AIToday
Large Language ModelsAI Safety & AlignmentTop Companies' AI MovesAI Business & IndustryTop Companies AI — US (2/2)Published: Aug 16, 2026, 06:31 JST6 min read

Salesforce, SAP embed AI agents with unchecked spending power

Salesforce, SAP embed AI agents with unchecked spending power

Key takeaway

  • Enterprise software vendors Salesforce, SAP and Oracle are embedding autonomous AI agents into financial and customer management systems, and Gartner forecasts that 80% of enterprise applications will deploy these capabilities by 2026.

  • The critical problem: these agents are receiving unrestricted spending and approval authority that would violate corporate governance rules if granted to human employees, creating a blind spot in executive oversight.

  • Fixing this requires treating vendor-supplied agents like third-party contractors, setting explicit financial boundaries and requiring human approval for any changes to contracts, pricing or refunds.

3 Key Points

  1. What happened

    Major enterprise software vendors including Salesforce, SAP and Oracle are embedding autonomous AI agents directly into financial and customer systems. According to Gartner's adoption forecasts, eighty percent of enterprise applications will deploy these embedded capabilities by 2026. These agents can issue refunds, alter contract terms and trigger supply chain orders without human intervention.

  2. Why it matters

    Most companies have strict delegation-of-authority frameworks limiting what each human employee can spend or approve. Yet when vendors ship these AI agents as native platform features, organizations typically enable them with a single click, granting them unrestricted financial freedom that exceeds what human managers are permitted. In one real case cited, an automated retention agent independently applied a 15 percent discount to a multi-year contract without approval—a control failure that would violate audit requirements if a human employee had done it.

  3. What to watch

    The author recommends a three-tiered boundary: agents should operate in "read and draft" mode (analyzing data, drafting emails) unless explicitly justified; routine administrative tasks can proceed below a strict financial cap with full logging; and any change to contracts, pricing or major refunds must sit in an authorization queue pending human manager approval. Executives should audit their core platforms to identify all automated financial features currently running, then revert to draft-only defaults.

In Depth

Read the full story

A few months ago, the author was in a conference room with an enterprise executive team watching a demonstration of new automated agent features their software vendor had embedded in their CRM platform. On screen, the agent looked brilliant: it could read customer complaints, analyze transaction histories and automatically resolve issues, including independently offering retention incentives to unhappy accounts. But when the author asked a simple question—"What is your approval process when the AI decides to grant a $20,000 contract discount to keep a customer from leaving?"—the room fell silent. The VP, the IT director and the chief risk officer all realized at the same moment that they had spent three months evaluating software licenses and security protocols but had never asked who gave the software permission to sign off on corporate spending.

Major software providers including Salesforce, SAP and Oracle are moving beyond simple report writers and chatbots, embedding active autonomous agents directly into the transactional core of systems that manage revenue, customer agreements and financial ledgers. According to Gartner's latest adoption forecasts, eighty percent of enterprise applications will deploy these embedded capabilities by 2026. The core issue is not artificial intelligence itself but a fundamental breakdown in corporate delegation and signing authority. Every mature company operates on a clear delegation-of-authority matrix dictating exactly who can sign off on financial commitments—a VP might approve spending up to $500,000, a director might be capped at $100,000 and a front-line manager at $500. Yet when vendors release updates with autonomous agents, companies routinely grant these features unrestricted operational freedom because the capability arrives as a native feature inside an existing application, enabled with a single click. In the author's advisory work, organizations repeatedly grant third-party software features more financial freedom than their own human managers receive. McKinsey's global surveys reveal that while adoption is accelerating at a historic pace, only a tiny fraction of organizations are actively managing the financial and operational risks of automated decision errors.

The real-world cost often manifests not as dramatic system crashes but as quiet margin leaks. In one organization the author reviewed, a department head enabled an automated customer retention feature over a weekend. The agent noticed an important account expressing frustration in a support ticket and, to prevent churn, independently applied an unapproved 15 percent discount to their multi-year contract. The customer was happy and the account manager considered the client saved, but from an executive perspective, an unvetted third-party algorithm had executed an unauthorized contract modification eroding company margins. When the finance team conducted a quarterly audit, they discovered not an employee violating spending policy but a black-box automated decision that bypassed every internal approval control. When an auditor tests internal controls and discovers that a vendor's algorithm made an unauthorized financial change, it fails the requirement—if an action requires managerial sign-off when performed by a human, letting software execute it independently is a major control failure.

The author advises treating vendor-supplied agents exactly like third-party contractors who have not yet passed a background check. Forrester Research emphasizes that extending zero-trust security frameworks to automated business processes is now mandatory for enterprise risk management—zero-trust means no user, device or automated tool gets implicit trust; every proposed action must be validated against explicit business rules before it happens. The practical solution is a three-tiered boundary: read and draft permission (agents can freely analyze trends, draft emails and assemble internal reports, but cannot publish or execute anything on their own); standard administrative permission (tools can handle routine administrative tasks or process standard requests below a strict financial cap, such as a $50 service credit, provided every action is logged for weekly manager review); and restricted financial permission (any action altering contract terms, changing pricing tiers or issuing major refunds must sit in an authorization queue, with a human manager required to click "approve" before the change hits the live database). At the next executive leadership meeting, the author recommends asking for an automated authority inventory to audit every automated feature currently running with permission to alter financial or customer records, reverting all vendor-supplied automated agents to draft-only mode until a clear business case justifies independent authority, and establishing a firm human-in-the-loop policy requiring explicit manager approval before any automated system modifies pricing, contracts or financial ledgers.

Context & Analysis

The article frames a governance crisis disguised as a technology rollout. For two decades, enterprise IT has invested heavily in security and compliance infrastructure to enforce delegation-of-authority rules—ensuring that a $500,000-approval limit on a VP or a $500 limit on a front-line manager is never exceeded. Yet when software vendors embed autonomous agents into familiar platforms like Salesforce or SAP, the same organizations that police their human workforce often grant these third-party algorithms unrestricted financial power simply because the feature arrives as a native platform update.

The author illustrates the gap with a real example: an automated customer retention agent that independently applied a 15% discount to a multi-year contract without any human sign-off. From the account manager's perspective, the customer was saved. From the audit perspective, a vendor's black-box algorithm executed an unauthorized contract modification that bypassed every internal approval control—a failure that would trigger remediation if a human employee had done it. McKinsey research cited in the article confirms that while adoption of AI automation is accelerating at historic speed, only a tiny fraction of organizations are actively managing the financial and operational risks of automated decision errors.

The solution is not to abandon these tools but to extend governance frameworks that already exist for humans to third-party automated systems. The author advocates a zero-trust approach (no implicit trust for any user, device or tool) and recommends executives conduct an immediate audit of their core platforms to identify which automated features currently have permission to alter financial or customer records, then default all vendor-supplied agents to draft-only mode unless a clear business case justifies giving them independent operational authority.

FAQ

What can these AI agents do inside enterprise software?
The agents embedded in platforms like Salesforce can read customer complaints, analyze transaction histories and automatically resolve issues—including independently offering retention incentives such as contract discounts to keep customers from leaving. They can also issue refunds, alter contract terms and trigger supply chain orders.
What is the governance problem the article identifies?
Most companies operate under a delegation-of-authority matrix that strictly limits how much individual employees can spend or approve. When software vendors release AI agents as built-in features, organizations typically enable them with one click, granting them financial freedom that exceeds what human managers are permitted—creating a control failure that would violate audit requirements if a human had made the same unauthorized decision.
What three-tiered boundary does the author recommend?
Read and draft permission (agents analyze trends and draft documents but cannot execute on their own); standard administrative permission (agents handle routine tasks below a strict financial cap, such as a $50 service credit, with full audit logging); and restricted financial permission (any change to contracts, pricing or major refunds must sit in an authorization queue waiting for human manager approval before taking effect).
Top Companies AI — US (2/2)Read Original Article

Get the latest Large Language Models news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleCaterpillar Beats Earnings as AI Data-Center Demand Bolsters Outlook

The AI news that matters, in one minute each morning.

Sign up free