Article

Can ChatGPT operate your accounting software, and does the maker allow it?

Yes, ChatGPT Work clicks through your books after you log in, but the Dutch AFAS allows only certified AI and FreshBooks has put its own connector in Claude.

By Piet Baudoin · September 2026

Yes, but you log in. Since 25 August 2026, ChatGPT Work stops at the login screen of your accounting software, carries on clicking by itself once you have logged in, and holds on to that login until it expires. Whether the maker allows it differs: the Dutch business software AFAS allows only certified AI, Intuit offers developers and partners its own door into QuickBooks, and FreshBooks has put its own connector inside Claude. On OpenAI’s own test, the best model completes 72.6 percent of computer tasks, with half-finished tasks counted.

Below is what happens to your login, how well it works by now, and what three software makers write about it themselves. The gap is no longer in what the assistant can do, but in what your software maker allows. How this plays out elsewhere in office work is in what AI agents take over in small businesses today.

What can ChatGPT do in accounting software today?

Click the buttons on websites where you are logged in, from a browser that runs at OpenAI and not on your computer.

The separate products are gone: agent mode has stopped, the Operator site is closed, and the Atlas browser has been switched off since 9 August 2026. What remains is called ChatGPT Work.

OpenAI itself names your books as an example: “Reconcile invoices and update records in your accounting software.” That means matching invoices to payments and keeping your records up to date, and the sentence is in its own help documentation.

When it reaches a login screen, it stops and asks you to log in. After that it keeps working on that site, and for a reservation or a payment it asks for separate approval. The help documentation says nothing about an entry in your books.

This is not a connection between two systems. It is an assistant that copies what you do on your screen, with the permissions of whoever logs in. What an assistant from another maker does is in what Claude can do on its own for a small business.

Where does your login go after you type it in?

It stays on OpenAI’s computer until it expires.

You log in once to QuickBooks or Xero. That logged-in state then stays ready for the next tasks, even when you walk away: “The authentication will persist for future tasks until it expires, so you do not need to sign in each time.”

There is also a permission setting: per website, or for all websites at once. OpenAI itself advises against the second option.

The help page says one more thing: a web page can take over the assistant. The example there is a comment that tells it to fetch a recovery code from Gmail and send it to a malicious site. OpenAI calls this prompt injection and adds that its safeguards do not remove every risk.

That is why nothing irreversible should happen until a person presses Approve, as in why an AI assistant should not send email on its own. If it does go wrong, the question is who pays for it: who is liable when an AI agent makes a mistake.

Do QuickBooks, AFAS and FreshBooks allow this?

Three makers, three answers, and none of them is about clicking on the screen. Here they are in their own words.

Software Own AI Outside AI Who is responsible Source
QuickBooks Online (Intuit) Agents that “act on your behalf with your permission”; “Currently, there isn’t a way to turn off AI features individually.” Its own door for outside AI, “a local MCP server” that runs “on the developer’s or partner’s machine” not stated on the pages quoted here help page, August 2026; GitHub page, read September 2026
AFAS (Dutch business software) Jonas, at no extra cost, within the European Economic Area only certified AI, none in June 2026 you: the rest is “entirely at your own risk” (translated from Dutch) customer portal, June 2026
FreshBooks not checked its own connector inside Claude, since September 2026 not stated on the page quoted here support page, September 2026

AFAS is the strictest: “AI integrations are allowed, provided the integration is certified” (translated from Dutch). Intuit calls its own door for outside AI “a local MCP server”. MCP is a common standard that lets an AI assistant work with another program, here QuickBooks Online, and Intuit’s version runs “on the developer’s or partner’s machine.”

AFAS, Intuit and FreshBooks all describe an AI that comes in through an agreed door, not an assistant that simply logs in and clicks. The Intuit pages quoted here say nothing about an assistant that logs in through the screen. There, the route is not forbidden and not allowed; it is simply not mentioned. What the AI in your own software does do is in the AI in QuickBooks or Xero or an AI agent alongside.

What does not work today?

On OpenAI’s toughest test, more than a quarter of the computer tasks fail, and that is with half-finished tasks already counted.

And sometimes it does something other than what you asked. On OpenAI’s own safety test, published 3 September 2026, the best model produced an unintended result in 2.4 percent of cases. So one in forty actions goes in a direction you did not choose.

People who have used it say the same. A user wrote on X on 19 September 2026 that it is noticeably better, but still slow, and that it gets stuck on simple tasks. In a public bug report from 10 September 2026, a running task stopped halfway because it hit the usage limit, and the rest had to be done by hand.

The math is simple. OpenAI presents Work as something that keeps going for hours, while its own pricing page gives five to forty-five turns per five hours on Plus. An afternoon of entering invoices does not fit in that. The numbers are in what an AI agent costs per month for ten people.

What happens if this pace continues?

The clicking is improving fast, and with that the question shifts to the door.

In January 2025, OpenAI’s first computer-using agent scored 38.1 percent on the OSWorld test. On 9 July 2026 the score was 62.6 percent on the harder OSWorld 2.0, and on 3 September 2026 it was 72.6 percent, that last one with half-finished tasks counted. On that last set, the previous model took about 75 minutes per task for 65.7 percent, the new one about 40 minutes for 72.6. And in that same step, OpenAI’s own error measure went from 22.0 to 2.4 percent. More than thirty percentage points up in twenty months, in almost half the time, with almost ten times fewer missteps. The maker is grading its own work, but this is not an assistant that can’t do the job.

My hypothesis: by the end of 2027, the question will no longer be whether an agent can operate your accounting software, but whether your software maker lets it in.

The reasoning, in two steps. Ability is rising at this one maker by more than thirty percentage points in twenty months, and the errors are falling faster than the ability is rising. Permission moves the other way: AFAS demands certification and had none in June 2026, and Intuit builds its own agents into QuickBooks while its official door for outside AI runs only on a developer’s or partner’s own machine. Whoever owns the door owns the customer relationship, and I think that is exactly why those doors are closing now.

What would break my hypothesis: a measurement from outside OpenAI that comes out much lower, or a software package that makes clicking from outside technically impossible instead of advising against it.

For a business, what counts then is not the model but your contract. Ask your software maker three things this week. Is an outside AI allowed to log in through the screen? Which AI connection is certified, and from when? Do my books stay within Europe?

Where do you start this week?

Small and reversible. Pick one task that comes back often and where you spot a mistake right away, such as supplier invoices someone retypes or a supplier invoice matched to the right project.

Don’t grant permission for all websites at once, and have someone look over its shoulder. For one week, compare the proposal with what your colleague would do. If it does not work, you have lost a week, not a quarter.

Bombos is the other route. An AI agent reads what comes in: email, chat messages, receipts and invoices. It looks up the details in the software you already use and prepares the work with the reason next to it. No message goes to a customer and no payment goes out until someone from your business presses Approve. That is technically enforced and always on.

If clicking gets much better over the next year, Bombos grows along with it. At Bombos, the model is a swappable part: all work passes through one place where the model is called, so a better model goes in underneath without you having to set anything up again. We can put the strongest and the most cost-efficient model underneath right away, and switch per client to what that client wants. What Bombos learns from your business does not sit in that model. It sits in what your people have approved, corrected and rejected, and that memory stays when the model changes. We also work in the software you already use, so whoever owns the door to your accounting software changes nothing about who does the work in between. However good the models get, that approval does not change.

Our promise: after three months, the work we start with is ready every day, without anyone having to think about it. Leave your number on the contact page, and we will call you back.

Do not give an assistant a door you cannot close yourself.

Sources

Every source was opened on 20 or 23 September 2026 and every quote appears in it word for word.

OpenAI on ChatGPT Work

The measurements

The software makers

People who ran it