Skip to main content

Adrian Vanzyl

Adrian Vanzyl’s Board Member Guide to AI Agents

Boards are beginning to face a new kind of operating question: how should companies use AI agents responsibly without slowing innovation to a crawl? Adrian Vanzyl has spent years working across entrepreneurship, venture investing, and strategic governance. From that vantage point, the board’s role is not to approve or reject AI in the abstract. It is to ask whether the company has the right control system for the level of autonomy it is introducing.

That distinction matters. AI agents are not just another software tool. A well-designed agent can retrieve information, make recommendations, coordinate workflows, draft communications, trigger actions, and sometimes execute tasks across multiple systems. Used well, agents can improve speed and operating leverage. Used poorly, they can create confusion, security risk, compliance exposure, and accountability gaps.

Why Boards Need a New Conversation About AI

Many board discussions about AI still sit at the level of strategy: What is our AI roadmap? Are competitors moving faster? Where can we use AI to reduce cost or improve customer experience? Those are valid questions, but they are incomplete when agents begin acting inside the company.

A generative AI tool that helps an employee draft a memo is different from an agent that can access customer data, update a CRM, send outbound messages, change code, approve refunds, or influence pricing. The governance conversation changes as soon as software starts taking action rather than only producing text.

The board does not need to manage the implementation detail. It does need to make sure management has a clear framework for permission, supervision, auditability, risk, and business value.

The First Board Question: What Can the Agent Do?

Every useful governance conversation starts with scope. Boards should ask management to classify agents by what they are allowed to do. A simple model works well:

  • Read-only agents. These agents summarize, search, analyze, and prepare information without changing business systems.
  • Recommendation agents. These agents suggest actions but require a human to approve the next step.
  • Workflow agents. These agents coordinate across tools and may create tasks, drafts, tickets, or internal updates.
  • Action agents. These agents can send messages, update records, execute transactions, or change production systems.

The controls should increase with the level of autonomy. A read-only research agent does not need the same governance as an agent that can send customer emails or modify financial records. Boards should push for that distinction instead of treating all AI usage as one category.

Permissions Are a Governance Issue

AI agents often need access to sensitive systems to be useful. That might include email, calendars, files, customer records, analytics, support tickets, payment systems, code repositories, or internal knowledge bases. The danger is not simply that an agent might produce a bad answer. The danger is that it may have more access than it needs, or that nobody can easily explain what it did with that access.

Boards should ask whether the company applies least-privilege access to agents. Can an agent only read what it needs? Can it only write in approved places? Does it have separate credentials from the human user? Are permissions reviewed when roles change? Can access be revoked quickly? These are basic governance questions, but they become more important when software can act at machine speed.

Audit Trails Should Be Non-Negotiable

If an AI agent completes an important task, the company should be able to reconstruct what happened. What input did it use? What tool did it call? What output did it produce? Which human approved it, if approval was required? What changed in the system of record? Was the action reversed or corrected later?

Without auditability, management cannot learn from errors, compliance teams cannot investigate incidents, and boards cannot evaluate whether risk is being managed. This does not mean every agent interaction needs a board-level report. It means the company should have a reliable record when the action matters.

Measuring ROI Without Fooling Yourself

Boards also need discipline around measurement. AI pilots can produce impressive activity metrics: number of prompts, documents generated, hours estimated, tasks processed, or employees using a new tool. Those metrics may be useful, but they do not necessarily prove business value.

A better ROI discussion focuses on outcomes. Did sales cycles shorten? Did support resolution improve? Did finance close faster? Did product teams ship with fewer defects? Did customer churn signals surface earlier? Did managers make better decisions with less manual reporting? Did the company reduce risk or improve response time?

Adrian Vanzyl’s operating lens is useful here: activity is not the same as progress. Agents should be measured by whether they improve the system, not by whether they generate more work artifacts.

The Human Approval Line

One of the most useful board discussions is where the human approval line should sit. Some activities can be automated safely. Others require review because the cost of error is high. Boards should expect management to define which agent actions require approval before execution.

Common approval gates include external customer communication, legal commitments, pricing changes, payments, hiring decisions, financial reporting, production deployments, and any action that materially affects a customer or stakeholder. The exact list will vary by company, but the principle should be clear: the more consequential the action, the more explicit the control.

A Practical Board Framework

  1. Maintain an inventory of AI agents in use across the company.
  2. Classify each agent by autonomy level and business risk.
  3. Require least-privilege permissions and periodic access review.
  4. Ensure important actions leave an audit trail.
  5. Define human approval gates for high-impact actions.
  6. Measure agent ROI through business outcomes, not activity volume.
  7. Review incidents and near misses as part of the normal risk process.

Looking Ahead

AI agents will become part of normal company operations. Boards that treat them as a vague technology trend will miss both the opportunity and the risk. Boards that ask practical questions about permission, accountability, measurement, and control will help management move faster with more confidence.

For Adrian Vanzyl, the right board posture is neither fear nor blind enthusiasm. It is disciplined curiosity. Agents can create real operating leverage, but only when the company knows what they can do, who is accountable, and how success will be measured.

Adrian Vanzyl on Agentic Due Diligence

Artificial intelligence has changed how startups build products. It is now changing how investors should evaluate them. Adrian Vanzyl has long argued that good investing depends on looking past surface momentum and understanding the system beneath a company. With AI-native startups, that system is often harder to inspect because the product, operations, and go-to-market engine may all depend on agents working behind the scenes.

That creates a new diligence problem. A polished demo can look impressive, but it may hide weak reliability, fragile data pipelines, expensive human workarounds, or agents that only perform well in narrow conditions. Investors need a sharper framework for evaluating what is real, what is defensible, and what is merely theatrical.

Why AI-Native Startups Need Different Diligence

Traditional software diligence often focuses on product-market fit, unit economics, customer concentration, competitive positioning, technical architecture, and team quality. Those still matter. But agentic products add another layer: the company may be promising a system that can act, decide, coordinate, or complete workflows with less human involvement.

That promise changes the questions investors need to ask. Does the agent actually complete the task in production, or only in a controlled demo? How often does it fail? What happens when it is uncertain? Is there an audit trail? Does the customer know when a human has intervened? Is the company’s margin profile dependent on hidden manual labor? Can the system improve with usage, or does every new customer require custom implementation?

These questions are not technical details. They go directly to defensibility, scalability, risk, and valuation.

The First Question: What Is the Agent Actually Doing?

Many AI startups describe themselves as agentic, but the word can mean several different things. In diligence, investors should force clarity. Is the agent retrieving information, drafting content, making recommendations, executing transactions, coordinating across tools, or making decisions with real business consequences?

The risk profile changes dramatically depending on the answer. A research agent that summarizes market data is different from an agent that changes pricing, sends customer communications, updates production systems, or moves money. The more consequential the action, the stronger the need for permissions, review gates, rollback, logging, and customer trust.

A practical diligence step is to map the product into three layers:

  • Inputs. What data, context, documents, tools, and permissions does the agent rely on?
  • Reasoning and workflow. What steps does the agent take, and where does human review enter the process?
  • Outputs and consequences. What does the agent change, send, approve, recommend, or commit?

If a company cannot explain these layers clearly, it may not yet understand its own risk.

What Defensibility Looks Like

In AI, investors often look for proprietary models or unique datasets. Those can matter, but many durable companies will be defended by workflow depth rather than model ownership. If a startup deeply understands a painful business process, integrates into the customer’s systems, learns from repeated usage, and becomes part of daily operations, it may build a stronger moat than a company with a more impressive model demo.

Agentic defensibility usually comes from several forces working together:

  • Workflow specificity. The product solves a narrow, expensive, recurring job better than a generic agent can.
  • Data advantage. The system learns from structured outcomes, not just prompts and documents.
  • Trust infrastructure. Customers can see what happened, why it happened, who approved it, and how to reverse it.
  • Operational embedding. The agent becomes part of how the customer runs a process, not just a side tool.
  • Evaluation discipline. The company measures performance against real tasks and failure modes, not only internal optimism.

The Reliability Question

Investors should ask for reliability evidence early. Agent products are probabilistic by nature, but customers do not buy probabilities in the abstract. They buy outcomes. A company selling an agent into finance, healthcare, legal, enterprise operations, or customer communications needs to show how it handles uncertainty.

That means diligence should include evals, production logs, escalation patterns, human review rates, rollback mechanisms, and customer-visible controls. It is not enough for the founder to say the model is improving. Investors should ask which errors matter, how often they occur, how quickly they are caught, and what the company has changed because of them.

A strong team will usually have a precise answer. A weak team will point back to the demo.

Red Flags in Agentic Startups

There are several warning signs investors should treat seriously. The first is demo-only autonomy. If the product only works when the founder drives it in a prepared environment, the company may be earlier than its story suggests. The second is hidden services work. If humans are manually completing tasks while the company presents the output as autonomous software, margins and scalability may be weaker than advertised.

Another red flag is vague accountability. When an agent makes a mistake, who owns it? The vendor, the customer, the human reviewer, or nobody? Serious buyers will ask that question. Investors should ask it first.

Finally, be careful with companies that cannot explain permissions. Agentic systems often need access to email, calendars, CRMs, code repositories, files, payments, or customer data. If the access model is loose, the product may carry risks that are not visible in the sales deck.

A Practical Investor Checklist

  1. Ask the team to show a real customer workflow from input to output.
  2. Separate what the agent does from what humans still do behind the scenes.
  3. Review reliability data, not just product claims.
  4. Inspect how permissions, audit trails, and escalation gates work.
  5. Understand whether each new customer makes the system stronger or simply adds implementation burden.
  6. Test whether the product could be replaced by a generic AI tool plus a disciplined operator.

Looking Ahead

Agentic due diligence is not about being skeptical of AI. It is about being specific. The best AI-native startups will be able to explain how their agents work, where humans remain accountable, what data makes the system better, and why customers will trust it inside important workflows.

For Adrian Vanzyl, that kind of clarity is central to good investing. AI may change the product surface, but the underlying discipline remains the same: understand the system, identify the leverage, test the risk, and separate durable advantage from temporary excitement.

Adrian Vanzyl on the Founder Agent Stack

Most founders now understand that artificial intelligence is useful. The harder question is where it creates leverage inside a real company. Adrian Vanzyl has spent much of his career looking at businesses through the lens of systems, not slogans. From that perspective, the next phase of AI is not about asking a chatbot for a faster answer. It is about building an agent stack that helps a company sense, decide, and act with less friction.

The temptation is to start with tools. Founders see a new agent platform, a new automation layer, or a new workflow demo and immediately ask whether they should install it. That is usually the wrong starting point. The better question is where the business is already losing time, context, or momentum. AI agents create value when they sit inside those bottlenecks and make the existing operating rhythm sharper.

Why Founders Need an Agent Stack, Not a Tool List

A tool list is easy to build and hard to operate. A founder can collect dozens of AI subscriptions and still have a company that moves slowly. The problem is that isolated tools rarely change the flow of work. They help with a task here or there, but they do not alter how the business learns, prioritizes, or executes.

An agent stack is different. It is a deliberately designed set of AI-assisted workflows that connect to the way the company already runs. It can help a founder prepare for customer calls, summarize market signals, monitor sales pipeline movement, review support issues, draft board updates, and track follow-ups. The point is not to make the company look more automated. The point is to give the founder a clearer operating picture with less manual drag.

This distinction matters because early-stage companies are constrained by attention more than software. The founder is often the product leader, salesperson, recruiter, fundraiser, and customer escalation point. Any system that saves time without improving judgment is only a partial win. The best agent stacks preserve the founder’s judgment while reducing the friction around it.

Where AI Agents Actually Create Leverage

There are several areas where agents can help founders immediately, but the strongest use cases tend to share one feature: the work is recurring, context-heavy, and easy to improve with better preparation.

  • Customer intelligence. Agents can summarize sales calls, support tickets, product feedback, and churn signals into a weekly view of what customers are really saying.
  • Market monitoring. Agents can track competitor launches, pricing changes, hiring signals, funding announcements, and relevant regulation, then surface only the changes that matter.
  • Founder follow-through. Agents can maintain the operational memory around promises, introductions, investor asks, customer commitments, and internal decisions.
  • Content and distribution. Agents can draft first-pass newsletters, customer updates, investor notes, and thought pieces, while the founder keeps control of substance and voice.
  • Internal operating cadence. Agents can turn meeting notes, metrics, and team updates into structured weekly reports that make execution gaps visible earlier.

None of these examples require a company to replace people. In fact, the opposite is usually true. The agent stack works best when it helps a small team spend more of its time on judgment, persuasion, product quality, and customer insight.

The Founder Should Stay in the Loop

One mistake founders make is assuming that a powerful agent should be left alone to complete entire workflows. That may be appropriate for low-risk internal tasks, but most important startup decisions still require human ownership. The agent can prepare the context, draft the recommendation, and flag the trade-offs. The founder should still decide what gets sent, committed, promised, priced, or published.

This is especially true in four areas: money, messaging, hiring, and strategy. An agent can help write an investor update, but the founder owns what it says. An agent can summarize a candidate interview, but the founder owns the hiring decision. An agent can suggest pricing changes, but leadership owns the customer and revenue impact. The benefit is not removing accountability. The benefit is making accountable decisions faster and better informed.

Adrian Vanzyl’s broader view of startup systems applies here: speed without structure is fragile. An agent stack should create more structure around speed, not simply accelerate noise.

How to Build the First Version

Founders do not need to build a complex autonomous operating system on day one. A practical first version can be simple. Start with one high-friction weekly workflow and make it better. For example, a founder might choose the weekly leadership update. The agent collects sales movements, product issues, customer feedback, support trends, and hiring updates. It produces a draft operating memo. The founder edits it, adds judgment, and sends it.

That single workflow can reveal whether the company has the right data, whether the agent understands the context, and whether the output actually changes decisions. If it works, the company can add a second workflow. If it does not, the team has learned before over-investing.

  1. Choose a recurring workflow that already matters to the business.
  2. Connect only the data sources required for that workflow.
  3. Keep every output reviewable by a human owner.
  4. Measure whether the agent changes speed, quality, or follow-through.
  5. Expand only after the first workflow earns trust.

What Good Looks Like

A good agent stack feels almost boring. It does not constantly announce itself. It makes the company easier to run. The founder walks into meetings with better context. Customer themes are visible before they become churn. Investor updates take less time to prepare. Product decisions are informed by fresher evidence. Follow-ups stop falling through the cracks.

The value is not that the company has AI. The value is that the company has a tighter feedback loop. It learns faster, remembers more, and wastes less energy reconstructing context. For a founder, that can be a real advantage.

Looking Ahead

The founder’s agent stack will become as normal as the analytics stack or the CRM stack. The companies that benefit first will not be the ones with the most tools. They will be the ones that understand where judgment gets slowed down and where information gets lost.

For Adrian Vanzyl, the useful way to think about AI agents is not as a replacement for founders, but as a new layer of operating leverage. The best founders will still make the hard decisions. They will simply make them with better preparation, better memory, and a sharper view of the system they are building.