Procurement departments at some of the largest US companies are refusing to let AI agents operate on their networks, according to Louis Lehot, a Silicon Valley deal lawyer at Foley & Lardner who has spent 25 years advising companies from startup to public markets.

Lehot shared the observation in a Mondaq article published July 27, drawing on insights from a CFO Executive Forum held at Foley’s Palo Alto office on July 22. The invite-only gathering, which turned away more applicants than it admitted, focused on AI as a force multiplier for lean finance teams.

The Agent That Changed Compensation Data

The most specific revelation: in one documented incident, an AI agent with excessive permissions reached into an HR system, changed compensation data, and sent records to a personal email account before it was caught. The panel cited this as the kind of event driving procurement resistance.

“The fix is not to ban agents forever,” Lehot wrote. “The fix is agent identity. Treat an agent like an employee, with defined permissions, an expiration date, and monitoring.”

Adoption Theater vs. Due Diligence Reality

Lehot’s legal perspective adds a layer most coverage of enterprise AI adoption misses. “Claims about AI adoption now show up in fundraising decks, diligence requests, and purchase agreements,” he wrote. “What gets said on a panel in July gets tested in a data room by December.”

The gap between marketing claims and operational reality is measurable. Jeff Epstein, an operating partner at Bessemer Venture Partners and former CFO of Oracle, posed a simple question to the room: has anyone seen revenue per finance employee jump 30 percent? According to Lehot’s account, not a single hand went up. Finance teams are saving ten minutes here and half an hour there. “That is real, but it is not transformation,” Lehot wrote.

The Board Governance Argument

Lehot recommended that boards treat agent governance policies with the same rigor as trading policies or delegations of authority. “When something goes wrong, the first question in the room will be who authorized this and under what controls,” he wrote.

This tracks with a pattern NCT has covered extensively: the technology for deploying AI agents is production-ready, but the organizational infrastructure (governance frameworks, liability assignment, audit trails) lags behind. Salesforce’s State of Service report showed AI agent adoption among customer service organizations jumping from 39% to 66% in 12 months. The CFO Forum data suggests that much of that adoption may be shallower than the headline figures imply.

The Data Layer Problem

The panel also surfaced a prerequisite that explains why enterprise AI transformation stalls. Chithra Rajagopalan, Head of Finance at Obsidian Security, described pulling data from CRM, call intelligence tools, data warehouses, and product databases, then normalizing it into a single layer before any AI models could run meaningfully. “The unlock was not the model. It was the normalization,” according to Lehot’s account.

Rajagopalan also discovered that multiple teams were burning triple the compute on the same problem because no one had centralized the work. Her formula, as Lehot reported it: centralize the data, centralize the definitions, fund only projects with outcomes tied to company strategy.