Starting, testing, and adjusting

How do you implement an AI agent for administrative processes?

Five phases over 12 to 20 weeks: task and owner, narrow access, recorded knowledge, shadow mode with a threshold, then autonomy by work type.

You implement an AI agent for an administrative process in five phases taking 12 to 20 weeks: choose one task with one owner, give the agent narrow access to email and software, record the rules in your people’s heads, run it in shadow mode until its proposals meet an agreed threshold, and then decide what it may do independently for each type of work. Technology is the smallest part. Most work involves access, GDPR agreements, employees, and management after launch.

This is an implementation plan for a business without an IT department. To assess relevance, see when an AI agent is useful. You will find phase durations from sources giving figures, permissions in AFAS, Dutch business software, and Exact Online, Dutch accounting software, GDPR and AI Act requirements, employee involvement, common failures, and management after launch. The test protocol is in testing an AI agent before automation, and task selection in which administrative processes to automate first. All sources were opened on September 30, 2026. Sources selling a program or product are identified.

The short answer

  • A Dutch provider allows 12 weeks for a single agent and 16 to 20 weeks including stabilization after launch (aiagency.nl, April 2, 2026). A British agency allows 6 to 8 weeks (helium42.com, undated).
  • The gap is between pilot and production. Forrester says three-quarters of enterprise leaders report implementing agentic AI, but only “a small minority” actually run it in production (Forrester, June 3, 2026).
  • The biggest obstacle is measurement rather than technology: 64 percent cite evaluation gaps, 57 percent governance, and 51 percent model reliability (Digital Applied, undated, attributed to Forrester and Anaconda).
  • An AFAS connection calls only explicitly attached connectors. An access token lasts just 1 hour (AFAS Help Center). Exact Online allows 60 calls per minute and 5,000 per day per company administration (OrderChief).
  • A DPIA is, in translation, “not automatically mandatory for every use of AI agents.” A processor agreement and logs that reconstruct decisions are necessary (SenS lawyers, February 24, 2026).
  • The AI Act has required staff AI literacy since February 2025. High-risk rules move to December 2, 2027, but transparency obligations apply from August 2, 2026 (AIComplianceHub, May 2026).
  • You must be able to retrieve what the agent posts and why for 7 years, the retention period for your administration (Dutch Tax Administration).
  • Our position: implementation is onboarding. Successful projects follow the same sequence as giving a new coworker independence.

How long does implementing an administrative AI agent take?

Allow 12 to 20 weeks from first conversation to an agent independently doing one type of work, and a few weeks until its first proposals. Providers often mix these figures, explaining major differences.

aiagency.nl states, in translation, “12 weeks for a single agent,” but 16 to 20 weeks “including the stabilization period after launch” (aiagency.nl, April 2, 2026). helium42 schedules 6 to 8 weeks from discovery to scaling (helium42.com, undated). Safebooks gives 8 to 12 weeks for a purchase-invoice agent with clean data, preceded by 3 to 6 months of data work if it is not clean (Safebooks, undated). A Dutch agency says, in translation, “a first, limited connection” to Exact Online is “often ready within a few weeks” (theaiagency.nl, undated). All four sell implementation programs.

Phase aiagency.nl helium42.com What happens in an administrative process
Discovery and selection Weeks 1-2 Weeks 1-2 Choose one recurring task and owner; record who currently does it and how often
Data and access Not separate Week 3 Email and software account, company administration, relevant part of the package
Build and test pilot Weeks 3-6 Weeks 4-5 Shadow mode: the agent proposes, the employee does the work and compares
Evaluate and adjust Weeks 7-8 Week 6 Count errors, adjust rules, set an autonomy threshold
Roll out and stabilize Weeks 9-12, plus 4-8 weeks Weeks 7-8 Assign management responsibility, choose a second task

Sources: aiagency.nl, April 2, 2026, helium42.com, undated. The right column is our application to administrative work.

“A few weeks” and “20 weeks” do not contradict each other. One measures a working connection; the other measures when you trust the agent. Ask providers which they mean. aiagency.nl also warns that compressing implementation into six weeks cuts discovery and evaluation, the phases determining whether the agent reaches production.

What phases do you follow when implementing an AI agent?

There are five phases. In an SME, the first five weeks involve little technical work. Time goes into choosing, arranging access, and writing down undocumented knowledge.

1. One task and one owner, weeks 1-2. Choose a weekly task currently transferred manually from email into software: retyping purchase invoices, leave requests, or resident reports. Name one person responsible for the agent on that task. Digital Applied identifies “one accountable owner per agent” as a characteristic of projects that survive (Digital Applied, July 11, 2026). In a business your size, this is an office manager or controller rather than an IT specialist.

2. Narrow access, weeks 2-3. Give the agent its own mailbox and software account, with permissions limited to the relevant area. The next section explains this by package.

3. Record knowledge, weeks 2-4. Much of how a task works is undocumented: which supplier always posts to project X, who handles which email. Interview the person currently doing the work and record their answers. Remaining gaps emerge in the next phase.

4. Shadow mode and evaluation, weeks 4-10. The agent proposes, while the employee works as usual and compares. Count differences and adjust rules until differences subside. See the testing section.

5. Autonomy by work type and handover, weeks 8-20. Only after a type of work runs without errors for a while should the agent complete it independently. Irreversible actions, such as payments or customer messages, keep waiting for a person. Digital Applied describes “augmentation → automation → autonomy,” with gates where “irreversible, customer-facing, or spend-bearing actions route through a human” (Digital Applied, July 11, 2026, attributed to Deloitte Tech Trends 2026).

For organizing the first three months as a bounded trial, see starting an administrative automation pilot.

What permissions does an AI agent need in AFAS and Exact Online?

An agent needs exactly the permissions its task touches. AFAS and Exact Online support that setup. Least privilege means the minimum necessary permissions. Here, it is a setting rather than an extra project. The OWASP agent list says: “Enforce least privilege so agents only get the goals, tools, and data they actually need” (Teleport on OWASP Top 10 for Agentic Applications, December 15, 2025; Teleport sells access management).

Package How access works Limit or caution Source
AFAS Profit An app connector with OAuth. Translated excerpts: “Only linked GetConnectors can be called in combination with this app connector.” The linked user’s authorization and filter authorization “therefore determine which data the application sees.” Translated excerpt: “An access token is valid for only 1 hour.” Treat the client secret as a password. AFAS Help Center
Exact Online OAuth connection per company administration, or division Maximum 60 calls per minute and 5,000 per day; “Refresh tokens have a limited life and rotate”; most lists return 60 rows per page, bulk and sync 1,000 OrderChief, Peliqan, Exact Online documentation

OrderChief and Peliqan sell connections. Exact’s official limits page did not load for us. Figures therefore come from secondary sources and may differ by contract.

Calculate the Exact limit: 5,000 daily calls divided by 60 per minute gives 83 minutes of continuous full load. At 60 rows per page, you retrieve at most 300,000 rows daily; bulk and sync routes allow at most 5 million. A twenty-person company’s administration gets nowhere near that. Limits become restrictive when a poorly built connection repeatedly retrieves entire lists instead of changes. Ask whether the provider retrieves only changes, rather than whether it reaches the limit.

Maintenance is the second issue. An AFAS token expires after an hour; an Exact token rotates. Renewal is automatic until someone changes the connection account password or disables the account. Then the agent can stop unnoticed. State who receives connection-failure alerts in management agreements. See AI working with your existing software and the AFAS and Exact Online integration pages.

What must you arrange for GDPR and the AI Act?

For GDPR, arrange a processor agreement covering the agent’s autonomous work, logs allowing every decision to be retrieved, and meaningful human review. A DPIA is not automatically mandatory. For the AI Act, you mainly need to demonstrate teaching staff to work with AI.

The strongest Dutch source here is a lawyer. Translated excerpts: “A DPIA is not automatically mandatory for every use of AI agents. Whether GDPR Article 35 applies depends on the specific processing.” On logging: “Provide logging that enables reconstruction of decision-making.” On human oversight: “The question is not only whether there is human intervention, but also whether that intervention is meaningful.” (SenS lawyers, Lucia Spaans, February 24, 2026; SenS sells legal advice.)

Rule What it requires Since or from Source
GDPR Article 28 Processor agreement with the vendor, also covering autonomous agent actions Already applies SenS lawyers
GDPR Article 35 DPIA only when the specific processing requires it Already applies Same
GDPR Article 22 Meaningful human intervention in decisions about people Already applies Same
AI Act Article 4 Staff AI literacy measures February 2025 AIComplianceHub
AI Act Article 50 Transparency for chatbots and AI-generated content August 2, 2026 Same
AI Act, high risk, Annex III Postponed December 2, 2027 Same
Tax retention requirement Administration retained 7 years, real estate 10 years Already applies Dutch Tax Administration

AIComplianceHub sells a compliance platform. It highlights a common mistake: reading that the AI Act has been postponed and assuming nothing applies in 2026. Only high-risk rules move. The transparency obligation, in translation, “does NOT move,” and AI literacy has applied for a year and a half.

Combine two rarely connected requirements. GDPR asks for logs reconstructing decisions. The Tax Administration asks for 7-year retention. Together, this means the reason behind each agent-proposed posting must remain retrievable for 7 years, longer than most vendor contracts or any language model’s use. Ask where those reasons reside and how you take them when switching vendors. An invoice in Exact without the underlying email and reasoning is worth less to an auditor than one with them.

Accounting firms have an additional professional layer. NBA and NOREA’s June 2026 guidance says, in translation: “Validation and human judgment must remain the basis of public trust” (Accountant.nl, June 5, 2026).

How do you test an AI agent before it posts independently?

Run it in shadow mode for weeks. It proposes for every real document while the employee works as usual. Count differences. Only when they stay below a threshold recorded beforehand may the agent complete that work type independently.

This sounds like a formality, but it is the phase most often missing. “Evaluation gaps” lead reported obstacles at 64 percent (Digital Applied, undated, attributed to Forrester and Anaconda 2026; secondary source). Anthropic, the model maker, advises: “Start with simple prompts, optimize them with comprehensive evaluation, and add multi-step agentic systems only when simpler solutions fall short” (Anthropic, December 19, 2024). This text is older than the rest, but Forrester and Gartner have since repeated the principle.

Three things make shadow testing useful. Use real documents from recent weeks, rather than invented examples. Count each work type separately: success on standard invoices does not establish success on credit notes. Record the threshold before starting so it cannot shift with enthusiasm. The full protocol, including sample size and counting, is in testing an AI agent before automating business processes.

How do you involve employees in implementation?

Make the person currently doing the work the source and reviewer. They explain the process, approve proposals, and turn corrections into agent rules. They know most and have most to lose. Sidelining them is the quickest route to an unused agent.

Training provider AOG writes, in translation: “Implementing AI is therefore not only a technical issue, but a change-management issue” (AOG, April 30, year unspecified; AOG sells change-management training). ai-agents.nl calls adoption the hardest part (ai-agents.nl, undated). helium42 targets more than 70 percent usage among intended employees (helium42.com, undated).

In practice:

  • Explain what replaces the freed work. An office manager watching invoice work disappear wants to know what comes next. In a growing business, it usually means currently neglected work.
  • Let the employee onboard the agent. The interview, corrections, and threshold come from them. They become the owner.
  • Show what the agent did and why. An unsupported proposal requires belief. A proposal with its source can be checked. GDPR also requires this.
  • Count this as AI literacy. Article 4 is best addressed through real proposals rather than a standalone course.

For employees configuring new tasks without a developer, see can employees adjust AI workflows themselves?.

What goes wrong when implementing an AI agent?

Most failures happen before technology: vague tasks, excessive scope, no owner, and no yardstick. Sources give large failure percentages, but their denominators differ. They measure three things.

Figure What it measures Source Caveat
88 percent “Agent pilots” failing to reach production Digital Applied, undated, attributed to Forrester and Anaconda 2026 Secondary source, large companies
60 percent Projects failing, in translation, “through inadequate preparation” aiagency.nl, April 2, 2026 No underlying study named; provider
More than 40 percent Agentic projects canceled by late 2027 Gartner, via Digital Applied, July 11, 2026 Forecast, not measurement

Do not add these figures or make a series. Their shared direction is failure through preparation and governance rather than model capability. Gartner analyst Anushree Verma says: “Most agentic AI projects right now are early stage experiments or proof of concepts that are mostly driven by hype and are often misapplied.”

The five most frequent source findings, ordered by when they strike:

  1. No precise task. “Automate administration” is not a task. “Post regular suppliers’ purchase invoices to the right project” is. See tasks AI can take over.
  2. Too much at once. ai-agents.nl describes an excessive-scope project where, in translation, “after three weeks everything stopped” (ai-agents.nl, undated).
  3. No owner. Without one name per agent, nobody owns the threshold or calls when the connection fails.
  4. No yardstick. Without a recorded threshold, the pilot stays a pilot forever or launches prematurely.
  5. An agent where a rule suffices. A fully predictable task is cheaper and more reliable with a fixed rule in your software. See AI agents versus traditional workflow automation.

What happens after an AI agent launches?

Management starts: someone monitors connections, updates rules, samples output, and decides the next task. Almost no implementation plan we read gives this a separate phase, although it lasts years.

Four agreements matter:

  • Catch silent failures. Tokens expire, AFAS after an hour, Exact through rotation, and renew automatically until someone changes the connection account. Agree who receives alerts.
  • Communicate work changes. New suppliers, VAT rates, or mailbox coworkers become known only when someone tells the agent. The cheapest route turns a proposal correction directly into a new rule.
  • Reverse like an accountant. Correct a wrong posting through a reversing entry, preserving the administrative trail. Record who may do this and how reasons are retained.
  • Check returns at each stage. Digital Applied cites “finance sign-off before each expansion,” following Deloitte’s advice that finance partners and business owners approve expansion (Digital Applied, July 11, 2026). For you: add a second task only when the first demonstrably reduces work.

Do not calculate returns too early. Figures attributed to BCG and Forrester give finance and operations agents a median 8.9-month payback. Within 12 months, 41 percent pay back, while 22 percent still have negative returns (Digital Applied, undated). Currentic says, in translation, “most AI agents pay for themselves in three to six months” (Currentic, undated). That is a factor of 1.5 to 3 difference. The shorter promise comes from the seller. See errors and review for keeping failures visible after launch.

What does implementing an administrative AI agent cost?

Dutch agencies charge €2,500 to €8,000 to build a custom agent, plus monthly usage, hosting, and monitoring. Compare annual totals rather than starting prices.

Offer Start Afterward Timeline Source
Simple agent €2,500 to €5,000 Model €50-500, hosting €100-500, monitoring €200-1,000 monthly Unspecified Currentic
Multistep agent €5,000 to €8,000 Same Unspecified Same
ai-agents.nl program From €1,500 Unspecified Unspecified ai-agents.nl
aiagency.nl single agent Not on page Unspecified 12 weeks, 16-20 with stabilization aiagency.nl
Bombos pilot €2,000 for three months €1,000 monthly Three-month pilot bombos.ai, September 30, 2026

Adding Currentic’s monthly costs gives €350 to €2,000 after construction, or €4,200 to €24,000 annually. See administrative AI automation costs for the full comparison and an AI platform including implementation and guidance for expected support.

Why do successful implementations succeed?

They onboard an agent like a new coworker. This is our position, supported by comparing the sources.

Compare four characteristics of surviving projects (Digital Applied, July 11, 2026) with onboarding an administrative employee:

Successful agent-project characteristic Onboarding a coworker
Staged autonomy: augmentation, automation, autonomy Observe first, then supervised work, then independence
Human oversight for irreversible actions and spending Manager reviews payments and customer email initially
Expansion only after checking returns Second task only when the first works
One owner per agent One regular supervisor

The sequence matches. Earlier failure figures concern projects reversing it: setting scope and autonomy upfront, building, delivering, and hoping. The largest obstacles, evaluation at 64 percent and governance at 57 percent, happen naturally with a new coworker because a manager observes.

For an SME, two consequences follow. You do not need an IT department: anyone knowing the work can onboard. Implementation value lies in recorded rules and corrections, while models and connections become cheaper annually. Those rules must remain yours and retrievable for 7 years. An agent whose rules stay in an agency’s code is a coworker you onboarded who works for another company.

Where is this heading?

The pace is high. CBS says one in six Dutch businesses used AI in 2025, double two years earlier. Among small businesses it is 27 percent, among midsize businesses with 50 to 250 people, 45 percent. Of users, 32 percent apply AI to administration and management (CBS, December 12, 2025). Forrester says only a small enterprise minority runs agents in production. Usage grows much faster than the ability to onboard agents.

Our expectation: by late 2027, implementing an AI agent for a Dutch administrative process will be an onboarding period your team follows itself, with a few shadow-mode weeks per task, rather than a 12-to-20-week project. The question shifts from build time to how quickly your team teaches a task.

Connections and model use currently cost time and money, and are getting cheaper. Currentic already lists €50 to €500 monthly model costs. Remaining obstacles, evaluation and governance, belong to people knowing the work. A consistent interview, shadow-mode, threshold, and owner structure makes this repeatable.

This expectation could fail if the Dutch Data Protection Authority interprets GDPR Article 22 more strictly, requiring heavier human checks on each posting. Or a major public administrative agent failure could make businesses unwilling to delegate any work.

Bombos handles this with you: we configure the first task together. Your team teaches subsequent tasks in the same format, so each new task does not become a new project.

What can this approach not yet do?

These limits apply to every provider.

  • Shadow mode takes your best employee’s time. Weeks comparing proposals add to ordinary work. Without allocated time, nobody validates the agent.
  • Messy data delays everything. Safebooks allows 3 to 6 additional months. An agent does not automatically clean a disorganized contact list.
  • No agent finds knowledge held only in someone’s head. Interview the person doing the work and record it first. Otherwise the agent keeps asking.
  • Below five people, recurring work is often insufficient to repay onboarding time.
  • Evidence is thin. Most timing and failure sources sell programs, measure large companies, or repeat figures without naming studies. We found no independent Dutch SME implementation research. User accounts appear in experiences with administrative AI agents.
  • Limits and rules change. Exact limits come from a secondary source and may vary by contract. The AI Act was already revised once in 2026.

How does Bombos approach this?

Bombos follows the same five phases as onboarding. The goal is more work at higher quality with the same team, without adding people.

You begin with Chef, which assigns incoming jobs to specialists, and Wegwijzer, which helps you navigate, set boundaries, and choose work Bombos can take over. We build specialists around your first task, systems, and rules. Connections to Exact, AFAS, Visma, a business software group, Twinfield, accounting software, Moneybird, online accounting software, SnelStart, bookkeeping software, Nmbrs, HR and payroll software, Syntess, software for installation businesses, and Microsoft 365 are routine work. Bombos reads and writes after your approval.

Bombos interviews your people and records undocumented knowledge. It then prepares each incoming item’s proposal with reason and source. You approve, change, or reject in Bombos. Exact or AFAS shows only the result after approval. Corrections become rules for coworkers too. What Bombos learns lives in your approvals and corrections rather than a model.

Payments, customer messages, and contracts wait for your approval by default. This boundary is technically enforced. If you want it removed for a work type, Bombos removes it at your request and risk.

The pilot costs €2,000 for three months, about 13 weeks, within the sources’ 12-to-20-week implementation range. Afterward, it costs €1,000 monthly. During those months, the makers guide the first task. Your team then teaches the next, without technical skills or returning to us.

Sources

Each source was opened on September 30, 2026, and each original excerpt appears verbatim in it. Dutch excerpts above are labeled as translations.

Free, no obligation

More work done, at a higher quality, with the same team.

That is what Bombos is for: companies that grow fast and want to keep the same team. We start with one task that keeps piling up and guide you until your team can handle it. Then your team teaches Bombos the next task. Leave your number and we will call you back to talk about your situation.

We read what you write. Within one working day you hear from the one of us who knows your kind of work best.