Published on October 2, 2026
Letting an AI agent write to your ERP: the five safeguards to demand
In June 2025, Gartner predicted that more than 40% of agentic AI projects would be abandoned by the end of 2027. The three reasons given were: soaring costs, poorly defined business value, and insufficient risk controls. Two of these three have nothing to do with the quality of the model. They stem from a question that few companies ask themselves before connecting an agent to their accounting system: who monitors it, and who can stop it?
Governance and monitoring: the difference
There governance It establishes in advance what an agent has the right to do, who authorizes it, and how it is proven. monitoring It shows what it actually does: its executions, its failures, its costs, the data it handles. budgetary safeguards They link the two: a rule decided in advance, which is applied live without waiting for anyone.
Why does an agent change the question?
A chatbot produces text that someone reviews before doing anything with it. An agent, on the other hand, handles the process independently: they read an invoice, locate the supplier in the ERP system, and then generate the accounting entry. The time savings come precisely from this. The risk, too: Between reading and writing, nobody looks anymore, unless otherwise stipulated.
Swiss law already partially addresses this. The nLPD (New Federal Act on Data Protection) requires that individuals be informed of decisions made exclusively by automated means when those decisions have legal effects on them or significantly affect them, and that they be given the right to request a review by a natural person (Art. 21). At the European level, the AI regulation requires effective human oversight of high-risk systems (Art. 14), an obligation postponed until December 2, 2027, for most of them. An employee who enters supplier invoices generally does not fall into these categories. However, the principle remains the same, and it is simply common sense: someone must be able to understand, correct, and stop the process.
The five safeguards
These are the controls we would require from any supplier, including ourselves, before allowing an agent to touch business software.
- No writing without a decision. The agent makes the request, but doesn't write it. Their entries wait in a queue where someone approves, rejects with a reason, or corrects them before final approval. For recurring cases, a pre-written rule can validate the request instead, but within specific limits: one agent, one tool, a maximum amount per entry, and a daily limit. The best indicator of a reliable system is that the agent doesn't write the entry in the ERP system, but rather a gateway, and only after the decision has been made.
- One register per agent. Before activating an agent, it must be possible to specify why it processes data: purpose, legal basis, data subjects, and retention period. These are sections of the processing activities register required by the nLPD (Art. 12). An agent without this record should not be able to start.
- A newspaper that proves its point without copying. Each execution must leave a log: which agent, which steps, which data categories, which destination (internal model, business software, external service), how long it took, and what the cost was. But if the log also retains the text of invoices and the model's responses, it becomes a second copy of your sensitive data, which must also be protected. The best compromise: record the type, size, and a fingerprint of the content, not the content itself.
- A ceiling that works. A monthly usage report offers no protection. Uber admitted in 2026 that it had used up its entire annual budget for AI coding tools in just four months. The spending limit must be checked before each execution: if the budget is full, the application cannot be executed, the agent is paused, and an alert is triggered. An external model whose price is not disclosed should never be considered free.
- A stop that works. Putting an agent on pause, stopping them urgently by freezing their pending entries, shutting down all agents at once: these actions must be available with a single click, logged, and restricted to identified individuals. A shutdown that requires a ticket request to the supplier is not a shutdown.
Monitoring, or how to spot a silent failure
An agent failure is rarely straightforward. Most often, the agent continues to run while producing errors, or it simply stops providing updates. We have described this scenario here The fault was discovered three days later by a colleague who was surprised that a request had not been processed.
Three monitoring reflexes make all the difference. First, count as a failure a run that went unreported, and not just those that return an error. Then, one alert per problem, Regardless of the number of repetitions, fifty notifications for the same failure end up being ignored. Finally, monitor each agent over time (24-hour and 7-day failure rates, median execution time) so that a deviation is detected before it becomes an incident.
Five questions to ask your supplier
- Who writes in my ERP: The agent himself, or a stepping stone after a decision?
- What does your journal contain? A record of what happened, or a copy of my documents?
- What happens when the budget is reached? An alert, or a stop?
- Can I stop everything myself?, And who can restart it?
- Where the monitoring console is located: At your place, or at my place?
If the answers are vague, the project risks joining the 40 % projects that Gartner sees as abandoned, not because the AI doesn't work, but because no one can guarantee what it does.
What we did with it
These five safeguards are those we have integrated into AgentHub Connect, the console that manages our agents on the client's infrastructure: validation of entries, register per agent, log without retention of content, ceilings in francs and emergency stop. The Governance and Monitoring page details each screen.
Sources
- Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027, Gartner, June 25, 2025.
- Federal Act on Data Protection (FADP, SR 235.1), art. 12 and 21, Fedlex.
- Current data protection law is directly applicable to AI, PFPDT, November 9, 2023.
- Regulation (EU) 2024/1689 on artificial intelligence, art. 14 (human control), EUR-Lex.
- EU AI Act Deal: Digital Omnibus Now in Force, Usercentrics, 2026.
- Uber Burns Its 2026 AI Budget In Four Months On Claude Code, Forbes, May 17, 2026.
Frequently asked questions
What is the governance of an AI agent?
This is the set of rules that define what an agent is authorized to do, who authorizes it, and how it is proven: validation of entries, processing register, journal, budget limits, and the possibility of stopping operations. Monitoring, on the other hand, shows what the agent actually does.
Does each entry need to be validated by hand?
No. An auto-validation rule can allow repetitive and low-risk transactions within specific limits: one agent, one tool, a maximum amount per transaction, and daily limits. Anything outside these limits requires a human decision.
Does the nLPD require human validation?
Not for all automation. Article 21 of the nLPD (New Federal Act on Data Protection) applies to decisions made exclusively by automated means that have legal effects on the data subject or significantly affect them: the data subject must be informed and may request a review by a natural person. Otherwise, human validation is good practice, not a legal requirement.
What should an AI agent's log contain?
What happened, by whom, and to where: the agent, the steps, the data categories affected, the destination of each call, the duration, and the cost. The processed content itself (documents, model responses) does not need to be included; a type, size, and fingerprint are sufficient to prove the transaction without duplicating the data.
To learn more: agent failures that nobody sees, And the true cost of AI subscriptions billed per token.
Do you want to see these five safeguards in action on one of your processes?
