AI in finance
9 min read
October 2, 2026

What is agentic credit control?

Adfin team
Adfin team

Agentic credit control means a system that chooses the next action on each of your unpaid invoices inside boundaries you have set, and then carries it out, instead of running a fixed sequence you wrote in advance. The distinction is narrow and real: a rules engine executes your instructions, and an agent decides within your limits.

In this article

The short version

  • The ICO's own definition: "Agentic AI combines the capabilities of generative AI with additional tools and new ways of interacting with the world."
  • A rules engine sends message two on day seven. An agent picks the action for one customer from what that customer has done before, inside limits you set.
  • The word belongs to enterprise order-to-cash vendors. None of the six UK credit control products we documented uses it, and neither does Xero.
  • The ICO's tech futures report names eight novel data protection risks in agentic systems, and two of them describe this use case closely.
  • Agentic chasing is newer and less proven than a schedule. No independent study shows it collecting money faster, so what can be claimed is capability.

A definition you can use

The most authoritative UK definition comes from the regulator and not a vendor. In its tech futures report on agentic AI of 8 January 2026, the ICO defines the category: "Agentic AI combines the capabilities of generative AI with additional tools and new ways of interacting with the world". Read the second half slowly, because it separates an agent from a chatbot. A model that writes you a reminder is generative. A model that can look at your ledger, choose a customer, choose a channel and send something is interacting with the world.

Applied to your receivables, agentic credit control has three components. Something decides what to do next for one named customer. Something acts, by sending, scheduling, applying a fee or handing the account to you. And something bounds both, so the range of permitted actions is yours and not the model's.

Take any one of those away and the description stops fitting. A tool that only drafts is generative AI with a human deciding. A tool that only follows your schedule is familiar automation, sold since long before anybody said agentic.

A rules engine and an agent are doing different jobs

Your existing reminder schedule is a rules engine, whether it lives in Xero, in a chaser or in a calendar reminder to yourself. You wrote the conditions, the system checks them, and the same thing happens to every customer who meets them.

The two failure modes in the last row are what the comparison is for. A badly designed sequence goes wrong the same way for everybody, so you find out quickly and fix it in one place. An agent given too much latitude goes wrong unevenly, in cases you didn't picture, and you find out from your customer. Running one is mostly setting and reviewing boundaries.

Neither approach wins outright. A hundred identical monthly fees on direct debit need almost no deciding, so a schedule is fine. Two hundred customers with wildly different habits give an agent something to work with.

Whose word this is

Before anybody sells you the term, know that it isn't yet a UK small-business word. Across the six UK credit control products we documented in August 2026, plus Xero's and QuickBooks' built-in reminders, "agentic" appears zero times. A targeted search for "agentic credit control" and "agentic accounts receivable" in a UK context returned no vendor using either phrase.

Where the language does live is enterprise order-to-cash, and it has lived there for a while. HighRadius markets "190+ AI Agents Orchestrated On a Single Platform" and describes "Agentic AI" as "End-to-End Process Orchestration". Sidetrade says its Aimie AI will "reason, decide, act, and monitor autonomously across the entire O2C cycle", and that its agents "execute collections outreach, cash application work, dispute triage, billing issue resolution, and credit-related actions". Intuit uses the word freely at group level while not applying it to the Payments AI that actually drafts reminders. Kolleno sells "AI Agents" that "handle collections and reconciliation autonomously", and then qualifies it in its own copy: the agents work "all inside your rules", and once you have set your objectives and credit policy, its agent "routes the right work".

That qualification is the more accurate description of what any of these products do today, including ours. If you're reading a page that claims autonomy in one sentence and your rules in the next, take the second sentence as the description of the software.

What a boundary looks like in practice

A boundary drawn by confidence, in the sense of letting the system act whenever it's sure, gives you no way to predict what it will do. A boundary drawn by consequence does.

So the questions to settle are about actions and not about accuracy. Which channels may it use for this customer, and how many contacts in a fortnight. May it apply a late fee, or offer an instalment plan, or does that wait for you. What happens the moment somebody replies with a query, promises a date, or disputes the amount. What it may never touch: an account already in a payment plan, a customer who has complained, a message asserting a legal consequence, and the first live send after you've changed a template.

Two design habits carry most of the weight. Make the human route visible, so a reply reaches a person and a name appears in the message, since a customer who can reach you rarely needs to escalate. And keep a full record of what went out, to whom, on what trigger and under whose approval, because you can't review a decision you can't reconstruct. Both are our reasoning about design rather than legal requirements, though they line up with the safeguards Parliament wrote into Article 22C for automated decisions that do carry legal weight, and is it safe to let AI email your clients? takes the law properly.

The risks the regulator has named

The ICO's report is horizon scanning and not guidance, so treat it as the regulator thinking aloud. Even so, it's the clearest published list of what to watch, and it names eight novel data protection risks in agentic systems. Four of them land squarely on a receivables use case.

  1. "Rapid automation of increasingly complex tasks resulting in a larger amount of automated decision-making." More autonomy means more decisions, and a process that starts as messaging can drift towards decisions about your customer's account.
  2. "Purposes for agentic processing of personal information being set too broadly to allow for open-ended tasks." An instruction like "collect this ledger" is broad in exactly the way data protection law dislikes.
  3. "Agentic systems processing personal information beyond what is necessary to achieve instructions or aims." An agent that reads your whole mailbox to chase one invoice has helped itself to more than the job needed.
  4. "Increased complexity impacting transparency and the ease with which people can exercise their information rights." If you can't explain why a customer got four messages, you can't answer them when they ask.

The report also notes that "the specific design and architecture of agentic systems impact how data protection law applies". Its other four risks cover controller and processor responsibilities through the supply chain, unintended inference of special category data, cyber security, and the concentration of personal information in assistant agents.

What hasn't been shown yet

Being straightforward about the evidence: nobody has published an independent study showing that agentic chasing collects money faster than a competently configured schedule. We haven't published one, and neither has anybody quoting you a percentage. The independent research that exists says a reminder itself changes payment behaviour substantially, and that machine learning can predict payment dates. Neither of those tells you that acting on the prediction improves the outcome.

Something narrower does survive contact with the evidence. Is there a best channel or send hour across all businesses and all customers? No reliable public evidence settles that, Adfin can't publish a finding either, and any confident universal answer is a guess. Does this client of yours answer a text and ignore email? Their own record answers it, and an agent working from that record needs no general rule.

So the case for agentic credit control is a capacity argument rather than a performance one. You can hold a pattern per customer in your head across ten accounts and probably not across four hundred, and businesses affected by late payment already spend an average of 86 hours a year on chasing, on the Small Business Commissioner's research. Adfin's Customer Agents work that way: you set the rules of engagement, the agent picks the next action per customer from your own email domain, and you review what you've chosen to review. Whether that collects more money than your current schedule is not something we can show you, and we'd rather say so than publish a number nobody can check. AI for credit control covers what the technology does stage by stage, and what finance teams get wrong about automating collections covers where it goes sideways.

Common questions

What is agentic credit control? A system that decides the next action on each unpaid invoice inside boundaries you set, then carries it out. It varies the timing, channel and wording by what each customer has done before, instead of running one sequence across your whole ledger.

How is it different from automated reminders? Automated reminders execute the rules you wrote, identically for everyone who meets the conditions. An agent chooses per customer inside your limits, so what you design is the boundary and not the message order. A rules engine fails the same way for everybody; an agent fails unevenly, in cases you didn't picture.

Is agentic AI the same as generative AI? No. The ICO defines agentic AI as combining generative AI's capabilities "with additional tools and new ways of interacting with the world". Writing you a draft reminder is generative. Choosing a customer, choosing a channel and sending is agentic.

Do UK credit control vendors offer this? The word doesn't appear on any of the six UK credit control products we documented, or on Xero's or QuickBooks' reminder documentation. Some sell "AI Agents" while describing them as working inside your rules. The vocabulary comes from enterprise order-to-cash vendors like HighRadius and Sidetrade.

Is it safe to let an agent send without approval? That depends on the action and not on the model. A first polite reminder on a small, undisputed, in-terms invoice is the safest unattended act. Anything changing what your customer owes or what they can buy, and anything to a customer who has raised a dispute, is where a person signs.

Does agentic chasing get invoices paid faster? No independent published study shows that, and any specific figure you're shown is vendor marketing without a method behind it. What can be said is that the routine work happens consistently, and that a per-customer pattern is beyond what most people can hold by hand across a large ledger.

Sources

Reviewed by the Adfin team. This article explains a term and summarises the ICO's published thinking and UK data protection law as at August 2026 for information, and it isn't legal advice. The ICO's tech futures report is horizon scanning and not guidance, its updated guidance on automated decision-making was still in draft when this was written, and no regulator has addressed invoice chasing, so the design points marked as ours are reasoning and not requirements. If you're planning to let software apply fees, stop accounts or refer debts without a person approving each one, take advice on your own facts, and members of a professional body should read their own body's guidance on AI tools, which is where the duties of competence and client confidentiality are set out.

Adfin team
Adfin team