CBSRCross-Border Stablecoin Register · the evidence layer for agentic finance

KYA · Know Your Agent  ·  working framework v0.1, open for comment

KYC asks who the customer is. KYB asks who the business is. Nobody asks who the agent is.

When an autonomous system initiates a payment, the existing obligation framework looks for a person or a legal entity to attach it to. Usually one is found. But at the moment of attachment everything about the system itself — what it was authorized to do, where its capability ends, which version of which rule it was reading — is discarded. Those are precisely the facts that turn out to matter afterwards.

4 questions  ·  4 assurance levels  ·  claim_class = proposed_framework  ·  not part of the citable subset  ·  comments to the issue tracker


what this page is, before anything else

This is not law, not a standard, and not a statement about any regime in force. The rest of this site states what is already written in the instruments, each claim pinpointed and enforced by the build. This page is different. It is a proposal about the shape the questions should take when the rules do arrive.

It is labelled with the same discipline as everything else here: claim_class = proposed_framework, which means citable_law() will never return it. Read it as a working draft in the open. It can be argued with, and it should be.


why the existing questions do not reach

KYC and KYB work because the thing they ask about holds still. A person's identity does not change between two transactions, and a company's authority is written into its constitution and its licence. An autonomous system satisfies neither condition.

What the existing framework assumes
  • 01The actor is persistent, and is the same actor between two interactions.
  • 02Authority is written down in advance, and changes to it leave a trace.
  • 03Capability follows from identity: a payments firm does not suddenly start providing custody.
  • 04When something goes wrong, the actor can be asked what it was working from, and the answer is admissible.
What an autonomous system is actually like
  • 01It may be a process re-instantiated on every call, over weights that are themselves still moving.
  • 02Its actual authority often lives in a prompt, and a prompt has no version and leaves no trace.
  • 03Its capability is set by whichever tools happen to be mounted, and can change mid-session.
  • 04Asked afterwards what it was working from, it produces a fluent reconstruction, which is not a record.

So KYA is not the KYC form with the subject swapped. It asks four questions that do not need asking of a person or a company, and that have to be answered afresh every time of an autonomous system.


The four questions that must be answerable before an agent moves money

The four are orthogonal to one another, on the same design as the register's three evidence axes: collapsing them into a single trustworthiness score destroys four different judgments at once.

Q1

Identity — is this the same agent?

Not what it is called, but whether the thing that made yesterday's transaction and the thing making today's are the same thing. Human identity is persistent by nature; an agent's persistence has to be constructed: a stable identifier bound to a specific model version, tool set, and configuration, which leaves a trace when any of them changes.

The test: can someone point at a transaction afterwards and name the configuration that executed it, in a form a third party can verify.

Q2

Authorization — who permitted this, and how far does it go?

The chain of authority has to trace back to a person or a legal entity that carries the liability, with every hop explicit. Today most agents' real authority lives in a natural-language prompt, which cannot be versioned, cannot be audited, and can be rewritten by later input.

The test: authority is a structured statement readable before execution and checkable after it — limits, counterparties, jurisdictions, time window — not text that a later message can overwrite.

Q3

Capability — what it can do, and what it cannot

Capability is not authority. An agent may be authorized to make cross-border payments while holding a tool that reaches a custody interface directly. Or it may be authorized broadly while the regulatory data it reads covers three jurisdictions. The second is the more dangerous, because it does not fail loudly: outside its coverage it produces a fluent answer anyway.

The test: the boundary is declared, and the behaviour at the boundary is refusal rather than extrapolation. This is the same commitment as the register publishing its verification backlog.

Q4

Accountability — can what it read be reconstructed afterwards?

The hardest of the four and the most often skipped. A supervisory enquiry happens months later, by which time the model has been updated, the prompt has been edited, and the regulation itself may have moved. If the rules the agent read were not pinned, the question of what it read can never be answered.

The test: each execution records the source, the version, and the as_of date of the rules it relied on, and that version can be fetched back. This is why the register carries a DOI per release — not for scholarly manners, but so that this question has an answer.


L1 – L4: the same questions, answered to what depth

The levels are not a score for how good an agent is. They state how much about an agent can be verified by a third party. A highly capable system that only reaches L1 is not a more dangerous agent; it is an unsupervisable one. Those are different claims, and conflating them leads somewhere wrong.

L1asserted

The agent states what it is

Identity, authority and capability exist as self-declaration with no external anchor. Most financial agents in production today sit here, including many that believe otherwise.

Answers: part of Q1. Does not answer: the extent of Q2, the boundary in Q3, any of Q4.

L2bound

Identity is bound to a responsible party

The agent's identifier traces to a named person or legal entity, and authority is expressed structurally rather than as a prompt. From here on, when something goes wrong there is at least someone to ask.

Answers: Q1 and Q2. Does not answer: behaviour at the Q3 boundary, or the Q4 reconstruction.

L3bounded

The capability boundary is explicit, and refusal is the behaviour at it

The agent knows where its regulatory data stops, and outside that it declines rather than extrapolates. This level requires the data it reads to be able to state its own gaps, which is why the register publishes its backlog as queryable data rather than as a disclaimer.

Answers: Q1, Q2, Q3. Does not answer: Q4, months later.

L4reconstructible

The rules behind each execution can be fetched back unchanged

The execution record carries the source, the version and the as_of of the rules relied on, and that version is pinned in an immutable archive. Eighteen months later a supervisor can fetch exactly that copy and judge whether the agent's action was reasonable then, rather than whether its account of itself is persuasive now.

Answers: all four. This level is technically available today. What is missing is not capability but anyone requiring it.

where this register sits in the framework

CBSR is not an agent and does not supply identity or authority. It solves half of L3 and half of L4: it gives an agent regulatory data that can state its own coverage boundary (L3), and it makes every read carry a version and a DOI that can be fetched back unchanged (L4). Q1 and Q2 lie entirely outside this project and need someone else.


what this framework does not claim

As with the SDG mapping elsewhere on this site, this is the most important section on the page. A framework that cannot state its own boundary is in breach of the requirement it sets out in Q3.

Not a standard

No standards body has adopted it and it has not been submitted to one. It is a working draft in the open, version 0.1.

Not a statement of law

No jurisdiction currently imposes anything corresponding to L1–L4 on autonomous systems. This page describes a gap, not an obligation.

Not an implementation

There is no reference implementation, protocol, or schema for KYA here. There are four questions, four levels, and an argument for why they should be kept apart.

Not claimed to be exhaustive

Four is the smallest set that currently holds up. If a fifth question is equally orthogonal and equally unnecessary to ask of a person, it belongs here.