Skip to main content
Get in touch
BLOG

Notes from the NORA AI Summit: agents, trust and where the returns show up first

Notes from the NORA AI Summit: agents, trust and where the returns show up first
Published on 7th September 2026

At the NORA Retail & Consumer AI Summit in Sydney last month, I sat on a panel with Andrew Millingen, Head of IT at Boody, talking about what changes when AI starts doing the work rather than helping with it.

TL;DR

  • The NORA AI Summit focused on agents buying from retailers – the nearer opportunity is agents doing the work inside the business, in finance, inventory and operations.
  • AI assistance hands a result back to a person while agentic AI completes the process and posts the result into the system of record.
  • Seat count measures access to intelligence. The metric that replaces it is the share of routine work that completes without a person in the middle.
  • Before a business can trust an agent it needs three things in place: a shared environment, governance and a record of what the agent did.
  • Start with high-volume, rules-heavy work such as invoice matching, order exceptions and replenishment, and keep customer-facing processes for later.

By the time our panel came on, the room had already heard the customer-side story. Google and Shopify had walked through agents in search, agents acting for shoppers and agents eventually buying for them, and all of it is coming very soon.

What the day left out is that if agents are going to buy from you, they are also going to buy for you, and for most retailers the second one is where the returns will show up first.

AI assistance and agentic AI are two different things

Before going further, two terms need separating because they get used as if they mean the same thing. Most of the AI conversation so far has been about the technology, whether that is LLMs, machine learning or what a GPT actually is. For someone running a business, the more useful split is between AI assistance and agentic AI, and it gives you a quick way to audit what your teams are already doing.

Assistance is what most of us use every day. You ask it to draft something, analyse something or generate a report, it produces a result and then you do something with that result. Even a purpose-built agent is still assistance if it hands the output back to a person to finish. In short, assistance gives your people access to intelligence.

Agentic AI applies when the last step is not a person. The agent completes the process and the result goes straight into the system of record.

Take month end as an example. Assistance helps you prepare it by cleaning up the data and getting the journals ready, and then someone on the team processes that last step. Agentic AI, on the other hand, runs the month end from start to finish, checking for anomalies, confirming each checkpoint has been passed and posting the result. You have gained a new digital employee.

That does not mean it has to be fully hands off. You can put approval checkpoints anywhere in the process, so the agent works, stops where you want it to stop, a person approves and it carries on. That is still agentic, because the last step is still the system of record and the person is in the loop rather than at the end of it. For most businesses that is exactly where to start, with the checkpoints in early and removed one at a time as the agent earns trust.

A thousand people using ChatGPT well is a thousand personal processes, and a personal process is not something the business owns or can audit.

– Jarred Spriggs, Directer at Annexa

The AI metric that is about to change

Almost every organisation currently measures AI adoption by seat count, tallying how many staff have a licence, how many use it each week and how much training has been delivered. It is an easy number to collect, and all it really tells you is how much access to intelligence the business has bought.

I think that is about to shift. Over the next couple of years, the businesses that get the most from AI will be measured by what share of their repeatable operational work completes without a person in the middle of it. That is what an intelligent business looks like: the highest proportion of routine operations running on their own, safely.

The models are already good enough for a large slice of routine finance and supply chain work. The variable is the controls, and which organisations build them well enough to trust what comes out.

Why trust is the real constraint

Here is the problem as it looks from inside a business. A company already has systems, automations and employees, and the employees own and run the workflows. They work inside policies, delegated authority limits and professional obligations, and in some cases actual laws. We trust them to do that, and the trust is underwritten by decades of accumulated controls we barely think about any more.

An agent arrives with none of that behind it. It has no professional judgement, no accountability structure and no legal obligation it is bound by, so before a business hands it real work it has to answer one question: how do we know this agent will operate the way we want it to?

From a systems point of view, that question breaks into three parts.

1. Where does it run?

If a process runs in someone’s personal ChatGPT or Claude account, it belongs to that person rather than the business. It stops the week they take leave, it cannot be handed over and nobody else can see what it did. An agent doing real work needs to run somewhere shared that the organisation controls, and increasingly that means inside the system of record itself.

2. How is it governed?

What guardrails does it have, what tools can it reach and what permissions does it run under? Governance exists to make sure the outcomes you want are the only outcomes available to the agent. In practice it is unglamorous and familiar: an identity, a set of permissions and an approval limit, essentially what you already do for a new employee.

3. Can you see what it did?

Can you see that the agent ran today, look back at previous runs and see exactly what it did, and would that record survive an audit? You cannot scale something you cannot describe.

Get those three right and you have the basis for trusting an agent with real work.

What this looks like in practice

Take accounts payable automation, which most mid-size retailers already run.

Traditional AP automation matches each invoice against the purchase order, and often against the goods receipt as well. Those matching rules are the guardrails that make the software safe to run without anyone watching it, and in our experience across our client base they get you to roughly an 85% success rate.

The other 15% fail for small reasons. A supplier changes their invoice layout, the automation no longer recognises it, the match fails and the invoice lands with a person as an exception. Enough of those and you are stuck at 85%.

Applying AI to those exceptions can lift the rate to around 95%. Ten points on thousands of invoices a month is a substantial operational gain, and it raises the question underneath this whole topic: how do you know the agent entered $100 and not $1,000?

With an employee, you trust the person. An agent has to be given the equivalent up front, in the form of reconciliation that checks its work, guardrails that limit what it can do and approval limits it cannot post beyond, all sitting inside your own system. Those foundations are what turn the 95% into a result you can rely on. Without them the agent is doing the same job faster and with less warning when it goes wrong, because a failed rule shows up in an exception queue and a failed agent looks exactly like a finished task.

Where to start

If you are a retailer looking at your first agents, start where Boody did and ask your teams where the opportunities are. They are the ones doing the manual work and they know exactly where the blockages are.

Then run a small pilot. ChatGPT and Claude both handle agents and tasks well enough for a first step and there is no reason to over-engineer it. At the same time, start working out how the business will run these agents in a shared environment, because that is the step between a good pilot and something the company can depend on.

Set your success measures up front and benchmark the result, so you can tell whether the pilot worked rather than whether it felt impressive. Bring IT in early too, so the transcripts are kept and the approvals and actions can be audited from day one instead of being reconstructed later.

On what to pick, look for work that is high volume and rules heavy: something done hundreds or thousands of times a month where the rules are already written down. Order exceptions, returns, supplier invoice matching and stock replenishment all fit. Steer clear of anything customer-facing or irreversible for the first one, so your early mistakes happen inside the business where you can undo them.

Get a personalised NetSuite pricing estimate

Receive a tailored NetSuite quote based on your business requirements, users, modules and implementation needs.

REQUEST PRICING

Why agentic AI projects are failing

Gartner expects more than 40% of agentic AI projects to be cancelled by the end of 2027, and the reasons it gives are escalating costs, unclear business value and inadequate risk controls, all three of which are management problems.

That matches what we see. Agents rarely stall because the technology failed, and far more often because the person running them changed roles and nobody could pick it up, or because six months in someone asked what the agent had actually been doing and nobody could answer. The hardest one to spot is when a policy changes and the agent does not, so it keeps applying last season’s rules perfectly well with nothing to alert anyone.

Each of those comes down to a missing owner, a missing record or a missing way to check the work. The businesses that look intelligent in 2027 will be the ones that can tell you what each of their agents did last Tuesday, under whose authority and whether anyone had to undo it.

Frequently asked questions

What is the difference between AI assistance and agentic AI?

AI assistance produces a result and hands it back to a person, who then decides what to do with it. Agentic AI completes the process itself and posts the result into the system of record, with approval checkpoints wherever the business wants them.

Is agentic AI safe to use in finance and operations?

It is when the agent runs in a shared environment the business controls, operates under a defined identity with permissions and approval limits and leaves a record of every action that would survive an audit. Without those three things in place, an agent is a faster way to make the same mistakes.

What is the best first use case for AI agents in retail?

High-volume, rules-heavy work where the rules are already written down. Supplier invoice matching, order exception handling, returns processing and stock replenishment are typical starting points. Customer-facing and irreversible processes are better left until the controls are proven.

How should a business measure AI adoption?

Seat count and weekly active users measure how much access to intelligence has been bought. A more useful measure is the share of repeatable operational work that completes without a person in the middle of it, alongside whether every one of those completions can be traced and audited.

Why do agentic AI projects fail?

Gartner cites escalating costs, unclear business value and inadequate risk controls, and in practice the failures come down to a missing owner, a missing record or no way to check the work. The technology is rarely the reason.

Can AI agents run inside NetSuite?

Yes. NetSuite’s AI Connector lets governed AI tools work with live ERP data under existing roles and permissions, and platforms such as Annexa’s Erstan run agentic workflows for finance and operations against NetSuite with approvals and audit trails built in. Talk to the Annexa team about where to start.

Learn more

Summarise with AI

Stay updated with Annexa