Would You Give AI the Company Credit Card?

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
AI agents may soon be able to buy services, reorder supplies and approve routine workflows. The practical question is not only whether an agent can spend money, but whether it is allowed to make the decision. Start with limited, visible and reviewable authority.
AI can already help you find things to buy. The next step is considerably more interesting: AI that can actually buy them for you.
Tell an AI agent to book a suitable hotel in Birmingham for Tuesday night, somewhere near the meeting and under £180. It researches the options, chooses one and makes the booking. In a business, you might ask it to reorder printer toner from an approved supplier. No employee opens the website, completes the checkout or necessarily approves that individual transaction.
That may sound like a shopping problem. It is really an authority problem.
The interesting bit is not the shopping
If somebody in your business has a company credit card, you probably put rules around it. There may be a spending limit, approved suppliers, categories they are allowed to purchase, transactions that need approval, receipts and an audit trail.
You do not usually give someone unrestricted access to the bank account and say: use your judgement. So why would you do that with an AI agent?
The plain-English question
Do not ask only whether the AI is allowed to spend £250. Ask whether it is allowed to make the decision that leads to the spending.
AI needs permissions too
The safer direction is limited authority rather than unrestricted payment details. A business might define an agent's permission like this:
- Maximum spend: £250
- Approved supplier: Microsoft
- Purpose: software licence
- Permission expires: Friday
- Anything outside those rules: ask a human
The system should also keep a record showing what you authorised, what the agent considered and what it eventually bought. That record matters when somebody needs to understand an unexpected charge or decide whether the experiment should continue.
But staying within a £250 limit does not mean the agent made a good decision. It could still buy the wrong thing.
A limit does not make a decision good
Imagine telling an AI to find and book the cheapest suitable flight to Barcelona next Thursday. It finds one for £120. That sounds successful until you discover that it leaves at 05:40, requires three trains to reach the airport and includes no luggage.
Technically, the agent followed the instruction. Practically, you have a terrible flight.
The same problem can appear inside a business. An AI could stay within its purchasing authority while still:
- buying the wrong licence
- choosing an unsuitable supplier
- agreeing to poor contract terms
- duplicating something the business already owns
- ordering too much stock
- purchasing information that turns out to be useless
Permission is not judgement
A payment control can answer “was this amount allowed?” It cannot automatically answer “was this the right decision for the business?”
This is bigger than the company credit card
This matters even if you have no intention of letting an AI agent loose with your Barclaycard. AI systems are increasingly being designed to do things, not merely answer questions.
A business workflow could eventually look like this:
Access systems → change records → contact customers → create accounts → buy services → renew subscriptions → cancel services → approve workflows.
Every one of those actions involves authority. The relevant questions are not limited to money:
What authority does the agent actually have?
- What systems can it access?
- What records can it change?
- What information can it send outside the business?
- What can it spend or commit the business to?
- What requires human approval?
- Who reviews what it has done?
- Can the business see exactly what happened afterwards?
- Can somebody withdraw its authority immediately?
These are familiar IT and management questions. They are the same questions you ask about employee accounts, administrator access and suppliers with access to business systems.
Start small and make autonomy visible
None of this means businesses should avoid AI agents. An agent that reorders routine supplies, buys a small amount of approved research or renews an existing service could remove a lot of tedious administration.
The useful principle is that autonomy should be earned, limited and visible.
- 1Choose one clearly defined, low-consequence task.
- 2Limit the systems, suppliers and information the agent can reach.
- 3Set a spending or commitment limit and an expiry date.
- 4Keep a human approval step for unusual, expensive or difficult-to-reverse actions.
- 5Review the records and outcomes before giving the agent more authority.
A small business does not need a large AI governance department to begin. It does need a named person who understands the experiment, can inspect the result and can turn the authority off.
The IT Club view
The conversation about AI is moving beyond what information a tool can see. The more important question is what we are prepared to let it do.
The right response is not to make every action wait for a person. That would remove much of the benefit. It is to match the control to the consequence: more freedom for routine, reversible work; more scrutiny for actions that spend money, expose data, affect customers or create a commitment that is difficult to undo.
If you are setting rules for AI use in your business, the IT Club Knowledge Centre has more practical material on AI governance and safe adoption.
Explore the AI Governance Knowledge Centre →
Want to talk through an AI workflow?
Describe the task, the systems the agent would need to access and what could go wrong if it made the wrong decision. The Ask the Advisor service can help you think through the boundaries before you automate it.
Found this useful? Forward it to someone who might too.
Sources and further reading
This is original IT Club commentary based on the broader question of how AI agents may be given bounded authority to take actions. The background reading below is used for context only and is not reproduced here.
Plain-English Takeaway
AI authority should be earned, limited and visible. Set clear boundaries around what an agent can access, change, spend and approve, keep humans involved when the consequences matter, and review what the agent actually does.
Frequently asked questions
Should a small business let an AI agent make purchases?
Possibly, but start with a narrow, low-consequence task. Use approved suppliers, a fixed limit, a clear purpose, an expiry date and a human approval route for anything outside those rules.
Is a spending limit enough to control an AI agent?
No. A spending limit controls the amount, but not necessarily the quality of the decision. An agent could stay within budget while choosing the wrong licence, supplier, contract or quantity.
What should businesses review before giving an AI agent authority?
Review what the agent can access, change, spend and approve; who owns the decision; what needs human approval; what records are kept; and how its authority can be withdrawn quickly.
Related Articles
AI Just Spent 88 Hours Solving a Problem Humans Have Wrestled With for Decades. So What?
The important story is not only the mathematical result. It is the shift from asking AI for information to giving AI systems complex problems to investigate.
Read articleShould Children Learn to Think Before They Learn to Use AI?
New York is restricting generative AI for younger pupils. The bigger question is whether people need to develop core skills before AI starts doing part of the thinking for them.
Read articleAI Needs Data Centres. But Who Should Pay for Them?
AI may feel like software, but it depends on very physical infrastructure. Who should pay for the electricity, water and grid investment behind the AI boom?
Read article