Thought Leaders

The Due Diligence Question Nobody Is Asking Yet

mm
Add Unite.AI to your preferred sources on Google

For as long as banks have opened accounts, compliance has rested on a single assumption: that a real, identifiable person stands behind each one. Verify that the person at onboarding and everything downstream inherits the trust. That assumption is eroding from two directions at once. AI agents now transact on people’s behalf, and synthetic identities now pass for people who never existed. Confirming that a genuine human stands behind an account, and that they intend what the account is doing, has never been harder.

Regulators have noticed, though they are moving unevenly and have yet to name agents as a category of their own. Two jurisdictions show the range.

Two Regulators, Two Directions

The clearest signal comes from Europe. The European Union’s AI Act enters its most consequential enforcement phase on August 2, 2026, when the full set of high-risk system obligations and Article 50 transparency rules become applicable, alongside the Commission’s own enforcement powers, which can fine providers of the most advanced general-purpose AI models up to 3% of global turnover or 15 million euros, whichever is higher. The act does not define an AI agent as its own legal category. It doesn’t need to. Any system that receives input, processes it, and takes action already qualifies as an AI system under the existing text, and an agent performing a high-risk function in lending, insurance, or identity verification inherits the same obligations a human-operated system would carry.

Singapore took the opposite approach. On January 22, 2026, at the World Economic Forum, the Ministry of Digital Development and Information unveiled the Model AI Governance Framework for Agentic AI, the first governance model built specifically around autonomous systems rather than adapted from general AI rules. It is voluntary, but it sets out what a formal framework looks like: an agent’s level of autonomy is assessed, a human accountability structure is assigned to it, and its risk is bounded by design rather than caught after the fact—two regulators, converging on the same problem from opposite ends of the rulebook. One stretches the laws it already has to cover agents. The other writes new rules for a category that did not exist when the old ones were drafted.

Who Answers for the Agent

Underneath both approaches sits a question compliance teams have not had to answer cleanly before: when an agent acts, who is accountable? Legal analysis from Baker McKenzie, published July 1, 2026, concludes that courts and regulators are converging on an answer, at least for now. Accountability lies with the humans and entities behind the agent, not with the agent itself, and a June 2026 U.S. executive order directing the Justice Department to prioritize enforcement against AI-enabled hacking reinforces this principle. That answer is workable as a legal default. It is not, on its own, an operational one.

Knowing a human is ultimately liable does not tell a compliance officer which human, at the moment a transaction clears. It does not tell them whether the entity behind an agent was verified once at onboarding or continuously as the agent’s permissions changed. Beneficial ownership rules were built to answer “who owns this,” largely as a one-time question. Agentic activity asks an ongoing question: who is currently directing this, and can that answer change without anyone being told?

The Compliance Function’s Actual Job

Most compliance functions cannot currently trace that chain end-to-end, and the tools to do so are still being built rather than bought off the shelf. One framework for adaptive AML program design argues that rigid, uniform screening rules applied identically across every customer and jurisdiction cannot keep pace with risk that changes shape this quickly, and that configurable screening profiles, matched to actual risk rather than a fixed rulebook, are the only structure flexible enough to hold. The same logic extends naturally to agentic activity. A screening program that cannot adjust to a new category of principal is not equipped to govern one.

Governance of the agents themselves follows the same logic. Recent guidance on giving AI tools access to risk-signal data argues for permissioned, logged connections that inherit existing role-based access controls. Hence, an agent’s actions carry the same audit trail as a human analyst’s would, rather than an untracked shortcut around it. That is a smaller-scale version of the exact problem regulators are now circling at the level of the entire financial system: an agent’s actions need to be attributable, in real time, to the accountable party behind them, rather than reconstructed after the fact.

Formalizing What Already Exists

Whatever the industry ends up calling it, Know Your Agent is a distinct discipline, not a subset of the customer and business due diligence compliance teams already run. The direction of travel is barely in doubt: the AI Act’s enforcement phase, Singapore’s governance framework and the emerging legal consensus on accountability all point toward the same destination, formal rules for who or what is allowed to act, and on whose authority.

The only real question is timing, whether financial institutions build that discipline ahead of the mandate or scramble to assemble it afterward. Regulators rarely reward the latter. And the harder problem lies beneath the rules either way: the customer in front of the institution is no longer reliably a person, and no streamlining of paperwork makes the human behind an account any easier to trust.

Tamás Kádár is the CEO and Co-Founder of SEON, a leading fraud prevention and AML company. He launched SEON in 2017 after facing fraud issues at his own crypto exchange. With expertise in fintech, AI, and cybersecurity, he built a platform delivering enterprise-grade tools for businesses of all sizes. Under his leadership, SEON has gained global recognition. A contributor to Forbes Technology Council and HackerNoon, Kádár advocates for the democratization of real-time fraud prevention.