Cohesity Agent Resilience Brings Backup, Recovery and Cyber Protection to Enterprise AI Agents
The company announced the product on September 16, 2026, at Cohesity Catalyst. At launch, Agent Resilience supports Amazon Bedrock AgentCore and Amazon Bedrock Agents, while Microsoft and Google agent platforms are on the company's roadmap.
The product is currently available to select customers, with general availability targeted for the end of 2026.
The launch reflects an important shift in enterprise AI security.
Organizations are increasingly thinking not only about how to monitor AI agents, but also about how to recover when an agent causes damage.
What Is Cohesity Agent Resilience?
Cohesity Agent Resilience is a new capability within the Cohesity Data Cloud designed to protect the infrastructure that supports enterprise AI agents.
An AI agent is not simply a model.
It can depend on several components, including:
- Agent memory
- Configuration
- Credentials
- Guardrails
- Workflows
- Databases
- File systems
- Connected applications
- Supporting infrastructure
If one of these components is corrupted or compromised, the agent may no longer behave as expected.
Cohesity's approach is to protect both the agent itself and the resources that the agent manages.
This gives organizations a recovery layer alongside existing AI monitoring and governance tools.
Why AI Agent Recovery Is Becoming Important
Traditional AI applications often provide information to users.
Agentic applications can go further.
They may query databases, update records, execute workflows or use privileged credentials.
That additional capability makes agents more useful, but it also creates more potential points of failure.
Cohesity says its research found that 56% of organizations surveyed were not well prepared to detect or contain unintended actions by AI agents and automated workflows. The company also reports that 58% were not very confident in their ability to verify the integrity of AI models and related data following a cyberattack.
These figures come from Cohesity's fifth annual Global Cyber Resilience Report and represent the company's survey findings.
The broader issue is straightforward.
Monitoring can tell an organization that an agent has behaved unexpectedly.
It does not necessarily restore the state that existed before the problem.
That is the gap Cohesity Agent Resilience is designed to address.
Agent Resilience Protects AI Agent State
One of the product's two core functions is protecting agent state.
Cohesity says Agent Resilience protects agent memory and configuration using technologies that already form part of its data-protection architecture.
These include:
- Snapshot architecture
- Immutable backups
- Clean-room recovery
- Point-in-time recovery
The objective is to allow an organization to restore an AI agent to a known-good state after events such as:
- Memory corruption
- Configuration mistakes
- Malicious activity
- Other damaging changes
This is different from simply restarting an AI agent.
Restarting an agent does not necessarily restore the memory, configuration or supporting information that existed before the incident.
A recovery system needs to know what the trusted state looked like.
Cohesity Also Protects What AI Agents Manage
The second major function extends protection beyond the AI agent itself.
AI agents frequently interact with external resources.
For example, an enterprise agent could work with:
- Databases
- File systems
- Business applications
- Data repositories
- Workflow systems
If an agent changes something incorrectly, restoring the agent alone may not be enough.
Cohesity says Agent Resilience can also protect the databases, file systems and other services that agents interact with. This is intended to enable precise recovery of affected resources when necessary.
That creates a two-layer recovery model:
Protect the agent → Protect what the agent changes
This is one of the more important aspects of the launch.
Agent Topology Shows the Connections Behind an AI Agent
Another capability is agent topology.
Enterprise AI agents can have complicated dependencies.
One agent might rely on a particular memory store, database, application and authentication system.
Without visibility into those relationships, recovery teams may not know which systems need to be restored.
Cohesity says its agent topology capability provides a unified view of an agent and its connected resources.
That includes:
- Agent memory stores
- Connected applications
- Databases
- Supporting infrastructure
The purpose is to help teams understand dependencies, determine protection coverage and identify the resources required to restore trusted operations after an incident.
For large enterprises, that dependency mapping can be particularly important as the number of AI agents grows.
Amazon Bedrock Is Supported at Launch
Cohesity Agent Resilience does not initially support every AI agent platform.
At launch, the product integrates with Amazon Bedrock AgentCore and Amazon Bedrock Agents. Cohesity says additional agent platforms from Microsoft and Google are on its roadmap.
This makes Amazon Bedrock the first major platform covered by the new capability.
The phased approach also shows that AI infrastructure protection is likely to become a broader category.
As organizations deploy agents through different cloud platforms, recovery systems will need to understand the architecture of each environment.
Cohesity Wants to Automate Cyber Resilience
Agent Resilience is only one part of Cohesity's broader announcement.
The company also introduced its vision for Autonomous Cyber Resilience.
The idea is to use agentic workflows to automate parts of its existing cyber-resilience framework.
Cohesity describes the framework around five areas:
- Protect data, identity, applications and agents.
- Help ensure recoverability.
- Remediate cyber and AI threats.
- Practice application recovery.
- Optimize data and AI risk posture.
The company's goal is to move beyond manually configured, point-in-time recovery plans toward workflows that can continuously assess protection and recovery readiness.
Cohesity says humans would remain involved in the process.
That is important because autonomous recovery itself can create risks if an automated system makes an incorrect decision.
Cohesity Copilot Could Define Recovery Objectives
Cohesity says its Autonomous Cyber Resilience approach would allow teams to define objectives through Cohesity Copilot rather than manually configuring policies across individual applications.
The approach builds on Cohesity RecoveryAgent, which is designed to orchestrate parts of incident response and recovery.
The broader idea is to let AI assist with recovery operations without eliminating human oversight.
Instead of manually creating a long sequence of recovery procedures, teams could define what needs to be protected and recovered while the system handles more of the operational coordination.
Cohesity describes this as a path toward reducing manual work involved in response and recovery.
Cohesity Maestro Will Connect More AI Tools
Cohesity also says Cohesity Maestro will eventually connect its protection, response and recovery capabilities with customers' preferred AI tools.
The company specifically names:
- Claude
- ChatGPT
- Gemini
Maestro is also intended to connect these capabilities with Cohesity Helios, the company's unified management console.
Expanded Maestro capabilities are expected later in 2026.
This is important because enterprise AI environments are rarely built around a single AI provider.
A company could use one model for coding, another for customer support and another for internal research.
Security and recovery infrastructure therefore needs to work across multiple AI environments.
AI Agents Need More Than Monitoring
The Cohesity launch highlights an important distinction in AI security.
There are several different questions an enterprise needs to answer:
What is the agent doing?
That is an observability problem.
Is the agent allowed to do it?
That is a governance and access-control problem.
Did the agent cause damage?
That is an incident-response problem.
How do we undo the damage?
That is a recovery problem.
Cohesity Agent Resilience focuses heavily on the final question.
That makes it different from many AI security products that concentrate primarily on detection, policy enforcement or runtime monitoring.
How Agent Resilience Could Help After an AI Incident
Consider an enterprise AI agent managing a database.
The agent has permission to modify records as part of its normal workflow.
A configuration mistake causes the agent to make incorrect changes.
A monitoring platform may detect unusual activity.
A security platform may identify the abnormal behavior.
But the organization still needs to restore the affected information.
With Agent Resilience, Cohesity's intended workflow is to maintain protected versions of the agent state and connected resources so teams can recover the affected environment to an earlier trusted state.
The exact recovery process will depend on the customer's architecture and deployment.
The underlying principle is simple:
Detection identifies the problem. Recovery restores the system.
AI Agents Are Changing the Traditional Backup Problem
Traditional backup systems were designed around applications, databases, virtual machines and files.
AI agents introduce another type of workload.
An agent can have:
- Persistent memory
- Dynamic configuration
- Tool permissions
- External dependencies
- Workflow state
- Connections to multiple systems
That makes protecting an AI agent more complicated than simply backing up a model file.
The model itself may be hosted by a third party.
The agent's valuable state may instead exist in databases, configuration files, memory stores and external tools.
Cohesity's approach reflects that reality by focusing on the infrastructure surrounding the agent, not simply the underlying AI model.
Cohesity Also Launches AI Resilience Academy
Alongside Agent Resilience, Cohesity announced the Cohesity AI Resilience Academy.
The company says the new learning path begins with a free, self-paced course called Foundations of AI Resilience with Cohesity.
The course is designed to help organizations understand risks associated with AI systems as they move from advising people toward taking actions.
Cohesity says the course takes approximately 25–30 minutes and focuses on concepts rather than product configuration.
This provides an educational component alongside the product launch.
The company is effectively addressing both sides of the problem:
Technology to protect AI systems + training to understand AI resilience.
What Makes Agent Resilience Different From AI Agent Security Tools?
The AI security market already contains tools designed to detect vulnerabilities, control agent permissions and monitor agent behavior.
TheInfoBytes has previously covered products such as Tenable AI Inspector, which focuses on securing AI agents and MCP servers, and Operant AI's Semantic Firewall, which focuses on preventing dangerous agent actions.
Cohesity is approaching the problem from another direction.
Its focus is recovery.
That distinction can be summarized as:
| AI Security Layer | Primary Purpose |
|---|---|
| Agent monitoring | Detect unexpected behavior |
| Security controls | Restrict risky actions |
| Governance | Define acceptable behavior |
| Threat detection | Identify attacks |
| Agent resilience | Restore trusted state after damage |
These layers can complement each other rather than necessarily replacing one another.
An enterprise could need controls that prevent an unsafe action and recovery infrastructure for situations where prevention fails.
Why Agent Recovery Could Become a Standard Enterprise Requirement
AI agents are increasingly being deployed into workflows where errors can affect real business systems.
A customer-service agent might modify records.
A coding agent might change production infrastructure.
A finance agent might interact with payment systems.
A research agent might access sensitive data.
As these systems become more autonomous, the potential consequences of an incorrect action increase.
That means enterprise AI deployment may eventually require the same principles that organizations already apply to critical applications:
Backup. Monitoring. Access control. Recovery. Testing.
Cohesity is applying that model directly to agentic AI.
What Businesses Should Consider Before Deploying AI Agents
Cohesity's launch also highlights several questions organizations should ask before giving AI agents access to important systems.
What Can the Agent Change?
Companies should define exactly which systems, records and resources an agent can modify.
Can Its Actions Be Reversed?
Organizations should know whether changes can be rolled back if an agent makes a mistake.
Where Is Agent Memory Stored?
Agent memory may contain important context and should be included in protection strategies where appropriate.
What Happens During a Cyberattack?
Recovery procedures should account for compromised credentials, corrupted data and malicious changes.
Are Recovery Procedures Tested?
Having backups is not enough if recovery has never been tested.
Who Approves Recovery Actions?
Organizations should establish appropriate human oversight for critical restoration decisions.
These questions become increasingly important as AI agents move from experimentation into production environments.
Cohesity Agent Resilience Availability
Cohesity Agent Resilience is currently available to select customers.
The company is targeting general availability by the end of 2026.
At launch, Amazon Bedrock AgentCore and Amazon Bedrock Agents are supported.
Microsoft and Google agent platforms are on the roadmap.
Organizations interested in the product will need to contact Cohesity for availability and deployment information.
Cohesity Agent Resilience official announcement
The Bigger Shift: AI Agents Need a Recovery Layer
The most interesting part of Cohesity's launch is not simply another AI security product.
It is the recognition that AI agents are becoming operational software.
Once an agent can access databases, modify files, use credentials and trigger workflows, it becomes part of an organization's infrastructure.
And infrastructure needs recovery.
This changes how companies should think about agentic AI.
The question is no longer only:
“How do we make this AI agent safer?”
It is also:
“What happens if the agent fails anyway?”
That second question is where resilience becomes important.
Final Takeaway
Cohesity Agent Resilience brings a familiar enterprise concept — backup and recovery — into the rapidly developing world of AI agents.
The new capability protects agent memory and configuration while also protecting the databases, file systems and other services those agents interact with.
At launch, it supports Amazon Bedrock AgentCore and Amazon Bedrock Agents, with Microsoft and Google platforms planned for the future. The product is currently available to select customers, with general availability targeted for the end of 2026.
Cohesity is also building a broader Autonomous Cyber Resilience strategy around agentic workflows, Cohesity Copilot and RecoveryAgent.
The significance of the launch is broader than one company's product roadmap.
As AI agents gain more access to business systems, organizations will need more than model security and runtime monitoring.
They will need to know what an agent changed, what resources it depends on and how to restore those systems when something goes wrong.
That makes AI resilience an increasingly important part of enterprise AI infrastructure.
The next phase of agentic AI may therefore not be defined only by how much an AI agent can accomplish.
It may also be defined by how safely an organization can recover when the agent gets it wrong.
FAQs
What is Cohesity Agent Resilience?
Cohesity Agent Resilience is a Cohesity Data Cloud capability designed to discover, protect and recover infrastructure supporting enterprise AI agents, including agent memory, configuration and connected resources.
What does Cohesity Agent Resilience protect?
At launch, the product protects AI agent memory and configuration as well as databases, file systems and other services that agents interact with.