Is Know Your Agent (KYA) Really Necessary?

Is “Know Your Agent” (KYA) Really Necessary? The tale of an Orphan Signal

Short Blog | June 2026

A new category of startup has emerged around “Know Your Agent” (KYA) — the idea that merchants and payment platforms need a framework to verify the identity, authority, and auditability of AI agents acting on behalf of consumers. PYMNTS has covered the space extensively, and KnowYourAgent.xyz is already pitching merchants on “identity, policy controls, and evidence for every AI-agent transaction at checkout.” The framing is intuitive: if a bot is buying something, shouldn’t you know who sent it?

I want to push back — not on the problem, but on whether KYA, as a standalone service category, is the right solution.

Continue reading

Carts and Mandates: Decoupling Discovery, Authentication, and Liability 

Executive Summary

I just got back from 2 weeks of vacation and catching up on all that transpired. No one reads this blog for its technical depth, but a few browse it for the economic implications and power struggles going on behind the scenes (hence “inside baseball”).

I/O 2026 was last week (see product announcements). The Commerce team showed how Universal Cart, Universal Commerce Protocol (UCP) and Agent Payments Protocol (AP2) would drive a frictionless revolution in digital commerce.  By consolidating products from Search, Gemini, YouTube, and Gmail into a single persistent cart, Google is attempting to establish itself as the default transaction and orchestration layer of the internet. While consumers would love to engage across any platform and any retailer from any device…. A universal cart is also necessary for operating across any agentic platform and “specialist”.  Agentic commerce is certainly gaining traction, but Walmart’s Rufas and Amazon’s Alexa also want to play in the game at the front end (so does Open AI)

Wallet expansion to universal cart is great for Google; however, it’s not great for everyone else, as platforms make for poor custodians (i.e., they are not neutral). Particularly when it comes to controlling credentials and measuring their own effectiveness.  My concerns here are shared by retailers, banks, processors and networks as this architecture conceals a profound structural conflict over control and economic value.  Google’s “own-it-all” will create a great customer experience, and allow them to move agentic from the current “conversational commerce to merchant checkout” state, but who wants to invest in a platform where they become disintermediated, or a dumb fulfillment pipe? 

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us

Card VAS Tailwind – Agentic

© Starpoint LLP, 2025. No part of this site, blog.starpointllp.com, may be reproduced or retransmitted, in whole or in part, in any manner without the permission of the copyright owner. Also, see our Legal/Disclaimer (this is a highly opinionated and partially informed blog). Enterprise readers, please consider Enterprise Subscription (not required for Starpoint Clients). 

I’ll be honest, I’ve been watching the “agentic commerce” hype train with a healthy dose of skepticism. The idea that AI agents will soon handle all our shopping feels like a solution in search of a problem. Yet, looking at the data, I have to admit something massive is happening under the surface. We are in the midst of a fundamental change in how the internet works, and while the “Agentic Era” is still 3+ years away, the tremors are already breaking the internet’s business model.

Continue reading

Machine to Machine Transactions: How to Resolve Trust and Governance Gaps. 

FIDO, VC, AP2, Tokenization, Credential Issuance, Biometrics, …etc

Executive Summary

The transition to agentic, machine-to-machine (M2M) commerce creates a profound governance gap that existing technology-first standards cannot fill. Today, human-in-the-loop (HIL) transactions, whether at a point-of-sale or in eCommerce, are secured not by technology alone, but by the robust, contract-based governance and risk-allocation models of networks like Visa and Mastercard. As stated previously, V/MA are the identity infrastructure for the internet and identity is the core “shaping force” for all new payment schemes.

Continue reading

Payment Authorization – Under The Hood

Retailers should tread very carefully in direct issuer connections

My focus over the last 18 months has been identity, trust, authorization and assertions. Today I thought we would get under the hood a little on the technology of authorization and the current operational issues with a key network service: 3DS. 

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us