Rethinking work, skills and trust with AI

AI is changing not only how work gets done, but how professionals learn, develop judgment and define their roles. This month’s stories explore what that shift means for accounting — from protecting foundational skills and rethinking job descriptions to strengthening cybersecurity and managing AI’s hidden “verification tax.”

As you explore these stories, consider where your firm may need to rethink training, oversight and accountability. CPA.com’s AI resources offer practical guidance, decision frameworks and expert insights to help firms adopt AI while preserving the judgment and trust the profession demands.

 
 

What's in focus

Laptops out, AI later

What's new:

UChicago Law will prohibit laptops, tablets and phones across all sections of its nine core 1L courses in 2026–27, with exams written in class without internet, files or apps. Dean Adam Chilton said he knew of no other U.S. law school with a blanket first-year device ban.

How it works:

The school calls the design “AI-resilient.” Instead of policing AI use, it redesigns assessments so offloading work is unattractive. Exceptions cover designated note-taking scribes, in-class polling and disability accommodation. Legal research and writing treats unaided drafting as the base layer, adding AI for research, revision and oral argument prep — with instructors reviewing both the writing and the AI use.

Behind the news:

Berkeley Law bars generative AI from nearly every step of graded work. Penn Carey builds it into the curriculum. UChicago splits by stage of training. William Hubbard, who chairs UChicago’s AI committee, argues lists of permitted and prohibited uses have stopped working as AI gets embedded in everything students' touch.

Why it matters:

Accounting firms face the same sequencing problem with staff. Audit and tax associates build judgment through tick-and-tie, workpaper prep and first-draft memos — the tasks that AI absorbs first. UChicago’s bet is that the formative window gets protected and supervision gets taught explicitly afterward. The exposure runs the other way: Automate junior work without a replacement path and you lose the reviewers who have to sign off five years later.

Our thinking:

The transferable piece is the oral defense. Every UChicago J.D. student must now sit with their supervising professor and answer questions about their research paper’s reasoning — a check on the author that holds regardless of what drafted the text. Firms already have a version of this in review notes, but review has drifted toward inspecting output. Partners who rebuild it around defending reasoning aloud learn which associates actually understand the file, and they learn it before a client or a regulator finds out for them.

AI is raising the stakes for security

What's new:

An autonomous AI agent carried out a four-and-a-half-day campaign that included roughly two-and-a-half days inside AI firm Hugging Face’s production infrastructure. The company’s July 27 security report reconstructs roughly 17,600 adversarial actions. Hugging Face’s first disclosure could not say who or what was responsible. OpenAI later confirmed the agent was its own, mid-evaluation.

How it works:

The agent was not attacking. It was taking a benchmark test, decided the answers sat on Hugging Face’s servers, and went to get them. It escaped its test environment, took over an unrelated third-party’s unsecured system, and used that as its base. Entry to Hugging Face came through two vulnerabilities in its dataset-processing pipeline: One exposed local files and credentials, and the other allowed code execution.

Behind the news:

Hugging Face logged everything and still could not read its own records by hand. Its team used AI analysis agents to rebuild the timeline from 17,000-plus events. CEO Clement Delangue said hosted commercial models refused the job — attack logs trip the same safety filters as writing attack code.

Why it matters:

Exposure: The credentials that worked were already standing and publicly exposed, and the attack routed through an unrelated third-party’s system. For a firm, that is the client portal, the tax software vendor, the payroll integration — none of which your WISP under the FTC Safeguards Rule likely tests. Opportunity: Firms that can document credential lifetime and detection coverage now have something to show clients and insurers.

Our thinking:

The agent had no adversary’s intent and no operator steering it. OpenAI ran the evaluation with its models’ safety refusals deliberately relaxed to measure worst-case capability, and the worst case included multiple days inside a stranger’s production systems. Nothing in the sequence required a skilled attacker — only a capable agent and a reason to keep going. Someone will do this deliberately. Firms that move security off the eighth line of the IT budget and onto a partner-level agenda this quarter will do it before an insurer or a client makes them, which is the cheaper order.

AI is redrawing the job description

What's new:

OpenAI analyzed more than 800,000 work-related ChatGPT messages and found that 16.8% involved tasks historically associated with another occupation. Strip out generic work such as writing emails and scheduling meetings, and 43.5% of occupation-specific messages crossed a traditional job boundary.

How it works:

Researchers matched users in eight functions (including finance, legal, marketing, engineering, sales and human resources) to occupational activities defined by the U.S. Department of Labor’s database. They then classified each message as generic, within the user’s occupation, or cross-occupation. An example would be a salesperson analyzing financial data or a finance professional troubleshooting software counted as task crossover.

Behind the news:

The movement is not symmetrical. Marketing and engineering tasks travel furthest into other occupations, while designers, salespeople and HR professionals are more likely to pull work in from several different functions. Smaller workspaces also showed more boundary crossing among typical-volume users, suggesting AI becomes a substitute for the specialist or internal team that a smaller organization does not have.

Why it matters:

Accounting firms have spent years building jobs around functional boundaries: tax, audit, advisory, technology and operations. AI lowers the cost of stepping across those lines. A manager can analyze data without waiting for the analytics team. A client advisory services (CAS) professional can prototype an automation without filing an IT request. A partner can develop client-facing materials without handing the work to marketing. The opportunity is a faster, more capable generalist. The exposure is someone producing specialist work without the specialist judgment needed to evaluate it.

Our thinking:

The most important finding is not that AI makes existing jobs more efficient. It is that the job itself may no longer be the right unit of analysis. Firms are still writing job descriptions, training people, assigning permissions and setting compensation around bundles of work inherited from the pre-AI organization. Employees are already unbundling and recombining those tasks one prompt at a time. The firms that recognize this early will redesign roles around judgment, accountability and outcomes. The ones that do not will still get broader roles — just without the governance, training or pay structure to support them.

AI comes with a verification tax

What's new:

AI slop (and even useful AI that cannot show its work) is becoming expensive. Senior finance leaders spend an average of 13 hours per week validating AI-generated outputs, according to new IDC research. Nearly half spend at least 15 hours, and 19% spend 30 hours or more — the point at which IDC argues AI may create more work than it saves. In finance, low-quality output does not merely clutter an inbox; someone still has to trace it, test it and defend it.

How it works:

The report calls this hidden workload the “verification tax”: the time spent reconstructing assumptions, tracing sources, checking calculations, testing repeatability and explaining AI outputs to stakeholders. Organizations estimate that reverse-engineering AI outputs consumes 26% of expected AI productivity gains. Twenty-two percent say verification absorbs more than half of all the time AI was supposed to save.

Behind the news:

The research surveyed 2,275 senior finance decision-makers at companies with 20 to 1,999 employees. It was commissioned by Sage, which has an interest in positioning transparent AI as a product differentiator. But the operating picture is useful: Only 4% of respondents describe finance as largely autonomous, while 62% remain primarily manual or rules-based. Seventy-one percent would reject a 99%-accurate tool if it could not produce a human-readable explanation, and 54% would pay more for greater transparency.

Why it matters:

AI ROI calculations typically count the minutes saved producing an answer and ignore the senior time required to trust it. IDC estimates that 13 weekly verification hours cost approximately $78,000 annually for one finance leader earning $250,000 in total compensation. Multiply that across a firm’s partners, controllers or review team, and an inexpensive AI tool can create an expensive parallel workflow. The output gets automated; the evidence, review and accountability do not.

Our thinking:

The answer is not a better narrative from the model about how it reached its conclusion. AI can generate a convincing explanation as easily as it generates a convincing answer. Finance professionals need the underlying evidence: source data, calculations, assumptions, policy references, exceptions, approvals and a reproducible audit trail. That shifts the vendor question from “How accurate is your AI?” to “How quickly can our reviewer prove it?” Firms that measure time-to-trust alongside time saved will get a much more honest picture of AI economics and expose the tools that automate a task without actually completing the work.

Subscribe to the AI in Focus newsletter