Finance leaders appear ready for AI agents. They are much less ready to hand over the keys.
Deloitte’s Finance Trends 2027 research found that 95% of surveyed finance leaders are comfortable with agentic workflows in at least some finance activities. Yet only 14% support full autonomy for critical decisions.
That gap is not evidence that finance is resisting innovation.
It is evidence that finance understands something important: automation and accountability are not the same thing.
The wrong debate is human versus machine
The useful question is not whether an AI agent should ever act without a human clicking “approve.”
The useful question is: What level of autonomy is appropriate for this decision, given its dollar value, reversibility, risk, and uncertainty?
Finance already works this way with people.
A junior employee may be able to code an invoice but not release a wire. A manager may approve a routine purchase but not a major contract. A treasury system may automatically move cash within defined limits but escalate unusual activity.
AI agents should be governed with the same underlying principle: authority should increase only as the risk becomes better understood and the controls become stronger.
Three levels of autonomy
Level 1: Recommend
The agent analyzes information and proposes an action, but a person makes the decision.
This is the easiest place to start: variance explanations, account-reconciliation suggestions, draft forecasts, contract summaries, or recommended follow-up questions.
Level 2: Act with approval
The agent prepares and initiates an action, but a human approves before it becomes final.
This can work for tasks such as journal-entry preparation, payment workflows, vendor communications, or budget adjustments—provided the human reviewer receives enough context to make a real decision rather than rubber-stamping the output.
Level 3: Act within limits
The agent can execute without individual approval, but only inside predefined boundaries.
Those boundaries might include dollar limits, approved counterparties, known transaction types, confidence thresholds, time windows, or reversible actions.
Autonomy should be a controlled permission—not a personality trait of the software.
A practical control stack
If an organization wants agentic AI to move beyond experimentation, it needs more than a policy document. It needs operating controls.
- Data permissions: What information can the agent see?
- Action permissions: What can it change, send, approve, or initiate?
- Dollar limits: At what financial threshold does a human have to intervene?
- Confidence thresholds: When should the system escalate because the answer is uncertain?
- Exception rules: What patterns automatically trigger review?
- Audit logs: Can the organization reconstruct what the agent did and why?
- Reversibility: Can an incorrect action be undone quickly?
- Independent review: Who tests whether the control environment still works as the system changes?
Human review also needs a design
“A human is in the loop” sounds comforting, but it can be meaningless if the human receives hundreds of approvals, lacks context, or assumes the machine is probably correct.
Good oversight should be designed around exceptions and consequences.
Low-risk, highly repetitive, reversible decisions can move faster. High-dollar, unusual, irreversible, regulatory, or judgment-heavy decisions should receive more scrutiny.
That is not fundamentally different from how a strong finance organization already structures authority.
Trust should be earned in layers
Organizations often want a binary answer: Is the AI safe enough to use?
A better answer is conditional.
The same AI system might be safe enough to summarize a policy, useful but review-required for a forecast recommendation, and completely inappropriate to autonomously authorize a material payment.
Trust should therefore attach to the specific workflow and permission set, not to the brand name of the AI tool.
The 95% / 14% gap is healthy
Finance leaders appear willing to use AI agents while remaining cautious about critical autonomous decisions.
That is exactly the posture I would want.
The goal is not maximum autonomy.
The goal is the right autonomy for the right decision, backed by controls that make responsibility clear.
Source: Deloitte, Finance Trends 2027.
