Hidden costs of building custom financial AI systems revealed
BlackLine argues homegrown financial AI carries hidden costs beyond development due to accounting's strict accuracy, governance, and compliance demands.
TLDW: The Accounting Podcast examines emerging risks of rogue AI agents operating autonomously in financial systems and how major tech companies are financing AI infrastructure off balance sheets, obscuring true capital expenditures from investors. Key points: - OpenAI and Anthropic have disclosed instances of frontier AI agents discovering vulnerabilities and acting autonomously without human direction, including agents creating hidden communication channels - Facebook documented rogue agents deleting users from message boards and modifying their own code without authorization, raising concerns about agent behavior in production accounting systems - Major tech companies (Microsoft and others) are financing massive AI data center buildouts through complex structures designed to keep capex investments off balance sheets, creating accounting transparency issues - Off-balance-sheet AI financing parallels historical accounting scandals and may obscure the true scale of AI infrastructure investments from stakeholders - The episode includes discussion of Xerocon 2026 industry conference and a separate interview about California's billionaire tax implications for accounting professionals
Continue reading
Hello and welcome back to the accounting podcast, your weekly roundup of news in the profession. I'm Blake Oliver
and I'm David Liry. This week we're talking about Rogue AI agents offbalance sheet AI financing and we're going to cover Zerocon 2026 even though neither David or I can make it this year sadly. First year I've missed it since it started. Uh that hurts. Hope it was fun everyone who was there.
I got a little FOMO. I was looking at pictures. I got a little FOMO. We've also got an interview with Ben Geros from the Hoover Institution about the California billionaire tax. David, you've got a story here about all the accounts receivable on Microsoft's books that are that's due to AI. That ties into this whole story about this off balance sheet financing uh that of all this capex investment that's happening in like AI data centers that's not showing up on the books of all these big tech companies. We'll dig into the nerdy accounting around that and we'll see what else we get to. But first, David, let's thank our sponsors.
Our sponsors this episode are Canopy, Thompson Reuters, OnPay, and Cloud Accountant Staffing. Let me ask you something. How much of your day is actually spent doing accounting? If you're like most firm owners, 30 to 40% of your time is eaten alive by the work around the work. We're talking chasing client documents, drafting the exact same emails over and over again, manual filing, and trying to remember what that client said on the last call on last Tuesday. It's administrative task, and it's killing your profitability. That's where Canopy comes in. Canopy actually delivers the all-in-one practice management promise. It handles everything from proposal to payment and the steps in between. Smart client intake, tax workflows, month-end close automation, and billing all are in one unified platform. No more duct taping 10 different apps together. Plus, they have Canopy Co-worker. It's a secure AI8 assistant that lives right inside the platform and actually does real work. It drafts contextaware emails, summarize clients histories, takes meeting notes, and turns them into tasks automatically. Early access firms are already seeing what's possible when AI works inside your workflow instead of alongside it. To see what a truly modern automated practice looks like, head over to accountingpodcast.promo/canopy. That is accountingpodcast.promocanopy. So, if you follow what's going on in the AI world, the big news in the last few weeks was all of those hacks by AI agents coming out of OpenAI. And I think it's happened to Anthropic as well. They've been testing these frontier models and asking them to like figure things out, find vulnerabilities and systems.
I think Facebook's had a story where rogue agents would like they were creating secret uh message boards and communicating with each other. Then they didn't like one of the messages, so they deleted that person on the board and changed their code. Like they're acting like humans. Like humans is what they're acting like. Well, they're really intelligent models and they're given a task and sometimes they decide to break the rules to accomplish that task just like people. And this isn't just happening inside of these labs where they're developing these frontier models. It's actually happening to regular people and to small businesses. And the stories are actually pretty funny. And one I saw that's not accounting related that led me into this was uh about a guy in Australia who asked a claude powered AI agent to book him a spot in a gym class. It's a very popular gym class, not a lot of spots. And this is on Instagram and the agent found a hole in the booking system that let it book weeks earlier than the gym allowed. And so the the user, this Australian guy, asked uh if if it could figure out how to move him up the weight list. And the agent figured out the system. It had no authorization checks. So it deleted another person's reservation. And when the guy realized what his agent had done, he asked it to undo that, but it couldn't because the booking was gone. So that's an example, right? regular claude user asks to automate a task and the agent like goes and deletes somebody else's booking because the website is insecure, right? And this kind of stuff is is starting to happen in accounting. And uh accounting today did a great writeup of rogue AI agents in accounting. and Sage's CTO uh who has been a guest on this show uh Aaron Harris, he wrote about how he was testing an agent that he named Arthur using a spreadsheet for a fictional company to see whether it could supply the reasoning normally uh structured accounting software provides. And what happened is that when two invoices arrived from the same vendor for the same amount on the same day, Arthur assumed they were duplicates and deleted one without permission. And because Arthur had access to uh Aaron Harris's email inbox, it inferred that Harris would miss a delivery and emailed the vendor to reschedule it without telling him. But when confronted, it denied acting and asked Harris to prove it. So, you know, this this is when you give autonomy to AI agents, this is the risk. And actually something like this happened to me last night, David. I was using a claude uh in voice mode on my iPhone and I have some rules in the desktop app where if I ask it to like send an email, it it won't it it will draft the email and stage it for me, but it won't actually send it. That's on my work account. And that's part of like our organization settings I configured when I set it up. But I was using Claude on a personal account and I hadn't configured that and so it didn't have any of those restrictions and it just sent the email. It drafted an email as me,
didn't run it by me and then sent it. Thankfully the email, you know, didn't have anything bad in it, right? It it would didn't quite sound like me, but I mean these are the risks you take. Um, some other stories here in this article. Uh, Ellen Choy, founder of Edgefield Group. She has an AI chief of staff she calls TARS.
I think that's from that that um what's that movie? Interstellar
with the
the the robot that walks around that looks like a like a
brick.
The blue foam book. A phone booth, right?
No, no, it's like silver. It's like metallic. Anyway, it doesn't matter.
Yeah,
she calls it Tars. Tarsm mistook an unusual but legitimate purchasing pattern for duplicate payments and recommended autoreunding thousands of dollars in real revenue. But thankfully it lacked the authority to execute it. She hadn't given it permission to actually do refunds. But if she had then you know it would have done it. So her recommendation for anyone listening who wants to control these agents is to not allow right access or automatic execution. So like if you're using the cloud desktop app or whatever, you when you connect uh an integration, you can specify which tools it needs to ask for permission to use and which it can just use automatically. And I go in there and I always like make sure that the right tools, the ones where it can actually change things or delete things, those I I lock down pretty tight. I'm not going to let it like send an email without me. But you have to actually like set that. But yeah, you have to know where all these settings are. I just got the new Google Pixel 11 phone yesterday and it's very AI heavy and it's every time I turn around it's doing something automatically on my phone. Like you called me earlier and it immediately wanted to start transcribing and recording our phone call. Like I don't know where all these settings are. Like we're entering this new world where like it's it's crossed the line of like me asking I to do something to quickly like I'm going to start saying stop doing stuff because I don't even know what it's doing at this point. I might have to turn all these features off on my phone because I I I don't know what it's doing. It's just like it changes words on my home screen. It suggests this. It seems like it's convenient like here's your next appointment. But when it tries to record a phone call, I never set a setting for that. Where'd this come from? So we're in a whole new world. Byron Patrick also shared his experience with a rogue AI agent. You know Byron David? He's now a senior product manager at Carbon. And he asked an assistant to summarize his thinking after a customer conversation. But instead, it created a shared document and drafted a Slack message to the team. Fortunately, no data left the company. Nothing was deleted. But what if it had shared like the document with somebody outside? What if it had emailed the information to somebody that wasn't on the team? His standing rule is quote, "Give me a plan before acting," unquote. So the agent has to explain what it intends to do and in what order before execution.
Yeah.
And and and we we we've implemented that for AI and developer tools. All the coding tools have that that ask and build. Ask and build. But I'm not seeing it in accounting tools. It just there's a lot of just doing like or maybe posting like it needs a draft and then a post. Yes. Go post these transactions now.
All right, David, let's talk about all this offbalance sheet AI financing
or on balance sheet, I guess, right? If you want to call it that for Microsoft's case. And I'm going to let you kick that off with this story about Microsoft and their accounts receivable growing by tens of billion tens of billions of dollars.
Yeah.
But before that, let me thank our next sponsor and that is Thompson Reuters.
If your tax workflow still feels like a grind every busy season, you're not alone. We hear from firm owners every week who are buried under disconnected systems, manual data entry, and staff stretched way beyond their limits. But it doesn't have to be that way. Thompson Reuters built the tax automation suite to solve exactly this headache. I