As enterprises continue to accelerate AI adoption, many overlook a critical question: how resilient are the data and systems on which the technology depends? The question carries significant weight. AI has quickly moved from pilot projects to powering global innovation, with 81% of UK CEOs citing AI investment as a top priority in 2026.
This puts many organizations in a potentially difficult position many have yet to establish the governance, security, and trust frameworks fundamental to ensuring that AI is both durable and defensible. According to Accenture, for example, 77% of organizations are missing essential data and AI security practices to protect critical models and pipelines, while 90% still lack the maturity to defend against AI-powered threats.
But why does this matter? On a fundamental level, AI is only as strong as the integrity of the data it runs on. Yet enterprise data is more distributed and growing faster than ever before. A single poisoned dataset, an undetected anomaly, a corrupted identity, or a myriad of other potential vulnerabilities can cascade through AI systems, casting doubt on reasoning and outputs. With AI, there is also much more data to be protected, and given that most models are born in the cloud, they are prone to greater levels of complexity.
A major part of the challenge is that traditional security and IT recovery operations cannot meet these demands, having been designed for isolated incidents and linear recovery workflows, rather than for AI environments where data, models, and identities are tightly coupled, and failures can propagate at machine speed across systems.
At the same time, the rise of agentic AI introduces and enables much greater operational autonomy, with non-human identities able to interact continuously with enterprise systems. This further increases complexity, particularly as data volumes grow and dependencies between systems become more tightly coupled.
The result is a widening gap between the speed at which AI-driven environments evolve and the effectiveness with which traditional security and recovery models can respond.
The ResOps approach
To address these important challenges, resilience operations (ResOps) has emerged as an operating model that transforms resilience from a passive backup function into an active and continuous discipline. Rather than treating security, identity, and recovery as separate activities, it unites them into a single operational framework that operates in real time across AI environments.
Fundamentally, it operates as a continuous loop built around four key actions: Discover, Secure, Detect, and Recover.
Firstly, Discover focuses on establishing visibility across enterprise data, including where it resides, how it is used, and which identities interact with it. Secure builds on that understanding by applying appropriate controls to protect access and reduce risk exposure. Detect enables organizations to identify anomalies and potential threats in near real time, ensuring that compromised or untrusted data is not propagated further. Finally, Recover completes the loop by restoring clean, trusted data and systems in a controlled, automated manner.
Collectively, this creates a continuously validated and trusted data foundation, ensuring that resilience is maintained as an active operational capability rather than a reactive response to failure.
But what does this actually look like in practice? Consider a scenario in which an organization runs AI-driven decision-making systems that rely on continuously updated enterprise data. An anomaly is detected in a dataset feeding a critical AI model, triggered by unusual access patterns associated with a non-human identity. In a traditional setup, this might create a security alert, which is then handled in isolation while downstream systems continue operating on potentially compromised data.
In the ResOps model, detection does not exist in isolation. The anomaly is immediately correlated with identity activity and data lineage, allowing teams to understand not just that something has changed, but which data was affected and which AI workloads depend on it.
Rather than treating recovery as a last resort, automated recovery workflows are triggered as part of the same process. Clean, trusted data is identified and restored from known-good points, while compromised data is isolated. At the same time, the affected AI pipelines are paused or rerouted to prevent contaminated outputs from propagating further into the business.
In these situations, organizations can shift the focus of resilience to meet the specific needs of AI workloads and processes. As the technology continues to develop, we are certain to see systems more heavily targeted by threat actors, along with the inevitable technology bugs and failures that always accompany such rapid innovation. Given that effective resilience depends heavily on good forward planning, organizations that focus on ResOps now will be well placed to cope with the increasing complexity and operational risk introduced by AI at enterprise scale.
The author
Mark Molyneux is Field CTO for North Europe at Commvault






