AI agents are approving transactions and nobody is watching

A new report finds most companies have handed financial controls to AI systems they cannot audit, trace, or investigate in real time.

ThreatVectr Newsdesk· 4 min read
A close-up, sharply focused photograph of a glowing laptop screen in a darkened office, showing lines of green and white code reflecting faintly on a glass desk
Share

Key points

  • 79% of organisations surveyed by Pathlock in 2026 have no dedicated team overseeing what their AI systems do inside business applications.
  • 28% of organisations allow AI agents to approve financial transactions without a human in the loop.
  • Only 13% of organisations can investigate an AI-driven incident as it happens.
  • More than half of surveyed organisations admit they cannot fully verify what actions their AI systems have actually taken.

Somewhere inside a company's finance or HR software, an AI agent is creating a vendor record, approving a payment, or kicking off a cross-department workflow. Nobody pressed a button. Nobody signed off. And at most companies, nobody is watching.

That is the core finding of Pathlock's 2026 AI Governance Gap Report, first covered in detail by CSO Online. Pathlock makes software that controls access to business applications, and its survey paints a picture of AI moving faster than the guardrails organisations are supposed to build around it.

What are AI agents, and why does this matter?

AI agents are software programs that can take actions inside other systems on your behalf, not just answer questions, but actually do things: file records, move money, update databases. Think of them as a new category of employee who never sleeps, never asks for permission, and leaves no signature on the forms.

For ordinary people this matters because the systems involved are the ones that control payroll, vendor payments, purchasing, and supply chains. Errors or abuse here produce real financial harm.

How much access do these AI agents actually have?

A lot, according to the report. Among the organisations surveyed, 38% said their AI agents can create or modify vendors and other business records. Thirty-five percent allow AI to run workflows that span multiple connected systems. Twenty-eight percent let AI approve transactions outright.

Perhaps most striking: roughly one in four organisations give AI agents direct access to backend databases, the raw stores of data that sit underneath business software.

AI agent permission Share of organisations
Create or modify business records 38%
Execute cross-system workflows 35%
Approve transactions 28%
Direct backend database access ~25%
Deployed in finance and accounting 36%

Can companies tell what their AI is doing?

Mostly no. Only 19% of organisations have full, real-time visibility into what their AI agents are doing across business systems. Forty-eight percent cannot trace AI activity end-to-end across multiple connected applications, which means reconstructing what led to a given outcome is often impossible. Only 13% can investigate an AI-driven incident while it is still happening.

"For decades, governance focused on controlling who could access a system," said Susan Stapleton, a governance and risk expert at Pathlock. "AI agents introduce a different challenge: understanding what actually happened after access was granted."

This is a meaningful shift. Traditional security tools check identities, meaning they ask "who are you?" before letting someone in. AI agents are not people. They hold what security teams call machine identities, digital credentials that prove a piece of software is allowed to act. Those machine identities are multiplying fast, and the tools to monitor what they do once inside are lagging badly.

What should organisations do right now?

Start by inventorying every AI agent that has been granted access to financial or HR systems, and confirm what permissions each one holds. Apply the same logic used for human employees: least privilege, meaning each agent should only be able to do the specific tasks it genuinely needs to perform, nothing more.

For employees who work alongside these systems, the immediate practical step is straightforward: if an AI-generated action in a financial system looks wrong, report it. Unusual new vendors, unexpected approvals, and unexplained database changes are worth flagging even if the software is supposed to be trusted.

Common questions

Does this mean AI agents are being hacked?

Not necessarily, though the audit gaps would make it easier for a hack to go undetected. The current concern is mainly that AI agents can make mistakes or be misconfigured, and most organisations would not catch it quickly.

Would adding extra login steps for humans fix this?

Partly. Multi-factor authentication, where a system asks for a second proof of identity such as a code sent to your phone, protects human accounts. It does not govern what an AI agent does after it has already been granted access, which is where the real gap sits.

© 2026 Threat Vectr