Agentic AI Is Moving Inside ERP.

Updated: Aug 31

Agentic AI Is Moving Inside ERP. That Does Not Mean It Is Ready to Run the Business.
The ERP AI conversation has moved on quickly.
A year or two ago, most of the talk was about copilots. Ask a question, draft a report narrative, summarise a variance, write a supplier email, explain a dashboard. Useful in places, but still mostly helping someone do the work rather than actually doing the work.
That is changing. Vendors are now talking about agents inside ERP workflows. Agents that do not just answer questions, but help complete tasks across reconciliation, procurement, forecasting, order management, financial analysis, reporting, billing, collections and operational exceptions.
That is a much bigger shift, and it is where the risk starts to get real.
There is a massive difference between AI drafting a paragraph and AI operating inside a finance or operational process. One is helpful admin support. The other starts to get close to approvals, controls, audit trails, segregation of duties, supplier decisions, customer commitments, stock, margin and management reporting.
I think there is a lot of value here. I also think it could become a mess very quickly if ERP agents are treated like another shiny productivity feature.
The business reality behind ERP agents
ERP is not just another system. It is where the business records what happened, decides what happens next and proves that the numbers can be trusted. It is where orders turn into revenue, purchase requests turn into commitments, stock movements turn into margin, projects turn into WIP, and journals turn into board reports.
That is why AI inside ERP needs to be treated differently from AI inside a note-taking tool or document app. If an AI assistant writes a poor meeting summary, someone corrects it. Annoying, but not usually a major business risk. If an ERP agent recommends the wrong supplier, reconciles the wrong transactions, misses a tolerance breach, pushes the wrong item into a purchase cycle or gives a confident but wrong explanation of financial performance, that is a different problem.
That can create real operational and financial risk.
This is where the conversation needs to be less excited and more practical. Can the agent see the right data? Can it explain what it has done? Can it work inside the approval rules? Can it respect roles and permissions? Can it deal with exceptions? Can it show what was suggested, what changed and who approved it?
If the answer is not clear, it should not be near a live process.
ERP agents are not really about AI. They are about trust.
Copilots were the warm-up. Agents are different.
A copilot helps the user do the work. An agent starts to take more of the work on. That sounds like a small difference, but it is not.
A copilot might help a finance user draft commentary on a cost variance. The finance user checks it, edits it and owns it. Fine. An ERP agent might monitor the variance, pull the transactions, compare trends, suggest the cause, route a task to the budget holder and draft the commentary for the reporting pack.
That is more useful, but it creates harder questions. Who owns the answer? Who checks the logic? What happens when the agent is right for the wrong reason? What happens when it works most of the time, but the mistake is material?
That is where businesses will trip up. They will look at the efficiency gain and not spend enough time on the operating model around it.
The vendor demo will always look clean. The agent finds the issue, recommends the action and presents a tidy answer. Everyone nods because it looks obvious. But live ERP is rarely that tidy. The data has gaps. Processes have exceptions. Approval rules have history. People have workarounds. Some fields are used properly. Some fields are abused. Some fields mean different things in different parts of the business, even though everyone pretends they do not.
That is the real test.
Do ERP agents genuinely execute controlled business processes, or do they just become expensive assistants that still need everything checked manually?
This is a big leap from wiring AI into ERP
This is where I think some businesses will confuse two very different things.
There is a difference between connecting your AI tool of choice to ERP through something like MCP, and having AI properly embedded inside an ERP workflow. MCP is useful. It gives AI tools a cleaner way to connect to systems, data sources, tools and actions. For reporting support, document lookups, internal search, query support and prototypes, it can be powerful.
But access is not the same as control.
Connecting a chatbot to NetSuite, Oracle Fusion, Dynamics or any other ERP is not the same as making it safe to operate inside the ERP process. A chatbot that can query customer records, supplier balances, stock positions or project data is one thing. An agent that can work inside a purchase process, reconciliation process, collections process, order process or forecasting process is something else entirely.
ERP is not just data. ERP is control.
It is roles, permissions, workflows, approvals, audit trails, posting rules, period controls, delegated authority, exception handling and accountability. That is why ERP-native agents are a bigger deal than just hooking up an AI tool through a connector.
The value is not just that AI can see the data. The value is that AI can work in the context of the process, with the right rules, approvals and audit trail around it. That is also where the risk is.
If an AI tool is only connected to ERP, the main question is whether it has the right access. If an AI agent is embedded inside ERP, the question is much bigger. Should it act? Should it only recommend? Who approves it? What evidence does it show? What happens when it is wrong? Who owns the outcome?
That is the real difference between AI beside ERP and AI inside ERP.
The vendors are moving fast
The direction of travel is obvious now.
Oracle has been pushing hard into agentic applications across Fusion. It has talked about agentic applications that can reason, coordinate, decide and execute work through Fusion business objects, workflows, tools, policies, approvals and logged actions. That is not generic chatbot language. That is AI moving closer to the transaction layer.
Microsoft is moving the same way. Its Dynamics 365 Business Central roadmap talks about AI-powered agents automating sales and purchase scenarios. Sales order creation, payables processing and purchase matching are exactly the kind of areas where businesses will be tempted to move quickly because the manual effort is obvious.
NetSuite is now very clearly in this conversation as well.
NetSuite Next matters because it brings this debate directly into the mid-market ERP space, not just large enterprise Fusion-style programmes. Oracle is positioning NetSuite Next around embedded conversational intelligence, agentic workflows, natural language search, Redwood, customer data and existing controls.
For NetSuite customers, that is a big shift.
The historic NetSuite value has always been around a single cloud suite, one source of operational and financial truth, and a platform that growing businesses can scale on. If NetSuite Next can put AI into that flow properly, there is obvious value. Faster analysis, better exception handling, less manual searching, smarter workflows and quicker answers for finance, sales, procurement and operations.
But it also raises the same old ERP question.
Is the business ready?
Because if the underlying process is poor, if the data is weak, if roles are messy, if approvals are unclear and if people do not trust the reports today, NetSuite Next will not magically fix that. It may just expose the gaps faster.
CFO interest is clearly rising. Deloitte’s latest UK CFO survey found 73% were optimistic about AI improving business performance, up from 59% at the end of 2025. You can see why. Finance teams are stretched. Month end is still too manual. Forecasting still sits in too many spreadsheets. Procurement still chases approvals. Reporting still takes too long. Operations still spend too much time firefighting exceptions.
There is real opportunity here, but there is also real risk if businesses confuse capability with readiness.
The risk is not AI. The risk is confusing access with control.
This is where the conversation needs to grow up a bit.
Too much AI chat still sits at the level of “it will save time” or “it will improve productivity”. Fine, but ERP needs a higher test. A faster bad process is still a bad process. A faster wrong answer is still a wrong answer. A faster approval that bypasses control is not progress.
The proper test is whether agents can work inside business controls without weakening them. That means approval limits, delegated authority, segregation of duties, audit trails, permissions, posting controls, period close rules, exception handling and human review points.
ERP should have an advantage here. Systems like NetSuite, Oracle Fusion and Microsoft Dynamics already have roles, permissions, workflows, transaction history and control structures. In theory, native agents should be more controlled than random AI tools bolted on around the edges.
But “in theory” is doing a lot of work.
Before letting an ERP agent near a live process, I would want very clear answers. What can the agent do? What can it only recommend? What can it change? Where is approval mandatory? What is logged? How is it tested? Who owns the output? Who monitors it? Who explains it to audit?
Those are not anti-AI questions. They are basic ERP questions.
If a human user needs controls to perform a task, an AI agent definitely does.
What I would do differently
The first thing I would do is avoid starting with the cleverest use case.
Do not start by letting an agent loose on something high risk, political or badly understood. Start where the process is clear, the data is reliable, the rules are known and the outcome can be checked.
Reconciliation support is a good place to look, but only if the agent is identifying matches, exceptions and explanations rather than quietly forcing things through. Procurement support could be useful, but not if it starts pushing supplier decisions without pricing context, policy and approval control. Forecasting support has potential, but nobody should pretend an agent understands the business better than the people accountable for the number.
The second thing is to fix the process before adding the agent.
This is not new. It is the same ERP point we have been making for years. Technology does not fix poor ownership, bad data or unclear decisions. AI may make the demo look better, but it will not fix the foundations.
If your item master is a mess, an agent will not make procurement intelligent. If your customer and project data is inconsistent, an agent will not make reporting trusted. If your approval rules are full of exceptions nobody understands, an agent will not make control easier.
It will just move the confusion quicker.
The third thing is to design the human role properly.
Everyone will talk about what the agent does. Not enough people will talk about what the human does differently. If the agent prepares a reconciliation, what is the reviewer actually reviewing? If it drafts a variance explanation, what evidence does the finance manager need to see before trusting it? If it suggests a supplier action, who checks the commercial context? If it prioritises collections, who decides whether the customer relationship needs a different approach?
AI changes the human job. That has to be designed properly. Otherwise people will either over-trust the agent or ignore it completely. Both are bad.
The fourth thing is to make auditability boring and non-negotiable.
If an ERP agent acts, recommends or routes something, the business needs a record. What data did it use? What rule did it apply? What did it suggest? What changed? Who approved it? What was overridden?
That is not exciting.
Good.
ERP control should not be exciting.
People-first ERP still matters in an agentic world
Agentic AI does not remove the need for people-first ERP. It makes it more important.
The technology may be smarter. The workflows may become more automated. The screens may become more conversational. NetSuite Next, Oracle Fusion agents and Microsoft’s Business Central agents all point in the same direction. More work will happen inside the system with less clicking.
That could be a very good thing, but the old ERP truths do not disappear.
Bad data will still hurt you. Weak ownership will still hurt you. Poor process design will still hurt you. Unclear controls will still hurt you. Leaders being too far away from the detail will still hurt you.
The difference is that agents could make the impact quicker and harder to spot if governance is weak.
The winners will not be the organisations that switch on the most agents. It will be the ones disciplined enough to decide where agents can act, where they can only recommend and where a human still needs to own the decision.
That is the real ERP debate.
Not whether the demo looks clever.
Whether the business can trust what happens after the demo.
Agentic AI inside ERP is coming. In NetSuite, Fusion, Dynamics and plenty of other platforms, it is already moving from marketing slide to product roadmap. The question is not whether businesses should pay attention. They should.
The question is whether they are ready to let agents near the workflows where accuracy, control and accountability actually matter.
What ERP workflow would you let an AI agent touch first, and which one would you keep well away from for now?



