Wise Hustlers — Digital Product & App Development Studio Logo
Get Consultation
By Wise Hustler Admin9/1/202613 min read

Agentic AI in an Energy ERP: What Actually Works in 2026 and What Is Still a Promise

Agentic AI in an Energy ERP: What Actually Works in 2026 and What Is Still a Promise

# Agentic AI in an Energy ERP: What Actually Works in 2026 and What Is Still a Promise

TL;DR: in 2026, agentic AI is already good at extracting data from documents, classifying entries and suggesting the next action for a human to approve; it is not yet reliable for acting on its own on financial postings inside an ERP — and in Angola, with the AGT and the ANPG requiring traceability and certification, that distinction has concrete legal consequences.

A sector full of forecasts — and few measurements

It is worth starting with the numbers: most of what circulates about "AI agents in the enterprise" is vendor promise dressed up as market statistic.

Gartner predicts that by the end of 2026, 40% of enterprise applications will include task-specific AI agents, up from less than 5% in 2025 — a forecast, not a measurement, and one that refers to agents embedded in applications for specific tasks, not to autonomous agents running an entire business [Gartner, Aug. 26, 2025].

The same analyst firm, a month earlier, published the mirror-image prediction: over 40% of agentic AI projects will be canceled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls. Gartner further estimates that only about 130 of the thousands of vendors marketing themselves as "agentic AI" have genuine agentic capabilities — the rest is rebranded chatbots and RPA, a pattern it calls "agent washing" [Gartner, June 25, 2025].

For a primary source on actual adoption rather than stated intent, there is MIT's Project NANDA report, "The GenAI Divide: State of AI in Business 2025," produced by MIT's own research team, not by a vendor with a product to sell. Drawing on 300 publicly disclosed AI initiatives, structured interviews with 52 organizations and a survey of 153 senior leaders, the report finds that 95% of generative AI pilots produce no measurable impact on company financial results, despite an estimated $30–40 billion in enterprise investment. The 5% that do work share a common pattern: buying specialized tools and integrating them deeply into an existing process, rather than building something generic in-house [MIT NANDA, July 2025].

These three numbers — 40% predicted adoption, 40% predicted cancellation, 95% with no measured return — do not contradict each other. They describe the same phenomenon: high adoption, low transformation. It is exactly the pattern visible from inside an energy ERP: plenty of people connecting an agent to something, and far fewer managing to get that agent to move a number on the income statement in a defensible way.

What already works: extraction, classification, suggestion with human approval

The useful distinction is not "AI yes or no." It is where the agent's action ends and the human decision begins — and that boundary gets drawn module by module, not in the abstract.

Document extraction. Reading a supplier invoice, a delivery note, an ANPG certificate or an HSE inspection report — as a PDF or a photograph — and turning it into structured fields (vendor, amount, tax ID, date, line items) is a solved problem today, at good accuracy. It is also the area where the large ERP vendors invest most visibly: SAP describes its Joule Invoicing Assistant as extracting invoice data from PDFs and images and validating it before any posting [SAP], and Oracle made dedicated Ledger, Expenses, Payables and Payments agents generally available in its 26B release within Fusion Cloud [Oracle, Apr. 9, 2026].

Classification and reconciliation. Matching an invoice to a purchase order and a goods receipt note (three-way match), coding a cost to the correct general-ledger account, or allocating an expense across the partners of a Joint Interest Billing per the Joint Operating Agreement — these are classification tasks with known rules, where an agent reduces repetitive work without having to "decide" anything irreversible. Quorum Software, a specialist upstream software vendor, describes exactly this kind of capability in its extraction of unstructured operational and contractual data into structured system fields [Quorum Software].

Suggestion with human approval. This is the most mature pattern and, honestly, the most underrated: the agent proposes — a payment action, a reorder of MRO spare-parts stock, a maintenance plan — and a person with delegated authority approves, adjusts or rejects it. IFS, focused on asset-intensive industries, describes its "digital workers" (the Loops brand, following the TheLoops acquisition) as able to recommend maintenance strategies and generate work orders, while keeping the higher-impact decisions inside a human approval loop [IFS, ERP Today].

What these three categories share: they are reversible, auditable field by field, and an agent's mistake costs minutes of correction — not a tax refiling with the AGT.

What is still a promise: autonomous action on financial postings

The widest gap between vendor messaging and production practice is autonomous action on financial postings — an agent that books a journal entry, approves a payment, or files a tax return without prior human review.

It is not for lack of vendor ambition: SAP itself describes its Invoicing Assistant as orchestrating "end-to-end processing with minimal human input" [SAP], and Oracle presents its Fusion Agentic Applications as a set of coordinated agents that "reason, decide, and execute" within existing security and approval frameworks [Oracle, Apr. 9, 2026]. Notice the phrasing: "within existing approval frameworks" — the autonomy is about orchestrating the process, not eliminating human control at the point of posting.

It is the gap the MIT NANDA report measures indirectly: if 95% of generative AI pilots produce no measurable financial-result impact, the most cited cause is not model quality — it is shallow integration and a failure to adapt to the company's actual process, exactly the kind of engineering work (mapping authorizations, approval limits, segregation of duties) that autonomous financial action requires, and that is rarely done by the time a pilot launches.

The practical reason for not fully automating this layer is not generic distrust of AI — it is that an incorrect journal entry, once reconciled, reported to a JIB partner, or submitted to the tax authority, has a far higher cost to reverse than the cost of keeping a human approval step in the path.

Angola: where agentic AI meets the AGT and the ANPG

Not an abstract argument in Angola — two concrete regimes make "suggesting" versus "acting" legally relevant.

Presidential Decree No. 71/25, of March 20, 2025, came into force on September 20, 2025 and, after a transitional period, made the issuance and reporting of electronic invoices to the Administração Geral Tributária (AGT), Angola's tax authority, mandatory from January 1, 2026. The first phase covers large taxpayers, State suppliers, and taxpayers issuing invoices of 25,000,000 AOA or more, and requires that the billing software used be certified or validated by the AGT. The same decree covers the SAF-T (AO) accounting file submission, due in 2026 covering 2025 data [EY Angola]. Angola's standard VAT rate, 14% since its introduction in 2019, applies to the general run of transactions covered by this regime [Portal do Contribuinte, AGT].

In this chain, an AI agent can do a lot of useful work without touching the final decision: pre-validating that an invoice's fields are complete, flagging discrepancies against the delivery note, preparing the SAF-T file for review. What makes no sense — neither technically nor legally — is letting an agent submit directly to the AGT without a tax officer confirming it, because the decree carries enhanced penalties for non-compliance, and that liability sits with the company, not with the software vendor.

The second regime is the oil sector's Local Content regime, set out in Presidential Decree No. 271/20, of October 20, 2020, which requires companies providing services to the sector to register and be certified with the Agência Nacional de Petróleo, Gás e Biocombustíveis (ANPG) before they can bid on contracts published by operators and concession associates [ANPG — Local Content]. An agent can help prepare and organize the documentation for a Local Content Plan, or check whether suppliers on a bid list hold valid certification — but the decision to submit a certification dossier, or to classify a company as eligible under an exclusivity or preference regime, carries direct legal consequence, including administrative fines ranging from $50,000 to $300,000 per infraction. It is not the kind of decision to leave unreviewed just because the model "sounds confident."

Why an agent with write access needs the same access control as a person

Here is the central engineering point of this piece, and it is simpler than the usual "AI governance" conversation suggests: an agent with permission to write to an ERP — post a journal entry, approve a requisition, change a vendor record — has exactly the same blast radius as a human user with those same permissions. Being a language model instead of a person does not reduce the possible harm; it often increases it, because the agent acts faster and at higher volume than any person would across a single shift.

The OWASP Gen AI Security Project formalized this in its risk list for agentic applications: the "Excessive Agency" category (LLM06) breaks the risk into three causes — excessive functionality (the agent can reach tools outside the scope of its task), excessive permissions (the tools it can reach operate with broader privileges than the task requires), and excessive autonomy (high-impact actions proceed without a human in the loop) [OWASP Gen AI Security Project]. None of these three causes is unique to AI agents — they are exactly the same questions any systems auditor asks about a human user account in an ERP: does it have access only to what it needs? Are approval limits respected? Is there segregation of duties between whoever proposes an action and whoever approves it?

In a well-designed ERP, access control already exists as a layer: roles, value-based approval limits, segregation of duties between whoever creates a requisition and whoever approves it, a per-action audit log. The correct way to introduce an agent is not to hand it an API key with administrator privileges "so it can get the job done" — it is to treat it as one more actor inside that same RBAC model, with its own role, its own limits, and every one of its actions landing in the same audit trail as a human action, identifiable as such. That is permissions-architecture work, not a choice of AI model, and it is the part of the project most often missing when an agentic AI pilot never reaches production — which is precisely what the MIT NANDA data suggests is happening in 95% of cases.

This is the kind of work — mapping real ERP processes, defining where an agent can act versus where it can only suggest, and wiring that into the permissions layer that already exists — that we deliver in the applied AI and intelligent automation projects we run for operators and service companies in the energy sector.

SAP, Oracle, IFS, Quorum — and where custom engineering fits in

None of these vendors is interchangeable, and none solves Angolan compliance on its own.

VendorWhere it is strongWhere it falls short
SAP (Joule)Finance and procurement, strong at invoice extraction and per-module assistants [SAP]Sized for large operators; little native adaptation to AGT/SAF-T (AO)
Oracle Fusion600+ pre-built agents across Financials, SCM and Procurement; Payables/Payments already GA [Oracle]Same local-adaptation gap; needs integration for specific tax regimes
IFSAsset-intensive industries — maintenance, EAM, "digital workers" for field ops [IFS]Less oriented toward the financial/tax core
Quorum SoftwareUpstream specialist — measurement, JIB, logistics — native operational extraction [Quorum]Narrower coverage outside upstream; less established presence in Angola
Custom build (e.g. Wise Hustlers)Direct mapping to local processes and obligations (AGT, SAF-T, ANPG)Requires dedicated engineering work, not an off-the-shelf license

For a global-scale operator, one of the first three vendors is usually the right starting point. For an Angolan service company with an ERP already in production and specific AGT and ANPG obligations, the more honest question is not "which of these agents do I buy" — it is "where does already-automatable extraction and classification connect to my actual approval process, without blindly trusting an autonomous action nobody has yet proven safe at scale."

Frequently asked questions

Can agentic AI already replace an accountant or a tax officer in Angola?

No, and that is not what ERP vendors themselves are promising for 2026 either — the agents available today extract, classify and suggest; submitting invoices to the AGT, filing the SAF-T (AO) file, or a certification dossier to the ANPG still requires human sign-off, not least because legal liability and fines fall on the company, not on the software vendor.

Does an AI agent really need the same controlled access as an employee?

Yes. If an agent has permission to write to a financial module, it has the same capacity to cause harm as a person with those permissions — sometimes greater, because it acts faster and at higher volume. The OWASP Gen AI Security Project treats this as a core risk ("Excessive Agency") in its guidance for agentic applications.

Is it worth waiting a few more years before investing in agentic AI in the ERP?

Not in the categories that already work — document extraction and classification already save real time today, at low risk because they remain reversible and auditable. It is worth waiting, or at least being cautious, only in the category of autonomous action on financial postings, where even the largest vendors keep a human in the loop by design.

Sources