AI agents are approving transactions and nobody is watching

A new report finds most companies have handed financial controls to AI systems they cannot audit, trace, or investigate in real time.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A close-up, sharply focused photograph of a glowing laptop screen in a darkened office, showing lines of green and white code reflecting faintly on a glass desk
Share

Key points

  • 79% of organisations surveyed by Pathlock in 2026 have no dedicated team overseeing what their AI systems do inside business applications.
  • 28% of organisations allow AI agents to approve financial transactions without a human in the loop.
  • Only 13% of organisations can investigate an AI-driven incident as it happens.
  • More than half of surveyed organisations admit they cannot fully verify what actions their AI systems have actually taken.

Somewhere inside a company's finance or HR software, an AI agent is creating a vendor record or approving a payment. Nobody signed off. At most companies, nobody's watching.

That's the core finding of Pathlock's 2026 AI Governance Gap Report, first covered in detail by CSO Online. Pathlock makes software that controls access to business applications, and its survey paints a picture of AI moving faster than the guardrails organisations are supposed to build around it. We've tracked this pattern across four stories since July, most recently autonomous agents attaching themselves to company accounts with wide permissions and no oversight.

What are AI agents, and why does this matter?

AI agents are software programs that act inside other systems on your behalf: not just answering questions, but actually doing things. Filing records, moving money, updating databases. Think of them as a new category of employee who never sleeps, never asks for permission, and leaves no signature on the forms.

The systems involved control payroll, vendor payments and supply chains. Errors or abuse here produce real financial harm, quickly.

How much access do these AI agents actually have?

A lot, according to the report. Among organisations surveyed, 38% said their AI agents can create or modify vendors and other business records. Thirty-five percent allow AI to run workflows that span multiple connected systems. Twenty-eight percent let AI approve transactions outright.

Perhaps most striking: roughly one in four organisations give AI agents direct access to backend databases, the raw stores of data sitting underneath business software. More than a third have already deployed AI agents inside finance and accounting environments.

AI agent permission Share of organisations
Create or modify business records 38%
Execute cross-system workflows 35%
Approve transactions 28%
Deployed in finance and accounting 36%

Can companies tell what their AI is doing?

Mostly no. Only 19% of organisations have full, real-time visibility into what their AI agents are doing across business systems. Forty-eight percent can't trace AI activity end-to-end across multiple connected applications, which means reconstructing what led to a given outcome is often impossible. Only 13% can investigate an AI-driven incident while it's still happening; 22% can't reliably investigate AI-driven actions at all.

"For decades, governance focused on controlling who could access a system," said Susan Stapleton, GRC expert at Pathlock. "AI agents introduce a different challenge: understanding what actually happened after access was granted."

Traditional security tools check identities: they ask "who are you?" before letting someone in. AI agents aren't people. They hold what security teams call machine identities, digital credentials proving a piece of software is allowed to act. Those credentials are multiplying fast, and the tools to monitor what they do once inside are lagging badly.

Should you worry about what your AI is doing right now?

Yes, and the place to start is an inventory. List every AI agent that holds access to financial or HR systems, confirm what permissions each one carries, and apply the same logic used for human employees: least privilege, meaning each agent should only be able to perform the specific tasks it genuinely needs, nothing more.

For employees working alongside these systems, the practical step is blunt: if an AI-generated action in a financial system looks wrong, report it. Unusual new vendors, unexpected approvals and unexplained database changes are worth flagging even if the software is supposed to be trusted.

Common questions

Does this mean AI agents are being hacked?

Not necessarily, though the audit gaps would make it easier for a hack to go undetected. The current concern is mainly that AI agents can make mistakes or be misconfigured, and most organisations wouldn't catch it quickly.

Would adding extra login steps for humans fix this?

Partly. Multi-factor authentication, where a system asks for a second proof of identity such as a code sent to your phone, protects human accounts. It doesn't govern what an AI agent does after it's already been granted access, which is where the real gap sits.

© 2026 Threat Vectr