Ant International, Mastercard, and Visa announced today that they have begun work on a Know-Your-Agent interoperability framework through BuildFin.ai. The scope: common signals for tracing an agent back to a validated operator, shared certification requirements, and continuous monitoring of identity and transaction behavior. Each network keeps its own verification and approval decisions.
What isn't there is a rule about who pays — no dispute-allocation mechanism, liability shift, merchant-recognition mandate, or conformance test. The framework establishes who sent the agent, which is useful and not the same thing as establishing who absorbs the cost when the agent buys something nobody wanted.
Two other efforts landed in the same week — the first working week after Labor Day, as it happens — and arrived at the same ordering by different routes. At the W3C/GS1 workshop in Zurich on September 8–9, participants brought concrete technical proposals for agent discovery, identity, and credential presentation. Recourse was on the agenda too: one session covered liability and consumer protection, and merchant participants asked for machine-readable evidence they could use in disputes. But the identity work showed up as protocols and the recourse work showed up as questions. That asymmetry in specificity is a reasonable proxy for where consensus already exists.
Then on September 9, Representative Gottheimer introduced the Stop Rogue AI Act, which calls for continuous agent inventory, identity verification, monitoring, and the ability to revoke an agent's access at any moment. It is silent on the commitments an agent has already made when that access gets pulled, and on who unwinds them.
I don't read this as three oversights. It looks more like the ordinary economics of building anything jointly with people whose interests only partly overlap. Shared identity signals, common discovery mechanisms, mutual credential recognition — these reduce duplicated cost for every participant at once. Nobody has to give anything up to agree, so agreement comes relatively cheaply. A liability rule is a different kind of object. Someone has to absorb the loss when an agent makes a technically valid purchase its principal never wanted, and settling who that someone is means negotiating over money that has to come from a specific pocket. Identity standards don't require that negotiation, but recourse standards are built from it.
Payment cards went the same way. EMVCo published its chip card specification in 1996. The U.S. counterfeit-fraud liability shift — the rule saying who eats the loss when a chip card gets swiped at a terminal that can't read the chip — didn't arrive until October 2015, and each network imposed it separately rather than jointly. Nineteen years between the shared blueprint and the allocation rule. Merchants adopted chip cards after the liability shift, not after the specification.
For anyone deploying agents into commerce, the practical shape of this is a window in which your agents are recognized by counterparties before there is any mature machinery for contesting what they do. I've argued before that reversibility needs four things — a deadline, an obligated party, an evidence channel, and someone funding the repair. Recognition supplies none of them. Attribution infrastructure, the ability to prove who acted, is maturing faster than mandate infrastructure, the ability to prove what they were authorized to do. Until an allocation rule exists, the cost of an agent's mistakes stays where costs always sit by default: with whoever deployed it.
Your agents will be able to transact before the ecosystem can adjudicate their errors. That interval is foreseeable, which means it is budgetable.
- Revoked policies survive in memory: A new preprint found that filtering obsolete records from agent memory didn't prevent the agent from writing unsafe conclusions back as fresh, unmarked entries, raising the question of whether revocation controls need to track the genealogy of derived decisions, not just source records.
- Delegation histories outlive permissions: A separate study constructed scenarios where identical present-day permissions required opposite decisions after a later grant was revoked, and found that only authenticated current-state queries resolved them correctly — a concrete challenge for the inventory-and-revoke model the proposed legislation envisions.
- Meta's agent as internal institution: Meta's Muse launched with a separate host-side system controlling every outbound network request, separating proposal from permission from credential custody — an architecture worth watching as a test of whether internal separation of duties can substitute for external dispute infrastructure.
- Forward-deployed engineers as ecosystem: Google Cloud and Accenture formed a 1,000-person engineering group dedicated to agent implementation, a signal that the scarce resource in agent deployment may be organizational integration rather than model capability.

