Know Your Agent: Verifying AI Agents Without Losing Accountability
Updated September 30, 2026: the AgentRegistry.sol extension no longer has a Q3 2026 date; no date is committed yet. Also removed an unsupported "first" claim.
Agentic DeFi is arriving: autonomous market makers, AI portfolio managers, on-chain agents holding real budgets. Every protocol that lets an agent touch real capital will need to answer the same question: is this a trusted, bounded agent, or an anonymous script? Today, there's no composable on-chain compliance rail for that distinction.
What KYA actually verifies
KYA (Know Your Agent) is KUMPLY's Tier 5 attestation. It doesn't try to identify the agent itself as a legal person - agents aren't legal persons. What it verifies is the chain of accountability behind it: a Tier 5 credential is tied to a Tier 4 (KYB) verified owner, a business or individual that already went through business verification. If the agent acts, the accountability chains upward to that owner. That's the actual mechanism: not "trust the agent," but "know who answers for the agent."
What's live today
The core mechanism is live: any contract can check an address's tier and expiry with a single verify(address) call, or pay for a stronger read via checkCompliance(address), a payable function that's fully implemented in AttestationStore on both Fuji and Mainnet C-Chain. That fee is currently set to zero on both networks. It's real, tested code, not a promise - but it's priced at zero while we're in beta, not because the metering doesn't exist yet.
A concrete example of the mechanism, illustrative, not a real transaction: an agent tries to execute a $50,000 trade. Before letting it through, the protocol's contract calls verify(agentAddress). The response returns the agent's tier, its expiry, and, through the Tier 4 credential it's tied to, who the verified owner behind it is. Tier 5 and unexpired: the trade proceeds, and the protocol already knows who's accountable if it doesn't go as planned. Missing, expired, or below Tier 5: the protocol rejects the trade or falls back to a human signer, before any funds move.
You can see the mechanism in action without a wallet: the interactive demo runs three scenarios against real attestations on the network of your choice, including an agent marketplace scenario - the exact context where a Tier 5 check would decide whether an agent can execute.
What's roadmap, not shipped
Two things worth being precise about, since it's easy to round "planned" up to "live" when describing your own roadmap. First, deeper agent-specific verification - model fingerprinting, behavior bounds, liveness checks - lives in a planned AgentRegistry.sol extension, with no date committed yet. It doesn't exist in the contracts yet. Second, per-agent payment standards like x402 are part of where this is heading, not something running in production today. Tier 5 attestation and the compliance check are real; automated micropayment rails on top of it are still ahead of us.
Why "first" needs a qualifier
KUMPLY isn't the first project building agent identity on Avalanche. Kite AI's Agent Passport, live on its own Avalanche L1, also gives agents a persistent cryptographic identity - by design pseudonymous, with no KYB behind it. What KUMPLY focuses on instead: tying that on-chain identity to a KYB-verified, legally accountable owner, inside the same attestation system that already handles KYC and KYB - not agent identity in general.
That distinction is the point. An agent with a pseudonymous passport can prove it's consistently the same agent. A Tier 5 agent can prove that, and prove who's legally on the hook if it isn't.
One more disambiguation, since the acronym is shared: KUMPLY's KYA is not KYA-OS (github.com/decentralized-identity/kya-os-mcp), a separate identity protocol for MCP agents donated to the Decentralized Identity Foundation. Different standard, different governance, no relationship between the two beyond the name.