
The next phase of digital payments may not be defined by faster checkouts or cheaper transfers, but by a more uncomfortable question: who or what is being trusted to move money?
As businesses begin experimenting with AI agents that can search for suppliers, compare prices, negotiate terms, initiate payments, and reconcile invoices, the old assumptions around financial control start to fray. A human no longer clicks every button. A finance team may not manually approve every step. In some cases, software will act on behalf of a company, within rules set in advance.
Also Read: The next AI payments boom may happen in the back office
That shift sits at the centre of “Beyond Automation: Defining Agentic Global Payments”, a report by Sunrate and Mastercard. Its central argument is straightforward: automation alone is not enough. If AI agents are to handle commercial decisions involving millions of US dollars, companies need more than speed. They need accountability.
The report calls this missing infrastructure the “Trust Layer”, a framework that allows businesses to verify an agent’s identity, understand its authority, and trace what it has done. In other words, the future of payments will not just depend on whether AI can act intelligently. It will depend on whether organisations can prove that these actions were authorised, limited, and auditable.
From Know Your Customer to Know Your Agent
For the past decade, much of fintech has been shaped by Know Your Customer (KYC) rules. Banks, payment companies, and fintech startups have built systems to verify that users are who they say they are, screen them for risk, and monitor suspicious activity.
Agentic commerce introduces a new layer of complexity. If an AI agent places an order, books travel, pays a supplier, or moves funds across borders, the payment ecosystem needs to know more than the identity of the company behind it. It must also understand the identity and authority of the agent itself.
This is where “Know Your Agent”, or KYA, comes in.
KYA is not simply a branding exercise. It points to a practical set of controls: verifying an AI agent, defining what it is allowed to do, recording the intent behind a transaction, and ensuring that actions remain within commercial and policy boundaries. An agent authorised to buy office supplies, for example, should not be able to approve a large foreign exchange transfer. A procurement agent with a US$10,000 spending limit should not be able to split payments to bypass that limit.
Also Read: From chatbots to payment agents: AI’s next role in SEA commerce
For Southeast Asia, where many companies already operate across fragmented markets, currencies, payment methods, and compliance regimes, this matters. A regional startup may have suppliers in Vietnam, customers in Indonesia, finance operations in Singapore, and banking relationships across several jurisdictions. Adding autonomous agents into that mix without governance could create a risk environment that is difficult to monitor.
The three pillars of the Trust Layer
The report breaks the Trust Layer into three broad pillars.
The first is credential protection. In today’s payment systems, tokenisation is already used to replace sensitive card or account details with secure digital tokens. In an agentic payments environment, this becomes even more important. AI agents should not be passing around raw card numbers, bank credentials, or account information. If those agents are compromised, the damage could be significant.
The second pillar is intent capture. This means securely transmitting the user’s budget, preferences, constraints, and instructions along with the transaction. In human terms, it is the difference between saying “buy the cheapest ticket” and “buy a refundable economy ticket under US$700, departing after 7pm, with no overnight layover”. For businesses, intent capture allows systems to determine whether an agent acted in line with approved instructions.
The third pillar is KYA and governance. This is the architecture that verifies the agent’s identity and sets strict permission boundaries. It includes authentication, policy enforcement, audit trails, and the ability to revoke or modify permissions when needed.
These controls may sound technical, but their commercial importance is simple. Businesses cannot delegate financial decisions to agents if they cannot later explain what happened, why it happened, and whether it was allowed.
Why many AI projects do not make it past pilots
The urgency is not theoretical. According to Gartner, at least 50 per cent of AI projects were abandoned last year after the proof-of-concept stage. The reasons included poor data readiness, high costs, and a lack of risk control.
That last point is particularly relevant for payments. In many companies, AI pilots are still treated as productivity experiments. Teams test whether a model can draft emails, summarise documents, or automate customer support. Payments are different. A bad recommendation may waste time. A bad transaction may move real money, breach regulations, or damage a company’s relationship with banks and suppliers.
Also Read: The scarcity mindset is killing creativity, not AI
For Southeast Asian startups, this creates both a warning and an opening. The warning is that building a clever agent is not enough. A product that can automate procurement or treasury workflows may impress in a demo, but enterprise customers will ask harder questions before deploying it in live payment flows.
Who approved this transaction? What data did the agent use? Can the company prove that the payment matched its internal policy? Can a bank or payment service provider trace the chain of authorisation? What happens if the agent is tricked by fraudulent instructions?
The opportunity lies in answering those questions better than competitors. The strongest companies in this space may not be the ones with the most sophisticated AI interface, but those that combine automation with controls that banks, CFOs, auditors, and regulators can trust.
Why the ecosystem matters
A Trust Layer cannot be built by a single startup in isolation. Agentic payments will require coordination across banks, card networks, payment service providers, enterprise software platforms, and regulators.
This is where established networks such as Mastercard are likely to play a significant role. Card networks already sit across large parts of the payment ecosystem and have experience with tokenisation, identity standards, fraud management, and dispute processes. Extending governed, traceable tokenisation into autonomous payment flows is a logical next step.
Payment service providers and cross-border platforms also matter, particularly in Southeast Asia. The region’s businesses often deal with multi-currency payments, varied settlement timelines, and uneven levels of banking infrastructure. If AI agents are to operate across borders, they will need infrastructure that can translate business intent into compliant payment execution across different markets.
Regulators will also have to catch up. Many existing rules assume a human actor at key decision points. Agentic systems challenge that assumption. Over time, authorities may need clearer standards on agent identity, liability, consent, auditability, and operational resilience.
Trust as a competitive advantage
The rise of AI agents in payments is often framed as a story about efficiency. There is truth in that. Agents could reduce manual work, speed up reconciliation, and help businesses optimise costs across suppliers and currencies.
But efficiency will not be the deciding factor if companies fear losing control.
Also Read: The next AI payments boom may happen in the back office
The more important race is to build systems where autonomy does not mean opacity. Businesses will need to know not only that an agent completed a task, but that it did so within defined limits. Banks will need confidence that transactions are legitimate. Payment networks will need ways to trace credentials and intent. Regulators will need evidence that responsibility has not disappeared into a black box.
For Southeast Asia’s startup ecosystem, the message is clear. The next wave of payments innovation will not be won by speed alone. It will be won by companies that can make AI agents accountable.
The future belongs not just to agents that are smart enough to act, but to systems that are safe enough to trust.
The post From KYC to KYA: how AI agents are reshaping payment risk appeared first on e27.








