Your client connected Xero to AI. Now what?
More clients are connecting their Xero files to Claude, ChatGPT and home-built AI tools, and practitioners are split between "their data, their risk" and cleaning up the journals. The three kinds of connection and where the risk sits, what to check in week one, what to say to the client, the house rules and engagement letter wording worth agreeing, and how to turn it into a reason to talk more.
Trent McLaren · 23 September 2026 · 9 min read
In this article
- First, work out what "connected" actually means
- The case for and against, honestly
- Week one: find out what is connected
- What to say to the client
- The house rules worth agreeing
- Put the clean-up on paper before it happens
- Turn it into a reason to talk more, not less
- The verdict
- Frequently asked questions
- Is it safe for a client to connect Xero to Claude?
- Can an AI tool actually post journals into Xero?
- How do I see which apps a client has connected?
- Should I charge to fix entries a client's AI created?
- Does Xero let app developers train AI on client data?
Part of our AI in accounting coverage. See the full AI for accountants guide →
An Australian practitioner group asked a simple question this week: how many of your clients have connected their Xero file to AI? The poster had a growing number connecting to Claude, ChatGPT or connections they had built themselves with an AI coding tool, and was most worried about that last group. "Amateurs playing professional," was the phrase.
The replies split, and both sides were right. One camp said it's the client's data and the client's risk, and that adults can make their own decisions. The other camp had already done the clean-up: one accountant described a client whose AI setup was posting multiple journals into the file with no accounting oversight, which created more review and reversal work, not less. The original poster added the point that matters most for a practice: it gets riskier when the practice holds the Xero subscription.
This isn't a trend you can stop, and you shouldn't try. It's one you can manage, and done well it makes you more useful to the client, not less. Here's how.
First, work out what "connected" actually means
"My client connected Xero to AI" covers three very different setups. The risk sits almost entirely in which one it is.
- Xero's own connector in Claude. Since May 2026 Xero has listed an official connector in Claude's connectors directory. The client signs in with their normal Xero login and picks an organisation. As at September 2026 it is read-only: it answers questions about profit, cash, receivables, financial position and top customers, and cannot change anything in the file. Xero says the data is used for the session only and is not used to train AI. This is the low-risk end.
- An MCP connection that can write. Model Context Protocol (explained in plain terms in MCP for accountants) is how most other connections work. Xero publishes its own open-source MCP server, and its tool list includes creating and updating invoices, contacts, bank transactions, payments and manual journals. Third-party hosted versions are appearing too. Some wait for a human to approve each change; many don't. This is where the unexpected journals come from.
- A home-built connection. A client (or their nephew) uses an AI coding tool to build a script against the Xero API, usually through a Custom Connection. The credentials may sit in a file on a laptop, nobody reviews the code, and nobody maintains it when the API changes. This is the setup the original poster meant.
So the first job is not a lecture. It's a question: which of the three is it?
The case for and against, honestly
| What goes right | What goes wrong |
|---|---|
| The client looks at their numbers more often, and asks better questions | Entries land in the file with nobody checking the coding, the GST treatment or the period |
| "What's my cash position?" stops being an email to you | Answers drawn from an unreconciled file are confident and wrong |
| Meetings start from a client who has already read the P&L | Home-built scripts hold live credentials with no review and no owner |
| Routine admin (draft invoices, contact updates) gets faster | Commercially sensitive data (supplier pricing, customer lists, payroll) leaves the file for a consumer AI account |
One reply in the thread recounted a second-hand story of a business whose product codes, held in a connected app, were used by someone at the app's vendor to approach her supplier for a copy of her product line. It's one anecdote, not verified, but the lesson stands whatever the source: every connection is another party with access to the file, and most clients have never looked at how many they have.
Week one: find out what is connected
- Look at the connected apps list in the Xero organisation's settings. It shows every app with access. Most files have more than the client remembers.
- Check the subscription for a Custom Connection. Xero bills a Custom Connection as a monthly add-on (available in Australia, New Zealand, the UK and the US), so one appearing on the bill is a strong sign of a home-built integration.
- Read the history. Look for manual journals, bank transactions or invoices created by an unfamiliar user or app name, or in bursts at odd hours.
- Ask three questions: what tool is it, can it change anything or only read, and who built it?
Then sort it. Read-only through Xero's own connector: note it and move on. A write-capable connection with an approval step: agree the rules below. Write access with no approval, or anything home-built holding credentials: that's the conversation to have this week.
What to say to the client
Clients who connect AI to their books are usually your most engaged clients. They're curious, they want to understand their numbers, and they're trying to save time. If the first thing they hear from you is disapproval, they'll keep doing it and stop telling you.
Lead with curiosity, then the one real risk, then a rule. Something like this works:
"Good to see you're using AI on the numbers. I'd like to see what you're asking it, because I can help you get better answers. One thing to sort out: the tool you've connected can post entries into Xero, and some of those have needed reversing. Can we set it up so it drafts and you or I approve before anything goes into the books?"
Three things make that land. It praises the behaviour you want more of (engagement with the numbers). It names a specific consequence rather than a vague fear. And it offers a setup, not a ban.
What not to say: "AI isn't safe", "you shouldn't have done that", or anything that sounds like you're protecting your own work.
The house rules worth agreeing
Put these in writing, in plain language, as an email the client replies to.
- Reading is fine. Writing needs an approval step. If the tool can create entries, they go in as drafts, or through a tool that holds changes for a human to approve. The client can make you the approver.
- No manual journals from AI. Journals are where an AI with good intentions does the most damage: accruals, reclassifications and GST adjustments that look plausible and aren't.
- No payroll and no employee data in a consumer AI account.
- One named owner for every connection, and a disconnect when a tool is no longer used.
- Home-built connections get reviewed or switched off. If nobody can explain where the credentials are stored, that's the answer.
Put the clean-up on paper before it happens
The accountant in the thread doing the reversals is doing unscoped work. Fix that in the engagement letter. Say that reviewing and correcting entries created by third-party or AI tools the client has connected is outside the standard scope and is billed separately, and that the client is responsible for the connections they authorise. The AI clause for Australian engagement letters covers the drafting, and AI client consent covers the other direction: your own firm's use of AI on their data.
When the practice holds the Xero subscription, go further. It's your subscription, so it's reasonable to make connections your call: the client asks, you approve. If a client wants full control over what they connect, the cleaner answer is a subscription in their own name. Either way, write it down. This isn't legal advice; for your own confidentiality and privacy obligations, check the Tax Practitioners Board, the OAIC or your professional body.
Turn it into a reason to talk more, not less
A client connecting AI is a signal of demand: they want faster answers about their business, and you're best placed to make those answers right.
- Offer a connection review. A scoped, one-off engagement: audit the connected apps, set up the approval step, disconnect what's stale, and write the house rules. Price it the way you'd price any other scoped work. App advisory that pays covers the discipline.
- Make the file worth asking. AI answers are only as good as the reconciliation behind them. "Your AI gives better answers when the file is current" is the most honest case for monthly bookkeeping you'll ever make.
- Teach the questions. Show the client five questions that are worth asking the AI each month, and the two it will get wrong without you (anything involving tax timing, and anything involving an unreconciled account).
- Review what it changed. For clients with write access, a short monthly check of AI-created entries is a natural add-on to the bookkeeping or advisory engagement.
For the wider picture of where AI fits in a firm, the AI for accounting firms hub collects everything The Firm has published on it.
The verdict
The "their data, their risk" camp is right that you can't and shouldn't police what clients connect. The clean-up camp is right that it becomes your problem the moment an entry lands in a file you sign off on. The way through is the same as for any other app a client adds: find out what it is, agree how it's used, put the clean-up in scope, and charge for the help. A read-only question tool is a gift to your advisory work. A write-capable tool with no approval step is a job waiting to happen. A home-built script with credentials on a laptop is a conversation you should have this week, nicely.
Frequently asked questions
Is it safe for a client to connect Xero to Claude?
Xero's own connector in Claude is read-only as at September 2026 and, per Xero, does not use the data to train AI. The risk rises with anything that can write to the file or that was built by someone who doesn't maintain it.
Can an AI tool actually post journals into Xero?
Yes. MCP servers built on the Xero API, including Xero's own open-source one, include tools for creating manual journals, invoices, bank transactions and payments. Whether a human approves each one depends entirely on the tool and how it was set up.
How do I see which apps a client has connected?
Open the connected apps list in the organisation's Xero settings, and check the subscription for a Custom Connection add-on, which usually means a home-built integration. The file history shows which user or app created each entry.
Should I charge to fix entries a client's AI created?
Yes, if your engagement letter says so. Scope correction of third-party and AI-created entries as separate work before it happens, so the conversation is about the letter, not about the bill.
Does Xero let app developers train AI on client data?
No. Xero's developer platform terms prohibit using data obtained through its APIs to train or fine-tune AI models. The terms applied immediately to developers who registered from 4 December 2025, and from 2 March 2026 for everyone else.
XeroAIMCPClient RelationshipsData SecurityEngagement Letters