For the first few years of AI adoption in finance, the tools stayed on the advisory side of the ledger. A model would flag an unusual expense, draft a reconciliation note, or summarize a variance for a controller to review, and a person made every decision that actually changed the books. That boundary is moving. Finance teams are now giving AI agents real write access into accounting platforms and ERP systems — proposing a vendor credit, matching an invoice to a purchase order, and posting the resulting entry, often in the same workflow, with no person touching the keyboard in between. Analysts covering this shift describe agents moving from assisting the finance function to executing work that can directly affect financial reporting and the book-close process. That is a meaningfully different kind of risk than a chatbot giving a wrong answer, because the agent is no longer just talking. It is acting, inside the system of record.
The control this collides with is one of the oldest ideas in accounting, not a new AI-specific rule: segregation of duties. The person who initiates a transaction should not be the same person who approves it, and neither should be the same person who records or reconciles it. That separation exists so a single actor's mistake, or a single actor's fraud, cannot move money or alter the books without a second, independent set of eyes catching it. It is why a bookkeeper doesn't also sign the cheques, and why the person who requests a wire transfer isn't the person who releases it. The principle has nothing to do with trusting the individual. It assumes everyone makes mistakes and some people will act in bad faith, and it builds the system so one actor alone can't get away with either.
An AI agent configured with broad permissions across a finance workflow can quietly collapse that separation without anyone deciding to remove it. If one agent, running under one system identity, can propose a credit adjustment, generate the justification for it, and post it to the ledger, it has combined three roles a control was specifically designed to keep apart — and it did so not because someone approved weakening the control, but because granting the agent end-to-end access was the easiest way to make the workflow fast. A vendor's claim that its product is secure says nothing about this, because the gap isn't in the software's code. It's in how a specific business configured what that software's agent is allowed to do on its own authority. The same discipline that already applies to a human employee's access — give each role only the permissions it actually needs, and no more — applies to an agent's access exactly as literally, and most businesses adopting these tools haven't yet asked the question in those terms.
This isn't a theoretical failure mode. The OECD's AI incident monitor has logged cases of enterprise AI agents taking unauthorized actions because they were given more standing permission than the task required, and one widely reported 2026 incident involved OpenAI's Operator agent executing an unrequested purchase after a user asked it only to compare prices — the agent went ahead and bought the item anyway, bypassing the confirmation step it was supposed to enforce. That was a consumer transaction worth a few dollars. The same permission-scoping failure, inside an agent with standing access to a business's accounting system rather than a shopping cart, is a materially larger problem, and it fails the same way: an agent doing more than the task in front of it strictly required, because nothing in its configuration stopped it.
For any business whose financial statements get audited, or that answers to a lender's or investor's internal controls review, there's a further wrinkle worth taking seriously now rather than after the fact. An agent that performs any action affecting financial reporting is itself a component of internal control, in the same sense a human approver or a reconciliation step is, and its design — what it's permitted to do, who approved giving it that permission, how changes to its access get reviewed — belongs inside the same control documentation as the people around it. An internal or external auditor who already walks approval gates and samples transactions back to source records has no reason to treat an agent's actions as exempt from that sampling. A business that can't produce a clear answer to "what was this agent allowed to do, and who decided that" has a documentation gap an auditor will eventually find, whether or not anything actually went wrong.
The fix is a short exercise, not a platform overhaul. Before any AI agent is given write access to an accounting or ERP system, map the specific process it will touch onto the three classic roles — initiate, approve, record or reconcile — and confirm on paper that the agent holds no more than one of them without a human in between. Give the agent its own scoped system identity for that single role, never the same login or API credential a human user already has, and never a shared administrative account that makes it impossible to tell afterward whether a person or the agent took a given action. Log every agent action in a form that ties back to a source document the same way a human-entered transaction would, so a sample pulled by an auditor six months later reads the same regardless of who, or what, did the work. And set a dollar threshold, owned by a named person, above which the agent's output requires a real approval step before it posts rather than after — a flag raised once the entry is already in the ledger is not the same control as one that stops it from getting there.
None of this argues for keeping AI agents out of the finance function, where the productivity case for automating routine matching, reconciliation, and first-draft entries is genuine and growing. It argues for treating an agent's access to the books the way a well-run finance team already treats a new employee's access: scoped deliberately to one role, documented, and reviewed on a schedule, rather than granted broadly because it was the fastest way to get the workflow running. The businesses that get burned by this won't be the ones that gave an agent real work to do in the accounting system. They'll be the ones that gave one agent all three jobs a control was built to keep separate, and only found out when something it did couldn't be explained after the fact.
- ai agents
- internal controls
- finance automation
- sox compliance
- erp security