Cohesity Extends Cyber Resilience to the Infrastructure Behind AI Agents

As enterprises move from AI systems that make recommendations to agents capable of taking action, Cohesity is expanding its cyber resilience approach to cover the infrastructure those agents depend on.
The company has introduced Cohesity Agent Resilience, a new capability within the Cohesity Data Cloud designed to discover, protect and recover the infrastructure behind enterprise AI agents. The announcement was made at Cohesity Catalyst, alongside the company’s vision for Autonomous Cyber Resilience and the launch of the Cohesity AI Resilience Academy.
Agent Resilience is currently available to select customers, with general availability targeted for the end of 2026. It initially supports Amazon Bedrock AgentCore and Amazon Bedrock Agents, with support for Microsoft and Google agent platforms planned for the future.
The move comes as AI agents increasingly gain the ability to query databases, modify workflows and operate using privileged credentials. That creates a recovery challenge that conventional AI governance and observability tools do not necessarily address.
According to Gartner, up to 40% of enterprise applications are expected to include integrated task-specific agents in 2026, compared with less than 5% previously. Cohesity argues that while monitoring can identify unexpected agent behaviour, it does not necessarily provide a way to restore data or systems after an agent has altered, corrupted or deleted them.
AI agents create a new recovery challenge
Cohesity’s fifth annual Global Cyber Resilience Report highlights the scale of the issue. The research found that 56% of organisations surveyed said they were not well prepared to detect or contain unintended actions by AI agents and automated workflows. Meanwhile, 58% said they were not very confident in their ability to verify the integrity of AI models and associated data following a cyberattack.
“Detection can tell you an AI agent went off course. It cannot undo the changes,” said Vasu Murthy, Chief Product Officer, Cohesity. “Cohesity Agent Resilience provides a precise recovery path for both the agents and the resources they impact. Our vision for Autonomous Cyber Resilience is to use agentic workflows to reduce manual work from response and recovery.”
An AI agent can depend on several components, including its memory, configuration, credentials, guardrails and workflows. Cohesity Agent Resilience initially focuses on protecting agent memory and configuration using the company’s existing snapshot architecture, immutable backups and clean-room recovery capabilities.
The technology is designed around two areas of protection. First, organisations can protect agent state and use point-in-time recovery to restore an agent to a known-good state following memory corruption, configuration problems or malicious activity.
Second, it can protect the databases, file systems and other services that agents interact with, allowing affected resources to be recovered when necessary.
Mapping the infrastructure behind an agent
Understanding what an AI agent can access is becoming as important as protecting the agent itself. Cohesity Agent Resilience provides an agent topology view showing an agent alongside its memory stores, connected applications, databases and supporting infrastructure.
The aim is to give IT and security teams a clearer picture of dependencies, protection coverage and the resources involved in restoring operations following an incident. The initial integration is with Amazon Bedrock. Microsoft and Google agent platforms are on Cohesity’s roadmap.
From cyber resilience to autonomous workflows
Beyond Agent Resilience, Cohesity is outlining a longer-term approach to Autonomous Cyber Resilience, using agentic workflows to automate elements of its five-step cyber resilience framework. The framework covers protecting data, identity, applications and agents; ensuring recoverability; remediating cyber and AI threats; practising application recovery; and continually improving an organisation’s data and AI risk posture.
The proposed approach would shift some of the work away from manually configuring individual protection and recovery policies. For example, administrators could use Cohesity Copilot to define objectives for critical applications and data, including recovery time objectives (RTOs), recovery point objectives (RPOs), threat-scanning requirements and recovery-testing requirements.
Cohesity Data Cloud could then assess the resilience posture of those workloads and recommend protection policies, threat-scanning strategies and recovery exercises. Those recommendations would be presented for approval before execution. During an incident, automated workflows could also help assess the scope of an attack, identify indicators of attacker activity and prepare an isolated recovery environment to support investigation and recovery.
The company stresses that the proposed model retains a human in the loop rather than removing human oversight from resilience decisions.
Automated protection for sensitive data
Cohesity has also made automated protection for newly discovered sensitive data generally available to customers using Cohesity Data Cloud Enterprise Edition and Cohesity DSPM.
The capability continuously discovers and classifies sensitive information, assesses whether it is already protected and can trigger protection actions according to defined policies. Administrators can configure and manage the workflows directly or through Cohesity Copilot.
This represents an early step towards Cohesity’s broader autonomous resilience model, where discovering risks and responding to them become more continuous processes rather than activities performed only during periodic assessments.
Connecting recovery with AI tools
The Autonomous Cyber Resilience approach builds on Cohesity RecoveryAgent, which is designed to orchestrate elements of incident response and recovery and help security and IT teams work from a common recovery plan.
Cohesity also says Cohesity Maestro, with expanded capabilities expected later in 2026, will connect its protection, response and recovery capabilities with customers’ preferred AI tools, including Claude, ChatGPT and Gemini, alongside Cohesity Helios, its unified management console.
The company plans to introduce additional automation as its Autonomous Cyber Resilience vision develops towards commercial availability.
“Cyber resilience is not a one-time assessment. It requires teams to protect data, test recovery, detect threats, rehearse responses, and continually improve their risk posture,” said Murthy. “Agentic workflows can take on more of that routine work and help keep the plan current.”
Building an AI resilience skillset
Alongside its technology announcements, Cohesity has launched the Cohesity AI Resilience Academy, a new learning path within Cohesity Academy.
Its first course, Foundations of AI Resilience with Cohesity, is a free, self-paced programme lasting approximately 25 to 30 minutes. Rather than focusing on product configuration, it introduces the concepts and terminology organisations need as AI moves from assisting people to taking action.
The course covers the difference between AI assistants and AI agents, the additional risks created when AI can make changes, and gaps that can emerge before and after an agent acts.
It also introduces Cohesity Gaia Catalog and Agent Resilience as examples of how Cohesity approaches those lifecycle gaps. The company notes that some of the capabilities discussed in the course may not yet be generally available.
Cohesity Catalyst attendees will receive early access to the course through a post-event enrolment link. It will initially remain exclusive to attendees for approximately two weeks before being added to the wider Cohesity Academy catalogue.
Learners who complete the course will receive a Credly badge, Foundations of AI Resilience with Cohesity, which can be shared on LinkedIn.
For enterprises deploying increasingly autonomous AI systems, the issue is therefore moving beyond whether an agent can perform a task. As those agents gain access to business-critical information and systems, organisations also need to consider what happens when an agent makes the wrong change, is compromised or operates outside its intended boundaries.
Cohesity’s latest announcements position recovery as a necessary part of that equation, alongside AI governance, monitoring and security.



