Skip to main content

Adrian Vanzyl

Adrian Vanzyl’s Board Member Guide to AI Agents

Boards are beginning to face a new kind of operating question: how should companies use AI agents responsibly without slowing innovation to a crawl? Adrian Vanzyl has spent years working across entrepreneurship, venture investing, and strategic governance. From that vantage point, the board’s role is not to approve or reject AI in the abstract. It is to ask whether the company has the right control system for the level of autonomy it is introducing.

That distinction matters. AI agents are not just another software tool. A well-designed agent can retrieve information, make recommendations, coordinate workflows, draft communications, trigger actions, and sometimes execute tasks across multiple systems. Used well, agents can improve speed and operating leverage. Used poorly, they can create confusion, security risk, compliance exposure, and accountability gaps.

Why Boards Need a New Conversation About AI

Many board discussions about AI still sit at the level of strategy: What is our AI roadmap? Are competitors moving faster? Where can we use AI to reduce cost or improve customer experience? Those are valid questions, but they are incomplete when agents begin acting inside the company.

A generative AI tool that helps an employee draft a memo is different from an agent that can access customer data, update a CRM, send outbound messages, change code, approve refunds, or influence pricing. The governance conversation changes as soon as software starts taking action rather than only producing text.

The board does not need to manage the implementation detail. It does need to make sure management has a clear framework for permission, supervision, auditability, risk, and business value.

The First Board Question: What Can the Agent Do?

Every useful governance conversation starts with scope. Boards should ask management to classify agents by what they are allowed to do. A simple model works well:

  • Read-only agents. These agents summarize, search, analyze, and prepare information without changing business systems.
  • Recommendation agents. These agents suggest actions but require a human to approve the next step.
  • Workflow agents. These agents coordinate across tools and may create tasks, drafts, tickets, or internal updates.
  • Action agents. These agents can send messages, update records, execute transactions, or change production systems.

The controls should increase with the level of autonomy. A read-only research agent does not need the same governance as an agent that can send customer emails or modify financial records. Boards should push for that distinction instead of treating all AI usage as one category.

Permissions Are a Governance Issue

AI agents often need access to sensitive systems to be useful. That might include email, calendars, files, customer records, analytics, support tickets, payment systems, code repositories, or internal knowledge bases. The danger is not simply that an agent might produce a bad answer. The danger is that it may have more access than it needs, or that nobody can easily explain what it did with that access.

Boards should ask whether the company applies least-privilege access to agents. Can an agent only read what it needs? Can it only write in approved places? Does it have separate credentials from the human user? Are permissions reviewed when roles change? Can access be revoked quickly? These are basic governance questions, but they become more important when software can act at machine speed.

Audit Trails Should Be Non-Negotiable

If an AI agent completes an important task, the company should be able to reconstruct what happened. What input did it use? What tool did it call? What output did it produce? Which human approved it, if approval was required? What changed in the system of record? Was the action reversed or corrected later?

Without auditability, management cannot learn from errors, compliance teams cannot investigate incidents, and boards cannot evaluate whether risk is being managed. This does not mean every agent interaction needs a board-level report. It means the company should have a reliable record when the action matters.

Measuring ROI Without Fooling Yourself

Boards also need discipline around measurement. AI pilots can produce impressive activity metrics: number of prompts, documents generated, hours estimated, tasks processed, or employees using a new tool. Those metrics may be useful, but they do not necessarily prove business value.

A better ROI discussion focuses on outcomes. Did sales cycles shorten? Did support resolution improve? Did finance close faster? Did product teams ship with fewer defects? Did customer churn signals surface earlier? Did managers make better decisions with less manual reporting? Did the company reduce risk or improve response time?

Adrian Vanzyl’s operating lens is useful here: activity is not the same as progress. Agents should be measured by whether they improve the system, not by whether they generate more work artifacts.

The Human Approval Line

One of the most useful board discussions is where the human approval line should sit. Some activities can be automated safely. Others require review because the cost of error is high. Boards should expect management to define which agent actions require approval before execution.

Common approval gates include external customer communication, legal commitments, pricing changes, payments, hiring decisions, financial reporting, production deployments, and any action that materially affects a customer or stakeholder. The exact list will vary by company, but the principle should be clear: the more consequential the action, the more explicit the control.

A Practical Board Framework

  1. Maintain an inventory of AI agents in use across the company.
  2. Classify each agent by autonomy level and business risk.
  3. Require least-privilege permissions and periodic access review.
  4. Ensure important actions leave an audit trail.
  5. Define human approval gates for high-impact actions.
  6. Measure agent ROI through business outcomes, not activity volume.
  7. Review incidents and near misses as part of the normal risk process.

Looking Ahead

AI agents will become part of normal company operations. Boards that treat them as a vague technology trend will miss both the opportunity and the risk. Boards that ask practical questions about permission, accountability, measurement, and control will help management move faster with more confidence.

For Adrian Vanzyl, the right board posture is neither fear nor blind enthusiasm. It is disciplined curiosity. Agents can create real operating leverage, but only when the company knows what they can do, who is accountable, and how success will be measured.