AI in your finance stack: July's Oracle changes, APRA's letter, and the KPMG lesson
1 August 2026 · 5 minute read
An enormous amount is happening where AI meets the finance-systems stack — Oracle's finance agents went generally available this quarter, APRA has put boards on notice, and two of the Big 4 have now published AI-hallucinated reports — but almost none of it is written up for the people who actually own the close. So here is the first of a regular briefing: four items, each with the "so what" for your environment. Five minutes, no fluff.
1. Oracle EPM July update: the GenAI cutoff is buried in the fine print
Oracle's July 2026 EPM Cloud update (26.07) carries a deadline that many teams will miss. Per Oracle's What's New: "Beginning in July 2026, Oracle will provide Generative AI functionality only for environments running the April (26.04) or later update. Environments that are not upgraded to 26.04 or later update by the end of July 2026 will lose access to Generative AI features." If your organisation defers updates — as many FCCS shops do around close periods — check where your pods sit before assuming the AI features in your roadmap deck still exist in your environment.
Also in 26.07: for Profitability and Cost Management users, individual rule editing disappears from the Rules Outline tab (Application > Calculation Rules) and the Waterfall tab (Models > Designer) — Rules Express Editing, Mass Edit and the Manage Rules screen keep full capability, so retrain anyone on your EPCM team who lives in the outline view. And in Account Reconciliation, Transaction Matching's default Reconciliation Status report becomes Match Metrics with additional metrics and a changed column order — check any downstream extract or reconciliation pack that scrapes that report by name before it silently breaks.
So what: two of these three changes break things quietly rather than loudly. Ten minutes with the What's New docs against your pod versions is the cheapest insurance you'll buy this month.
2. Fusion 26B: the finance agents are GA — now ask the configuration question
With Release 26B, Oracle moved four finance AI agents to general availability in Fusion Cloud ERP: Ledger, Expenses, Payables, and Payments (Oracle's agent documentation). The pitch is "touchless operations" — and 26B also lets you build multi-agent applications directly in AI Agent Studio.
Here is the question to ask before anyone enables these in production: what can each agent do on its own, and under which configuration? It's worth reading Oracle's descriptions at both levels side by side, because (as at 1 August 2026) they answer that question at different altitudes. The launch blog describes the Expenses Agent as a "touchless flow" that can "trigger reimbursement" without the employee "even logging into an application." The 26B What's New entry for the same agent states the expense is "marked as ready to submit (or will be auto-submitted if that option is enabled)" — autonomous submission is an opt-in profile option (EXM_AGENTIC_EMAIL_PROCESSING), not an inherent behaviour, with exceptions routed back to the employee. The Ledger Agent, per its What's New entry, is monitoring and inquiry only — no posting capability is documented. Same products, accurately described both times — but "touchless" and "opt-in, configuration-dependent" put very different lines in your controls documentation.
So what: an agent that prepares items for approval and an agent that submits transactions are different control environments. If 26B is landing in your environment, add one line to your control matrix per enabled agent: what can it write, under which profile options, and who approves. Check your own environment's configuration rather than relying on any description — including this one.
3. APRA's AI letter, translated: what your auditor will ask by Christmas
APRA's 30 April letter to all regulated entities is the first AI-specific statement of expectations for AU boards and accountable executives — and it reads like supervision, not guidance. Drawn from targeted reviews of large banks, insurers and super trustees, the headline observation is that governance, risk management, assurance and operational resilience are not keeping pace with AI adoption (MinterEllison's analysis; Clayton Utz calls it "a shift from framework to targeted expectations").
The practical minimums for anyone running AI inside finance systems, in APRA's own words: boards need the "technical literacy required to provide effective challenge on AI related risks"; executives are expected to maintain "an inventory of AI tooling and AI use cases"; and the letter calls out AI agents specifically — including that "identity and access management capabilities have not yet adjusted to nonhuman actors." That last line is aimed squarely at item 2: the ERP-embedded agents count, not just the chatbots. And the closing stance is not advisory — APRA says it will "take stronger supervisory action and, where appropriate, pursue enforcement."
So what: the AI inventory is the tractable first move — one page listing every AI capability live in your finance stack, what it can write, and who owns it. Item 2's control-matrix line is the same artefact. Start there before your internal auditor asks for it, because APRA has told them to.
4. Cautionary tale: KPMG's AI report became an AI-hallucination demo
In June, KPMG pulled its "Total Experience: Redefining Excellence in the Age of Agentic AI" study after UBS, the NHS, Swiss Federal Railways and Transport for London told the Financial Times that its claims about their AI usage were untrue or misleading — errors that AI-detection firm GPTZero traced to hallucinations. One example: the report described an Emirates "chatbot" that could change passenger flights; the real Sara is a 2023 robot assistant that can't. KPMG removed the report pending its own investigation.
It's not an isolated case: Deloitte partially refunded a AU$440k government contract in 2025 after a GPT-4o-drafted report shipped with fabricated citations and a made-up court quote, and EY Canada withdrew a study in May after most of its citations were found to be hallucinated.
So what: these are the firms selling AI-governance services, with review processes far heavier than most finance teams — and the errors still shipped. The lesson isn't "don't use AI"; all three failures share one shape: AI-generated content that crossed an organisational boundary without a named human owning its accuracy. That's the control. Every AI-drafted artefact that leaves your team — board pack, variance commentary, rec narrative — needs a human whose name is on it.
Has your EPM environment had an independent look since the agents arrived?
We run a fixed-price Oracle EPM Cloud health-check — two weeks, any module, A$10,000.
This briefing is curation and commentary, not original reporting — links go to primary sources wherever possible. It is general commentary as at the date above, not professional, legal or financial advice; product behaviour is configuration- and version-dependent, so verify anything here in your own environment and against the linked primary sources before acting on it. Product names and trademarks belong to their owners; quotes remain the property of the cited publishers. Spotted an error? Email us and we'll publish a correction.