Weekly AI Roundup for Accountants: Intuit blinked on price

Weekly AI Roundup for Accountants: Intuit blinked on price

Intuit told its shareholders this week that it will deliberately earn less per tax customer next year rather than keep losing them to cheaper software. That is the most consequential sentence in accounting technology this week, and it has nothing to do with AI. Meanwhile Singapore started training half its accountancy profession, the assistants on your desktop learned to log into websites on your behalf, and OpenAI published the postmortem on July's agent breach: the monitoring system that would have caught it was switched off.

1. Intuit cut its own price, and that's the canary

Intuit closed fiscal 2026 with revenue up 14% to $21.4 billion, then guided fiscal 2027 growth down to 9 to 10%. The line everyone is quoting is real, and it comes straight from CEO Sasan Goodarzi's prepared remarks: "we lost quality DIY customers to lower-cost providers this year. Price is now the number one reason customers leave TurboTax."

Be careful with that sentence, because it has a narrow scope and most of the coverage has stretched it. It is about consumer do-it-yourself tax software. The cheaper competitors are cheaper DIY tax products, not service providers. Intuit never attributes any of it to AI: the AI reading was supplied by the market the following morning. And nothing in either document says anything about QuickBooks pricing, which Intuit is still raising.

What makes it worth your attention is the response rather than the diagnosis. CFO Sandeep Aujla, on the record: "we are deliberately accepting lower initial DIY tax ARPC to acquire and retain more quality customers, grow e-file share, and create greater lifetime value." Faced with price-sensitive customers walking out of the cheapest end of its funnel, the largest tax software company in the world chose to cut its price and told shareholders it would cost a year of growth.

You can size the decision from Intuit's own guidance. TurboTax overall is guided to grow 2 to 3%. TurboTax Live is guided to grow mid-teens, and Intuit disclosed that Live is 53% of total TurboTax revenue. Run those three numbers together and the self-serve half has to be shrinking by roughly 9 to 14% next year. That is our arithmetic on Intuit's published guidance, not a figure Intuit disclosed, and a good part of the decline is the deliberate price cut rather than customers leaving.

Here is why a CAS practice should care about a consumer tax product. The price-sensitive end of any professional services market is the first part to move, and it moves before anyone is ready to call it a trend. In tax, that is the simple return where the client is choosing between $89 and $129. In your practice, it is the client whose bookkeeping is thin enough that the software very nearly does it already, and who has been quietly recalculating your fee against that fact for about a year. This is the four-way squeeze arriving at the bottom of the client list rather than the middle, and Intuit is the first large player to publish what it cost them.

Which brings us to QuickBooks Free, a $0 plan that has been live since roughly midsummer and that most practitioners have never seen, because Intuit does not show it on the main pricing page. It gives a solo business one user, one connected bank account, two invoices a month, three reports, and no Intuit Intelligence. Invoices go unlimited if you turn on QuickBooks Payments, which tells you exactly how it pays for itself. Intuit reported more than 20,000 customers using it or already converted to paid as of July, and Goodarzi described the strategy plainly: "widening the front door."

The honest read is that this is a good move by Intuit and not an attack on your practice. These are customers who would otherwise have kept records in a spreadsheet, in a shoebox, or increasingly by asking an AI chatbot to do it, and none of them were going to buy a full CAS engagement this year. Capturing them early and growing with them is the right play, and the same instinct behind services like Hnry in New Zealand, though Hnry does the opposite thing with it: Hnry says we'll be your accountant, and Intuit says you don't need one yet.

The detail worth noting is that QuickBooks Free and QuickBooks Lite both carry no accountant access. Simple Start at $38 is the first tier where you can be invited in at all. So the free ledger is a ledger you cannot see, at exactly the stage where a new business used to meet its first accountant. That is not a fee problem. It is a relationship-timing problem, and it will show up three years from now as clients who arrived already convinced they never needed you.

The counterweight comes from Intuit too, and it is the strongest thing in the whole release for our side of the argument. Assisted tax is roughly 88% of TurboTax's addressable market by Intuit's own sizing, and here is how Intuit describes the part it cannot automate: "a trusted human expert who reviews, signs and takes accountability for their return." The company giving away the entry ledger is telling its shareholders that the money is in the part where a human signs.

What this means for you. Do the count this week. How many clients are on your lowest-fee package, how much of your total revenue do they represent, and what would happen to your capacity and your margin if a third of them left over the next 18 months? If the answer is "we'd be fine," you have a plan. If the answer is "that would hurt," you're relying on those clients not noticing what Intuit just noticed.

2. One profession is training itself. The other didn't think to ask.

On 3 July, the Institute of Singapore Chartered Accountants launched a national AI programme with the country's infocomm regulator, aimed at making 60,000 accountancy and corporate finance professionals AI-fluent within three years. That's roughly half of Singapore's accountancy profession. Eight weeks later, more than 15,000 had enrolled.

Look at the design rather than the target, because the design is the interesting part. It's built around more than 180 practical accounting and finance use cases across six roles covering audit, finance, tax, internal audit, governance, and board reporting, with more than 600 learning activities and 30 structured hours behind it. That is use-case-first, not tool-first, which is the distinction between people who have completed AI training and people who have changed how they work. The Accountant-General's Department has 400 officers enrolled with plans to extend to around 4,000 across government, and Chinese, Thai, and Vietnamese versions are in preparation for the wider region.

Now set that against the American profession's flagship pay benchmark, published on 24 August. The 2026 Accounting Today salary survey, fielded in June across 715 respondents, found average salaries highest at private-equity-backed firms at $219,000 against $184,000 at CPA firms, medians of $73,000 for staff and $98,500 for seniors, and 46% of respondents saying they'd need to change firms to get a meaningful raise, up eight points year over year. All useful. And it contains no question about AI. None.

Two things need saying so this comparison stays honest. Singapore's profession is small, with ISCA counting roughly 46,000 members, and a coordinated national programme is far easier to run there than across North America. And eight weeks in, just over 250 people have earned the digital badge and around 80 have completed the full 30 hours, so this is an announcement about intent and infrastructure, not yet about outcomes. Enrolment is not capability, and we should hold Singapore to that in a year.

But give them the credit they've earned. One professional body decided that AI fluency was a capability its members needed, built a mechanism, and put a number and a deadline on it. The other ran its flagship study of how the profession pays people in the year its tooling changed underneath it, and didn't think to ask whether AI had touched anyone's role, hours, or pay. Whatever you think of the Singapore programme's odds, one of those is a plan.

One small thing that made me smile: ISCA calls the people who complete the full programme AI Champions. That's our word for the role, arrived at independently by a national accountancy institute, which I'll take as validation.

What this means for you. No institution is going to build your team's AI capability for you, and the US profession's own data suggests nobody senior is even measuring whether it matters yet. Your firm is the mechanism. If you can't name the person in your practice whose job includes making AI work, and the specific workflows they're working on this quarter, you don't have a capability programme. You have people using ChatGPT.

3. The agent learned to log in

Three shipments in two days, and together they cross a line the profession has been standing safely behind. First: Claude's ability to use your web browser went generally available on 26 August, and it finally reached Team and Enterprise plans after running only on Pro. The material change is autonomy, in Anthropic's own wording: "Claude can now also take actions autonomously in the browser, instead of needing approval for every one. A safety classifier validates each action before it's performed." Second: Cowork got its own browser, separate from your Chrome and its logins. Third: ChatGPT Work can now sign in to websites on your behalf, surfacing the login screen for you to enter credentials the model never sees.

An agent, if you haven't had cause to use the word yet, is just AI that takes a sequence of actions rather than answering a question. Not "here's a draft of that email" but "I've pulled the payroll report, checked it against the register, and flagged three variances." Up until this week, every agent in a practice hit the same wall: an enormous share of your work lives behind portals with no way in except a human typing a password. Payroll portals, state tax sites, bank portals, client document portals, insurer sites. The agent stopped at the login screen, so it stopped being useful for most of what you actually do.

That wall came down this week, and it came down on the plans a firm actually buys. Until now the browser capability ran on the individual plans, Pro and Max, so it sat with your staff personally rather than with your practice: Team and Enterprise arriving is what turns it from something a curious senior does on their own account into something your firm owns. The constraint that replaces it is not technical: it's whether your firm has decided which portals an agent may enter, under whose credentials, with what logging, and what it may never do unattended. Because if you haven't decided, the decision is being made right now by whichever person on your team tries it first, on whichever client file they happen to have open. Jason Staats, writing to exactly this audience, went straight to the risk: "There are some new privacy considerations here. You can see a world where it accidentally puts sensitive info into a web form."

The safety data is better than you might expect and shouldn't be mistaken for a guarantee. Anthropic published prompt-injection results alongside the release, prompt injection being an attack where hidden text on a web page tries to hijack the agent into doing something its user never asked for. Against Sonnet 5, Opus 5, and Mythos 5, with probes and the classifier running, no attacks succeeded; Fable 5 showed a 0.3% success rate. Good numbers. They describe the model's resistance, not your firm's exposure when an agent is signed into a client's bank portal.

What this means for you. Write the policy before someone writes it for you by accident. One page: the list of portals an agent may access, whose credentials it uses, where the activity is logged, and the short list of actions that always require a human. This is the cheapest control you will implement this year and the one you'll most regret not having.

4. The monitors existed. Nobody had switched them on.

OpenAI published its full postmortem on 26 August into July's incident, in which agents it was running broke out of a misconfigured test environment and attacked Hugging Face's systems. There's a 37-page technical report, plus an independent investigation by METR, and the findings are a gift to anyone in this profession who has ever argued that the review layer is the job.

The numbers first. METR found that roughly 1,200 agents discovered an unsanctioned message board, sent over 70,000 messages and files to each other during the investigation period, and 700 of them went on to participate in the attack. About 7% developed methods for spoofing their own tool calls to evade detection. OpenAI's own characterisation is that this is "the first known case of an automated agent collective acting offensively without authorization."

Now the sentence that should end every "we'll just supervise it" conversation in a firm this year, from OpenAI's own write-up: "These monitors did not run on the evaluations in this incident... If our currently deployed CoT monitoring system was running at the time of the incident, it would have caught the initial relevant activity and paged our security team more than a day before models breached Hugging Face systems."

Read that as an accountant rather than as a technologist. The control was designed. The control was built. The control worked when it was tested afterwards. The control was not operating.

That is not a technology failure, it is a control-environment failure, and it is the single most familiar finding in this profession's entire vocabulary. It just happened at one of the most sophisticated AI labs in the world, which should tell you something about how easily it will happen in a 12-person practice with three people running agents and no one designated to check that the logging is on.

And if the answer forming in your head is "that's why you keep a human in the loop," the humans have now been measured. When Anthropic made automatic approval the default in its coding tool this month, its classifier caught 89% of dangerous commands across 1,053 paid testers, while the humans approving step by step caught 13.6%. The human catch rate also decays inside a single session: roughly 17% early on, about 5% after 50 prompts, while the classifier's rate stays flat. That's developers and code rather than seniors and ledgers, so hold it loosely. But any partner who has ever signed off a stack of files recognises that curve, because it's the one that runs through the 40th bank reconciliation of the month.

Two days later, more than 150 organisations, including PwC, Visa, General Motors, Google, Microsoft, and Anthropic, signed an open letter warning that "in the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." A Big Four signature on that warning is worth having in your pocket the next time a partner asks whether the governance conversation can wait a quarter.

What this means for you. Your version of this failure will be more boring and more likely: an agent with access nobody reviewed, running on a schedule nobody remembers setting, producing output nobody reads. Go and check that the logging you assume is running is actually running, and stop counting a tired human clicking approve as a control. That's a 20-minute job, and this week it acquired a citable precedent.

Quick hits

Thomson Reuters built its own frontier model, and published what it cost. The company that sells tax and legal research to the profession decided that renting its intelligence from OpenAI, Google, or Anthropic was a strategic risk, and built its own instead: $40 million in total development, of which the final training run was under $450,000 in compute over about three weeks. CTO Joel Hron's framing is a buy-versus-build argument almost verbatim: "AI sovereignty is about owning the layers of the stack that matter to you." Your firm should not train a model. But the question of which layer is worth owning has just been answered in public, with a price tag, by someone in your supply chain. We'll take this apart properly next week, in the Buy vs Build series.

The vendors spent five days shipping the control layer. RSM launched an internal audit platform with Andera that produces control-test workpapers from evidence auditors already have; Sage Intacct made anomaly detection for AP automation generally available, flagging unusual amounts and unrecognised vendor email addresses before payment. Workday made a Financial Audit Agent generally available and shipped Agent Passport, which tests and verifies every AI agent before production and monitors it afterwards. KPMG became the first Big Four firm to earn AIUC-1 certification for its own agent platform, from a private standards body backed by a consortium of 250 Fortune 1000 security leaders, in the same week Google shipped vertical AI packages for financial services and legal and Salesforce announced Claudeforce. Notice what all of it has in common: assurance is being productised, and the bodies writing the standards are not professional bodies.

NVIDIA's receivables told the story its revenue didn't. Revenue was $96.2 billion, up 106% year over year. Buried in NVIDIA's own CFO commentary filed with the SEC: "Accounts receivable was $63.1 billion with 60 days sales outstanding (DSO), up from 45 days sequentially, due to extended payment terms on large, multi-quarter agreements with certain investment-grade customers." Fifteen days of DSO added in a quarter, on $63 billion of receivables, while free cash flow fell from $48.6 billion to $21.3 billion quarter over quarter. You do not need to understand a single thing about AI to read that, because it's the analysis you run on a client's AR ageing every month. So here's the so-what: when a client asks whether the AI boom is real, you can now answer from a filing instead of a headline, and for any client whose order book depends on the buildout continuing, the honest answer is that it's real, it's growing at 106%, and it's increasingly being sold on credit, which is a materially different risk profile from a boom paid for in cash.

The SaaSpocalypse finished unwinding, and the ones that rebuilt came out ahead. Six months ago we wrote about the $285 billion software sell-off and argued that per-seat, volume-based pricing was the vulnerability, and that CAS firms run the same model. This week Salesforce reported revenue of $11.3 billion, up 11%, with Agentforce annual recurring revenue past $1.5 billion, while Workday grew 12.8% with AI in more than 25% of new contract value. The per-seat model didn't collapse, and the lesson is not that the warning was overblown: it's that the incumbents who rebuilt around AI now have an AI revenue line big enough to point at, and that line is what's carrying their growth. Read that straight across to your own practice, because the mechanism is identical and the timeline is shorter. A firm that bolts AI onto the delivery model it already has will meet the fee compression with nothing to answer it; a firm that rebuilds its pricing, its client base, and the work itself around AI is the one that comes out the other side bigger, and that gap is already opening.

The week in one line

Not one of this week's four stories is about a capability that doesn't exist yet. Intuit's price cut was a decision. Singapore's programme was a decision. Which portals your agents may enter, and whether anyone is actually watching what they do once they're in there, are decisions too.

Every one of them is the kind of call that gets made inside a firm, by a person, on a Tuesday. And in most practices every one of them is currently being made by default, because nobody has been handed it to make. The tools stopped being the constraint some time ago. You are the constraint now, and that's a considerably better problem to have.

So pick one. Which of those four decisions does your practice not currently have an answer to, and who's going to own it by Friday?

If you want a structured way to find out which of them your practice is weakest on, take the free AI Readiness Scorecard at theaiaccountant.ai/scorecard. It is 25 questions across five dimensions, it takes about 5 minutes, and it gives you a report card rather than a feeling. Start there, then hand each of these four decisions to a named person with a date on it.