TLDRocket
Sign in

Know your agent: Why UK fintech needs an identity system for its AI before the Treasury builds one

Startups Magazine Yuliia Harkusha

UK officials want an ID system for AI agents that move money. Because “the bot did it” won’t cut it when payments go wrong.

Based on reporting by Startups Magazine, Yuliia Harkusha — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

For years, financial services has run on a simple rule: if something is allowed to move money, you need to know who or what it is. AI agents have started to break that rule. They can search, negotiate, manage accounts and even initiate payments on someone’s behalf, which leaves banks and payment firms with a basic problem nobody has cleanly solved: how do you verify an agent before you trust its instructions?

HM Treasury has now put that question on the table. Its July Financial Services AI Adoption Plan names agentic payments in one of its ten recommendations, and Recommendation 10 calls for a trust framework built around liability rules, interoperable authentication and “Know Your Agent,” or KYA. The linked payments consultation stays open until 6 October. The idea sounds narrow. It isn’t. If this works, identity becomes a core control layer for agentic finance.

The catch is that KYA is not just KYC with a new acronym. A person has a stable identity. An AI agent might exist for one transaction, then vanish. It might be run by a bank, built by a fintech, powered by someone else’s model and hand work off to yet another agent. So the real question is not only whether an agent exists, but what it is, whose authority it is using, what it can do and whether that authority can be delegated or revoked.

That distinction matters fast. If someone tells an agent to book a flight to Madrid for under £250, the system has to know more than the agent’s name. It has to know the person authorised the spend, that the limit is £250 and that three business-class tickets to Dubai are nowhere near the brief. Today, many systems lean on human-era credentials like API keys, OAuth tokens and service accounts. They work technically. Governance-wise, they are shaky.

The UK is not starting from nothing. In March, the Competition and Markets Authority warned that as agents transact for users, reliable verification of identity and authority becomes essential, and that fragmented identity systems could raise fraud and disputes. It also pushed for open standards on permissions and logging, and said businesses stay liable for their AI agents even when a third party built them, with penalties up to 10% of worldwide turnover. Treasury, the CMA and the identity sector are circling the same missing layer: identity, permissions and logs that make agentic finance accountable instead of merely clever.

My take — AI-written commentary, not fact-checked reporting

This is one of those rare moments where regulation is pointing at the obvious before the market has time to make a mess of it. If an AI can spend money, it needs a paper trail that survives contact with compliance, fraud teams and lawyers. The industry loves autonomy right up until someone asks who signed the cheque.

Read more about this at: Startups Magazine

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.