---
title: "Agent compliance"
description: "The controls that keep AI-agent payments inside a compliance program — a verified principal, screening on every instruction, and a record for every transfer."
reviewedBy: "Krisan Nichani, Chief Compliance Officer"
updated: "August 2026"
canonical: "https://infinite.net/learn/glossary/agent-compliance"
---

# Agent compliance

Agent compliance is the application of a payments compliance program to transactions initiated by AI agents. The obligations do not change because software sent the money: the business behind the agent is verified through KYB, every instruction runs sanctions screening and transaction monitoring, flagged payments stop for human review, and each transfer closes with a record of who initiated it, under what authority, and what was checked. What changes is enforcement — controls have to bind at the account and platform layer, because an agent cannot be trained, only bounded.

Agents stress a compliance program in specific ways: they transact at volumes and hours no reviewer can shadow, they act on inference rather than judgment, and when an examiner asks who authorized a payment, “the model decided” is not an answer. The program maps onto them cleanly once identity is anchored — the agent acts for a verified business, its authority is a recorded grant, screening and monitoring run per instruction before settlement, breaches escalate to a person, and the case file assembles itself per payment instead of being reconstructed from application logs.

On Infinite there is no separate agent lane: an instruction from an API key runs the same counterparty screening and transaction monitoring as one from a person, flagged payments stop before funds move, and Infinite Agents assemble the case so a human analyst makes every compliance decision.

## Frequently asked questions

### Do AI agents go through KYC?

No — KYC and KYB verify legal persons, and an agent is not one. Verification applies to the business or individual behind the agent; the agent then acts under that verified status with its own revocable credentials. [Know Your Customer (KYC)](https://infinite.net/learn/glossary/know-your-customer.md)

### Who is responsible when an AI agent breaks a compliance rule?

The business that deployed it. Delegating execution to software does not delegate liability — regulators look through the agent to the verified party behind it, which owns the account, the authority it granted, and the obligation to explain every payment.

### What audit trail should an agent-initiated payment leave?

The same one a human payment leaves, produced automatically: the request that created it, the counterparty’s screening state, the monitoring result, the route, and settlement confirmation — assembled so a reviewer can answer why the payment moved without forensics on application logs. [Infinite Agents](https://infinite.net/compliance/ai)

## Where it fits on Infinite

- [Stablecoin compliance](https://infinite.net/use-cases/global-compliance)
- [Compliance AI](https://infinite.net/compliance/ai)
- [Agentic Commerce](https://infinite.net/use-cases/agentic-commerce)

## See also

- [Know Your Business (KYB)](https://infinite.net/learn/glossary/know-your-business.md)
- [Sanctions screening](https://infinite.net/learn/glossary/sanctions-screening.md)
- [Human-in-the-loop approval](https://infinite.net/learn/glossary/human-in-the-loop-approval.md)
