Karina Portugal Makes the Case for Know Your Agent
Karina Portugal advocates for 'Know Your Agent' to verify AI software acting on behalf of users.
Summary
Karina Portugal, Director at Prove Identity, argues for a 'Know Your Agent' (KYA) approach to address the growing risks of AI software acting autonomously. Traditional Know Your Customer (KYC) methods are insufficient as compromised agents can retain legitimate credentials, leading to authorized but malicious actions. Portugal emphasizes the need for continuous authorization checks during agent execution, not just at initial access, citing a significant rise in AI-driven fraud.
Full text
Artificial Intelligence TechnologyKarina Portugal Makes the Case for Know Your AgentbyOwais SultanOctober 6, 20263 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Karina Portugal has spent more than ten years working in digital identity, fraud prevention, anti-money laundering and Know Your Customer controls with banks, fintechs and marketplaces in the United States, Brazil and Latin America. Now Director of Banking, Marketplaces, Strategic Partnerships and Agentic Trust at Prove Identity, she argues that companies need a separate approach for verifying software agents acting on behalf of users. Traditional identity controls establish who a person is, but autonomous agents create another question: whether the software is still performing the task its user approved. Why Know Your Customer Does Not Cover AI Agents The number of agents operating inside business applications is expected to grow quickly. Gartner projects that 40 percent of enterprise applications will integrate task-specific AI agents by the end of 2026, up from less than 5 percent in 2025. “A compromised agent keeps its legitimate credentials and session tokens,” Portugal said. “Everything downstream sees an authorized action, because on paper that is what it is.” KYC can establish who a person is, but it does not determine whether an autonomous agent is still acting within the task and permissions its user approved. Portugal argues that agent authorization must therefore be checked during execution, not only when access is first granted. “Human authentication asks whether this is the right person,” she said. “Agent authentication has to ask a second question: is this agent still performing its intended function at this specific moment? Trust granted once, at deployment, does not answer that.” She uses concert-ticket purchases as an example. A seller may know that an agent has permission to buy a ticket, but it may have no reliable way to determine whether the agent remains within the parameters set by the customer or has been redirected to misuse the payment method connected to it. Karina Portugal AI Fraud and Agent Adoption Are Increasing Portugal cites Pindrop’s internal data, which recorded a 1,210 percent increase in AI-driven or “non-live” fraud during 2025. She also references a World Economic Forum article stating that AI fraud agents capable of creating synthetic identities, interacting with verification systems and adapting their behaviour could become mainstream within 18 months. Guidance from the US National Institute of Standards and Technology addresses some of the same concerns. The voluntary NIST AI Risk Management Framework describes AI systems as operating with varying levels of autonomy and encourages organizations to consider risk throughout design, deployment, use and evaluation. Four Layers of Continuous Trust Portugal describes four controls that companies can use together when authorizing AI agents. The first involves issuing narrowly scoped, short-lived credentials for individual tasks instead of giving agents static API keys. She points to Stripe’s agent-payment system, which can issue a one-time-use card or Shared Payment Token after a customer approves a specific purchase, without exposing the underlying payment credentials. The second covers context and tool access. Model Context Protocol provides a standard way for agents to connect with tools and data, but authentication alone does not establish whether each requested action matches the user’s instructions. Portugal argues that authorization should be checked before a tool executes. Behavioural verification forms the third layer. Risk signals can be reassessed when an agent performs a significant action, checking whether the request matches expected behaviour, remains consistent with the original task and follows logically from earlier actions. Files, URLs and payloads encountered during execution can also be examined before they are processed. The fourth layer is an audit trail connecting each action to its authorization. Records should identify the credential used, the approved task, the requester and the time of the action so investigators can reconstruct what happened after a security incident. Questions for Buyers and Investors Portugal believes companies buying agentic products, and investors funding them, should ask whether the technology verifies an agent throughout its operation. “Enterprises adopting these products, and the investors funding them, should be asking whether real verification is there,” she said. “Otherwise a product inherits trust it never earned.” Portugal calls this approach Know Your Agent. It would sit alongside Know Your Customer by checking whether an agent’s identity, permissions and actions still match what the user authorized. Owais Sultan Owais has been part of HackRead since 2012, covering artificial intelligence, cybersecurity, and emerging technologies. An avid writer with a keen interest in technological developments, he focuses on making complex topics accessible to readers while examining their impact on businesses and everyday users. View Posts Agentic AIAIAI AgentsArtificial IntelligenceTechnology Leave a Reply Cancel reply View Comments (0) Related Posts Read More Artificial Intelligence Data Breaches Security Survey: Rapid AI Adoption Causes Major Cyber Risk Visibility Gaps As software supply chains become longer and more interconnected, enterprises have become well aware of the need to… byOwais Sultan Read More Security Artificial Intelligence Leaks Firebase Misconfiguration Exposes 300M Messages From Chat & Ask AI Users A technical mistake in the popular Chat & Ask AI app has left 300 million private messages from 25 million users exposed online. Discover what happened and how you can protect your personal data when using AI chatbots. byDeeba Ahmed Read More Apple News Google News Malware Security Technology Google to Protect Mac Chrome Users with Additional “Safe Browsing” Alerts It is a fact that lately, malware attacks against Mac devices are on the rise. Chrome users are… byOwais Sultan Read More News Hacking News Security Technology Twitter Confirms Data Breach as 5.4M Accounts Sold on Hacker Forum Twitter was forced to investigate the incident when a hacker offered the personal details of 5.4 million Twitter… byDeeba Ahmed
Indicators of Compromise
- malware — AI-driven or 'non-live' fraud