As enterprises connect AI agents to email, procurement software, ERP systems, bank accounts and payment infrastructure, they are giving software authority. An agent that can read an invoice, create a vendor, approve a purchase and initiate a payment does not necessarily need to defeat a company’s financial controls to cause damage. The company may have inadvertently automated its way around them.
“I think every enterprise is already agentic, and the question is how far along are they on that journey,” PYMNTS CEO Karen Webster said in a Tuesday (Oct. 6) thought leadership piece for the seventh annual PYMNTS B2B Payments event. “There’s always been a deployment of AI in these businesses. The question is how much is it embedded in the organization … and how many business activities does it really cover?”
That is turning one of accounting’s oldest ideas, segregation of duties, into a freshly important component of AI security architecture.
See also: The New Cyber Math for CFOs: One Attack, Hundreds of Disclosures
AI Agents Are Breaking Finance’s Oldest Rule
Finance organizations have spent decades ensuring that the person who creates a vendor cannot also approve that vendor and release its payments. The principle assumes that no one should control enough of a financial process to turn a mistake or malicious instruction into money leaving the company.
Agentic AI complicates that assumption because enterprises are increasingly designing agents around outcomes rather than roles. “Pay this invoice” may look like one task to an AI system. To a controller, it is deliberately several.
There is already evidence that the infrastructure connecting agents to enterprise systems creates new trust problems. Organizations as varied as Google, JPMorganChase, Weaviate and France’s interministerial digital directorate have confirmed vulnerabilities involving the agentic ecosystem’s model context protocol, or MCP, implementations. Several involved server-side request forgery, in which insufficiently validated inputs could cause a server to communicate with unintended destinations, while others included prompt injection attacks.
What makes the pattern relevant to finance is less any particular vulnerability than the architectural assumption underneath it. Data arriving through an agentic workflow cannot automatically be treated as trustworthy simply because it came from somewhere inside the system.
Google’s security teams have warned that such attacks become more consequential as models gain agentic capabilities and access to multiple data sources.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
The PYMNTS Intelligence report “When Fraud Becomes the Customer: The Next Battlefront for Issuers” found in September that the industry is confronting a shift from isolated fraudulent transactions toward persistent identity-based attacks that can begin before a payment is initiated, thanks to AI advances.
Read also: Agentic AI Could Make Net 30 Obsolete
Finance Agents Are Collapsing the Payment Control Stack
Traditional segregation of duties divides a transaction into distinct authorities. Somebody requests an action, somebody validates it, somebody approves it, and somebody or something executes it.
Agentic systems are recombining these steps. Consider what that means inside accounts payable. An invoice arrives by email. An agent extracts the payment information, checks the purchase order, enters the invoice into the ERP and prepares the payment. The efficiency gain comes from eliminating handoffs.
But the handoffs were often security-critical controls. The irony is that finance may already possess one of the most useful frameworks for securing AI. Segregation of duties was designed for a world in which employees could make mistakes, collude or abuse legitimate authority. Agentic AI introduces a different player, but the control logic survives.
The PYMNTS Intelligence report “Tech on Tech: How the Technology Sector Is Powering Agentic AI Adoption” revealed in August 2025 a widening agentic readiness gap between tech companies and firms in goods and services, with 75% of tech firms reporting they were extremely familiar with agentic AI, versus 33% of goods firms and 38% of services firms.
“As an AI agent begins to assist with purchasing decisions, the payment ecosystem has to make that value chain machine readable,” Mike Magennis, senior director of Strategy, Networks at FIS, told PYMNTS this month. “An agent needs to understand not just whether a payment credential works, but which choice delivers the best relevant outcome for that consumer.”
The more scalable model is likely risk-based autonomy. An agent could automatically execute repetitive, low-value transactions with established vendors inside predetermined limits. New beneficiaries, changed bank details, unusual transaction patterns, large payments or attempts to alter permissions could trigger progressively stronger controls.
For all PYMNTS AI, B2B and digital transformation coverage, subscribe to our daily newsletters.