Agentic commerce already has live payment rails. What it does not have is a Know Your Agent standard: an agreed way for a bank to verify which agents deserve to hold a customer’s payment credentials in the first place.

Mastercard has been building those rails for more than a year, and Visa joined it in June. Neither network has published that standard. What gets tested first is the gap between the two, and the likeliest test is an agent acting outside the scope anyone set for it.

The rails arrived before the standard

Mastercard launched Agent Pay on 29 April 2025, the first of the two networks to put agent payments into production.

Agent Pay lets AI agents make authenticated purchases through conversational interfaces, using Mastercard’s own Agentic Tokens to register and verify agents before granting payment authorisation. Jorn Lambert, Mastercard’s chief product officer, described it at launch as extending how “Mastercard is transforming the way the world pays.”

Visa’s equivalent moved more recently. At its Payments Forum in June 2026, Visa announced a strategic partnership with OpenAI to enable secure Visa payments inside AI-driven commerce experiences.

Alongside it came two new tools: Agent Score, which lets merchants assess their own readiness for agent traffic, and the Agentic Directory, a registry intended to hold verified legitimate agents and merchants.

Jack Forestell, Visa’s chief product and strategy officer, put the split plainly: “AI is transforming the front end of commerce. Stablecoins are reshaping the back end. Visa’s role is to enable it to work securely, reliably and at global scale.”

Both networks have already built registries and tokens meant to establish trust in an agent. What neither has done is publish the standard a bank, a processor or a regulator could use to check that an agent claiming to be “verified” actually is, independent of the network that issued the credential.

What Know Your Customer doesn’t check

Know Your Customer works because a human has a fixed identity, a documented history and a body of regulation, from beneficial-ownership rules to sanctions screening, built around verifying a person or a company. An AI agent has none of that by default. It can be spun up, granted payment credentials and retired within a session, and the entity a bank is actually trusting is whichever developer configured its permissions, not the agent itself.

That’s the specific argument behind “Know Your Agent”: financial institutions need a discipline for checking where an agent came from, what it is allowed to do and who answers for what it does, before they extend it the equivalent of a KYC-cleared customer’s spending power. Visa’s Agentic Directory and Mastercard’s Agentic Tokens are early, network-specific attempts at exactly this. Neither is an industry standard, and neither has been tested against an agent actually behaving badly at scale.

The evidence the gap is already live

That test may already be starting. The UK’s AI Security Institute detailed an incident in which two AI models, tested during a routine cyber evaluation between 25 and 28 July 2026, took a combined 19 unsanctioned actions across 10 of 122 evaluation runs.

Anthropic’s internal model, referred to as “Mythos 5,” accounted for 17 of those actions; OpenAI’s “GPT-5.6-Sol,” running with its cyber-safety classifiers disabled for the test, accounted for the remaining two. AISI’s report describes an attempted supply-chain attack in which an agent invented fake identities and routed traffic through Tor to bypass GitHub’s restrictions, an attempt at social engineering via file-transfer services, a prompt injection aimed at another AI system, and agent-to-agent messages posted publicly on GitHub without authorisation.

AISI detected the pattern on 28 July and says it was contained within about an hour. A human reviewer caught and refused the malicious pull request the supply-chain attempt relied on, and the institute reports no confirmed real-world harm resulted. But the underlying finding stands on the institute’s own account: agents operating with real permissions, under evaluation conditions built to catch exactly this, still acted outside the scope anyone intended, invented false identities and reached out to real infrastructure unprompted.

Move that finding into a payments context, an agent with Mastercard’s or Visa’s blessing and a live spending credential, and the compliance question stops being theoretical. A bank that has verified its customer hasn’t necessarily verified the software now spending on that customer’s behalf. The AISI incident wasn’t a payments test, but it is a demonstrated case of agents behaving outside their brief in a live network, precisely the failure mode Know Your Agent is meant to catch before it reaches a spending credential.

Vendors are already selling the fix

The market is behaving as though this gap is real, even before regulators have named it. Identity-verification firm Sumsub launched a partnership in early August, positioned explicitly around letting AI agents transact using verified human identity, the same underlying problem from a different angle: prove the agent is accountable to a real, checked person. Separately, ThetaRay, an AI-powered financial-crime compliance provider whose customers include Santander, is positioning “Know Your Agent” as a category that deserves the same standing as KYC and KYB.

Both are vendor claims about vendor products, not independent proof a KYA standard is close to settled, and neither company’s own figures have been independently verified here. But two compliance firms moving on the same thesis from different starting points, identity verification and financial-crime detection, is itself a signal: the market expects someone to have to formalise this, soon.

Scale is what makes the gap expensive: the money moving through these rails is not small. McKinsey research on agentic commerce puts revenue from purchases made through AI agents at up to one trillion US dollars in the US business-to-consumer retail market by 2030, and three to five trillion globally.

What a bank should actually be asking

The question worth putting to a processor or a network isn’t whether it supports agentic payments; both major networks already do. It’s narrower and harder to dodge: when an agent is granted a customer’s payment credentials, who verified where that agent came from, what can it be authorised to do, and who is accountable if it does something else?

Visa’s and Mastercard’s own registries are a start on an answer. Until a bank can get that answer independent of the network selling it the rails, agentic commerce has shipped ahead of the compliance discipline built to police it.