← All insights

BoardLens Briefing, 5 July

Expertise on tap, cloneable software moats, build versus buy from the GP's seat, and the audit committee's AI blind spot.

Raffaela Rein
· 7 min read

Reid Hoffman: what if everyone could afford an expert?

Employment for software developers under 26 has fallen by about a fifth since the fall of 2022, and in the first five months of 2026 tech companies explicitly cited AI in laying off 87,000+ employees, often to free up capital for AI infrastructure. On the opposite side stands the possibility of abundance: billions of people each carrying a designated AI health advisor, legal advisor and tutor, the way they now carry a smartphone. Expertise on tap.

The smartphone democratised knowledge, the facts, the maps, the prices. AI democratises expertise, knowledge operationalised and brought to bear on your specific situation, at the moment you need it. The threshold for engaging with your own interests drops by orders of magnitude.
Boardroom takeaway. Abundance and displacement arrive on the same wave, and boards have to govern for both at once. We see the job losses, but we also see the opportunity: an 84-year-old raising eight figures for a new AI company (see below), and an expert of any kind now living in your pocket. On strategy, watch any business built on expertise being scarce and rationed, healthcare, legal, education, advisory, where abundance lands first, as either the opening or the erosion. On people, ask whether your workforce plan treats AI as a headcount cut or a capability multiplier.

Bain is building AI replicas of its own takeover targets

Bain is stress-testing potential software-takeover targets by "vibecoding" AI replicas of their products, standing up a rough working clone with AI to gauge how defensible the real thing actually is. If a consulting team can build a passable imitation in days, the moat around that product's code is thinner than its revenue multiple assumes.

Durable value is migrating away from the software itself and toward what cannot be vibecoded: proprietary data, distribution, switching costs, regulatory position, brand.

Boardroom takeaway. For anyone underwriting software assets, GPs, corp-dev teams, and boards weighing build-versus-buy of their own systems, replicability has become a diligence question, not a philosophical one. Ask of any software target, and of your own crown-jewel products: if a smart team could clone this in a fortnight, what exactly are we paying, or charging, the premium for?

Build or buy, from the GP's seat

A seed fund triages inbound decks through ChatGPT. A growth team turns a founder's data room into a first draft of an IC memo with Claude. An associate builds a market map in minutes. The hardest thing about using AI on an investment team used to be getting anything to work at all; now that has flipped. Getting to something that looks like it works is the easy part. The hard part is making it actually work, maintaining it, getting a real edge from it, and staying fully compliant while you use it. It tends to come apart in three places.

  • What the models are built to do. These systems are built to give you the most likely answer, while much of a venture investor's job is to reach conviction the market has not reached yet. In Correlation Ventures' data on more than 21,000 financings, roughly 65% of deals returned less than the capital put in and only about 4% returned more than 10x. The edge is the deal the rest of the market mispriced. A tool that pulls every answer back toward the average is least useful in exactly the place where the dispersion you are paid to find is widest.
  • The data is not yours to expose. Much of what a fund handles belongs to someone else, a data room under NDA, a portfolio company's financials, an unannounced round, your LPs' information. IBM's 2025 research found ungoverned "shadow AI" was a factor in around one in five breaches, adding roughly $670,000 to the cost, with nearly two-thirds of organisations running no AI governance policy at all. Since January 2025, the EU's DORA rules make regulated managers formally accountable for the third-party tools they depend on, and LPs now expect that standard in operational due diligence.
  • A process you can show. A built tool is usually one person's undocumented prompt or script; when they leave, the method leaves with them. A GP has to demonstrate a process, not simply have one. So the differentiator is less whether you use AI and more whether the process behind the answer is one you would put in front of the people you raise from.
Boardroom takeaway. Build only what actually gives you an edge, and buy the rest. Every system you build carries a tail: maintenance, key-person risk, and potentially a compliance certification. The test is not whether AI is faster (it is); it is whether the output is defendable and independent enough that the view is yours, not the model's. Before your team's next AI build touches a live deal or LP data: conviction or consensus, whose servers hold the data, and could you show an LP how the answer was reached?
Reader poll

Your AI stack, where do you land?

  • Build
  • Buy
  • Both
  • No policy yet

The audit committee's blind spot, quantified

Geopolitical risk is back as the number-one concern among the companies surveyed (63% rate it high, up from 52%), yet risk management itself stays underdeveloped: only cybersecurity is being actively expanded (by 75% of companies), and fewer than half invest in three or more risk areas at all. Audit-committee chairs rank urgency as Cyber/NIS2/DORA at 92%, CSRD and supply-chain at 80%, the EU AI Act at 75%, and geopolitics/sanctions at 70%. The numbers come from a June event Deloitte's Center for Corporate Governance ran with the Financial Experts Association for audit-committee chairs.

The blind spot is the gap between those two facts: the risks rising fastest, AI, cyber, regulatory, are exactly the ones most committees are least equipped to oversee, and least likely to hear about in time. As the session put it, "no bad news" is the most dangerous signal a committee can receive.

Boardroom takeaway. This is the board-fluency gap made concrete, now with the EU AI Act running as a live compliance clock. The Deloitte checklist translates cleanly: put risk on the committee's own agenda rather than reacting to management's slides; secure a direct reporting line from internal audit to the committee; run at least one deep-dive a year on a top risk; and close the cyber/AI/ESG competence gap by design, not by hoping a sitting director grows into it. Simple test: if you cannot name the director who could cross-examine management on your AI Act exposure, that is the next seat to fill.
Reader poll

Could your board substantively challenge management on AI and cyber risk today?

  • Yes
  • Partly
  • No

Also this week

Anthropic accused Alibaba of stealing 29 million Claude conversations. Anthropic says Alibaba ran 25,000 fake accounts to mass-harvest nearly 29 million conversations out of Claude, the concern being that a rival was quietly siphoning Claude's outputs at scale, the kind of data you would use to train or sharpen a competing model, then took the evidence to the White House. The tell for investors: the only companies cleanly printing money this week sell memory and silicon, not models. The value keeps pooling in the physical layer.

Martha Stewart raised $10M at 84 for a new AI company. Her startup, Hint, is an AI home-management platform: it pulls public property data and your own documents (warranties, insurance policies) to flag problems like a leaky ceiling, an expiring policy or a creeping utility bill before they turn expensive. What pulled the round together is not the tech; it is 40 years of brand equity no competitor can replicate.

Read the full briefing on Substack →

Enjoyed this? Get the next one.

Subscribe to The AI Leadership Edge for new insights as they land.

No spam. One click to unsubscribe.