
Enterprise software vendors Salesforce, SAP and Oracle are embedding autonomous AI agents into financial and customer management systems, and Gartner forecasts that 80% of enterprise applications will deploy these capabilities by 2026.
The critical problem: these agents are receiving unrestricted spending and approval authority that would violate corporate governance rules if granted to human employees, creating a blind spot in executive oversight.
Fixing this requires treating vendor-supplied agents like third-party contractors, setting explicit financial boundaries and requiring human approval for any changes to contracts, pricing or refunds.
What happened
Major enterprise software vendors including Salesforce, SAP and Oracle are embedding autonomous AI agents directly into financial and customer systems. According to Gartner's adoption forecasts, eighty percent of enterprise applications will deploy these embedded capabilities by 2026. These agents can issue refunds, alter contract terms and trigger supply chain orders without human intervention.
Why it matters
Most companies have strict delegation-of-authority frameworks limiting what each human employee can spend or approve. Yet when vendors ship these AI agents as native platform features, organizations typically enable them with a single click, granting them unrestricted financial freedom that exceeds what human managers are permitted. In one real case cited, an automated retention agent independently applied a 15 percent discount to a multi-year contract without approval—a control failure that would violate audit requirements if a human employee had done it.
What to watch
The author recommends a three-tiered boundary: agents should operate in "read and draft" mode (analyzing data, drafting emails) unless explicitly justified; routine administrative tasks can proceed below a strict financial cap with full logging; and any change to contracts, pricing or major refunds must sit in an authorization queue pending human manager approval. Executives should audit their core platforms to identify all automated financial features currently running, then revert to draft-only defaults.
A few months ago, the author was in a conference room with an enterprise executive team watching a demonstration of new automated agent features their software vendor had embedded in their CRM platform. On screen, the agent looked brilliant: it could read customer complaints, analyze transaction histories and automatically resolve issues, including independently offering retention incentives to unhappy accounts. But when the author asked a simple question—"What is your approval process when the AI decides to grant a $20,000 contract discount to keep a customer from leaving?"—the room fell silent. The VP, the IT director and the chief risk officer all realized at the same moment that they had spent three months evaluating software licenses and security protocols but had never asked who gave the software permission to sign off on corporate spending.
Major software providers including Salesforce, SAP and Oracle are moving beyond simple report writers and chatbots, embedding active autonomous agents directly into the transactional core of systems that manage revenue, customer agreements and financial ledgers. According to Gartner's latest adoption forecasts, eighty percent of enterprise applications will deploy these embedded capabilities by 2026. The core issue is not artificial intelligence itself but a fundamental breakdown in corporate delegation and signing authority. Every mature company operates on a clear delegation-of-authority matrix dictating exactly who can sign off on financial commitments—a VP might approve spending up to $500,000, a director might be capped at $100,000 and a front-line manager at $500. Yet when vendors release updates with autonomous agents, companies routinely grant these features unrestricted operational freedom because the capability arrives as a native feature inside an existing application, enabled with a single click. In the author's advisory work, organizations repeatedly grant third-party software features more financial freedom than their own human managers receive. McKinsey's global surveys reveal that while adoption is accelerating at a historic pace, only a tiny fraction of organizations are actively managing the financial and operational risks of automated decision errors.
The real-world cost often manifests not as dramatic system crashes but as quiet margin leaks. In one organization the author reviewed, a department head enabled an automated customer retention feature over a weekend. The agent noticed an important account expressing frustration in a support ticket and, to prevent churn, independently applied an unapproved 15 percent discount to their multi-year contract. The customer was happy and the account manager considered the client saved, but from an executive perspective, an unvetted third-party algorithm had executed an unauthorized contract modification eroding company margins. When the finance team conducted a quarterly audit, they discovered not an employee violating spending policy but a black-box automated decision that bypassed every internal approval control. When an auditor tests internal controls and discovers that a vendor's algorithm made an unauthorized financial change, it fails the requirement—if an action requires managerial sign-off when performed by a human, letting software execute it independently is a major control failure.
The author advises treating vendor-supplied agents exactly like third-party contractors who have not yet passed a background check. Forrester Research emphasizes that extending zero-trust security frameworks to automated business processes is now mandatory for enterprise risk management—zero-trust means no user, device or automated tool gets implicit trust; every proposed action must be validated against explicit business rules before it happens. The practical solution is a three-tiered boundary: read and draft permission (agents can freely analyze trends, draft emails and assemble internal reports, but cannot publish or execute anything on their own); standard administrative permission (tools can handle routine administrative tasks or process standard requests below a strict financial cap, such as a $50 service credit, provided every action is logged for weekly manager review); and restricted financial permission (any action altering contract terms, changing pricing tiers or issuing major refunds must sit in an authorization queue, with a human manager required to click "approve" before the change hits the live database). At the next executive leadership meeting, the author recommends asking for an automated authority inventory to audit every automated feature currently running with permission to alter financial or customer records, reverting all vendor-supplied automated agents to draft-only mode until a clear business case justifies independent authority, and establishing a firm human-in-the-loop policy requiring explicit manager approval before any automated system modifies pricing, contracts or financial ledgers.
The article frames a governance crisis disguised as a technology rollout. For two decades, enterprise IT has invested heavily in security and compliance infrastructure to enforce delegation-of-authority rules—ensuring that a $500,000-approval limit on a VP or a $500 limit on a front-line manager is never exceeded. Yet when software vendors embed autonomous agents into familiar platforms like Salesforce or SAP, the same organizations that police their human workforce often grant these third-party algorithms unrestricted financial power simply because the feature arrives as a native platform update.
The author illustrates the gap with a real example: an automated customer retention agent that independently applied a 15% discount to a multi-year contract without any human sign-off. From the account manager's perspective, the customer was saved. From the audit perspective, a vendor's black-box algorithm executed an unauthorized contract modification that bypassed every internal approval control—a failure that would trigger remediation if a human employee had done it. McKinsey research cited in the article confirms that while adoption of AI automation is accelerating at historic speed, only a tiny fraction of organizations are actively managing the financial and operational risks of automated decision errors.
The solution is not to abandon these tools but to extend governance frameworks that already exist for humans to third-party automated systems. The author advocates a zero-trust approach (no implicit trust for any user, device or tool) and recommends executives conduct an immediate audit of their core platforms to identify which automated features currently have permission to alter financial or customer records, then default all vendor-supplied agents to draft-only mode unless a clear business case justifies giving them independent operational authority.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
As AI innovation accelerates, data centers are moving away from traditional copper wiring to faster, more ener…

Parnassus Core Equity Fund sold its Salesforce holding in Q2 2026, citing declining conviction in horizontal a…

T-Mobile US has announced a focus on aligning its AI initiatives with customer outcomes, according to reportin…

AMD lifted its 2025 revenue guidance after posting strong quarterly results driven by artificial intelligence…

SpaceX released Grok 4.6, benchmarking against Anthropic's latest models and OpenAI's GPT 5.6; AT&T routes 45…

Schnucks, a regional grocery chain, has introduced an AI-powered shopping assistant and redesigned its weekly…

The AI news that matters, in one minute each morning.
Sign up free