When frontier AI models started making headlines, most of the discussion centered on one question: What happens when attackers gain access to them?
It’s a fair question.
Models capable of discovering vulnerabilities faster, chaining exploits together, and operating at unprecedented speed naturally raise concerns for every CISO.
But after spending time talking with customers over the past several months – and in my conversation with Tim Zonca, Commvault’s VP of Portfolio Marketing, in this episode of STRIVE – I think there’s an even more important question emerging.
What happens to resilience itself?
Because while frontier AI will undoubtedly accelerate cyber threats, it’s also accelerating something else: Enterprise complexity.
Watch the full episode.
Key Takeaways
- Frontier AI isn’t just accelerating cyberattacks – it’s accelerating enterprise complexity.
- Vulnerability management isn’t disappearing, but the speed and scale of discovery are changing dramatically.
- AI systems introduce entirely new recovery dependencies, including agents, vector databases, embeddings, and distributed state.
- Organizations need a coherent understanding of their environments before they can recover them.
- The next generation of resilience will depend on trusted systems of record that explain what happened, why it happened, and how to recover confidently.
The Conversation Has Changed
One thing Tim and I discuss early in the episode is how differently organizations are reacting to frontier AI.
- Some see an entirely new class of cybersecurity challenge.
- Others view it as simply the next evolution of vulnerability management.
What’s interesting is that neither perspective is necessarily wrong.
The processes organizations use to identify, prioritize, and remediate vulnerabilities remain familiar. But the pace at which AI can discover those vulnerabilities – and uncover entirely new chains of attack – is unlike anything we’ve seen before.
That’s the shift.
The work isn’t fundamentally different. The speed is.
When AI Changes the Shape of Recovery
Most conversations about AI focus on security and prevention:
- How do we secure models?
- How do we protect prompts?
- How do we defend against AI-assisted attacks?
Those are important questions. But resilience introduces a different one: What exactly are we recovering?
Traditional enterprise applications already involve complicated relationships between infrastructure, applications, and data. AI expands that picture considerably. Now there are agents operating across multiple systems. Vector databases. Embeddings. Models interacting with different data sources simultaneously. It’s become far more than a traditional application stack.
Recovery is no longer about restoring an application. It’s about restoring an ecosystem.
Sneak Peek: Check This Out
In this moment from our STRIVE discussion, Tim and I discuss the growing complexity of AI stacks, what coherent recovery is (and why it matters), and how Commvault is helping our customers with full AI-stack recovery.
Why Coherency Matters
One idea that keeps surfacing throughout our conversation is coherence.
For years, organizations have worked to map application dependencies, understand infrastructure relationships, and identify critical services. AI makes that challenge significantly more difficult.
Applications no longer interact with a single database or service. They may depend on multiple models, agents, data stores, and orchestration layers – all changing dynamically.
Understanding those relationships isn’t just an architectural exercise anymore.
It’s a recovery requirement.
Because if you don’t understand what makes up the system, it’s difficult to know whether you’ve actually recovered it.
A New System of Record
Another concept from Tim that I found compelling is the idea of a system of record for the AI era. Historically, systems of record gave organizations confidence in business data. Customer records lived in CRM platforms. Financial records lived in ERP systems.
AI changes that expectation.
Organizations increasingly need trusted visibility into how data is used, what agents interact with it, why decisions are made, and whether restored environments represent a known-good state.
That doesn’t replace resilience. It strengthens it. Because confidence in recovery depends on confidence in what you’re recovering.
AI Can Also Help Solve the Problem
As organizations struggle to understand increasingly distributed environments, AI becomes a powerful tool for discovery, classification, and policy recommendation.
Rather than manually identifying relationships across sprawling environments, organizations can use AI to help identify dependencies, recommend protection policies, and continuously update those relationships as environments evolve.
That’s an important shift.
The same technology that’s adding to organizational complexity may also become one of the best tools for managing it.
Why This Conversation Matters
Frontier AI isn’t simply introducing another cybersecurity challenge. It’s forcing organizations to rethink resilience itself.
Recovery is becoming less about individual systems and more about restoring trusted business operations across increasingly intelligent environments. That means resilience strategies must evolve alongside the technologies they’re protecting.
Organizations that prepare for that shift won’t just recover faster. They’ll recover with greater confidence.
Watch the Full Episode
In this conversation, Tim and I explore:
- How frontier AI is changing enterprise risk.
- Why vulnerability management is entering a new phase.
- What AI means for modern recovery architectures.
- The role of coherent recovery across AI-enabled environments.
- Why trusted systems of record will become increasingly important.
FAQs
Q: What are frontier AI models?
A: Frontier AI models are the latest generation of highly capable AI systems designed to solve increasingly complex reasoning and cybersecurity tasks.
Q: Why are organizations concerned about them?
A: They dramatically accelerate vulnerability discovery, exploit chaining, and security research, increasing both defensive and offensive capabilities.
Q: How does AI change cyber resilience?
A: AI introduces new dependencies – including agents, models, vector databases, and distributed states – that make recovery more complex.
Q: What is a coherent recovery strategy?
A: It’s an approach that restores not only data, but also the applications, infrastructure, dependencies, and AI components required for trusted business operations.
Q: What is a system of record in the AI era?
A: It’s a trusted source that helps organizations understand what happened, why it happened, and whether recovered systems represent a known-good state.
Q: What should organizations do now?
A: Begin mapping AI dependencies, understand how AI changes recovery requirements, and develop resilience strategies that account for increasingly intelligent application environments.
Chris Mierzwa is Senior Director of Portfolio Marketing at Commvault.