China's payment industry adopts a 'Know Your Agent' rulebook for AI that spends money

Share
China's payment industry adopts a 'Know Your Agent' rulebook for AI that spends money

While the US debate over agentic commerce stays theoretical, the world's largest mobile-payments market just wrote actual rules for it.


China's Payment and Clearing Association has issued the industry's first self-regulation convention for AI-agent payments — headlined by a "Know Your Agent" (KYA) framework that extends know-your-customer checks to the software doing the spending. The convention, released August 24 under People's Bank of China guidance, binds association members handling accounts, transaction processing, acquiring and clearing. It requires institutions to identify and verify every agent plugged into the payments chain, risk-rank them high, medium or low by examining their model provenance, identity markers, permission boundaries, API-call patterns and behavioral signatures, and pass that identity data across the entire payment chain so an agent stays attributable from authorization to settlement.

The core consumer-protection move is a hard line against unauthorized spending: licensed institutions must sign users to explicit authorization agreements spelling out transaction limits, which account gets charged and in what priority order, and expiry dates, then strictly verify both identity and genuine intent to pay before any instruction executes. Institutions must also build a tamper-evident evidence chain recording user authorization, model decisions, payment instructions and risk-control steps at key transaction nodes — the raw material for settling "my agent bought that, not me" disputes. And liability lands squarely on regulated firms: whoever provides the payment service owns account, funds and information security, no matter how autonomous the software layer becomes.

The convention sorts agentic payments into three stages — agent-assisted, autonomous-under-preset-conditions, and autonomous-under-all-conditions — and requires filing with the association plus business-effectiveness, technical-security and ethics assessments, backed by human support, monitoring and rollback mechanisms, before anyone serves the public with the two fully-autonomous tiers.

Our take: this is the first serious regulatory answer to a question everyone else is still pitching on stage — what happens when software, not a person, initiates the charge? KYA is the payments-world equivalent of Botslop-proofing identity: you cannot audit an agent you cannot name. Expect Western regulators to borrow the shape if not the text, because card networks and banks face the identical problem with far less coordination. We previously looked at what happens when agents get unfettered access to real money in Binance lets AI agents trade real money on its exchange — this is the counterweight arriving from the other direction.

What to watch: whether Alipay and WeChat Pay publish KYA implementation timelines, whether the association's assessment regime hardens into formal licensing for autonomous-payment tiers, and whether Visa or Mastercard answer with their own agent-identity standard.

If your AI agent had to pass a KYA check before touching your wallet, would you trust it more — or just opt out entirely? Tell us in the comments.

Read more

Google's Gemini 4 Carbon reportedly matches Opus 5.5 on coding

Google's Gemini 4 Carbon reportedly matches Opus 5.5 on coding

Google hasn't launched Gemini 4 Argon yet, but internal documents suggest a faster follow-up is already in testing — and early impressions put it level with Anthropic's best coding model. Google is testing a Gemini 4 variant called "Carbon" that employees say performs on par with Anthropic's Opus 5.5 on programming tasks. Business Insider, citing internal documents, screenshots, and chats, reports that Google deployed Carbon on Jetski — its internal coding platform — over the past few days, wi

Open Source Radar — October 10: reviewers, skills, and 3D maps

Open Source Radar — October 10: reviewers, skills, and 3D maps

Today's trending board skews practical: tooling that fixes code, teaches agents a framework, and rebuilds 3D scenes from video. Here's what's worth your stars. alibaba/open-code-review (Go, 45.6k stars) — Alibaba open-sourced the code review tool it runs internally, and it shows: a hybrid of deterministic static-analysis pipelines for the known bug classes (null dereferences, thread-safety, XSS, SQL injection) plus an LLM agent that writes precise, line-level comments. It talks to OpenAI- or A

Deep Dive — Congress has the data center numbers, still no bill

Deep Dive — Congress has the data center numbers, still no bill

A yearlong Senate investigation into seven of the biggest data center developers in the country concluded this week that the public case for the AI buildout does not survive the companies' own paperwork — and it landed at the exact moment Congress needs it, because the one federal bill written to make data centers pay for their own power fell three votes short of advancing in the Senate, despite passing the House 417-3. The report, led by the offices of Senators Elizabeth Warren, Chris Van Holle

WorldArena 2.0 puts world models to the test on real robots

WorldArena 2.0 puts world models to the test on real robots

The world-model field has argued for two years about video quality. This week the first full results landed for a benchmark that asks the harder question: can a robot actually use the prediction? WorldArena 2.0's global challenge has closed its leaderboard, and for the first time world models are being graded on physical robots instead of plausible video. The benchmark — designed by a Tsinghua-led consortium with PKU, CMU, Stanford, Princeton and others — extends its 1.0 video scoring along th