KYC stands for "Know Your Customer" and it's a reference to laws that require businesses to have a clue who they're doing business with. It's not a legitimate response to the concern here. The concern is failure to provide adequate information about the consequences of your actions up front. They're going to benefit from the ads, and they won't necessarily have to pay for that benefit, because they didn't adequately obtain informed consent before they began by informing you that you need to pony up PII to a third party.
AML is probably Anti-Money Laundering. It again has nothing to do with informed consent. It is possible to prevent money from being laundered by telling a person up front, before they agree to sign up, that they have to give their private information to a third party.
CYA is probably "Cover Your Arse". Again, it's not a legitimate concern for the same reason as above.
IANAL is obviously not a response to the original concern but merely intended to reduce the risk of the reply. But there's no legal issues being raised. The issue is purely whether or not a business who praises their privacy credentials should clearly let their customers know that, if they choose to engage in business with them, their private information will need to be shared with a business who they may not trust.
If OP's story is true, Brave is not above engaging in distrust for dollars. That's the lesson to be learnt here. Brave doesn't care about your privacy. They just hope that by marketing privacy, they can get a few customers. And they will and apparently do engage in shady practices that compromise your privacy. No acronym can justify that, other than something that stands for "Businesses need to be responsible for their actions, not just their profits".