Know your agent: Why UK fintech needs an identity system for its AI before the Treasury builds one
Yuliia Harkusha is a London-based AI marketing strategist, Google Product…
For decades, financial services have been built around a fairly basic assumption: before someone is allowed to move money, you should probably know who they are. Banks verify customers, firms authenticate employees, payment providers separate authorised transactions from fraud.
Then along came AI agents that search, negotiate, manage accounts and increasingly initiate payments on someone’s behalf. There is one awkward question nobody has quite answered: who is the agent? Not what model powers it, whose authority is it using, what is it allowed to do, and how does another system verify that before accepting its instructions?
The UK government has started asking the same question. HM Treasury’s July Financial Services AI Adoption Plan made agentic payments one of its ten recommendations. Recommendation 10 calls for a trust framework built around liability rules, interoperable authentication and an acronym waiting to happen: Know Your Agent, or KYA – standardised identity and verification for autonomous software agents. The linked payments consultation stays open until 6 October.
That may sound niche. It isn’t – identity could become the most important control layer in agentic finance.
KYC for humans, agents need something different
It’s tempting to treat KYA as KYC for robots. That analogy survives about thirty seconds. A human customer has an identity that persists. An AI agent may exist for a single transaction and disappear, be owned by a bank, deployed by a fintech, powered by another company’s model, and delegate work to another agent entirely. Verifying it cannot simply mean establishing that “Agent 8472 exists.” A useful system must answer what the agent is, whose authority it’s exercising, what it’s permitted to do, and whether that permission can be delegated or revoked. That’s not identity verification. It’s identity plus authority.
Say you instruct an agent: find the cheapest direct flight to Madrid on Friday and book it if it’s under £250. It finds one for £190 and asks a payment service to complete the purchase. The system doesn’t just need to know it’s a recognised agent – it needs to know the agent is acting for you, that you authorised travel spending up to £250, and that three business-class tickets to Dubai would fall dramatically outside the brief.
Your agent needs more than a password
Today, most agentic systems inherit credentials built for humans: an API key, an OAuth token, a service account. Technically, this works. Governance-wise, it’s like lending your intern the company card and your CEO’s login because separate permissions felt tedious. A bank should eventually be able to distinguish “this is an authenticated agent” from “this is Agent X, operated by Provider Y, acting for Customer Z under a mandate permitting purchases up to £500, with no permission to transfer funds or delegate to another agent.” The first tells you who knocked. The second tells you whether to let them near the safe.
The CMA has already spotted the missing layer
Treasury isn’t the only UK institution circling this. In March, the Competition and Markets Authority published its analysis of agentic AI and consumers, warning that as agents transact on users’ behalf, reliable mechanisms for verifying identity and authority to act become essential, and that fragmented identity systems could increase fraud and disputes. It also warned that closed, proprietary agent ecosystems risk market lock-in, and called for open standards on permissions and logging. Put identity, permissions and logs together and you get the foundations of an accountable system: identity tells you who acted, permissions tell you what they were allowed to do, logs tell you what they actually did – considerably stronger than asking the model nicely not to buy anything inappropriate.
Britain isn’t starting from zero. The Office for Digital Identities and Attributes released version 1.0 of the UK’s digital verification trust framework in June, built for people and organisations rather than agents – but the same government’s July Digital Identity Sectoral Analysis already flagged AI agent identity as an emerging use case. Treasury, the CMA and the identity sector are, without quite saying so, describing the same missing infrastructure – the same architecture-not-paperwork argument I’ve made writing about governance-as-code, applied here to who an agent is rather than what it produces.
Don’t wait for the rulebook
The Adoption Plan is explicit that practical standards should initially be industry-led – Treasury is effectively telling the market not to wait for Treasury. Founders building agentic financial products should already be designing around a few assumptions:
● Every agent needs a distinct identity – “one of our AI systems did it” will not survive a dispute.
● Identity has to connect back to a principal, and authority should be explicit and scoped, not inherited wholesale.
● Every significant action needs an attributable record, ready before a dispute, not reconstructed after one.
There’s a commercial upside hiding inside the governance. “Our AI can autonomously manage payments” and “every agent has a verifiable identity, every transaction ties to a mandate, and your compliance team can see the whole chain” are different pitches to a bank’s procurement team, and only one gets through quickly — especially given the CMA has made clear businesses stay liable for their AI agents even when a third party built them, with penalties up to 10% of worldwide turnover. “The vendor’s model decided that” was never a compelling defence.
The conversation around AI agents has focused on intelligence – can they reason, use tools, negotiate. Financial services is about to force a more useful question: can we identify them, authenticate them, prove who authorised them, and reconstruct what happened when it goes wrong? Before an AI agent gets a wallet, it needs something resembling a passport, an employee badge and a power of attorney rolled into one. Call it KYA. Just don’t wait for the first unauthorised payment to find out why you needed it.
For more startup news, check out the other articles on the website, and subscribe to the magazine for free. Listen to The Cereal Entrepreneur podcast for more interviews with entrepreneurs and big-hitters in the startup ecosystem.




