Welcome back to this month's ERP news roundup. Last month the headline was agentic ERP shipping at every major vendor. This month the story is the quieter one that follows it: once software starts making and acting on decisions, somebody has to answer for those decisions. That question - who is accountable, and can you prove it - moved to the front of the ERP buying conversation over the past few weeks, and the trigger is regulatory.

The EU AI Act's transparency provisions take effect in August 2026, and the deadline has concentrated minds. Suddenly "AI governance" - a phrase that sounded like a policy workshop a year ago - is showing up in RFPs, vendor demos, and auditor questionnaires. For SMEs the shift is real: explainability, audit trails, and human attribution are starting to behave less like compliance overhead and more like features you actively shop for.

What "AI Governance" Actually Means in an ERP

Stripped of the jargon, AI governance in an ERP comes down to three capabilities. The first is explainable AI, or XAI - the ability to trace and interpret why an AI system produced a specific output. Regulators increasingly expect high-risk decisions to be explainable under rules like the EU AI Act and GDPR, and "the model said so" is not an acceptable answer when the decision affects someone's credit terms, payroll, or supplier payment.

The second is the audit trail: a traceable record of system activity - prompts, outputs, data access, events, and human interventions. If an AI agent reclassifies an invoice or flags a transaction, you need a durable record of what it saw, what it did, and who confirmed it. The third is human attribution - tying an AI action back to the authenticated person whose session set it in motion. That third one is where most 2026 deployments are quietly falling short.

The EU AI Act Deadline Is Doing the Pushing

The reason governance is topping agendas right now is timing. The EU AI Act's transparency provisions take effect in August 2026, and member states are required to establish AI regulatory sandboxes - supervised environments for testing AI systems - by the same month. The enforcement teeth are significant: penalties can reach up to 35 million euro for non-compliant high-risk AI systems. Even for a smaller company that will never be fined at that scale, the direction of travel is unmistakable, and the larger customers you sell to are passing their obligations down the chain.

This is not only a European story. Emerging frameworks worth naming - ISO/IEC 42001, the first management-system standard for AI, and the NIST AI Risk Management Framework - are becoming the common vocabulary that global buyers and vendors use to describe "responsible AI." A vendor that can map its controls to these frameworks is easier to trust than one that cannot. (None of this is legal advice; your obligations depend on your jurisdiction and use case, so confirm them with a qualified adviser.)

The Attribution Gap Auditors Keep Finding

If there is one repeatable finding from the finance-audit world in 2026, it is this. An AI agent accesses ERP data through an API key tied to a service account - and there is no log of which finance team member initiated the work. The activity shows up as "the integration" did it, not "a named accounts-payable clerk, acting on this task, did it." That fails SOX's individual-attribution standard, which expects you to trace a financially material action to a specific person.

The fix has a name that is becoming standard: dual attribution. The system logs both the AI system identity and the authenticated human user whose session triggered the action. You get the efficiency of an agent and the accountability of a named operator in the same record. When you evaluate any AI-enabled ERP feature that touches the books, this is the single most useful question you can ask - and many products still cannot answer it cleanly.

This month in one sentence

With the EU AI Act's transparency rules now in force, AI governance has flipped from a compliance chore into an ERP buying criterion - and the vendors that can prove explainability, audit trails, and human attribution will win deals the others lose.

Governance as a Competitive Advantage, Not a Burden

It is tempting to file all of this under "cost of compliance" and move on. That framing misses what is happening in the market. Forrester expects roughly half of ERP vendors to introduce autonomous governance capabilities during 2026 - explainable AI, automated audit trails, policy enforcement, and continuous compliance monitoring built into the product rather than bolted on afterward. When governance becomes a standard product category, the vendors who do it well turn it into a selling point.

For the buyer, that is good news. Governance done properly is also good operational hygiene: clear audit trails shorten your own month-end and year-end audits, explainability makes AI output easier to trust and act on, and named attribution protects your people when something goes wrong. The companies treating governance as a feature are the same ones making their AI genuinely usable.

What SMEs Should Ask Vendors

If you are evaluating an AI-enabled ERP this quarter, a short, pointed checklist will tell you more than any demo:

  • "Is every AI decision explainable, and how do I see the explanation?" Ask to see the actual trace for a real decision, not a marketing slide about XAI.
  • "Show me the audit trail." It should capture prompts, outputs, data access, events, and human interventions - and be exportable for your auditors.
  • "Do you support dual attribution?" Confirm the system logs both the AI identity and the authenticated human user behind each action, so you can satisfy standards like SOX.
  • "Which frameworks do you align with?" Look for concrete answers referencing the EU AI Act, ISO/IEC 42001, or the NIST AI Risk Management Framework - not vague "enterprise-grade" language.
  • "Who is accountable when the AI is wrong?" A good vendor has a clear answer about human-in-the-loop controls and override paths.

Where Inovexa fits into this trend

We build Inovexa for SMEs, so we treat explainability and audit trails as features our customers can use, not legal boxes to tick. When an AI-assisted step touches your books, the trail should show what the system did, why, and which authenticated person's session stood behind it - the dual-attribution record that turns an auditor's hard question into a two-minute answer.

We are not going to claim we have "solved" AI governance - the rules and frameworks are still maturing. What we can do is keep the human accountable, align our controls with recognised frameworks, and walk you through exactly how a decision gets recorded before you rely on it.

The Bottom Line

The past month marked a shift in how ERP gets evaluated. Agentic features made the software capable; the EU AI Act deadline made governance non-negotiable. For SMEs the smart response is not to fear the regulation but to use it as a buying lens: insist on explainable decisions, demand a complete audit trail, and never accept an AI feature that cannot tell you which human stood behind an action. The vendors worth your money are already treating those as selling points - because they are.

Talk to our team if you want a straight answer on how AI governance should work in an ERP sized for your business.

More ERP news this month: The ‘Autonomous Enterprise’ Race Heats Up · Agentic AI Reality Check: Where SMEs Should Start

Further reading & sources: EU Artificial Intelligence Act - official overview · Forrester - Predictions 2026: AI Agents & Enterprise Software · Gartner - ERP Insights.