Langlotz.AI
Operating model

Your Next Chief of Staff Is Not Human. Build It First.

· 1970 words

One person now runs a hundred agents. Not in a lab and not in a demo. In rooms I have been sitting in. The bottleneck in that person's work is no longer how much they can produce. It is how much they can still be accountable for.

I have argued for a while that agents would come to outnumber employees. I did not expect one person to reach that ratio alone, and this fast. And in my May 2025 chapter in The AI Revolution, I made a narrower, dated prediction: that the hard problem for agentic AI in high stakes finance would not be capability, it would be accountability, who answers for what an autonomous system decides. Both are here now, faster and at a scale I did not price in. When one person commands a hundred agents, accountability stops being a clause in a policy and becomes an architecture problem.

So the question a board should be asking is not whether agents will proliferate. That is settled. It is who stays accountable when they do. The answer the frontier is quietly converging on has a deceptively soft name: the Chief of Staff.

Agent adoption has three thresholds, and each asks a different question

Most people are staring at one threshold and missing the other two.

Zero to one. Can you trust a single agent? This is the question the first agent through to production lived in: model risk, human in the loop, a clean audit trail, a low risk rating earned by design. Hard, but bounded, and far better understood than what comes after it.

One to a hundred. Can you stay accountable when you can no longer supervise directly? A person cannot review the work of a hundred agents. Do it anyway and you become the bottleneck. Stop and you lose control. This threshold is where most of the excitement is, and where I see the least governance thinking.

A hundred and beyond. Can the enterprise stay aligned when every person has their own fleet? This is the threshold I have yet to see an institution genuinely reach, and it is the one that decides whether an institution is governed or merely fast.

The Chief of Staff is the answer to the middle threshold, and it is the thing you have to build before the fleet, not after.

The Chief of Staff is a governance object wearing a productivity name

The program I am part of introduces the Chief of Staff agent through productivity: your agents produce so much that you become the bottleneck, so you build one agent to orchestrate the rest. That is true, and it is the fastest way to make the idea land. It is also the smaller half of what the thing actually is. The larger half is governance.

The Chief of Staff is the point where accountability concentrates. When a hundred agents act, responsibility cannot be spread across a hundred loose threads. It has to attach to a single owned place, or it evaporates. The Chief of Staff is that place: the one node a named human stands behind, the one seat that answers for everything downstream. It restores span of control. It becomes the point where the organization's rules get enforced across the fleet. And it gives a human a way to stay accountable for more work than they could ever personally inspect.

That is why you build it first. It is the same law at the human level, where the hire that matters is the one who can make yes safe, made before you hire the people who ship. Build the layer that can say no and owns the outcome before you build the capability that acts. The organization that scales its fleet before its Chief of Staff is the organization that hired builders before governance. It produces enormous capability with no one accountable for what it does.

A hundred well run private kingdoms is not a governed institution

Here is where it gets harder.

In an enterprise you do not have one Chief of Staff. You have hundreds, one per person or team, each orchestrating its own fleet. If each is built the way the frontier builds them today, by hand, by whoever is standing there, then each one interprets governance its own way. Every individual feels in perfect control of their own fleet, and the enterprise as a whole is governed by no one.

That is the failure mode a board should be able to picture, because it is invisible from every dashboard the board currently reads. Nothing is broken. Every local owner is diligent. There is no incident to report. The institution simply has no single answer to what its agents are allowed to do, and will not discover that until the day it needs one.

A file the user can delete is not a control

The obvious fix is a shared standard that every Chief of Staff inherits, a common profile the agents are built on top of. I raised exactly this with the people teaching me the frontier, and the sharpest answer came, fittingly, from one of the program's own agents: a shared profile can distribute a baseline, but a file sitting in a user's own workspace is not a control an enterprise can rely on. The person owns the file. They can edit it, or quietly delete it.

That distinction is the whole design problem. A baseline you distribute is a suggestion. A control is something the user cannot switch off.

I hit this building my own Chief of Staff. My agent wrote one of its operating rules into a file that gets replaced whenever the underlying package updates. I only caught it because I went looking during an audit. Nothing had broken and nothing had alerted. Had I not checked, the rule would have been gone at the next update, with no record that it had ever been there. The rule does not break. Nobody is told it is gone.

So the enforceable layer cannot live inside the agent a person controls. It has to sit outside it, in a corporate control plane. In practice that means identity and device controls; gateways that constrain which tools and actions an agent can actually take; policy bundles that are signed and versioned, so you know which rules are running; drift checks; and an audit trail. The individual Chief of Staff carries the local profile. The control plane verifies and constrains what that profile is allowed to do.

A colleague in that program, who builds this for a living, put the current state of the market plainly: today enterprises either set people free inside their AI tools and accept the sprawl and the loss of control, or they centralize everything and lose the personalization that made the agents useful in the first place. Nobody has the third thing yet, the one that gives you both.

If that sounds familiar, it should. The enterprise answer to the Chief of Staff is a control plane, and a control plane still needs an agreed standard to enforce. Build the plane without the standard and every one of them enforces a different idea of what good looks like.

And there is a quieter failure underneath the live one: continuity. When the person leaves, the fleet they built on their own account, on their own laptop, leaves with them. Workflows that ran part of the business on Monday are gone on Friday, with no handover and no record. For a regulated firm that adds a legal edge, because the same ungoverned setup that loses knowledge when someone walks out is the setup that cannot answer a retention or discovery request when a regulator or a court asks.

Which is the part that belongs on a balance sheet. An agent estate that nobody can inventory is not an asset the institution owns. It is a position it is carrying. The productivity books this quarter, visibly, in someone's objectives. The exposure books whenever it books, and you find out the size of it on the day somebody asks.

You cannot mandate this, and banning it is worse

I have made the provision argument before, about the shadow AI already on your balance sheet: you do not ban your way out, you make the governed path the fast path. It holds here too, for a worse reason.

When orchestration becomes this easy, people build their own. Tell them a homemade Chief of Staff is not allowed and they build one anyway, quietly, because it makes their work better today. But an unsanctioned orchestrator is not the same risk as an unsanctioned tool. A shadow tool does one thing badly. A shadow orchestrator inherits its owner's privileges and then directs everything downstream of them. It is not a gap in the estate. It is an unmonitored actor with delegated authority, and it is faster than the people who would have caught it.

So you fix it the way you fix any shadow system, with more urgency than the last time: you ship a governed Chief of Staff, wired into the control plane, and you make it better than anything a person would build for themselves. Governance by provision, not by prohibition. If the sanctioned path is the fast path, the standard spreads because people want it. If it is slow, they route around it and your alignment is a fiction you tell the board.

I put it this way in that May 2025 chapter: determining responsibility for decisions made by agentic AI systems presents complex legal and ethical challenges, particularly in high stakes financial operations. What I did not yet see was that the answer would look like an org chart made of agents, with a human accountable at the top of each one, and a control plane above all of them holding every one to a standard the enterprise sets and none of them can quietly edit.

Three questions to answer before you approve a fleet

If you carry risk in a regulated institution, the three thresholds are not abstract. They are a sequence you are already somewhere inside, whether or not anyone has told you. These are the questions that locate you, and they should be answerable cold.

1. How many agents are running against our systems today, who authorized each one, and which named human answers for what they do? 2. If one of our people left on Friday, which of the workflows they built would still be running on Monday, and could we produce a record of what those workflows did? 3. When we change a rule, how do we know it reached every fleet, and how would we know if someone edited it back?

If the first answer is a number nobody can produce, you are past the first threshold without having governed it. If the second is no, you have a continuity and discovery problem before you have an AI problem. If the third is a file you hope people keep, you do not have a control. You have a convention.

The one decision underneath all of this

The Chief of Staff will not stay a novelty. I would expect most people doing serious work to have one within a couple of years, whether the enterprise sanctioned it or not. Treat the timeline as a guess. The direction is not. The orchestrator will become the most powerful actor in the building, because it is the one thing that can direct everything else.

Whether accountability is attached to it, and whether it answers to a control plane it cannot edit, is the whole game. Get it right and you have an institution that can move at the speed agents allow and still answer for what they do. Skip it and you have a hundred fast, private, ungoverned fleets, an exposure nobody has priced, and a board that believes it is in control.

Build the Chief of Staff first. Then build the thing it answers to, before you have a hundred of them answering to no one.

If you sit on a board or carry risk: of the three questions above, which one would your institution struggle with most today, and would you say so out loud in the meeting?