Visa and Mastercard do not co-author standards for recreation. When two companies that spend the rest of the calendar trying to cannibalize each other's interchange revenue sit at the same table and publish a joint framework, the correct inference is not cooperation. It is fear. The framework is called KYA — Know Your Agent — and it arrived flanked by three co-signatories, four supporting research papers, and a $2.4 billion acquisition sitting underneath it: Visa's purchase of BioCatch. That is a lot of capital aimed at a problem most of this industry still waves off as "the future of AI agents."
Here is the anomaly. I read the source digest three times, waiting for the usual blockchain garnish. It never came. A framework about autonomous agents transacting on shared rails — published by a Web3 information feed — contains zero references to on-chain identity, decentralized identifiers, verifiable credentials, or smart contract wallets. The absence is the signal. Auditing the invisible supply chain means reading what a document refuses to say as carefully as what it prints. Trying to trace the hash that broke the ledger here means tracing a hash that was never written down.
KYA is not difficult to describe once you strip the marketing. It reduces to three pillars: cross-network traceability, shared authentication, and continuous transaction monitoring. Every one is a known primitive. KYC and KYB taught the industry how to verify an entity at onboarding; KYA just moves the subject from a human or a business to an agent. No new computational paradigm ships with it.
The more interesting admission is buried in the framing. The discussion has, in the authors' own words, shifted "from 'who is this agent' to 'whether this agent's behavior falls inside my mandate.'" Read that slowly, because it is the whole game. That sentence is describing the separation of authentication from authorization — a classic security-first layering decision. KYA covers the first half. It does not cover the second.
The surrounding commercial context makes the urgency legible. Payment networks have watched agent-native commerce move from thought experiment to funded roadmap in under two years. An estimate circulating in the material puts agent commerce anywhere between three and five trillion dollars — a figure I will return to, because it has no source, no timeframe, and no unit of account. Visa's $2.4 billion purchase of BioCatch, a behavioral-biometrics vendor, is the tell that the networks believe the shift is real. BioCatch is not a revenue asset. It is an insurance policy written against the possibility that agents route around the rails entirely.
So the picture is clear enough: a standards coalition, a biometrics acquisition, and a marketing number. What is missing is the part that actually matters — the mechanics of authorization. That gap is where the rest of this analysis lives.
KYA is a composite, and composites inherit the failure modes of their parts. Cross-network traceability and shared authentication are standard identity-infrastructure components. Continuous transaction monitoring is transaction risk control. Bolt three mature parts together and you get a framework — not a breakthrough. The evidence standard matters here: three parties published a framework, which places it at the standards-and-proof-of-concept stage. No production-scale validation. No service-level agreements. No adoption telemetry. That is not a knock; it is simply where the technology sits, and pricing it as though it were live is sifting noise to find the alpha signal in a file that contains none.
The deeper problem is the mandate. To authorize an agent, you must express, in machine-readable form, what a human delegated: which merchants, which amount ceilings, which time windows, which conditional triggers. That expression must be verifiable by any counterparty and revocable by the principal. KYA does not solve this. It confirms the agent is who it claims to be; it does not read what the agent was told it may do. Authentication without authorization is a locked door with no key policy — it tells you someone is standing there, not whether they belong.
Now watch BioCatch. Behavioral biometrics assume a human generating continuous physical signals — typing cadence, cursor velocity, micro-tremor. When the operator is a process, an AI agent, the subject of those signals changes at an ontological level. Whose behavior is being measured? The agent's? The delegating human's? The model provider's? The source material never touches this. It is not a footnote; it is the load-bearing wall. Behavioral biometrics migrated from human to agent is a semantic mismatch dressed up as a security feature.
Here is the irony that should bother anyone with an engineering background. The mandate problem was partially solved on-chain years ago. Account abstraction and session keys let a smart contract wallet grant an agent scoped, expiring, revocable permissions — amount caps, allow-listed contracts, time bounds — expressed in code and enforced at execution. Decentralized identifiers and verifiable credentials provide portable, cryptographically signed attestations of who is acting. This is precisely the fine-grained, conditional, machine-readable authorization the mandate requires. So why is the card cartel building a permissioned registry instead of leaning on the open primitives that already exist?
Because the permissioned registry is the moat. On-chain identity is permissionless and composable — anyone can issue, anyone can verify, no toll booth. A closed agent-identity registry, by contrast, makes the standard-setter the gatekeeper. Whoever operates the registry sets admission. Whoever sets admission sets fees. That is the point. The absence of blockchain vocabulary in the source is not an oversight; it is a business decision. A standard that routes around the toll booth cannot itself be a toll booth.
The registry question also exposes the coalition's weakest link. Cross-network interoperability requires a shared agent-identity namespace and resolver — a single place where agents are registered and looked up. Someone must run it; someone must govern it. When three entities "jointly publish" a framework, the honest reading is that governance is not yet settled. That unresolved question — who owns the namespace — determines the entire power topology. Until it is answered, KYA is a press release with a schema attached.
Then there is the latency requirement. Continuous transaction monitoring at agent speed demands millisecond-scale inference. The practical consequence is structural: a payment network that operates this stops being a clearing house and becomes, de facto, a real-time AI risk platform. That is a profound identity shift for an institution whose regulatory charter was written for settlement, not surveillance.

And the commercial truth is uncomfortable. KYA is not a product you sell. It is a defensive standard. The network's existential risk is not "we fail to earn on agent commerce." It is "agent commerce removes us from the flow." If an agent transacts directly with a merchant's agent, or settles out of an agent wallet, interchange never clears. KYA plus BioCatch is a double hedge against that. Note the admission buried in the framing: identity infrastructure is "a precondition, not a solution." Translated, KYA generates no near-term revenue. It is a cost line. Networks do not fund cost lines against zero return unless the downside is existential.
Follow the money and the monetization path becomes obvious. KYA will almost certainly be free, because open standards only get adopted when they are. The revenue sits in the value-added layer above it: premium behavioral verification, dispute resolution, warranties, agent credit scoring. That is the EMV and 3-D Secure playbook. Build the track, then charge for the freight.
I have seen the demand side from the inside. In 2026 I traced a dataset of 10,000 autonomous trading bots interacting with decentralized exchanges and found coordination patterns that conventional surveillance missed entirely. The lesson transfers directly. The actors generating market data are evolving faster than the instruments watching them. A framework that authenticates agents but cannot read their mandates will authenticate collusion just as cheerfully as it authenticates commerce.
In 2024 I built an automated bot that captured a persistent 1.5% premium window between GBTC and IBIT, adding roughly 4% annualized for our fund while legal and compliance fought over the edges. The lesson there was simpler: the moment a structural inefficiency becomes legible, capital closes it. The same will happen to the trust layer. Whoever stands the agent-identity verification stack up first — cartel or protocol — owns a window that closes fast. The arbitrage window closes fast.
Now the part that should make you suspicious of everything above.
The entire demand case rests on stated preference — survey answers about hypothetical scenarios — not revealed preference. Firms and consumers say they want verifiable agent identity. What they actually do when the experience is smooth, the amounts are small, and refunds exist is another matter entirely. Revealed preference almost always tolerates more risk than stated preference claims. This is the material's biggest methodological soft spot, and it biases the near-term adoption forecast upward in the surveys and downward in reality. Concern about agent fraud and willingness to pay for a trust layer are correlated, not causal, and the correlation is doing a lot of unearned work.
There is a second blind spot the analysis ignores: small merchants. A trust layer adds marginal cost to every agent transaction. Large merchants absorb it; SMBs cannot. The likely outcome is not broader commerce but faster head-of-market concentration — the same dynamic that compressed online payments into a three-company game. The beneficiaries the source never names are the trust intermediaries, a credit-rating agency for agents, a genuine zero-to-one window that the document leaves on the table.
And the deepest contrarian point: the framework can be correct and irrelevant at once. If agent commerce matures on open protocols that never touch the card rails, KYA secures a door in a building the traffic has already left.
So what is the signal to watch next week? Not the press releases. Watch three concrete things. First, the mandate specification: whether anyone publishes a machine-readable, revocable authorization schema — and whether it is open. Second, the registry: who operates the shared agent-identity namespace, and under whose governance. Third, the rival protocols: if agent-native standards absorb KYA rather than compete with it, the networks won the standard war; if they route around it, the $2.4 billion buys a very expensive seat in an empty room. The blockchain already wrote the answer. The question is whether anyone in the cartel is willing to read it.