Jerry Xiong / Intelligence Brief
AI Governance · Internal Control · Agents
AI Governance · Internal Control · Finance Agents

When AI Becomes a Digital Employee: A Bounded Autonomy Framework for Finance AI Internal Control

Reading Anthropic’s September 2026 report, Detecting and countering misuse of AI, from the perspective of corporate finance and internal control. When AI stops answering questions and starts executing inside workflows, a control system built around people and systems needs a third object of control: the AI agent.

AI治理 · 内部控制 · 财务Agent

当AI成为“数字员工”:
财务AI内部控制的受控自治框架

从 Anthropic 2026 年 9 月《Detecting and countering misuse of AI》看未来财务治理。当 AI 不再只是回答问题,而是进入真实工作流承担执行,以“人 + 系统”为中心设计的内控体系需要增加第三类控制对象:AI Agent。

This article represents the author’s personal views only. The finance scenarios, system architectures and business processes described are conceptual illustrations and do not represent the actual systems, processes or business information of any organisation the author works for.

In September 2026, Anthropic published Detecting and countering misuse of AI. On its face it is a threat-intelligence report about AI misuse: cyber operations, influence operations, surveillance, fraud, biosecurity and model distillation. Read from the perspective of corporate finance and internal control, however, the problems it reveals go well beyond “cybersecurity”.

The report documents a reality that is forming quickly. AI is no longer only a tool that answers questions. It is entering real workflows and taking on analysis, code generation, tool calls, data processing, task decomposition and even multi-agent coordinated execution. Anthropic is explicit that the cases it describes span several high-risk domains, and that they are not typical usage but the most notable and novel misuse activity it has identified.

One caveat matters. This is a threat-intelligence report published by a model provider, not a judicial investigation. Some of its attributions carry probabilistic labels such as “medium confidence”. This article is therefore concerned with the technical capabilities and governance trends the report reveals, not with treating every attribution as a judicially established fact.

For the finance profession, the question worth asking is this:

My judgment is that it is not.

Future finance governance will need a third object of control: the AI agent.

The real change is not “more automation” but the transfer of execution authority

Finance automation is nothing new.

Automatic posting in the ERP, RPA bots downloading bank statements, Python scripts generating reports: all of these remain deterministic automation. The logic is defined by a person in advance, and the system executes fixed rules.

Agentic AI is different.

It can understand a goal, decompose the task on its own, choose tools, generate SQL, write code, read the results, notice anomalies, revise its method and run again. Anthropic’s cyber cases already show AI that is not merely “answering questions” but embedded in a complete execution chain.

Mapped onto finance, the system of the near future looks like this:

Business data / contracts / invoices / GL→ SQL / Python→ AI agent→ analysis / reconciliation / reporting / adjustment proposals / forecasts

At that point AI is no longer only “assisting the finance team”. It is gradually becoming a digital employee with system permissions, data access and a degree of execution authority.

The central question of finance AI governance therefore shifts from:

“Is the AI’s answer accurate?”

to:

First challenge: enterprises must rethink the AI information boundary

When companies discussed AI security in the past, the most common question was:

“Will my data be used to train the model?”

Anthropic’s report shows that this question is too narrow.

In several of its threat investigations, the platform combines account behaviour, infrastructure, VPN use, time zones, language settings and activity patterns to analyse and attribute activity. The report also states that the platform uses metadata and anomalous activity patterns to identify proxy networks, and in some cases tries to attribute activity to specific organisations.

More notably, in the biosecurity section Anthropic states that governance of high-risk use needs to combine:

account and institutional signals

with:

observability provided by data retention

The report goes further: an AI provider may gradually gain a kind of real-world threat visibility that even governments and international organisations do not necessarily have.

This does not mean “the model provider can see everything a user does”. The report itself notes that in influence-operation investigations, its direct visibility ends once the activity leaves the Claude platform, after which it relies on open-source intelligence, industry data and public reporting.

From a corporate governance standpoint, however, this is enough to establish an important point:

For finance systems that hold bank data, tax files, management reports, pricing, treasury plans, customer information and business strategy, the distinction matters a great deal.

When enterprises evaluate AI services in future, they may need to consider data retention, telemetry, account linkage, human investigation access, third-party sharing and legal disclosure together, not the training policy alone.

Second challenge: “approve every write” is not governance

Faced with an AI agent, the most natural control reflex is:

Every write operation requires human approval.

It sounds safe. In practice it can create new risk.

If the agent needs a human to click Approve every time it runs a Python script, writes a temporary table or modifies an intermediate result, users very quickly develop approval fatigue.

The usual end state is:

Every prompt gets approved without thinking.

At that point the human in the loop is no longer reducing risk. It is adding a control that exists only in form.

The more reasonable design principle is therefore not “the more human approval, the safer”, but:

I call this approach:

Framework

Finance AI Bounded Autonomy Framework

财务 AI 受控自治框架

Full autonomy inside the boundary, approval only at the crossing. Routine work executes automatically; exceptions get human review.

The object of governance should be the risk boundary, not read versus write

Traditional IT permission management is used to a simple distinction:

Read = relatively safe. Write = relatively dangerous.

In an agent setting, that classification is too coarse.

An agent writing large volumes of intermediate results into an isolated scratch table is technically a write, but the risk may be very low.

Conversely, a read-only query that touches payroll, bank accounts or sensitive customer data may carry higher risk.

Agent risk should therefore be assessed on at least these dimensions:

Impact, reversibility, scope, data sensitivity and external effect.

Together these form a new permission envelope.

A finance analysis agent, for example, might be authorised to:

  • read approved data sources;
  • run SQL and Python;
  • generate analytical results;
  • write to an isolated workspace;
  • retry and validate automatically.

But not to:

  • modify the official ledger;
  • change vendor master data;
  • release payments;
  • alter production permissions;
  • send sensitive data outside the enterprise;
  • access credentials it has not been granted.

Only when the agent needs to step outside this envelope does the system genuinely require human approval.

What has real value is “semantic approval”, not “technical approval”

Many agent systems today still ask the user to approve:

Allow this Python to run? Allow this SQL to execute? Allow this API call?

For a finance leader, these are poor objects of approval.

What a finance manager can actually judge is:

What business consequence will this adjustment have?

The more sensible model, then, is to approve “business impact” rather than “technical action”.

A manager should not be asked to approve:

Run the reconciliation script

They should instead be asked to review:

The system proposes a set of adjustments, several of which exceed the established materiality threshold. Please confirm their effect on profit, the balance sheet and disclosure.

This can be summarised as:

In other words:

Machines control technical actions; humans judge business consequences.

None of this conflicts with existing finance internal control.

Traditional financial control already rests on:

materiality, segregation of duties, exception control and the audit trail.

AI governance should inherit those principles rather than invent an approval system detached from finance logic.

The future is more likely human-on-the-loop than human-in-the-loop

A mature finance agent system should not require a person to take part in every step.

The more realistic state is that the agent completes a large volume of routine work autonomously, while humans supervise risk and exceptions from above.

A month-end close agent, for instance, can read the data, reconcile, apply matching rules, flag anomalies and produce reports on its own, while finance staff review only a small number of exceptions.

That is:

100% automated processing + risk-based exception review

rather than:

100% manual approval

This can be called human-on-the-loop.

The human is no longer the button-presser for each step the agent takes. The human is its supervisor and the bearer of final accountability.

This is close to how audit already thinks:

Prompts, memory and agent skills are becoming the new “code”

Anthropic’s report reveals another trend that enterprises should take seriously.

In some influence operations, the operators no longer relied on one-off prompts. They wrote doctrine, approved sources, banned words and evasion rules into long-term memory or shared files, so that the agent could keep executing across sessions.

The implication for enterprise AI governance is direct.

The following can no longer be treated as ordinary “configuration”:

System prompts Rule libraries Exception lists Agent skills Accounting-policy configuration Long-term memory Approval rules

They are, in effect, close to code.

Enterprises may therefore need to manage agent instructions the way they manage program code:

version control, testing, approval, change records and production lock-down.

The principle can be summarised as:

If one rule is wrong, the damage may not be a single output. It may be the next several hundred automated executions.

Finance AI needs a control plane that sits outside the model

This is the most important layer of the whole framework.

An enterprise cannot hand every security and permission decision to the LLM’s own judgment.

An LLM can reason, recommend and plan. It should not itself be the final security boundary.

A more reasonable enterprise AI architecture might look like this:

Data plane
ERP / GL / contracts / invoices / bank
Compute plane
SQL / Python / rules engine
Intelligence plane
LLM / agent
Control plane
RBAC / policy / approval / audit / network control
Human oversight
Exception review / accountability

The core principle:

Put another way:

AIThink
PolicyDecide
SystemExecute
HumanGovern

This may become the foundational architecture of finance AI internal control.

Data sovereignty may raise the share of self-hosted and open-weight AI

The report also offers a case worth reading in reverse.

In the Mali surveillance case, the report states that the platform ultimately deployed ran on fully on-premises local models. Anthropic could ban the relevant accounts, but a system already deployed locally does not stop running because of account enforcement.

From a platform-security standpoint, that is a governance problem.

From the standpoint of a legitimate enterprise, it illustrates the value of self-hosted AI:

Demand for open-weight and self-hosted AI in highly sensitive sectors, finance, banking, law, healthcare and government among them, is therefore likely to keep growing.

The real value is not that “the model is free”. It is:

privacy, sovereignty and control.

Enterprise AI architecture is also unlikely to rest on a single model. A hybrid pattern is more probable:

Data typeLikely AI environment
Highly sensitiveLocal / self-hosted
General internal confidentialEnterprise AI
Public information and high-end reasoningFrontier cloud model

One can go a step further and separate “computation” from “reasoning”.

Raw transactions, bank statements and sensitive line items are processed locally with SQL, Python and a local model. Only aggregated, de-identified conclusions are then passed to a more capable cloud model for further interpretation.

That is:

This may become an important pattern in enterprise AI architecture.

A possible management prototype: the AI Internal Control Framework

Taken together, these changes suggest that enterprises will gradually form a new body of controls, analogous to ITGC, SOX or the internal control frameworks that already exist:

Prototype

AI Internal Control Framework

Its purpose is not to restrict AI. It is to let AI operate with a high degree of autonomy inside clear boundaries.

I expect at least five core pillars:

Core pillarKey question
Permission EnvelopeWhat may the agent do on its own?
Semantic ApprovalWhich business consequences must a human approve?
Human-on-the-loopWhich exceptions need human review?
Control PlaneHow are permissions, policy and audit kept independent of the model?
Data SovereigntyWhat data may leave the enterprise boundary?

Together the five resolve one central tension:

A truly mature governance structure is:

High autonomy + strong boundaries + exception review + traceable accountability.

Conclusion: the competition in finance AI may not be about who uses the strongest model

Anthropic’s report is not a finance-governance report.

But it opens an important window onto the present.

It shows AI evolving from a chat tool into an executing actor inside real workflows. At the same time, model providers now have content-level and behaviour-level observability that ordinary software vendors rarely had.

When those two changes compound, the question for enterprises is no longer only “how do we use AI to become more efficient”, but:

Finance internal control used to manage two objects:

people and systems.

A third is arriving:

the AI agent.

The real competitive advantage in finance digitalisation may therefore not be “who uses the strongest model”, but who can build a governance system that allows AI a high degree of autonomy while preserving data sovereignty, controllable permissions, auditable behaviour and traceable accountability.

That is the core of what I understand by the Finance AI Bounded Autonomy Framework:

This may be the earliest management prototype of finance AI governance.

This article is a general discussion of AI governance and internal control. It is not professional advice on any specific system, organisation or jurisdiction.
本文仅代表作者个人观点。文中的财务场景、系统架构和业务流程均为概念性示例,不代表任何任职机构的实际系统、流程或经营信息。

2026 年 9 月,Anthropic 发布了《Detecting and countering misuse of AI》。从表面看,这是一份关于 AI 滥用、网络攻击、影响行动、监控、诈骗、生物安全与模型蒸馏的威胁情报报告;但如果从企业财务和内部控制的角度阅读,它揭示的问题远远超出了“网络安全”。

报告展示了一个正在快速形成的现实:AI 已经不再只是回答问题的工具,而是在逐渐进入真实工作流,承担分析、代码生成、工具调用、数据处理、任务分解甚至多 Agent 协同执行等角色。Anthropic 也明确指出,其观察到的案例覆盖多个高风险领域,而且这些案例并非一般性使用,而是其认为较突出、较新颖的滥用活动。

需要强调的是,这是一份由模型供应商发布的威胁情报报告,而不是司法调查报告。报告中的部分归因带有“medium confidence”等概率性判断,因此本文关注的是它所揭示的技术能力与治理趋势,而不是把每一项归因都视为经过司法确认的事实。

对财务行业而言,真正值得关注的问题是:

我的判断是:不够。

未来财务治理需要增加第三类控制对象——AI Agent。

真正的变化,不是“自动化更多”,而是“执行权开始转移”

财务自动化并不新鲜。

ERP 自动过账、RPA 自动下载银行流水、Python 自动生成报表,本质上仍然是确定性自动化:逻辑由人事先定义,系统按照固定规则执行。

Agent 型 AI 不同。

它可以理解目标、自主拆解任务、选择工具、生成 SQL、编写代码、读取结果、发现异常、修改方法并再次运行。Anthropic 的网络安全案例已经显示,AI 在一些操作中不只是“回答问题”,而是被嵌入完整的执行链条之中。

映射到财务场景,未来的系统很可能变成:

业务数据 / 合同 / 发票 / GL→ SQL / Python→ AI Agent→ 分析 / 对账 / 报告 / 调整建议 / 预测

这时,AI 已经不仅是在“辅助财务人员”,而是在逐步成为一个拥有系统权限、数据访问权和一定执行权的数字员工。

因此,未来财务 AI Governance 的核心问题将从:

“AI 回答得准不准?”

转向:

第一项挑战:企业必须重新理解 AI 的信息边界

过去企业讨论 AI 安全时,最常问的问题是:

“我的数据会不会被拿去训练模型?”

但 Anthropic 的报告说明,这个问题太窄了。

在其部分威胁调查中,平台会结合账户行为、基础设施、VPN、时区、语言环境、活动模式等信号进行分析和归因;报告也明确提到,平台会利用 metadata 和异常活动模式识别代理网络,并在部分场景下尝试把活动归因到具体组织。

更值得注意的是,在生物安全部分,Anthropic 明确提出,高风险使用的治理需要结合:

account and institutional signals

以及:

observability provided by data retention

报告进一步指出,AI provider 可能逐渐获得一种连政府和国际组织都未必拥有的现实世界威胁可见性。

这并不等于“模型供应商可以看到用户的一切”。报告本身也说明,在影响行动的调查中,一旦活动离开 Claude 平台,其直接可见性就结束,之后需要依赖 OSINT、行业数据和公开报道。

但从企业治理角度,这已经足够说明一个重要问题:

对于包含银行数据、税务资料、管理报表、定价、资金计划、客户信息和经营策略的财务系统而言,这种区别非常重要。

未来企业评估 AI 服务时,可能需要同时考虑数据保留、遥测、账户关联、人工调查权限、第三方共享和法律披露,而不仅仅是训练政策。

第二项挑战:不能把“所有写操作都审批”当成治理

面对 AI Agent,最自然的控制反应是:

所有 write operation 都要人工批准。

听起来很安全,实际却可能制造新的风险。

如果 Agent 每运行一次 Python、每写一张临时表、每修改一个中间结果都要求人工点击 Approve,用户很快就会产生“审批疲劳”。

最后的结果往往是:

所有提示都被无脑批准。

这时 Human-in-the-loop 并没有真正降低风险,只是增加了形式上的控制。

因此,未来更合理的思路不是“人工审批越多越安全”,而是:

我把这一思路称为:

框架

财务 AI 受控自治框架

Finance AI Bounded Autonomy Framework

边界内充分自治,越界才审批;常规自动执行,异常人工复核。

治理对象不应是 Read / Write,而应是风险边界

传统 IT 权限管理习惯于区分:

Read = 较安全;Write = 较危险。

但 Agent 场景中,这种分类过于粗糙。

一个 Agent 向隔离的临时分析表写入大量中间结果,技术上属于 write,但风险可能很低。

相反,一个只读查询如果访问的是工资、银行账户或客户敏感信息,风险反而可能更高。

因此,Agent 风险至少应该从几个维度判断:

影响程度、可逆性、作用范围、数据敏感度和外部影响。

这会形成一种新的 Permission Envelope。

例如,一个财务分析 Agent 可以被授权:

  • 读取批准的数据源;
  • 运行 SQL 和 Python;
  • 生成分析结果;
  • 写入隔离工作区;
  • 进行自动重试和验证。

但它不能:

  • 修改正式账簿;
  • 改变供应商账户;
  • 释放付款;
  • 修改生产权限;
  • 向外部发送敏感数据;
  • 访问未经授权的凭证。

一旦 Agent 要跨出这个 envelope,系统才真正要求人工批准。

真正有价值的是“语义审批”,而不是“技术审批”

今天很多 Agent 系统仍然要求用户审批:

是否允许运行这段 Python?是否允许执行这条 SQL?是否允许调用这个 API?

对于财务负责人来说,这些并不是好的审批对象。

一个财务经理真正能够判断的是:

这项调整会带来什么业务后果?

因此,未来更合理的模式不是审批“技术动作”,而是审批“业务影响”。

例如,不应要求管理者审批:

运行对账脚本

而应该让其审核:

系统拟提交若干项调整,其中部分超过既定重要性阈值,请确认其对利润、资产负债表和披露的影响。

这可以概括为:

换句话说:

机器控制技术动作,人负责判断业务后果。

这其实与现有财务内部控制并不冲突。

传统财务控制本来就依赖:

materiality、segregation of duties、exception control 和 audit trail。

AI Governance 应该继承这些原则,而不是重新发明一套完全脱离财务逻辑的审批体系。

未来更可能是 Human-on-the-loop,而不是 Human-in-the-loop

成熟的财务 Agent 系统不应该要求人类参与每一个步骤。

更现实的状态是:Agent 自主完成大量日常任务,人类在上层监督风险和异常。

例如,一个月结 Agent 可以自动完成数据读取、对账、规则匹配、异常识别和报表生成,而财务人员只需要审阅少量 exception。

也就是说:

100% automated processing + risk-based exception review

而不是:

100% manual approval

这可以称为 Human-on-the-loop。

人不再是 Agent 每一步的“按钮操作员”,而是它的监督者和最终责任承担者。

这与审计思想其实非常接近:

Prompt、Memory 和 Agent Skill 将逐渐变成新的“代码”

Anthropic 的报告还揭示了一个值得企业高度重视的趋势。

在部分影响行动中,操作方已经不再依赖一次性 prompt,而是把 doctrine、approved sources、banned words、evasion rules 等信息写入长期 memory 或共享文件,使 Agent 能跨 session 持续执行任务。

这对企业 AI Governance 有一个很直接的启示:

未来以下内容都不能再被视为普通“配置”:

系统提示词 规则库 例外清单 Agent Skill 会计政策配置 长期 Memory 审批规则

它们实际上已经接近代码。

所以未来企业可能需要像管理程序代码一样管理 Agent 指令:

版本控制、测试、审批、变更记录、生产锁定。

可以把这一原则概括为:

如果一套规则错误,影响的可能不是一次输出,而是之后连续数百次自动执行。

财务 AI 需要一个独立于模型之外的 Control Plane

这也是整个框架最重要的一层。

企业不能把安全和权限控制全部交给 LLM 自己判断。

LLM 可以推理、建议和规划,但它本身不应该成为最终的 security boundary。

未来更合理的企业 AI 架构可能是:

Data plane
ERP / GL / Contract / Invoice / Bank
Compute plane
SQL / Python / Rules Engine
Intelligence plane
LLM / Agent
Control plane
RBAC / Policy / Approval / Audit / Network Control
Human oversight
Exception Review / Accountability

核心原则是:

也可以进一步表达为:

AIThink
PolicyDecide
SystemExecute
HumanGovern

这可能会成为未来财务 AI 内部控制体系的基础架构。

数据主权可能推动 Self-hosted / Open-weight AI 的比重上升

Anthropic 的报告还提供了一个值得反向思考的案例。

在 Mali 的监控系统案例中,报告明确指出,最终部署的平台使用 fully on-premises local models。Anthropic 可以封禁相关账户,但已经部署在本地的系统并不会因为账户 enforcement 而停止运行。

从平台安全的角度,这是治理难题。

但从正常企业的角度看,它反过来说明了 self-hosted AI 的价值:

因此,未来财务、银行、法律、医疗和政府等高敏感行业,对 open-weight 和 self-hosted AI 的需求很可能持续增加。

其真正价值未必是“模型免费”,而是:

Privacy、Sovereignty、Control。

未来企业 AI 架构也很可能不是单一模型,而是混合模式:

数据类型更可能的 AI 环境
高度敏感Local / Self-hosted
一般内部机密Enterprise AI
公开信息与高阶推理Frontier Cloud Model

甚至可以进一步把“计算”和“推理”分离。

原始交易、银行流水和敏感明细在本地完成 SQL、Python 和 local model 分析,再把已经聚合、脱敏后的结论交给能力更强的云端模型做进一步解释。

即:

这可能成为未来企业 AI 架构中的重要模式。

一个可能出现的管理雏形:AI Internal Control Framework

如果把这些变化放在一起,未来企业很可能逐渐形成一种类似 ITGC、SOX 或内部控制框架的新体系:

雏形

AI Internal Control Framework

其目的不是限制 AI,而是允许 AI 在清晰边界内高度自治。

我认为其中至少会形成五个核心支柱:

核心支柱关键问题
Permission EnvelopeAgent 可以自主做什么?
Semantic Approval哪些业务后果必须由人批准?
Human-on-the-loop哪些异常需要人工复核?
Control Plane权限、策略和审计如何独立于模型?
Data Sovereignty什么数据可以离开企业边界?

这五部分共同解决一个核心矛盾:

真正成熟的治理结构,应该是:

高自治 + 强边界 + 异常复核 + 可追溯责任。

结语:财务 AI 的竞争,最终可能不是“谁用了最强模型”

Anthropic 的这份报告不是一份财务治理报告。

但它给了我们一个非常重要的现实观察窗口。

它表明,AI 正在从聊天工具演变为能够介入真实工作流的执行主体;与此同时,模型供应商也拥有了过去普通软件服务商较少具备的内容级和行为级可观测能力。

这两种变化叠加之后,企业面临的问题已经不只是“如何用 AI 提高效率”,而是:

过去财务内部控制主要管理两个对象:

人和系统。

未来还会增加第三个对象:

AI Agent。

因此,未来财务数字化真正的竞争优势,可能不会只是“谁使用了最强的模型”,而是谁能够建立一套既允许 AI 高度自治,又能保持数据主权、权限可控、行为可审计、责任可追溯的治理体系。

这也是我所理解的 Finance AI Bounded Autonomy Framework 的核心:

这或许就是未来财务 AI Governance 最早的管理雏形。

本文仅作 AI 治理与内部控制的一般性讨论,不构成针对任何具体系统、机构或司法管辖区的专业意见。

Jerry Xiong writes on AI governance, markets and operational risk for finance and business decision-makers.熊焱|为财务与企业决策者解读 AI 治理、市场与运营风险。