ibl.ai Agentic AI Blog

Insights on building and deploying agentic AI systems. Our blog covers AI agent architectures, LLM infrastructure, MCP servers, enterprise deployment strategies, and real-world implementation guides. Whether you are a developer building AI agents, a CTO evaluating agentic platforms, or a technical leader driving AI adoption, you will find practical guidance here.

Topics We Cover

Featured Research and Reports

We analyze key research from leading institutions and labs including Google DeepMind, Anthropic, OpenAI, Meta AI, McKinsey, and the World Economic Forum. Our content includes detailed analysis of reports on AI agents, foundation models, and enterprise AI strategy.

For Technical Leaders

CTOs, engineering leads, and AI architects turn to our blog for guidance on agent orchestration, model evaluation, infrastructure planning, and building production-ready AI systems. We provide frameworks for responsible AI deployment that balance capability with safety and reliability.

Back to Blog

Finance AI With No Audit Trail Is Evidence, Not Speed

Jaione AmigotSeptember 16, 2026
Premium

Gartner reports 93% of audit leaders and auditors using AI, while a May 2026 poll found only 38% of chief audit executives have any AI strategy, and PCAOB AS 1105 makes an untraceable entry a rework bill.

The Short Answer

Mid-market finance teams adopted AI without a governance layer. Gartner reports 93% of audit leaders and auditors using AI, and a May 2026 poll found only 38% of chief audit executives with an AI strategy. Under PCAOB AS 1105 an auditor must test company-produced information, so an AI-assisted entry with no retained trail is a finding, not a saving. With ibl.ai you own all the code and the data, so the trail is yours to produce.

The absence of a record is not a gap in the evidence. In an audit or a dispute, it is the evidence.

What does "mid-market" mean here, and which rules actually bind a mid-market finance team?

It means a revenue band, and the answer to the second half is narrower than most coverage implies.

The National Center for the Middle Market defines the U.S. middle market as companies with annual revenues between $10 million and $1 billion: roughly 200,000 businesses, about 3% of U.S. companies, producing 33% of private sector GDP and 33% of private sector jobs.

Most are private, so SOX's internal-control reporting requirements do not apply to them.

Even among public filers the obligation is thinner than assumed. 15 U.S.C. 7262 requires management to state its responsibility for internal control over financial reporting and assess its effectiveness at year end.

Subsection (c) exempts issuers that are neither large accelerated nor accelerated filers from the 404(b) auditor attestation, and the SEC's 2020 amendment widened that carve-out to smaller reporting companies under $100 million in annual revenue, effective 27 April 2020.

Banking guidance does not cover the gap either. SR 26-2, issued by the Federal Reserve, OCC and FDIC on 17 April 2026, is most relevant to organizations above $30 billion in total assets.

Its footnote 3 states that "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance."

The same footnote extends the guidance's principles to "non-generative, non-agentic AI models" β€” the reading examined in inference engineering, not architecture.

So a controller waiting for a rule to arrive is waiting for something that is not coming. The exposure is evidentiary, and it is already here.

How much unsanctioned AI is really running inside finance functions?

Enough that the honest answer is nobody has a finance-specific number worth citing, and the adjacent numbers are bad enough.

BlackFog's survey of 2,000 workers at companies with more than 500 employees, reported 29 January 2026, found 49% using unapproved AI tools and 51% who connected an AI tool to a work system without IT approval.

23% said they had put company financial information into one, and 58% of unapproved-tool users were on free consumer tiers: accounts the employer has no contract with and no retention control over.

The audit side is further along and no better governed. Gartner reports, via Help Net Security, that 93% of audit leaders and auditors use AI at some level, and 15% say their department runs formal use cases routinely.

In a separate May 2026 poll of 161 chief audit executives, only 38% have an AI strategy at any level; of 142 CAEs polled that month, 54% have not started measuring the value.

Read those together and the picture is specific: the function that will ask your team how a number was produced is itself using AI without a documented approach to it.

The same exposure shows up in security incidents involving unapproved AI tools, the argument made at length in shadow IT stored data, shadow agents take actions.

Why is an AI-assisted journal entry with no trail a finding rather than a productivity gain?

Because of what an auditor is required to do with information your company produced.

PCAOB AS 1105 requires sufficient appropriate audit evidence, where appropriateness is "the measure of the quality of audit evidence, i.e., its relevance and reliability."

When the auditor uses information produced by the company, the standard requires testing its accuracy and completeness β€” or the controls over it β€” and confirming it is sufficiently precise and detailed for the audit.

An accrual estimate, a flux explanation or a reconciliation an analyst obtained from a consumer chatbot satisfies none of that. There is no control to test, and no record to test, because the session belongs to a personal account.

The result is rarely a penalty. It is rework: the auditor cannot rely on the number, so the procedure is redone at audit rates, during the close.

The same asymmetry applies in a dispute. An AI-assisted forecast, valuation input or credit decision is discoverable, and in discovery the absence of a trail is not neutral.

You cannot show what the model saw, which version answered, or who approved it. Opposing counsel does not have to prove the number was wrong, only that you cannot show it was right.

Speed without auditability is therefore not innovation. The artifact it leaves behind is evidence you did not choose to create.

Which three controls can a mid-market controller stand up without an enterprise programme?

Three, and none of them requires a platform purchase, a committee, or a policy your team will not read.

  • An inventory of where AI touches the close. One sheet: process step, person, tool, and whether the output lands in the ledger, a schedule, or a memo. It has to come first, because the other two controls take a named process as their input.
  • A retained per-run trail. For every AI-assisted output that reaches a statement, retain the prompt, the input data, the output, the model and version, and the reviewer, in storage the author cannot edit.
  • Data classification with one hard line. Name the categories that may never leave a system the company controls, then enforce it at the network and identity layer rather than in a policy document.

Classification is where most programmes stall, because it gets written as a taxonomy exercise. One tier naming the data that may not enter an unmanaged tool is more enforceable than five nobody can apply on day three of the close.

Why does running the platform inside your own perimeter make the trail yours to produce?

Because an audit trail you cannot export on demand is an assurance, not a record.

When the assistant runs on a vendor's infrastructure, the log is the vendor's log. What you receive is what their retention policy, export format and contract term decide you receive, on their timetable rather than your auditor's.

When the platform runs inside your perimeter, every prompt, retrieval, model response and approval is written to your storage, under your retention schedule, queryable by your team. Producing it is a query, not a support ticket.

This is the same structural argument that determines whether banking AI reaches production, arriving at a smaller company.

How does ibl.ai give a finance team a trail it can produce on demand?

By putting the platform, and its source, inside the company's own perimeter.

With ibl.ai you own all the code and the data.

The platform deploys on your infrastructure with full source code access, so retention windows, logging schema, approval gates and classification rules are components your team reads and changes rather than vendor behavior you observe.

It is model-agnostic across any LLM, so a governance record survives a model swap instead of being rebuilt around it.

Billing is usage-based with no per-seat pricing, so bringing the whole finance organization under one governed system does not cost more than leaving them on consumer accounts.

You can deploy anywhere: your own cloud, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

Agent access is role-scoped through your identity provider and enforced server-side by the broker, and every tool call is written to a tamper-resistant log the agent cannot alter.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY.

Related reading: shadow IT stored data, shadow agents take actions β€” the six day-one controls that sit under any agent runtime; and inference engineering, not architecture β€” the full reading of SR 26-2's footnote 3.

Sources: the revenue band and the 3%/33% shares from the National Center for the Middle Market; the ICFR report and 404(b) exemption from 15 U.S.C. 7262, with the 2020 carve-out from Cooley; the issuance date, applicability and footnote 3 from SR 26-2; the audit-evidence requirements from PCAOB AS 1105; the unapproved-tool figures from CIO on BlackFog's survey; the AI-use, strategy and value-measurement figures from Help Net Security on Gartner's internal-audit research.

Why does owning the AI stack matter?

ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing β€” so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.

  • You own all the code and the data

    Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform β€” the stack itself is yours.

  • Model-agnostic

    Run any LLM β€” Claude, GPT, Gemini, Llama, Command, or your own fine-tune β€” and switch providers without rewriting the platform.

  • No per-seat pricing

    Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.

  • Deploy anywhere

    Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY β€” a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.

Related Articles

Shadow IT Stored Data. Shadow Agents Take Actions.

IBM's 2026 breach report puts shadow AI in 43% of security incidents, more than double the year before, while close to seven in ten breached organizations had no governance policy covering unapproved AI use.

ibl.ai EngineeringSeptember 11, 2026

Shadow AI in Healthcare: The Patient Safety Crisis

Clinicians are already pasting PHI into consumer AI tools, and no acceptable-use policy has ever stopped a productivity habit. The fix is infrastructure: a sanctioned AI platform the hospital owns and runs itself, so PHI never leaves the building.

ibl.ai EngineeringAugust 5, 2026

Shadow AI Is Already Inside Every Government Agency

Unsanctioned AI use is already routine across federal agencies, and in government the exposure is statutory rather than commercial β€” Privacy Act records sent to commercial providers, federal records generated in systems the agency cannot subpoena, supply-chain restrictions under EO 13873, and mosaic classification spillage. This post maps each exposure to its legal basis and gives the data-classification tiers that decide which workloads need managed cloud, agency-controlled infrastructure, or a fully air-gapped deployment.

ibl.ai EngineeringAugust 4, 2026

Shadow AI Is Enterprise AI's Biggest Security Threat β€” And Buying More Tools Makes It Worse

The average enterprise now has 4-7 AI tools across departments with no unified governance. Shadow AI β€” unauthorized AI use by employees β€” is growing faster than any sanctioned deployment. The fix isn't more tools. It's a platform layer.

Blanca AmigotJune 9, 2026

See the ibl.ai AI Operating System in Action

Discover how leading universities and organizations are transforming education with the ibl.ai AI Operating System. Explore real-world implementations from Harvard, MIT, Stanford, and users from 400+ institutions worldwide.

View Case Studies
Work with our team

Pilots, deployment, and full ownership

Most enterprise engagements are one-time, not subscriptions. You integrate ibl.ai with your own data, deploy it on your own infrastructure, and the engineering hours scale with the work β€” so the price tracks the scope, not your headcount.

Start here

Pilot

from $15K

fixed scope Β· fixed timeline

A time-boxed proof of value on your real data β€” not a slide deck.

Best for: Teams that want to see ibl.ai working before committing.

  • Deployed on your infrastructure or our cloud
  • 1–2 production agents wired to a slice of your data
  • One integration (LMS / SIS / SSO / data source)
  • Weekly working sessions with our engineers
  • Pilot fee credits toward a full engagement
Scope a pilot
Most common

Integration & Deployment

$25K – $80K

one-time Β· not a subscription

Full deployment integrated with your data and systems. Engineering hours scale with scope.

Best for: Organizations rolling ibl.ai out across a department, campus, or business unit.

  • Platform deployed in your VPC, on-prem, or air-gapped
  • Integrated with your data + identity (SSO / SAML)
  • Multiple custom agents built to your workflows
  • Engineering hours proportional to scope
  • You own the data Β· run any LLM you choose
Plan a deployment
Full ownership

Codebase Transfer + Custom AI Engineering

Six figures

perpetual license Β· you own the stack

We transfer the full source code. You own and self-host the entire platform β€” outright.

Best for: Government, defense, and enterprises that require perpetual ownership and sovereignty.

  • Complete source-code transfer + perpetual license
  • Dedicated AI engineering team on your roadmap
  • Custom agents, models, and integrations to spec
  • Air-gapped capable Β· zero vendor lock-in
  • Family-owned, New York–based long-term partner
Talk about ownership
You own the code and data Run any LLM β€” Claude, GPT, Gemini, Llama Family-owned & operated from New York, NY