Protect and secure your data from cyber attacks
Data Protection
Data Security
Data Insights
The 5 Steps to Cyber Resilience
Cloud & SaaS
Enterprise
Industries
Frontier labs can pace AI's development. Enterprises still have to recover from agent failures today.
I recently read Dario Amodei's essay “We Must Pace the Frontier.” He argues that AI capabilities are advancing faster than alignment, interpretability, and evaluation can keep up. His three-step plan begins with independent evaluators who have ongoing, employee-like access to verify how frontier labs operate.
I agree with the principle behind his argument: the ability of AI to act should not advance faster than our ability to make it safe. Pacing does not mean stopping progress. It means giving safety work a chance to keep pace with capability. That matters even more as AI systems begin helping to develop the next generation of models.
But from the enterprise front line, we also have to contend with what is already happening. Companies are deploying copilots, coding assistants, and autonomous agents. Employees are experimenting, and adversaries are using AI to speed up and improve their operations. Enterprise adoption will not wait for a global agreement on pacing.
We have to work on both fronts. Frontier labs must keep making models safer, while every enterprise builds the resilience to manage AI capabilities already in use.
Cohesity supports both closed and open frontier models in our cyber defense work. We believe we're the only vendor in our space that's part of five initiatives that address the risks of AI adoption: Anthropic's Project Glasswing, OpenAI's Daybreak, Google Gemini for Cyber, the Open Secure AI Alliance, and the Open Weights and American AI Leadership initiative. None of our competitors can say the same. These efforts help our customers ensure that AI resilience spans agents, identity, and data.
Historically, cyberattacks unfolded through a sequence of human decisions. An attacker stole credentials, searched for vulnerabilities, moved laterally, and tried to disrupt operations or steal data.
Malicious use of AI agents changes that model. Agents can interact with applications, data, infrastructure, and other agents at machine speed, completing a sequence of actions before a person can interpret an alert, much less intervene.
I think the term “agent-state attack” captures the shift: multiple agents can discover, decide, and act together at machine speed. That automation can help criminal groups operate with greater scale, capability, and persistence—narrowing advantages long held by nation-states.
And the threat is not limited to malicious actors. An authorized agent can cause serious damage due to a faulty objective, poor context, compromised inputs, excessive permissions, or an unintended chain of actions.
Enterprise AI security, therefore, has to address both hostile activity and trusted AI that makes an untrusted decision.
An agent that can read sensitive information, change a record, execute code, alter infrastructure, or start a business process is a privileged identity. It should be subject to the same Zero Trust principles as any other form of privileged access.
Agents need least-privilege access, short-lived credentials, traceable actions, clear boundaries, and a reliable way to stop execution. These identity and governance controls are essential, but they cannot prevent every harmful outcome. A properly authenticated and authorized agent can still make the wrong change.
Traditional controls ask whether an agent should be allowed to act.
AI resilience asks what happens next: Can we determine what changed, contain the damage, and return the business to a trusted state?
Dario is right to emphasize independent evaluation, operational discipline, alignment, interpretability, testing, and verification. Those practices can reduce risk at the model and development layers.
Enterprises need the same discipline at the operational layer.
Governance can set policy. Observability can record behavior. Security systems can detect anomalies, and people can approve high-consequence decisions.
Yet none of those controls can restore a business after an agent corrupts data, deletes files, changes an application, modifies its memory, or triggers a cascading workflow.
That is the practical distinction between AI safety and enterprise resilience.
AI safety seeks to reduce harmful or unintended behavior. Agent resilience assumes some failures, attacks, and surprises will still occur and prepares the enterprise to withstand and recover from them.
We need both. Cohesity Agent Resilience is a major focus for the company and will be part of the discussion at this week’s Cohesity Catalyst virtual event (register here).
As AI becomes part of day-to-day operations, companies need to protect the model and the stateful environment around it, including:
Cohesity’s Enterprise AI Resilience strategy is built for this operational reality. It is designed to help organizations protect the systems AI depends on, establish what changed, and recover to a trusted state. See our announcement earlier this year here.
Cohesity preserves immutable, point-in-time copies of critical environments and is extending resilience across agents, their data, and supporting infrastructure. This helps organizations determine what changed and restore affected resources to a known-good state without rebuilding the entire environment from scratch.
Detection and prevention remain critical. But no defensive layer will be perfect when machines act faster, across more systems, and with greater autonomy.
Recovery is the control that must still work when an earlier control fails.
Human-speed defense will not be enough for machine-speed incidents. Enterprises will increasingly need defensive AI that can detect anomalies, contain activity, preserve evidence, and begin recovery at comparable speed.
Responses should reflect the consequences. Low-risk containment and recovery can be automated. Decisions with significant business, customer, legal, or safety implications should remain under human authority.
The goal is controlled automation with explicit objectives, trusted recovery points, immutable evidence, and human ownership of the most consequential decisions.
Each incident should also improve the defense. Lessons from blocked attacks, agent errors, and recovery events should strengthen detection and resilience without compromising privacy or data governance.
A model is only as trustworthy as the data and context it uses.
If that data has been exposed, manipulated, corrupted, or made unavailable, even a well-aligned model can produce the wrong answer or take the wrong action.
Our Chief Product Officer, Vasu Murthy, has distilled that responsibility into six principles for using AI agents safely:
This is where Cohesity has a distinct role. We do not build frontier models or claim to solve every aspect of model alignment. We protect, secure, govern, and recover the enterprise data, applications, identity systems, and AI environments that production AI relies on.
That foundation also helps companies put their data to work. When enterprise data is protected, governed, and recoverable, organizations can apply AI with greater confidence.
AI labs, governments, security companies, and enterprise leaders each have different roles to play.
Frontier labs should invest in independent expert evaluation, rigorous testing, transparency, secure development, and responsible pacing.
Governments should support coordination, set clear expectations for high-risk systems, and protect the critical infrastructure behind the AI ecosystem. They should also hold malicious actors accountable and build credible deterrence against AI-enabled attacks.
Security and resilience companies must design for autonomous campaigns, privileged agents, machine-speed incidents, and rapid recovery across complex enterprise environments.
Boards and executive teams should ask three direct questions:
Restoring the business depends on recovering the data, applications, identities, agents, and AI infrastructure that support those operations. The answers must be demonstrated through tested operational capabilities, not left in a policy document.
I support greater care at the frontier. The industry should take recursive improvement, agentic behavior, cyber misuse, and misalignment seriously.
But enterprises cannot base their security strategy on the assumption that global pacing will succeed, every model will behave as intended, or every harmful action will be detected in time.
They have to prepare for progress to continue.
At Cohesity, we believe organizations should be able to adopt AI boldly, without being reckless. That requires secure data, governed access, resilient AI infrastructure, immutable evidence, rapid containment, and trusted, speedy recovery.
Pacing can make the frontier safer. Resilience is what keeps the enterprise running when safety controls fall short.
Written By
Sanjay Poonen
CEO and President