This isn’t another “AI is coming for accountants” piece. It’s about the org chart — specifically, the blank space in it where AI accountability is supposed to sit.
Ask a finance leader whether AI touches their numbers now, and you’ll get a quick yes. Ask them who’s actually accountable when it gets something wrong, and the pace of the conversation changes. There’s a pause. Sometimes a laugh that isn’t really a laugh. AI has slid into forecasting, fraud detection, expense review, collections — real steps in the decision chain, not just dashboards nobody reads. What hasn’t kept up is the much older, much less exciting question of whose name goes on the outcome. There’s a term for this gap now: the “AI proof gap” — the distance between how far AI has actually been deployed and how confidently a company could prove, if pressed, who owns what it produces. And the gap is bigger than most people in finance would guess. A large majority of executives surveyed in 2026 admitted they couldn’t pass an independent AI governance audit within 90 days if asked. Meanwhile three in four boards have already approved serious AI spending. Fewer than half of them bothered setting governance expectations before writing the check.
Who’s on the hook when the AI gets it wrong?
Most finance functions, if they’re honest, have never actually answered this. If a model misclassifies an expense, buries a fraud signal, or hands the board a forecast built on a bad number, the real answer at a lot of companies is: depends who’s standing nearby when someone notices. That was fine when AI was just offering suggestions a human could wave off. It’s a different story now that AI increasingly acts on its own, and regulators have started to notice the difference too. US banking supervisors flagged something worth sitting with earlier this year: the model risk guidance everyone relies on was written before generative and agentic AI existed. It doesn’t clearly cover either one.When “human review” stops meaning anything
Every AI rollout in finance comes with the same reassurance — don’t worry, there’s a human in the loop. Fewer of those claims survive a second look. Nobody exercises real judgment reviewing a hundred AI-flagged items in the time it used to take to review ten. That’s not oversight, that’s a rubber stamp with extra steps, and most people on the team quietly know it. The distinction regulators and auditors are starting to press on isn’t whether a human technically clicked approve. It’s whether that human had the time, the context, and the actual authority to say no. A signature isn’t the same thing as a judgment.Model risk and knowing where the numbers came from
Old-school model risk management assumed a static model — something built, documented, and left alone until the next scheduled review. Agentic AI doesn’t sit still like that. The same system can behave differently next month as it fine-tunes itself or gets chained together with other tools nobody formally signed off on. So the control frameworks are moving — pushing oversight earlier, asking for real-time evidence of how a judgment actually got made rather than just checking the final number. For a finance team, that changes the question from “is this number right” to something harder: “could we explain, six months from now, exactly how the model arrived at it.” Most teams can’t, yet.Segregation of duties, now that the duties aren’t human
Segregation of duties is about as old an idea as finance controls get — one person requests the payment, a different person approves it. Autonomous workflows quietly erase that line. The same AI system that flags an anomaly can turn around and propose the fix, and unless someone deliberately built a wall in the middle, nothing stops it. Newer governance frameworks are trying to name this explicitly: map every AI step that carries real financial consequence, and make sure at least one checkpoint in that chain sits outside the system’s own control — not just outside one employee’s inbox.An uncomfortable one: does finance actually understand what it’s approving?
Here’s the question that doesn’t get asked out loud very often. When finance signs off on a new AI forecasting tool, do they actually understand how it reaches its numbers — or did the demo look good and the vendor’s compliance page say the right words? A 2026 survey of banking and finance leaders found most don’t have full confidence in their own AI controls, which is a fairly striking thing for the people responsible for approving them to admit. It’s hard to own a risk you can’t explain to someone else.What an audit committee is going to ask anyway
Guidance for audit committees this year has more or less converged on the same handful of questions. Worth asking yourself before someone else asks you first:- Where is AI actually being used across reporting, controls, and compliance — and how confident are you in that inventory?
- How are those AI-driven processes monitored as the underlying models and data keep changing?
- Who specifically owns each AI-related risk, and what happens when something needs to be escalated?
- Is the governance behind it documented well enough to hold up to an outside auditor, not just an internal review?
- Can internal audit actually test the AI-driven control itself, or only the human step wrapped around it?
- Where does AI influence judgment calls in accounting estimates and disclosures — and is that influence disclosed anywhere?