At Xerocon London this month, Xero announced XeroForce, a natural-language tool that lets accountants and small business owners build their own custom AI agents on top of their Xero data, without writing a line of code. Alongside it came direct integrations with Claude and Microsoft 365 Copilot, meaning a business owner can now pull live financial data out of Xero and into whatever AI assistant they already use for day-to-day work. It’s a significant step, and it’s arriving at the same time as Sage and QuickBooks push their own AI copilots into every plan, so this isn’t a one-off product launch, it’s the accounting software category moving as a whole.

For years, “AI in accounting software” has mostly meant a chatbot bolted onto the side that could answer questions about your numbers. XeroForce is a different proposition: it lets you describe a workflow in plain English, chasing overdue invoices a certain way, flagging unusual expense patterns, drafting a cash flow summary every Monday, and have an agent actually carry it out using your live data. That’s a meaningful jump from “AI that answers questions” to “AI that takes actions,” and it’s worth understanding before you switch it on.

Why this matters even if you’re not techy

You don’t need to be technical to be affected by this. If your bookkeeper or accountant uses Xero, agentic features may start appearing in your workflow whether or not you asked for them, through automated reminders, AI-drafted reports, or agents your accountant sets up on your behalf. The genuinely useful part is that routine, repetitive finance admin, chasing payments, categorising expenses, producing standard reports, is exactly the kind of task agentic AI handles well. The part that needs a slower look is what data those agents can see and what they’re allowed to do without a human checking first.

Questions worth asking before you turn any of it on

What data can the agent actually access? “Connected to your live Xero data” is powerful, but it’s worth knowing whether an agent built for one task (like invoice chasing) has broader access than it needs. Scope matters more than capability here.

What happens if it gets something wrong? An AI agent that sends a slightly wrong payment reminder to a customer is a minor embarrassment. One that acts on bad assumptions about cash flow or VAT figures is a bigger problem. Look for a human-approval step on anything that sends external communications or touches money directly.

Who’s actually reviewing the output? Agentic AI in finance software works best as a draft-and-review tool early on, not a fully autonomous one. If you’re testing this, start with a single narrow use case and keep a person checking the first month of output before trusting it unsupervised.

Is it actually saving time, or just moving the work? Reviewing an agent’s output properly still takes attention. The genuine win only shows up once you trust a task enough to spot-check it occasionally rather than review every single action, and that trust should be earned over weeks, not assumed on day one.

If you want a structured way to trial agentic AI tools like this without overcommitting, BuildApps works with UK businesses on exactly this kind of staged AI adoption. And if data access scope is the part that worries you most, that’s squarely KeepSafe’s territory, monitoring what your connected tools can actually see and do.

The takeaway

This isn’t a feature to ignore, but it’s also not one to switch on wholesale on day one. Ask your accountant or bookkeeper whether they’re using any of Xero’s new agentic tools, pick one narrow, low-risk task to pilot if you want to try it yourself, and keep a human in the loop until you’ve seen a few weeks of it working exactly as expected.