Enterprise Adoption3 min read

Finance Staff Are Already Using AI. The Boss Isn't.

June 2, 2026Synthesized from 1 source: MIT Technology Review

Finance departments worldwide are being reshaped from the bottom up as employees adopt AI tools without approval, creating a hidden data risk that regulators are now racing to catch, while a new wave of autonomous AI agents is poised to make the current chaos feel like the calm before the storm.

Something unusual is happening inside finance departments globally. Staff are not waiting for permission to use AI. They are using it to write variance reports, draft board commentaries, review contracts, and speed through month-end tasks. Leadership, meanwhile, is still building the governance framework that was supposed to come first.

This bottom-up adoption has a name: shadow AI. And in finance, it is a more serious problem than it sounds. When a finance analyst pastes a cash flow model or a client dataset into a public AI tool to get a faster answer, that data leaves the company's systems entirely. It goes to a third-party server. There may be no record of it. Surveys now suggest that over 80% of employees globally are using AI tools their employers never approved, and roughly three in four of those people are sharing sensitive company or customer data when they do it.

The financial cost of this is already measurable. IBM's 2025 data breach research found that one in five organizations has already suffered a security incident tied to unsanctioned AI use, and such incidents add an average of $670,000 to the cost of a breach on top of what a standard incident would cost. In a sector where regulators across the US, EU, and Asia are all tightening their scrutiny of AI simultaneously, that is not just a security problem. It is a compliance and reputational exposure that a CFO's existing risk framework was never designed to catch.

The regulatory environment is moving fast but unevenly. The US Treasury published a new AI risk framework for financial services in early 2026. The EU AI Act is now imposing strict obligations on high-risk AI applications, including credit scoring and fraud detection. The Federal Reserve recently clarified that its existing model-oversight rules do not apply to newer generative and agentic AI, meaning institutions need new frameworks, not just updated ones. Regulators are not blocking AI adoption. They are, however, signalling clearly that governance needs to be built in from the start, not added after the fact.

The talent problem sits at the centre of all of this. Almost three quarters of financial services leaders cite a shortage of people who understand both how finance works and how AI works. The risk is not just about missing technical skills. It is that the people making decisions about which AI tools to trust, which outputs to question, and which workflows to automate, may not have the knowledge to do that well. When AI produces a confident-sounding but incorrect figure in a financial report, someone needs to catch it. That requires human judgment, and human judgment requires understanding.

The next wave of AI in finance will make the current situation look modest. A new category of tools, often called agentic AI, does not just answer questions or draft text. These systems independently execute multi-step workflows: reconciling transactions, closing the books, running compliance checks, and routing exceptions for human sign-off. Companies already using these systems report month-end close cycles falling from an average of six days to under two. EY has deployed 150 AI agents across its tax operations. Anthropic recently released ready-to-run agent templates specifically for financial services work. This is not a future trend. It is already in production at large firms.

For mid-sized and non-financial businesses with finance functions, the window to get ahead of this is narrowing quickly. The organisations that will benefit most are not the ones waiting for a perfect governance policy before starting. They are the ones building simple, clear rules now, telling staff which tools are approved and which data categories are never to be shared with an outside system, and then using that structure as a foundation to layer on more capable tools over time. The risk of moving too slowly is no longer just missing efficiency gains. It is watching staff improvise in the absence of guidance, which is already happening.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable