Our recommendation: Adopt AI through your platform’s native capability, and connect it properly
Almost every finance leader we speak to is being asked the same question by their board: what are we doing about AI?
For most organisations, the honest answer starts with a different question – not what AI can do, but how it is connected to your data.
The pattern we’d steer you away from
A finance team wants faster analysis. Someone opens a general-purpose chatbot, pastes in a management pack, a customer list or a ledger extract, and asks it questions. The answers are impressive. The habit spreads quietly, because it works.
This now has a name – shadow AI – and a price tag. IBM’s Cost of a Data Breach Report 2025 found that one in five organisations studied experienced breaches linked to shadow AI, meaning unsanctioned AI tools adopted by employees without IT or security oversight. Those incidents added as much as USD 670,000 to the average breach cost, and disproportionately exposed customer personally identifiable information and intellectual property. Customer PII was compromised in 53% of breaches overall, but in shadow AI those breaches rose to nearly two-thirds.
The instinct behind it, though, is not wrong. IBM makes the point directly: shadow AI is a cultural problem as much as a technical one – employees are under pressure to adopt tools that make their jobs easier, and without guidance they can inadvertently bypass security protocols.
Ban it outright and it moves onto personal devices, which is worse. Better to channel the instinct somewhere safer, and that somewhere is already inside the platforms you own.
Start with native AI
The finance platforms we work with are embedding AI directly into the product: predictive forecasting, anomaly detection, automated narrative reporting, scenario modelling.
Because these capabilities run inside the platform:
- Your data stays within an environment you have already contracted, governed and secured
- The model works with structured, validated finance data – not a pasted extract stripped of its context
- Results reflect your actual chart of accounts, hierarchies and business rules
- Permissions follow your existing user model
- Output lands where the work happens, not in a chat window someone must re-key
Our recommendation: Exhaust what your platform does natively before looking anywhere else. It usually covers more ground than teams realise – much of it already paid for. Ask each vendor a simple question: what AI capability sits in our current licence, and what would it take to switch on?
When you do connect, use MCP
Sometimes you genuinely need to connect an assistant across systems – pulling data from platforms that don’t talk to each other or applying a capability your vendor doesn’t offer. Then the connection method matters enormously.
MCP, the Model Context Protocol, is an open standard for connecting AI applications to external systems. Rather than pasting data into a chat window or building brittle one-off connections, it defines a structured, permissioned way for an assistant to request exactly what it needs.
It is also no longer a single vendor’s project. Originally developed by Anthropic, MCP was donated in December 2025 to the Agentic AI Foundation, a directed fund under the Linux Foundation, co-founded by Anthropic, Block and OpenAI with support from Google, Microsoft, AWS, Cloudflare and Bloomberg. There are now more than 10,000 actives public MCP servers, and the standard has been adopted by ChatGPT, Gemini, Microsoft Copilot, Cursor and Visual Studio Code. OpenAI adopted it across its products in March 2025 – a competitor backing a rival’s standard, which tells you something about its durability.
For a finance function, that means:
- Data stays put: In its source system, not copied into a chat window
- Access is scoped: An assistant sees only what it should
- Connections are reusable: Standardised rather than bespoke and fragile
- Everything is traceable: A record of what was accessed, and when
- Nothing is locked in: Vendor-neutral governance survives a change of supplier
This is the same discipline you’d apply to any system connecting to your ledger. It simply hasn’t been applied consistently to AI yet, because the technology arrived faster than the governance around it.
The constraint is rarely the AI
When AI underdelivers in finance, the model is almost never the problem. Fragmentation is. The 2025 FP&A Trends Survey found that only 11% of organisations have fully aligned strategic, financial and operational planning, only 17% rate their data quality as good, and 46% of FP&A time still goes on collecting and validating data rather than analysing it.
Point an intelligent tool at that and you don’t get insight, you get confident-sounding answers built on inconsistent inputs, which is more dangerous than no answer at all.
Where to start
- Audit what you already have. Ask your vendors what AI is included in your current licence.
- Agree a position on general-purpose tools. Most organisations write theirs after something has already gone into a chatbot.
- Fix the data foundations. Fragmented sources cap the value of any AI you deploy.
- Plan for adoption from day one. A capability nobody trusts is one nobody uses, and that returns nothing, regardless of cost.
AI is only as good as the connected, accurate data feeding it. Get the foundations right and the capability follows.
Unsure where AI fits in your finance function? Schedule a complimentary call with a Verostone consultant here.
For more information you can call us on +44 (0)1932 548 465, or email us at hello@verostone.com.
