An informal checklist for inspecting an AI agent's identity, operator, scope, data, authority, and review path. KYA is not a regulated, certified, or universally accepted technical standard.
Supports: NIST identifies agent and service identity, authorization, auditability, least privilege, and lifecycle management as key considerations for software and AI agents.
Supports: NIST's AI Risk Management Framework treats governance, transparency, accountability, security, and monitoring as context-specific risk-management work, not a generic badge of trustworthiness.
Supports: OWASP explains that broad authority and weak controls can let model output trigger damaging actions, supporting least privilege, approval, and action-boundary controls.
KYA is an informal due-diligence checklist, not a regulated standard or safety certification.
Identify the accountable operator, service identity, model or workflow version, tools, update owner, and incident path.
Disclose data sources, trust boundaries, requested actions, allowlists, value and rate limits, approvals, logging, pause, revocation, and recovery.
Keep financial, account, and irreversible actions behind independent policy checks and explicit human approval.
A research agent drafts a daily market brief. Its KYA record names the operator, read-only source APIs, input timestamps, model and workflow versions, prompt-injection tests, monthly cost cap, output archive, and incident contact. It cannot connect to a wallet, place an order, or change an account; a human reviews the cited brief before sharing it.
A wallet or smart-account workflow that gives software an explicitly bounded ability to prepare or execute actions. It is an implementation pattern, not an ERC-4337 feature, safety guarantee, or reason to grant a model unrestricted signing authority.
A hardware-backed isolated execution environment that can protect specified code and data under an explicit platform threat model. Its assurance depends on the implementation, attestation policy, measured software, key release, configuration, and remaining hardware and software attack surface.
An organization or governance arrangement that uses blockchain-based rules, proposals, membership, and treasury controls to coordinate decisions or actions. Its voting, execution, transparency, and legal structure vary by design.
A program and its state deployed at a blockchain address, which runs its defined functions when transactions call it.
Explore all our strategic guides about Blockchain to take your operations to the next level.
View all articles