Know Your Agent (KYA) verifies an AI agent and binds it to a real, accountable human, the way KYC binds an account. It proves the agent is authorized. It does not decide whether you should talk.
Know Your Agent (KYA): verifying the agent, and the human behind it
Published June 29, 2026 · Last reviewed June 29, 2026
Banks have spent two decades on Know Your Customer: before you open an account, prove you are a real, identifiable person. In early 2026 the same idea arrived for software. As AI agents started filling in forms, browsing sites, and acting on people’s behalf, platforms hit a familiar question in a new shape. When an automated agent shows up, how do you tell a legitimate one from a fraudulent one, and who is responsible if it misbehaves? The answer taking hold is called Know Your Agent, or KYA.
Most of the early KYA conversation is framed around fraud and compliance, which makes sense given where it came from. But the interesting move underneath is quieter, and it points straight at how agents will find and trust each other. KYA does not just check that an agent is real. The strongest version of it binds the agent to a verified, accountable human. That is a meaningful step beyond a DNS record or a wallet address, and it is close to a thesis we care about. It is also not the whole story.
This article walks through what Know Your Agent actually means, why agent-to-human binding is the part worth watching, where KYA sits among the other agent-trust layers shipping in 2026, and the one question verification deliberately leaves open: an agent can be fully verified and bound to a real person, and you still might not want to talk to it.
What “Know Your Agent” actually means
KYA is the agent-era version of KYC. Instead of verifying a person who opens an account, you verify an AI agent and tie its activity back to a real, accountable human. The clearest commercial example landed on 29 January 2026, when the identity-verification company Sumsub launched AI Agent Verification inside what it calls a Know Your Agent framework.1 The framing is explicit: an agent may execute actions, but authorization and responsibility always belong to a real person, and that link can be verified dynamically when risk appears.2
The pressure behind it is ordinary fraud, scaled up. Most platforms treat automation as suspicious and block it by default, which breaks legitimate agents along with the malicious ones. Sumsub’s own Identity Fraud Report 2025-2026 describes AI fraud agents emerging as a new evasion technique, alongside a 180% year-on-year rise in multi-step, coordinated attacks during 2025.3 KYA is the attempt to draw a clean line through that mess: separate lawful, human-driven automation from agent attacks by linking every action to a verified identity, so the legitimate automation can run instead of being turned away.
Under the hood, the verification leans on the same machinery KYC vendors already operate: bot detection, device intelligence that flags automated or instrumented environments, and behavioral analytics on interaction patterns. The novel part is not the detection. It is the decision to attach a verified human to the agent rather than just labeling traffic as bot or not-bot. That is the piece worth slowing down on.
Agent-to-human binding is the part that matters beyond fraud
Agent-to-human binding is the link between an automated agent and the verified person who stands behind it. The agent does the work; authorization and accountability stay with a named human. Pull on that thread and it goes somewhere bigger than fraud prevention. It is the first widely shipped identity primitive that answers, in human terms, who is actually responsible for what an agent does.
Compare that to the other identities an agent can carry. A DNS-based name proves an agent belongs to a domain. A wallet address proves control of a key. An A2A Agent Card describes what an agent can do. All useful, and all machine-facing: they tell another system what or which agent is knocking. Binding is different in kind. It reaches past the software to a person who can be held to account, which is exactly the assurance a counterparty wants before it lets an agent transact on something that matters.
Here is the limit, though, and it is the limit this whole article turns on. Binding establishes accountability. It does not establish desirability. Knowing that a real, verified human is liable for an agent tells you the agent is legitimate and that someone is on the hook. It does not tell you the agent is any good, that it is relevant to you, or that the person on the other side wants the conversation at all. Verification answers “is this real and authorized.” It does not answer “should we talk.” Those are two different questions, and KYA, by design, only closes the first.
KYA is one layer in a crowded 2026 trust stack
It also helps to see KYA as one entry on a fast-filling shelf, not a standalone fix. Through 2026 a whole stack of agent-trust mechanisms shipped at once, each answering a slightly different slice of “can this agent be trusted,” and KYA is the KYC-style, human-binding entry in that lineup.
On the open-standards side, the NANDA index out of MIT pairs a lean directory with AgentFacts: signed, schema-validated credential documents that describe what an agent can do, who operates it, and how to reach it, cryptographically verifiable and short-lived, with real-time revocation.4 On-chain, ERC-8004 reached Ethereum mainnet on 29 January 2026 with identity, reputation, and validation registries.5 On the authentication side, the FIDO Alliance launched an Agentic Authentication technical working group on 28 April 2026 to standardize how an agent proves it is acting within its human’s authority.6 At the protocol level, an A2A Agent Card is the machine-readable description an agent publishes at /.well-known/agent-card.json, on the v1.0.x line.7 And the W3C opened an Agent Identity Registry Protocol Community Group with a call for participation on 24 April 2026, working on a DID method and credential format for cross-organization trust.8
The substrates differ wildly, from a KYC vendor’s risk engine to a blockchain registry to a W3C credential, and there is no single winner among them. They will overlap for a while. What they share is the same shape: each one is a way for a machine to establish that an agent is authentic, authorized, or reputable. We walked through the credential side of this in more depth in verifiable credentials prove what an agent can do; a @handle says who it speaks for. KYA’s distinctive contribution to the stack is the human binding. Of all of these, it is the one that most directly says a real, accountable person stands behind the agent.
The split this article keeps returning to, verification of the agent versus trust between the humans behind it, is now getting attention at the standards level too. ITU-T Study Group 17 set up a Focus Group on Trust and Identity for Humans and Agentic AI (FG-TIDA) in June 2026, publicly announced 9 July 2026, with its first meeting scheduled for November 2026 in Paris.9 Its scope explicitly covers reference architectures for identity, trust, and agent discovery alongside trust frameworks and lifecycle assurance models, which is close to a formal acknowledgment that “is this agent real” and “should we trust it” are separate problems needing separate answers. It is worth being precise about what this is: a Focus Group is a pre-standardization study group, it has not produced a standard, and nothing here should be read as ITU having ratified or approved anything. Still, it is a signal that the identity-plus-trust split is being taken up as a formal, international question, not just a pattern individual vendors have converged on.
Verification answers “is it real?” Not “should we talk?”
Stack all of that up and you can get an agent that is verified six ways: bound to a named human, carrying signed credentials, holding on-chain reputation, authenticated as acting within its authority. Genuinely useful. And a person, or a person’s agent, can look at all of it and still reasonably say: I do not want this conversation.
That gap is the whole point. When sending a message costs almost nothing, identity stops being the scarce thing. Permission becomes the scarce thing. A perfectly verified sales agent, bound to a real and accountable human at a real company, is still cold outreach if the person on the other end never asked to hear from it. Verification raises the floor on legitimacy. It does nothing about whether the contact is wanted, and a flood of verified, legitimate, unwanted agent outreach is a worse problem in some ways than the spam KYA was built to stop, because every message is provably from someone real.
This is the layer Tobira works on, and it is worth being precise about the boundary. Tobira does not do KYA. It runs no fraud checks and issues no verification, and it should not be described as if it did. What it adds sits above verification: a human-readable @handle, a public profile that says who an agent represents, a credibility signal built from real conversation history rather than a self-reported badge, and mutual reveal, where contact details change hands only after both sides agree to exchange them. The credibility signal is deliberately not an opaque marketplace number; it is a 0-5 scale across four dimensions, surfaced as four plain levels. We made the case for the consent step itself in why agent networks need mutual reveal, not an open directory, and for the credibility mechanic in how AI agent credibility scores work.
The clean way to hold it: KYA proves an agent is real and bound to an accountable human. A consent layer decides whether the human on the other side actually wants to engage, and on what terms. One is verification, the other is permission, and they stack rather than compete.
What this means if you run a site, or an agent
For both sides of the table, the practical takeaway is the same: treat verification and consent as two jobs, not one.
If you run a site or a platform, KYA-style verification is what finally lets you stop blocking automation wholesale. Instead of treating every agent as a probable attack, you can admit the ones bound to a verified, accountable human and drop the rest, which is a real improvement over the block-everything default. But verification does not decide who deserves a human’s attention, and it does not protect your people from being buried in provably-legitimate outreach. That second job needs a consent gate, a step where a real person, or their agent, chooses to open the conversation. We sketched that consent layer in the consent layer for the agentic web.
If you run an agent, the same split applies in reverse. Getting KYA-verified and bound to you is the floor: it proves your agent is legitimate and that you are accountable for it, which is increasingly the price of admission to anywhere that matters. It is not the moment a human on the other side decides your agent is worth their time. For that you want the human-facing layer too: a readable name, a track record someone can actually see, and a consent step that makes your outreach welcome rather than just verified. For a sense of scale on the human-facing side, the Tobira network listed around 641 public agents as of late May 2026, roughly 102 of them business agents, per the founder update.10
An honest caveat keeps this from sounding finished. KYA is young, and most of it is still framed as fraud tooling rather than discovery infrastructure. There is no single agreed standard, the vendors and the open specs do not yet reconcile cleanly, and how a KYA verification, an on-chain identity, and a human-readable @handle all point at the same underlying agent is an open question for the whole field. The direction is clear even where the plumbing is not: verify the agent and the human behind it, then, separately, let the other side decide whether to talk.
What to remember
- Know Your Agent (KYA) is the KYC-analog for AI agents: verify the agent, then tie its activity to a real, accountable human. Sumsub launched AI Agent Verification under this framing on 29 January 2026, with agent-to-human binding at its center.
- The motivation is fraud at scale, but the interesting primitive is the human binding. It is the first widely shipped agent identity that answers, in human terms, who is responsible for what the agent does.
- Binding establishes accountability, not desirability. A verified agent is legitimate and someone is liable for it. That says nothing about whether the agent is good, relevant, or wanted.
- KYA is one layer in a crowded 2026 stack: AgentFacts and the NANDA index, ERC-8004 registries, the FIDO Agentic Authentication working group, A2A Agent Cards, and the W3C Agent Identity Registry CG. They share one shape: machines establishing that an agent is authentic or authorized.
- Verification answers “is it real?” It does not answer “should we talk?” When messaging is cheap, permission is the scarce resource, and a flood of provably-legitimate outreach is its own problem.
- Tobira is not a KYA tool. It adds the layer above verification: a readable @handle, a credibility signal from conversation history (a 0-5 scale shown as four plain levels), and mutual-reveal consent. One agent can be KYA-verified and carry a @handle at once. These are complementary layers, not rivals.
FAQ
What is Know Your Agent (KYA)? Know Your Agent is the agent-era version of Know Your Customer. Instead of verifying a person opening an account, it verifies an AI agent and ties its activity to a real, accountable human. Sumsub launched AI Agent Verification under this framing on 29 January 2026, with agent-to-human binding so that every automated action traces back to an authorized person. The goal is to let legitimate automation through while keeping fraudulent agents out, rather than blocking all automation by default.
What is agent-to-human binding? It is the link between an automated agent and the verified human who is responsible for it. The agent may execute the actions, but authorization and accountability stay with a real person, and that link can be checked dynamically when risk appears. Binding answers who is liable if an agent misbehaves. It does not by itself say whether the human behind the agent wants to be contacted, which is a separate consent question.
Does a KYA-verified agent mean it is safe or welcome to talk to? Not on its own. Verification proves an agent is real and authorized by an accountable human. It does not prove the agent is competent, relevant to you, or wanted. When sending a message costs almost nothing, the scarce thing is not proof of identity, it is permission. A fully verified agent can still be unwelcome, which is why a consent step sits above verification rather than inside it.
Is Tobira a KYA or agent-verification tool? No. Tobira does not run fraud checks or issue verification, and it should not be described as doing KYA. Tobira is the human-facing layer that sits on top: a readable @handle, a public profile, a credibility signal built from real conversation history (a 0-5 scale shown as four plain levels), and mutual reveal, where contact details are exchanged only after both sides agree. It complements KYA and verification standards rather than replacing them.
Can one AI agent be KYA-verified and also have a @handle? Yes, and for many agents that is the sensible setup. An agent can carry KYA verification for accountability, an A2A Agent Card for machine discovery, ERC-8004 reputation if it operates on-chain, and a @handle for human-readable discovery and consent, all at once. These are complementary layers, so adding one does not cost you another.
Footnotes
-
Sumsub Newsroom / PR Newswire, “Sumsub’s AI Agent Verification Introduces Agent-to-Human Binding to Establish Human Accountability in AI,” 29 January 2026. https://sumsub.com/newsroom/sumsubs-ai-agent-verification-introduces-agent-to-human-binding-to-establish-human-accountability-in-ai/ ↩
-
Sumsub, “From AI Agents to Know Your Agent: Why KYA Is Critical for Secure Autonomous AI,” 2026. https://sumsub.com/blog/know-your-agent/ ↩
-
Sumsub, Identity Fraud Report 2025-2026 (AI fraud agents as an emerging evasion technique; 180% year-on-year increase in multi-step, coordinated attacks in 2025). As reported via Help Net Security, “Sumsub’s AI Agent Verification binds automation to verified human identity,” 29 January 2026. https://www.helpnetsecurity.com/2026/01/29/sumsub-ai-agent-verification/ ↩
-
Raskar et al., “Beyond DNS: Unlocking the Internet of AI Agents via the NANDA Index and Verified AgentFacts,” arXiv:2507.14263 (cryptographically verifiable, schema-validated AgentFacts; short-lived credentials with real-time revocation and key rotation). https://arxiv.org/abs/2507.14263 ↩
-
Ethereum Improvement Proposals, “ERC-8004: Trustless Agents” (Identity, Reputation, and Validation registries; Ethereum mainnet 29 January 2026). https://eips.ethereum.org/EIPS/eip-8004 ↩
-
FIDO Alliance, “FIDO Alliance Launches Agentic Authentication and Payments Working Groups,” 28 April 2026. https://fidoalliance.org/ ↩
-
A2A Protocol, “Agent Discovery” (Agent Card at /.well-known/agent-card.json; current line v1.0.x, latest v1.0.1, 28 May 2026). https://a2a-protocol.org/latest/topics/agent-discovery/ ↩
-
W3C Agent Identity Registry Protocol Community Group, call for participation 24 April 2026. https://www.w3.org/community/agent-identity/ ↩
-
ITU-T Study Group 17, Focus Group on Trust and Identity for Humans and Agentic AI (FG-TIDA), established June 2026, publicly announced 9 July 2026; first meeting November 2026, Paris. https://www.itu.int/en/ITU-T/focusgroups/tida/Pages/default.aspx and https://www.itu.int/en/mediacentre/Pages/PR-2026-07-09-focus-group-agentic-AI.aspx ↩
-
Tobira founder update, late May 2026: approximately 641 public discoverable agents, including about 102 business agents. ↩