A merchant's checkout receives a purchase request. It is not from a person at a keyboard. It is from software acting for someone.
Four questions follow, and they are not the same question. Which agent is this. Who operates it. What was it actually authorized to do. And if another network already answered those questions, can this merchant rely on the answer.
The fourth one is the interesting one, and it is the one Ant International, Mastercard and Visa started working on this week.
What they announced
On September 9, the three said they have begun collaboration on a Know-Your-Agent interoperability framework, meant to help card networks, wallet ecosystems, agent platforms and marketplaces streamline agent onboarding and identification across networks.
The collaboration centers on three things, in their words. Cross-network operator traceability, where each agent is linked to a validated operator, cardholder, or business, enabling clear attribution of agent activity. Shared certification requirements, where each agent is assessed against security and behavioral requirements. And continuous transaction monitoring, where each agent is evaluated on an ongoing basis using identity and transaction signals.
Some of this work will run through BuildFin.ai, an industry platform convened by the Monetary Authority of Singapore, building on a framework called Safeguards for Agentic Finance at Runtime. The workstream is described as operating across payment ecosystems in Singapore.
Note the verbs. Begun. Explore. There is no specification, no governance body, no timeline, and no launch.
Newsletter
Follow the research
Research notes and analysis on how AI, digital transformation, product discovery, and customer behavior are changing commerce.
Subscribe to Hu's Weekly HootThe sentence that defines the limit
The framework is described as based on shared principles while preserving each network's own verification and decisioning processes.
That clause does more work than the headline. It means the networks are not proposing to accept each other's verdicts. Each keeps its own verification. Each keeps its own decision about whether to trust a given agent.
So what is actually becoming portable is not trust. It is the questions. The three are aligning on what has to be known about an agent, what it has to be certified against, and the fact that it should be monitored after certification. They are not aligning on who gets to conclude that the agent is fine.
That is real, and smaller than a portable agent identity. It is closer to a shared syllabus than a shared diploma.
Three companies, three different problems
The gap becomes clearer when you look at what each brought, because the protocols are not solving the same thing.
Visa's Trusted Agent Protocol is about recognition at the merchant's door. Agents sign their requests, and merchants validate the signature. Visa's own documentation frames the problem as merchants historically classifying automated traffic as bots and blocking it, and the protocol as a way to distinguish trusted commerce agents from malicious ones. The signal it carries is that this is a Visa trusted agent. Visa also notes the product is in development and deployment and may not be available in all markets. Card issuers have been verifying agent identity for months, each on their own terms.
Mastercard Verifiable Intent is not primarily an identity system at all. It creates a record of what the user authorized, linking the cardholder, the instruction, and the outcome, as cryptographic proof of authorization. Mastercard's Chief Digital Officer described the goal as verifying that actions reflect the user's intent and preserving accountability.
Ant International's Agentic Mobile Protocol comes from the wallet side rather than the card side, and it already contains its own Know Your Agent framework covering an agent's digital identity and certified capabilities, plus a proprietary Agent Trust Rating that it describes as a dynamic risk tool controlling how much autonomy an agent gets.
Three organizations, three layers. Recognition, authorization, and delegation on wallet rails.
Why that distinction survives the announcement
This is my interpretation rather than anyone's claim.
Knowing which agent is at the door is not the same as knowing what it was allowed to do. And neither is the same as knowing it did that thing correctly.
An agent can be legitimately operated, properly certified, correctly identified, and still execute an instruction badly or beyond its scope. That is not a hypothetical gap. It is the same boundary I keep running into wherever software acts on a business's behalf, and identity infrastructure does not close it. A verified agent that sends the wrong thing is still a verified agent.
The KYA work is aimed primarily at the first problem, touches the second through Mastercard's contribution, and does not claim to solve the third.
Continuous trust is the part worth watching
The monitoring language is the most forward-leaning thing in the announcement, and it points somewhere structurally different.
If an agent is continuously evaluated using identity and transaction signals, then verification stops being a one-time gate. Ant's Chief Innovation Officer talked about the industry drawing on richer signals, naming capabilities, behavior, execution performance, and risk data.
Read that plainly and a verified agent is not permanently a trusted agent. Its status can move. Ant already ships something along these lines in its own protocol, tied to how much autonomy an agent is granted.
I want to be careful here. There is no shared cross-network trust score, nothing in these materials says merchants can rank or block agents by trust history, and Ant's rating is its own proprietary mechanism rather than an output of this collaboration. What the announcement supports is narrower: the participants think ongoing assessment belongs in the model.
The objections
The strongest one is the collaboration's own framing. Preserving each network's own decisioning is exactly the thing that keeps a merchant from being able to rely on a single answer, and it is in the defining sentence.
Commercial incentives point both ways. Trust intelligence about agents is competitive information, and a network that fully honors a rival's verification gives up some of the reason to be the network. Common principles are cheap to agree on. Common infrastructure is not.
The scope is also narrower than the company names suggest. The concrete regulator-adjacent workstream is described as operating in Singapore, and one of the three protocols involved is still in development by its own documentation.
Merchants will keep their own risk controls regardless, and most existing fraud systems were not built to consume agent-specific trust signals. Identity does not establish that a transaction was authorized correctly, liability rules remain unsettled, and a global agent identity layer would concentrate governance in a way that creates its own problems.
What I would actually watch
Commerce spent decades making identity and money portable between institutions. A merchant does not evaluate a card credential from first principles, because infrastructure carries that trust. Agentic commerce may need something similar for the software actor, and this is a step toward it rather than an arrival.
The signal I would watch for is not another framework announcement. It is the first time one network's verification is accepted by another without a second check, because that is the moment the questions stop being shared and the answers start being.
If every network keeps the right to decide for itself which agents to trust, what exactly has become interoperable?