AI in Invoicing: What to Automate and What a Human Must Always Confirm
Ungrounded tax chatbots fail up to 50% of the time. AI Act Article 50 transparency duties bind from 2 August 2026. The rule: machines propose, humans confirm every irreversible action. Here is the framework.
AI in Invoicing: What to Automate and What a Human Must Always Confirm
AI in invoicing has a delegation boundary. Users accept AI that proposes from reliable data. Users and regulators reject AI that opines or commits. The boundary is not caution. It is the design.
Ungrounded tax chatbots tested inaccurate up to 50% of the time on complex questions. AI Act Article 50 transparency duties bind from 2 August 2026, requiring disclosure of AI interaction and machine-readable marking of AI-generated content. The design rule that follows: AI fills the form, the human presses the button.
What AI Can Do
Extraction (table stakes)
When invoices arrive as FA(3) XML, extraction accuracy approaches 100%. The data is structured. No OCR is needed. Incumbents declare over 95% accuracy on PDF extraction, and KSeF's structured XML shifts this to near-perfect for KSeF-native invoices.
Extraction is not a differentiator. It is a baseline. Every tool that handles KSeF invoices does it.
Categorisation
AI can suggest GTU codes, expense categories, and cost-center allocations based on invoice content. The suggestion is non-binding. The human confirms or overrides.
Parameter suggestions
On structured invoice data, AI can suggest VAT rates, tax points, and currency rates based on the transaction type. The suggestion is grounded in rules, not in a language model's training data. If the rule says "art. 31a: NBP rate from the last working day before the tax point," the AI pulls the rate from the NBP API and fills the field. The human verifies.
Drafting
AI can draft invoice descriptions, payment terms, and email cover notes from structured data. The draft is editable. The human reviews and sends.
Error explanation
KSeF returns developer-grade exception codes (21401, 21405, 21301, 440). No Polish vendor ships a plain-language explanation. AI can map each code to cause, failing field, and fix, grounded in official documentation. This is the P0 AI feature for the penalty era.
What AI Must Not Do
Send invoices
KSeF submission is irreversible. Once the KSeF number is assigned, the invoice is in legal circulation permanently. AI must not submit without explicit human confirmation.
Issue corrections
Corrections have tax consequences. A korekta do zera zeroes out an invoice in the tax records. AI must not issue corrections without human review and confirmation.
Change bank details
Bank-detail changes are the primary invoice fraud vector. AI must not accept or process a bank-detail change without human verification (callback to a known number, biała lista check).
Provide tax advice
Ungrounded tax chat is the documented worst failure mode. Major chatbots give inaccurate advice up to 50% of the time on complex tax questions. AI must not provide tax advice. It can explain what the law says, with citations to primary sources. It cannot recommend a course of action for a specific taxpayer's situation.
Authorise payments
PSD2's strong customer authentication requires two-factor authorisation for payments. Voice biometrics are defeated by 3-second deepfake clones. AI must not authorise payments. Ever.
The Human-in-the-Loop Framework
| Action | AI role | Human role |
|---|---|---|
| Extract invoice data | Automatic | Review exceptions |
| Suggest VAT rate | Suggest | Confirm or override |
| Fill currency rate from NBP | Automatic | Verify on transmission date |
| Draft invoice description | Draft | Edit and approve |
| Submit to KSeF | Prepare | Press submit |
| Issue correction | Prepare | Review and confirm |
| Change bank details | Flag for review | Verify and approve |
| Explain error code | Explain with citations | Read and act |
| Authorise payment | Never | Always |
AI Act Compliance
From 2 August 2026, AI Act Article 50 requires:
- Disclosure when the user is interacting with an AI system
- Machine-readable marking of AI-generated content
- Transparency about the system's capabilities and limitations
Label every AI surface in the product. Mark AI-generated outbound content. State what the AI can and cannot do. These are not just compliance requirements. They are trust signals.
The Decision Log
Every AI-proposed action that a human confirms or rejects should be logged:
- What the AI proposed
- What the human did (accepted, modified, rejected)
- When
- The source data the AI used
The log is not for the regulator. It is for the user. When a correction is needed three months later, the log tells the accountant what happened and why. It is the audit trail for AI-assisted workflows.
This material is information of a general nature and does not constitute legal or tax advice. For a specific situation, verify the current rules or consult a qualified adviser.