KYA: Know Your Agent - The Trust Problem Nobody Is Solving Fast Enough

KYA: Know Your Agent - The Trust Problem Nobody Is Solving Fast Enough

OpenAI just bet $650 million on Isara, a startup founded by two 23-year-olds whose pitch is simple: train swarms of AI agents to coordinate, and they will outperform any single model on complex problems. Their demo? Thousands of agents forecasting the price of gold. Their target? Finance, biotech, geopolitics.

That number — $650M valuation, less than a year after founding — tells you something about where capital is flowing. Not into smarter individual models. Into coordination. Into orchestration. Into the question of what happens when you have a thousand agents working together.

Here is the question nobody in the room is asking: how do you know which agent did what?


The Coordination Problem Is Real. So Is the Trust Problem.

In March 2026, the agent economy went mainstream. Bybit shipped 253 API endpoints built for AI agents. Trust Wallet gave agents direct execution access across 25 blockchains. Crossmint gave agents their own Visa cards with programmable spending limits. x402 made HTTP payments native for machines. MoonPay open-sourced OWS, a local-first memory and state layer for agent infrastructure.

Meanwhile, OpenAI backed Isara to coordinate thousands of agents simultaneously. Solana's CPO said 99.99% of on-chain transactions will be agent-initiated within a year. And the NEAR co-founder published that AI agents will become the primary users of blockchain infrastructure.

The payment layer is being built. The coordination layer is being built. But verification — the ability to prove which agent took which action, under whose authority, within what constraints — is still an afterthought in most of these systems.

This is the KYA problem. Know Your Agent.


What KYA Actually Means

KYC (Know Your Customer) was the compliance standard that made financial access conditional on identity. You cannot open a bank account, trade securities, or wire money internationally without proving who you are.

KYA is the agent equivalent. It is not bot detection — that is a blunt instrument that asks "is this a human or a machine?" KYA asks a different question: which machine, acting for whom, authorized to do what?

There are four components:

Identity: A verifiable, persistent credential tied to this specific agent and version. Not a wallet address — those are pseudonymous and transferable. An agent-specific identifier with provenance data attached.

Authority binding: A cryptographic proof that this agent is authorized to act on behalf of a specific principal. If an agent is trading your portfolio, something on-chain needs to link the agent to your wallet in a way that auditors can verify.

Runtime constraints: What the agent is permitted to do at execution time. Spending limits. Merchant allowlists. Approval thresholds. Policy constraints that cannot be overridden by the agent itself.

Audit trail: A tamper-evident log of every action the agent took, sufficient to reconstruct what happened if something goes wrong.

The stablecoininsider.org research team published a detailed breakdown of this framework in February 2026. Their key finding: KYA is not optional infrastructure for a world of coordinated agents. It is required infrastructure. Gartner predicts 40% of enterprise applications will embed task-specific agents by 2026. Over 40% of those projects will be canceled by 2027 without adequate value and risk controls.


The Numbers Behind the Problem

Bots already account for nearly 50% of internet traffic. Bad bots — scrapers, credential stuffers, fraud agents — account for roughly 30%. The agent economy is being layered on top of this infrastructure without solving the bot problem first.

The fraud trajectory is not reassuring. Thales reports 59% of companies have already experienced deepfake-driven attacks. Experian found that 60% of companies saw increased fraud losses from 2024 to 2025, with agentic AI and deepfakes flagged as the primary driver. Feedzai puts AI-assisted fraud at over 50% of total fraud cases.

Now extend this to a world where agents hold virtual credit cards, execute trades, manage DeFi positions, vote in DAOs, and interact with other agents autonomously. The attack surface is not incrementally larger — it is categorically different.

One tweet circulating this week put it cleanly: "non-human identities now outnumber humans 96:1 in finance." That ratio is going to 1000:1 before the regulation catches up.


Who Is Building the Valves

The infrastructure gap can be described precisely: the pipes are built. The valves are not.

x402 solves "how does an agent pay?" Coinbase Agentic Wallets solve "what wallet does an agent use?" MoonPay OWS solves "where does agent state live?" Isara is solving "how do agents coordinate?" None of these — on their own — solve "which agent did this and were they authorized?"

A few teams are working specifically on the authorization and accountability layer:

ERC-8004 is an on-chain standard for registering AI agents with verifiable credentials. It gives agents a persistent identity that survives chain migrations, is not wallet-address-tied, and can be looked up by any protocol that wants to verify who it is interacting with. The standard has been deployed on 17+ chains.

knowyouragent.network launched three weeks ago with a focus on trust scoring, wallet tenure analysis, and soulbound identity for agent operators. Their framing: "As AI agents begin transacting onchain, managing wallets, and operating across protocols like ERC-8004, platforms need a way to verify who built an agent, how long its wallet address has existed, and whether its ownership history is clean."

Crossmint took a programmatic approach: virtual Visa/Mastercard cards for agents with hardcoded guardrails. Spending limits, merchant whitelisting, human-in-the-loop thresholds above certain amounts, and auditable logs. Their subscription revenue grew 1,100% year-over-year — suggesting strong product-market fit even before the accountability narrative fully landed.

IDChain launched in late March with ENS-native identity for AI agents across Base, Arbitrum, Optimism, and Ethereum mainnet — giving agents human-readable names tied to verifiable on-chain credentials.

Para published a detailed breakdown of the delegation chain problem: DeFi protocols that enforce KYC gates do a simple lookup on wallet addresses. There is no standard mechanism for checking that a wallet's authorized agent is acting within the original permission scope. The result is a cryptographic gap between user identity and agent authorization.


The OpenAI-Isara Bet as Signal

Return to the $650M valuation. What OpenAI is betting on is not just that multi-agent coordination is technically valuable. It is betting on a specific architectural assumption: that the future of AI is not one powerful model, but many smaller agents collaborating.

If that assumption is correct — and the evidence from Isara's gold-price forecast demo suggests it can work at scale — then the trust surface expands dramatically. A single model with a system prompt is relatively easy to audit. A swarm of thousands of agents, each taking partial actions that combine into a complex outcome, is not.

Isara recruited engineers from Google, Meta, and OpenAI. They are serious researchers. But their pitch decks almost certainly do not lead with "here is how regulators will verify which of our 10,000 agents made this bad trade." That problem belongs to whoever builds the accountability layer.

The signal from this investment is not just that multi-agent coordination is real. It is that the race to build it is happening faster than the governance layer can follow.


What Happens Without KYA

The worst-case scenario is not science fiction. It is a straight-line projection from where we are.

In a world with thousands of coordinated agents acting autonomously in financial markets — trading, managing DeFi positions, voting in DAOs, executing payroll, responding to invoices — attribution becomes the central unsolved problem. When an agent makes a bad trade that costs a fund $50M, who is liable? The operator? The deployer? The framework?

TRM Labs just shipped AI agents specifically for tracking illicit crypto activity — agents investigating agents. Their launch signals that regulators and compliance teams are already thinking about a world where the audit trail runs agent-to-agent. "Which agent did this and were they authorized?" will not be a philosophical question for long. It will be a legal requirement.

The industry has historically built the money-movement layer first and the accountability layer when forced. KYC was not a natural evolution — it was a regulatory mandate. The history of financial compliance suggests that KYA will follow the same path: adopted when required, not when optimal.

The window to build it proactively — to make it a design constraint rather than a retrofit — is right now, in the 18 months before agent swarms are processing enough real value that the first major incident forces the issue.


The Practical Checklist

If you are building agent infrastructure today, these are the accountability primitives that need answers before scale:

For agent operators:

  • Does your agent have a verifiable credential tied to its version? (Not just a wallet address)

  • Can any protocol you interact with look up who authorized this agent?

  • Do your spending limits and permission scopes live in a tamper-evident location?

  • Can you reconstruct the full action log if something goes wrong?

For protocol builders:

  • Are you checking agent credentials or just wallet addresses?

  • Does your integration distinguish between a human-controlled wallet and an agent-controlled wallet?

  • What is your liability exposure if an unauthorized agent exploits your protocol?

For investors:

  • Is the agent infrastructure you are funding solving coordination? Payments? Memory? Or accountability?

  • The $3-5 trillion McKinsey estimate for agentic commerce by 2030 assumes the trust problem gets solved. How much of that capital is flowing to the companies actually solving it?


What This Means for the Agent Economy

The agent payment stack assembled itself in early 2026 faster than anyone predicted. x402, Agentic Wallets, OWS, ERC-8004, Crossmint guardrails — these were built independently, by teams that did not coordinate, and they fit together almost by accident.

The KYA layer is assembling more slowly because accountability is harder to monetize than payments. You can charge a per-transaction fee on a payment rail. It is harder to build a business model around "you can prove which agent did this." The incentive structure is different.

But the Isara investment, the Trust Wallet Agent Kit, the Bybit AI Skills launch, and the 100+ projects now on the agent payments map collectively represent a convergence point. When enough value is flowing through these systems, accountability stops being optional.

The question is not whether KYA infrastructure gets built. It is whether it gets built before the first major attributed incident — or because of it.


Sources