Skip to content

1.10.2026 | Last updated: 1.10.2026

5 min read

How far should AI be allowed to go in treasury?

A lot of the current discussion around AI agents is focused on capability. What can an agent answer? Which tasks can it perform? How many steps can it automate?

Those are useful questions. In treasury, I think there is another one that matters even more: how much authority should the system have?

The answer cannot be “as much as the technology allows”. Treasury has spent decades building controls around access, payments, financial instruments and approvals for good reasons. An AI layer should not make those reasons disappear.

The product challenge is therefore to increase the amount of work software can handle while being very deliberate about the moments where a person remains responsible.

We should separate information, preparation and authority

I find it useful to think about AI activity in three levels.

The first is information. The user asks a question and the system retrieves the relevant data, calculates through the financial platform and explains the answer.

The second is preparation. AI can assemble a report, draft a supported change or prepare the next step for review.

The third is authority. Something actually changes: a record is updated, a workflow moves or a financial action is approved.

These levels should not be treated as one continuous permission. A user may be comfortable allowing AI to retrieve and organise information while still requiring a clear confirmation before a change and a separate authorised approval for a payment.

That separation is where good agent design begins.

Treasury does not need the language model to do the maths

One architectural choice I feel strongly about is keeping financial calculation outside the language model.

If you ask an AI assistant for the current cash position, the model is excellent at understanding what you mean by “current”, which entities you are referring to and how you want the answer presented.

It should not invent the number or calculate the position from memory.

The platform already has services for retrieving balances, aggregating data and converting currencies. Those services are deterministic and subject to the existing permission model. The AI should orchestrate them and explain the result.

This sounds technical, but it is actually a product principle: use AI for the parts where language and flexibility are valuable, and use the financial system for the parts where repeatability is essential.

The permission model should survive every interface

We are also entering a world where the user interface may no longer belong to one application.

A treasury professional might ask a question inside Nomentia today and use an approved enterprise AI client like Copilot/Claude tomorrow. An organisation may build an internal agent that works across several finance systems.

That creates a temptation to treat the agent as a privileged integration. I think the opposite should happen.

The user’s identity and permissions should remain the boundary. If a person can see three entities in Nomentia, an agent acting for that person should see those three entities. If the user does not have access to a module, asking through another AI client should not change that.

MCP is valuable here because it can provide a common interaction standard. But the protocol is only useful for treasury when the services behind it retain the same governance as the platform itself.

Confirmation is a design feature, not friction

In consumer software, every extra confirmation is usually treated as bad user experience.

Treasury is different. There are moments where a confirmation is the product working correctly.

If AI proposes a supported change, the user should see what is about to happen and actively confirm it. A wrong or incomplete answer should never silently become an irreversible action.

That review moment also makes the boundary legible. Users can become comfortable letting the system prepare more work because they know when responsibility returns to them.

The same logic applies to payments and other governed workflows. An AI agent can help explain an exception, gather context or prepare the next step. The authorised approver still owns the approval.

We should not confuse agents with autonomous finance

The word “agent” is already being used very broadly.

Sometimes it means a conversational assistant that can call tools. Sometimes it means a system that runs a multi-step process independently. Sometimes it implies software making decisions without a person in the loop.

Treasury buyers deserve clarity about which of those meanings applies.

Our current approach is focused on assisted and augmented work. The AI can interpret a request, retrieve live data, use governed platform services, present the answer and prepare certain supported actions. The human reviews, decides and confirms. Existing module approvals remain human.

That may sound less dramatic than fully autonomous treasury. It is also much more useful as a starting point for organisations that need to deploy AI inside real financial controls.

The value appears long before full autonomy

There is sometimes an assumption that agentic AI becomes valuable only when it can run an entire process by itself.

I disagree.

Consider the amount of treasury time spent locating information. Which payments are rejected? What arrived overnight? How much did we pay this counterparty? Which entity owns this account? What is the cash position by currency? How do I perform this task in the system?

None of these questions requires autonomous decision-making. They require fast, reliable access to information.

If a team can remove ten navigation exercises and five expert interruptions from a normal day, that is already meaningful. If the CFO can ask a question during a meeting and treasury can answer while the discussion is still happening, that changes the quality of the interaction.

We should not delay practical value while waiting for a future definition of autonomy.

The biggest adoption risk may be unmanaged AI outside the platform

There is another reason to bring governed AI into treasury sooner.

Employees already use AI. If the treasury system has no practical route into that way of working, the workaround is predictable: export the data and paste it somewhere else.

From a product perspective, telling users not to do that is unlikely to be enough. The governed route has to be at least as useful as the shortcut.

That means treasury platforms need to support natural-language access and increasingly the AI clients organisations have approved at enterprise level. But they need to do it without giving up the permission, audit and data-handling model that finance depends on.

The best defense against shadow AI is a controlled alternative people actually want to use.

Audit trails need to follow the agent

If a person clicks through a treasury system, we expect important activity to be logged. The expectation should be the same when an AI agent calls the service.

The interface cannot determine whether an action is auditable.

This becomes more important as finance teams connect agents across applications. IT, treasury and audit need to be able to see that an interaction came from a particular authenticated user, stayed within that user’s rights and resulted in a particular confirmed action.

Otherwise the organisation gains a faster interface while losing evidence about how the work was performed.

CFOs will ask whether the controls scale with the capability

Nomentia’s 2026 treasury research shows how quickly the AI conversation is moving: respondents saw AI as potentially applicable to 93% of organisations’ treasury operations over the coming years.

I expect CFOs to become much more specific about the governance behind those use cases.

Can the AI see information the user cannot? Where does the number come from? Can it change something without a person confirming? What happens to existing four-eyes controls? Can we audit an agent interaction from another client? What happens if the AI service is unavailable?

These are healthy questions. A credible AI strategy for treasury should be able to answer them without relying on the phrase “trust the model”.

The control model defines how far AI can go

Over time, AI will be able to handle more of the treasury workflow. I expect systems to become more proactive, better at preparing work and more capable of coordinating tasks across financial processes.

The pace of that development should be determined by the quality of the control model around it.

When permissions are explicit, calculations are deterministic, actions are separated by authority, confirmations are meaningful and the audit trail is complete, treasury can safely delegate more preparation to the system.

That is how I think about the future of AI agents in treasury. The goal is not maximum autonomy. The goal is giving software the right amount of responsibility at each stage, so treasury professionals can spend more of their time on the decisions that still require judgement.

Marc Vietor
Chief Product Officer, Nomentia