Home Business News World AI Week: As AI adoption grows, recovery must keep pace

World AI Week: As AI adoption grows, recovery must keep pace

9

Words by Johnny Karam, Managing Director and Vice President, International Emerging Markets at Cohesity

“This World AI Week, UAE organisations should ask what agentic AI can access and change and what happens when it acts unexpectedly. Adoption is outpacing AI safety, and every connection to production data expands the attack surface. The UAE Cybersecurity Council warned that AI-enabled threats are becoming harder to identify and trace.

“Cohesity’s 2026 Global Cyber Resilience Report found 73% of UAE organisations experienced a material cyberattack in the past 12 months, up from 59% in 2025. Yet 63% lack a complete inventory of their AI agents, 53% are not well prepared to contain and recover from unintended agent actions, and 91% say recovery plans need moderate or significant change for AI-accelerated attacks.

“Agents with access to sensitive data are privileged identities and should follow Zero Trust principles: limit access and keep actions traceable. Yet governance cannot undo a harmful action, and even an authorised agent can make the wrong change. That is why AI safety, which reduces harm, must be matched by enterprise resilience, which prepares the business to recover. No organisation can strike that balance alone. 

“Best practice is being shaped through collaboration between AI developers, security providers and governments, including initiatives such as Anthropic’s Project Glasswing and OpenAI’s Daybreak, which Cohesity is part of. These conversations also need to happen locally, so UAE organisations can help shape the standards they will be expected to meet.

“A practical starting point is to define a minimum viable company: the essential services, data, people and suppliers needed during disruption. After an incident, identify what the agent touched, restore clean data, configurations and credentials, and bring dependent applications back in a tested sequence.

“Defensive AI can help contain activity at machine speed, while people retain authority over significant decisions. Recovery must work when other controls fail. For UAE organisations, AI readiness can be tested with one question: after an agent acts unexpectedly, what must be restored first to keep critical services running?”