AI Leadership Weekly · Issue #95 · Tuesday 4 August 2026 · 08:00 BST
Good morning.
An assistant that can complete an errand is more interesting than one that describes how to do it. It is also a different proposition to manage. This week, Google brings that distinction into the browser and the physical world, while IBM publishes a new study of breached organisations.
The opportunity is practical: reduce the small pieces of work that interrupt a day. The caution is equally practical: a login, an approval and a safe stopping point are not interchangeable. Before handing over an errand, make sure the assistant knows which part is still yours.
IN 60 SECONDS
Browser: Gemini Spark adds a route to carrying out tasks in a signed-in environment, with important rollout limits. Security: Read IBM’s breach findings as a study of its sample, not a probability forecast for your business. Robotics: Better planning software is not a finished robot. Three stories about capability becoming action—and what still sits around it.
CEO / COO / CXO CHECKLIST
CEO: Select a useful delegated task, rather than an impressive but unnecessary demonstration.
COO: Mark the point where a recommendation becomes a commitment or a physical action.
CXO: Confirm country availability, permitted accounts and the route back to a human.
TOP STORIES
1. Gemini Spark moves closer to completing browser errands
Google · 30 July 2026
What happened. Google’s 30 July Spark update adds permission-based interaction with signed-in Chrome accounts, handing sensitive steps such as payments back to the user. Chrome auto-browse initially launches in the US. A wider international Spark expansion is a separate rollout, not proof that the browser feature is available in Britain.
Why it matters. Our take: the useful unit of value is a completed errand with a clear end state. Finding three suitable options is different from booking one; preparing a supplier form is different from submitting it. Those distinctions should be visible in the product and in the trial brief. Otherwise “help me with this” can become an argument about what help was authorised.
What to do. Choose a low-risk task using an approved account. Define what the assistant may inspect, prepare and submit. Keep payment, contract acceptance and other consequential steps with a person until the specific workflow and its controls have been assessed.
2. IBM’s breach report puts AI-enabled attacks in context
IBM / Ponemon Institute · 29 July 2026
What happened. IBM’s 29 July report, researched by Ponemon Institute, covers 602 organisations breached between March 2025 and February 2026. It classifies one in four malicious breaches in that sample as AI-enabled. Their average cost was $6 million, versus $4.99 million across the full study.
Why it matters. Our take: these figures justify asking better questions, not claiming that a quarter of all companies will suffer an AI attack. The sample concerns organisations that were breached, and the cost comparison does not establish that AI alone caused the difference. For a business leader, the relevant conversation is how suspicious requests are verified and how quickly access can be contained.
What to do. Run through a believable but fictitious urgent-payment or account-change request with the team. Check the independent verification route and escalation contact. Record where a convincing message could bypass an ordinary control, then fix that weakness before buying another dashboard.
3. Gemini Robotics-ER 2 targets the planning layer
Google DeepMind · 30 July 2026
What happened. Google announced Gemini Robotics-ER 2 on 30 July, including access through developer platforms. It supports high-level reasoning and coordination for robotic tasks. Lower-level systems still control movement; this is not a ready-made robot that can be dropped into any workplace.
Why it matters. Our take: separate the planner, the machinery and the safe operating environment when assessing an automation proposal. An excellent plan is useless when a device cannot execute it reliably. Conversely, a capable machine needs sensible task selection. The business case should identify a bounded activity and account for supervision, interruptions and recovery—not simply compare an AI demonstration with a person’s whole job.
What to do. Ask a proposed supplier to diagram one task from instruction to physical completion. Require clear responsibility for safety limits, stopping and recovery. Start assessment in simulation or another properly controlled setting, with relevant engineering specialists involved before real-world operation.
SIGNALS FROM THE LAST MONTH
21 July: Google’s Flash releases keep the model-cost comparison moving; repeat task-level tests rather than assuming an upgrade wins. Google · 21 July 2026
22 July: RAAPID’s published example highlights evidence-linked review, with the limitations of a supplier case study. Microsoft · 22 July 2026
21 July disclosure: Research-agent access boundaries deserve scrutiny alongside model capability. OpenAI · 21 July 2026
9 July: AlphaEvolve on Cloud is a reminder that valuable AI can optimise a specific algorithm, not just produce text. Google · 9 July 2026
IN BRIEF
Further dated updates, including recent context worth keeping in view.
29 July: Lyria 3.5 adds music-creation controls through Google’s Flow Music rollout. Google · 29 July 2026
30 July: Anthropic reports evaluation incidents involving unintended access to external infrastructure under reduced safeguards. Anthropic · 30 July 2026
3 August: Microsoft announces a 30-day Copilot trial route for eligible smaller businesses through partners. Microsoft, 3 August entry · 3 August 2026
16 July lookback: Gemini Notebook’s new capabilities remain subject to product and subscription availability. Google · 16 July 2026
THE 15-MINUTE PLAYBOOK
Minutes 0–4: Write down an errand a colleague repeatedly completes. Describe its starting information and its finish in one sentence each.
Minutes 4–8: Divide the steps into reading, preparing and committing. Highlight any money movement, external communication, sensitive record change or physical action.
Minutes 8–12: Give each highlighted step an explicit approval or technical restriction. Decide what happens when information is missing or the service is unavailable. “Try harder” is not an exception process.
Minutes 12–15: Agree a small supervised test and name the person who checks completion. Count the time that person spends checking, too. The goal is less work overall, not moving the same effort from doing the task to watching a screen.
DATA WAVE MOMENT
The strongest automation brief is often a modest one: complete this useful task, within these boundaries, and show me what happened. That leaves room to expand without pretending the first version can run a department. Data Wave starts with that end-to-end job, including the person who must pick things up when the easy path runs out.
QUESTION FOR READERS
Which everyday errand would you delegate first—and exactly where would you keep the final decision?
Brought to you by Data Wave — your AI & Data Team as a Subscription.
