← Back to blog
NewsAbout 6 min read

China Started Writing Rules for Agent Identity, and the Question Is Who the Agent Works For

Published Oct 4, 2026
China Started Writing Rules for Agent Identity, and the Question Is Who the Agent Works For

When a software agent books your flight, pays a supplier or negotiates with another company's agent, four questions appear at once. Whose agent is it? Who authorised it? What is it allowed to do? And if it goes wrong, who carries the liability?

At the 2026 Inclusion conference in Shanghai in September, Ant Digital Technologies and more than ten partner organisations launched the drafting of a national standardisation guiding document on agent identity management for blockchain and distributed ledger technology. The document proposes a blockchain-based model for agent identity across the whole chain: overall architecture, identity identifiers, identity establishment, verification mechanisms, cross-chain interoperability and interface specifications. It is described as the first systematic proposal of its kind in China. Ant Group released a trusted agent identity solution and a product built on the same idea at the same event.

From KYC to KYA

The shorthand the industry has settled on is KYA, Know Your Agent, and it sits next to two older acronyms. KYC, know your customer, and KYB, know your business, were built for transactions where the parties were people or companies. Ant Group's chief executive, Han Xinyi, put the gap plainly: now that agents transact, the system needs to know the agent as well.

Mastercard's chief product officer, Jorn Lambert, offered the historical analogy. Twenty-five years ago, typing card details into an unfamiliar website felt reckless. E-commerce became normal not because payment technology alone improved but because identity verification, transaction rules, dispute handling and consumer protection were built around it. Agent commerce is at roughly the same stage, he argued, and needs roughly the same scaffolding.

China's Payment and Clearing Association has already issued a self-regulatory convention on agent payment applications, telling member institutions to explore a know-your-agent mechanism built on top of existing KYC processes. That is a softer instrument than a national standard, and it arrived first, which is usually how these sequences go: an industry convention establishes the vocabulary, and a standard turns the vocabulary into requirements.

The liability chain is the hard part

Identity is the easy half. The difficult half is attribution.

Han described the problem as a chain that has to be traceable. When an agent transaction produces a bad outcome, was the authorisation wrong, did the user's own agent misunderstand the instruction, was information lost in transfer, or did the merchant's system fail to execute? Without a record that can be replayed, none of those answers is available, and the dispute defaults to whoever has the better lawyer.

The other problem Han raised is trust between agents. If your agent is negotiating with a merchant's agent, what makes your agent believe the merchant's agent is competent and honest? Capability trust between machines is a different question from human trust in a brand, and no existing consumer-protection framework covers it.

Ant's answer draws on assets it has held for a decade. The company has spent eleven years on blockchain, holds more than 6,000 blockchain patents, and its Alipay AI payment product has passed 100 million payments and 100 million users. The chief executive of Ant Digital Technologies, Zhao Wenbiao, put the combination as a division of labour: AI creates intelligence, blockchain creates trust. A decentralised, verifiable ledger can issue an agent an identifier that is unique and checkable, and can tie that identifier to a responsible party and to a specific running instance. A technical lead at the company described the pairing as automating two different things, trust and intelligence, which is what lets the transaction close.

What an agent identity record would have to contain

The scope of the document suggests the shape of the answer. An agent needs an identifier that is unique and portable, a link to the principal it acts for, a statement of the permissions it holds, and a way for a third party to verify all three without calling the issuer. Cross-chain interoperability is in the document because an identity that works inside one ledger is a vendor lock rather than infrastructure.

That last requirement is the one that will decide adoption. If a bank's agent can verify a merchant's agent because both sit on the same chain, the system is a closed club. If verification works across chains and across borders, it becomes something closer to a certificate authority for machines. Ant's positioning, and the reason a payments company is the one pushing the standard, is the second version.

There is also a data-protection question the outside reader cannot answer. A verifiable record of what an agent was authorised to do is, in aggregate, a record of what a company's automation does all day. Ant's answer is that privacy computing sits alongside blockchain and digital identity in the same stack, which is a plausible design and not yet a demonstrated one.

Standards arrive before markets

The same conference produced a second artefact in the same direction. The Shanghai Advanced Institute of Finance's think tank and Ant Group's research institute published a report on ten trends in enterprise agent commerce, arguing that competition is shifting away from raw model capability and toward delivery channels, orchestration governance and commercial systems. The claim underneath it is that model capability is converging, so the differentiator becomes where the agent is delivered and how it is supervised.

Ant Digital Technologies itself runs an "agent super factory" with hundreds of skills, digital expert templates and connectors, aimed at letting companies mass-produce agents and have several of them work toward one business goal. The company's example is a retail banking team that used to pull data from several systems and apply staff judgement to decide which customer gets which product; the platform version builds that reasoning into an agent.

Ant's own growth suggests the bet is not speculative. The business is growing close to 50 percent a year, and the company says it now measures itself on AI value delivered, AI-native application revenue and platform ARR rather than on headcount or licence sales. It has also created a field team that sits with customers through the whole process of finding a place to use agents and building the first one, which is the consulting work that usually decides whether a platform gets renewed.

The instructive part for anyone outside China is the order of operations. A standard, an industry convention and a commercial product all appeared within weeks of each other, before agent-to-agent payments are common. Whoever writes the identity layer also decides what an agent is allowed to be, and that decision is easier to make before the transactions exist than after. The open question is whether a blockchain-based identity scheme becomes the basis for cross-border agent commerce, or stays a domestic system that agents have to translate out of when they leave. On the current timeline, the standard will be drafted long before the first transaction that needs it.

Related articles