This page was originally written in Indonesian. This English version was translated automatically using machine translation (AI/Google engine) and may contain contextual inaccuracies. View the original Indonesian version.

AI at the Corporate Table

Infografik panduan etika dan tata kelola kecerdasan buatan untuk akuntan dan direksi korporat

Author's note. Most of the illustrations in this piece draw on Continuing Professional Education (PPL) material from the Indonesian Institute of Accountants, themed “The Code of Ethics for Indonesian Accountants and Technology Ethics for Business Accountants,” which I attended on 30 July 2026. The two main case studies I use here involve incidents at Deloitte and Samsung.

Picture a finance manager receiving a forecasting model's output for next quarter's sales growth. The number looks optimistic, 18 percent, with high confidence because the calculation follows the pattern of the past three years. But conditions on the ground tell a different story: new orders are slowing, churn is rising, and the market is going through major shifts. Even so, the manager wants to stick with that 18 percent figure, for a simple reason: the model has already read all the available data. This is exactly the kind of bet AI governance faces in corporate finance.

This illustration came up in an Indonesian Institute of Accountants technology ethics training session. I open with it deliberately, because it feels close to the experience of anyone who has sat at a corporate decision-making table. Pressure to hit targets, over-trust in numbers that look precise, and the temptation to stop asking questions once the result matches expectations, these are all familiar. Artificial intelligence did not create that temptation. It just makes it faster.

To keep this from being just a hypothetical illustration, I looked into real incidents that have already happened. The two most relevant cases, it turns out, come from two completely different ends of the spectrum. The first involves a Big Four firm that should itself be a reference point for AI governance. The second comes from a technology conglomerate, where the data leak actually started from an employee's good intentions.

The Case That Tripped Up Deloitte

In October 2025, Deloitte Australia was forced to refund part of the AU$440,000 (about US$290,000, or roughly Rp4.6 billion) paid by Australia's Department of Employment and Workplace Relations. The funds were originally meant to produce a 237-page assessment report on the welfare compliance framework.

The problem surfaced not from Deloitte's internal audit but from Chris Rudge, a welfare law researcher at the University of Sydney. While reading the report, he found a citation to a book supposedly written by Lisa Burton Crawford, a professor of public and constitutional law at his own university. The trouble was, the book did not exist at all. Rudge told the Associated Press that he immediately recognized it as an AI hallucination because the title sounded made up.

Further digging showed the report contained 12 fictitious references attributed to the same professor. There were also two references to reports by a Swedish professor who likewise did not exist, plus a direct quote attributed to a federal court judge who never actually said it. A revised version Deloitte quietly published in late September revealed the root cause: the report had been produced with the help of Azure OpenAI, Microsoft's generative language system. Deloitte argued the revision did not affect the substance, findings, or recommendations of the report. Senator Barbara Pocock of the Australian Greens rejected that defense. She called the use of AI misguided because it fabricated a judge's quote and used fictitious references, even remarking that mistakes like that are usually only made by first-year students.

There is a striking irony to this case. Two years earlier, Deloitte was actually one of the lead authors of one of the business world's most widely cited AI risk governance guides. The Committee of Sponsoring Organizations of the Treadway Commission (COSO) published a guide titled “Realize the Full Potential of Artificial Intelligence,” produced in collaboration with Deloitte and built on COSO's 2017 Enterprise Risk Management framework. The firm that helped write the guide on managing AI risk responsibly was tripped up by its own team failing to apply what it had written.

The lesson here is not that we should stop using AI. Deloitte itself just announced a three-billion-dollar investment in generative AI development through fiscal year 2030, including a partnership with Anthropic. The real lesson runs deeper: writing a governance framework and actually following it in practice are two very different things. The gap between them often only becomes visible when someone else reads your work more carefully than you did.

Good Intentions, Leaked Data

The second case comes from a completely different direction. Not a report containing errors, but confidential data leaked without any malicious intent.

In April 2023, three employees in Samsung Electronics' semiconductor division unknowingly fed sensitive company data into ChatGPT. The information was first reported by The Economist Korea, then widely covered by other outlets including CIO Dive. The first employee entered problematic source code from a Samsung facility database download program while looking for a fix. The second entered code for a defective equipment identification program and asked the AI to optimize it. The third converted a recording of an internal meeting into text and fed it to ChatGPT to generate meeting minutes.

None of them intended to leak company secrets. They just wanted to get their work done faster. Unfortunately, ChatGPT's interface at the time still used user input to train and refine its language model. Once the source code or meeting minutes entered the system, the company automatically lost control over that information. As a responsive measure, Samsung eventually capped upload capacity at 1,024 bytes per prompt, though that was only a technical fix applied after the fact.

The Root Problem Isn't the Technology

Placed side by side, these two cases actually tell the same story from two different sides. Deloitte failed on the output side, using AI-generated work without adequate verification before handing it to a client. Samsung failed on the input side, sending sensitive data into a public system before the AI had even produced anything.

Drawing on the IAI training material, there are five basic ethical principles for accountants that could actually have prevented both incidents without needing any complicated new rules.

  1. Integrity, never rely on technology output that is wrong, misleading, or unverified.
  2. Objectivity, do not let bias or excessive reliance on machines cloud professional judgment.
  3. Confidentiality, client or internal data should never be entered into any platform without clear access controls.
  4. Professional competence and due care, understand the quality of the data and the relevance of the output before using it.
  5. Professional behavior, keep complying with applicable standards and laws, regardless of which tool is used.

None of these five principles are new. What is new is only the context, because now someone can violate all five at once with a single click.

Infografik panduan etika dan tata kelola kecerdasan buatan untuk akuntan dan direksi korporat
Infographic created by Gemini AI from the author's material and IAI presentations.

Regulation Is Starting to Take Shape

Regulators and professional associations in Indonesia have actually started responding to these developments, though the steps taken so far remain partial.

In 2025, the Indonesian Institute of Accountants revised the Code of Ethics for Indonesian Accountants based on the 2024 international guidance issued by IESBA. The revision explicitly addresses reliance on systems, the need for technology competence, data protection, and identifying threats when making decisions based on technology output.

The Indonesian Institute of Certified Public Accountants (IAPI) took a similar step. In July 2025, IAPI's Professional Ethics Board issued a technology-related code of ethics revision adapted from IESBA. In the banking sector, the Financial Services Authority (OJK) went further by launching Indonesian Banking Artificial Intelligence Governance in April 2025, so that AI systems are developed and applied responsibly from initiation through periodic evaluation, referring to international standards such as the EU AI Act and Basel Committee on Banking Supervision guidance.

But these three steps do not yet form a unified whole. The IAI and IAPI codes of ethics only bind individual accountants, not their organizations. OJK's guidance only applies to the banking sector. That is where the real challenge lies: non-bank companies and regional state-owned enterprises that are increasingly adopting AI now have to rely on their own boards and finance functions to build their own governance from scratch.

Putting Effective Governance Into Practice

The good news is that businesses do not need to start from zero. Proven frameworks already exist. At the conceptual level, the COSO and Deloitte guidance positions AI governance as an extension of existing enterprise risk management. The principle is simple: if your organization already has a well-functioning internal control system, you do not need to build a new parallel system, you just need to extend the existing framework to cover this new risk.

At the technical level, organizations can refer to the ISO/IEC 42001:2023 standard, the world's first technical AI governance standard, released in late 2023. The world's first AI management standard, it provides a framework that can be independently audited and certified by third parties. In practice, this control cycle can be broken down into three simple stages: preparation, use, and monitoring.

Before use, the organization must define its operational objectives and assess data security risks. During use, access authority must be restricted and human approval remains a strict requirement. After use, the system's performance and potential bias must be monitored regularly. Good governance is not about owning the most cutting-edge AI, it is about building in enough of a gap between an AI output and a decision so that a competent person has time to verify it.

A Practical Guide for Boards of Directors and Commissioners

For a company or regional state-owned enterprise planning to use AI in its finance division for decision-making, the most relevant question today is not whether the technology may be used. The question is who is accountable if the output is wrong, and how to catch that before it ends up in the financial statements.

There are a few concrete steps that can be applied right away:

  1. Build an inventory of every AI tool used within the finance function, no matter how small its scale.
  2. Set written rules on what data may be entered into those tools, especially client data or information not yet released to the public.
  3. Require a review process by competent staff before AI output is used for any significant decision.
  4. Document the entire process carefully, from which tool was used and for what purpose, down to who carried out the review.

The drive for efficiency often outpaces readiness for accountability. Do not let your company only set boundaries after data has already leaked, as in Samsung's case, or only realize a mistake after being called out by an outside party, as happened to Deloitte.

Back to the opening illustration, the model predicting 18 percent growth. The right move is neither to flatly reject the AI's output nor to swallow it whole. The wisest response is to start asking questions: what data did the model actually read? What assumptions did it use? And whose job is it to check whether those assumptions still hold up against current conditions?

Technology can certainly deliver recommendations that are faster and richer in data. But the final decision, and all the responsibility that comes with it, still rests with the human being who approves it, not with the machine model or the vendor that sold it.

For a more specific discussion of the safe limits of AI in analytical work such as market research, risk assessments, and formal reports, see the article “Fluent Doesn't Mean Correct: The Safe Limits of AI for Business”.

Ilustrasi hubungan manusia dan kecerdasan buatan, menekankan tanggung jawab manusia atas keputusan yang dibuat dengan bantuan AI
Source: Bovee and Thill, via Wikimedia Commons, CC BY 2.0.

Sources and references

Response

  1. […] yang kerap membedah struktur kelayakan finansial (topik yang juga saya bahas lebih jauh di AI di Meja Korporat), saya sering menemukan kelemahan mendasar di sini. Asumsi dasar seperti pertumbuhan pasar, […]

Leave a Reply

See Also

Loading related articles...

Discover more from Mulyagusdin

Subscribe now to keep reading and get access to the full archive.

Continue reading