Know Your Agent (KYA) for banks

Know Your Agent: verify the AI agent before it opens an account.

When an AI agent asks a bank to open an account for someone, the bank needs to know three things before anything else: which agent this is, who it is acting for, and whether that person is really there. The Agentic Financial Services Protocol (AFSP) answers those questions with five signed checks, before the agent reaches the bank's systems.

What is Know Your Agent?

Know Your Agent (KYA) applies the logic of Know Your Customer (KYC) to the software acting on a customer's behalf. KYC asks who the customer is. KYA asks who built and operates the AI agent, whether it is the build it claims to be, and whether a real person authorized what it is doing.

Banks need this because agents arrive before KYC can start. Existing standards such as OAuth 2.0, FAPI 2.0, FDX and FIDO assume a relationship already exists. When an agent asks a bank to begin a relationship for someone the bank has never met, there is no agreed way to say yes safely. Without one, the only safe answer is no.

AFSP is an open specification for exactly that moment. Its specification does not use the term Know Your Agent, but its first two signals do what the industry means by it, and three more cover the person behind the agent.

Five checks, answered before the agent gets in.

Each check is a signed attestation. The bank receives all of them together in one package, and verifies them itself.

SignalThe bank's questionWhat is verifiedStatus in v0.1
S1 Agent provenanceWho is this agent?A certified, registered, unmodified build from an accountable operator.Mandatory
S2 Biometric consentWho sent it, and did they say yes?A real person, on their own enrolled device, explicitly authorized this session. The biometric never leaves the device.Mandatory
S3 Federated referralHas their identity been verified before?A trusted network institution has already completed KYC on this person. An attestation only, with no raw data.Optional
S4 Financial identityAre they financially real?Behavioral financial signals consistent with an established profile, from data the person permissioned under Section 1033.Mandatory
S5 Session integrityAre they present right now?The session is operated by a person within normal behavioral parameters.Conditional

Source: AFSP Specification v0.1, Sections 1.1 and 3.3. A missing S3 or S5 is noted and handled by the bank's own risk framework. Under the Non-Decline Principle, an S5 anomaly is never declined automatically.

One package

Signed, bound and single-use

The checks arrive as one signed Pre-Credential Agent Attestation (PCAA) package. It is bound to a single bank, valid for at most an hour, and can be used only once. A package bound to one bank is useless at another.

The bank decides

Three possible answers

The bank validates the package and returns PROCEED_TO_KYC, REQUEST_ADDITIONAL_VERIFICATION or DECLINE_SESSION. KYC then runs in the bank's own interface. The AFSP platform never receives KYC data.

What it is not

Not a score, not a KYC replacement

AFSP delivers attested facts, not a model or a fraud score. The bank keeps full KYC accountability and makes every decision. The agent presents, the human decides, the bank executes.

Questions banks ask about Know Your Agent

What is Know Your Agent (KYA)?

Know Your Agent is the idea of applying KYC-style checks to the software acting for a customer: who built and operates the AI agent, whether it is the build it claims to be, and whether a real person authorized what it is doing.

Is AFSP a Know Your Agent standard?

The AFSP specification does not use the term, but it covers what Know Your Agent means for banks. Signal 1 verifies the agent's build and operator, and Signal 2 verifies that the person authorized the session on their own device. AFSP adds checks on the person's verified identity, financial profile and presence, all delivered in one signed package.

Does AFSP replace KYC?

No. AFSP decides only whether an AI agent session should proceed to the bank's open banking API layer. Identity verification, KYC, underwriting and the account-opening decision stay with the bank, which keeps full KYC accountability.

Which AFSP checks are mandatory?

Agent provenance (S1), biometric consent (S2) and financial identity (S4) are mandatory. Federated referral (S3) is optional. Session integrity (S5) is conditional, and an S5 anomaly is never declined automatically: it is routed to reauthorization, step-up verification or review.

How can a bank or fintech take part?

Read the v0.1 specification and comment publicly on GitHub before November 16, 2026, or become a Founding Endorser: a letter of endorsement and a working-group commitment, with no implementation required. Contact afsp@primitive.com.

Help build the trust layer for agentic banking.

Become a Founding Endorser