Opens in a new tab
vmblog logo 2024 wht (updated)

Enterprises Are Handing AI Agents Financial Workflows, While More Than Half Can’t Fully Verify Their Actions

Share: 

David Marshall | Published: July 30, 2026

Pathlock released new research revealing a widening governance gap as enterprises deploy AI agents into core business processes, including finance, procurement, and human resources. The AI Governance Gap Report finds that AI agents — the fastest-growing class of non-human identities (NHIs) — are not only assisting employees with productivity tasks; they are actively approving transactions, modifying vendor records, and executing cross-system workflows at a speed no human could match, often without adequate oversight, traceability, or accountability structures in place.

Most alarmingly, the damage is already happening. 23% of organizations surveyed have already experienced at least one AI incident requiring investigation and remediation. Worryingly, known incidents are likely only the tip of the iceberg. More than half (51%) aren’t confident they know all the AI agents operating in their systems, and 31% are unsure whether incidents have occurred at all. With visibility this limited, the true scale of AI-driven irregularities is almost certainly higher than what’s been formally reported.

AI Agents Have Crossed into Financial Controls Territory

Unlike traditional non-human identities such as service accounts, AI agents can make contextual decisions and execute multi-step business processes across applications.

The report documents a decisive shift in how AI agents are being used inside enterprise environments. While early AI deployments focused on analytics and data summarization, organizations are now granting AI agents powers traditionally reserved for human employees with financial authority:

  • 38% of organizations allow AI agents to create and modify business records
  • 28% allow AI agents to approve transactions
  • 35% allow AI agents to execute cross-system workflows
  • 36% have already embedded or are currently implementing AI agents in finance and accounting

Perhaps most striking, 25% of organizations allow AI agents to access backend databases directly, increasing the risk of changes that bypass application-level business logic.

“Three forces are converging — the explosion of identities, increasingly interconnected business applications, and AI agents that can now execute business processes autonomously at machine speed. Together, they’re transforming governance from an IT discipline into a business imperative. As AI agents begin influencing financial outcomes, governance becomes a matter of business risk, financial integrity, and regulatory compliance.” — Chris Radkowski, GRC Expert at Pathlock

Governance Has Not Kept Pace

Despite this rapid expansion of AI agent authority, the research reveals that most organizations lack the governance infrastructure required to manage the risks that come with it:

  • 79% of organizations have no dedicated AI governance team or officer
  • 52% cannot verify actions Al agents execute across business systems
  • 48% cannot trace AI agent activity end-to-end across systems

The investigation gap is particularly acute. If a questionable AI-driven action were flagged today, only 13% of organizations could investigate it in real time, and only 18% could complete an investigation within hours. Nearly a quarter (22%) could not reliably investigate at all.

“For decades, governance focused on controlling who could access a system. AI agents introduce a different challenge: understanding what actually happened after access was granted. The organizations best prepared for AI will be those that can verify, trace, investigate, and explain AI-driven actions in real time across their entire business application landscape, regardless of how many data sources must be correlated to reconstruct the full picture.” — Susan Stapleton, GRC Expert at Pathlock