The Biggest Risk in Agentic Commerce Is Unauthorized Autonomous Spend

Small Business | July 23, 2026

The Biggest Risk in Agentic Commerce Is Unauthorized Autonomous Spend

The businesses that treat autonomous spending as a controls problem, not just an automation opportunity, will be in a much better position to use it responsibly.

Andrew Jamison

There is a lot of understandable excitement around AI taking friction out of business purchasing. If software can book travel, buy supplies, renew services, or trigger payments on its own, companies save time, work moves faster, and fewer low-value decisions land on someone’s desk. But the closer AI gets to the point of purchase, the less this becomes a story about efficiency and the more it becomes a story about control. Once a system can actually commit company funds, the central question is no longer whether it saves time but whether the business can explain the spend after the fact: who authorized it, what rules were in place, and what records exist if someone needs to review them later.

That is why I think the bigger risk in agentic commerce is unauthorized spend. I don’t mean fraud in the usual sense. I mean spend that a system was able to initiate because the agents authority was too broad, the controls were too loose, or the audit trail was too thin. A payment can go through exactly as designed and still create a governance problem for finance and accounting.

That distinction matters because enterprises already know how to think about employee spend. There is usually a policy, an approval path, a manager, a cardholder, and some record of why a purchase was made. The process may not be elegant, but the line of responsibility is usually visible. AI changes that by compressing decision-making into software. An agent can move from instruction to transaction in seconds, which is useful, but it also puts pressure on control frameworks that were built around human action and after-the-fact review. When money is moving on the basis of automated judgment, the old questions come back with more urgency: Who had the right to initiate the spend? Was the purchase within policy? Should a human have reviewed it first? Can the company reconstruct what happened without guessing?

For accountants and finance leaders, this isn’t an abstract concern. Consider a simple example: an AI assistant is allowed to handle recurring operating purchases and renew a software subscription that looks routine. The transaction may post cleanly, and the vendor may be legitimate, but if the contract terms changed, the amount crossed an approval threshold, or the purchase hit a merchant category that should have triggered a review, the issue is no longer whether the agent completed the task. The issue is whether the system was built to notice — to flag the change, hold it for approval, or deny it outright. If it wasn’t, the transaction just goes through, and nobody finds out until it surfaces in an audit. 

Compare that to how this already works with humans. Finance might set a $20 approval review threshold on employee cards, but a reviewer who’s rubber-stamping approvals will notice at a glance when an $8.99 Netflix charge or an $11.99 Spotify charge starts showing up on a card that shouldn’t have either. An AI approver won’t catch that unless it’s explicitly told to care about merchant category. Without that rule, those charges just clear quietly, until someone finds them in an audit months later — by which point they’ve compounded.

The same problem applies to travel booking, ad spend, vendor payments, procurement, and expense workflows. If businesses give AI broad authority because it’s convenient, they may only discover the gaps later, during close, during audit prep, or when someone asks why money moved without the controls everyone assumed were there.

That’s why the control layer matters so much. In practice, companies will need to define autonomous spend much more narrowly than many of today’s AI demos suggest. Permissions need to be specific, merchant restrictions need to be explicit, and spend thresholds need to be enforced at the point of transaction rather than buried in a policy document. Approval logic also needs to reflect context so that a low-risk repeat purchase is treated differently from a new vendor payment or an unusual exception. And if a transaction goes through, there should be a clear record showing what the system was allowed to do and why it was allowed to do it.

That last point is especially important because auditability is not some extra layer to add later. It is part of whether autonomous spend is workable at all. If a company can’t trace a transaction back to a permission set, a rule set, and a chain of approval, then it has automation without accountability. That may be acceptable in a product demo, but it’s not acceptable inside an enterprise finance environment.

This is also where I think the conversation around AI in payments is becoming more practical. For a while, the attention was on what AI could do. Now the more useful question is what AI should be allowed to do on its own, and under what conditions. That is a better enterprise question because it gets closer to how finance teams actually operate. They are not rewarded for novelty. They are rewarded for making sure spend is authorized, documented, and defensible.

The companies that get this right will not be the ones that simply make payments disappear into the background. They will be the ones who make automated spend easier to govern. In other words, the next phase of payments infrastructure is less about handing more authority to software and more about building better rules around delegated authority in the first place. That is the shift I expect accounting and finance teams to push hardest on as AI purchasing becomes more common. Before they embrace autonomous payments at scale, they will want answers to some basic questions: What can this system buy? On whose behalf? Is there an upper limit on spend amount or velocity of transactions? With what approvals? And if something goes wrong, what justification can be produced?

Those are the real adoption questions. AI will absolutely make parts of enterprise purchasing faster, but once software can spend, speed is not the hardest part. Governance is. The businesses that treat autonomous spending as a controls problem, not just an automation opportunity, will be in a much better position to use it responsibly. For the accounting profession, that is likely to be the dividing line between AI systems that are merely impressive and AI systems that are actually usable in production.

ABOUT THE AUTHOR:

Andrew Jamison is CEO and co-founder of Extend, an AI-powered spend and expense management platform that helps businesses and banks modernize card spend, expense workflows, and embedded payments without replacing existing card programs. Before founding Extend, he led B2B Corporate Payments Products at American Express, where he drove digital payment innovation and doubled B2B payment volumes over six years. He previously spent eight years managing global SAP deployments for large multinational corporations.

Sign in to get access to this free resource, and all of our whitepapers and reports.

Download this content today!

Register to get free access to this content, as well as newsletters, continuing education, podcasts, and more…

Leave a Reply

Andrew Jamison

Andrew Jamison

Chief Executive Officer, Co-founder of Extend

Andrew Jamison started Extend with a view to fill the gap in modern spend & expense tools for SMBs and their trusted bank partners. Prior to Extend, Andrew was the head of B2B Corporate Payments Products at American Express with a mandate to drive digital payment innovation and adoption. Over the course of six years, he doubled B2B payment volumes by launching and scaling new capabilities and platforms. Prior to American Express, Andrew spent eight years managing global SAP deployments for large multinational corporations. He earned an MBA from INSEAD.