Fleur de Roos
KYC Was Designed for Humans and Corporations: Agentic AI May Force Us to Invent a Third Category
KYC Was Designed for Humans and Corporations: Agentic AI May Force Us to Invent a Third Category
One of the most interesting unanswered questions in artificial intelligence is not technical. It’s legal.
For centuries, modern legal systems have operated on a remarkably stable assumption that every participant in economic life is either a natural person or a legal person. The distinction underpins everything from banking and taxation to contracts and liability. Know Your Customer (KYC) regulations, in particular, are built around this binary architecture. Regulators ask a simple question: who is behind the transaction?
Increasingly, the answer may be neither.
The rise of agentic AI is forcing policymakers, lawyers, banks, and technologists to confront a category of actor that exists awkwardly between human and corporation. Autonomous agents can already research, negotiate, book services, execute payments, and manage workflows with limited human intervention. What they cannot do, at least formally, is exist within the legal identity frameworks that govern the digital economy.
That tension became more tangible this year when PhotonPay and Mastercard announced a live demonstration of an autonomous AI agent completing a real-world payment transaction on behalf of a user. In the test, an AI agent independently selected and booked transportation, then executed the payment through Mastercard's emerging agentic payment infrastructure. The demonstration was significant not because of the payment itself, but because it revealed a deeper question: if an AI agent can transact, what exactly is it?
Europe may be approaching that question from two directions at once.
On one track sits the EU AI Act, a sweeping regulatory framework that explicitly recognizes increasingly autonomous AI systems and attempts to govern their risks. On another, sits eIDAS 2.0 and the forthcoming European Digital Identity Wallet, an ambitious effort to create trusted digital identity infrastructure across the European Union. Yet these two frameworks expose something interesting.
Under Europe's identity architecture, electronic identity remains tied to natural persons, legal persons, or humans acting on behalf of them. Meanwhile, the AI Act regulates autonomous systems without granting them legal personality. The result is a peculiar grey zone in which AI agents may soon become operational actors in the economy without becoming recognised legal actors.
The implications for this extend far beyond payments.
Imagine an AI agent applying for a financial service, signing procurement documents, accessing regulated infrastructure, or negotiating contracts with another AI agent. Is it merely software? A delegated representative? An extension of a corporation? A new form of regulated electronic agent? Existing law offers incomplete answers.
Legal scholars have wrestled with similar questions for years. Discussions around autonomous systems increasingly resemble older debates about corporations themselves. After all, the corporation was once a novel legal invention. It was a mechanism created because economic reality demanded a way for organizations to own assets, enter contracts, and bear liability independently of their founders.
Some academics have even explored whether robots deserve a new legal status.
Researchers and legal scholars have argued that highly autonomous machines may eventually require frameworks that sit somewhere between property and personhood. Others reject the idea entirely, warning that granting legal status to machines could obscure human accountability rather than clarify it. The central concern remains liability. And by that, I mean, when a robot or AI system causes harm, society must still identify someone, or something, to hold responsible.
The debate is becoming less theoretical with every passing month. Courts across the United States, Europe, and Asia are grappling with questions involving autonomous vehicles, algorithmic decision-making, AI-generated content, and robotic systems. The challenge goes beyond merely determining what AI can do, to determining who answers for it when it does something.
Perhaps the most revealing sign of where this conversation is heading comes from the identity community itself.
Researchers are already developing identity frameworks specifically for AI agents, arguing that existing authentication systems were designed for humans and traditional machines rather than autonomous actors capable of creating, managing, and proving their own identities. The emerging field is not asking whether AI agents will participate in the digital economy. Instead, it is asking how they will be identified once they do.
For decades, KYC has been a process of verifying people and corporations; however, the next frontier may not be verifying identity at all. It may be defining the nature of the entity being verified.
The coming debate is unlikely to be about whether AI should have rights.
It will more likely revolve around a more practical question which is: what legal category should we assign to systems that can act, transact, negotiate, and create consequences in the world without quite being human and without quite being a company?
The twentieth century built institutions for citizens and corporations. The twenty-first may discover that those are no longer the only participants in economic life.
One of the most interesting unanswered questions in artificial intelligence is not technical. It’s legal.
For centuries, modern legal systems have operated on a remarkably stable assumption that every participant in economic life is either a natural person or a legal person. The distinction underpins everything from banking and taxation to contracts and liability. Know Your Customer (KYC) regulations, in particular, are built around this binary architecture. Regulators ask a simple question: who is behind the transaction?
Increasingly, the answer may be neither.
The rise of agentic AI is forcing policymakers, lawyers, banks, and technologists to confront a category of actor that exists awkwardly between human and corporation. Autonomous agents can already research, negotiate, book services, execute payments, and manage workflows with limited human intervention. What they cannot do, at least formally, is exist within the legal identity frameworks that govern the digital economy.
That tension became more tangible this year when PhotonPay and Mastercard announced a live demonstration of an autonomous AI agent completing a real-world payment transaction on behalf of a user. In the test, an AI agent independently selected and booked transportation, then executed the payment through Mastercard's emerging agentic payment infrastructure. The demonstration was significant not because of the payment itself, but because it revealed a deeper question: if an AI agent can transact, what exactly is it?
Europe may be approaching that question from two directions at once.
On one track sits the EU AI Act, a sweeping regulatory framework that explicitly recognizes increasingly autonomous AI systems and attempts to govern their risks. On another, sits eIDAS 2.0 and the forthcoming European Digital Identity Wallet, an ambitious effort to create trusted digital identity infrastructure across the European Union. Yet these two frameworks expose something interesting.
Under Europe's identity architecture, electronic identity remains tied to natural persons, legal persons, or humans acting on behalf of them. Meanwhile, the AI Act regulates autonomous systems without granting them legal personality. The result is a peculiar grey zone in which AI agents may soon become operational actors in the economy without becoming recognised legal actors.
The implications for this extend far beyond payments.
Imagine an AI agent applying for a financial service, signing procurement documents, accessing regulated infrastructure, or negotiating contracts with another AI agent. Is it merely software? A delegated representative? An extension of a corporation? A new form of regulated electronic agent? Existing law offers incomplete answers.
Legal scholars have wrestled with similar questions for years. Discussions around autonomous systems increasingly resemble older debates about corporations themselves. After all, the corporation was once a novel legal invention. It was a mechanism created because economic reality demanded a way for organizations to own assets, enter contracts, and bear liability independently of their founders.
Some academics have even explored whether robots deserve a new legal status.
Researchers and legal scholars have argued that highly autonomous machines may eventually require frameworks that sit somewhere between property and personhood. Others reject the idea entirely, warning that granting legal status to machines could obscure human accountability rather than clarify it. The central concern remains liability. And by that, I mean, when a robot or AI system causes harm, society must still identify someone, or something, to hold responsible.
The debate is becoming less theoretical with every passing month. Courts across the United States, Europe, and Asia are grappling with questions involving autonomous vehicles, algorithmic decision-making, AI-generated content, and robotic systems. The challenge goes beyond merely determining what AI can do, to determining who answers for it when it does something.
Perhaps the most revealing sign of where this conversation is heading comes from the identity community itself.
Researchers are already developing identity frameworks specifically for AI agents, arguing that existing authentication systems were designed for humans and traditional machines rather than autonomous actors capable of creating, managing, and proving their own identities. The emerging field is not asking whether AI agents will participate in the digital economy. Instead, it is asking how they will be identified once they do.
For decades, KYC has been a process of verifying people and corporations; however, the next frontier may not be verifying identity at all. It may be defining the nature of the entity being verified.
The coming debate is unlikely to be about whether AI should have rights.
It will more likely revolve around a more practical question which is: what legal category should we assign to systems that can act, transact, negotiate, and create consequences in the world without quite being human and without quite being a company?
The twentieth century built institutions for citizens and corporations. The twenty-first may discover that those are no longer the only participants in economic life.
Solutions
Solutions
Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.
Copyright © 2026 - Fourthline B.V. - All rights reserved.
Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.
Copyright © 2026 - Fourthline B.V. - All rights reserved.