Leadership · 4 minute read
How to Write an AI Memo to the Board
An AI memo to the board should fit one page plus an appendix, lead with outcomes against baselines, state the inventory and risk position, report incidents plainly, name the decisions requested, and avoid technology explanation. Directors need enough to oversee, not enough to build.
Board memos on AI tend to fail in the same three ways: too long, too technical, and too optimistic. Directors then either disengage or ask questions that reveal the memo did not answer what they needed. This guide gives a structure that works, the numbers directors actually need, and how to handle problems credibly.
What is the structure?
One page, in this order:
- Outcomes (three to five lines). For each committed deployment: the process, the baseline, the current figure, and the trend. Numbers, not adjectives.
- Portfolio and inventory (two lines). How many agents are in production by risk tier, what changed this period, what is coming next.
- Risk and controls (three lines). Evaluation status for material systems, autonomy changes made and the evidence, vendor concentration, and any appetite breaches.
- Incidents (two lines). What happened, how it was detected, what changed. "None this period" if true, with a note on detection capability.
- Regulatory (one line). Developments that affect the company, and readiness.
- Decisions requested (explicit). What you want the board to approve, note, or discuss.
Everything else goes in an appendix. The how to report AI progress to the board guide covers the reporting structure this memo summarizes.
What numbers do directors need?
| Number | Why directors need it |
|---|---|
| Baseline, current, trend per outcome | Whether the program produces results |
| Agents in production by risk tier | Scale and risk concentration |
| Evaluation pass rates for material systems | Whether quality is measured at all |
| Incidents and time to detection | Whether problems are found by the company or by customers |
| Cost: build and run, with cost per task | Whether the economics work |
| Vendor concentration and tested alternative | Dependency exposure |
Directors do not need model names, architecture diagrams, or a description of what an agent is, beyond an annual education session. The board director's guide to AI and agentic AI covers what that session should convey.
What should be left out?
Technology explanation beyond a sentence. Pilot counts. Tool adoption statistics. Vendor names except where concentration is the point. Roadmap slides. Anything that would not change a director's assessment of whether the program is working and controlled.
The test for each line: would a director act differently if this line said something else? If not, it belongs in the appendix or nowhere.
How should problems be reported?
Early and plainly. State what happened, when it was detected and by whom, who was affected, what was done, and what changed as a result. Do not minimize, do not blame the technology, and do not wait for the next cycle if the matter is material.
Two dynamics make this the right approach even when uncomfortable. First, directors respond far better to a problem management reported than to one they hear about elsewhere, because the first demonstrates control. Second, a program that never reports problems is assumed to be either lucky or concealing, and both assumptions damage credibility more than the incident would have. The AI oversight and fiduciary duty piece covers why the record of reporting matters.
Why must the format stay identical?
Because directors read across periods. When the same six sections appear in the same order with the same metrics, a trend is visible at a glance and a change is noticeable. When the format changes each quarter, directors cannot compare, and a reformatted memo is often read as an attempt to reframe bad numbers, fairly or not.
Who should write it?
The accountable executive, from management's own review rather than as a separate exercise. A memo assembled specially for the board, containing numbers management does not review monthly, is a warning sign that the program is managed for reporting rather than for results. The AI operating rhythm for leadership teams guide describes the review the memo should derive from.
What belongs in the appendix?
The evidence a director might want to check: evaluation results with dates and case counts, the full inventory with owners and permissions, incident reports, the cost breakdown by build and run, vendor terms relevant to concentration, and the regulatory mapping. Directors rarely read appendices, and that is fine: their existence means the memo's claims are checkable, which is what makes the one-page summary credible. A memo with no supporting detail invites questions that could have been pre-empted; an appendix nobody opens has still done its job.
What should executives ask themselves before sending?
- Does every line change what a director would think or do?
- Is the leading item an outcome with a baseline, or an activity?
- Have I named the decisions I want, or left them implicit?
- Would this memo look consistent beside last quarter's?
- Have I reported the thing I would rather not mention?
How can FISTA Solutions help?
FISTA Solutions helps executive teams produce the evidence a board memo requires, baselines, evaluation results, incident records, and cost per task, through its AI enablement practice, and builds AI agents that generate that evidence as a by-product of running. Since 2017, FISTA has delivered 150+ projects for 50+ companies across 12+ countries.
To build a reporting pack your board can read in five minutes, talk to FISTA on WhatsApp, or read the executive guide to AI agent governance.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01What should an AI board memo contain?
Outcomes against baselines for committed deployments; the inventory by risk tier and its changes; evaluation evidence for material systems; incidents and remediation; vendor concentration; regulatory developments affecting the company; and the specific decisions being requested. One page, with detail in an appendix.
02How long should a board AI memo be?
One page for the memo itself, with an appendix for supporting detail. Directors read many papers; a page they finish is worth more than five they skim. If the content cannot fit, the structure is wrong or the program lacks the clarity to summarize itself.
03Should AI board memos explain the technology?
Rarely, and never at length. Directors need to oversee, not build. Brief technology explanation belongs in an annual education session or an appendix, not in the regular memo, which should be about outcomes, risks, controls, and decisions.
04How should bad news be reported to the board about AI?
Early, plainly, with the facts, the cause, the remediation, and what changed as a result. Directors respond far better to a problem reported by management than to one discovered elsewhere, and a program that never reports problems is assumed to be either lucky or hiding them.
05How often should the board receive an AI memo?
Quarterly for most companies, derived from management's own review rather than prepared separately, with immediate escalation of material incidents outside the cycle. Monthly is appropriate where AI is central to the business or during a period of significant deployment.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.