AI for ERP: how AI works with the ERP you already run
AI for ERP means software that reads the data in the ERP you already run, answers questions about it with the record each answer came from, and drafts entries such as sales orders, purchase orders and supplier bills for a person to approve. The major ERP vendors now ship assistants and agents inside their products, and open connectors let outside AI tools reach the same data. If your ERP is older and has no API, an agent can read and key data through its screens. This guide covers the jobs AI does in an ERP, the four ways to connect it, and what each major vendor offers.

What AI for ERP means
An ERP, short for enterprise resource planning, is the business system that holds a company’s orders, inventory, purchasing, production and accounting. AI for ERP is a layer on top of the ERP you already have: it reads it, answers questions about it, and prepares work inside it. The table shows the four jobs it does and who signs off on each.
| Job | Example | Who signs off |
|---|---|---|
| Answer a question | “Which open orders for this customer will ship late, and why?” answered with the order numbers | Nobody needs to, but the answer names its records so anyone can check them |
| Flag an exception | A supplier’s price rose on the last three invoices, or an item’s on-hand quantity went negative | The person who owns that supplier, item or account |
| Draft an entry | A sales order from a customer’s emailed purchase order, a purchase order from a reorder suggestion, a supplier bill from an invoice | A named person approves before it is saved or sent |
| Operate the screens | An agent keys an approved order into an older ERP the way a clerk would | The same approval, given before the agent types |
One rule keeps this safe. The AI reads what the person using it is allowed to see and prepares drafts, and a named person approves anything that changes a record or leaves the building. Human in the loop covers how to design that approval step.
Answering questions with the source record
Many questions people ask their ERP are lookups spread across several screens: what a customer ordered last year, which purchase orders are late, what a part cost the last three times. An AI system answers them in one of two ways. It can write a database query from the question and run it, or it can use retrieval-augmented generation (RAG), which AWS describes as having a model reference “an authoritative knowledge base outside of its training data sources” before it answers, “all without the need to retrain the model.”
Either way, an answer about your business should name its records: the order number, the invoice, the receipt date. A number with no source cannot be checked. The answer should also respect who is asking. Microsoft’s MCP server for Business Central, for example, performs all operations “with your user identity and permissions, ensuring audit trails show who performed each action.” An assistant that reads the ERP through an administrator’s account can show anyone who asks the margin on every customer.
Drafting entries for a person to approve
Drafting targets the documents people retype: customer purchase orders keyed as sales orders, supplier invoices keyed as bills, reorder lists keyed as purchase orders. AI reads the document, finds the customer, supplier and items in the ERP, and fills in a draft.
The vendors that ship this build in the same approval. Microsoft’s Sales Order Agent “always involves designated Business Central users to review and approve all outgoing messages before it sends them to customers,” and it always creates a sales quote first because quotes “have no impact on planning, reservations, availability calculations, or cash flow forecasts.” Its Payables Agent “creates drafts only and never automatically posts invoices.” AI invoice processing walks through the supplier side, and AI in procurement the purchasing side.
Four ways to connect AI to an ERP
How AI reaches your ERP decides what it can do and how much can go wrong. There are four routes, and many companies use two of them.
| Route | How it works | Good for | Watch for |
|---|---|---|---|
| API or MCP server | The ERP’s own connection for other software. An MCP server is one built on the Model Context Protocol, an open standard for AI tools | Reading and writing with the ERP’s business rules applied | Usually needs a cloud or recent version of the ERP. Check which records and actions are exposed |
| Read-only database connection | A report user reads the ERP’s database tables directly | Fast answers and reports on an on-premises ERP | Skips the ERP’s business rules, so keep it read-only. Ask the vendor or your IT support first |
| Scheduled exports and imports | The ERP writes reports to files on a schedule, and approved entries go back through its import tool | Older systems with good reports | Answers are only as fresh as the last export |
| Screen agent | Software reads the screen and uses the keyboard and mouse like a clerk | Older ERPs with no API, for keying approved entries | Slower than an API, and it needs a person approving what it types |
The Model Context Protocol (MCP) is “an open standard that defines how AI applications communicate with data sources and tools,” in Microsoft’s words. It matters because one connector can serve several AI tools. Microsoft’s documentation names Copilot Studio, GitHub Copilot, Claude and ChatGPT as clients for Business Central’s server, and says that by default it “provides read-only access to all exposed Business Central API pages.” Write access has to be granted on purpose, page by page. Keep the same default on any ERP connection: read-only until a specific write is needed.
What the major ERP vendors now ship
Each of the vendors below now builds AI into its product. The descriptions are the vendors’ own, checked September 28, 2026. Features change with each release, so check your version.
| ERP | What the vendor ships | In the vendor’s words |
|---|---|---|
| Microsoft Dynamics 365 Business Central | Sales Order Agent, Payables Agent and an MCP server | The Sales Order Agent “uses AI to analyze customer requests received via email and locates the customer in Business Central” |
| Oracle NetSuite | AI Connector Service and Bill Capture | “NetSuite has adopted the Model Context Protocol (MCP), which boosts its integration capabilities and enables secure interactions between AI models and data systems” |
| SAP | Joule Assistants | “Joule Assistants use deep role and process context to coordinate AI agents and autonomously execute complex workflows across your business” |
| Sage X3 | Sage Copilot for Sage X3 | Starts with helping sales teams “query customer orders, shipping timelines, and fulfilment issues,” with questions asked in English, French or Spanish |
| Epicor Kinetic | Epicor Prism | “Engage in natural language conversations with Epicor Prism to gather information, request insights, or execute actions” |
| Infor CloudSuite | Infor GenAI assistant | “a conversational assistant enabled with industry-specific AI agents,” embedded in Infor CloudSuites |
| Acumatica | AI Assistant and AP document recognition | “The Acumatica AI Assistant helps employees ask questions about business data in plain language” |
Three questions apply to all of them. First, how is it billed? Microsoft bills selected Business Central agents per use in Copilot Credits, through prepaid capacity or pay-as-you-go, as its billing documentation explains. Ask every vendor for its model and check its own pricing page. Second, which records and actions can it reach, and under whose permissions. Third, where are prompts processed: Microsoft’s Payables Agent FAQ says that if an environment sits where Azure OpenAI is not available, “administrators must allow data to move across geographies.” Private AI for business covers that last question in depth, and enterprise AI platform compares these built-in tools with a platform that spans several systems.
Which route fits your ERP
Tell Derik which ERP you run, which version, and where it is hosted. He will tell you which of the four routes it supports and what AI can do through each.
Start a conversationWhat to do when your ERP has no API
If your ERP was installed on your own server years ago and has no modern API, the vendor’s cloud agents are usually out of reach. AI can still work with it.
- Ask the vendor or reseller what exists. Some older systems have an add-on API, an ODBC driver (a standard way for reporting tools to read a database) or an import tool that nobody at the company has used.
- Read from a copy. A read-only connection to the database, or a nightly export of the reports people already use, is enough for questions, answers and exception flags.
- Write back through the screens, with approval. A computer use agent can key approved entries. Anthropic describes its computer use tool as providing “screenshot capabilities and mouse/keyboard control for autonomous desktop interaction,” and among its recommended precautions lists “Asking a human to confirm decisions that might result in meaningful real-world consequences.” Legacy ERP automation explains how to set this up on an older system.
- Keep the ERP as the record. Whatever the route, the ERP stays the system of record, and the AI layer keeps a log of what it read, what it drafted and who approved it.
Running AI next to an old ERP also produces a record of the questions people ask and the documents they retype, which is a useful list of requirements if you later replace the ERP.
Where to start
Pick one job with a clear before and after. Two kinds of job make good first projects: the question that someone answers by hand every day, such as late orders or stock for a customer, and the document that someone retypes every day, such as customer purchase orders or supplier invoices. Measure the time and the error rate for a month by hand, then with the AI drafting and a person approving. How to build an AI agent covers the steps and the timeline, and AI for inventory management shows what the same ERP data supports for stock.
How ThriveAI helps
ThriveAI is an AI engineering company in Ottawa that builds private AI systems on a client’s own data, for manufacturers and distributors in Ontario and Quebec. It works with the ERP a company already runs, through whichever route that ERP supports, including screen agents for older systems. Answers name the record they came from, and drafts go to a named person for approval before anything is saved or sent. The platform is designed to keep each client’s data on its own server in Canada. The client chooses a model on that server or a hosted model under a written zero data retention agreement, a contract under which the provider keeps no copy of a request or its answer. A hosted model may process requests outside Canada. Derik Lawlis, the founder, leads every project and stays close to the build. More is on About ThriveAI.