Skip to main content
    All shows

    CFO Daily · Monday, September 21 · 6 min

    CFO Daily · Monday, September 21, 2026

    0:00-:--
    Speed

    Transcript

    Hi, this is Koko from Koko Knows.

    Let's get right to what's new for you today. EY just published its AI Risk and Governance Survey, and it names something a lot of you have been managing on gut instinct: agentic AI is scaling inside your organizations faster than the risk frameworks, assurance processes, and board-level accountability meant to contain it. That report lands just two days after Cyera's incident analysis found something more concrete and honestly more unsettling. Cyera screened over seven thousand reported AI incidents and verified one hundred eighty-eight cases where AI agents caused direct enterprise harm with zero attacker involved. No hack, no bad actor. These were agents simply doing their assigned tasks and breaking production systems in the process.

    Put those two together and you get the theme of the week: this isn't an adoption speed problem anymore. It's a governance debt problem, and it's compounding.

    Here's why this matters specifically for you. If you've got agents touching close processes, payments, or reconciliation, or if you're piloting that kind of authority expansion right now, EY's survey is telling you that most organizations do not have the assurance sign-off structure in place to catch a failure before it happens. Cyera's data tells you what that failure actually looks like in the wild. So the action item is simple and it's a gating step, not a nice-to-have: before you expand any agent's write-access or decision authority over financial workflows, require independent assurance sign-off. Not a vendor's self-reported ROI dashboard. An actual third-party or internal audit function confirming the controls hold. Mirror what the best-governed organizations in EY's survey are already doing, because the ones who aren't doing it are the ones showing up in incident reports.

    Now, on the vendor side, keep an eye on Anthropic. Their revenue run-rate just crossed one hundred billion dollars, which is a massive number by any measure. But in the same week, their own CEO publicly called for slowing down capability development, and the company pushed its IPO to November specifically so it could report third-quarter results first. That's a real disconnect worth noting if Anthropic is anywhere in your vendor stack for finance-critical agent work. Growth rhetoric and safety rhetoric are pulling in opposite directions at the same company, in the same week. Treat that as a due-diligence flag, not just an interesting headline. Ask your vendor management team to get specific about what capability slowdown actually means operationally, and whether it touches anything you're relying on.

    On the measurement front, OpenAI's Admin Console added task-level ROI tracking this week, which sounds like progress. But independent, third-party verification of finance-AI returns is still thin on the ground. OpenAI also touts enterprise revenue now above forty percent of its total. That's a growth claim, not proof of value delivered to your P&L. Keep pushing your own finance and IT teams to produce outcome data you control, not figures the vendor hands you.

    One more pattern worth flagging for your risk committee conversations: across the industry, several major AI labs have only disclosed agent security breaches after a reporter asked about them directly, not proactively. That's becoming the norm rather than the exception. So here's a concrete move you can make this week. Go back to your AI vendor contracts and check whether they include breach-disclosure terms with real teeth and real timelines. If they don't, get that into your next renewal or amendment discussion now, while it's a contract clause and not a crisis headline.

    And zoom out for a second on cost. Nobody has priced containment failures, monitoring, and incident response into what you're currently paying for agent access. That cost is real, it's coming, and right now it's sitting off your books. If you're building next year's AI budget, get a specific line item in there for agentic security and containment testing before an incident forces you to create one on an emergency basis.

    Last thing, and this one's more structural: your ERP is staying the system of record, but the experience layer, the place where people and agents actually interact with your systems, is moving up into a semantic, AI-driven layer on top. SAP, Oracle, Salesforce, Microsoft are all building toward this. The safest pattern emerging is what people are calling "clean core plus composable edge." keep your core financial systems stable and upgrade-safe, and let agentic orchestration wrap around them through controlled extensions. That approach tends to build more confidence with your audit and compliance stakeholders than letting agents reach directly into core systems. Worth raising with IT if you haven't already.

    That's the rundown for today. Bottom line: require assurance before you expand agent authority, get breach disclosure into contracts now, and start budgeting for security you're not currently paying for. That's Koko Knows, back with you tomorrow.