Agentic AI in Accounting, Explained (Before a Vendor Explains It to You)
Every accounting software keynote now says "agentic," and most of the audience is nodding along without a working definition. Here's what an AI agent actually is, which agents are real in accounting today versus demo-reel material, and the three questions that matter more than anything a vendor shows you on stage.
Trent McLaren · 22 July 2026 · 9 min read
In this article
- Why every vendor is suddenly agentic
- What agents can actually do today, versus the demo reel
- The three questions that matter more than the demo
- 1. What can it touch?
- 2. What needs my sign-off?
- 3. What happens when it's wrong?
- Where MCP fits
- How to pilot an agent without betting the firm
- Frequently asked questions
- What's the difference between agentic AI and regular AI?
- What are real examples of AI agents in accounting today?
- Will AI agents replace accounting staff?
- How do you keep an AI agent safe with client data?
- How should a firm start with agentic AI?
Part of our AI in accounting coverage. See the full AI for accounting firms guide →
Here's the definition you need before your next software meeting. A chatbot answers questions: you ask, it responds, you do the work. An AI agent is given a goal ("reconcile this bank feed," "draft proposals for these three leads") and works out the steps itself, using connected tools to actually do them: reading transactions, matching them, drafting the email, updating the record. Three ingredients make something an agent: a goal instead of a single question, multi-step reasoning where it plans and adjusts as it goes, and tool access: real connections into your ledger, inbox and practice management system. Plus one ingredient that keeps you out of trouble: a human-in-the-loop, defined points where it stops and asks before anything consequential happens. That's it. That's the word every keynote is now built around.
The reason you need the definition in your pocket is that "agentic" has become 2026's most profitable adjective. Some products wearing it are genuine agents. Some are the same chatbot with a new slide deck. The rest of this article is how to tell the difference.
Why every vendor is suddenly agentic
The short answer: the underlying AI models got good enough at using tools and chaining steps, and now every vendor with access to your data is racing to be the one that acts on it.
At Xerocon London in July 2026, Xero's entire keynote was framed as "the agentic era": JAX now handles auto bank reconciliation, matching transactions to bank feeds in real time, with Bill Protection inspecting bills before payment and Payment Follow Ups planning collection sequences on the roadmap. The bigger tell was XeroForce, in early access now: a natural-language builder that lets accountants assemble their own custom agents connecting Xero to third-party tools, no code involved. When a ledger vendor ships an agent factory rather than an agent, the race is officially on. (Our Xerocon London breakdown separates the shipping from the "coming soon.")
Anthropic (the company behind Claude) is building the same thing from the other direction. Claude Cowork runs multi-step working sessions where Claude reads from connected tools (email, files, calendars, and now Xero directly), executes recurring workflows packaged as skills, and runs scheduled tasks in the cloud without your machine switched on. Anthropic also ships ready-made agent templates, including a set built for finance workflows: we've collected the ones worth stealing. And Ignition's MCP connection turns a discovery-call transcript into a drafted proposal against your real service library in minutes, with you confirming in Ignition before anything reaches a client.
Three companies, one identical bet: the value is moving from software that holds your data to AI that acts on it. So the practical question for your firm is no longer "what is this". It's "how much acting am I comfortable with."
What agents can actually do today, versus the demo reel
Honest list first. These are agent workflows that verifiably work in firms right now:
- Bank reconciliation matching. JAX matches transactions to bank feeds in real time inside Xero. Complex cases (one payment split across sales and fees) are still listed as coming soon, which tells you where the current ceiling is.
- Document data extraction. Xero's Smart Document Capture reads source documents and pushes the data into the ledger without rekeying.
- Multi-step research and drafting. A Claude session connected to your inbox and files can pull a client's recent correspondence, check the ledger position, and produce a briefing note or drafted reply in one pass: the kind of task that used to be twenty browser tabs.
- Proposal drafting from a transcript. Ignition's flow: call notes in, drafted proposal out, human confirms before send.
- Scheduled recurring jobs. A Monday-morning WIP summary or daily inbox triage that runs on a schedule in the cloud, producing a draft for a human to act on.
- Meeting notes and follow-ups. Assistants like Vinyl sit in client meetings and produce the file note plus a drafted follow-up email for a human to review (Vinyl is a commercial partner of The Firm).
Now the demo reel: the things that present beautifully on stage and are not yet what you should build a firm process on:
- The unsupervised month-end. No shipping product closes a set of books end-to-end without human review. Xero's own framing ("full human oversight at every step") concedes the point.
- Client-facing communication on autopilot. Payment chasing that adapts tone and channel per client is announced, not generally available. Even then, an agent contacting clients without sign-off should be a deliberate choice, never a default.
- Judgement calls. Revenue recognition positions, Division 7A, an R&D claim's eligibility: agents can assemble the workpaper; they cannot hold the opinion. The registered agent's name on the lodgement is still yours.
- "Just connect everything and it figures it out." Agents degrade fast on vague goals across many systems. The reliable deployments are narrow: one workflow, defined inputs, a review step.
The pattern across both lists: agents are currently excellent at bounded, reviewable work and unproven at open-ended, irreversible work. Pilot accordingly.
The three questions that matter more than the demo
1. What can it touch?
Ask for the actual list of systems and actions, in writing. Read access to the ledger is a different animal to write access, and "draft an invoice" is not "send an invoice." Good implementations split permissions finely and let you scope them per user: the admin partner and the first-year grad should not hand an agent the same powers. If the vendor can't produce the list, that's your answer.
2. What needs my sign-off?
Every serious agent platform builds in confirmation points: Ignition drafts and you confirm, Claude asks permission before acting by default, Xero promises human oversight at every step. In the demo, those pauses look like friction. In your firm, they're the control that protects your licence. Map exactly which actions proceed automatically and which stop for a human, and be suspicious of any product where the answer is "you can turn all that off." No AI is ever going to jail for you.
3. What happens when it's wrong?
Not if. When. Three sub-questions: Is there an audit log of every action, so you can reconstruct what happened? Can every action be reversed, or are some (a sent email, a submitted lodgement) permanent? And whose professional indemnity responds when an agent's error reaches a client? There's also a newer failure mode worth naming: prompt injection, where malicious instructions hidden in content the agent reads (an emailed PDF, a web page) try to hijack what it does with its tool access. The security community's OWASP project ranks it the number-one risk for AI applications. The defence is unglamorous: least-privilege permissions, read-only by default, human confirmation on anything that leaves the building. The boring settings are the safety system.
Where MCP fits
One paragraph, because we've covered it properly elsewhere. Agents are only as useful as the systems they can reach, and MCP (Model Context Protocol) is the open standard (think USB-C for AI) that lets an agent plug into the software your firm already runs, which is why Xero, Ignition and half your app stack suddenly mention it in the same breath as "agentic." Agents are the workers; MCP is the doorway they walk through. The full plain-English version, including the questions to ask any vendor claiming MCP support, is in our MCP for accountants explainer.
How to pilot an agent without betting the firm
Pick one workflow, not a transformation. Something recurring, internal, and annoying: WIP reporting, missing-document chasing, meeting prep. Not client communication, not anything that lodges.
Start read-only. Let the agent see data and produce drafts before it can change anything. You'll learn in a fortnight whether the output is trustworthy, at zero risk.
Run it parallel, then compare. For the first month, a human does the task the old way too. Score the agent on the cases that matter, especially the weird ones. Agents fail on edge cases, and you want to find those in the pilot, not in a client file.
Write down the sign-off rule before you scale. One sentence per workflow: "the agent drafts, [named person] approves, nothing client-facing goes out unapproved." Put it in your procedures alongside your engagement-letter and privacy updates, so AI use is covered on paper, not just in practice.
Widen slowly. More workflows before more autonomy. The firms getting real value from agents in 2026 aren't the ones that connected everything at the keynote's urging. They're the ones that gave one agent one job, watched it, and only then gave it more rope. For where agents sit in the broader stack, see our AI for accounting firms guide.
You now know more about agentic AI than most of the people who'll present it to you this year. Use the three questions. Watch how the vendor handles the third one.
Frequently asked questions
What's the difference between agentic AI and regular AI?
Regular AI in the chatbot sense responds to one prompt at a time: you ask, it answers, you act. Agentic AI takes a goal, breaks it into steps, and executes those steps itself using connected tools (reading your ledger, drafting the email, updating the record), checking in with a human at defined points. The practical difference is tool access and initiative: a chatbot tells you which invoices are overdue; an agent finds them, drafts the chasers, and queues them for your approval.
What are real examples of AI agents in accounting today?
Verifiable examples as of mid-2026: Xero's JAX performs auto bank reconciliation, matching transactions to feeds in real time, with XeroForce (a no-code custom agent builder) in early access; Anthropic's Claude runs multi-step workflows through Cowork using skills, connectors and scheduled tasks, with ready-made finance agent templates; and Ignition's MCP connection drafts proposals and billing from your real client and service data. Features like Xero's Payment Follow Ups are announced but not yet generally available.
Will AI agents replace accounting staff?
Agents replace tasks, not roles: specifically the bounded, repetitive ones: matching, extracting, drafting, chasing. The judgement work (advisory positions, review, anything requiring a professional opinion or a registered agent's signature) stays human, both because the technology isn't reliable enough for unsupervised use and because the liability doesn't transfer. The realistic near-term shift is staff spending less time producing drafts and more time reviewing them: job content changes well before headcount does.
How do you keep an AI agent safe with client data?
Four controls do most of the work: least-privilege permissions (read-only first, then only the specific write actions you need); human sign-off on anything client-facing or irreversible; an audit log of every action the agent takes; and a written data-handling answer from the vendor, including whether your data trains their models. These are also the defences against prompt injection, the top-ranked risk in OWASP's Top 10 for AI applications. If a vendor treats the permission conversation as an afterthought, walk.
How should a firm start with agentic AI?
Pick one internal, recurring workflow (WIP reporting, missing-document chasing, meeting prep) and pilot a single agent with read-only access, running parallel to your existing process for a month. Compare outputs, write a one-sentence sign-off rule, update your engagement letters and privacy policy to cover AI use, and only then add write actions or a second workflow. Claude's finance agent templates or Xero's built-in JAX features let you test the concept without a procurement project.
AIPractice Technology