MMAchain
News

Know Your Agent: The 4700% Traffic Surge, the 14% Trust Floor, and the Identity Layer Three Giants Are Racing to Own

CryptoBear

On September 10, 2026, three payment networks stood on the same stage in São Paulo and announced they would agree on something. That alone should make you suspicious.

Visa, Mastercard, and Ant International unveiled a joint interoperability framework they call Know Your Agent, or KYA. The pitch is clean. AI agents are about to transact on behalf of humans at scale, and nobody can verify who — or what — is actually pressing the button. KYA promises to fix that: one identity, registered once, recognized across three proprietary protocols, three clearing networks, and an unknown number of merchant endpoints.

Here is the anomaly I cannot stop staring at.

Visa's own disclosure, buried in the same week's briefing materials, reports that AI-driven retail traffic is up 4,700% year over year. Read that number again. Then read the one next to it: consumer trust in AI-initiated purchases stands at 14% unverified, and 42% of consumers refuse to trust an agent with any purchase above $25.

A metric that says the supply side has arrived. A metric that says the demand side has not. Both true. Both on the same ledger. That gap — the 4,700% against the 14% — is the entire story of KYA, and almost nobody on the stage in São Paulo wanted to name it.

I built my first wallet-cluster tracker in August 2020, isolating fourteen addresses that had quietly extracted $2.3 million from Uniswap V2 slippage miscalculations. The lesson from that summer was not about arbitrage. It was about divergence — when two numbers that should move together stop moving together, the market is lying to you somewhere. The 4,700% and the 14% are diverging. KYA is the industry's attempt to close that gap with cryptography.

Whether it can is a different question. This is a forensic walk through the framework, the three protocols underneath it, the registry problem no one wants to discuss, and the reason I think the most important number in this entire announcement is a $25 threshold that nobody explained.

The blockchain doesn't care about the press release. Let us audit the claim.


Context: What KYA Actually Is, and What It Is Not

The first thing to establish, because the coverage has been sloppy, is that KYA is not a product. It is a translation layer. It is not a company, not a token, not a chain. It is a standard — an interoperability agreement between three parties who each already operate a proprietary identity protocol and now want those protocols to recognize each other.

To understand the framework, you have to understand the three protocols it is stitching together.

Visa TAP — Trusted Agent Protocol. Visa's native agent-identity layer, already in deployment with 12 named partners, among them Adyen, Shopify, and Stripe. TAP is the incumbent's attempt to make sure that when an AI agent arrives at a merchant checkout, the merchant can verify the agent's provenance and authorization chain before the transaction hits the card rails.

Mastercard Verifiable Intent — built in collaboration with Google, and open-sourced. This is the more interesting one, and I will return to it. Verifiable Intent does not merely answer "which agent is this." It attempts to answer "what did the human actually authorize this agent to do." That is a semantic layer, not an identity layer. It is a bigger claim.

Ant AMP — Ant International's agent protocol, sitting on top of a wallet ecosystem that the company says represents $13 trillion in annual spending across emerging markets. Ant is the challenger here. It is the only party at the table that is not a Western card network.

Now the framework. KYA claims that an agent registered under any one of these three protocols becomes recognizable and trustworthy across all of them. Register once. Operate everywhere. Ant's CIO framed it exactly that way: eliminate redundant registration, reduce integration friction, let the agent move.

On paper this is elegant. In practice it is a very hard problem wearing a friendly name.

Here is why. Interoperability between three proprietary protocols is not, primarily, a cryptography problem. It is a governance problem. Visa TAP, Mastercard Verifiable Intent, and Ant AMP were each built to serve their owner's clearing network. They are not neutral rails. They are competitive assets dressed as public goods. Asking them to recognize each other's agent identities means asking each network to trust an identity minted by a competitor.

That trust has to be anchored somewhere. A translator layer needs a root. And the moment you ask where the root lives, the friendly interoperability story collapses into the only question that has ever mattered in identity systems: who holds the keys?

The announcement does not say. I checked the briefing twice. Fourteen references to "interoperability," zero references to the registry's custodian. That silence is not an oversight. It is the negotiation that has not finished yet.

And then there is São Paulo. Not New York. Not Beijing. São Paulo. A choice that looks like logistics and reads like strategy. Latin America, Southeast Asia, and Africa are where digital wallets already outrun card penetration, where traditional finance never fully locked in, and where a new standard faces the least incumbency resistance. Ant's wallet footprint in those markets is the reason it is at the table at all. It is also the reason its position is the most exposed.

Regulators were not present. No agency endorsed KYA. No sandbox, no blessing, no enforcement action. This is a pure industry self-regulatory play — the PCI DSS model, where private actors define the de facto standard first and let regulators catch up later. That is the strategy. It is not a neutral fact. It is a bet: define the rules before the rule-makers wake up.


Core: The Four Unresolved Technical Questions That Decide Everything

Strip the marketing away and KYA rests on four technical problems. None of them are solved. All of them are load-bearing.

Question One: The Registry Problem — Who Mints Agent Identity?

An agent needs a credential. Something cryptographic, verifiable, portable across three networks. The industry-standard candidates are W3C Verifiable Credentials and Decentralized Identifiers. Both are mature enough to use. But credentials need an issuer, and issuers need a root of trust — a registry that says "this agent exists, this agent's key is valid, this agent's human principal is known."

Who operates that registry?

If Visa operates it, Mastercard is trusting a competitor's database. If Mastercard operates it, the reverse. If it is a neutral consortium, then the consortium's governance, funding, and dispute rules become the single most important document in agentic commerce — and we have not seen it.

This is the hard part. Not the protocol translation. The protocol translation is engineering; it can be solved with infrastructure and time. The registry is power. Whoever maintains the registry of agent identities holds the issuance authority for the entire agent economy — functionally a root certificate authority for autonomous transacting software. That authority carries long-term rent and rule-making leverage. It is not a technical component. It is a throne.

And here is the operational consequence nobody has priced. A central agent registry becomes a single point of trust for commerce across three networks. Attack it, and you do not knock out one protocol. You knock out agent transactions everywhere they are accepted. The three parties are proposing to consolidate trust that is currently distributed across their independent networks into one new component with no disclosed governance and no disclosed disaster recovery. That is an efficiency-for-resilience trade — and the resilience side of the ledger is blank.

I have seen this pattern before. In 2022, I audited DEX liquidity depth after Terra collapsed. SushiSwap showed trading volume that did not match wallet behavior. When I clustered the addresses, roughly 60% of that volume traced to a single entity running a wash loop — $45 million in fake motion. The lesson: apparent network activity is not the same as distributed activity. Centralize the mechanism and you centralize the failure mode.

A unified agent registry is the single most concentrated trust point this industry will have built. The market is treating it as plumbing. It is infrastructure with a target painted on it.

Question Two: The Intent Problem — Proving What a Human Meant

Cryptography can prove which agent is transacting. It cannot prove that the human behind the agent actually authorized this specific transaction, at this price, with this counterparty, at this moment.

That gap is where Mastercard's Verifiable Intent enters, and it is why the Mastercard-Google collaboration matters more than the Visa partnerships people are counting. Identity answers "who." Intent answers "why." The second is harder and more valuable.

Consider the failure mode. A user instructs an agent: "buy me the cheapest flight to Bogotá next Tuesday." The agent, authorized and verified, executes. But did the user intend a $400 ticket or a $4,000 ticket? Did they intend refundable or non-refundable? Did they intend to include a checked bag? The identity layer says the agent is legitimate. The intent layer has to say the transaction is within the mandate the human granted.

Verifiable Intent tries to make "within the mandate" cryptographically checkable rather than trust-based. That is the semantic layer of risk control — and it is a deeper moat than identity, because it decides whether a transaction is authorized, not merely whether the agent is real.

Mastercard open-sourced it. Read that move carefully. Open-sourcing a standard is not generosity. It is a land grab executed in the language of public benefit. By open-sourcing Verifiable Intent, Mastercard invites the market to build on its grammar. If the industry adopts Verifiable Intent as the way to express authorization, Mastercard controls the language in which every agent transaction is written. That is the real prize. Not the fee. The syntax.

And note the shape of the competitive asymmetry. Visa's answer to the intent problem is behavioral: BioCatch, the $2.4 billion acquisition — behavioral biometrics, used to verify that the human on the other end moves like the human who owns the account. Mastercard's answer is semantic and collaborative: Verifiable Intent with Google. Two different bets. Visa is buying a sensor. Mastercard is writing a language. One of these scales better. I will tell you which, and it is not the one with the bigger price tag.

Question Three: The Behavioral Problem — BioCatch and the Cost of the Second Check

Let me be precise about what the BioCatch acquisition actually buys, because the coverage has been imprecise.

BioCatch produces behavioral biometrics — how you type, how you scroll, how you hold the device, how you hesitate. It is a signal used to catch account takeover, because an attacker on a valid credential often behaves unlike the legitimate owner. In the KYA context, this becomes Visa's fallback: when cryptographic identity is valid but something feels wrong, the behavioral layer provides a second check.

It is also, and I want to be very clear about this, sensitive personal data. Behavior doesn't biometries sit squarely inside the definition of sensitive personal information under both GDPR and China's PIPL. That means a higher consent bar, stricter retention limits, and a substantially larger breach consequence.

Now connect the dots the announcement does not. To make a behavioral layer work inside an agent identity chain, you need to bind a human's behavioral signature to an agent's authorization. You are using the human's body as the trust anchor for the agent's action. Every time the agent transacts, some derivative of human behavior is in the loop.

The privacy cost of that design is not marginal. It is structural. You have moved physiological data into the transaction path of a commercial payment. The GDPR exposure alone should have consumed the entire São Paulo press conference. It did not come up.

And there is a second-order problem. Behavioral biometrics are probabilistic. They produce a confidence score, not a binary truth. That means the agent identity chain now contains a probabilistic component whose false-positive rate — flagging a legitimate user as a threat — is a customer-experience liability and whose false-negative rate — missing a genuine attacker — is a security liability. You have imported a statistically noisy signal into a system that markets itself as cryptographic certainty. Those two things do not rhyme.

Question Four: The Legitimacy Problem — The $25 Threshold

Here is the number nobody explained, and the one I think is the most diagnostic data point in the entire framework.

42% of consumers say they will not trust an AI agent with a purchase above $25. Below that line, willingness rises sharply. The market has, without saying so, discovered a natural boundary in agentic commerce.

That boundary is not psychological. It is economic. $25 is roughly where the cost of disputing a transaction meets the value of the transaction. Below the line, the economics of a chargeback — the time, the friction, the operator cost — exceed the disputed amount. Merchants can absorb the loss; the system tolerates fraud because contesting it costs more than eating it. Above the line, disputes become worth pursuing, and the moment they are worth pursuing, someone has to decide who pays.

That is the real constraint. Not technology. Liability.

When an agent it transacts and something goes wrong, who is responsible? The human who deployed the agent? The agent's developer? The network that verified the agent's identity — Visa, Mastercard, or Ant? The merchant who accepted the transaction? The behavioral biometric layer that failed to flag it?

The KYA framework is an interoperability layer. Interoperability, by design, distributes execution across multiple parties. And distributed execution, when liability is undefined, produces distributed excuses. Right now, a hijacked agent that transacts across three networks has three candidate responsible parties — and the fastest outcome for all three is to point at each other.

That is not a hypothetical. That is the current design. And it explains the $25 threshold better than any survey can: the market has already solved the high-value liability problem by refusing to enter it.

KYA does not fix that. It may make it worse, because a framework built on three-party mutual recognition has no single arbiter to assign fault.

The Bot Filter: Who Is Actually Transacting

I run a bot filter on every market analysis. Let me run one here.

The 4,700% AI traffic growth is real, but it is not what the headline implies. The vast majority of that traffic is experimental. Bots exploring storefronts. Agents completing low-value test transactions. Automated catalog scans. Developer sandboxes. The percentage of that 4,700% that represents genuine consumer-authorized, fulfilled, settled agentic commerce at meaningful value is a small fraction of the headline.

I have seen this exact pattern before. In early 2026, as autonomous agents began transacting on-chain, I clustered 500-plus AI-driven wallets and found that roughly 80% of volume in the newer agent protocols was generated by autonomous software, not humans. The volatility looked like sentiment. It was algorithmic noise. Traders reading it as human conviction were reading a machine talking to itself.

The same filter applies here. The 4,700% is a supply-side number. Merchants and developers pulling agents into their funnels. It is not a demand-side number — not consumers pushing agents out into the world. Until the trust metric converges with the traffic metric, the traffic metric is not a signal of adoption. It is a signal of prototyping.

A 4,700% traffic surge against a 14% trust floor is not a growth story. It is a supply side talking to itself in a room the demand side has not entered.


The Registry Is the Whole Game

Let me push harder on this, because I keep landing here and I think it is correct.

Every identity system in history reduces to the question of issuance. Passports are valuable because a state mints them and other states recognize them. Certificates are valuable because a root authority signs them and browsers trust that root. The moment issuance is contested, the system fragments.

KYA defers the issuance question. Each protocol issues its own agent identities, and the framework translates between them. That works while the three parties agree. The trouble is that the agreement is about translation, not about issuance — and translation agreements decay the moment the parties diverge commercially.

Watch the commercial divergence. Visa and Mastercard compete on clearing. Ant competes on distribution. In the identity layer, they are cooperating. In the clearing layer, they are fighting. A framework that requires cooperation in one layer while the parties fight in another is structurally unstable. It holds while there is joint upside. It fractures the moment the upside is unevenly distributed — and the upside will be unevenly distributed, because the three parties do not contribute symmetrically.

Visa brings clearing network and TAP's 12 partners. Mastercard brings clearing network and Verifiable Intent's Google-backed grammar. Ant brings wallet distribution across $13 trillion in spending — but distribution is the layer that gets commoditized first. Distribution is what you have when you have not yet built a moat. In a protocol war, the party with distribution but without protocol ownership is the party that gets absorbed.

That is Ant's position. It has the strongest reach and the weakest standard. It can move agents to merchants faster than either card network — but it does not control the identity grammar or the intent grammar. It is translating other people's languages.

There is a cleaner way to say it. Ant's capital is distribution. Visa's and Mastercard's capital is the standard. When the standard is what gets charged for, distribution becomes the thing that gets rented. If Ant settles for being the protocol translator, it becomes a permanent access point on the card rails — a valuable node, but a subordinate one. It loses the identity-layer voice it needs to matter in 2030.


The Contrarian Angle: Correlation Is Not Causation, and the Announcement Is Not the Cause

The market will read this announcement as bullish for agentic commerce infrastructure. Let me separate the correlation from the causation, because the reflex is wrong.

KYA did not cause the 4,700% traffic. KYA did not cause the $3–5 trillion 2030 forecast that everyone is quoting. KYA did not cause agents to show up. Those things were already happening. The three parties are reacting to a trend, not creating one. What they are creating is a claim over that trend's identity infrastructure.

The distinction matters because it changes what you should expect. If KYA were the cause, its success would be a leading indicator. Because KYA is a reaction, its failure is entirely survivable — the agent economy will keep growing with or without this particular framework. The framework is a bet on capturing the standard, not a bet on the growth. Growth is the tide. KYA is a raft trying to own the harbor.

Here is the second contrarian point, and the one I think is most underrated.

The greatest competitive threat to KYA is not Visa versus Mastercard versus Ant. It is the platforms that own the agent itself. If OpenAI, Google, or Apple builds identity and payment directly into the agent runtime, the agent never reaches out to a card network's identity layer at all. The KYA framework becomes a backend lookup the platform chooses whether to call. The card networks would be reduced to clearing — a commodity layer beneath a platform-owned experience.

That is why Visa and Mastercard pulled Google into the tent. Co-building Verifiable Intent with Google is a defensive move that converts a potential disintermediator into a partner. But partners become acquirers. The history of platforms absorbing partners is long enough that I will not cite examples. The strategic risk is embedded in the strategy.

Standardization isn't neutrality. When three giants agree on a standard, they are not agreeing because the standard is correct. They are agreeing because agreement blocks the field. The question a good detective asks is not "what does the standard do." It is "who does the standard exclude."

The answer here is: regional wallets, independent identity providers, and any agent platform large enough to build its own. KYA's interoperability is interoperability among the three. It is not open. The network effect it is chasing may arrive as an exclusionary barrier rather than a public good. That is not a flaw in the plan. It is the plan.

And the regulators? They were absent by design. The framework offers traceability and continuous transaction monitoring — capabilities regulators generally want. Building the regulated capability before building the regulation is a RegTech play: become the compliance standard so the compliance standard becomes you. It is a long game, and it is smart. It also means the framework's biggest single risk is that a regulator eventually decides agent identity is quasi-public infrastructure and forces it open. When that happens, the registry question — deferred today — becomes a forced-marriage negotiation tomorrow.


The Three Fault Lines to Watch

Let me compress this into the three lines that actually matter, and then give you the forward signal.

Fault line one: the registry custodian. Watch for any disclosure of who operates the unified agent identity registry, or any sign that the three parties are federating rather than unifying. A federation of registries preserves Ant's leverage. A single registry owned by Visa or Mastercard ends it. This is the single most important structural disclosure to wait for. It will not be announced loudly. It will appear in a technical specification or a governance appendix, if it appears at all.

Fault line two: the intent standard. Watch whether Verifiable Intent wins the grammar war or whether the industry splits between Mastercard's semantic approach and Visa's behavioral approach. If two incompatible intent standards emerge, KYA's interoperability claim weakens, because the parties will agree on identity and disagree on authorization — which is the worst possible split, because authorization is where liability lives.

Fault line three: the liability rule. Watch for any framework document that names the responsible party for a hijacked agent. Until that exists, high-value agentic commerce cannot scale, because no merchant will accept above the $25 line without knowing who eats the loss. The $25 threshold is a symptom. The cure is a liability rule, and there is no cure on the horizon.

Now the cross-border dimension, because it is Ant's specific burden and the framework's hidden fuse.

An agent identity registry that shares identity and transaction data across Visa, Mastercard, and Ant is, by definition, a cross-border data flow. Mastercard and Visa are U.S.-anchored. Ant operates with China-linked infrastructure. The moment the registry is asked to share agent identities and transaction histories across these three, you collide with two regulatory regimes at once: China's data-export security assessment regime and U.S. sanctions and export-control screening. There is no pre-built safe path through that intersection.

This is Ant's structural cost of membership. It gains the compliance passport into Western networks — and it takes on the risk of being caught between two data-sovereignty regimes. Watch the first time a sanctions-screening question is asked of the registry. The answer will tell you whether KYA is a genuine cross-border standard or a Western standard with a challenger's name on the cover page.


Takeaway: What to Watch Next Week

Mark the date. September 10, 2026 is the baseline, and everything after it is a deviation to be measured against it.

Next week's signals, in priority order:

First, the technical specification. If KYA publishes a specification that names a registry custodian, the framework is real and moving. If it publishes a specification that describes translation between three registries and never names a custodian, the negotiation is still open and the framework is a press release with a roadmap attached.

Second, the first BioCatch deployment inside a KYA transaction path. The moment behavioral biometrics appear in a live agent authorization, the privacy clock starts. Watch for the first data-protection inquiry. None of the three parties want that light.

Third, the first high-value agent transaction that breaks the $25 line and settles cleanly across two networks. That is the real milestone — not the traffic number, not the trust survey. One settled seven-figure agent purchase across two networks with no dispute will do more for the thesis than ten thousand press releases.

Fourth, the first regulator. Watch which jurisdiction moves first to claim jurisdiction over agent identity. São Paulo suggests Latin America is the laboratory, but the first regulator to intervene will probably not be Latin American. It will be whichever large market realizes that agent identity is becoming infrastructure and decides infrastructure cannot be privately minted.

The framework's golden hour is now — the window before regulation, before scale, before the platforms arrive in force. Whether the three parties hold it, or whether it slips to the platform layer and to the regulators, is the real contest. Not the protocols. The throne.

KYA built an interoperability layer and called it a standard. It has not yet told us who holds the keys. Until it does, treat the 4,700% traffic figure as a supply-side heart rate and the 14% trust figure as the truth serum. One number is the market talking to itself. The other is the market telling you what it will actually do.

Trust the code, verify the transaction. And this time, verify the registry — because the registry is where the money, the liability, and the leverage all live. Find the custodian before the custodian finds you. That is the analysis the press conference skipped, and it is the only one that will still matter in 2030.

Final note for the standard-setters among you: a framework that cannot name who is responsible for a hijacked agent is not a framework. It is an aspiration with a logo. The next twelve months will tell us which one KYA is.

Market Prices

BTC Bitcoin
$76,648.6 +0.62%
ETH Ethereum
$2,454.67 +1.80%
SOL Solana
$101.16 +2.65%
BNB BNB Chain
$735.3 +2.07%
XRP XRP Ledger
$1.3 -0.51%
DOGE Dogecoin
$0.0819 +1.58%
ADA Cardano
$0.2027 +3.84%
AVAX Avalanche
$7.62 +3.48%
DOT Polkadot
$1.08 +7.36%
LINK Chainlink
$11.36 +3.48%

Fear & Greed

50

Neutral

Market Sentiment

Event Calendar

{{年份}}
12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$76,648.6
1
Ethereum ETH
$2,454.67
1
Solana SOL
$101.16
1
BNB Chain BNB
$735.3
1
XRP Ledger XRP
$1.3
1
Dogecoin DOGE
$0.0819
1
Cardano ADA
$0.2027
1
Avalanche AVAX
$7.62
1
Polkadot DOT
$1.08
1
Chainlink LINK
$11.36

🐋 Whale Tracker

🔴
0x9be0...17f9
30m ago
Out
33,747 SOL
🔵
0xd6b1...bf72
30m ago
Stake
967.03 BTC
🔴
0x5876...5f62
1h ago
Out
451,027 USDC

💡 Smart Money

0x9d08...f35c
Market Maker
+$3.5M
74%
0xdc36...b816
Early Investor
+$2.5M
69%
0x31fc...6c34
Market Maker
+$0.5M
67%

Tools

All →