Skip to main content

The first decision: your 90-day AI priorities memo for your own organization (and why you will revise it in shame later)

The short answer

The memo is your first command act

A 90-day AI priorities memo turns your AI systems inventory into a decision you own. It is the moment you stop collecting information and start being accountable for a choice, which is what Topic 0.1 said makes the expert. (see Topic 0.1)

What you will be able to do

  • Write a 90-day AI priorities memo for your own organization that names at most three priorities, each with a decision, a named owner, a deadline, and a falsifiable success criterion.
  • Distinguish a priority (a choice made among competing goods) from a wish list (everything anyone wants), and defend why your memo has a short de-prioritization list.
  • Build the memo directly from the AI systems inventory you produced in Topic 0.2, choosing which system to govern first by consequence, not by convenience. (see Topic 0.2)
  • State for each priority the single result that would prove the decision wrong, so the memo can be tested rather than admired.
  • Classify each decision as a reversible ("two-way door") bet or a hard-to-reverse ("one-way door") commitment, and explain why a 90-day memo should favor reversible bets.
  • Assign clear accountability: every priority in the memo has one named owner and a date, because a decision with no owner and no date is a hope, not a decision.
  • Anticipate the attack: predict which line of your own memo a hostile reviewer will hit first, and pre-answer it in the document.
  • Diagnose a weak memo by recognizing the five failure patterns (the everything memo, the mood memo, the orphan memo, the undated memo, and the silent-tradeoff memo) and naming the fix for each.
  • Connect the memo to your accumulating dossier: explain where this artifact is attacked (Module 11) and revised (Module 13), so you write it today as a first-class record, not a throwaway exercise.

The lesson

On May 1, 2023, IBM chief executive Arvind Krishna sat for a Bloomberg interview and said out loud what most executives only think in private. This chart shows his exact proposal. He stated IBM would pause hiring for back-office, non-customer-facing roles, projecting that nearly 30% of those jobs, roughly 7,800 positions, would be replaced by AI and automation over the next five years.

Look at what Krishna didn't do here. He didn't commission an exploratory study, he didn't form a committee to look into the implications of AI, and he certainly didn't publish a 50-slide deck of generalities. The default behavior for most corporate leaders is to stay perfectly safe.

They collect information perpetually, they write long wish lists where every department gets AI, and they present those lists as strategies. Leading your organization's AI adoption requires you to stop spectating and start deciding. The tool to force that transition is the 90-day AI priorities memo.

It is your first command act, a short, checkable document that turns an inventory of ideas into a concrete choice. A proper 90-day AI priorities memo is strictly one to two pages long. It does not contain themes, intentions, or moods.

It forces you to choose exactly what you will spend your scarce attention on right now. This sorting matrix illustrates the first rule of the memo, rank by consequence, not by volume. You might have constant requests for a visible customer chatbot, placing it high in volume, but a quiet, high-stakes system like a resume-ranking hiring AI sits at the very top for consequence.

If you govern the loudest system first, you spend your resources preventing minor customer annoyances while leaving real legal exposure completely ungoverned. You have to govern the system whose failure hurts actual people the most. The second rule is numerical.

Your memo will contain a maximum of three priorities, never ten. A list of ten priorities means you have refused to make a trade-off. Spreading a budget that thin guarantees nothing actually moves.

Constraining yourself to two or three items stops scope creep and forces you to allocate resources where they matter. Rule three dictates that you favor two-way doors. This is a framework for measuring the reversibility of your decisions.

Looking at this flowchart, the path ending in a locked block is a one-way door, like signing a three-year enterprise AI contract. The path that loops back is a two-way door, like running a bounded pilot with a single team and a strict stop condition. A 90-day window requires two-way doors because your organization is still learning.

You need to run tests, gather new data, and be able to reverse course cheaply when the world teaches you something unexpected. Rule four requires every item on your list to carry three specific marks, falsifiable, owned, and dated. These are the mechanics that separate a testable decision from an unactionable mood.

Falsifiable means the priority includes a proves wrong condition. You must name the exact metric, derived entirely from your own internal data, that would force you to stop the project and admit it failed. Owned means assigning accountability to one named human, because a priority owned by a committee is a priority owned by no one.

Dated means setting a hard deadline inside the 90-day window. If a priority lacks any of these three marks, it cannot be failed, and a decision that cannot fail cannot teach you a thing. Rule five brings us to the hardest part of the document, the deprioritization list.

This is the section where you record what you are explicitly choosing not to do. This logic tree separates your active bets from the systems you've set aside. Every item in the no column must include the reason it waits, and the specific risk your organization accepts by making that choice.

By naming the trade-off out loud, that risk flag becomes a shielded, defensible record of your leadership logic. If a deprioritized system causes an incident, the memo acts as evidence of a considered trade-off. It proves you weighed the risk and made a documented choice, whereas a silent omission leaves you with no record of why the system was ignored in the first place.

Anyone can say yes to everything. Explicitly documenting what you will not do is the proof that a hard executive choice actually took place. When your 90 days are up, the bill comes due.

You have to check your priorities against reality. Sometimes a proves wrong condition will fire. This brings us to the final discipline, revising without shame.

Adjusting your plan because a falsifiable test caught an error is the entire goal of the process. It is not an embarrassment. To see this in action, we can return to Arvind Krishna's bold 2023 statement and jump forward to IBM's reality in May 2025.

This chart compares the projection to the outcome. By 2025, IBM's AI automated about 94% of routine HR tasks, but the massive block of 7,800 lost jobs didn't materialize. Instead, they actually replaced a couple hundred roles.

Total IBM employment actually rose. The chart shows the reallocation of resources. As routine tasks were automated, IBM funded thousands of new roles for programmers and sales staff, leading to $3.5 billion in productivity gains.

The reality of 2025 was messier than the 2023 headline, but the initial bet gave the organization the structure it needed to execute, measure the outcome, and adapt to the truth on the ground. Writing a 90-day priorities memo strips away the safety of endless research. It forces you to stop spectating from the sidelines, put your name on a specific choice, and become an accountable commander.

The ideas, one by one

Two or three priorities, never ten

A priority is a choice made among competing goods. A list of ten priorities is a confession that nothing was chosen. If the memo does not fit on one page, you have written a wish list, not a decision.

Every priority carries three marks

Falsifiable (it names the result that proves it wrong), owned (one named person, never a committee), and dated (a real date within ninety days). A line missing any mark is a mood, not a decision.

Rank by consequence, not by volume

The first system you govern should be the one whose failure reaches real people and real law, even if leadership is louder about a lower-risk system like a chatbot. Consequence over convenience. (see Topic 5.3)

The de-prioritization list is the real memo

Naming what you will not do this quarter, with the risk you accept by waiting, is what makes your priorities real and your choices defensible when they are attacked. An empty "not doing" list means you have not chosen.

Favor two-way doors

In ninety days you are still learning your AI estate. Prefer reversible bets you can undo cheaply over one-way-door commitments (long contracts, public promises) that lock you in before you understand them.

Expose the memo to attack before a critic does

Predict the sharpest objection to your own memo and pre-answer it on the page. The line you judge weakest is the line Module 11 is most likely to hit. (see Topic 11.1)

Revision is the goal, not the shame

A real decision commits you, then teaches you. IBM's 2023 projection was revised by 2025 reality, and the organization was better informed for it. The mild wince of rereading your first memo is the felt sensation of having learned something checkable.

The artifact persists

This memo is not an exercise you discard. It comes back in Module 11 to be attacked and in Module 13 to be revised as the opening page of your command dossier. Keep it exactly as written today. (see Topic 13.1)

A falsifier is confidence, not doubt

Naming the result that would prove you wrong does not make you look uncommitted; it makes you trustworthy, because only someone sure of their reasoning is willing to say in advance how they would know they were wrong. The memo that hides its failure conditions is the timid one.

Never carry a vendor's number as your own fact

If a priority rests on a supplier's savings or accuracy claim, make verifying that claim the falsifier itself, and measure real success against your own data once the tool is running. Borrowed numbers are how defensible memos become indefensible under scrutiny.

You read it. Now prove it.

Explain this lesson in your own words, the way you would to a colleague, without looking back at it. It is graded against the lesson itself, by the same grader our learners face. One free try a day, no account needed.

The conversation

The same lesson, talked through at length by two hosts: the full transcript of the audio deep dive.

Listen to it as episode 4 of the podcast.

Read the full conversation

On May 1st, 2023, the chief executive of IBM went on television and did something that, well, usually gets Fortune 500 leaders fired. Right. He made a massive, highly public prediction.

Exactly. And one that could be proven entirely wrong. I mean, during this Bloomberg interview, Arvind Krishna stated that IBM was going to pause or slow down hiring for back-office, non-customer-facing roles.

And he didn't just hint at some vague AI transformation, you know. He put a hard number right on the table. Yeah, he predicted that nearly a third of those specific jobs, which was roughly 7,800 out of 26,000 positions, would just be replaced by AI and automation over the next five years.

It's wild. He named a time frame, a specific class of work, a hard head count, and he basically attached his personal reputation to it right in front of the global market. The audacity of that moment really can't be overstated.

No, it can't. Because if you look at the standard playbook for executive communication, especially when we're talking about emerging tech, the goal is almost always to maximize enthusiasm while minimizing any real accountability. Right.

You form a committee. Exactly. Leaders form committees, or they release these vague statements about, you know, exploring synergies or mapping the implications of machine learning for the workforce of tomorrow.

They go out and buy a 50-slide strategy deck from some consulting firm that basically just offers a painting of clouds. But Krishna bypassed all of that. He did.

He established a falsifiable baseline. The world and his own board of directors could simply wait and check the math. And the fascinating part is that the world didn't even have to wait the full five years to audit that decision.

By the May 2025 Think Conference, and this was reported via the Wall Street Journal Reality, had completely revised the headline. Oh, totally. The deployment of AI within IBM's HR department was practically staggering in its technical success.

Their Ask HR agent ended up automating something like 94% of routine HR tasks. But when it came to the actual headcount, it only replaced a couple hundred roles. I mean, nowhere near the 7800 prediction.

Right. And what's the ultimate twist there? Total IBM employment actually increased. Yes.

Because the resources freed up by that back office automation were reinvested into hiring more programmers, more salespeople. And that reinvestment drove, what was it, $3.5 billion in productivity improvements. Yeah, across more than 70 operational areas.

So the instinct for a casual observer here is to look at the 2023 prediction compared to the 2025 reality, and just declare that the CEO missed the mark. You know, the number was wrong, therefore the strategy failed. But evaluating governance through that lens is just a fundamental misunderstanding of how effective leadership actually operates under extreme uncertainty.

I mean, Krishna's 2023 declaration wasn't a failure just because the numbers changed. It was honestly a masterclass in executive command because he committed the organization to a very specific vector. And by doing that, he allowed the real world to teach the organization.

The operational direction held firm. They automated the back office. Exactly.

The specific figures were just revised by reality. That is the anatomy of a real decision. It commits you, and then it teaches you.

Which brings us to the core mission of our deep dive today. We're looking at a stack of sources designed to equip you, the sharp, busy professional, the governance leader, the executive, with the exact framework to transition from passively gathering AI information to actively commanding your organization's AI strategy. Because if you're listening to this and you're looking at your own company's endless risk registers, the pilot programs, the vendor pitches.

You're probably realizing you have a ton of activity, but very few actual decisions. Precisely. So the goal of this discussion is to give you the blueprint for drafting a singular, decisive document, which is the 90-day AI priorities memo.

We are stripping away all the theoretical futures today and focusing entirely on the operational mechanics. This is where high-level Harvard business review theory meets the unforgiving reality of a Monday morning leadership meeting. Your time and your organizational capital are scarce, so we're going to deliver the precise framework necessary to take control of your AI estate today.

Our sources structure this framework around a very specific spine. We're going to examine the six core rules of drafting your 90-day AI priorities memo. And I want to list them right out of the gate.

Go for it. They are, the memo is your first command act. Two or three priorities, never 10.

Every priority carries three marks. Ranked by consequence, not by volume. The deprioritization list is the real memo.

And finally, favor two-way doors. Master these six and you transition from being a spectator of AI hype into a real governor of AI reality. And that transition really begins with understanding why IBM's move worked while so many other corporate AI initiatives just stall out.

Krishna didn't study the AI landscape until he felt perfectly comfortable. He acted. Which introduces our first foundational rule.

The memo is your first command act. Right. In the context of enterprise governance, gathering information just keeps you perpetually in the beginner phase.

Deciding is what makes you an expert. Let's define the physical reality of this document, because we are not talking about a comprehensive 50-page strategy portfolio here. No, absolutely not.

A 90-day AI priorities memo is a one, maybe two-page document. It answers exactly five questions, plainly, with zero technical jargon masking a lack of business logic. And those five questions are, what are the two or three priorities? What exactly will we do? Who owns it? And when is it due? How will we know it worked and what proves it didn't? And the last, most crucial question, what are we deliberately not doing? That document sits above the risk registers.

It sits above the data privacy policies and the acceptable use guidelines. It's the absolute tip of the spear dictating exactly where your finite attention and budget will be allocated for the next quarter. The time horizon here seems like the most vital engineering choice in this whole framework.

Why exactly 90 days? The 90-day window is perfectly calibrated to force a measurable rhythm. Because if you attempt a 30-day sprint in enterprise AI governance, you're going to fail. 30 days is really only enough time to complete tasks, not to execute actual decisions.

Like, you can schedule a vendor meeting in a month. Right. Or you can draft a policy.

But you cannot run a meaningful pilot, or audit a complex system, or extract any real signal from the noise in 30 days. 30-day memos just devolve into glorified to-do lists. But the danger on the other end of the spectrum seems even worse to me.

I mean, the traditional corporate reflex is to build an annual operating plan, right? Oh, an annual AI plan is just a documented illusion at this point. If you set a 12-month priority, there is no proximate checkpoint to hold the owner accountable. The mandate just drifts.

Because the technology moves so fast. Exactly. By the time month 11 rolls around, both your organizational needs and the external AI landscape have fundamentally mutated.

So the failure conditions you set a year ago aren't even relevant anymore, which means they never get checked. 90 days gives you enough runway to run a bounded pilot or implement governance, but it keeps that review date visibly close. That proximity is what keeps the organization honest.

Experienced governance leaders use a mental model here that the sources call the Decide-Date-Expose-Revise loop. It's a fantastic model. You decide where the consequence lies.

You date the action. You expose the decision by explicitly writing down how it could be proven wrong. And then, and this is the phrase that really anchors the whole concept, you revise in shame later.

I love that phrase, revise in shame later. It sounds so self-deprecating. It does, but it's actually a highly sophisticated governance feature.

Think back to the IBM scenario. When you reach day 90, you place your memo next to the actual data your organization generated, that mild wince you feel when rereading your initial assumptions. That is the literal physical sensation of having learned something checkable.

The only executive who never feels that specific embarrassment is the one who never committed to a measurable outcome in the first place. I want to channel the anxiety I see in boardrooms when this concept gets introduced, though, because the immediate pushback is almost always about the map. Oh, the map, yes.

A leader will say, I have dozens of legacy systems. I have a massive shadow IT problem with employees using unauthorized generative AI on their phones. I don't fully understand our data architecture.

So, if I know I'm going to have to revise this memo in shame, shouldn't I commission a comprehensive audit first? Shouldn't I wait until I have a complete map of my AI estate before committing to anything? That desire for a complete map is probably the most common trap in modern leadership right now. Waiting for full comprehension before acting is a psychological comfort mechanism. It's not a strategy.

The field of AI is accelerating faster than any internal study you can commission. So the map is basically obsolete the moment it's printed. Exactly.

The 90-day memo is intentionally short, precisely so you can decide before you achieve certainty. You let the result of a short-term, bounded decision teach you about your own estate. The trap is believing that waiting is a neutral state.

Which it isn't. No, waiting is a decision. It's the active choice to remain vulnerable to unmitigated risks while your competitors are out there accruing real operational data.

It shields you from short-term criticism because, well, you haven't made a falsifiable claim yet, but it practically guarantees long-term strategic failure. So if the goal is to make a decision that cuts through all that noise, you have to acknowledge that you simply can't command everything simultaneously. The constraints of reality demand ruthless limitation.

Which brings us to the second rule, two or three priorities, never ten. The etymology of the word priority is highly instructive here. It comes from the Latin prior, meaning first.

For centuries, the word existed only in the singular. You could only have one prior thing. Right, there were no priorities.

Exactly. It was only in the mid-20th century, right alongside the explosion of corporate management culture, that we decided to pluralize the word and somehow convince ourselves we could bend reality to accommodate ten first things at once. When an executive publishes a memo with ten priorities, they haven't actually made a strategy.

They've published a confession. That is so true. They're basically confessing that they lacked the political capital or the analytical rigor to make a hard choice.

A list of ten priorities is just a wish list. And a wish list sounds uniformly positive, right? We will adopt AI to drive revenue, upskill our workforce, optimize our supply chains, ensure perfect ethical compliance, and cut operational costs. Every stakeholder in the room nods in agreement because every item is a perceived good.

But no actual decisions have been made because nothing was sacrificed. Precisely. A true priority only materializes when you name what it defeats.

You have to be able to say, we are allocating our top engineers to govern the hiring algorithm, which means the customer service chatbot will not receive any technical support this quarter. I use a mental model for this called the reversal test. It's the fastest way to identify whether an organization has a real priority or just a slogan.

If you write in your memo, we prioritize responsible and ethical AI. You have to ask yourself, could a rational competitor publicly state the exact opposite? And of course, no company is ever going to release a press statement claiming, we prioritize irresponsible and unethical AI. Right.

Because the opposite is absurd. Your statement isn't a decision. It's a mood.

It's corporate wallpaper. However, if your memo states, we will not deploy any generative AI feature to our client-facing platform until it successfully passes our internal red team test suite, well, that passes the reversal test. Because a competitor could rationally argue the opposite there.

They could say, we believe in speed to market. We're going to ship the beta version immediately and patch vulnerabilities based on live user telemetry. Exactly.

Because the opposite is a viable business strategy. Your statement represents a real strategic choice. And that reversal test forces you to strip away all the vanity metrics.

Once you apply it, you start to realize that most strong defensible first priorities fall into a few specific proven shapes. Recognizing these shapes really helps leaders operationalize their intent. The sources outline five distinct shapes that a priority can take in a 90-day memo.

Let's break down the mechanics of each one. The first is the stop until proven shape. Right.

This priority looks like a deliberate roadblock. It basically states, we will halt the use of system X until it passes a specific internal validation check. When would you use that? You deploy the shape for high consequence systems where trust hasn't been earned yet.

So, for instance, an algorithmic credit scoring tool or maybe an AI determining industrial safety protocols. The failure condition is straightforward. If the system fails the internal check, it stays off.

It's an excellent defensive priority because it halts immediate harm while providing a clear path back to reinstatement once the tech actually proves reliable. Got it. The second shape is the verify the vendor priority.

Which is critical in the current market environment. This priority reads, we will audit vendor-wise core claims regarding their AI application and trace the provenance of their training data. Because so much software right now is just marketing hype.

Exactly. You utilize this when your organization is adopting third-party software because a vast amount of so-called AI-powered enterprise software is essentially just a thin wrapper around a generic language model heavily disguised by slick sales pitch. This shape is designed to prevent you from absorbing a vendor's unverified marketing claim as a foundational fact in your own operations.

The third shape is the bounded pilot. The bounded pilot states, we will run a restricted deployment of tool Z with one specific team under a strict stop condition. This is probably the cleanest example of a two-way door, which we'll analyze a bit deeper shortly.

What's the main benefit there? It allows you to acquire empirical data about how a tool interacts with your specific corporate culture and your data architecture without exposing the entire enterprise to the disruption of a massive rollout. If the pilot fails to hit the metric, you just sever access. The financial and cultural cost is minimal.

Fourth, we have the govern-the-quiet-one shape. Often, an audit reveals that an AI system has been operating in the background of your company for months, maybe embedded in a procurement tool or a logistics planner, completely devoid of any oversight. Shadow IT.

Exactly. The govern-the-quiet-one priority is an operational rescue mission. It states, we will bring System X under basic governance by implementing activity logging, assigning a human owner, and establishing a monthly review cadence.

It isn't necessarily about shutting the system down, it's just about shining a light on a blind spot. Finally, the literacy-first shape. Right.

We will establish and verify a minimum standard of AI literacy for the specific teams interacting with Tool X. You choose this priority when the real vulnerability isn't the software's code, but the humans operating it. Like lawyers using Chad GPT. Perfect example.

If your legal team is using a generative tech tool to draft contracts without understanding how hallucination works, the technology isn't the immediate risk. Their lack of user comprehension is. So the executive has narrowed the universe down.

They've selected two or three priorities that pass the reversal test and fit these proven shapes. But selecting them is only half the battle. How do you format them so they actually survive contact with the daily friction of corporate operations? This requires the third rule.

Every priority carries three marks. And if a statement is missing any of these three specific marks, it reverts from a decision right back into a mood. These marks are the architectural supports that separate intent from actual execution.

Mark one. Falsifiable. A priority must contain a proves wrong condition.

It has to name the singular measurable metric that would unambiguously demonstrate that the priority was a failure. But, and this is where most frameworks totally collapse, the proves wrong condition is useless unless it is structurally paired with a pre-committed stop action. So a weak priority would say something like, we will monitor customer satisfaction and we will flag it for review if it drops.

Yeah, that's just monitoring the weather. A falsifiable priority with a stop action says, if the median handle time in the call center has not dropped by 15% after 60 days of the pilot, we will immediately terminate the pilot and revert to the legacy software. Without the pre-committed stop action, the priority can't fail in a way that actually alters organizational behavior.

Exactly. If failure doesn't trigger a change, the experiment can't teach you anything. The sources place a massive emphasis on where these falsifiable metrics originate, particularly regarding vendor relationships.

The proves wrong condition must be measurable entirely from your own internal data. This is a profound trap for so many leaders. Imagine a vendor sells you an automated code inspection application.

Their promotional material guarantees, our proprietary AI reduces inspection time by 40%. Okay. An inexperienced governance leader will write a memo that says, our priority is to deploy this application to achieve a 40% time saving.

They have just allowed the vendor's marketing department to define their internal success metrics. You are outsourcing your reality to a salesperson. Exactly.

A mature governance structure turns the verification process itself into the falsifier. So the strong memo reads, if the vendor cannot provide transparent documentation showing exactly how the 40% claim was calculated and the specific provenance of the training data used to build the model by day 30, the application is immediately moved to the governor drop category. You measure the outcome against your own standard of evidence, not their slide deck.

Right. Mark two, owned. The priority must name one specific human being or one singular role.

Not the IT department, not legal and compliance, not the cross-functional AI task force. This highlights a phenomenon I often describe as the corporate bystander effect. I mean, we form committees because we want diverse input, sure, but we also form them to diffuse risk.

Oh, absolutely. If an algorithm fails and a committee of 12 people owns it, nobody gets fired. It's like a relay race where the baton is dropped and everyone on the track just points at the person next to them.

The baton has to be in exactly one hand at any given millisecond. And the corporate bystander effect is devastating in algorithmic governance because AI systems can fail silently and continuously. Shared ownership inevitably degrades into zero ownership.

When you reach that 90 day review and ask, why did this pilot fail? A committee will just offer you a consensus of excuses. Why? A named owner, like the head of talent acquisition or the director of data architecture, provides absolute accountability. They wake up every morning feeling the weight of that specific priority.

It isn't about creating a scapegoat. It's about establishing a single point of operational clarity. Mark three, dated.

A date converts an intention into a contractual commitment with reality. Phrasing like in the near term or by the end of the year or as soon as feasible. Those aren't dates.

They are escape hatches. A date must be a specific day within the 90 day window where the falsifier will be checked. To really understand the catastrophic consequences of ignoring these three marks, we have to look at the Michigan MIDAS case study detailed in the sources because this isn't some theoretical corporate fumble.

This is a massive public sector failure that literally destroyed lives. Yeah. The Michigan Integrated Data Automated System, or MIDAS, was deployed to modernize the state's unemployment insurance agency.

The system utilized automated decision making to flag supposed instances of unemployment fraud. On paper, the goal was efficiency. But in practice.

In practice, the state ran this automated system for years with shockingly inadequate human oversight. And the mechanics of the failure are just chilling. Because the system operated without sufficient friction, it generated tens of thousands of wrongful fraud accusations against real citizens, automatically initiating penalties and wage garnishments.

And the failure compounded specifically because it lacked the three marks we're discussing. There was no falsifiable stop action. A responsible priority would have established a circuit breaker saying something like, if human auditors overturned more than 5% of the AI's fraud flags within a 30 day window, the automated flagging system is immediately suspended pending investigation.

But they didn't have that. No. Because there was no proves wrong condition, the system functioned exactly as coded, relentlessly amplifying its own errors.

Furthermore, because ownership was diffused across technical vendors and disparate state agency departments, there was no single empowered owner actively monitoring the error rate with the authority to actually pull the plug. It's tragic. The system failed slowly, it failed extensively, and it caused immense measurable human suffering.

It's the ultimate cautionary tale of unfalsifiable committee owned AI. You know, a lot of executives hear a story like Midas and their immediate reaction is defensiveness. I want to role play the skeptical executive for a second.

Let's do it. If I'm leading an innovative AI transformation and I explicitly document the exact conditions under which my project will fail, my proves wrong conditions, won't my board of directors view that as a lack of conviction? Won't the CEO look at my memo and assume I am already preparing for defeat? That anxiety is so common, but it fundamentally misreads how sophisticated capital and leadership actually evaluate risk. Naming your failure conditions doesn't signal timidity.

It projects absolute rigorous confidence. Walk me through the psychology of that. Why does it look confident? Because only an executive who has exhaustively stress tested their own logic is willing to state in advance the exact metrics that would prove them wrong.

It demonstrates that you are in control of the variables, not a victim of them. A memo that hides its potential failure modes isn't confident, it's fragile. Establishing a falsifier removes your future self's ability to rationalize a disastrous outcome into a qualitative success.

We have all sat in those post-mortem meetings. The project missed every single quantitative KPI, but the project lead stands up and says, well, the user adoption numbers are down, but we generated incredible qualitative synergies and cross-departmental learnings. Yeah, the falsifier terminates that exact rationalization.

It forces intellectual honesty. Okay, so we know how to construct the priority. Now we face the hardest part of the framework, triage.

How do you select which systems actually occupy those top three slots? This brings us to the fourth rule, rank by consequence, not by volume. The prioritization matrix for AI governance is completely different from standard IT procurement. You do not rank systems by how many employees use them or by how much the software license costs.

You must rank your systems entirely by the severity of the damage they will cause if they operate incorrectly. The blast radius. Exactly.

The absolute top of your list are systems that impact human rights, physical safety, and severe legal exposure. At the bottom of the list are systems where a failure merely results in excess cost or operational annoyance. This principle runs directly counter to what the sources call the visibility trap.

The visibility trap is the bane of the governance professional. It happens when organizational leadership obsesses over the technology that is most visible rather than the technology that is most consequential. Imagine a CEO who attends an industry conference, sees a dazzling demo of a generative AI customer service chatbot, and returns to the office demanding that the chatbot become the company's number one priority.

Because they can see it, they can interact with it on their phone, they can show it to the board. Precisely. But let's analyze the actual consequence there.

If the customer service chatbot hallucinates and provides a user with incorrect store hours or, I don't know, a nonsensical answer about a returning olysee, what is the actual harm? It's a public relations embarrassment. It annoys the customer. Right.

But it is a highly reversible annoyance. You can identify the bad output, issue an apology, and switch the chatbot off in 20 minutes. The blast radius is totally contained.

Now contrast that with a system running quietly in the background. Like an algorithmic resume screening tool that the HR department bought from a vendor two years ago. But the resume screener is practically invisible to the CEO.

But consider the consequence of failure. If that algorithm contains a statistical bias against certain demographics, it is silently and systematically violating employment law. It is actively discriminating against human beings.

Wow. The harm is profound. It accrues over time without triggering obvious alarms.

It carries catastrophic legal liability and, crucially, is incredibly difficult to reverse. You can't easily unreject a thousand candidates a year later. Governing the loud, low-consequence chatbot while leaving the quiet, high-consequence hiring tool unmonitored is literal governance malpractice.

Regulators aren't waiting for companies to figure this out either. They're explicitly coding this consequence-based ranking into law. The regulatory landscape validates this entire approach.

Look at the European Union's AI Act, specifically Regulation 2024-1689. The architects of that legislation didn't just ban AI, but they created strict consequence-based peers. The Act explicitly classifies artificial intelligence systems used in employment, worker management, and access to self-employment as high-risk.

What does that high-risk classification actually require mechanically from a company? What do you have to do? It triggers heavy, non-negotiable obligations. If you deploy a high-risk system, you are legally mandated to implement continuous risk management systems, ensure high-quality data governance to prevent bias, maintain extensive technical documentation, and guarantee human oversight. The EU understands that a biased hiring tool destroys lives, whereas a clunky chatbot is just bad software.

The sources also provide a really vital lesson regarding the volatility of regulatory timelines using the EU AI Act as an example. Yeah, a critical element of the 90-day memo is dating your assumptions because external reality shifts. For example, many compliance officers anchored their strategy to the original implementation dates of the EU AI Act.

However, the Council of the EU adopted the Digital Omnibus Simplification Package on June 29, 2026. And what did that do? That legislative maneuver deferred the application of standalone high-risk obligations out to December 2, 2027. If you built a rigid three-year plan based on the original date, your capital allocation is suddenly totally out of sync with reality.

The 90-day loop allows you to adjust to the digital omnibus shift in real time. Let's bring this back to the boardroom for a second. I want to play the CEO who just fell into the visibility trap.

All right. I'm slamming my hand on the table on Monday morning telling you, my head of AI governance, that the board wants to see our AI capabilities immediately, and therefore the customer chatbot is priority number one. You have 60 seconds to defend ranking the invisible hiring tool above my pet project.

Let's go. I would meet that pressure with structural logic, I'd say. Both of these systems are critical to our future, so this is a debate about the sequence of our actions, not neglect.

Let's look at the mechanics of failure. If the chatbot gives a wrong answer to a client today, we'll suffer a minor PR hit, but we can correct the output and switch the system off in an afternoon. The harm is small and entirely reversible.

OK. I'm listening. However, if our automated hiring tool is screening people unfairly right now, the harm impacts real applicants.

It triggers severe legal exposure under frameworks like the EU AI Act, and we cannot simply undo thousands of discriminatory hiring decisions next year. Therefore, I am governing the hiring tool first. I am placing your chatbot on our documented deprioritization list for this quarter, and I'm explicitly accepting the risk that a chatbot error might occur.

In 90 days, we will have spent our finite engineering hours securing the system where failure would have destroyed the company. Wow. That response is a fortress.

You validate the CEO's desire, you pivot the conversation to the mechanics of consequence and reversibility, and you openly accept the risk of delaying the chatbot. It removes the emotion from the debate. You mentioned reversibility, which is the perfect transition to the fifth rule.

Favor two-way doors. When you're writing a 90-day memo, you are attempting to command a technology that is evolving weekly. How do you mitigate the inherent risk of just being flat-out wrong? You mitigate the risk by architecting your decisions to be reversible.

The conceptual framework here was famously articulated by Jeff Bezos in his 2015 Amazon shareholder letter. He categorized corporate decisions into two distinct types, two-way doors and one-way doors. Let's map that metaphor directly onto enterprise AI.

What constitutes a two-way door? A two-way door is a strategic bet that can be reversed at a remarkably low cost. If you walk through the door and discover the environment is hostile or unproductive, you simply turn around and walk back out. Give me a concrete example.

Running a bounded pilot of an AI drafting tool with a single five-person marketing team governed by a strict 30-day stop condition, that is a two-way door. If the tool hallucinates wildly or the team just hates the interface, you revoke the licenses. The financial cost is minimal, your core data architecture is untouched, and the organization gained valuable empirical knowledge about that vendor.

Now contrast that with a one-way door. A one-way door is a decision where the cost of reversal is catastrophic or practically impossible. Imagine signing a massive three-year enterprise contract to integrate a foundational AI platform across your entire corporate infrastructure.

You migrate all of your proprietary secure records into the vendor's specific data format. You spend six months retraining your global workforce to use their interface. If you realize in year two that the platform's security is fundamentally flawed, the technical friction and the financial penalty of extracting your data and reversing course will literally paralyze the company.

In a 90-day window, when you are essentially still mapping the dark corners of your own AI estate, you must heavily favor two-way doors. You want to buy knowledge cheaply, but the sources highlight a nuance that often traps executives. Partial one-way doors.

Partial one-way doors are incredibly dangerous because they appear reversible on a spreadsheet, but they are irreversible in human terms. These are decisions that, when reversed, cost you trust, credibility, or cultural capital assets you really cannot easily repurchase. This connects directly back to Arvind Krishna at IBM, doesn't it? Exactly.

When Krishna went on Bloomberg Television and publicly announced that AI would replace a named number of human jobs, he walked through a partial one-way door. Even when the internal reality shifted and the actual number of replaced roles was vastly smaller by 2025, that initial public declaration was permanently lodged in the public consciousness and the minds of his employees. The reputational commitment persists long after the internal spreadsheet is updated.

Right. We see this internally all the time, too. An executive team announces to the entire company, we are retiring this beloved legacy software system and moving everyone to a new AI-powered platform.

Six weeks later, the AI platform crashes repeatedly. Technically, you can reverse the decision. You can apologize, reinstall the legacy software, and restore the old workflows.

But the cultural capital is incinerated. Your employees will view your next technology initiative with deep, entrenched cynicism. Which is why the rule holds.

Treat a partial one-way door with the same extreme caution as a full one-way door. If a potential priority forces you through a one-way door, you have two choices. You either deconstruct the project and downgrade it to a reversible first step, like running a closed sandbox pilot before the platform migration, or you explicitly acknowledge the irreversible nature of the bet in your memo and document the exact logic of why the risk is necessary right now.

I think your analogy on this is perfect. Oh, the tattoo versus marker thing. Yes.

Yeah, my favorite analogy for this is the difference between a tattoo and a marker. A public promise or a massive data migration is like getting a tattoo. A bounded internal pilot is like writing a note on your hand with a marker.

In a quarter where you are still figuring out what AI actually does to your specific workflows, you want marker, not ink. That captures the operational posture perfectly. Your priorities should be reversible probes designed to reduce uncertainty.

Okay, so we've selected our three priorities based on consequence. We've structured them with falsifiable metrics, single owners, and hard dates. We've ensured they are mostly two-way doors.

But this leads to the most uncomfortable reality of governance. A modern enterprise might have 50 AI systems touching its data. If you only prioritize three, what happens to the other 47? Which brings us to the sixth and arguably the most crucial rule of the framework.

The deprioritization list is the real memo. This is where the rubber meets the road. It really is.

Most executives are highly skilled at articulating what they intend to do. Almost no one possesses the discipline to formally document what they are actively choosing not to do. But a priority that costs you nothing to hold is a fiction.

If your focus doesn't require a sacrifice, you aren't actually focused. The deprioritization list is a dedicated, explicit section at the very bottom of your one to two page memo. It catalogs the major AI initiatives and systems that you are deliberately ignoring for the next 90 days.

But you cannot simply list the names of the tools, right? No, for every parked system, you must include a one sentence rationale for the delay, and you must explicitly name the specific risk you are accepting by waiting. Why is this so critical? This list performs three critical functions. First, it makes your strategic tradeoffs transparent and defensible.

When a division head corners you and demands to know why their pet project is stalled, you don't have to improvise a political excuse. The logic is already codified on the page. Second, it serves as a fortress against scope creep.

Just one more quick feature is the exact mechanism by which timelines are destroyed. The deprioritization list is the physical boundary around your finite engineering resources. And the third function is about creating a vital legal and operational record.

Yeah. To truly grasp the mechanics of this, we need to dive deep into the immersive scenario provided in the sources, the Northwind Freight case study. Oh, this is a great scenario.

Let's establish the variables. We have a fictional midsize logistics company named Northwind Freight. The protagonist is Bradley, who has just been appointed as the head of AI governance.

Bradley is staring down a Monday morning leadership meeting in 90 minutes, where he must present his AI strategy. He's run an inventory and discovered nine distinct AI systems currently interacting with the company's data and workflows. Nine systems is a nightmare for a single quarter.

I mean, he has route optimization algorithms, generative AI drafting tools, the CEO's chatbot, a hiring tool. He knows he cannot govern them all effectively. He has to apply the framework.

So Bradley filters the nine systems through the matrix of consequence and reversibility. He locks in his top three. Priority one is the resume ranking tool used in HR.

It's high consequence, carries immense legal exposure under employment law, and operates as a one-way door if biased hiring decisions are finalized. Makes sense. Priority two is a verify the vendor audit.

Northwind uses a third-party app to inspect freight damage, and Bradley just doesn't trust the vendor's accuracy claims. Priority three is a bounded pilot. He's taking an informal AI writing assistant that employees have been using covertly and putting it into a governed 30-day sandbox to measure actual productivity gains.

Those are three impeccably structured priorities. But the tension in this scenario revolves around what Bradley does with the remaining six systems. Specifically, that CEO's highly visible customer service chatbot we talked about earlier.

Exactly. Bradley places the chatbot squarely on the deprioritization list. But he executes a maneuver that really separates novice managers from true governance leaders.

He reads his own memo through the eyes of his harshest critic. He actively anticipates the attack. This is the expose beat of the decision loop.

He is exposing his logic to friction. Precisely. Bradley visualizes the boardroom.

He knows the sharpest attack will be. You left a client-facing system completely ungoverned so you could play with an internal HR tool. You are ignoring the customer.

Instead of capitulating and watering down his top three priorities to include the chatbot, Bradley pre-answers the attack directly in the text of the memo. He notes that while the chatbot is highly visible, it is fundamentally low consequence and easily reversible. If it breaks, they switch it off.

And then he writes the hardest sentence a leader can commit to paper. Risk accepted. A chatbot incident during this quarter would land on an ungoverned system.

That sentence requires immense professional courage. He is looking at a known risk, acknowledging it, and deciding that the company's finite resources are better spent preventing a discriminatory hiring lawsuit than preventing a clunky customer interaction. I want to push back hard on Bradley's logic here, though, because I've spoken with corporate counsel who would hyperventilate at the site of that sentence.

Oh, sure. Let's look at the legal and liability implications. Imagine a different deprioritized system, say, an algorithmic fraud flagging tool goes rogue mid-quarter.

It causes a massive financial disruption. If I am the executive and that system is sitting on my deprioritization list with the words risk accepted next to it, haven't I just handed the plaintiff's lawyers a signed confession? Yeah. Doesn't documenting that risk prove that I knew about the danger and intentionally ignored it? Isn't this creating a paper trail of gross negligence? That is a profound, yet incredibly common, misconception regarding liability and governance.

The legal and operational reality is the exact opposite. I thought so. If a system fails catastrophically, and there is zero internal documentation referencing it anywhere, that scenario looks like negligence.

It suggests an unconsidered gap. It implies that the governance team was entirely blind to the risks operating within their own infrastructure. You look like you were asleep at the wheel.

Precisely. But if the system is explicitly documented on a deprioritization list, it fundamentally alters the narrative. It proves that you conducted an audit.

It proves you saw the system. You evaluated the threat. You weighed it against the finite capital and engineering resources available to the organization.

And you made a documented, defensible, strategic bet under conditions of uncertainty. That is not negligence. That is the very definition of governance.

Wow. Okay. It changes the conversation in the courtroom from, you were totally ignorant of this massive vulnerability, to you made a calculated risk allocation decision that unfortunately didn't pay off in this instance.

Yes. Consider the framework of medical triage in a flooded emergency room. A triage nurse must look at a waiting room full of suffering people and decide out loud who receives immediate care and who waits.

Explicitly accepting the risk that a patient with a broken arm might experience prolonged pain while you treat a cardiac arrest, that is the responsible ethical act. Because you only have so many doctors. Right.

Pretending you have the resources to treat everyone simultaneously is what leads to systemic collapse and catastrophic negligence. The deprioritization list is simply corporate triage. That reframing of negligence versus triage is incredibly powerful.

So we've constructed the memo. We have three consequence-ranked priorities, complete with falsifiers and dates. We have a robust deprioritization list that documents our accepted risks.

But before an executive signs this document and makes it an official command act, we need to run a diagnostic pre-flight check. Section 7 of our framework is dedicated to diagnosing weak memos. Because even with the best intentions, organizations naturally drift toward these failure patterns.

The sources outline specific failure patterns. Identifying these dysfunctions before the memo is published allows you to fix the architecture while it is still computationally cheap to do so. Let's run through them.

The first failure pattern is the everything memo. The everything memo is easily identifiable. It features 10 or 12 priorities, lacks any coherent ranking mechanism based on consequence, and the deprioritization list is entirely blank.

It is the physical manifestation of an executive's refusal to make a choice. And the fix. The structural fix is ruthless but simple.

Force the author to cut the list to three, park the remainder, and demand written reasons for the delay. The second pattern is the mood memo. We discussed this earlier with the reversal test.

The mood memo phrases its priorities as generalized themes. We will embrace AI. We will optimize workflows.

We will manage algorithmic risk. No rational entity could oppose these statements, and more importantly, no empirical result could ever falsify them. So you have to convert the mood into a metric.

The fix is to rewrite the thematic preference into a concrete action that carries the three marks. It must be falsifiable, owned by a named human, and dated. The third is the orphan memo, which ties back to the corporate bystander effect.

Every priority in the orphan memo is owned by a collective. The IT department will lead this. The AI steering committee owns this deliverable.

When ownership is distributed across a group, accountability evaporates. When you inevitably reach the 90-day review, and the falsifier has fired, a committee cannot give you an operational answer. They can only give you a political defense.

The fix is obvious here. Cross out the committee name and assign exactly one empowered human being or one highly specific role to every priority. The fourth pattern is the undated memo.

This memo contains strong, falsifiable priorities with clear owners, but the timeline relies on adverbs instead of calendars. We will audit the hiring algorithm soon. We will roll out the sandbox pilot in the near term.

Soon is not a strategy. Exactly. If a priority lacks a concrete date within the 90-day window, it cannot be enforced by reality.

The fix is to attach a hard date that forces a review. The fifth pattern is highly deceptive. The silent trade-off memo.

Oh, this one is tricky. The silent trade-off memo looks structurally sound at first glance. It has three well-crafted priorities.

But the deprioritization list is either completely missing or entirely cosmetic-filled only with absurd projects that no one in the company actually wanted to execute anyway. It hides the real sacrifices. Exactly.

It means the author is dodging the political friction of telling a division head no. If a consequential deprioritized system fails mid-quarter, the executive has no documented proof that they weighed the trade-off. The structural fix is to mandate that at least one genuinely tempting, highly visible project is placed on the deprioritization list, accompanied by the explicit acceptance of risk.

The final failure pattern is perhaps the most insidious because it sounds so intelligent. The analysis paralysis memo. The analysis paralysis memo is the mood memo wearing a suit.

It is disguised as prudent governance. The priorities read like this. We will explore the implications of AI fairness.

We will assess the landscape of vendor contracts. It sounds rigorous. It sounds great, but it decides absolutely nothing.

It merely schedules homework. If the stated outcome of a priority is simply, we will possess more information, but no operational action is tied to that information, you have deferred governance. How do you force a decision out of an assessment then? You weaponize the timeline.

You structure the priority so that the assessment itself has a falsifiable deadline that triggers an action. You write, the director of data architecture will spend 30 days assessing the vendor's training data. By day 45, based on that assessment, we pre-commit to a binary choice.

We will either migrate fully to the system or we will terminate the vendor contract. You force the homework to yield a keep, change, or kill decision. We have mapped the entire journey today.

We have transitioned from the passive consumption of AI hype to the active drafting of a singular falsifiable, owned and dated command document. A document that demands real organizational sacrifice and embraces the friction of reality. Operating under this framework represents a radical shift in executive posture.

You move from predicting the future to actually navigating the present. To crystallize this framework, I want to speak directly to you, the listener, about the physical actions you should take on Monday morning, because we promise zero filler. What is the single most valuable operational move a governance leader can make when they sit down at their desk? The directive is immediate execution.

Do not wait for a mandate, create the mandate. Here is the exact blueprint for your Monday morning. Open your organization's AI systems inventory.

If you don't have one, write down every piece of software you know is utilizing machine learning to touch your data. Look at every single system on that list. Tag each one with a specific consequence label.

Does a failure here impact human rights, physical safety, legal exposure, or is it merely a matter of operational cost or annoyance? Sort that list ruthlessly. Extract the top three highest consequence systems. For each of those three, write a clear, measurable, proves wrong condition paired with a stop action.

Assign one human owner, attach a date within the next quarter. And then you have to park the rest. Yes.

Take the remainder of your inventory and construct your deprioritization list. Write the one sentence rationale for delaying them and explicitly state the risk you are accepting by focusing your engineering resources elsewhere. Date the document, sign it, and set a calendar invite for a review in exactly 90 days.

Lock it in your command dossier. And then, and this requires supreme discipline, do not edit that document for 90 days. Let the friction of the real world test your logic.

Do not touch the text. The value of the memo is realized in its collision with reality. Which really leads us to a fundamental paradigm shift regarding the nature of modern leadership.

For decades, the archetype of the brilliant CEO was the visionary mapmaker. You know, the leader who could stand on a stage, unroll a flawless five-year strategic blueprint, and flawlessly predict the technological future. Like the Arvind Krishna prediction from 2023.

That was the ghost of that old archetype. Precisely. But in an era where artificial intelligence introduces exponential, unpredictable change into the market every six weeks, the five-year strategic blueprint is dead.

It is a corporate artifact. The DNA of the future CEO must fundamentally mutate. The goal of AI leadership is no longer about being right on your first try.

What is it about? The true mark of an expert executive is the ability to architect a machine that is relentlessly capable of proving them wrong. Because if the machine proves you wrong quickly and clearly, you're judging compounds. You iterate faster than the competitor who is still defending their initial flawed thesis.

Exactly. As a 50-page strategy deck that you never revise, a priority that never has a falsifier fire, that's just a static photograph of a guess. It is fragile.

But a 90-day memo with a fired falsifier, a document that forces an organization to absorb hard data and publicly revise its assumptions, that is a steering wheel. It is the only mechanism that actually allows you to navigate velocity. The 90-day AI priorities memo is not a map of the territory.

It is a compass, a steering wheel, and a shock absorber combined. It embraces the muddy waters of enterprise AI by acknowledging that we will not get the deployment perfectly right on day one. But by establishing falsifiable metrics, we will measure exactly how we fail and we will course correct with more precision and speed than anyone else in the market.

Go build your steering wheel.

Real cases

These examples show real organizations making, or failing to make, a first public AI-priorities decision, with the reasoning stated plainly. The centerpiece is IBM; the others are referenced from their owner topics for contrast.

Example 1: IBM's 2023 hiring-pause decision (the anchor). In a Bloomberg interview on 1 May 2023, IBM chief executive Arvind Krishna said the company would pause or slow hiring for back-office, non-customer-facing roles that AI was likely to absorb, and that he could "easily see" about 30 percent of those roughly 26,000 roles, near 7,800 jobs, replaced by AI and automation over five years, largely through not backfilling departures rather than through layoffs (Bloomberg, 1 May 2023). Read it as a memo. The decision was concrete (pause and slow specific hiring). The scope was named (back-office, non-customer-facing). The timeframe was dated (five years). The claim was falsifiable (a checkable percentage). And it carried an implicit de-prioritization and reinvestment: pulling back in back-office meant pushing elsewhere. Note the epistemic honesty of the original framing: "could easily see" is a projection, not a guarantee, and the program marks forward-looking claims that way.

Example 2: The same decision, revised (why "in shame later" is a feature). By its May 2025 Think conference, IBM described the outcome, and it was messier and more instructive than the 2023 headline. Krishna said AI, through the company's AskHR agent, had automated about 94 percent of routine HR tasks and replaced "a couple hundred" HR roles, far fewer than the 7,800 the headline implied, while total IBM employment actually rose, because the resources AI freed were spent hiring more programmers and salespeople; IBM also cited about USD 3.5 billion in productivity improvement across more than 70 areas (Krishna, WSJ-reported, May 2025). The direction of the 2023 decision held; the specifics were revised by reality. This is the model in Section 3G, beat 4: a real decision, publicly made, honestly revised. The 2023 memo was not wrong to write; it was right to write and then right to update.

Example 3: A decision that failed for lack of a falsifier and an owner (contrast). When an organization deploys AI with no dated success criterion and no single owner, there is no moment at which anyone must say "this is not working." The Michigan MiDAS unemployment system ran automated fraud decisions for years with inadequate human oversight before the scale of wrongful accusations forced a reckoning; a clear falsifier ("if human review overturns more than a set share of flags, we stop") and a named owner would have created a stopping point long before the harm compounded. That case is examined in depth as the build-buy-with-real-budget decision. (see Topic 3.2) The lesson here is narrow: a priority with no falsifier and no owner cannot fail on schedule, so it fails slowly and expensively instead.

Example 4: Choosing which system to govern first (consequence over convenience). Regulators reward organizations that put their highest-risk AI at the front of the queue. Under the EU AI Act (Regulation (EU) 2024/1689), certain uses such as AI in hiring and worker management are treated as high-risk and carry the heaviest obligations; a memo that governs a flashy customer chatbot first while leaving a high-risk hiring tool ungoverned has ranked by visibility, not by consequence. Risk classification is the owned subject of a later topic. (see Topic 5.3) For your memo, the takeaway is the ranking rule: the first system you govern should be the one whose failure reaches real people and real law, even if it is not the one your leadership finds most exciting.

Example 5: The honest-ROI check behind a headline number (from the money module). Bold public AI numbers invite scrutiny of the economics behind them. When a company claims a large cost cut from replacing staff with AI, the defensible version of that claim shows the real, fully-loaded costs, including the human supervision the AI still needs. The honest reckoning behind such claims is the owned subject of the ROI topic. (see Topic 8.1) For your 90-day memo, borrow one habit: if a priority rests on a savings or productivity number, write the number you expect and the number that would prove you wrong, from your own accounts, not a vendor's slide.

Example 6: The workforce priority as a decision, not a slogan (from the humans module). IBM's decision was, at heart, a workforce decision: which roles change, which grow, which end. The defensible way to make a workforce-AI priority is the same as any other: name the change, own it, date it, and state what would prove it wrong, rather than issuing a vague "we will reskill our people" that no one can check. The deep work of mapping which roles change belongs to a later topic. (see Topic 9.1) The borrow for your memo: if one of your priorities touches people's jobs, treat it with more falsifiability, not less, because the human stakes make a vague promise both crueler and less defensible.

Example 7: Sequencing under a real deadline. Priorities also have to respect the clock the outside world sets. Under the EU AI Act (Regulation (EU) 2024/1689), the timeline was itself revised: the Council of the EU's "Digital Omnibus on AI" simplification package, formally adopted 29 June 2026, deferred application of the stand-alone high-risk obligations to 2 December 2027 (Council of the EU press release, "Artificial intelligence: Council gives final green light to simplify and streamline rules," 29 June 2026). That is a live reminder that even the deadlines you plan against can move, weeks before you expected. A memo that sequences its priorities against a fixed external date should note that the date is current-as-of-today and may shift, and should prefer reversible first steps so a moved deadline does not strand an irreversible commitment. The specific current dates and their full implications are owned by the law modules; here the lesson is only that a good memo dates its assumptions, not just its tasks.

Where people go wrong

  • "A priorities memo should be comprehensive." Wrong, and the most common failure. A memo that lists ten priorities has made zero choices. Comprehensiveness is the enemy of a priorities memo; its whole value is the ruthless cut to two or three. If it does not fit on a page, you have written an inventory or a wish list, not a priorities memo.
  • "We should wait until we understand AI fully before committing to priorities." This is the information trap Topic 0.1 warned against. (see Topic 0.1) You will never understand AI "fully"; the field moves faster than any study. The memo is deliberately short-horizon (ninety days) and reversible precisely so you can decide before you are certain and learn from the decision. Waiting for certainty is a decision too, usually a bad one.
  • "A decision without a named owner is fine if the team is aligned." No. Shared ownership is no ownership. "The AI committee owns it" means that in ninety days, when you ask what happened, everyone points at everyone. One named owner per priority is not bureaucracy; it is the difference between a result that someone is answerable for and a result that quietly does not happen.
  • "The success criterion can be qualitative, like 'improved efficiency.'" A criterion you cannot measure cannot be failed, and a decision that cannot fail cannot teach. Use a number from your own organization's data and pair it with the result that would prove you wrong. "Improved efficiency" is a mood; "median handle time drops by our target by day 60, or we stop" is a decision.
  • "Revising the memo later means the first one was a failure." Backwards. Revision is the goal, not the embarrassment. IBM's 2023 projection was revised by 2025 actuals, and the organization was better for it (Bloomberg 2023; WSJ-reported 2025). A memo you never revise is a memo you never checked against reality. The mild wince of rereading your first draft is the feeling of having learned something checkable.
  • "Put the most visible or most requested system first." Rank by consequence, not by volume of requests. The system your leadership asks about most is often the least risky (a chatbot), while the real exposure sits in a quiet high-risk tool (hiring, credit, fraud). Governing the loud one first feels responsive and is often a misallocation. (see Topic 5.3)
  • "The de-prioritization list is optional." It is the most important part. Without it, every priority is under constant pressure to expand, and every choice not to do something is undocumented and therefore indefensible when attacked. If your "not doing" list is empty or contains only things nobody wanted, you have not actually chosen.
  • "A public, bold statement is a stronger decision than an internal one." Not necessarily, because public statements are closer to one-way doors. A public AI promise is hard to unsay when reality shifts, as IBM found. For a 90-day memo, prefer reversible internal bets you can update quietly. Save the public commitment for a decision you have already tested and are ready to defend.
  • "The memo replaces the strategy, the policy, and the risk register." No. The memo sits above those and points to what comes first; it does not do their job. Your policies, risk assessments, and conformity files are longer, later artifacts. The memo's job is only to decide where your scarce attention goes this quarter. Trying to make it comprehensive turns it back into the wish list it was meant to cut through.
  • "If I write a proves-wrong condition, I am promising to fail." A falsifier is not a prediction of failure; it is a pre-commitment to honesty about the result. Most priorities with good falsifiers succeed. The falsifier simply removes your future self's ability to rationalize a bad result into a "qualitative win." You are promising to look, not promising to lose.
  • "Once signed, the memo should not change for ninety days." The signature dates a decision; it does not freeze the world. If a serious incident or a legal change lands on day 20, you update the memo and note why, the same way a navigator corrects course mid-voyage. What you do not do is quietly relax a falsifier because a priority is going badly; that is editing the scorecard, not the plan.

Questions people ask

What is 90-day AI priorities memo?
A one to two page decision document, written by a governance leader for their own organization, that names the two or three AI priorities for the next ninety days, and for each states the decision, a single named owner, a date within the ninety days, and a falsifiable proves-wrong condition, plus an explicit de-prioritization list and a dated signature. It is the artifact this topic produces; it is attacked in Module 11 and revised in Module 13.
What is priority?
A choice made among competing goods, ranking one good above another with a stated reason. A true priority names what it beats. A list of many "priorities" with nothing given up is a wish list, not a set of priorities.
What is decision (versus a mood)?
A commitment that can be checked. A decision carries three marks: it is falsifiable (it names the result that would prove it wrong), owned (one named person or role is accountable), and dated (it has a real deadline). A statement missing any mark is a mood: it sounds like a commitment but cannot be tested, owned, or timed.
What is falsifiable (proves-wrong condition)?
The single, measurable result that would show a decision was a mistake. A priority without a falsifier can never fail and therefore can never teach; the falsifier is what turns a plan into a test.
What is owner?
The one named person or role accountable for a priority. Committees and "the team" are not owners, because shared ownership means no one is answerable at review time. Ownership is about having a single person to ask "what happened?", not about assigning blame. More on Owner

Keep going