Karina Portugal Makes the Case for Know Your Agent

Karina Portugal Makes the Case for Know Your Agent

Listen to this article

0:00 —

Press play to start listening

Karina Portugal has spent more than ten years working in digital identity, fraud prevention, anti-money laundering and Know Your Customer controls with banks, fintechs and marketplaces in the United States, Brazil and Latin America.

Now Director of Banking, Marketplaces, Strategic Partnerships and Agentic Trust at Prove Identity, she argues that companies need a separate approach for verifying software agents acting on behalf of users.

    Traditional identity controls establish who a person is, but autonomous agents create another question: whether the software is still performing the task its user approved.

    Why Know Your Customer Does Not Cover AI Agents

    The number of agents operating inside business applications is expected to grow quickly. Gartner projects that 40 percent of enterprise applications will integrate task-specific AI agents by the end of 2026, up from less than 5 percent in 2025.

    “A compromised agent keeps its legitimate credentials and session tokens,” Portugal said. “Everything downstream sees an authorized action, because on paper that is what it is.”

    KYC can establish who a person is, but it does not determine whether an autonomous agent is still acting within the task and permissions its user approved. Portugal argues that agent authorization must therefore be checked during execution, not only when access is first granted.

    “Human authentication asks whether this is the right person,” she said. “Agent authentication has to ask a second question: is this agent still performing its intended function at this specific moment? Trust granted once, at deployment, does not answer that.”

    She uses concert-ticket purchases as an example. A seller may know that an agent has permission to buy a ticket, but it may have no reliable way to determine whether the agent remains within the parameters set by the customer or has been redirected to misuse the payment method connected to it.

    AI Fraud and Agent Adoption Are Increasing

    Portugal cites Pindrop’s internal data, which recorded a 1,210 percent increase in AI-driven or “non-live” fraud during 2025.

    She also references a World Economic Forum article stating that AI fraud agents capable of creating synthetic identities, interacting with verification systems and adapting their behaviour could become mainstream within 18 months.

    Guidance from the US National Institute of Standards and Technology addresses some of the same concerns. The voluntary NIST AI Risk Management Framework describes AI systems as operating with varying levels of autonomy and encourages organizations to consider risk throughout design, deployment, use and evaluation.

    Four Layers of Continuous Trust

    Portugal describes four controls that companies can use together when authorizing AI agents.

    The first involves issuing narrowly scoped, short-lived credentials for individual tasks instead of giving agents static API keys. She points to Stripe’s agent-payment system, which can issue a one-time-use card or Shared Payment Token after a customer approves a specific purchase, without exposing the underlying payment credentials.

    The second covers context and tool access. Model Context Protocol provides a standard way for agents to connect with tools and data, but authentication alone does not establish whether each requested action matches the user’s instructions. Portugal argues that authorization should be checked before a tool executes.

    Behavioural verification forms the third layer. Risk signals can be reassessed when an agent performs a significant action, checking whether the request matches expected behaviour, remains consistent with the original task and follows logically from earlier actions. Files, URLs and payloads encountered during execution can also be examined before they are processed.

    The fourth layer is an audit trail connecting each action to its authorization. Records should identify the credential used, the approved task, the requester and the time of the action so investigators can reconstruct what happened after a security incident.

    Questions for Buyers and Investors

    Portugal believes companies buying agentic products, and investors funding them, should ask whether the technology verifies an agent throughout its operation.

    “Enterprises adopting these products, and the investors funding them, should be asking whether real verification is there,” she said. “Otherwise a product inherits trust it never earned.”

    Portugal calls this approach Know Your Agent. It would sit alongside Know Your Customer by checking whether an agent’s identity, permissions and actions still match what the user authorized.

    Owais has been part of HackRead since 2012, covering artificial intelligence, cybersecurity, and emerging technologies. An avid writer with a keen interest in technological developments, he focuses on making complex topics accessible to readers while examining their impact on businesses and everyday users.
    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Related Posts