I bet you a dark chocolate Kit-Kat that, as individuals, your board and leadership team have not yet built anything with AI - nor do they get it.
Why would they? Building is somebody else's job.
But there’s a problem with that. You need a basic level of fluency in AI to understand the decisions, risks and opportunities you are responsible for. Fluency in AI comes from doing rather than from reading a paper.
Take this week's news as a test for the board.
SpaceX reported its first results as a public company. Revenue jumped 92%. Capital expenditure came in at $18.4bn for the quarter, more than double its sales for the same three months, with $15.8bn of that going into the xAI unit. The shares fell more than 8% when investors got the AI invoice jitters.
Wall Street is trying to get AI lending off its own books. JPMorgan, Morgan Stanley and others have been approaching investors about significant risk transfers, which move the riskiest slices of data centre loans into private credit, hedge funds and pension money. The Financial Stability Board noted that AI firms took more than a third of private credit deals in 2025, up from 17% over the previous five years. One Louisiana campus is funded by $3.25bn of bonds against a lease backed by Google, as part of a wider partnership with Anthropic.
And the machines had a bad week. The UK's AI Security Institute reported that Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol broke into third-party software and emailed real people to steal their credentials during a routine cyber evaluation. The FT, reporting the findings, describes it as among the first public examples of a cyber attack by an AI system operating outside human control.
Anthropic's Mythos 5 accounted for almost all of it and OpenAI's GPT-5.6 Sol for a couple.
From a board point of view, a director can read these, nod along and have no idea what they do to the risk register.
So question one today, folks, is: Is your board fit for purpose in this context?
Send the Kit-Kat's to the address below.
The Executive Summary AI Strategy Triangle
If you remember the AI Strategy Triangle, it shows safety at the bottom, productivity in the middle and value at the top.
The argument is, people are so desperate to show productivity and value they are missing fundamental safety, security, data governance and risk controls.

You can of course achieve the top two, but failing to understand the full context of risks and safety steps could see you sinking in quicksand in coming months.
Why am I being such a whin donkey about safety and risk when this newsletter is about growth?
Any company that has had to stop work to unpick a data leak, explain an agent to a regulator or re-do a rollout has lost more time than some of these checks would ever have cost.
A lot of readers of the Executive Summary are board members of listed and regulated companies.
Confidence comes from knowing what is underneath you.
Nuff said?
After my last article on cyber safety, several of you wrote in to ask for a risk register, so here is my back-of-napkin effort.
The Executive Summary AI Risk Register
(Use what you need. Kill what you don't. Improve what you can. This is designed to be basic and easy to use for anyone who doesn't have AI fluency).

1. Ownership and governance
- [ ] Named owner for AI safety, productivity and value, reporting monthly to the board
- [ ] A written AI policy every employee has seen
- [ ] An inventory of every AI tool and agent running, including the unapproved ones
- [ ] AI as a standing board item rather than a project update
- [ ] A written list of decisions that must always carry a human signature
2. Data
- [ ] We know which tools our people paste company data into
- [ ] Contracts not buttons stop our data training anyone else's model
- [ ] Residency and retention are documented for every AI tool in use
- [ ] Confidential material is blocked at source rather than by policy alone
- [ ] We can reproduce what a system was given and what it returned
3. Agents and cyber
- [ ] Every agent has an owner, an identity, permissions and an end date
- [ ] Agents are isolated and contained, with no route sideways into other systems
- [ ] We measure discovery to verified fix rather than counting vulnerabilities
- [ ] Finance controls assume our executives' voices can be faked
- [ ] We have tested what an agent could do if it ignored its instructions
- [ ] Agents have no choice in how they behave and are locked down by policy and working rules they have no control in changing
4. Models and suppliers
- [ ] We know which model is approved for which job
- [ ] We can be agnostic about our AI stack so we may switch providers easily
- [ ] We re-test when a vendor changes a model underneath us
- [ ] Every supplier has answered in writing the hacked-tomorrow question
- [ ] We know what AI arrived inside products we already bought
- [ ] We have an exit plan covering supplier failure and supplier outage
5. Legal and liability
- [ ] The broker has confirmed in writing that agent actions are covered
- [ ] Indemnities and liability caps read against AI-specific loss
- [ ] We know who owns the output our people create with these tools
- [ ] Our AI uses are classified against the regulation that applies to us
- [ ] Public claims about our AI match what we can evidence
6. Growth and pace
- [ ] We know what we spent on AI last year and what it returned
- [ ] Every department has a backlog with effort and value against each item
- [ ] One shared language on AI, from the board to the front line
- [ ] We have taken real work off real people and can name it
- [ ] We know what a competitor could do to us with these tools within a year
It's not easy
There will be several of these that throw a spanner in the works for you. For example, who owns the outputs or software made by the AI tool? Have you got indemnity insurance for work that was made by AI?
I haven't even done personal scam attacks using fake voices or videos.
Look at these too:
- The exit plan. Ask what happens if your main AI supplier fails and you will get an answer about switching models. Are you ready for that? Because if one goes bust, it could have a big impact not only on your tech but on the wider economy too.
- The agent inventory. Can you tell me how many agents are running in your business? They are arriving through developers, through tools people already had and through vendors adding them to products you bought years ago. Is an agent on Copilot the same as a custom-developed agent in an isolated unit? Do you know how to answer, 'oh ServiceNow just switched on AI by default,' or 'Is Adobe's new AI assistant that four people use in marketing taking data outside the organisation without us knowing?'
Have a great day and I hope it's useful to you.
Dan
If your leaders need to get fluent in AI fast, check out my AI fluency workshop] for leadership teams and boards. In less than day, you'll go from knowing nothing to using agents and making your own software tools.
Subscribe

