artificial-intelligence

Know Your Agent - Where Does Accountability Lie?

The question raised at a media round-table, was not whether AI agents will enter banking. It was whether anyone in the room would let one near their live account.

Sumsub AI Agent Round Table

Sumsub AI Agent Round Table

Share

The Rise of Agentic Concerns

Advertisement

When machines start checking machines, or when AI agents start giving instructions autonomously to other agents, trust is what holds the process together.  However trust is the product of effective guardrails, and South Africa does not yet have a name for who owns the mistake when it happens.

In a Sandton hotel dining room this week, the question raised at a media round-table, was not whether AI agents will enter banking. It was whether anyone in the room would let one near their live account.

Know Your Agent. Every payment-capable agent is bound to a verified principal, a scope — payees, limits, merchants, hours — and a kill switch. Money movement without a recorded mandate should not clear.

Sumsub’s media luncheon, "Closing the Trust Gap", has already been framed elsewhere, as a debate about accountability when software stops advising and starts acting. That coverage is fair. 

There is a sharper story sitting underneath that is uglier, and perhaps more useful. The same architecture that might book a flight to Nairobi is already being used to invent people. The next verification problem is not “is this face real?” It is “is the system acting in this customer’s name a person, a helper, or a criminal?” Sumsub’s own technologists now talk about agents verifying other agents. That is not a slogan. It is an admission that human identity has left the body.

AI Shift in Focus

Mick Amelishko, Sumsub’s AI advocate, put the shift in one word: agency. Last year’s AI helped you rewrite an email. This year’s AI can register on a site, scrape the open web, and, if you are reckless, reach a payment rail. Civilisation’s payment systems still assume a human on the far side of the click. That assumption is now a liability. Amelishko’s advice was blunt: do not give it the bank account. Treat the agent as another species — tireless, fast, and naively obedient.

Advertisement

Jarryd Jensen, Sumsub's Regional Director, Southern Africa, looking at Southern Africa, refused the hype. Local banks are digitally mature. Instant payments and eKYC are normal. That is not the same as an agent given a goal and left to choose the steps. 

Hannes Bezuidenhout, VP Sales Africa, was less patient with developments and commented that customers will not sit with a compliance manual. One local bank is already testing the space. China is not waiting. His working picture of a useful agent was modest and correct: sort the flights, the hotel and the car; and then a human clicks yes to confirm.

The big Question with No Answer

Around that modest picture the table kept returning to the only question that scales: if it pays the wrong person, follows a deepfake reservation, or decides the dark web is an efficient way to find yield, who do you lock up? The computer? The vendor? The customer who typed “handle it”? The bank that honoured the instruction?

Nobody at the table had a statute that answered. That absence is the trust gap. 

Regulation is being drafted for a world of assistants. The market is already shipping actors.

Two Agents, One stack

Sumsub’s Identity Fraud Report 2025–2026 is the document the luncheon was circling without quoting chapter and verse. 

Global identity-fraud rates eased from 2.6% in 2024 to 2.2% in 2025. That looks like a win. Rather It is a change in quality. Attacks the firm classifies as sophisticated — synthetic identities, deepfakes, social engineering and telemetry tampering stacked together, rose 180%. Advanced fraud went from about a tenth of cases to 28%. Amateur copy-paste is dying. Industrial deception is not.

AI Agents Are Also Working For the Bad Actors

The report’s most important new character is the AI fraud agent: a system that can mint a persona, sit in a liveness check, fiddle device signals, fail, learn, and try again. Sumsub says these are still early, and that 2026 is when fleets of them become ordinary. 

Pavel Goldman-Kalaydin, the firm’s head of AI/ML, has already named the defensive product: confirm not only who you are, but who acts on your behalf. CTO Vyacheslav Zholudev goes further — the breakthrough will be agents checking agents.

DeepFake Acceleration

South Africa is the awkward exhibit. Overall fraud on Sumsub’s rails fell 31% year on year, to 1.4%, a result the report ties to stronger AML/CFT, bank verification and biometric eKYC. Deepfake incidents in the same market rose more than 269%. Across Africa, 53% of businesses and 47% of consumers in the firm’s survey were hit in 2025. 

Ninety-one percent of African respondents have encountered deepfakes; one in five say they were targeted; a quarter cannot tell real from fake. Finance remains the most trusted industry on the continent, at 84%. That trust is exactly what an unsupervised payment agent will spend.

Consumers already know the difference between help and custody. Visa’s 2026 Stay Secure work found 77% of South Africans use AI to shop. Only 23% would trust an agent to complete checkout. The appetite is for a research assistant. It is not for a signatory. 

Payments networks have noticed. This week Visa, Mastercard and Ant International were lining up Know-Your-Agent principles so an agent can be bound to a validated operator. An agent without a principal is a synthetic identity with a credit line. African companies in Sumsub’s survey already name synthetic identity as the first-party fraud they fight most often. Agentic commerce without KYA is that pattern with travel expenses.

The Law is Late, and Pretoria Proved it

Europe’s answer, which Amelishko reached for at the table, is human-centric by design. Article 14 of the EU AI Act requires high-risk systems to be overseen by people who understand the limits, resist automation bias, override the output and stop the machine. It does not grant the model a soul. It refuses the idea that “the algorithm decided” is a defence. That is slow. It is also the only public doctrine on offer that still treats agency as a human attribute.

South Africa does not have an equivalent that can survive contact with a live payment. Banking rules have tightened around EFT credits, screen-scraping and beneficial ownership. That is why yesterday’s fraud rate fell. 

What the country does not have is a living AI statute that can name an agent, register a mandate, or allocate loss when the mandate is vague. 

The draft National AI Policy went out for comment in April and was withdrawn after AI-hallucinated citations. 

That episode is not a sideshow. It is the failure mode in miniature: a system used as if it had judgement, with no official able to stand behind the footnotes. You cannot lecture banks about human-in-the-loop while the state publishes ghosts.

So the Ai Wild West is not a shortage of opinions. It is three clocks running at different speeds. Criminal agents are industrialising now. Consumer agents are arriving in shopping and, more slowly, in banks. The rulebook is still written for a person who typed the amount.

Is the Wider Ai Machine Going too Fast?

The big question sits inside a louder one. This week researchers leaving frontier labs warned that companies are racing toward systems that help build the next systems — recursive self-improvement — faster than anyone has a plan to control them. 

Yann LeCun, from the other end of the field, still insists today’s language models will never become animal-like intelligence until they can observe the world and learn from it, and that extinction talk about chatbots is theatre.

Both camps can be set aside for long enough to see the local point. You do not need a house-cat mind, let alone a god, to wire a payment. You need tools, a mandate that is too loose, and an institution that cannot tell a helper from a mule. Speed is already the fraudster’s edge. Sumsub keeps repeating that AI does not get tired. A single mistake at that tempo can empty a book, not a basket. The journalists in Sandton asked whether one error could wipe out a firm. The honest answer is yes, if attribution is optional.

The acceleration that should worry a bank in Johannesburg is not metaphysical. It is operational. Capability is compounding in software. Identity, liability and public literacy are not. That gap is where money disappears.

What Has to Happen to Halt a Catastrophe

Accountability does not need a philosophy seminar. It needs a ledger.

No legal personality for agents. An identifier is not a citizen. Estonia can give agents an ID the way cars get number plates. The fine still lands on a person or a company.

Know Your Agent. Every payment-capable agent is bound to a verified principal, a scope — payees, limits, merchants, hours — and a kill switch. Money movement without a recorded mandate should not clear.

Logged intent. “Pay these ten suppliers” is a different legal object from “maximise my balance.” If the instruction is just a vibe, the deployer owns the downside. “The model chose” is not and will never be a fact in law.

Provider duty of care is also key. If you sell an agent as able to transact, you own the sandbox, the tool-abuse cases, prompt injection, and the forensic trail. Selling autonomy and disclaiming the result is product negligence dressed as innovation.

Detect what is acting. Helper agents and fraud agents share a stack. Defence has to separate a customer’s delegate from a synthetic ring that learned to complete onboarding. That is the real meaning of agents verifying agents: continuous, behavioural, cross-channel proof that the actor matches the mandate.

Solid Regulatory Framework

Shared responsibility that consumers have already asked for is what is needed. In Sumsub’s Africa survey, 55% want companies and government jointly on the hook for fraud. Only 8% think government can do it alone. Banks already live this in authorised-push-payment scam environment. Deepfake calls and agent-initiated payments are the next edition of the same crime.

Write the South African rules with humans in the loop, then publish the sources. The withdrawn policy is the object lesson. Public-private tables should include the people who will be impersonated, not only the vendors who will sell the detector.

Sensible Guardrails 

For individuals the hygiene is unfashionable and sufficient. Do not grant a general power of attorney to a chatbot. Cap what it may spend. Require approval for money. Assume a voice that sounds like your CEO is a recording until a second channel says otherwise.

For businesses the sequence is - mandate, limit, log, insure and rehearse. If you cannot reconstruct what the agent did at 14:03, you are not ready to let it leave the building. If your board cannot answer “who is the principal?”, you do not have an agent strategy. You have an intern with root access.

For the AI industry the obligation is to stop shipping actors and calling them features. Guardrails that exist only in a system card are not guardrails. They are literature. The firms building agents should treat KYA, scoped tools and interruptibility as shipping criteria, not as a later compliance overlay.

The  useful conclusion from the conversation, was not that South Africa should wait for China to burn its fingers, nor that it should copy Europe’s pace. It was that trust is not a feeling. It is a chain of names. 

Until every agent action can be walked back to a human who set the goal, a firm that built the machine, and an institution that accepted the payment, “act on my behalf” is a slogan with a hole in it. 

Close the hole before you scale the agent, because the attackers already have.

Reporting for Business Tech Africa on the funding, tools and strategy shaping the continent's founders and SMEs.

Was this useful?0 reactions
AI Tools
Read nextartificial-intelligence

Business Tools: How Fireflies.ai can help businesses keep track of meetings

For a small business, a meeting can create another job. Someone has to take notes. Someone has to remember what the customer asked for. Someone needs to follow up on the things the team agreed to do.

Vutomi Manzini · readContinue reading