Accountancy firms are rolling out AI agents that carry out audit tasks rather than merely assist with them. The technology is working, but the harder question is how to govern and evidence it. Meanwhile, European national regulators are moving to define what a trustworthy AI-supported audit looks like and how AI used by clients impacts the audit.
For as long as audits have existed, they have rested on a compromise: no one can check everything, so an auditor takes samples and judges everything else from that sampling. Artificial intelligence is now dissolving that constraint. Each year, EY’s global audit platform processes more than 1.4 trillion lines of journal-entry data, and in April 2026 part of that work was handed over to AI agents.
End-to-end, AI-integrated audit is past the pilot phase
Embedded directly into EY Canvas, the platform its assurance professionals use on some 160,000 audits a year, the agents are expected to support all end-to-end activities by 2028. EY is not alone: KPMG has built agents into its Clara audit platform, Deloitte’s agentic platform Zora launched in 2025, and PwC says an end-to-end, AI-integrated audit process will be in place for calendar 2026 audits. This is no longer a pilot phase.
‘Human-led, agent-operated’
What the tools change first is the method. ‘Our approach is evolving from an initial AI-first mindset to a fully data-driven audit that enables analysis of entire data populations instead of sampling, with the human firmly at the centre,’ says Sebastian Stöckle, global head of innovation and AI for audit at KPMG International. ‘The auditor’s role is moving from execution to steering, review and critical assessment. Professional judgment remains central.’
EY describes the same destination as a delivery model that is ‘human-led, agent-operated’, in the words of Paul Goodhew, the firm’s global assurance innovation and digital leader. In practice, its agents now can help assign tasks, raise review notes, initiate client requests and answer engagement questions with source references, while evidence-gathering and workpaper agents are due later in 2026.
‘Audit professionals decide whether AI insights are accurate and relevant’
Capabilities are tested and certified before release and monitored afterwards, including for ‘model drift’ (the tendency of a model’s behaviour to wander from its original performance). ‘AI can surface information faster,’ Goodhew says, ‘but audit professionals decide whether it is accurate, relevant and appropriate.’
Governance
However, there are two shifts under way at once, and they are easily conflated: auditors using AI to deliver audits, and auditors auditing the AI their clients deploy. As far as the first shift is concerned, the firms’ platforms are the product of years of investment and operate inside the profession’s quality management frameworks.
Auditing the AI deployed by clients is where the readiness gap lies. EY’s Global DNA of the CFO survey, published in June 2026, found 80% of CFOs expect AI-enabled business models to feature significantly or moderately in their organisations within a year. Grant Thornton’s 2026 AI Impact survey of nearly 1,000 senior US business leaders suggests governance is not keeping up: 78% lack full confidence their organisation could pass an independent AI governance audit within 90 days, and only one in five have tested a response plan for AI failures.
Governance is not the brake on AI value, it is the condition for it
‘AI deployment is simply outpacing the infrastructure that supports it,’ says Tom Puthiyamadam, managing partner of advisory services at Grant Thornton. Yet the same survey found well-governed AI adopters nearly four times more likely to report AI-driven revenue growth. Governance is not the brake on AI value, it is the condition for it.
Normalising AI audit
Nowhere is that being worked through more systematically than in the Netherlands. The country’s financial markets regulator AFM has made AI tooling in audits a supervision priority for 2026, and its December 2025 report, 12 building blocks for the controlled use of audit tooling, gives the sector a shared benchmark for governance, data quality and security as the technology scales.
Practitioners are matching that pace. For instance, Deloitte Netherlands has rolled out its AI tool, Headstart, across the practice with the aim of supporting virtually all statutory audits.
In Germany, the audit standard-setter IDW has issued PS 861, a standard for auditing AI systems, alongside guidance on the EU AI Act, and around 60% of German audit firms now have an AI competence centre. The audit regulator WPK published updated guidance on AI use in June 2026, and firms such as BDO market dedicated audit services for AI systems.
The use of AI in the audit process by businesses is being normalised not as a tool exemption but as something to be audited like any other system of internal control. Markets are shaping the global tools, with EY citing Germany and the Netherlands among the most active contributors to its transformation programme.
‘We anticipate audit pricing evolving from a traditional rate-per-hour model’
The growth market follows: firms are building assurance services over AI itself, from diagnostics and governance reviews to, in time, attestation and certification.
The economics may shift with the work. ‘We anticipate that the audit evolves from being priced with a traditional rate-per-hour model to models based on factors including risk, complexity, value and technology,’ Goodhew says. That clearly has implications for how firms sell, staff and measure the audit.
Staff impact
For auditors, the day-to-day work is already changing shape, and with it the skills. Audit teams, Stöckle argues, need stronger data and technology literacy, and above all the ability to critically challenge and validate AI outputs.
Junior staff will increasingly be reviewing machine-generated findings
The steepest learning curve belongs to junior members of staff, says Marc Welters, chair of the board of Norea, the Netherlands professional organisation for IT auditors. The data-heavy tasks that once trained junior staff – reconciliations, document review, population analysis – are the ones where AI lands first, so they will increasingly be reviewing and judging machine-generated findings rather than performing those procedures themselves. EY frames the same shift as a move ‘from repetitive execution toward judgment-led oversight’.
But as agents grow more autonomous, the issue becomes systemic, Welters argues. ‘The key question is no longer only whether an individual output is reliable, but whether the entire process is sufficiently controlled with adequate human oversight and validation.’