Before an AI Can Spend Your Money, Someone Has to Solve KYC for Robots

In the last article, I argued the idea of giving each person an AI agent that represents them online — one that can, in a meaningful sense, legally act on their behalf. I spent a lot of words on identity and trust, and then I did the thing every optimistic tech essay does: I gestured at the hard part and moved on.

The hard part is money.

Everything a Personal AI Representative would be genuinely useful for eventually touches a payment. Chasing the refund, cancelling the subscription, comparing the insurance quotes and buying one, paying the invoice, moving funds between your accounts. The moment your agent stops reading the world and starts changing it — with your money — it walks up to a system I’ve spent twenty years inside. And that system does not care how clever your agent is. Before a single cent moves, it asks a short list of unglamorous questions, and it will not proceed until each one has an answer.

Your agent cannot currently answer any of them.

The four questions money asks

We talk about “AI acting on your behalf” as if it’s a new idea. It isn’t. Finance has let one party act for another for centuries, and it built machinery to make that safe. When a payment leaves your account today, the system is quietly running four checks — and it’s worth understanding them precisely, because your agent breaks all four.

One: is the human real and actually here? This is authentication, and in a lot of the world it’s now the law. In Europe, Strong Customer Authentication requires two independent factors for most electronic payments — something you know, something you have, something you are. Your phone buzzes, you press your thumb to it, you approve. The entire design assumes a present human with a body.

Two: is this actor allowed to do this, and up to what limit? This is authorization, and finance has a beautiful, boring instrument for delegating it: the mandate. When you set up a direct debit, you’re not handing your gym a blank cheque. You’re lodging a scoped, revocable authorization — this creditor, this kind of charge — that the banking system honors and that you can pull back, with a guarantee attached that refunds you if it’s misused. A power of attorney is the same idea with more teeth: a legal document that lets a named person act for you, within a defined scope, that a bank will verify before it honors.

Three: does the system know who is ultimately acting, and are they clean? This is KYC and AML — Know Your Customer, Anti-Money-Laundering — and it is not optional paperwork. Banks are legally required to identify the customer, understand the purpose of the relationship, screen every party to a transaction against sanctions and politically-exposed-person lists, and monitor the account for patterns that don’t fit. Somewhere in the chain there must be an identified, screened, accountable person or entity.

Four: when this goes wrong, who pays? This is liability, and there’s a whole regulatory apparatus for it — Reg E in the US, PSD2 in Europe — that mostly protects you from transactions you didn’t authorize, provided you report them. The load-bearing word in all of it is authorized. Unauthorized: the bank generally eats it. Authorized: you generally do.

Four questions. Human answers for all of them. Now watch what happens when the actor is a robot.

Why each answer breaks for a robot

Authentication assumes a body, and your agent doesn’t have one. Strong Customer Authentication was written around a human with a fingerprint and a phone. An autonomous agent can’t be the biometric factor; at best it can hold a credential and act as “something you have.” So either you approve every payment yourself — at which point it isn’t really acting on your behalf, it’s a very expensive autocomplete — or we invent a way for an agent to carry delegated authentication that satisfies a regulation that never imagined it. That standard does not exist yet. People are building toward it, but “yet” is doing a lot of work.

Mandates assume human speed, and your agent doesn’t have that either. The direct-debit model is lovely precisely because it’s slow and legible: a handful of known creditors, monthly, easy to eyeball and revoke. Now imagine your agent holding standing authority to transact across hundreds of merchants, adapting in real time, firing off payments faster than you could ever review them. The mandate concept survives. The mandate infrastructure — built for a world where a human sets up a few and checks a statement once a month — does not. And revocation, the thing that makes mandates safe, has to become instant and machine-speed, because an agent gone wrong at machine speed can do a month of damage before you’ve finished your coffee.

KYC has no idea what to do with a non-person. The entire framework is built to land on an identified, accountable human or legal entity. An AI agent is neither. So what, exactly, does the system “know”? Not the agent — a model behind an API is not a customer. It has to be you, the human behind it, with the agent bound to your identity as a verifiable extension of it. But that binding — cryptographic, provable, scoped — is not how any bank’s KYC works today. Worse, transaction monitoring will actively fight you: the fraud models that protect your account are trained on human rhythms, and an agent’s rapid, atypical, machine-paced activity looks exactly like a compromised account. The security system built to protect you will keep freezing your agent, because from where it sits, your agent and a fraudster are indistinguishable.

Liability collapses into the grey zone finance already fears. Here’s the one that keeps me up. When your agent makes a genuinely dumb but technically authorized payment, which bucket is it in? You gave it standing authority. It used that authority. That’s not an unauthorized transaction the bank refunds — that’s you, holding the bag. We already have a name for the messy version of this: authorized push payment fraud, where a human is manipulated into approving a payment they shouldn’t have. It’s one of the fastest-growing fraud categories in the world, and it’s brutal precisely because the victim authorized it. An AI agent is an authorized-push-payment engine that never sleeps. The law has no settled answer for “my agent was tricked,” and “my agent was just wrong” is even murkier.

The part twenty years in this business taught me

Here’s something the AI crowd tends to miss, and it’s the whole reason I wanted to write this. Banks are slow to trust delegation on purpose. It is not incompetence or foot-dragging. Delegated authority is the single richest vein of fraud and abuse in all of finance.

Ask anyone who has worked near power-of-attorney operations. The document that lets a trusted person act for a vulnerable one is also the document that enables a staggering amount of elder financial abuse. That’s why banks move so cautiously before honoring a PoA — verifying the instrument, checking it’s registered and not revoked, confirming the scope, confirming the principal had capacity. Every one of those checks exists because someone, somewhere, weaponized delegation. The friction is the feature.

Now look at what agentic AI proposes: delegation, to a non-human, at industrial scale and machine speed, across the entire population at once. It doesn’t just reopen finance’s oldest wound. It industrializes it. Any serious attempt to put agents into the payment system has to start from that respect for how dangerous delegation is — not from a demo where it all just works.

So what does “KYC for robots” actually look like?

Not KYC-ing the robot as if it were a customer. That’s the wrong mental model, and it’s a dead end. You don’t run due diligence on my hands when I sign a cheque. The agent is hands, not a person.

What we actually need is to rebuild the two instruments finance already trusts — the mandate and the power of attorney — for machine speed, and wire them into identity. Concretely, the shape I’d bet on:

  • Bind the agent to a verified human. The agent never has standalone standing. Every action it takes carries a cryptographic, provable “acting on behalf of this KYC’d human, under this authority” — a token the bank can verify in the moment, the way it would verify a signature on a PoA.
  • Register scoped mandates, like direct debits but granular. Not “my agent can pay things.” Instead: this category, this ceiling, this velocity, these counterparties. Lodged with the institution, honored by the rails, and — critically — visible to you in one place.
  • Make revocation instant and machine-speed. The kill switch can’t be a support ticket. If a mandate is pulled, the next agent action fails closed, immediately, everywhere.
  • Teach transaction monitoring the difference. Fraud models need a new category: “authorized agent, known mandate, expected pattern,” so your own security stops mistaking your representative for an intruder.
  • Assign liability by making authority explicit and bounded. If the agent acted inside a registered, scoped mandate, responsibility follows the human who set it — and the tight scope is what keeps that from being ruinous. Step outside the mandate, and it’s a security failure the way an unauthorized transaction is today.

That’s the answer to the headline. “KYC for robots” isn’t a new onboarding flow for AIs. It’s verified human identity plus a machine-speed, revocable, scoped mandate, provable on every transaction — the direct-debit guarantee and the power of attorney, rebuilt for a delegate that acts a thousand times a second and can’t be held accountable on its own.

What worries me

Two things, in the spirit of my last piece.

First, that grey zone of “authorized.” We are about to hand millions of people a tireless engine for making authorized payments, in a world where “you authorized it, you own it” is the default rule. If the frameworks don’t evolve, the losses from agents-behaving-badly land squarely on individuals, and the most convenient reading of the law will let everyone else off the hook. That needs fixing before the volume arrives, not after.

Second, whoever builds the agent-identity rails owns a chokepoint most people won’t notice until it’s set. The registry that says “this agent is authorized to act for this human” is enormous power — over competition, over privacy, over access. I’d rather that be an open standard with real oversight than a moat someone digs quietly while we’re all distracted by the demos.

The bank that learns to say yes

For all that, I’m not bearish. I think the institution that figures out how to safely say yes to agents — how to accept a verified, mandated, revocable AI delegate and let it transact — wins a decade. Every one of the four questions is answerable. None of the answers require new AI. They require new plumbing: identity, mandates, revocation, liability. The same conclusion I keep landing on. The capability is already here. The trust is the work.

So, to the builders and the bankers both: before you let an agent spend a customer’s money, make sure you can answer the four questions the money is going to ask. And to everyone else — the same question I left you with last time, now with a price tag attached: what is the one payment you would never let your agent make without looking you in the eye first?

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.