Sandra Buckingham

For years, we have been teaching artificial intelligence to assist us. It can summarise a report, recommend a product, draft an email or answer a customer query.
Now we are teaching it to act for us.
AI agents can move beyond generating information to completing tasks, interacting with other systems and executing entire workflows. An agent could compare financial products, manage subscriptions, make purchases or initiate payments without a human approving every individual step.
This changes the trust equation completely.
The question is no longer simply whether AI agents are capable of doing the work. It is what businesses should safely allow them to do, and whether our identity, security and regulatory systems are ready for it.
A New Actor in the System
Our digital infrastructure has largely been designed around the assumption that the person on the other side of an interaction is human.
We verify people using passports, identity documents, facial recognition and other personal credentials. Businesses can also authenticate servers, devices and software through keys, tokens and certificates.
An AI agent sits somewhere between these two worlds.
It may have a technical identity, but that does not tell a bank, payment provider or business who created it, who owns it, who it represents or what authority it has been given.
Proving that a piece of software is legitimate is not the same as proving that it is authorised to make a R100,000 payment on someone’s behalf.
The difficult question is therefore not simply: What is this agent?
It is: Who is this agent acting for, and what has it been authorised to do?
What Should We Delegate?
South Africa’s sophisticated banking infrastructure, strong fintech ecosystem and increasingly automated business environment make it an attractive market for agentic AI.
The opportunity is significant. Agents could manage administrative workflows, retrieve information, schedule appointments, classify documents and handle routine customer requests. They may eventually make low-value payments or manage recurring transactions on behalf of customers.
But autonomy cannot be unlimited.
A useful way for businesses to approach agentic AI is through a spectrum of risk. Routine, low-value and easily reversible actions may be suitable for greater autonomy. High-value financial transactions, changes to account ownership, identity exceptions, credit decisions and other actions with serious or irreversible consequences should require stronger verification or meaningful human approval.
“Human in the loop” cannot become another compliance phrase that sounds reassuring but means very little in practice. Human oversight must be active, informed and positioned at the points where intervention genuinely matters.
Agents need clearly defined roles, limits, escalation paths and auditable records of what they have done.
From Know Your Customer to Know Your Agent
Traditional Know Your Customer processes answer a familiar question: Who are you?
When an AI agent acts for a customer, businesses need to answer several more:
What is the agent?
Who owns or controls it?
Who authorised this particular action?
What information and systems may it access?
How long does that authority remain valid?
Can every action be traced back to an accountable person or organisation?
Sumsub describes the emerging framework for answering these questions as Know Your Agent, or KYA.
KYA connects the agent’s technical identity to the verified human or organisation behind it. It combines four essential layers: identity, authentication, authorisation and accountability.
The agent must have a distinct, verifiable identity. The system must confirm that it is the agent it claims to be. Its permissions must be clearly defined, and its actions must be linked to a responsible person or organisation through a reliable audit trail.
Crucially, authorisation should be specific, context-aware and, where necessary, time-bound. An agent might be permitted to retrieve a balance or make a routine payment but require further approval before transferring a large amount, opening a new product or changing account information.
As Hannes Bezuidenhout, VP Sales Africa at Sumsub said: “Trust is not binary. An agent should not be either fully trusted or completely blocked. Its autonomy should be limited, monitored and proportionate to the risk of the action it is taking.”
Regulation Has Not Caught Up
South Africa does not yet have AI-specific legislation. Existing frameworks such as POPIA, FICA and consumer-protection laws still apply, but they were largely developed around human customers and conventional organisational systems.
POPIA already places restrictions on certain decisions made solely through automated processing when those decisions have legal or substantial consequences for an individual. What it does not specifically address is an autonomous AI agent taking action on that individual’s behalf.
South Africa’s Draft National Artificial Intelligence Policy was withdrawn in June 2026 to be reworked, leaving the country’s formal AI governance framework under development.
The gap raises difficult questions. If an agent makes an incorrect payment, approves a damaging decision or acts beyond its authority, who is responsible? The customer? The organisation using the agent? Its developer? The platform through which it acted?
These questions cannot wait until autonomous agents are operating at scale.
The Fraud Problem Is Already Evolving
The urgency becomes clearer when viewed against the changing fraud landscape.
According to Sumsub’s Identity Fraud Report 2025–2026, the share of sophisticated, multi-step fraud rose from 10% of identity fraud in 2024 to 28% in 2025. That represents year-on-year growth of 180%, even as the overall global identity fraud rate declined slightly.
Criminals are already using AI and automation to increase the sophistication and scale of their attacks. At the same time, legitimate customers will increasingly use agents to manage real financial and commercial activities.
Businesses will therefore not be able to treat every bot or automated interaction as a bad actor. Automation itself is not the risk signal. Identity, authority, intent, context and behaviour are what matter.
Autonomy Without Losing Accountability
AI agents are likely to become capable of far more than the systems governing them are currently prepared to allow.
The businesses that benefit most will not necessarily be those that adopt agents fastest. They will be those that make deliberate decisions about what an agent may do, when it must ask for permission and who remains accountable when something goes wrong.
The next phase of AI will not be defined only by what the technology can do.
It will be defined by what we are prepared to trust it to do.