AI Agents Are Doing Business—Now Ant Group Wants to Make Sure You Can Trust Them
AI Agents Are Doing Business—Now Ant Group Wants to Make Sure You Can Trust Them
On September 11, at the 2026 Inclusion · Bund AI Payment Forum, Ant Group unveiled APASS, a new trust infrastructure designed for commercial activities carried out by AI agents. Think of it as a background check system for the bots that are increasingly shopping, booking, and paying on our behalf.

When Your AI Assistant Starts Making Deals
AI has already moved beyond generating content or answering questions. Today's agents can search for products, book tickets, complete purchases, and even handle payments for users. They also represent companies in procurement, marketing, and customer service. As these autonomous actors take on more business tasks, a glaring question emerges: who should the business world trust when an AI is doing the dealing?
Gartner predicts that by 2028, 90% of B2B procurement will be handled by AI agents, driving over $15 trillion in spending through agent platforms. That's a lot of money changing hands without a human in the loop.
The old internet trust model—built around people, accounts, and platforms—doesn't fit. Agents aren't traditional humans, nor are they passive software waiting for commands. They perceive, decide, and act on their own. So the industry needs to answer not just "can they do it," but "can they be trusted to do it."
"Agents are becoming the 'new population' of the business world," said Chen Shupeng, head of AI payment security at Ant Group. "When they start calling services and participating in transactions, the industry must answer both 'who is involved in the transaction' and 'why the transaction is happening.'" APASS, he explains, helps participants confirm who the cooperating agent is, who it represents, what authorization it has, and whether it's currently trustworthy—plus provides traceable evidence if something goes wrong.

Figure caption: Chen Shupeng, AI payment security officer of Ant Group
Beyond ID Checks: Continuous Trust for Continuous Actions
One-time identity verification simply won't cut it. An agent might be created by an individual but run on a third-party platform. It could represent a person or a company, receive one-time authorization or continuously call services. Its operating environment, goals, and behavior can shift at any moment.
APASS tackles this with four core capabilities: trusted identity, continuous verification, intent security, and trusted evidence. It uses a three-layer identity model—static, runtime, and responsible entity—along with a six-dimensional verification mechanism. Before a transaction, it checks identity and authorization. During, it spots abnormal behavior or intent deviation and applies dynamic risk controls. After, it keeps key evidence for audits and accountability.
In short, APASS extends traditional ID checks into ongoing verification of an agent's identity, authorization, intent, and behavior. It's a recognition that computing power lets AI operate, models make it smart, but trust mechanisms determine whether it can truly enter the real commercial world.
A Growing Ecosystem: Over 1 Million Agents Connected
APASS already supports more than 1 million agents, with 110,000 activated, covering 442 service providers. These range from independent assistants to productivity tools, hardware terminals, and merchant services. Developers can integrate through three simple steps, embedding trusted capabilities into service calls, business processing, and payments. The system adapts to different entities and technical paths, cutting down on repetitive security integration work.
More than 50 organizations—including Alibaba, Li Auto, Ant Group, Lenovo, OPPO, Qwen, Xiaomi, Ctrip, and the China Academy of Information and Communications Technology—have joined the IIFAA Intelligent Agent Trust Ecosystem Construction Plan to push alliance standards forward.
Internationally, Alipay+ AMP, Mastercard's Verifiable Intent, and Visa's Intelligent Agent Trust Protocol have established a KYA interoperability framework, enabling cross-border agent identity verification and trust collaboration.
Ant Group is essentially extending its long-accumulated identity, security, risk control, and payment capabilities into the agent era. Alipay once solved how people and merchants establish transaction trust. Now APASS is exploring how people and agents, agents and merchants, and even agents and agents establish action trust.
Key Points
- Ant Group launched APASS, a trust infrastructure for AI agents in commercial activities.
- APASS uses KYA (Know Your Agent) to verify identity, authorization, intent, and behavior continuously.
- Over 1 million agents are connected, with 110,000 activated across 442 service providers.
- More than 50 institutions have joined the IIFAA trust ecosystem; international protocols are also aligned.
- The move addresses the question of trust as AI agents increasingly handle transactions autonomously.