AI Leadership Weekly · Issue #80 · Tuesday 21 April 2026 · 08:00 BST

Good morning.

Anthropic released Opus 4.7, IBM announced measures aimed at AI-enabled attacks, and Google made prototyping in AI Studio more accessible to eligible subscribers. This is a practical week for teams with something already in use. New capability is welcome, but an upgrade also needs to preserve the behaviour, permissions and costs that the existing service relies on.

IN 60 SECONDS

Claude Opus 4.7 is released. Anthropic launched Opus 4.7, with changes in capability and model behaviour that make migration testing important.

IBM responds to agentic cyber threats. IBM announced coordinated security assessment and automation measures aimed at helping enterprises respond to AI-enabled attacks.

Google AI subscriptions connect to AI Studio. Google introduced a route for eligible AI subscribers to prototype in AI Studio, subject to the service’s usage conditions.

CEO / COO / CXO CHECKLIST

  • CEO: Define the outcomes and safeguards an upgrade must preserve.

  • COO: Include an awkward case that previously exposed a failure.

  • CXO: Separate the prototype allowance from the cost and responsibility of a live service.

TOP STORIES

1. Claude Opus 4.7 is released

Anthropic · 16 April 2026

What happened. Anthropic released Claude Opus 4.7 on 16 April across Claude and major API platforms. The announcement highlights changes in instruction following and visual processing, and warns that tokenisation changes can affect usage for the same input. Improved benchmark results do not remove the need to test existing workflows.

Why it matters. Our take: A model that follows instructions more literally can expose ambiguity in instructions that previously seemed to work. A cost comparison can also change even when the stated price per token does not. Ask the team to rerun representative work with the same acceptance criteria and inspect where behaviour differs. Keep the previous configuration available until the comparison is understood.

What to do. Use a dozen real examples: straightforward, ambiguous, incomplete and high-consequence. Compare correctness, intervention and total usage. Record which instruction changes were necessary rather than quietly editing prompts until a demonstration looks better.

2. IBM responds to agentic cyber threats

IBM · 15 April 2026

What happened. IBM announced new cybersecurity measures on 15 April, including a readiness assessment for AI-related threats and IBM Autonomous Security, a service built around coordinated agents. The release describes intended detection, response and remediation capabilities. It does not establish that a particular customer environment is protected or that autonomous actions are always appropriate.

Why it matters. Our take: An automated defensive action still needs a business context. Isolating a system may be the right response to a genuine incident and a costly mistake for a false alarm. Define the conditions under which the system may act and where an operator must decide. Also ask how a decision is explained afterwards, particularly when several tools contributed to it.

What to do. With the security owner, choose one proposed automated response and document its evidence threshold, authority, recovery route and service impact. Treat that as an acceptance test, not merely a configuration setting.

3. Google AI subscriptions connect to AI Studio

Google · 20 April 2026

What happened. Google announced on 20 April that AI Pro and Ultra subscribers would receive increased AI Studio limits and access to additional models. It positioned the subscription benefit as an easier route into experimentation, while distinguishing that from pay-per-request API use for production-scale launches.

Why it matters. Our take: Removing early billing friction can help a team explore an idea. It can also obscure the point at which an experiment becomes a service people depend on. Before sharing a prototype widely, clarify who pays for usage, who can access its data and who handles failure. A working link is not a production operating model.

What to do. Put a visible gate between “demo” and “live”. Require a named owner, a permitted-data decision, a rough cost model and a support route before crossing it. Keep the gate lightweight enough that people actually use it.

SIGNALS FROM THE LAST MONTH

2 April · Google releases Gemma 4. Google introduced Gemma 4, adding open-model deployment options for organisations assessing on-device and self-managed AI. Source

31 March · Mistral designs tools for agents. Mistral described Spaces, a command-line tool designed to serve both people and agents working with development environments. Source

26 March · Search Live expands internationally. Google expanded Search Live, allowing more users to ask questions through voice and camera input while searching. Source

24 March · Claude Code previews auto mode. Anthropic introduced a research preview that automates some permission decisions in Claude Code while retaining checks for higher-risk actions. Source

IN BRIEF

More dated updates from the preceding 30 days.

8 April · Claude Managed Agents enters beta. Anthropic introduced a public beta for managed agent infrastructure, taking on more of the execution and session-management layer. Source

8 April · Colab adds a learning mode. Google introduced Colab features aimed at helping people understand and develop code, rather than only generating finished answers. Source

7 April · Project Glasswing focuses on defence. Anthropic announced Project Glasswing with selected partners, using restricted model access to find and address software vulnerabilities. Source

2 April · Google Vids adds creation tools. Google expanded Vids with new generative video and music capabilities; feature limits and access depended on the account and plan. Source

THE 15-MINUTE PLAYBOOK

Minutes 0–4: Select four ordinary examples and two exceptions from one workflow. Remove unnecessary sensitive information before using them in a test environment.

Minutes 4–8: Write the essential checks for each: correct facts, correct action, acceptable wording and an appropriate response to missing information.

Minutes 8–12: Add one cost or latency limit and one permissions test. Decide which failure blocks release and which can be accepted with a documented workaround.

Minutes 12–15: Name the owner of the pack and the changes that trigger a rerun: model, instructions, sources, tools or permissions. Start small and add cases when real work exposes something new.

DATA WAVE MOMENT

The aim is not to slow upgrades with a large testing programme. It is to give the business a quick, repeatable way to distinguish a useful improvement from a changed demonstration. Build a handful of representative examples with the people who know the work, then keep using them as the technology changes.

QUESTION FOR READERS

Which result would have to become worse for us to reject an otherwise impressive upgrade?

Brought to you by Data Wave — your AI & Data Team as a Subscription.