threat_intelligence526 wordsRead on Arc Codex

AI agents gain access to financial workflows amid growing governance gaps

A Pathlock report found that 53% of organizations cannot fully verify what AI agents do across business systems, even as they gain authority over finance, HR, procurement, and supply chain workflows. AI agents are now being allowed to create business records, approve transactions, and execute financial workflows. ERP security firm Pathlock says most organizations don’t know if that is all they are doing. The company’s 2026 AI Governance Gap Report found that 79% of organizations do not have a dedicated AI governance team, despite AI agents being increasingly plugged into business-critical operations like finance, procurement, HR, and supply chain applications. More than half of the organizations surveyed by Pathlock said they can’t fully verify actions AI agents execute across these business systems. “For decades, governance focused on controlling who could access a system,” said Susan Stapleton, GRC expert at Pathlock. “AI agents introduce a different challenge: understanding what actually happened after access was granted.” Being able to verify, trace, investigate, and explain AI-driven actions in real time across business applications will determine an organization’s AI preparedness, she added. Agents moving from copilots to financial operators The survey suggested enterprises are already trusting AI agents with responsibilities that until recently belonged exclusively to employees. Among surveyed respondents, 38% said AI agents can create or modify vendors and other business records, 35% allow them to execute cross-system workflows, and 28% permit them to approve transactions. More than one-third (36%) have already deployed, or are actively implementing, AI agents within finance and accounting environments. Most notably, about one in four organizations allow AI agents direct access to backend databases, Pathlock said in a report that CSO reviewed ahead of its publication. Chris Radkowski, another GRC expert at Pathlock, said three trends are converging simultaneously: the growth of machine identities, increasingly interconnected enterprise applications, and AI agents capable of executing business processes autonomously. The findings illustrate why machine identities are becoming a problem for security, said Crystal Morin, senior cybersecurity strategist at Sysdig. “As automation and AI-driven development explode, the gap between human and machine identities is becoming one of the defining security challenges of our time,” Morin said. “Businesses must treat machine identities as the new firewall.” Governance is still catching up While enterprises have begun introducing governance controls, the report argues most remain rooted in human-centric security models that focus on who receives access rather than what autonomous systems actually do after access is granted. Only 19% of organizations said they have complete, real-time visibility into AI agent activity across business systems, while 53% admitted they cannot fully verify AI-driven actions. Nearly half (48%) cannot trace AI activity end-to-end across multiple systems, making it difficult to reconstruct how an AI-driven outcome was produced. Investigation capabilities remain equally immature. Just 13% can investigate AI incidents in real time, while 22% cannot reliably investigate AI-driven actions at all. Ram Varadarajan, CEO at Acalvio, said traditional security approaches are unlikely to help. “General-purpose AI and traditional ‘check-the-box’ security audits are a false comfort when the actual battle is moving in milliseconds,” he said. “To maintain competitive edge and protect valuation, companies have to pivot from reactive defense to active, game-theoretic defense.”

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.