Industry News
Know-Your-Agent: AI agent payments and your virtual cards
Visa, Mastercard and Ant started a Know-Your-Agent framework on Sept 10. What it changes for virtual card users, and what it does not.

Three rivals at one table, to issue ID cards for AI agents
On September 10, 2026, Reuters reported a story that was easy to miss but hard to overrate: Visa, Mastercard and Ant International started collaborating on a Know-Your-Agent (KYA) interoperability framework (source: Reuters). In plain terms: before an AI agent shops or pays on your behalf, it will need a verifiable identity that every network recognizes, and the three companies intend to define that verification standard together.
The three networks bring in more than $77 billion in combined annual revenue, and they have been fighting each other for decades. The only reason they share a table now is the size of the prize. The joint announcement cites a projection that by 2030, AI agents will orchestrate somewhere between $3 trillion and $5 trillion in global consumer commerce. Nobody wants to lose that market because their agent identity standard does not talk to anyone else's.
This is not a concept press release either. Rewind a few months. On June 11, Visa and OpenAI announced that tokenized Visa credentials can settle agent-initiated checkouts inside ChatGPT. The same month, Mastercard launched Agent Pay for Machines, which lets agents pay other agents, with transactions going as low as $0.000001. Ant International open-sourced its Agentic Mobile Protocol in late April. The cards have already reached the agents. What is missing is an answer to a simpler question: how does a merchant or a card network know that the thing checking out is your agent and not someone who hijacked it? KYA is that answer taking shape.
What the framework covers, and what it does not
Lets set expectations straight. The announcement says the parties will explore working toward common principles. There is no launch date, no technical specification, and no mandatory onboarding.
The substance so far has three parts. First, the three existing agent protocols, Visa's Trusted Agent Protocol, Mastercard's Verifiable Intent, and Ant's Agentic Mobile Protocol, will explore mutual recognition, so an agent verified on one network produces trust signals that other networks and wallets can accept without re-verification. Second, the collaboration anchors in Singapore, building on MAS' Safeguards for Agentic Finance at Runtime (SAFR) framework and running through BuildFin.ai to align agent verification, accountability and risk practices. Third, the stated use case is onboarding cost: less duplicated identity checking, faster time to market for new agent services (source: Ant International announcement).
Translate that into virtual card language. This is the agent-era equivalent of what card networks did decades ago with BIN interoperability and clearing recognition. It is not a product. It is infrastructure answering the question of who is who. Cooperation at this layer usually takes 18 to 36 months from principles to production. So within 2026, you will notice exactly nothing as a user. Anyone marketing KYA as live today is selling a press release.
An agent's card is, structurally, a virtual card
Here is the part that matters most to virtual card users.
Visa's agent credential is officially described as an agent-specific tokenized payment credential, bound to the agent's identity rather than the human cardholder, with category limits, per-transaction caps and validity windows set by the user at issuance. Category limits, per-transaction caps, validity windows. Virtual card platforms have sold exactly these three controls for years. On Mastercard's side, Agent Pay for Machines has signed more than 30 partners including Stripe, Adyen, Coinbase and Ripple, with agent permissions and credentials recorded on chains like Polygon and Solana for auditability.
Put simply, the payment credential that card networks designed for AI agents is a controlled virtual card with a machine as the cardholder. The industry is converging on virtual card logic, not bypassing it. Market data points the same way: Grand View Research estimates the global virtual card market at $27.7 billion in 2026, growing above 22 percent a year, with remote payment and B2C use cases expanding fastest.
That is good news for virtual card platforms, with one condition: they need an API. A manual web dashboard where a human clicks through card issuance cannot serve an agent. Platforms in our directory that lead with API-driven issuance, such as Doopcard, are naturally positioned for this lane. Platforms with a web backend only will miss it. If you want to know whether a platform holds a ticket for the agent era, check whether developer documentation exists.
The riskiest thing you can do today: paste your card number into an agent
Frameworks aside, the real risk right now comes from users themselves.
Agents fill forms, compare prices and check out, so plenty of people paste a virtual card's number, expiry and CVV straight into the chat and let the agent pay. That is the worst payment practice of 2026. The reasons are concrete. Credentials stored in an agent's context can be exfiltrated through prompt injection, leaked into tool call logs, or abused by a hijacked agent. This is not a theoretical scenario, it has happened in production systems.
The right approach has two layers. Layer one, available today: open a dedicated virtual card for agent-driven payments, load only what the current task needs, then lock or delete the card when the task ends. The logic matches what we described in our subscription cancellation guide: keep the exposure of every authorization as small as possible. Layer two, for when the rails mature: once schemes like Visa Intelligent Commerce Connect spread, remove plaintext card numbers from the flow entirely. What an agent should hold is a scoped token, valid only for one merchant and one amount window, nearly worthless if leaked.
A note on single-use cards. Mordor Intelligence data puts single-use virtual cards above 59 percent of virtual card transaction value in 2025, growing faster than multi-use cards. Agent workloads will push that share higher: one card per task, discarded after use, is the closest thing to least-privilege payments. If you have never used a single-use card product, the card directory is the place to find platforms that offer them.
For the earlier chapters of this story, two of our previous analyses are worth a read: when AI agents started spending covered the concept, and the ChatGPT Instant Checkout story covered the settlement protocol war. KYA is where those two threads meet: once agents could spend, the industry started fixing the identity and trust gap.
Your card choice does not need to change, your checklist does
Here is a possibly surprising take: KYA changes no platform rankings in the near term. The framework has not landed, and agent tokens are not open to third-party virtual card platforms. Switching platforms over a news headline would be an overreaction.
What deserves an update is your evaluation checklist. The old questions were fees, BINs and KYC thresholds. Add three more. Does the platform offer API issuance? Can you set per-transaction and per-category limits per task? Does it support merchant locking or single-use cards? Those three capabilities are the passing grade for the agent era, and we will fold them into the checks behind our provider directory over time.
One warning in the other direction. Over the coming months, expect platforms to market themselves with AI agent payment branding. The test is simple: ask for developer documentation, ask whether the agent credential is tokenized, ask what spend controls attach to it. Platforms that cannot answer are repackaging a press release as a product.
The regulatory shadow: SAFR runs first, windows close
The choice of Singapore as the starting point is not accidental. MAS' SAFR framework is among the world's first runtime safeguards for AI agents in financial scenarios, covering agent-assisted payments, treasury operations and advisory workflows. The compliance bar for agent payments will rise: who the agent is, who is accountable for its behavior, and how a failed transaction gets traced will become requirements, not options.
For users, the implication is direct. Agent payments will end up as verified agents plus constrained credentials, the same way virtual cards ended up as verified users plus limited cards. The window for anonymous, grey-zone agent payments will not stay open long. If your cross-border business counts on automated agent purchasing, moving the payment leg onto constrained credentials early costs far less than cleaning up afterwards.
FAQ
Can I use the KYA framework now?
No. The September 2026 announcement is a collaboration start with common principles under exploration. There is no launch timeline, and zero impact on your payment experience this year.
Can an AI agent charge my virtual card today?
Technically yes if you hand over the card details, but that is high risk. The regulated path is the agent token approach from Visa and Mastercard, currently rolling out mainly inside platforms like ChatGPT. Third-party virtual card platforms are not integrated yet.
Will agent tokens replace virtual cards?
Not soon, and the relationship runs the other way. Agent tokens are controlled virtual cards by architecture, and the limits, locks and single-use patterns that virtual card platforms already offer are exactly the primitives agent payments need. Platforms without APIs are the ones at risk of marginalization.
What should I add to my platform checklist?
API issuance, per-task spend limits, single-use cards or merchant locking. Those three decide whether a platform can absorb agent-era payment demand.