By Craig S. Cody, CPA, Certified Tax Coach. Published July 25, 2026.
Here's the answer up front. The biggest risk in letting AI make purchases isn't fraud, it's unauthorized spend: money that moved because the agent's authority was too broad, the controls were too loose, or the audit trail was too thin. Nothing gets stolen. The charge posts, the vendor is legitimate, the books balance, and six weeks later nobody in your shop can say who authorized it or why it was allowed. The fix isn't slowing AI down. It's writing one page that answers five questions before any tool touches your money, and enforcing those rules at the transaction instead of in a policy document nobody reads.
I spent 17 years in the NYPD and retired as a Lieutenant, so I've thought about delegated authority longer than I've been a CPA. In the department you were handed real authority, but it never came alone. There was a defined reason to act, a threshold where you kicked it up to a supervisor, and a memo book where you wrote down what you did and when. Take away any one of those three and the whole thing stops being accountable. That's exactly what most businesses are doing right now with AI and their credit cards.
It's spend a system was able to initiate because its permissions were too wide, its controls too loose, or its record-keeping too thin. Not theft. Not a bug. The transaction worked exactly as designed, and the control is what failed.
The term comes from a piece Andrew Jamison wrote in CPA Practice Advisor on July 23, 2026. He's the CEO of Extend, a spend and expense platform, and he ran B2B corporate payments at American Express before that, so he's watched a great deal of company money move. His argument is that as AI moves from recommending a purchase to actually making one, the real exposure isn't a criminal, it's a permission set.
His line is the one worth keeping: a payment can go through exactly as designed and still create a governance problem. That's the whole issue in a sentence.
You already know how to think about this. When a human spends your money there's a path: a policy, an approver, a cardholder, and some record of why. It's clunky, but you can see who's responsible. AI compresses all of that into software that moves from instruction to transaction in seconds, which is genuinely useful, and which puts every ounce of pressure on a control system you built around humans and monthly review.
No, and that's precisely what makes it dangerous. Fraud sets off alarms. This doesn't.
Jamison's example is deliberately boring. An AI assistant is allowed to handle recurring operating purchases, and it renews a software subscription that looks routine. The charge posts cleanly. The vendor is real. But the contract terms changed, or the amount crossed an approval threshold, or it hit a merchant category that should have triggered a review. The question stops being whether the agent completed the task. The question is whether the system was built to notice.
Here's the comparison that makes it land, and it's his. Say you've got a $20 review threshold on employee cards. Even a reviewer who's rubber-stamping approvals is going to look up when an $8.99 Netflix charge or an $11.99 Spotify charge shows up on a card that has no business carrying either one. A bored human still catches that at a glance. An AI approver won't, unless somebody explicitly told it to care about merchant category. Nobody told it. So those charges clear quietly for months, compounding, until they surface in an audit.
That's the difference between a human control and a machine control. Humans notice things nobody wrote down. Software only notices what you defined.
When owners hear "agentic commerce" they picture a Fortune 500 procurement department and tune out. Skip that. In a 15-person agency there is no procurement department. You are the control layer, and you don't scale to machine speed. Four places this lands:
If you run paid media, you're already moving other humans' money through your accounts. Those pass-through billings inflate your revenue and never touch your gross profit, so they're easy to stop watching closely. Meanwhile the ad platforms keep shipping AI that reallocates budget on its own. That means software with authority to move client dollars at machine speed, against a cap somebody approved on a kickoff call three months ago.
When a client asks why 40% of the month's budget went to a placement they never signed off on, "the tool decided" doesn't survive that meeting. That's not a technology problem. That's a trust problem, and trust is the entire business.
Three ways, and I see all three downstream.
Your deductions. A business expense has to be ordinary and necessary for your business, and the burden of proving that sits with you, not with the IRS. Some categories, travel being the obvious one, carry tighter documentation requirements still. A vendor name on a statement with no context isn't a record of business purpose. Your bookkeeper then does what any reasonable person does with a mystery charge: guesses, or parks it in a catch-all. Either way you paid full price and took a discount you can't defend.
Your monthly close. Every charge nobody can explain is somebody's afternoon. Multiply that by a system generating charges automatically, and your close gets slower and less accurate at the same time, which is the opposite of why you bought the AI.
Your valuation. This is the expensive one. If you ever sell this agency, a buyer will go through your books, and what they're really testing is whether your numbers can be believed. Spend nobody authorized, sitting in an account nobody can trace, is exactly the finding that turns a clean process into a discount. Not because the dollars were big. Because it tells them your controls are soft, and now they wonder what else is.
Jamison puts the principle better than I would: if a company can't trace a transaction back to a permission set, a rule set, and a chain of approval, it has automation without accountability. That's fine in a product demo. It isn't fine in your business.
Write one page. Before any AI in your shop touches a card, an account, or a media budget, answer these five questions in writing. They come straight from Jamison's piece, and they're the right five.
Notice there isn't one word in there about which model or which vendor you use. This isn't an AI policy. It's the same delegated-authority sheet you'd write for a human you just handed a card to, which means you already know how to do it. You just haven't done it for software.
That's the memo book, in business clothes. Defined authority, a threshold, and a record made in the moment.
Because this is the kind of thing a historian will never save you from. Most accountants look in the rearview mirror and tell you what already happened. By the time unauthorized spend shows up as a line on a return, the money's gone and the trail is cold.
The windshield version costs you an hour: one page, five questions, before you switch the thing on. That's running the agency by the numbers applied to a new kind of risk, and it's the cheapest hour you'll spend this quarter.
I'm not anti-AI. I use it, and I've written about what it costs you, how to price so you keep the savings, and how to measure what it returned. This is the fourth question, and it's a different animal from the other three. Those are about money you decided to move. This is about money the software decides to move.
Once software can spend, speed isn't the hard part anymore. Governance is. The owners who treat autonomous spending as a controls problem, not just an automation win, are the ones who'll be able to use this technology aggressively and flourish while doing it. Everybody else gets a surprise, and they'll get it during an audit or during a sale, which are the two worst possible times.
This is for you if any tool, automation, or platform in your business can already move money without a human clicking approve, and you couldn't say off the top of your head what its limits are. It scales down to a founder with a couple of contractors and up to a full floor of humans. The size of the charges isn't the point. The traceability is.
If you're still in the "AI writes our first drafts" stage and nothing you own touches a payment method, bookmark this and come back when it does. And if you were hoping I'd tell you to rip it all out and go back to paper, I'm not your guy. The answer isn't less automation. It's narrower authority, hard limits, and a record you can produce on demand.
What is unauthorized autonomous spend?
It's spending initiated by an AI system that a business didn't meaningfully authorize, because the agent's permissions were too broad, its controls were too loose, or the audit trail was too thin. It isn't fraud. The transaction goes through exactly as designed, and the failure is in the control environment, which usually surfaces months later during a close or an audit.
How do I set spending limits for an AI agent?
Answer five questions in writing before the tool goes live: what it can buy, on whose behalf, the ceiling on both amount and velocity, what requires a human approval, and what justification you can produce afterward. Set the limits at the payment rail or card level so they're enforced at the point of transaction, because a limit written in a policy document doesn't block anything.
Can AI legitimately approve business expenses?
It can screen them, but it only catches what you defined. A human reviewer notices an out-of-place charge like a personal streaming subscription at a glance, while an AI approver won't flag it unless it was explicitly told to care about merchant category. Use AI to enforce the rules you wrote, and keep a human in the loop for new vendors, threshold breaches, and any change in terms.
Is unauthorized AI spending a tax problem?
It can become one. A business expense has to be ordinary and necessary, the burden of substantiation is on the taxpayer, and some categories like travel carry stricter documentation rules. A charge with a vendor name and no record of business purpose is the kind of thing that gets miscoded or parked in a catch-all account, which costs you the deduction or creates a mess at audit.
Should agencies let AI manage client ad budgets?
Only with written client authorization and hard caps on both spend amount and pace. Agencies move client money through their own accounts, so an AI reallocating budget on its own is spending someone else's dollars under your name. Put the authority in the scope of work, not in a Slack thread, and keep a record showing what the system was allowed to do.
Here's a 40-minute exercise for this week. Pull the last 90 days of charges on every company card and connected account, and circle every one no human specifically approved. Don't judge them yet, just count. That number is your actual exposure, and it's usually bigger than owners expect because most of it is renewals and platform charges you stopped reading a year ago.
Then write the five answers on one page for anything AI-driven that can touch money. If you can't answer all five, that tool's authority is too broad, and today is a much better time to tighten it than after the close.
If you'd like a second set of eyes on your controls, your books, and whether the money moving through your agency is actually defensible, a free tax and profit analysis is where we look at the real numbers together and tell you the truth about what we find. Let's talk.
Craig S. Cody is a CPA, Certified Tax Coach, and former NYPD Lieutenant who helps agency owners keep more of what they make through proactive, year-round tax planning and fractional CFO work. The definition of unauthorized autonomous spend, the routine-renewal example, the merchant-category comparison, and the five adoption questions come from Andrew Jamison's July 23, 2026 article in CPA Practice Advisor; the agency application, the cost analysis, and the one-page framing are my own.