AI Is Moving Faster Than Most Companies’ Internal Controls
Published Jul 25, 2026
Artificial intelligence is becoming part of everyday business operations. Employees use it to analyze spreadsheets, summarize contracts, draft correspondence, prepare marketing materials, write software, research technical questions, and respond to customers. Companies are embedding AI into accounting platforms, customer-service systems, hiring processes, cybersecurity tools, and financial forecasting models.
The potential benefits are real. AI can reduce repetitive work, accelerate analysis, identify patterns in large datasets, and make sophisticated capabilities available to smaller organizations that previously could not afford them. Employees can complete many manual tasks that previously required hours of manual effort in minutes.
The problem is not that companies are using AI. The problem is that many are adopting it faster than they are developing the controls needed to govern it. That creates a familiar internal-control problem in a new form where a powerful system is introduced into an important business process without clearly defined authority, data restrictions, testing, documentation, monitoring, or accountability. The objective is not to prevent professionals from using AI. The objective is to provide an approved, well-controlled way to realize those productivity gains without compromising the confidentiality of client information or the organization's governance responsibilities.
What's the Harm? A Common Misunderstanding
One of the greatest internal-control risks associated with artificial intelligence is not malicious intent, it's well-intentioned employees using AI in ways they believe are completely safe.
Consider the common scenario below.
A tax manager has been asked to review an S corporation tax return for planning opportunities. The return contains dozens of supporting schedules, depreciation, shareholder basis calculations, state apportionment information, related-party transactions, and prior-year carryforwards. Rather than spending several hours reviewing the return manually, the manager uploads it to an AI tool and asks it to identify tax planning opportunities, unusual deductions, and potential audit risks.
Within minutes, the AI produces a thorough, well-organized analysis that would have taken considerably longer to prepare manually.
To many professionals, the decision appears entirely reasonable. They have saved hours of tedious work and the analysis appears accurate. They may have used a temporary-chat feature after watching a respected accounting technology influencer explain that it is a safe way to use AI. They understand that temporary chats are not used to train the model and assume the information simply disappears once the browser window is closed, much like using Chrome's Incognito mode. From their perspective, no one is sitting on the other side reviewing prompts looking for confidential information to steal. The productivity gains are obvious, while the risks seem remote or even theoretical.
That reasoning is understandable. It is also where many organizations and their employees unintentionally confuse convenience with governance.
For decades, accountants have evaluated new technology through the lens of internal control. Whether the technology was online banking, cloud accounting, electronic signatures, or remote access, the questions have always been the same. Who approved it? What information is leaving the organization? Who can access it? What evidence exists that the process is operating as intended?
Artificial intelligence is no different. The technology has changed. The principles have not.
The issue is not whether someone at the AI provider intends to misuse the information. The issue is that confidential client information has been transmitted to an external system before the organization determined whether that transfer was appropriate, authorized, and protected by adequate controls.
A common misconception is that a temporary AI chat functions like a private workspace on the user's computer. It does not.
Information entered into an AI prompt must generally be transmitted to the provider's systems so the request can be processed. Closing the browser window does not reverse that transmission. OpenAI states that ChatGPT Temporary Chats do not appear in the user's history, do not create memories, and are not used to improve its models. OpenAI also states that Temporary Chats may be retained for up to 30 days for safety purposes, and information shared through third-party actions connected to a custom GPT may be subject to those providers' separate privacy practices.
Those protections may make Temporary Chat appropriate for certain approved business uses. They do not, however, authorize employees to upload confidential client tax returns or other sensitive business information.
The comparison to Chrome's Incognito mode is also misleading. Incognito primarily limits what is stored on the user's local device. It does not prevent information from being transmitted to websites or external service providers. Likewise, a temporary AI chat changes how information is handled after processing, not whether the information was transmitted in the first place.
From a governance perspective, management must still ask the same questions. Was the AI application approved for this purpose? Has the organization evaluated the provider's security and privacy practices? Was transmitting an entire tax return necessary to accomplish the objective? Could a less sensitive version of the information have been used? How long might the information be retained? Who could potentially access it? Does the transmission comply with the firm's confidentiality policies, professional standards, client agreements, and applicable privacy laws?
The fact that the analysis may have been accurate does not answer those questions. Nor does the fact that no one may ever manually review the information. The tax manager may have saved several hours of work, the AI provider may have excellent security, and no misuse of the data may ever occur. Even so, confidential client information may have been transmitted to an external system without authorization, creating an unnecessary internal-control risk.
The question is not whether the AI provider is trustworthy. Most major providers invest heavily in security. The question is whether your organization, and not your organization's employee, made the decision that this particular information could appropriately be shared with that provider under those circumstances.
Another important consideration is whether the entire tax return needed to be uploaded at all. A request for planning ideas may require only selected schedules or a summarized set of financial information rather than a complete return containing ownership details, compensation, depreciation schedules, related-party transactions, elections, state filings, and other confidential business information.
One of the fundamental principles of sound internal control is data minimization, i.e., disclose only the information reasonably necessary to accomplish the intended business purpose. That principle applies whether information is shared with another employee, an outside service provider, or an artificial intelligence platform.
Additionally, internal controls are not designed solely to prevent intentional theft of information. They also exist to reduce the risk of accidental disclosures, compromised accounts, excessive system access, vendor failures, browser extensions, security incidents, inappropriate data retention, and violations of contractual, regulatory, or professional confidentiality obligations. The absence of an immediate negative consequence does not establish that the activity was properly controlled.
Most companies know which accounting system they use. They know which bank has access to their funds and which payroll provider processes employee information. Many do not know which AI systems their employees are using. The use of AI applications without formal authorization, security review, or monitoring is an emerging problem and has become known as "Shadow AI". A policy that simply says “do not enter confidential information into AI” is unlikely to be enough. Companies must define what information is confidential, which tools are approved, what data may be entered, who may authorize exceptions, and how compliance will be monitored. The same principle applies to third-party software. A company may believe it has not adopted AI while its existing vendors quietly add AI features to accounting, human resources, customer relationship management, or productivity platforms.
AI governance therefore begins with an inventory. Management cannot control systems it does not know are being used.
Financial information requires particular caution
The use of AI in accounting and financial reporting can be valuable, but it also raises significant internal-control concerns.
An AI tool may help categorize transactions, identify unusual journal entries, prepare account reconciliations, summarize variances, or generate a draft management report. None of these activities should automatically be treated as reliable merely because they were produced by a sophisticated system.
Management should understand:
- What data the system uses
- Whether the data is complete and accurate
- How the model reaches its conclusions
- Whether outputs are independently reviewed
- Whether changes to the system are documented
- Whether access is appropriately restricted
- Whether the company retains an audit trail
These questions are not radically different from the questions companies should already ask about spreadsheets, system reports, automated journal entries, and third-party service providers. AI simply makes the need for those controls more urgent.
For example, a company may use AI to prepare a cash-flow forecast. The forecast may appear reasonable, but the system could exclude recently entered liabilities, misinterpret nonrecurring revenue, or rely on outdated assumptions. Unless someone understands the inputs and reviews the output, the company may make a major financing or spending decision based on information that was never properly validated.
The control cannot be merely that “a person looked at it.” Effective review requires a qualified person, access to the underlying information, defined review criteria, evidence that the review occurred, and a process for resolving exceptions.
Cybersecurity risks extend beyond data leakage
AI systems also introduce distinct cybersecurity risks.
The OWASP Foundation’s current guidance for large language model applications identifies risks that include prompt injection, sensitive-information disclosure, improper output handling, excessive agency, data and model poisoning, and overreliance on AI-generated results.
Prompt injection is particularly important for companies developing AI agents or connecting AI systems to internal databases and applications. A malicious instruction embedded in an email, document, website, or customer message may attempt to manipulate the AI system into revealing information or taking an unauthorized action.
Excessive agency presents another risk. An AI assistant that can only draft an email has limited authority. An AI agent that can access customer files, modify accounting records, initiate payments, change system configurations, or send communications has a much larger risk profile.
The principle of least privilege should apply to AI just as it applies to employees and conventional software. An AI system should receive only the access necessary for its defined purpose. High-impact actions should require separate human authorization.
Companies should also consider whether their existing data-loss-prevention controls are strong enough to govern AI use.
At Gomez CPA, strict security policies apply to internal users, including working from personally owned devices under our BYOD policy. Users cannot copy internal documents or email content to an unmanaged clipboard, capture screenshots of protected information, or save company data to external devices. Most users are also restricted from sending or receiving email attachments.
Some may consider these controls overly restrictive. Their purpose, however, is to reduce the risk that client information is copied, downloaded, transferred, or otherwise removed from the firm’s controlled environment.
Similar restrictions apply to AI tools. Access should be limited to approved applications, and confidential client, tax, payroll, financial, and personally identifiable information should not be entered into systems that have not been reviewed and authorized.
This type of control is more effective than relying exclusively on employee judgment. Training is important, but technical restrictions help prevent an accidental disclosure before it occurs.
Regulation is moving toward formal accountability
AI governance is no longer solely a matter of good practice.
The European Union’s AI Act entered into force on August 1, 2024, with requirements becoming applicable in stages. Many of its broader provisions are scheduled to apply beginning August 2, 2026. The law uses a risk-based structure and imposes more extensive obligations on certain high-risk uses of AI.
In the United States, regulation remains more fragmented, but state laws, industry requirements, consumer-protection rules, privacy laws, employment laws, contractual obligations, and existing professional standards may already apply to an AI-enabled process. The Securities and Exchange Commission’s Investor Advisory Committee has also recommended more consistent corporate disclosure concerning the use of artificial intelligence, reflecting concern that investors may receive vague or incomplete information about how AI affects a company’s operations and risks.
Companies should not assume that the absence of a single comprehensive federal AI law means the absence of legal exposure. An inaccurate AI-generated statement may still constitute a misleading representation. An automated hiring decision may still violate employment law. Improper disclosure of customer information may still violate privacy obligations. A weakly controlled financial process may still produce a material misstatement.
AI changes the method. It does not erase the underlying obligation.
Practical AI Governance
The National Institute of Standards and Technology (NIST) has developed an AI Risk Management Framework to help organizations govern the use of artificial intelligence. Although every organization will implement controls differently, the underlying principles are familiar. Companies should know which AI tools are being used, who is using them, what information is being shared, and how AI influences business decisions. They should classify AI applications according to their financial, operational, privacy, security, and regulatory risks, establish policies governing appropriate use, restrict access to sensitive information, require human review of significant AI-generated outputs, maintain appropriate audit trails, evaluate third-party providers, and train employees on approved uses and data-handling requirements.
The objective is not to prevent employees from using AI. Broad prohibitions often encourage the use of unapproved tools while organizations with stronger governance realize the productivity benefits. A better approach is controlled adoption which is allowing AI to improve efficiency while applying stronger controls when confidential information, financial reporting, customer communications, employment decisions, or other high-risk activities are involved.
The question management should ask is not, "Does our company use AI?" A more meaningful question is, "Where is AI being used, what could go wrong, and what evidence do we have that the risks are being controlled?" Artificial intelligence may change how companies operate, but it does not change the principles of sound internal control. Organizations that establish those guardrails can improve both efficiency and risk management. Those that do not may eventually discover they automated not only their work, but also their errors.
Sources
- EU AI Act enters into force: https://commission.europa.eu/news-and-media/news/ai-act-enters-force-2024-08-01_en
- SEC IAC disclosure of AI impact on Operations: https://www.sec.gov/files/sec-iac-artificial-intelligence-recommendation-111825.pdf
- Open AI - Temporary Chat FAQ: https://help.openai.com/en/articles/8914046-temporary-chat-faq
- Google - Browse in Incognito mode: https://support.google.com/chrome/answer/95464
- OWASP - Top 10 Risk & Mitigations for LLMs: https://genai.owasp.org/llm-top-10/
- NIST AI Risk Framework: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
© 2026 Gomez CPA. All rights reserved.