Know Your Agent: verify the AI agent before it opens an account.
When an AI agent asks a bank to open an account for someone, the bank needs to know three things before anything else: which agent this is, who it is acting for, and whether that person is really there. The Agentic Financial Services Protocol (AFSP) answers those questions with five signed checks, before the agent reaches the bank's systems.
Know Your Agent (KYA) applies the logic of Know Your Customer (KYC) to the software acting on a customer's behalf. KYC asks who the customer is. KYA asks who built and operates the AI agent, whether it is the build it claims to be, and whether a real person authorized what it is doing.
Banks need this because agents arrive before KYC can start. Existing standards such as OAuth 2.0, FAPI 2.0, FDX and FIDO assume a relationship already exists. When an agent asks a bank to begin a relationship for someone the bank has never met, there is no agreed way to say yes safely. Without one, the only safe answer is no.
AFSP is an open specification for exactly that moment. Its specification does not use the term Know Your Agent, but its first two signals do what the industry means by it, and three more cover the person behind the agent.
Five checks, answered before the agent gets in.
Each check is a signed attestation. The bank receives all of them together in one package, and verifies them itself.
Signal
The bank's question
What is verified
Status in v0.1
S1 Agent provenance
Who is this agent?
A certified, registered, unmodified build from an accountable operator.
Mandatory
S2 Biometric consent
Who sent it, and did they say yes?
A real person, on their own enrolled device, explicitly authorized this session. The biometric never leaves the device.
Mandatory
S3 Federated referral
Has their identity been verified before?
A trusted network institution has already completed KYC on this person. An attestation only, with no raw data.
Optional
S4 Financial identity
Are they financially real?
Behavioral financial signals consistent with an established profile, from data the person permissioned under Section 1033.
Mandatory
S5 Session integrity
Are they present right now?
The session is operated by a person within normal behavioral parameters.
Conditional
Source: AFSP Specification v0.1, Sections 1.1 and 3.3. A missing S3 or S5 is noted and handled by the bank's own risk framework. Under the Non-Decline Principle, an S5 anomaly is never declined automatically.
One package
Signed, bound and single-use
The checks arrive as one signed Pre-Credential Agent Attestation (PCAA) package. It is bound to a single bank, valid for at most an hour, and can be used only once. A package bound to one bank is useless at another.
The bank decides
Three possible answers
The bank validates the package and returns PROCEED_TO_KYC, REQUEST_ADDITIONAL_VERIFICATION or DECLINE_SESSION. KYC then runs in the bank's own interface. The AFSP platform never receives KYC data.
What it is not
Not a score, not a KYC replacement
AFSP delivers attested facts, not a model or a fraud score. The bank keeps full KYC accountability and makes every decision. The agent presents, the human decides, the bank executes.
Questions banks ask about Know Your Agent
What is Know Your Agent (KYA)?
Know Your Agent is the idea of applying KYC-style checks to the software acting for a customer: who built and operates the AI agent, whether it is the build it claims to be, and whether a real person authorized what it is doing.
Is AFSP a Know Your Agent standard?
The AFSP specification does not use the term, but it covers what Know Your Agent means for banks. Signal 1 verifies the agent's build and operator, and Signal 2 verifies that the person authorized the session on their own device. AFSP adds checks on the person's verified identity, financial profile and presence, all delivered in one signed package.
Does AFSP replace KYC?
No. AFSP decides only whether an AI agent session should proceed to the bank's open banking API layer. Identity verification, KYC, underwriting and the account-opening decision stay with the bank, which keeps full KYC accountability.
Which AFSP checks are mandatory?
Agent provenance (S1), biometric consent (S2) and financial identity (S4) are mandatory. Federated referral (S3) is optional. Session integrity (S5) is conditional, and an S5 anomaly is never declined automatically: it is routed to reauthorization, step-up verification or review.
How can a bank or fintech take part?
Read the v0.1 specification and comment publicly on GitHub before November 16, 2026, or become a Founding Endorser: a letter of endorsement and a working-group commitment, with no implementation required. Contact afsp@primitive.com.