Who is liable when the agent makes the booking?

Title Page: Who Is Liable When the Agent Makes a Booking? AI Agents, the Board of Directors, and the Internal Control System

Share This Post

Several major providers of SME software are currently rolling out AI agents that read documents, suggest account assignments, post entries independently, and reconcile the results with bank transactions. To this end, one of them acquired a specialized Swiss company in the fall of 2025, whose solution had already been used by several thousand businesses and fiduciaries.

This isn't just a pipe dream or a conference slide. This is the software that Swiss SMEs use for accounting today—the Agent isn't a project, but an update.

This isn't a criticism of the providers. The agents are doing what they were designed to do, and they're doing it well.

The question is not whether agents are working in Swiss accounting firms. The question is who noticed it—and who is responsible for it.

Three out of four board members are kept in the dark

The swissVR Monitor regularly surveys board members from publicly traded companies and SMEs. In the survey on generative AI—which included 391 participants in May and June 2024—there is one figure that’s worth reading twice:

75 percent rarely or never receive regular reports on the use of AI within their own company.

The other figures support this. 55 percent of respondents rarely or never use AI applications themselves. Only 17 percent have all AI-generated content reviewed by a human. And 60 percent consider erroneous AI results to be the greatest risk—without having a reporting system that would show them whether such errors occur.

A body that identifies a risk but does not measure it does not have a risk problem. It has a supervisory problem.

This survey is from mid-2024. Anyone who argues that it is outdated is right—but not in the way they think. KPMG surveyed executives in March 2026, and that report contains a more up-to-date version of the same findings:

57 percent work with a person in the loop who reviews the result—but not the individual steps the agent took along the way.

That’s a difference that’s immediately apparent in accounting. Someone looks at the balance and finds it plausible. They don’t see how it was arrived at. For 91 percent of those surveyed, security and risk are the most important factors in their AI strategy—and yet oversight stops at the result.

There is one caveat: The KPMG figures are based on large U.S. companies. The general trend is correct, but the figures cannot be applied directly to a Swiss SME.

Why this cannot be delegated

Article 716a of the Swiss Code of Obligations lists the duties that the board of directors may neither delegate nor relinquish. Two of these are relevant here: the organization of accounting and financial control —and the overall supervision of the persons entrusted with the management of the company.

When an agent is granted write access to the accounting system, the ERP system, or the payment processing system, this constitutes a change to the internal control system. Not in a figurative sense, but quite literally: a control step that was previously performed by a person is being replaced.

Today, this change is usually decided by someone who isn't responsible for it—often by the person who set up the agent. Sometimes it never even appears on the agenda.

That is the real finding. It is not that agents are dangerous—but rather that jurisdiction has tacitly shifted.

The audit trail is telling a lie

There is a second point that sounds technical but isn't.

Most agents do not have their own identity in the systems in which they operate. They operate using the login credentials of a person—usually the one who set them up.

The log then says: “Ms. Meier made the reservation.” But Ms. Meier didn’t make the reservation. Three months ago, Ms. Meier set up an automation that has been running every night ever since.

This represents a breach of the separation of duties. Recording, approval, and control are suddenly back in the hands of a single entity—except that it’s no longer even a single entity, but an account. An audit firm that takes a close look will note this as a deficiency in the internal control system. And it will be right.

The solution is unspectacular and costs almost nothing: Each agent gets their own account.

Then the minutes will reflect what actually happened.

This is not just one person’s opinion. PwC summarizes this same idea in five points: Every agent needs a verifiable identity, a defined role, task-specific permissions, traceable activity logs, and clear boundaries for independent action. Furthermore, oversight must evolve as autonomy and scope increase.

A trustee reads in it the separation of duties, which he is already familiar with—only in the case of an actor who is not a human being.

Six months versus ten years

The transparency requirements of the EU AI Act have been in effect since August 2, 2026. Article 50 requires that people be informed when they are interacting with an AI system and that AI-generated content be labeled as such. Article 26 requires operators of high-risk systems to ensure human oversight, to monitor operations, and to retain logs for at least six months.

Six months.

Article 958f of the Swiss Code of Obligations requires that business records and accounting documents be retained for ten years and made available for inspection at any time.

When an agent makes a reservation, their log is part of the audit trail. It explains why a reservation was made in a particular way and not another. It is deleted after six months—but the reservation itself remains on record for nine and a half years.

No one has put these two figures together yet. You should do so before an auditor does.

Who the EU AI Act Actually Applies To in Switzerland

It's worth being precise here, because nonsense is being spread in both directions.

The EU AI Act does not apply to Swiss companies simply because they use AI. It applies to them if they place AI systems on the market or put them into service in the EU—or if the output is used in the EU. A fiduciary mandate for a Zurich-based craft business does not fall under this scope. A software product with German customers does.

Those affected should take a close look. Article 99 provides for fines of up to 15 million euros or 3 percent of global annual revenue for violations of operator and transparency obligations.

For SMEs and startups, the lower of the two figures explicitly applies. So with five million francs in revenue, we’re not talking about 15 million, but 150,000. That’s still a bit of a headache—but anyone who throws out the 15-million figure hasn’t read the paragraph all the way through.

There is no specific AI law in Switzerland itself. On February 12, 2025, the Federal Council decided to rely on existing legislation, targeted adjustments, and industry-specific solutions. The FDJP is drafting a consultation paper by the end of 2026—focusing on transparency, data protection, non-discrimination, and oversight—to implement the Council of Europe’s AI Convention.

So anyone waiting for a law that tells them what to do will have to wait a while longer. In the meantime, the Swiss Code of Obligations remains in effect without change.

The only rule you need

Michael Domanic, Head of AI at the continuing education provider Section, has developed a matrix for this that avoids technical jargon. Two questions: How much damage would be caused if things went wrong? And can it be undone?

In terms of financial processes:

What the Agent Does Damage Reversible Rule
Enter and Pre-Post Documents small Yes, via a adjusting entry run
Prepare the dunning run medium No — the email is with the customer have them produced, ship them by hand
Calculate VAT Return medium Yes, via a corrective statement Have it calculated, submit it by hand
Approve Payments large practically no Humans in a loop, without exception

The goal isn't to prevent every mistake. The goal is to make sure the first mistakes are inexpensive.

And the practical version for an SME with twenty employees—without a set of guidelines or an AI department—can be summed up in one sentence:

Grant write permissions only where a person can spot the error on the same day.

Four Questions for the Next Meeting

You don't need an AI strategy to get started. You need four answers:

  1. Which agents are running on our system—and since when?Not “let’s use AI,” but the list.
  2. Which one of them has write access to accounting, ERP, or payment processing?That's exactly where the experiment ends.
  3. Under whose account is he acting?If the answer is a person's name, the audit trail is incorrect.
  4. Who notices when they make a mistake—and how quickly?The answer to this question determines how much independence is appropriate.

If you ask these four questions at the board meeting and no one can answer them, you have your answer. It's the same as with the 75 percent.

The point is not to ban agents. They will remain in accounting because they handle a large portion of the work better and more cost-effectively than any manual data entry. The point is that someone must maintain oversight. This responsibility has not been newly regulated in the Swiss Code of Obligations because it has never been changed.

An agent can act. But he cannot be held accountable for anything.

If you can't answer the four questions above, that's not a failure—it's the norm. A consultation about this is free and non-binding.

Schedule an Initial Consultation

Sources

swissVR Monitor on Generative AI, swissVR in collaboration with Deloitte and the Lucerne University of Applied Sciences and Arts, 391 board members, survey conducted May 15 through June 27, 2024 · swissVR Monitor I/2026, 314 participants, published March 2, 2026 · KPMG, AI Quarterly Pulse Survey Q1 2026, published in March 2026 (executives from major U.S. companies) · PwC, Trust and Safety Outlook: AI Agent Governance for Workforce Use · EU AI Act, Articles 26, 50, and 99 · Swiss Code of Obligations, Articles 716a and 958f · Federal Council, Decision of February 12, 2025 · Michael Domanic, Section, “Developing an AI Agent Governance Strategy”