AI Discoveries

Would You Give AI the Company Credit Card?

IT Club Editorial7 minutes read19 September 2026
WhatsAppEmail
Would You Give AI the Company Credit Card?

Keep up with IT Club

Add IT Club as a preferred source in Google Search.

AI agents may soon be able to buy services, reorder supplies and approve routine workflows. The practical question is not only whether an agent can spend money, but whether it is allowed to make the decision. Start with limited, visible and reviewable authority.

AI can already help you find things to buy. The next step is considerably more interesting: AI that can actually buy them for you.

Tell an AI agent to book a suitable hotel in Birmingham for Tuesday night, somewhere near the meeting and under £180. It researches the options, chooses one and makes the booking. In a business, you might ask it to reorder printer toner from an approved supplier. No employee opens the website, completes the checkout or necessarily approves that individual transaction.

That may sound like a shopping problem. It is really an authority problem.

The interesting bit is not the shopping

If somebody in your business has a company credit card, you probably put rules around it. There may be a spending limit, approved suppliers, categories they are allowed to purchase, transactions that need approval, receipts and an audit trail.

You do not usually give someone unrestricted access to the bank account and say: use your judgement. So why would you do that with an AI agent?

The plain-English question

Do not ask only whether the AI is allowed to spend £250. Ask whether it is allowed to make the decision that leads to the spending.

AI needs permissions too

The safer direction is limited authority rather than unrestricted payment details. A business might define an agent's permission like this:

  • Maximum spend: £250
  • Approved supplier: Microsoft
  • Purpose: software licence
  • Permission expires: Friday
  • Anything outside those rules: ask a human

The system should also keep a record showing what you authorised, what the agent considered and what it eventually bought. That record matters when somebody needs to understand an unexpected charge or decide whether the experiment should continue.

But staying within a £250 limit does not mean the agent made a good decision. It could still buy the wrong thing.

A limit does not make a decision good

Imagine telling an AI to find and book the cheapest suitable flight to Barcelona next Thursday. It finds one for £120. That sounds successful until you discover that it leaves at 05:40, requires three trains to reach the airport and includes no luggage.

Technically, the agent followed the instruction. Practically, you have a terrible flight.

The same problem can appear inside a business. An AI could stay within its purchasing authority while still:

  • buying the wrong licence
  • choosing an unsuitable supplier
  • agreeing to poor contract terms
  • duplicating something the business already owns
  • ordering too much stock
  • purchasing information that turns out to be useless

Permission is not judgement

A payment control can answer “was this amount allowed?” It cannot automatically answer “was this the right decision for the business?”

This is bigger than the company credit card

This matters even if you have no intention of letting an AI agent loose with your Barclaycard. AI systems are increasingly being designed to do things, not merely answer questions.

A business workflow could eventually look like this:

Access systems → change records → contact customers → create accounts → buy services → renew subscriptions → cancel services → approve workflows.

Every one of those actions involves authority. The relevant questions are not limited to money:

What authority does the agent actually have?

  • What systems can it access?
  • What records can it change?
  • What information can it send outside the business?
  • What can it spend or commit the business to?
  • What requires human approval?
  • Who reviews what it has done?
  • Can the business see exactly what happened afterwards?
  • Can somebody withdraw its authority immediately?

These are familiar IT and management questions. They are the same questions you ask about employee accounts, administrator access and suppliers with access to business systems.

Start small and make autonomy visible

None of this means businesses should avoid AI agents. An agent that reorders routine supplies, buys a small amount of approved research or renews an existing service could remove a lot of tedious administration.

The useful principle is that autonomy should be earned, limited and visible.

  1. 1Choose one clearly defined, low-consequence task.
  2. 2Limit the systems, suppliers and information the agent can reach.
  3. 3Set a spending or commitment limit and an expiry date.
  4. 4Keep a human approval step for unusual, expensive or difficult-to-reverse actions.
  5. 5Review the records and outcomes before giving the agent more authority.

A small business does not need a large AI governance department to begin. It does need a named person who understands the experiment, can inspect the result and can turn the authority off.

The IT Club view

The conversation about AI is moving beyond what information a tool can see. The more important question is what we are prepared to let it do.

The right response is not to make every action wait for a person. That would remove much of the benefit. It is to match the control to the consequence: more freedom for routine, reversible work; more scrutiny for actions that spend money, expose data, affect customers or create a commitment that is difficult to undo.

If you are setting rules for AI use in your business, the IT Club Knowledge Centre has more practical material on AI governance and safe adoption.

Explore the AI Governance Knowledge Centre

Want to talk through an AI workflow?

Describe the task, the systems the agent would need to access and what could go wrong if it made the wrong decision. The Ask the Advisor service can help you think through the boundaries before you automate it.

Ask the IT Club Advisor

Found this useful? Forward it to someone who might too.

Sources and further reading

This is original IT Club commentary based on the broader question of how AI agents may be given bounded authority to take actions. The background reading below is used for context only and is not reproduced here.

Background reading: Who Pays When AI Does The Shopping?

Plain-English Takeaway

AI authority should be earned, limited and visible. Set clear boundaries around what an agent can access, change, spend and approve, keep humans involved when the consequences matter, and review what the agent actually does.

Frequently asked questions

Should a small business let an AI agent make purchases?

Possibly, but start with a narrow, low-consequence task. Use approved suppliers, a fixed limit, a clear purpose, an expiry date and a human approval route for anything outside those rules.

Is a spending limit enough to control an AI agent?

No. A spending limit controls the amount, but not necessarily the quality of the decision. An agent could stay within budget while choosing the wrong licence, supplier, contract or quantity.

What should businesses review before giving an AI agent authority?

Review what the agent can access, change, spend and approve; who owns the decision; what needs human approval; what records are kept; and how its authority can be withdrawn quickly.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor