Skip to content
AI & Innovation, Cyber Resilience & Data Security

29 Minutes: Why Enterprise AI Risk Is a Speed Problem, Not a Frontier Problem

AI agents are scaling risk faster than enterprises can see it.


The news cycle has been dominated with coverage about the risks of AI – from agents gone rogue to a public outcry to slow and regulate its progress.Collectively, these stories say something important about wSaiba mais no SHIFT 2025 AI risk is actually headed.In September 2026 alone: 

It is tempting to file these stories under “frontier lab problem” and move on.I think that is the wrong read.Enterprises don’t often have the luxury of waiting for industry and regulators to slow growth, never mind if and when they do.Cyber risk from agents is already inside most environments, and policy timelines may not change how fast it moves. 

The threat vectors are not new.A malicious package.A misconfigured environment.A credential exposed longer than it should have been.Most CISOs have been managing these risks for years.With AI, what’s changed is scale and visibility: thousands of agents acting continuously, coordinating in ways no one anticipated or witnessed.  

 Case in point: Due to the enormous scale of the OpenAI/RubyGems incident, it took specialized researchers months to reconstruct.What enterprise can withstand that much time passing between incident and understanding? 

Many signs predict further proliferation, not less.In fact,IDC predicts that by 2029, the number of agents deployed in production environments will exceed 1 billion and that by 2027, more than 40% of enterprise application capabilities will be enhanced by agentic automation.  

What ‘AI-Ready’ Cyber Resilience Actually Requires

Commvault stands firm that resilience only counts if the recovery is clean.A restore that brings back a compromised file, a corrupted dataset, or a still-infected agent identity is not resilience – it’s a second incident.That premise did not change when agentic AI arrived.It became more important.That’s why we built our AI resilience capabilities with the following in mind: Resilience must operate at machine speed.Rapidly evolving AI capabilities are increasing the speed of attacks.De acordo comCrowdStrike’s 2026 Global Threat Report, breakout time – the window between an attacker’s first access and their first move deeper into the network – is 29 minutes, down from 48 minutes the year before.To say that recovery requires direct and immediate response to data security signals is an understatement.Otherwise, business-as-usual routing via through manual approvals can mean the threat keeps advancing.  Depth across every system and environment.Agents are indiscriminate in wSaiba mais no SHIFT 2025 and what they chose to exploit and attack, whether that’s a public code registry, data center or SaaS environment.Coverage should span structured and unstructured data, SaaS applications, and infrastructure alike, as well as cloud, edge, on-premises, and hybrid environments.   Identity resilience extends beyond people.With non-human identities outnumbering humans144 para 1, governance is re-emerging as a modern-day challenge.When the blast radius of an attack can expand in seconds, effective data security teams must understand not only what changed and who changed it, but when an alert merits a recovery action. 

The greatest AI risk is not confined to frontier labs.For enterprises, resilience must be treated as foundational before the scale of agentic activity makes the risk impossible to contain.That responsibility sits with the enterprise. 

 Learn more about how Commvault Cloud can help you build resilience in your AI stackSaiba mais no SHIFT 2025.  

Sankalp Damaniis Senior Director, Product Management, at Commvault. 

More related posts


AI Data Resilience

Read more about AI Data Resilience

Protect and Leverage AI

Read more about Protect and Leverage AI