Every board TSP has watched respond to an AI failure elsewhere goes through the same first instinct: get closer to the risk. Add a standing agenda item. Ask for more frequent updates. Read the vendor contracts personally instead of trusting the summary memo. None of this looks like a mistake while it is happening. It looks like diligence.
The pattern only becomes visible later, and only from a specific vantage point: the moment a director stops asking whether the AI oversight architecture is sound and starts asking which model version is deployed in which workflow. That is not a governance question. It is a management question, asked by the wrong person, in the wrong room.
TSP has watched this sequence enough times to describe it precisely. A board grows uneasy about an AI system it does not fully understand. Rather than demand a named owner, a documented threshold, and a review cadence it can hold someone accountable to, the board begins reviewing the thing itself. Model selection comes to committee. Vendor paperwork gets redlined by directors instead of counsel. A quarterly briefing becomes a monthly one, then a standing item that consumes forty minutes of every meeting. The board has not become more rigorous. It has become a second engineering review, staffed by people who were never meant to hold that job and who have no time to do it well.
Here is the law underneath what TSP has observed.
TOUCH STONE LAW: The Law of the Borrowed Wheel *A board that takes the wheel to prevent a wreck has already caused one.*
The origin of this law is not a single company. It is a composite, drawn from the pattern TSP has watched recur across boards responding to AI risk in the last two years: healthcare systems reacting to a clinical-decision-support scare, energy boards reacting to a permitting dispute, financial services boards reacting to an examiner's letter. Different triggers. Same failure shape.
The mechanism is straightforward once it is named. A board exists to set the standard and to hold one person, the CEO, accountable for meeting it. That is the entire job. The moment a board starts making the operational calls a management team was hired to make, it has not added a layer of safety. It has removed the only person who was supposed to be answerable for the outcome. If the board picked the vendor, the board owns the vendor's failure. If the board approved the deployment window, the board owns the timing. Accountability does not survive contact with a shared decision. It evaporates.
This is the Governance Boundary Principle in its sharpest form: the board governs, management manages, and the organizations that fail are not the ones where the line was crossed once, dramatically. They are the ones where it eroded one reasonable-sounding exception at a time, until no one could say with a straight face who was actually running the AI program.
The cost is not abstract. TSP has watched the executive team of a composite organization in this exact position lose two senior technical leaders inside eighteen months, both citing the same reason on the way out: they were being second-guessed on decisions inside their own competence by a board that had stopped trusting the accountability structure it built. The board did not gain control. It lost the people who could have executed the standard it claimed to want. What remained was a governance body reviewing PDFs it did not have the technical grounding to evaluate, and a management team that had learned not to bring hard problems forward, because bringing them forward meant losing the authority to solve them.
The application is not complicated, which is exactly why it gets missed. A board facing new AI exposure has one job at the moment the unease sets in: resist the urge to get closer to the machine, and get closer to the accountability conversation instead. Name who owns the oversight standard. State, in one sitting, what evidence that person must produce and on what cadence. Then hold them to it, in the boardroom, not in the model registry. The board that does this well never touches a vendor contract. It also never has to.
The alternative is not caution. It is a slower version of the same failure the board was trying to prevent, now with the board's fingerprints on it.
A board that builds this discipline before the next AI incident, rather than after one forces the question, leaves its successors something specific to inherit: a CEO and an executive team who know exactly what they are accountable for, and a board that never had to learn where the line was by crossing it. Built from conviction rather than crisis, not a paper trail. A company that keeps running the standard correctly long after the directors who set it have moved on, because the people beneath them were never asked to give up the job of running it.