Commvault Warns ANZ Organisations Are Scaling AI Faster Than They Can Secure It

     

    For Commvault, the conversation around cyber resilience in 2026 is no longer centred purely on security. It is increasingly about operational continuity, business survivability, and whether organisations can continue functioning when disruption inevitably occurs.

    That was the key message emerging from Commvault’s recent ANZ media roundtable discussing findings from its sixth annual State of Data Resilience report, where executives warned that organisations across Australia and New Zealand are rapidly scaling AI adoption while struggling to maintain control over resilience, governance, and recoverability.

    Speaking during the session, Martin Creighan, Vice President APAC at Commvault, argued that resilience has shifted beyond the remit of IT teams and into the core operational fabric of the enterprise.

    “Traditionally, resilience has been treated as an IT capability. Today, it’s becoming an operational requirement across the business,” Creighan said.

    “It’s no longer about recovering eventually, it’s about maintaining operations with minimal disruption. Failure is no longer measured by whether a breach occurs. It’s measured by downtime.”

    The findings are based on research involving 411 organisations across Australia and New Zealand, including CIOs, CISOs, and senior IT leaders, offering what Commvault describes as a practical snapshot of how enterprises are managing increasingly complex hybrid environments.

    That complexity is accelerating rapidly.

    According to the report, organisations are now managing expanding estates spanning public cloud, private infrastructure, SaaS platforms, and increasingly AI-driven workloads. Data growth across ANZ has again accelerated beyond 30 percent year-on-year, while 67 percent of workloads now sit within multi-cloud or hybrid environments.

    Creighan said the scale of AI adoption is fundamentally reshaping enterprise environments.

    “AI is making environments even more complex. It’s accelerating data proliferation, with data growing exponentially across organisations,” he said.

    “At the same time, it’s increasing pressure from a governance, regulation, and compliance perspective.”

    The conversation repeatedly returned to the challenge of operational control.

    While most organisations now acknowledge the need for AI governance, Commvault argued that policy creation alone is insufficient if businesses cannot operationalise and enforce those controls consistently across environments.

    “What’s missing is operational control,” Creighan said.

    “Policies are being defined, but organisations are not always able to enforce them effectively across environments. That creates gaps that can be exploited.”

    The rise of agentic AI is also introducing entirely new resilience concerns.

    During the roundtable, Gareth Russell, Field CTO ANZ at Commvault, said organisations have moved beyond experimentation and are now embedding AI into live business operations.

    “AI growth is unmatched right now,” Russell said.

    “95 percent of organisations in ANZ are increasing investment in AI, with around a third increasing spend by more than 25 percent. More than 30 percent are deploying or trialling agentic AI.”

    “What’s changed is that organisations are no longer experimenting. AI is moving into core business operations. We’ve effectively moved from experimentation to execution.”

    But according to the research, governance maturity is not keeping pace.

    Only one-third of organisations surveyed said they had assessed AI risks before deployment, while just 36 percent had planned resilience strategies specifically for AI agents. Meanwhile, 71 percent said AI was increasing operational complexity.

    Russell warned that organisations are effectively “building while operating,” creating risks around governance, hallucinations, bias, and unpredictable autonomous behaviour.

    The challenge becomes even more pronounced when recovery enters the equation.

    One of the starkest findings from the report was the gap between executive recovery expectations and operational reality. While 83 percent of leaders expected their organisation to resume operations within five days of a major incident, the actual average recovery time across ANZ sits at 28 days.

    Russell said this disconnect highlights a broader issue around preparedness.

    “The real question organisations need to ask is: what are you going to do for 28 days?” Russell said.

    “Even getting back to a minimum level of operation takes time.”

    Ransomware pressures continue to expose those weaknesses.

    The report found that 30 percent of organisations admitted to paying a ransom following an incident, yet half of those still failed to recover successfully afterwards.

    Creighan said those decisions are often driven by a lack of confidence in existing recovery capabilities.

    “Most organisations that pay do so because they lack confidence in their backup and recovery strategy,” he said.

    To address that, Commvault is encouraging organisations to rethink resilience through what it describes as a “minimum viable company” approach — identifying the core applications, systems, and datasets required to continue operating during a crisis and ensuring they can be restored rapidly.

    The discussion also highlighted how AI itself is now becoming a critical workload requiring protection.

    In one example cited during the session, an organisation was operating approximately 30,000 AI agents interacting with enterprise systems, data stores, and identity frameworks simultaneously.

    Russell said this is why resilience strategies must evolve beyond traditional backup thinking.

    “From our perspective, managing AI requires a lifecycle approach,” he said.

    “It starts with activating trusted data, then protecting AI agents, and ensuring recovery to a trusted state.”

    “The goal is not just to build AI, but to operate it safely at scale.”

    For Australian and New Zealand organisations already navigating growing regulatory expectations around operational resilience, cyber governance, and data recoverability, the message from Commvault was clear: AI adoption is accelerating regardless, but resilience maturity still has significant ground to cover.