Cohesity Launches Agent Resilience to Roll Back Wayward AI Agents
Cohesity introduced Agent Resilience at its Catalyst conference, a Data Cloud capability that backs up AI agent memory and configuration so enterprises can restore a trusted state. It also outlined a longer-term automation plan and reported that 69% of surveyed organizations suffered a material cyberattack in the past year.
The need arises because AI agents inside large companies already query databases and act with privileged credentials, sometimes with nobody reviewing each step. Cohesity said governance and observability tools can flag unexpected behavior but cannot restore the data or systems an agent has changed, corrupted or deleted. "Detection can tell you an AI agent went off course," said Vasu Murthy, Cohesity's chief product officer. "It cannot undo the changes."
Cohesity said most organizations do not protect agent state today, and a prompt injection can leave an agent that looks normal on the surface acting on information it should never have trusted. An agent with no clean recovery point may have to be wiped and rebuilt. Agent Resilience covers memory and configuration at launch, protected by the same immutable backups and clean-room recovery Cohesity already runs for on-premises, cloud and software-as-a-service workloads.
If something does go wrong, an administrator selects a recovery point from before the suspicious behavior started, and only the affected memory or settings are restored. A second function finds the databases, file systems and vector stores an agent works with and protects those as well. Each agent also gets a topology map listing the systems it connects to and the data it can reach, which Cohesity says is meant to expose protection gaps and recovery dependencies before anything breaks.
At launch, the service only covers agents built on Amazon Web Services Inc.'s Bedrock, including both Bedrock AgentCore and Bedrock Agents. Support for Microsoft Corp. and Google LLC agent platforms is on the roadmap. Only select customers have access until general availability, which Cohesity expects by the end of the year.
The automation plan Cohesity also laid out at Catalyst is on a longer timeline. Called Autonomous Cyber Resilience, it would keep data discovery and protection running without pause. Cohesity said resilience plans built on manual triage may not keep pace with attackers using AI to speed up their intrusions. Under the plan, an administrator would give Cohesity Copilot, the company's natural-language assistant, a goal such as requiring every application the business needs during a cyberattack to meet set recovery time and recovery point objectives. Cohesity Data Cloud would assess those workloads and recommend protection policies, threat scans and recovery rehearsals. Nothing would run without approval.
Once an attack is underway, administrators could launch automated workflows that size up the impact and look for signs of attacker activity. The same workflows would prepare an isolated environment for investigation and recovery. The approach builds on Cohesity RecoveryAgent, which already orchestrates parts of incident response and recovery. Cohesity Maestro comes next. First shown in June, it will let customers reach Cohesity's protection and recovery functions from Anthropic PBC's Claude, OpenAI Group PBC's ChatGPT and Google's Gemini, and the company expects to ship it later this year. Murthy said cyber resilience is "not a onetime assessment" and that agentic workflows can take on more of the routine work of keeping a plan current.
One piece of the plan is shipping now. Customers that run Cohesity Data Cloud Enterprise Edition with Cohesity DSPM, the company's data security posture management tool, can automatically protect newly discovered sensitive data that has no protection yet. In a tutorial on its Autonomous Cyber Resilience plans, Cohesity showed administrators building dynamic object groups from the tool's sensitivity tags, such as everything marked Financial or Restricted, then attaching smart rules that set backup frequency and retention. New data joins a group as soon as it is classified, and a simulation step previews which objects a rule would add or drop before anything changes.
Cohesity paired the Catalyst announcements with its fifth annual Global Cyber Resilience Report. Of the more than 3,200 information technology and security decision-makers Vanson Bourne polled across 11 countries for the report, 69% said their organization had been hit by a material cyberattack in the past 12 months. In last year's report, the figure was 54%.