2 Sources
[1]
Your AI opens a bank account for you. Who goes to jail if it lies?: By Moritz Cremer
Most people still view artificial intelligence through the lens of a chat box. We tend to think of AI as a glorified autocomplete tool: a helpful assistant that answers queries, drafts emails, or summarises long PDFs. This view is dangerously out of date. We have entered the era of agentic AI.
[2]
Why It's Time to Know Your Agent | PYMNTS.com
That is the operating reality of agentic commerce today. AI agents are already transacting across retail, finance, travel and enterprise procurement at speeds no human oversight loop can match. The identity infrastructure that would allow any party to verify who an agent is, what it is authorized
Share
Copy Link
AI agents are now executing financial transactions, opening bank accounts, and signing contracts autonomously, but the infrastructure to verify their identity and authority doesn't exist. With AI-driven traffic to retail sites up 805% and agents driving over $22 billion in sales, regulators and standards bodies are racing to establish frameworks like Know Your Agent before the trust gap triggers widespread fraud and liability disputes.
The shift from chatbots to action-taking systems marks a fundamental change in how we interact with the digital economy. Agentic AI now controls operating systems, navigates websites, and executes transactions exactly like humans sitting at desks
1
. Within three to five years, manually logging into apps and completing web forms will become obsolete as users simply instruct AI agents to find better savings rates, open accounts, or switch service providers1
. Morgan Stanley and Bain analysts estimate that AI agents could drive 15 to 25 percent of US e-commerce by 2030, representing between $300 and $500 billion in value1
. The global AI agents market, valued at $5.4 billion in 2024, is projected to reach $236 billion by 20342
.
Source: PYMNTS
When autonomous AI actions occur without human oversight, the entire legal concept of consent unravels. Every website requires users to click acceptance of terms and conditions, privacy policies, and tracking cookies—actions carrying immense legal weight
1
. When an AI agent autonomously clicks "I agree" to terms the human user has never seen, businesses cannot definitively prove who authorized these actions1
. This creates what experts call orphaned liability: when AI makes unauthorized financial commitments, shares sensitive medical data, or signs binding contracts, determining who takes the fall becomes impossible1
. By Black Friday 2025, AI-driven traffic to U.S. retail sites had risen 805% year over year, with AI agents driving over $22 billion in global online sales2
. Yet the identity infrastructure that would allow any party to verify AI agent identity and authorization does not exist at scale2
.A functional Know Your Agent framework builds on the Know Your Customer model established during financial globalization in the 1970s
2
. This AI governance framework hinges on four capabilities: establishing who and what the agent is, confirming what it is permitted to do, maintaining accountability for every action it takes, and continuously monitoring its behavior against approved parameters2
. The proposed Power of Attorney for AI requires three non-negotiable layers: Proof of Human for high-assurance verification of the natural person behind the screen, Proof of Authority as the scoped mandate dictating exactly what AI is permitted to do, and Proof of Authenticity creating an immutable audit log for regulators1
. Without these capabilities, distinguishing between legitimate agentic commerce agents and malicious bots impersonating them becomes impossible2
.Related Stories
NIST launched the AI Agent Standards Initiative in February to ensure AI agents function securely on behalf of users and interoperate smoothly across digital interactions
2
. The initiative advances along three pillars: industry-led development of interoperability standards, community-led open-source protocol development, and research in AI agent security and identity2
. NIST's National Cybersecurity Center of Excellence published a concept paper covering identification, authorization, auditing, and controls to prevent prompt injection2
. Without standards for who agents are and what they are allowed to do, the agent economy cannot be trusted at scale2
.The IMF argues that as AI in e-commerce shifts payments from human-initiated instructions to agent-mediated decisions, traditional fraud prevention models built on human behavioral patterns become ineffective
2
. Regulators now demand verifiable identities for financial bots linked to legal entities, tokenized authorization mechanisms allowing agents to initiate transactions using preapproved payment methods without accessing underlying credentials, and cryptographic mandate frameworks binding agent-initiated actions to verifiable scope and limits2
. For banks, payment companies, and utilities, this represents a compliance and identity nightmare requiring businesses to answer four crucial questions when AI agents attempt regulated actions1
. The identity and accountability infrastructure built today will determine whether agentic commerce becomes a catalyst for global prosperity or a new frontier for unprecedented fraud2
.Summarized by
Navi
[1]
27 Jun 2025•Technology
28 May 2026•Technology
27 Oct 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
