Know Your Agent: compliance when the thing initiating the payment is software
As agents start moving money, KYC becomes Know Your Agent. Why the audit trail — not autonomy — is the real product of agentic compliance.

Four posts into this series I’ve argued about where agents should act and where a human should sit. This one is about the question that decides whether any of it is allowed: when the thing initiating a payment is software, how do you stay compliant?
Both papers I’ve been drawing on — the IMF’s How Agentic AI Will Reshape Payments and Hui Gong’s Agent-to-Agent Finance — spend real space here, and they converge on the same answer: a new discipline they both call Know Your Agent. It’s the least glamorous part of agentic finance and, I think, the part that actually determines who gets to build in it. So let me lay out the problem, the discipline, and why our whole approach to it comes down to one unglamorous thing: the audit trail.
KYC was built for a human clicking “pay”
Every compliance control we have — KYC, multi-factor authentication, the whole apparatus — assumes a person who explicitly authorises each transaction. The IMF puts the problem precisely: those mechanisms are “designed around human users who explicitly approve transactions.” When a payment is initiated autonomously by an agent under delegated authority, “verifying both the identity of the agent and the intent of the underlying user becomes significantly more complex.”
Two identities to verify now, not one: the agent, and the human intent behind it. And when that breaks, it breaks in a genuinely new way. The IMF names the sharpest edge of it — existing regulation “struggle[s] to distinguish between ‘unauthorized use’ and ‘user negligence’ if an agent hallucinates and misdirects funds.” That sentence should stop anyone building in this space. If an agent sends money to the wrong place, is that fraud, a defective product, or your own failure to supervise it? Today, nobody can tell you with confidence. That ambiguity is a compliance problem before it’s a legal one.
Know Your Agent, in five checks
The answer both papers reach isn’t “trust the model more.” It’s to make the agent, and every action it takes, knowable. The IMF frames the regulatory shift as moving from Know Your Customer to Know Your Agent — verifiable identities for financial bots, linked to real legal entities. Gong is more operational, and his five checks are the clearest checklist I’ve seen for judging any agent you’d let near money:
- Identity — who operates this agent, and which legal person ultimately stands behind it?
- Capability — what does it actually do, on what model and tool stack, within what limits?
- Authority — what accounts, permissions and spend limits does it hold?
- Provenance — what evidence links a given action back to an instruction, a policy, and a reason?
- Recourse — who can pause, revoke, dispute or undo what it did?
Read that list against most “agentic finance” demos and you’ll notice how much of it is missing. An agent with your credentials and no verifiable identity fails check one. Blanket access with no scoped limits fails check three. And the one that quietly matters most — provenance — is failed by almost everything: an agent that acts but can’t show why, traceable from the money back to the instruction.
The hard part isn’t explaining. It’s accounting.
Here’s the distinction Gong makes that reframed compliance for me: accountability cannot be reduced to explainability. Explainability asks why a model produced an output. Accountability asks who is responsible, and what’s the remedy when it goes wrong. An agent, he notes, can be “explainable but unauthorised; authorised but manipulated; manipulated but still technically compliant with a narrow rule; compliant but harmful because the rule was poorly designed.”
So a chatty AI that narrates its reasoning isn’t compliance. What compliance actually needs is an audit object — the IMF’s word is audit trail — that connects three things a supervisor might one day ask about: the natural-language intent, the technical execution, and the legal authority under which it happened. Not the model’s chain-of-thought. The economically consequential chain: this instruction, under this mandate, selected this counterparty, paid this amount, for this reason, approved by this person.
That is a much higher bar than “the AI can explain itself.” And it’s the bar the whole category will be judged against.
Why reconciliation is the compliance engine
This is where I think our design has an unfair advantage, and it’s almost boring: the audit trail isn’t a feature we bolt on for compliance — it’s what falls out of how the agents already work.
Fynex agents reconcile the whole money chain continuously. Every payment is tied to its invoice and its purchase order, matched into your ledger, with the agent’s reasoning for proposing it attached. So by the time anything reaches the human approval before money moves, the provenance already exists — you’re not reconstructing it later, you’re approving from it. The approval itself becomes the record: a named person, a timestamp, and the full decision chain behind every payment that left the business.
That’s what the IMF means by “compliance by design” — embedding the regulatory logic into the workflow so that traceability is a property of the system, not a report someone assembles afterward. It’s the same principle behind the payment networks it cites (Mastercard scoring transactions in milliseconds, Visa’s real-time risk checks): compliance runs inside the flow, at its speed. Our version runs it inside the money chain: because the agents reconcile everything anyway, the evidence for every action is a side-effect of doing the work.
And it answers the ugly question from earlier. When there’s a named human approval sitting on top of a complete, reconciled decision chain, the “unauthorized use versus user negligence” ambiguity shrinks. You can show exactly what the agent proposed, on what evidence, and who authorised the release. That’s not a full answer to the liability question — the law still has catching up to do — but it’s the difference between having the record and not having it.
Compliance as a job agents do — carefully
Both papers also point at something more forward-looking: compliance itself becoming agentic. The IMF describes multi-agent compliance — one agent scanning for regulatory changes, another scoring risk, a third mapping controls, a fourth handling remediation, all coordinated. Gong describes a payment agent calling an AML-screening agent before paying a new counterparty. This is genuinely promising: compliance work is mostly reading, matching, flagging and evidencing — exactly what agents are good at.
But notice it lands in the same place as everything else in this series. An agent that screens and flags and assembles the evidence pack is doing reversible reasoning — let it run. An agent that clears a payment past a sanctions check with no human on a genuine hit is making an irreversible call with legal consequences. The IMF is careful here too: these systems “flag suspicious transactions, escalate high-risk cases” — escalate, not autonomously absolve. Agentic compliance is a reason to give agents more reach over the reasoning, and exactly the same reason to keep the human on the consequential decision.
The unglamorous conclusion
The headline of agentic finance is autonomy. The thing that actually decides who’s allowed to operate is the opposite: knowability. Can you prove which agent acted, under whose authority, on what evidence, and who can undo it? That’s Know Your Agent, and both a central-bank note and an academic paper independently concluded it’s the hinge the whole category turns on.
We built the audit trail first, almost by accident, because reconciling the whole money chain and keeping a human on every money movement produces the evidence as a matter of course. It turns out the boring infrastructure — reconciliation, provenance, a legible approval — is the compliance product. Autonomy makes the demos. Knowability is what ships to a regulated business. If you’re evaluating anything in this space, ours included, don’t ask how autonomous the agent is. Ask whether you’d know what it did.