a consistent lesson. Building identity infrastructure reactively, under regulatory pressure and with evidence preserved for investigation, costs an order of magnitude more than building it correctly the first time.
FAQ
What is Know Your Human (KYH)? Know Your Human is a compliance framework that stretches traditional KYC onto AI agents acting on a human's behalf. Documented delegation of authority, continuous validation that the human remains in control, and a full audit trail linking every agentic transaction to the authorizing human are all required.
Why does traditional KYC fail for agentic transactions? A human identity is verified by traditional KYC at a single point in time. The human's AI agent can then execute transactions autonomously, with no additional identity check, once that step is complete. Standard KYC has no mechanism to verify that each agentic action falls within the scope authorized by the verified human.
What did the IMF say about AI agents and KYC? Published April 22, 2026, IMF Note 2026/004 warns that AI agents capable of executing payments expose gaps in KYC and multifactor authentication, which "rely on explicit human action." Developing trusted identity frameworks and interoperable standards for agentic delegation verification is what the IMF recommends.
How is Know Your Human different from Know Your Agent (KYA)? Verifying the machine is the focus of KYA — establishing a digital identity for the agent and certifying what it is technically authorized to do. Maintaining the verified human's accountability throughout every transaction the agent executes on their behalf is the focus of KYH. Both are necessary; neither alone is sufficient.
What regulatory frameworks currently govern agentic payments in the EU? PSD3, the Payment Services Regulation, AMLR, and MiCA for crypto asset transfers are the frameworks under which agentic payments fall. None were designed with autonomous agents in mind. As of May 2026, regulatory guidance specific to agentic payment flows has not yet been issued by the EBA or ESMA.
How do I know if my KYC system is prepared for agentic transactions? Three questions decide it. Does your system capture the scope of any AI agent delegations granted by verified users? Does it validate each agentic transaction against that delegation record before execution? Does it produce an audit trail linking every agentic action to the authorizing human? A no to any of those means your KYC architecture has an agentic gap.
Related Articles

Visa Launches Agentic Ready: AI-Powered Autonomous Commerce Gets Payment Infrastructure
Visa introduces its Agentic Ready program in Europe with 21 issuing banks. We analyze what it means for identity verification, KYA, and digital trust in agentic commerce.

The 45-Day Mule Account Gap: Why FRAML Needs Agentic AI
Money mule accounts stay active 45 days before detection. Here is how FRAML convergence and agentic AI are closing the gap for banks in 2026.

PSD3 and PSR: What Payments Firms Must Know About KYC
PSD3 and PSR shift fraud liability to PSPs who miss identity checks. Here is what payment firms need before late-2026 enforcement kicks in.