Home Cyber Security

The Real AI Risk for Enterprises Isn’t the Model — It’s Everything Around It

For years, the conversation around artificial intelligence has focused on what AI models can do. But according to new research from Commvault, the bigger issue for enterprises may now be everything surrounding the models themselves: the data, identities, governance controls, and operational resilience needed to keep AI environments trustworthy.

Commvault’s State of Data Resilience – Australia and New Zealand, 6th Edition paints a picture of organisations rapidly embracing AI while struggling to maintain visibility and control across increasingly complex environments.

The report found AI is now actively amplifying existing cybersecurity challenges across ANZ, including the speed and scale of attacks, adaptive malware, and exploitation of business AI environments.

At the same time, organisations are deploying agentic AI systems that operate autonomously across IT, cybersecurity, and business workflows — often with elevated privileges and broad access to enterprise systems.

That creates a new operational problem: organisations are no longer just managing human users. They are now managing fleets of machine identities, autonomous agents, and AI-driven workflows that move across hybrid and multi-cloud environments at machine speed.

The research suggests many organisations are not ready for that shift.

Only 36% of Australian organisations currently incorporate non-human identities into cyber resilience planning. Common challenges include integrating AI workflows into legacy identity systems, assigning appropriate privileges to AI agents, and monitoring agent activity across distributed environments.

There is also a broader trust issue emerging around AI operations.

Less than half of organisations surveyed said they were highly confident they could identify when AI systems had been compromised or had breached governance requirements.

As a result, explainability and transparency have become some of the most valued attributes in AI cybersecurity solutions, ahead of factors such as scalability and cost effectiveness.

This reflects a broader shift happening across enterprise technology.

For many organisations, the challenge is no longer whether AI can improve operations. That question has largely been answered. The issue now is whether businesses can operationalise AI safely, govern it consistently, and recover from failures quickly when systems inevitably go wrong.

The report argues this requires a move away from traditional recovery models toward what Commvault describes as “ResOps” — a resilience-first operational approach that integrates security, recovery, governance, and automation into everyday operations.

Under that model, recovery is no longer simply about restoring files after an incident. It becomes about restoring trusted operational states — including data, identities, AI systems, dependencies, and configurations — across highly interconnected environments.

That distinction matters more as AI becomes embedded deeper into enterprise decision-making.

Because once autonomous systems are making decisions across infrastructure, operations, and customer environments, resilience is no longer just an IT issue.

It becomes a business continuity issue.

And increasingly, a trust issue too.