The UK’s financial regulator is urging banks to start preparing for a new era of “know your agent” checks, as AI tools begin to make payments and financial decisions on behalf of consumers.

In exclusive interviews, senior Financial Conduct Authority officials said the rise of agentic commerce — where AI agents can shop, transact and manage accounts for users — means banks will need to rethink how they establish trust, consent and accountability in digital finance.

Colin Payne, the FCA’s head of innovation and chair of the Global Financial Innovation Network, said the regulator was seeking to get ahead of the issue rather than wait for consumer harm to emerge.

“We’re active, rather than reactive and passive,” Payne said, adding that the tools for AI agents were already available and “perfectly capable”.

Jane Moore, the FCA’s head of department for payments and digital assets, said stablecoins currently appeared to be the most immediate route for agentic commerce because “they are here right now”.

The FCA’s focus is crystallising around what industry figures are calling know your agent, or KYA: a framework for establishing who an AI agent is acting for, what it is authorised to do, how its actions can be audited, and who is liable when something goes wrong.

Acting with permission

The issue is becoming urgent because customers may soon no longer need to open a banking app, press “confirm” or manually authorise every payment. Instead, an AI agent could manage accounts, compare prices, buy goods, switch services or arrange financial products within parameters set by the customer.

As Anne Boden, founder of Starling Bank, put it: “The next era of banking will not be built around apps, but around agents acting with permission.”

The FCA’s intervention follows a landmark paper co-published by Payne and Nicole Sandler, chief ecosystem officer at Ubyx and head of corporate and regulatory affairs at the Centre for Finance, Innovation and Technology, which set out a regulatory architecture for agentic commerce. Sandler and Payne are expected to publish a further paper at the end of this month detailing how a KYA process could work in practice from a regulatory perspective.

The proposed approach would require banks and payment firms to establish clear parameters of authorisation during onboarding. That could include limits on what an AI agent can buy, how much it can spend, when it can act, whether transactions can be reversed, and how the customer can revoke permission.

The aim is to avoid a world in which AI agents can cause harm without clear recourse for consumers. The New York Times recently reported on a case in which an AI agent cost a start-up founder SFr24,000 ($30,000) while he slept, forcing him to negotiate a settlement.

“People will not trust an AI agent with a blank cheque,” Boden said. “They may trust one with clear limits, audit trails, revocation rights and accountability.”

How the agent can work

The FCA-backed paper recommends five layers of architecture, spanning the way an agent interacts with merchants through to settlement across jurisdictions. At its core is the idea that an AI agent should be subject to a trust framework comparable to the checks already applied to customers and counterparties in finance.

That framework is likely to become more important as programmable forms of money develop. Stablecoins, central bank digital currencies and tokenised deposits could enable cheaper, faster and more traceable transactions, potentially unlocking large amounts of capital currently trapped in inefficient payment and settlement systems.

Combined with digital identification, smart contracts and AI, those technologies could open up forms of commerce that are difficult or impossible with conventional money. Restaurants could automatically restock ingredients as customers pay. An AI assistant could shop for an elderly parent. Personalised insurance, grocery deals or concert tickets could be purchased and paid for automatically on a customer’s behalf.

Agentic commerce is still in its infancy, but is developing quickly. McKinsey has estimated that as much as $5tn could be transacted globally through AI agents by 2030.

Recommended

Recommended article's image

The ‘uncomfortable fiction’ of AI agent compliance

For regulators, two gaps are apparent. The first is legal accountability: who is responsible when an agent acts outside its mandate or causes harm? The second is interoperability: whether agents, payment systems and digital money networks can communicate across technologies and jurisdictions.

Payne said the FCA wanted firms to avoid building closed, incompatible systems. He argued that agentic commerce should develop more like the early internet, based on common protocols rather than isolated private infrastructure.

“The whole point about the internet was it was a protocol that everyone adopted,” he said. “It wasn’t about the commercialisation of independent systems.”

That concern sits within a wider debate about the UK’s future “multi-moneyverse”, in which stablecoins, tokenised deposits and potentially central bank digital money might coexist. Regulators are encouraging firms to build bridges between different forms of money rather than bet everything on one winner.

Sandler said banks should not assume that one form of programmable money will dominate, but instead develop a suite of strategic options.

The market has cautiously welcomed clearer regulatory thinking. The collapse of FTX, which left customers facing billions of dollars in losses, remains an example of how quickly confidence can evaporate when new financial technologies develop without adequate safeguards.

For banks, the FCA’s message is that it is setting out its expectations, and firms need to start building the trust and interoperability architecture that will allow AI agents to act safely on customers’ behalf.