Visa and Mastercard’s 'Know Your Agent' Play: A Defensive Standard That Crypto Should Watch Closely

SatoshiSignal Investment Research

In September 2026, two of the world’s largest payment networks—Visa and Mastercard—did something they rarely do together: they jointly released a new identity framework. Dubbed ‘Know Your Agent’ (KYA), the standard is designed to verify and monitor AI agents before they execute financial transactions. At the same time, Visa completed its ~$2.4 billion acquisition of BioCatch, a behavioral biometrics firm. The timing is not coincidental.

For those of us who have spent years inside crypto’s identity debates—watching decentralized identifiers (DIDs), verifiable credentials (VCs), and self-sovereign identity (SSI) struggle for mainstream adoption—this move is both familiar and unsettling. Familiar, because the problem KYA tries to solve (who is this agent, and what is it allowed to do?) is exactly the problem that blockchain-based identity projects have been tackling since the ICO era. Unsettling, because Visa and Mastercard are not building this for crypto. They are building it to protect their own payment rails from being disintermediated by AI-native commerce protocols.

Let’s peel apart the layers, because the real story isn’t about a new standard—it’s about a structural war for the trust layer of an agent-driven economy.

## The Hook: A Joint Standard That Speaks Volumes When direct competitors co-author a technical framework, it’s rarely a sign of collaboration—it’s a sign of shared fear. Visa and Mastercard have spent decades fighting over every basis point of interchange fees. The fact that they jointly proposed KYA suggests they see a common external threat large enough to override their rivalry. That threat is the rise of autonomous AI agents that can negotiate, transact, and settle payments directly with merchants, bypassing the traditional four-party model.

In my experience auditing early DeFi protocols during the 2020 summer, I saw the same pattern: when a new technology enables direct value transfer without intermediaries, the incumbents first ignore it, then ridicule it, then rush to co-opt it. The ICO whitepapers I reviewed back in 2017 often promised ‘disintermediation,’ but few delivered. Now, AI agents might actually do it—and the payment networks are not waiting for the hype cycle.

## Context: The Identity Gap for AI Agents Current payment infrastructure is built for humans. KYC (Know Your Customer) relies on government-issued IDs, biometrics, and manual reviews. But an AI agent has no face, no fingerprints, no consistent typing pattern. It can be cloned, forked, or hijacked through a prompt injection. The core question—‘How do I know this agent is acting within my authorization?’—remains unanswered in both traditional finance and crypto.

Crypto projects like Ceramic, Idena, and even some Layer-2 identity rollups have attempted to create on-chain agent identities. But none have reached the scale or trust of a Visa-backed standard. KYA’s three pillars—cross-network traceability, shared authentication, and continuous transaction monitoring—are not new individually. As I’ve written before, “Noise filtered. Signal preserved.” But their combination into a single framework for AI agents is novel. The catch? KYA only covers authentication, not authorization. It tells you who the agent claims to be, but not what it is allowed to do.

## Core: KYA as a Defensive Moat, Not a Product Here’s the uncomfortable truth for crypto maximalists: KYA is not interesting because of its technology. It’s interesting because of its economics. The standard is likely to be offered for free—an open base layer that every payment network can adopt. The real monetization will happen at the trust layer above: advanced behavior verification, dispute resolution, agent credit scoring, and guarantees.

This is a classic ‘razor-and-blades’ strategy, but applied to infrastructure. Visa and Mastercard are not trying to sell KYA. They are trying to ensure that when an AI agent initiates a transaction, the payment flows through their rails—and pays interchange fees—rather than settling directly via a stablecoin or a peer-to-peer protocol. “Trust is the only currency that matters.” And Visa is minting its own.

The acquisition of BioCatch fits perfectly. BioCatch’s behavioral biometrics work by analyzing human patterns: keystroke dynamics, mouse movements, device handling. But when the “user” is an AI agent running on a server, those signals evaporate. So why pay $2.4 billion? Because for the next 3–5 years, most AI transactions will be hybrid: a human authorizes, an agent executes, and the human reviews. In that window, BioCatch can still verify the human behind the agent. It’s a hedge against the transition period.

From my work examining the psychological drivers of the Bored Ape Yacht Club phenomenon in 2021, I learned that narrative often precedes technology. The narrative here is that legacy finance is adopting a defensive posture. But in crypto, we’ve already seen what happens when centralized identity layers become honeypots: they get hacked, exploited, or captured by regulators. The cross-chain bridge attacks that drained over $2.5 billion were often failures of identity and authorization—the protocols trusted the wrong data. KYA, if centrally governed, could suffer the same fate.

## Contrarian: The Blind Spot – Governance and the ‘Who Watches the Watchers’ Problem Every identity system needs a root of trust. For KYA, that root is likely a consortium of payment networks, acquirers, and maybe regulators. But who governs the shared agent identity registry? Who decides when an agent’s credentials are revoked? What happens when a prompt injection attack corrupts an agent mid-transaction? The KYA announcement mentioned “joint development” but was silent on governance.

In my experience covering the 2022 bear market, I saw how quickly centralized trust structures can crack under pressure. When FTX collapsed, the identity and authorization layers (exchange accounts, API keys) became worthless overnight. KYA faces a similar fragility: if the consortium disagrees, the standard splits. If a rogue agent floods the registry with fake identities, the entire trust model degrades.

Crypto’s alternative—decentralized identity with on-chain attestation and self-sovereign control—offers no single point of failure, but it also offers no clear enforcement mechanism. The contrarian thesis is this: KYA’s success might actually accelerate adoption of blockchain-based identity for AI agents. Why? Because once merchants and agents get used to the idea of a verifiable identity layer, they will crave the portability and composability that only blockchains can provide. The payment networks’ walled garden could become a stepping stone to a truly open standard.

## Takeaway: The Next Narrative Battle The immediate future is not about whether AI agents will transact—they already do, in small ways. The question is which trust layer they will rely on. Visa and Mastercard have fired the first shot with KYA, but they are fighting on ground they control: the traditional payment rail. Crypto projects—especially those focusing on decentralized identity, authorization protocols (like OAuth 2.1 on-chain), and agent-specific smart contracts—have a narrow window to offer a superior alternative.

But the window is narrow. If KYA gathers enough adoption in the hybrid human-agent period, it will become the default. And defaults are sticky. “Truth over hype. Always.” The truth is that both centralized and decentralized solutions have flaws. The one that wins will be the one that solves the authorization puzzle—not just authentication—while maintaining usability and security at scale.

For now, I’ll be watching the governance of the KYA consortium. That’s where the real power lies. And as I’ve said for years in my market briefs: the most important code is the rules that decide who can change the rules.

Noise filtered. Signal preserved.