Leadership · 4 minute read
Agentic AI for Public Company Executives
Public company executives should keep AI claims disciplined and supportable, extend internal control over financial reporting to agents acting in finance processes, give investors a narrative backed by measured results, and report to the board on a fixed cadence. This is general guidance, not legal or accounting advice.
Public companies face AI questions from four directions at once: investors asking what it does for earnings, auditors asking about controls, regulators asking whether claims are accurate, and boards asking whether anyone is in charge. The answers have to be consistent, because they are compared. This guide covers disclosure discipline, controls, the investor narrative, and board reporting. It is general guidance, not legal or accounting advice.
Why is disclosure discipline the first issue?
Because exaggerated AI claims have attracted regulatory attention in several jurisdictions, and because inconsistency between the investor narrative and internal reality is discoverable. The discipline is simple to state and hard to maintain under pressure: public claims should be specific, supportable by evidence management actually reviews, and consistent across channels.
| Claim type | Risky version | Supportable version |
|---|---|---|
| Adoption | "AI-powered across the enterprise" | "Agents in production in three processes, named" |
| Results | "Significant efficiency gains" | "Cost per task in claims intake down against a measured baseline" |
| Capability | "Our AI predicts customer behavior" | "A model supports prioritization; humans decide" |
| Roadmap | "AI will transform our margins" | "Two committed outcomes with production dates" |
The rule that keeps companies safe: do not say publicly what your monthly management review would not support. The how to brief investors on AI guide covers the narrative construction.
How do agents interact with internal control over financial reporting?
Where an agent acts in a process feeding the financial statements (invoice processing, revenue transactions, reconciliations, accruals support), the related controls fall within scope. Practically, that means:
- Access and authorization: the agent has its own identity with least privilege, and its permissions are reviewed like any user's.
- Segregation of duties: the agent that prepares does not also approve; thresholds are enforced.
- Completeness and accuracy: controls over the agent's processing, with evidence.
- Audit trail: every action recorded with inputs, outputs, and reviewer.
- Change management: prompts, tools, and model versions under change control, including provider-initiated model updates.
Involve internal audit and the external auditors early. Discovering at year-end that an agent has been posting entries without documented controls is an expensive conversation. The CFO's guide to AI and agentic AI covers the finance controls; the AI guide for internal audit leaders covers the assurance side.
What do investors actually ask?
What is in production rather than planned; the measured effect on cost, cycle time, or revenue; the run cost; the risks and dependencies, particularly on a single model provider; and how it changes competitive position. Roadmaps without results are increasingly discounted, and analysts have learned to ask for the baseline. Companies that can answer with specific numbers on named processes differentiate themselves simply by being concrete. The AI value realization whitepaper covers producing evidence that survives scrutiny.
When does an AI matter become disclosable?
When it meets the company's materiality threshold or triggers a specific obligation, such as cybersecurity incident reporting rules where an agent-related breach qualifies. Two preparations matter: decide the assessment process in advance with counsel so the judgment is not improvised during an incident, and ensure the incident response produces the facts the assessment needs (scope, affected parties, timing, remediation) quickly. The what executives should do in the first hour of an AI incident guide covers the response sequence.
What should the board receive?
A consistent quarterly report derived from management's own review, not prepared separately: inventory by risk tier, outcomes against baselines, evaluation evidence for material systems, incidents and remediation, vendor concentration and exit readiness, regulatory developments mapped to the inventory, and control status. Material matters escalate immediately. The board director's guide to AI and agentic AI describes what directors should expect; the AI oversight and fiduciary duty piece covers why the records matter.
What governance does a public company need?
The standard structure, with more documentation: a named accountable executive; an inventory with risk tiers; a written risk appetite; evaluation as a release gate; monitoring; incident procedures with a disclosure assessment step; vendor management with concentration limits; and mapping to a recognized framework such as NIST AI RMF or ISO/IEC 42001 so auditors and regulators recognize the shape. The executive guide to AI agent governance describes it.
What should public company executives ask?
- Would our last investor statement about AI survive comparison with our internal review?
- Which agents touch financial reporting processes, and have the auditors seen the controls?
- What is our disclosure assessment process for an AI incident, and who runs it?
- What measured results could we put in the next earnings call, with baselines?
- Does the board see the same numbers management reviews?
How can FISTA Solutions help public companies?
FISTA Solutions builds AI agents with the identity, segregation, audit trail, and change controls that financial reporting scope requires, and works with executives through its AI enablement practice on governance, evidence production, and board and investor reporting derived from management's own review. Since 2017, FISTA has delivered 150+ projects for 50+ companies across 12+ countries, with a 99.9% uptime record on production systems.
To prepare evidence your auditors and investors will accept, talk to FISTA on WhatsApp, or read how to report AI progress to the board.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01What disclosure risks come with AI claims?
Overstating AI capability or adoption in public statements has attracted regulatory enforcement in several jurisdictions. Claims should be specific, supportable by evidence, and consistent with what management reviews internally. Avoid describing pilots as deployments or research as products. Consult securities counsel; this is general guidance, not legal advice.
02Do AI agents fall within internal control over financial reporting?
Where agents act in processes that feed the financial statements, the related controls fall within scope: access and authorization, segregation of duties, completeness and accuracy of processing, audit trails, and change management. Involve internal audit and external auditors early rather than at year-end.
03What do investors ask public companies about AI?
What is in production rather than planned; what measurable effect it has had on cost, cycle time, or revenue; what it costs to run; what the risks and dependencies are; and how it changes the competitive position. Roadmaps without measured results are increasingly discounted.
04When is an AI incident disclosable?
When it meets the company's materiality threshold or triggers specific reporting obligations, such as cybersecurity incident rules where an agent-related breach qualifies. Decide the assessment process in advance with counsel, so the judgment is not made under time pressure during the incident.
05What should a public company board receive about AI?
A consistent quarterly report derived from management's own review: inventory by risk tier, outcomes against baselines, evaluation evidence, incidents and remediation, vendor concentration, regulatory developments, and control status, with material matters escalated immediately rather than held for the cycle.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.