There is no cavalry coming to tell us how to govern AI. We are on our own.

In the United States, the federal government has made clear it does not want to set binding rules on AI. On July 17 I was in the room in Nashville when SEC Chairman Paul Atkins said essentially the same thing about his own agency. Securities regulators are dismantling disclosure rules, not adding new ones. Materiality means financial materiality, full stop.

You can agree or disagree with the doctrine. The consequence is the same either way.

No agency is going to define what good AI oversight looks like. No rule is coming that tells boards which committee owns it, what expertise the matrix needs, or when the risk crosses the line.

That means the last line of defense on AI is the board.

What boards actually have to do

Boards have to opine on strategies that will help their companies thrive in the AI era. They have to ensure defenses evolve as fast as AI-driven threats: what the STAR framework calls threat parity. And they have to make sure the risk budget is explicit: which risks the company runs to capture value, which are out of bounds, and who answers when something breaks.

None of that requires new board competencies. It requires applying the ones boards already have, strategy, capital allocation, and risk, in new conditions.

The uncomfortable part

A company can lose 10% of its value in a single trading session on an AI story. The market is already grading boards on this. It just does not send a syllabus first.

If no one is coming to set the standard, who on your board owns it today?