The news cycle has been dominated with coverage about the risks of AI – from agents gone rogue to a public outcry to slow and regulate its progress. Collectively, these stories say something important about where AI risk is actually headed. In September 2026 alone:
- OpenAI announced six previously undisclosed incidents of concerning model behavior observed over the past six months as well as a new reporting framework for sharing such updates in the future.
- Researchers disclosed that OpenAI agents flooded the RubyGems software registry with more than 2,000 malicious packages in May, months before anyone connected it to the company.
- Anthropic published an alignment assessment describing a fourth incident in which a Claude model reached a real third-party system during what was supposed to be a sandboxed cybersecurity evaluation, using terms such as “recklessness” and “biased reasoning” to describe the models’ behavior.
- The CEOs of Anthropic and OpenAI both called for the industry to slow down, warning that a swarm of agents could take over meaningful parts of the internet within months if safeguards do not keep pace.
- The Wall Street Journal reported that Google Gemini hacked three companies, though Google said it didn’t consider it an instance of misalignment.
It is tempting to file these stories under “frontier lab problem” and move on. I think that is the wrong read. Enterprises don’t often have the luxury of waiting for industry and regulators to slow growth, never mind if and when they do. Cyber risk from agents is already inside most environments, and policy timelines may not change how fast it moves.
The threat vectors are not new. A malicious package. A misconfigured environment. A credential exposed longer than it should have been. Most CISOs have been managing these risks for years. With AI, what’s changed is scale and visibility: thousands of agents acting continuously, coordinating in ways no one anticipated or witnessed.
Case in point: Due to the enormous scale of the OpenAI/RubyGems incident, it took specialized researchers months to reconstruct. What enterprise can withstand that much time passing between incident and understanding?
Many signs predict further proliferation, not less. In fact, IDC predicts that by 2029, the number of agents deployed in production environments will exceed 1 billion and that by 2027, more than 40% of enterprise application capabilities will be enhanced by agentic automation.
What ‘AI-Ready’ Cyber Resilience Actually Requires
Commvault stands firm that resilience only counts if the recovery is clean. A restore that brings back a compromised file, a corrupted dataset, or a still-infected agent identity is not resilience – it’s a second incident. That premise did not change when agentic AI arrived. It became more important. That’s why we built our AI resilience capabilities with the following in mind:
Resilience must operate at machine speed. Rapidly evolving AI capabilities are increasing the speed of attacks. According to CrowdStrike’s 2026 Global Threat Report, breakout time – the window between an attacker’s first access and their first move deeper into the network – is 29 minutes, down from 48 minutes the year before. To say that recovery requires direct and immediate response to data security signals is an understatement. Otherwise, business-as-usual routing via through manual approvals can mean the threat keeps advancing.
Depth across every system and environment. Agents are indiscriminate in where and what they chose to exploit and attack, whether that’s a public code registry, data center or SaaS environment. Coverage should span structured and unstructured data, SaaS applications, and infrastructure alike, as well as cloud, edge, on-premises, and hybrid environments.
Identity resilience extends beyond people. With non-human identities outnumbering humans 144 to 1, governance is re-emerging as a modern-day challenge. When the blast radius of an attack can expand in seconds, effective data security teams must understand not only what changed and who changed it, but when an alert merits a recovery action.
The greatest AI risk is not confined to frontier labs. For enterprises, resilience must be treated as foundational before the scale of agentic activity makes the risk impossible to contain. That responsibility sits with the enterprise.
Learn more about how Commvault Cloud can help you build resilience in your AI stack here.
Sankalp Damani is Senior Director, Product Management, at Commvault.