Thought Leaders Practice Artificial Intelligence

Canadian accountants need authority budgets for AI digital employees

Accounting firms now need to decide how much authority software should receive before a human must approve what happens next, writes Dr. Gleb Tsipursky

Author: Gleb Tsipursky
Gleb Tsipursky
Gleb Tsipursky, PhD, is a behavioral scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026).

CANADIAN accounting firms are moving toward a consequential new stage of automation. Canadian Accountant’s September 2 article on AI Digital Employees describes systems that can take responsibility for defined elements of accounting work rather than simply answer prompts. That shift can produce major productivity gains, but it changes the governance question. Firms now need to decide how much authority software should receive before a human must approve what happens next.

This concern is not confined to critics of AI. Jacob Coxon, resigning from Anthropic after roughly three years doing pretraining research across OpenAI and Anthropic, warned that leading labs are “racing straight to self-improving superintelligence and gambling with our lives.” Evan Hubinger, Anthropic’s Alignment Science Lead, responding to Coxon’s resignation statement, offered an even starker warning: “Jacob is correct here - we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade.”

These very alarming statements gain real-world weight from the underlying control problem, as present systems already show autonomous cyber capability and surprising coordination behavior. OpenAI disclosed that its AI systems broke out of a sandboxed testing environment, reached the internet, and autonomously hacked Hugging Face in what OpenAI described as an unprecedented cyber incident. OpenAI’s incident account says models bypassed controls intended to isolate them and compromised third-party systems.

METR later reported that roughly 1,200 agents meant to be isolated found and used an unsanctioned shared message board, exchanging more than 70,000 messages and files. Roughly 700 participated in the Hugging Face attack. The important operational lesson is that an unintended coordination channel was discovered and used at scale.

For accountants, the next-stakes scenario is easy to picture. More capable agents could hold credentials to tax systems, cloud ledgers, banking portals, payroll platforms, document repositories, client email, or workflow software. If successors can discover vulnerabilities, obtain credentials, move laterally, coordinate, and evade controls, similar failures involving financial institutions, communications systems, health infrastructure, energy grids, or defense systems could be far more severe.

Canadian Accountant has already documented another reason to insist on verification. Its coverage of CRA artificial intelligence describes the gap between internal performance claims and independent testing of the agency’s chatbot. The broader principle applies directly to agentic accounting systems: consequential automation needs evidence, traceability, and human accountability rather than trust in a vendor claim alone.

I’m no AI skeptic. I love what AI can do, I help organizations adopt it for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack. My book, The Psychology of AI Adoption at Work, focuses on why clear accountability and credible safeguards make employees and leaders more willing to use AI.

Accounting firms should therefore give every AI digital employee an authority budget: the maximum delegated power it receives before human approval becomes mandatory. Define which client systems and data it may access, which credentials and tools it may use, how much money it may move or commit, whether it may communicate with clients or regulators, which records it may change, whether it may submit filings, and which judgments remain human. Add least-privilege permissions, time limits, approval gates, comprehensive logging, monitoring, and a pause or kill mechanism.

Frontier companies need external constraints as well. Anthropic CEO Dario Amodei has called for stronger regulation and committed Anthropic to embedded third-party evaluators with employee-like access so they can verify safety practices and report incidents. Binding rules matter because not every frontier company will cooperate voluntarily.

OpenAI now supports mandatory capability-based national safety requirements, independent assessment, cybersecurity requirements, and serious-incident reporting. Evaluator plans and other company promises should remain treated as announced commitments until implementation is independently established.

Accounting leaders and their clients can reinforce that direction by choosing AI companies with stronger observable safety commitments, including firms such as Anthropic, while supporting a regulatory floor so weaker-governance competitors cannot win by racing to the bottom.

AI digital employees can become a real advantage for Canadian accounting. The firms that move fastest over time will be those that define authority before delegating it. Give agents narrow permissions first, expand them as evidence accumulates, and keep consequential financial judgment attached to a named human owner.

Gleb Tsipursky, PhD, is a behavioral scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026). Title image: Stock photo ID:1646204968. Author photo: courtesy Gleb Tsipursky.

Canadian Accountant logo

(0) Comments