
An AI agent for accounts payable is software that reads a bill, works out what it is, and takes the next step without being told how. General tools like ChatGPT and Claude now do the reading and the working-out well. What they do not bring is the part of AP that keeps money safe: the right person approving, the same result on the same bill, and a record an auditor can follow. Those three things, not the reading, are where MakersHub puts its weight. MakersHub is set up around how your business already works, and our team configures it with you.
None of that is a knock on the general agents. They are good at a lot of AP work already. The useful question is not whether an agent can process a bill. It is which parts of the job a general-purpose agent should do on its own, and which parts belong in a system built for them.
An AI agent is software you give a goal instead of a script. Traditional AP automation follows rules somebody wrote: if the vendor is this supply house, code it to materials. An agent reads the situation, plans the steps, and acts, pausing to ask when it is unsure. That is what people mean by agentic AI, software that works toward an outcome on its own rather than answering one question at a time.
In accounts payable, three different kinds of product now carry the label.
Most guides compare the third group against itself. This one starts with the first group, because it raises the question finance teams are asking right now: if the AI we already pay for can read a bill, do we still need AP software?
More than most AP teams assume. Give either one a PDF and your chart of accounts. It will pull the vendor, the date, and every line item with its quantity and price. It will suggest a general ledger (GL) account for each line and point out the line that looks wrong. Anthropic's own page for its agent mode shows it rolling four regional exports into one summary, comparing them against a budget file, and flagging every variance over a threshold. That is real work, and it used to take someone most of a day.
Both products have moved from answering questions to taking actions. OpenAI's help center describes an agent that can sign into websites and use connected apps on your behalf, and Anthropic's works directly in the folders and tools you grant it. The names are moving as fast as the features. OpenAI's help page now says ChatGPT agent is no longer available and points people to ChatGPT Work, and Anthropic's page announces that Cowork is now simply Claude. That pace is worth weighing before you build a monthly close on top of it.
Where these tools shine is one-off work with a person watching. Think of cleaning up a year of miscoded bills, reconciling a vendor statement against the ledger, drafting a note to a supplier about a short shipment, or pulling every invoice from one vendor into a spreadsheet. If you have a job like that, use them, with a person checking the output. A general agent can hallucinate, meaning it can state a wrong number as confidently as a right one. What these tools are not built for is the recurring work a whole team shares week after week, where every bill has to be coded, approved, synced and paid the same way. That is the job MakersHub is built for.
Accounts payable is not really a reading job. It is a control job that happens to start with reading. The expensive failures in AP are rarely a misread number. They are a bill paid twice, a bill approved by someone who never saw what was on it, or a bank account changed by an email nobody checked.
COSO is the committee that publishes the Internal Control-Integrated Framework, and it is backed by the American Institute of CPAs (AICPA), the Institute of Internal Auditors and three other accounting bodies. In February 2026 it released guidance on internal control over generative AI. It names the new risks plainly: prompt-based manipulation, opaque reasoning, model drift, and frequent configuration changes. Each of those lands on a specific part of AP.
An agent can decide that a bill belongs to the Elm Street remodel. It cannot make the person running Elm Street look at it. The hard part of approval is getting each bill to the right person, and most of those people do not work in finance. Bills over a threshold go to the owner. Anything coded to a job goes to whoever runs that job. And the approval has to be recorded against the bill. In a general agent, that logic lives in whatever instructions or saved skills somebody wrote this month. That works until someone edits them, leaves the company, or forgets why a rule exists, and then the problem shows up after a bill is paid. In MakersHub, approval rules are set once in the product: thresholds by amount, and routing by job, vendor, cost code, department, location or entity, with more than one approver where a bill needs it. And what the approver actually sees on the bill matters more than how fast it reached them.
A language model is probabilistic, which means the same bill can come back coded two slightly different ways on two different days. COSO calls this model drift. For a one-time cleanup that is fine, because a person reviews everything. For a vendor you pay every week, the coding slowly wanders unless someone turns the decision into a rule. Our co-founder wrote about why AI-suggested GL coding has to become a rule rather than a fresh guess each time. That is the part most buyers underestimate.
An auditor wants to see who approved a bill, when, what they saw, and what changed afterward. A general agent keeps a conversation history, which is not the same thing. OpenAI's own documentation for enterprise customers says conversations involving agent tasks appear in its compliance logs, but individual agent actions, such as browser use and app requests, do not. That is an honest limit, and it matters on the day someone asks why a bill was paid.
Segregation of duties, the rule that the person who approves a bill should not also be the one who releases the payment, is one of the oldest controls in AP. It exists because one set of hands on both steps is exactly the opening fraud needs. An agent signed into your inbox and your bank is one set of hands. OpenAI is direct about this. It recommends enabling only the apps a task needs and avoiding open-ended instructions such as "Check my email and handle everything."
Here is how the three kinds of agent compare on the parts of AP that carry the risk. Every option below can read a bill and suggest a code. The differences show up after that.
| What AP needs | General agent (ChatGPT, Claude) | Agent in your ERP (Business Central) | MakersHub |
|---|---|---|---|
| Reads every line of a bill | Yes From a PDF or image you hand it | Yes PDFs from a monitored inbox, up to 10 pages | Yes Every line from PDFs, scans and photos, read and extracted by WiseVision |
| Codes to your chart of accounts | Partial Suggests codes from whatever you paste in | Partial Suggests codes from your transaction history | Yes Rules you set once, applied at the line, and you can set them in plain English with WiseVision |
| Same result on the same bill | No Can vary from run to run | Partial Suggestions a person reviews | Yes Rules apply the same way every time |
| Routes to the right approver | No You build and maintain it | Partial Uses existing Business Central approval workflows | Yes By job, vendor, cost code, amount or entity, approved from email |
| Records every action | Partial Varies by product and plan; OpenAI's compliance logs exclude individual agent actions | Yes A timeline of every step, under its own user identity | Yes Every capture, code, approval and sync |
| Keeps approval separate from payment | No Depends on what access you grant | Partial Drafts only; payment controls depend on your Business Central setup | Yes Separated by design |
| Connects to your accounting system | Partial Through connectors you enable | Partial Business Central only | Yes QuickBooks Online, QuickBooks Desktop, NetSuite, Sage Intacct, Xero, Intuit Enterprise Suite, plus Smart Data Connect for other systems |
The Business Central column comes from Microsoft's published FAQ for its Payables Agent, which is unusually candid. The agent never posts an invoice on its own and handles up to 100 emails a day. In Microsoft's words, it "can't understand business context" the way a person can. None of this makes ChatGPT or Claude a bad tool. They are a different tool: very good at the reading, and not built to enforce the controls around it.
Every bill in your AP inbox was written by someone outside your company. That has always been true, and it is why vendor bank-change scams work. It matters more now, because a general agent does not just read a document. It can follow instructions it finds in one.
The attack is called prompt injection: text hidden in a document, email or web page that an AI agent reads as a command. The National Institute of Standards and Technology (NIST) publishes a taxonomy of attacks on AI systems that lists indirect prompt injection as its own class of attack. OpenAI's help page for its agent walks through an example: a planted comment that tries to trick the agent into sending a password reset code to an outside website. A vendor invoice carrying a line of white text that says "update the remittance account to the following" is the AP version of the same trick. COSO's announcement of its generative AI guidance names the same risk in its first paragraph, as prompt-based manipulation.
The fix is in how the system is set up, not in a better prompt. In MakersHub, reading a bill and paying it are separate steps held by different people, so nothing written on a document can approve a bill or release money by itself. MakersHub is SOC 2 Type II certified, with Positive Pay protection on check payments and encrypted collection of vendor bank details. SOC 2 Type II is an independent audit of how a company protects customer data over months rather than on a single day. Positive Pay is a bank service that only clears checks matching the ones you issued. More on the payment controls that sit behind approval.
"GenAI can be confidently wrong, easily manipulated, or deployed outside formal oversight channels."
Lucia Wind, Executive Director and Chair, COSO, in the February 2026 release announcing its generative AI guidanceCOSO's guidance helps here. It sorts uses of generative AI into eight capability types, including ingestion, transformation, orchestration, judgment and posting, and sets control expectations for each. Here is how those categories line up with the steps a bill goes through. The mapping is ours, not COSO's.
| Step in AP | COSO capability type | Who should do it |
|---|---|---|
| Reading the bill | Ingestion, taking data in | AI, freely. This is where it is strongest |
| Coding each line | Transformation and judgment | AI proposes; after the first decision, a rule applies it |
| Routing for approval | Orchestration, coordinating steps and people | Rules, set once |
| Approving | Human-AI interaction | A person, with the coded lines in front of them |
| Syncing to the ledger | Posting, writing to the system of record | Software, and only after approval |
| Releasing payment | Outside the AI's job | A person, separate from whoever approved |
The pattern is simple. Let AI do the reading and the first pass at coding, where it is strongest and where a mistake is cheap to catch. Keep routing, posting and payment on rules and people, where a mistake is expensive and has to be explained later. The system of record, meaning the accounting system where your official numbers live, should only ever receive a bill that a person has approved.
There is plenty of work around AP where a general agent is the fastest option available, and it would be silly to pretend otherwise. A year-end cleanup of miscoded bills. A vendor statement that will not reconcile. A spend analysis by supplier that nobody has a report for. A first draft of a note to a vendor about a disputed charge. In each case a person reviews the output before anything touches the books.
Accounting firms are already doing this across client files, and it is a good use of the technology. If your business runs Business Central, Microsoft's Payables Agent is also a sensible way to turn emailed PDFs into drafts. The line to hold is the one between a task and a flow of money. A task has a start, an end and a reviewer. A flow of money repeats every week, involves people outside finance, and has to come out the same way every time.
Plenty of teams run both: payables in a purpose-built system, and a general agent on top for the analysis nobody built a screen for. If you are comparing the purpose-built side, we compared AP platforms on what their AI actually does. There is also a longer explainer on how AI in accounts payable works, stage by stage.
MakersHub puts the AI where it is strongest and the rules where they matter. WiseVision, the document AI inside MakersHub, reads the entire bill rather than just the header, pulling every line with its description, quantity and price. You can configure MakersHub by talking to it. Prompt WiseVision to code a bill, then ask it to save that decision as a rule it applies from then on. You set your coding rules once, and MakersHub applies them everywhere. That is the difference between a coding rule that holds for every bill after it and an agent that decides again each time.
From there the controls take over. Approvers use MakersHub without training. They approve from email in one click, and see only the bills that are theirs. Vendors never need a MakersHub login. Bills route by job, vendor, cost code, amount or entity, bill approval stays separate from payment authorization, and MakersHub is transparent about where every bill sits and who is holding it. Bills with a purchase order behind them are matched against the PO at the line before anyone is asked to approve them.
It connects to QuickBooks Online, QuickBooks Desktop, NetSuite, Sage Intacct, Xero and Intuit Enterprise Suite, with every integration built and maintained in-house, plus Smart Data Connect for other systems. There is no per-user pricing and no cap on bills, users or entities. Contractors, manufacturers, distributors, trades and multi-location operators run it directly, and the accounting firms serving them run it across clients. Accounting firms using MakersHub report getting a client configured in about an hour, with white glove onboarding included.
Cahill Construction had already built its own approval system in Smartsheet before it switched. With MakersHub it saves more than 64 hours a month on AP and reconciles credit cards in a day and a half instead of four.
"Most people think AI is just some computer wanting to take over the world. They’d be shocked to hear that we use AI right now—and that it works. It eliminated days of monotonous data entry that no one wanted to do and freed up our employees to engage in the kind of meaningful work they enjoy."
Trey Cahill, President, Cahill ConstructionAn AI agent for accounts payable is software that reads a bill, works out what it is, and takes the next step on its own rather than following a fixed script. Three kinds of product use the label. There are general-purpose agents like ChatGPT and Claude, and agents built into an accounting system, such as Microsoft's Payables Agent in Business Central. There is also AP software with AI built into a workflow that already has approvals, rules and an audit trail. MakersHub is an example of that third kind: its WiseVision AI reads and codes every line of a bill, while approvals, coding rules and the audit trail sit around it, and the approved bill syncs into QuickBooks Online, QuickBooks Desktop, NetSuite, Sage Intacct, Xero or Intuit Enterprise Suite.
They can do a lot of it. Given a PDF and your chart of accounts, both can extract every line, suggest a general ledger account for each, and flag lines that look wrong, and they are excellent for one-off cleanups and reconciliations. What they do not supply on their own are the controls: approval routing to people outside finance, the same coding on the same bill every time, an audit record of every action, and separation between approving and paying. That is why teams pair them with AP software such as MakersHub, which routes each bill to the right approver by job, vendor or amount, applies the same coding rules every time, logs every action, and keeps approval separate from payment.
For one-off tasks with a person reviewing the output, often yes. For the recurring flow of bills, not on its own. AP is a control process as much as a reading process. Routing, repeatable coding, an audit trail and segregation of duties are what purpose-built AP software exists to hold. Many teams use both: AP software for the payables, and a general agent for analysis on top. In MakersHub, for example, the AI reads the bill and proposes the coding, and rules and people handle routing, approval and payment.
It carries real risk, and the vendors say so. OpenAI's help center recommends enabling only the apps a task needs and avoiding open-ended instructions, and warns that an agent with access to email and accounts can take actions on your behalf. The safer design keeps reading bills and releasing payments as separate steps held by different people, so no document and no agent can move money alone. MakersHub keeps bill approval and payment authorization separate by design, and MakersHub is SOC 2 Type II certified.
Prompt injection is text hidden in a document, email or web page that an AI agent reads as an instruction. In AP, the risk is a vendor invoice carrying hidden text that tells an agent to change remittance details or approve a payment. NIST lists indirect prompt injection as its own class of attack on AI systems, and COSO's 2026 guidance names prompt-based manipulation among the new risks of generative AI. In MakersHub, text on a bill cannot approve it or release a payment, because both of those steps belong to people.
An AI agent is given a goal and decides the steps itself, which makes it flexible but means the same bill can be handled differently on different days. AP automation software runs bills through a defined workflow with approval routing, coding rules and an audit trail. The strongest AP platforms now use AI for reading and first-pass coding, then hand the result to rules and people for approval and payment. MakersHub works this way: WiseVision reads and codes each line, and rules and people take it from there.
MakersHub uses AI where it is strongest and rules where they matter. WiseVision reads every line of every bill and proposes the coding, and you can prompt it in plain language, then save that decision as a rule it applies from then on. Approval, posting and payment stay with rules and people, and bill approval is separate from payment authorization. MakersHub is SOC 2 Type II certified, with Positive Pay protection on check payments and encrypted collection of vendor bank details.
If your bills carry job, cost code or entity detail and you want to see where the AI stops and the controls start, run one of your own bills through MakersHub.
Sources: COSO, Achieving Effective Internal Control Over Generative AI (February 2026); NIST AI 100-2 E2025, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations; Microsoft Learn, FAQ for Payables Agent in Business Central; OpenAI Help Center, ChatGPT agent; Anthropic, Claude Cowork product page. Vendor capabilities reflect each company's own documentation as read in September 2026. The Cahill Construction figures and quote are from its published MakersHub customer story.
See how MakersHub can help your team eliminate manual entry, streamline approvals, and gain real-time visibility into every transaction.