Three networks, three protocols, one unresolved standard
Visa, Mastercard and Ant International announced a collaboration to build an interoperable Know Your Agent framework, convened with the Monetary Authority of Singapore as a neutral party. The problem the three are trying to solve is straightforward to state and hard to fix: each network has already shipped its own way of identifying and verifying AI shopping agents, Visa's Trusted Agent Protocol, Mastercard's Verifiable Intent, and Ant International's Agentic Mobile Protocol, and none of them talk to each other today.
Rubail Birwadker of Visa framed the stakes directly, saying that as AI agents become bigger in discovery and buying, trust must scale with them, and that collaboration creates consistency, accountability, and confidence. Mastercard's Pablo Fourez put it in almost identical terms, calling interoperability across Know Your Agent frameworks essential to making agentic commerce work at scale. That the two biggest card networks are saying the same thing publicly while still running separate protocols is itself the tell that this is unresolved, not solved.
The cost of not solving it is already measured in the billions
This is not a speculative problem the networks invented to justify a new standards body. PYMNTS Intelligence research from earlier this year found that nearly 90 percent of enterprises already identify bot management as a major operational challenge, and outdated identity controls are estimated to cost businesses roughly 100 billion dollars annually through fraud, false declines, and customers lost to friction. Agent commerce adds a new category of bot to manage, one with legitimate purchasing intent that still needs to be told apart from a fraudulent script.
Jiang-Ming Yang, Ant International's chief innovation officer, described the direction as drawing on richer signals, capabilities, behavior, execution performance, and risk data, to build trust and simplify transactions. That is a meaningfully more sophisticated identity model than a static API key or merchant allowlist, and it is the kind of signal-rich verification that only becomes practical if all three networks agree on a shared data model rather than each maintaining an incompatible one.
What the framework is actually built on
The technical foundation draws on the SAFR framework, Safeguards for Agentic Finance at Runtime, and the BuildFin.ai platform, with features including agent traceability across networks, clear attribution to validated operators and organizations, standard certification requirements, and continuous monitoring using identity and transaction signals rather than a one-time verification check. That continuous model matters because an agent's behavior can change after certification, through a model update, a compromised integration, or a operator simply changing what the agent is instructed to do.
Continuous monitoring also implies ongoing data sharing between networks about agent behavior, which raises its own governance questions merchants should be asking now: who audits the monitoring, what happens when a certified agent's risk score changes mid-session, and which network's revocation decision takes precedence when Visa, Mastercard, and Ant International disagree about whether a specific agent should still be trusted. None of the public materials from this announcement answer those questions yet, which means merchants adopting early are trusting the framework's intent rather than a finished specification.
Why the market size makes this unavoidable
The number driving urgency across all three networks is the projection that AI agents will orchestrate between 3 and 5 trillion dollars of global consumer commerce by 2030. Whatever the precision of that estimate, it is large enough that no single network wants to be the one still running an incompatible, non-interoperable identity protocol when transaction volume of that scale materializes. That is why competitors who spent the last two years building separate protocols are now standing on the same stage talking about interoperability instead of competitive advantage.
It also explains the choice of the Monetary Authority of Singapore as convening partner rather than a US or European regulator. Singapore has positioned itself as a neutral, technically credible venue for exactly this kind of multi-network standards conversation, and choosing that convener signals the three companies want this framework to read as an industry standard, not as a feature of any single network's proprietary stack, a distinction that matters enormously to merchants deciding whether to integrate now or wait for broader ratification.
The lesson from tokenization applies here too
Payment tokenization went through a similar early phase, where each network pushed its own token vault specification before EMVCo eventually standardized token requesting and provisioning across networks. Merchants who integrated early against a single network's proprietary tokenization approach often carried duplicate integration cost once the industry standard landed, maintaining both the early implementation and the converged one during a multi-year transition. Agent identity is following the same arc, just compressed into months rather than years given how fast agentic commerce is scaling.
The difference this time is the size of the number driving convergence. Tokenization converged because card-present fraud losses were large but bounded. Agent commerce convergence is being pulled forward by a market projection in the trillions, which means the networks have far more incentive to move quickly toward a shared standard than they did with tokenization, and commerce technology leaders should expect the Know Your Agent framework to solidify faster than past payment standards did.
The decision this creates for commerce technology leaders
If your commerce stack is integrating agent checkout capability right now, you are choosing between three protocols that all say they intend to interoperate eventually but do not yet. That is a familiar position for anyone who lived through early payment tokenization standards, where committing engineering effort to one network's specification ahead of convergence sometimes meant a costly rebuild once the industry-wide standard emerged. The safer near-term move is building an abstraction layer that can swap agent identity providers rather than hard-coding integration to any single network's protocol.
Longer term, agent identity infrastructure deserves the same governance attention CTOs already give to payment tokenization and PCI compliance, because the risk profile is comparable: a compromised or poorly verified agent identity is a direct path to fraudulent transactions at scale. Track this standards effort the way you would track a PCI DSS revision, with a named owner inside the organization and a plan to adopt whichever framework the three networks actually converge on, rather than betting early on the one that arrived first.



