Know Your Business Agent: Why AI Agents Will Need Company Verification Before They Can Do Business

08/05/2026 08:19 · 15 min read
Know Your Business Agent: Why AI Agents Will Need Company Verification Before They Can Do Business

AI agents are evolving from productivity assistants into participants in commercial workflows. They can research suppliers, retrieve company records, negotiate purchases, review invoices and initiate transactions. As enterprises give software greater authority, a new question becomes unavoidable: which legal entity stands behind the AI agent?

For more than two decades, digital trust has centred on verifying people and companies. Know Your Customer processes identify individuals. Know Your Business processes establish whether a legal entity exists, who owns it and whether it presents an unacceptable risk.

Autonomous AI introduces a third participant: software acting on behalf of a person or organisation.

Authenticating that software is important, but it is not sufficient. A recognised agent may still represent the wrong company, operate beyond its authority or rely on outdated corporate information. Enterprises also need to identify the organisation responsible for the agent and retrieve current evidence about that organisation.

The next enterprise trust problem is not simply identifying the AI agent. It is verifying the business behind it.

We describe this emerging layer as Know Your Business Agent, or KYBA: a framework for connecting a commercial AI agent to a verified legal entity, its ownership, its delegated authority and the official evidence supporting that relationship.

AI Agents Are Becoming Economic Actors

The first generation of enterprise generative AI primarily assisted employees. It drafted emails, summarised documents and answered questions. The software could influence a decision, but a human usually executed the action.

Agentic systems are changing that model. An AI agent can receive an objective, select tools, retrieve external information and complete a multi-step workflow with limited intervention.

In enterprise environments, agents are being designed to:

  • Identify and compare suppliers.
  • Enrich company and customer records.
  • Review invoices and payment requests.
  • Perform business-verification checks.
  • Assess financial and ownership information.
  • Request quotations or commercial terms.
  • Interact with other agents and external applications.

These are not merely content-generation tasks. They are operational activities that may affect contracts, payments, access permissions, procurement decisions and regulatory obligations.

Stage 1

KYC

Verify the individual participating in a transaction.

Stage 2

KYB

Verify the legal entity and its ownership.

Stage 3

KYA

Identify the agent and confirm delegated intent.

Stage 4

KYBA

Bind the agent to the verified business responsible for it.

The more authority an agent receives, the more important this binding becomes. A research assistant presents relatively limited risk. An agent permitted to alter supplier details or initiate a large transaction presents a very different risk profile.

Why Agent Identity Alone Is Not Enough

Identity infrastructure can answer important questions:

  • Which agent is making the request?
  • Which person authorised it?
  • Is the agent using valid credentials?
  • What permissions were delegated to it?

Enterprise transactions require additional business context:

  • Which legal entity operates the agent?
  • Is that company active and registered?
  • Who ultimately owns and controls it?
  • Is the agent acting for the parent company or one subsidiary?
  • Is the business financially and operationally eligible?
  • Has anything material changed since the agent was approved?
Agent identity

Establish the software and authority

  • Which agent made the request?
  • Who authorised it?
  • Are its credentials valid?
  • What actions were delegated?
Company intelligence

Establish the accountable organisation

  • Which legal entity does it represent?
  • Is that business active?
  • Who owns and controls it?
  • What corporate evidence supports the claim?
Neither layer approves the action alone. Enterprise policy evaluates both.

Neither layer should make the complete decision independently. Agent identity, company evidence, delegated authority, transaction intent and enterprise policy must be evaluated together.

Agent identity establishes which software is acting. Company intelligence establishes which organisation is accountable.
From identity to accountable autonomous commerceSix connected trust layers moving from human identity through agent identity and authority to a verified legal entity, ownership intelligence and enterprise policy.From identity to accountabilityEach layer answers a different question. None is sufficient on its own.Human identityWho initiatedthe authority?Agent identityWhich softwareis acting?AuthorityWhat may itdo?Legal entityWhich companyis responsible?OwnershipWho ultimatelycontrols it?Policy decisionApprove, limit,escalate or rejectIdentity + authority + corporate evidence = accountable agent activity
The receiving enterprise needs all six layers before a consequential autonomous action can be approved responsibly.

What Is Know Your Business Agent?

KYBA definition

Know Your Business Agent is a proposed framework for verifying the legal entity behind a commercial AI agent and connecting that entity to the agent's identity, authority, ownership and supporting corporate evidence.

KYBA extends conventional business verification into autonomous workflows. It does not treat the agent as an isolated piece of software. It treats the agent as a digital representative of an organisation.

A mature KYBA response could include:

01

Legal identity

Registered name, company number, VAT or tax identifiers, legal form, jurisdiction and status.

02

Corporate ownership

Shareholders, beneficial owners, parent entities and relevant control relationships.

03

Group structure

The immediate entity, subsidiaries, intermediate holdings and ultimate parent.

04

Corporate authority

Directors, officers, authorised representatives and approved corporate domains.

05

Business condition

Filed financials, insolvency indicators, legal events and operational status.

06

Evidence

Official registry, filing reference, retrieval time and a record of the checks performed.

KYBA is not yet an established international standard. It is a category that enterprises, identity providers and company-intelligence platforms will need to define as autonomous systems enter higher-risk commercial workflows.

The Minimum Viable KYBA Standard

A category becomes useful only when buyers can distinguish a genuine implementation from a renamed company lookup. At minimum, a KYBA service should satisfy six requirements.

  • Persistent agent identity.
    The service must identify a durable agent or workload, not merely an anonymous browser session.
  • Exact legal-entity binding.
    The agent must be matched to a legal entity through official registration, tax or other authoritative identifiers.
  • Independent relationship verification.
    The organisation-to-agent connection cannot rely solely on a company name entered during registration.
  • Recorded delegated authority.
    The system must retain the permitted actions, value limits, approving principal and expiry of authority.
  • Source-linked evidence.
    Material company facts must include the registry, filing or authoritative source and the time retrieved.
  • Event-driven reassessment.
    Material changes to the company, authority or agent must trigger review, restriction or revocation.
Optional enhanced modules: UBO and ownership resolution, group-level policy, filed financials, sanctions and PEP screening, behavioural signals, transaction reputation and continuous financial-risk monitoring.

This definition prevents a basic company-name search or a permanent trust badge from being presented as a complete KYBA control.

How KYBA Could Work

Consider an AI procurement agent attempting to onboard a supplier. Before the agent can recommend approval, a KYBA workflow could perform five stages of verification.

1

Identify the agent and its authority

Authenticate the agent, establish who authorised it and retrieve the permissions attached to the request.

2

Resolve the legal entity

Match the company name, registration number, tax identifier, website or application account to the correct official business record.

3

Retrieve ownership and group structure

Identify direct owners, beneficial owners, subsidiaries and the ultimate parent relevant to the commercial relationship.

4

Evaluate business eligibility

Check legal status, financial condition, corporate events and the rules required for the intended action.

5

Return evidence to the policy engine

Provide structured facts, sources and timestamps so the receiving enterprise can approve, restrict, escalate or reject the request.

The company-intelligence provider should not impose one universal definition of trust. It should establish the corporate facts. The receiving enterprise should retain control over its own risk policy.

A Worked KYBA Transaction

Consider a procurement agent requesting enterprise pricing and authority to negotiate a three-year data licence.

Request received

The agent claims to represent ABC Manufacturing and asks to commit the group to a contract worth £310,000.

Agent: procurement-agent-4821 Domain: abc-manufacturing.com Authority limit: £250,000 Requested commitment: £310,000

Checks performed

  1. Authenticate the agent and validate its credential.
  2. Verify the person or enterprise application that delegated authority.
  3. Resolve ABC Manufacturing to the exact registered legal entity.
  4. Confirm that the submitted domain is authorised by that company.
  5. Identify its ultimate parent and relevant subsidiaries.
  6. Check whether another company in the group already has a commercial agreement.
  7. Confirm legal status and retrieve the corporate evidence required by procurement policy.
  8. Compare the requested commitment with the agent's delegated limit.
{
  "agent_verified": true,
  "legal_entity_verified": true,
  "ultimate_parent": "ABC Global Holdings plc",
  "existing_group_agreement": true,
  "delegated_limit_gbp": 250000,
  "requested_commitment_gbp": 310000,
  "decision": "human_approval_required",
  "reasons": [
    "Requested commitment exceeds delegated authority",
    "Existing group agreement requires account-owner review"
  ],
  "evidence": {
    "company_registry_source": "linked",
    "ownership_last_checked": "2026-07-28T07:14:00Z"
  }
}

The important point: KYBA does not declare the company universally trustworthy. It supplies verified corporate facts and authority limits to the enterprise policy engine, which determines the next action.

Enterprise Use Cases for KYBA

AI procurement agents

Verify suppliers, identify the relevant legal entity, map ownership and retrieve financial evidence before the agent recommends onboarding or negotiates terms.

Accounts payable

Confirm that a supplier remains active and that ownership, legal status or authorised payment details have not changed before funds are released.

Banking and KYB

Connect an agent requesting a business account or financial service to the company it represents, its owners and its authorised representatives.

Commercial insurance

Ground automated underwriting in official company identity, filed financials, industry classification and corporate group information.

Supply-chain monitoring

Reassess an agent when the underlying company changes status, directors, ownership, parent group or financial condition.

Enterprise pricing and access

Recognise that an agent represents an existing multinational customer and apply the appropriate agreement, rate limit, data access and purchasing rules.

M&A and corporate research

Allow research agents to resolve targets, follow ownership across jurisdictions and return source-linked corporate structures.

Agent-to-agent transactions

Enable a buyer agent and supplier agent to verify each other's organisations and authority before exchanging terms or executing a transaction.

Who Owns KYBA Inside the Enterprise?

KYBA crosses several established control functions. This is both its value and its adoption risk: everyone may agree the problem matters while no single team owns the budget.

Access and security

IAM: agent credentials, delegated access and revocation.

CISO: authentication, compromise detection and incident response.

Business verification

Compliance and KYB: legal entity, directors, UBO and ownership.

Data governance: provenance, lineage, retention and auditability.

Commercial control

Procurement: supplier eligibility, group agreements and authority.

Finance: transaction limits, payment controls and approval thresholds.

Platform and legal

AI platform team: orchestration, tool access and evidence retrieval.

Legal: contractual effect, corporate authority and liability rules.

Likely initial budget owners

IAM and security are the natural owners for agent access. Payments, procurement or compliance are more likely to fund the first production deployments because they already carry measurable fraud, onboarding and counterparty risk.

Why Official Registry Data Matters

Large language models can reason about corporate information, but they are not the authoritative source of that information.

A model can explain a balance sheet or summarise an ownership structure placed in its context. It cannot independently guarantee that the latest directors, shareholders, financial statements or legal status are correct at the time a decision is made.

Corporate facts change continuously:

  • Companies are incorporated, dissolved and restored.
  • Directors and legal representatives change.
  • Businesses are acquired or moved into new corporate groups.
  • New accounts and financial statements are filed.
  • Ownership and beneficial ownership records are updated.
  • Companies enter insolvency or liquidation.

An autonomous decision should therefore retrieve current evidence rather than rely solely on model memory, web summaries or a static company profile.

The AI should determine what information the workflow needs. The company-intelligence layer should establish what the available official evidence says.

Provenance matters as much as the answer. Enterprise users need to know which source supplied the information, when it was retrieved and whether the conclusion can be reproduced later.

Agent Identity Is Becoming a Standards Problem

KYBA is not emerging in a vacuum. Public standards initiatives are beginning to address secure agent identity, interoperability and authorisation.

NIST is organising an agent-standards initiative

On 17 February 2026, the US National Institute of Standards and Technology launched its AI Agent Standards Initiative. NIST said the programme would foster industry-led standards and open protocols, with specific research into agent security and identity so agents can act securely on behalf of users and interoperate across the digital ecosystem.

OpenID is developing authorisation profiles for agent workflows

On 15 June 2026, the OpenID Foundation's AuthZEN Working Group approved official Working Group Drafts for the Access Request and Approval Profile and MCP Tool Authorization profile. The work addresses cases in which a policy cannot yet authorise an action because approval, consent, delegated authority, attestation or another prerequisite is still required.

IETF participants are documenting agent authentication and delegation

An active July 2026 Internet-Draft on AI Agent Authentication and Authorization describes how existing standards such as OAuth 2.0 and workload-identity architectures could be applied to agent interactions, delegated authority, audit trails and monitoring.

Important standards caveat

IETF Internet-Drafts are works in progress. They may be updated, replaced or abandoned and are not IETF-endorsed standards or RFCs. Their relevance here is evidence of active technical work, not proof of an agreed standard.

These initiatives focus primarily on identifying agents, authenticating workloads and determining whether an action is authorised. They do not independently resolve the adjacent corporate question: which verified legal entity is commercially responsible for the agent?

Emerging standards can carry agent identity and authority. KYBA supplies the verified corporate identity those controls need to become commercially accountable.

The Agent-Trust Market Is Already Taking Shape

Identity providers, payment networks and internet-infrastructure companies are already developing parts of the agent-trust stack.

Experian Agent Trust

Experian announced Agent Trust on 30 April 2026. Its Know Your Agent framework uses Human-to-Agent Binding to create a persistent connection between verified consumers, devices and the agents acting on their behalf.

Experian also described an Agent Trust Token that evaluates identity and transaction risk, supported by an Agent Registry with dynamic trust scoring based on behaviour and other risk signals.

On 24 July 2026, Experian announced that Fastly had joined the ecosystem. The collaboration is intended to allow organisations to evaluate agent identity, delegated authority, intent and payment credentials at the network edge before a request reaches the underlying application.

Visa Trusted Agent Protocol

Visa's Trusted Agent Protocol provides a cryptographic framework through which merchants and site-protection providers can distinguish approved commercial agents from malicious bots or unidentified automated traffic.

The protocol is designed to carry linked, verifiable and time-bound credentials over existing web and API infrastructure, helping merchants recognise the agent and the commercial intent attached to the interaction.

Mastercard Agent Pay

Mastercard has developed Agent Pay around a Know Your Agent trust framework. Mastercard describes an agent as being identified, registered, authenticated and required to demonstrate verified intent before transacting.

These initiatives establish that agents need recognisable identities, permission controls and traceable transaction intent. However, they also expose the adjacent corporate question: which legal entity is accountable for the agent?

The missing layer

Current agent-trust initiatives primarily establish the agent, the consumer or user behind it, and the intended transaction. Enterprise workflows also need verified company identity, ownership and business status.

The Complete Enterprise Agent-Trust Stack

01

Identify

Authenticate the agent and the person, system or organisation authorising it.

02

Bind

Connect the agent to the exact legal entity and its corporate group.

03

Verify

Retrieve ownership, business status, financial and source-linked evidence.

04

Decide

Compare delegated authority and transaction intent with enterprise policy.

05

Monitor

Reassess trust when the agent, authority or underlying company changes.

Over time, these signals could be presented through a machine-readable Business Agent Passport. The credential could include the persistent agent identifier, verified legal entity, relevant parent company, authorised domains, delegated permissions and references to the evidence supporting the binding.

The passport should not provide universal approval. Each receiving organisation would validate the evidence and apply its own policy to the requested action.

What a Business Agent Passport Could Contain

A portable credential could allow an agent to present its identity, legal entity and authority in a consistent format. The receiving enterprise would still validate the underlying evidence and apply its own policy.

Business Agent Passport conceptA conceptual machine-readable business agent credential containing agent identity, verified legal entity, authority, ownership, evidence and monitoring status.Business Agent PassportA portable claim set backed by current, independently verifiable evidenceVerified commercial agentACTIVEAGENT IDLEGAL ENTITYREGISTRATIONAUTHORISED DOMAINSLAST VERIFIEDULTIMATE PARENTAUTHORITY SCOPETRANSACTION LIMITEVIDENCE STATUSMONITORINGagent_8c42fExample Technologies Limited09410808 · United Kingdomexample.com · procurement.example.com28 July 2026 · 07:14 UTCExample Holdings plcResearch · Quote · Negotiate£250,000 · Human approval above limitRegistry and ownership sources linkedCompany, authority and behaviour activePortable identity does not mean universal approval: local enterprise policy remains decisive.
Conceptual credential only. A production passport would require interoperable identity, signing, revocation and evidence-validation standards.

KYBA Establishes Attribution, Not Legal Capacity

Verifying an agent, its user and its company does not automatically prove that the agent can legally bind the organisation to every contract or transaction.

This boundary strengthens rather than weakens the proposition. A credible KYBA service should state precisely which facts it verifies and leave legal and policy decisions with the organisation responsible for them.

Where Global Database Fits

Global Database already provides the company-verification and corporate-evidence capabilities required within a KYBA architecture, including legal entity resolution, ownership, group structures, financials and source-linked registry evidence. It does not currently market a standalone agent-trust layer for issuing persistent agent identities, binding agents cryptographically to organisations, managing delegated permissions or enforcing those permissions.

Its immediate role in the emerging ecosystem is therefore to verify the legal entity behind an agent and supply the corporate evidence used by identity, authorisation and policy-enforcement systems.

Global Database collects company information directly from official registries across more than 200 countries. Its current data estate covers more than 600 million company profiles sourced from over 400 official registries, with source attribution and last-verified timestamps.

Relevant KYBA outputs can include:

  • Exact legal entity and registration status.
  • Company registration, VAT, tax, EIN and LEI identifiers.
  • Directors, officers and authorised representatives.
  • Shareholders and beneficial ownership.
  • Parent companies, subsidiaries and group structures.
  • Filed financial statements and financial indicators.
  • Registry source, filing reference and retrieval timestamp.
  • Monitoring for changes in corporate status and control.

These capabilities can be consumed through several delivery models, including Regis, the Regis API and the Global Database MCP server.

RegisNatural-language company research for compliance, risk and commercial teams.
Regis APIComplex agent questions requiring planning, entity resolution or ownership traversal.
Structured APIsDeterministic checks requiring defined company, financial or ownership fields.
MCP and connectorsVerified company-data tools inside Claude, ChatGPT and internal AI systems.
Bulk data feedsHigh-volume processing, local data environments and recurring enrichment.

The strongest positioning is not that Global Database is a database agents can search. It is that Global Database can become the corporate evidence layer used to establish which legal entity stands behind a commercial agent.

Agent-identity providers can verify the software. Global Database can verify the company behind it.

How KYBA Could Fail

KYBA will not become credible enterprise infrastructure if it is reduced to a badge, a self-declared company name or an unexplained trust score.

Incorrect entity matching

Trading names, similar company names and complex groups can cause an agent to be linked to the wrong legal entity.

Requirement: Resolve entities using official identifiers and multiple matching signals.

Self-attested business identity

An agent operator may claim to represent a recognised brand, parent company or corporate domain without authority.

Requirement: Independently verify the business and its authorised digital properties.

Stale corporate evidence

A valid company may later change ownership, enter insolvency or revoke the authority behind the agent.

Requirement: Monitor material corporate events and reassess trust continuously.

Opaque trust scoring

A score may hide which evidence was used, how recent it is or why an agent was restricted.

Requirement: Expose the facts, sources and policy factors behind the result.

Ambiguous delegated authority

A legitimate employee may authorise research but not contract negotiation, payment or further delegation.

Requirement: Make authority explicit, narrowly scoped, time-bound and revocable.

Provider concentration

One provider controlling agent identity, company evidence, trust scoring and enforcement creates dependency and limited explainability.

Requirement: Keep the trust stack modular and allow independent evidence validation.

KYBA should also avoid implying that verification guarantees good behaviour. A registered and financially healthy business can still breach a contract or misuse an agent.

Verification reduces uncertainty and establishes accountability. It does not eliminate commercial risk.

A Practical KYBA Adoption Roadmap

Most organisations do not need to build the complete future trust stack immediately. They do need foundations that avoid anonymous agents, unverified company claims and untraceable authority.

Phase 1 · Identify

Make consequential agents visible

  • Assign persistent agent identities.
  • Record the person or system that authorised each agent.
  • Log high-impact actions and tool calls.
  • Define when human review is mandatory.
Phase 2 · Bind

Connect agents to legal entities

  • Resolve the exact operating company.
  • Verify registration and authorised domains.
  • Attach ownership and group evidence.
  • Record delegated scope, limits and expiry.
Phase 3 · Enforce

Apply continuous policy

  • Use risk-based verification depth.
  • Escalate requests above delegated limits.
  • Monitor changes to company and authority.
  • Restrict or revoke access automatically.

Start with one measurable workflow

The best first deployment is not a universal agent registry. It is a high-value process with an existing control problem, such as supplier onboarding, payment-detail changes, enterprise API access or autonomous purchasing above a defined threshold.

What KYBA Could Look Like Over the Next Five Years

Adoption is likely to begin in high-value workflows where enterprises already perform company verification: payments, supplier onboarding, financial services, insurance, credit risk and regulated data access.

Persistent agent identities

Commercial agents will require durable, revocable identifiers that can be recognised across platforms and transactions.

Machine-readable company credentials

Company registration, ownership, group relationships, authorised domains and source evidence will increasingly be delivered in standardised formats that policy engines can interpret.

Risk-based verification

A low-risk information request may require only agent authentication and active company status. A high-value transaction may require full ownership, financial, authority and evidence checks.

Dynamic access and pricing

A verified business identity could determine which data an agent may access, whether enterprise pricing applies, which payment terms are available and when human approval is required.

Mutual agent verification

In agent-to-agent commerce, buyer and supplier agents will need to verify each other's identities, businesses, authority and intended actions.

Continuous corporate monitoring

Agent behaviour and the underlying company will be monitored together. Changes in ownership, corporate status, financial condition or the authorising relationship could automatically alter the agent's permissions.

Every Commercial Agent Will Need a Verifiable Business Behind It

AI agents will become faster, more capable and more autonomous. That progress will increase the value they create, but it will also increase the consequences of unauthorised or incorrectly attributed actions.

Enterprises will need more than technical authentication. They will need to establish:

  • Which agent acted.
  • Who authorised it.
  • Which legal entity is responsible.
  • Who owns and controls that entity.
  • What the agent is permitted to do.
  • Which evidence supports the decision.

Know Your Business Agent provides a framework for connecting those elements.

It does not replace KYC, KYB, cybersecurity or delegated-authority controls. It binds them to a verified corporate identity so that an autonomous action can be traced back to the organisation responsible for it.

The market is already developing agent registries, agent credentials, transaction-intent protocols and edge enforcement. The remaining opportunity is to ensure that the company behind the agent is not treated as an unverified profile field.

In autonomous commerce, every agent will need an identity. Every commercial agent will also need a verified business behind it.

Know Your Business Agent FAQs

1. What is Know Your Business Agent?

Know Your Business Agent, or KYBA, is a proposed framework for connecting an AI agent to the verified legal entity responsible for it. It combines agent identity and delegated authority with company registration, ownership, financial and source evidence.

2. What is the difference between KYA and KYBA?

Know Your Agent focuses on identifying and authenticating an AI agent, the person behind it and its intended action. Know Your Business Agent adds the corporate layer by verifying the exact legal entity the agent represents and the organisation responsible for its commercial activity.

3. Why do AI agents need company verification?

AI agents may request pricing, onboard suppliers, access restricted information, negotiate terms or initiate transactions. The receiving enterprise needs to know whether the agent represents a genuine, active and eligible company before allowing those actions.

4. How is KYBA different from traditional KYB?

Traditional KYB verifies a company during onboarding or a periodic review. KYBA applies company verification to autonomous software, connects the verified company to a specific agent and reassesses the relationship when the agent, authority or business changes.

5. What information is needed for KYBA verification?

A KYBA check may include the company's legal name, registration number, jurisdiction, legal status, tax identifiers, directors, shareholders, beneficial owners, ultimate parent, group structure, financial information, authorised domains and official source evidence.

6. What is a Business Agent Passport?

A Business Agent Passport is a potential machine-readable credential that connects an agent identifier to a verified legal entity, delegated permissions, authorised applications and references to the corporate evidence supporting the relationship.

7. Is KYC enough to trust an AI agent?

No. KYC may verify the person authorising the agent, but it does not necessarily establish which company the agent represents or whether that person has authority to commit the company to the requested action.

8. How does official registry data support AI agent verification?

Official registries provide evidence of company incorporation, status, identifiers, directors, filings and, where available, ownership. A company-intelligence platform can normalise these records, resolve the correct entity and return the evidence to an enterprise policy engine.

9. How can a company integrate KYBA into an AI workflow?

Companies can use structured company-data APIs for deterministic checks, the Regis API for adaptive natural-language retrieval, MCP or AI connectors for agent tools, and bulk data feeds for high-volume or locally controlled deployments.

10. Is KYBA currently a regulatory requirement?

KYBA is not currently a universal regulatory standard. It is an emerging trust model whose underlying controls relate to existing obligations around business verification, delegated authority, fraud prevention, payment security, risk management and auditability.