At the IT Press Tour, CEO Sanjay Poonen explained why Cohesity gave frontier AI models access to its own code, how it plans to protect AI agents, and why it treats a breach as a given.
Cohesity wants to be the last line of defense when everything else fails. At the IT Press Tour in Silicon Valley, CEO Sanjay Poonen outlined how the data security vendor uses unrestricted frontier AI models to harden its own software, and why recovery, not prevention alone, will decide how companies fare against increasingly automated attacks.
Poonen positions Cohesity as a cross between security vendors such as CrowdStrike and Palo Alto Networks and data platforms such as Databricks and Snowflake. According to the CEO, the company protects around 200 exabytes of data for roughly 12,000 customers, mostly Global 2000 enterprises in banking, the public sector, healthcare, telecommunications and technology. His argument: once attackers have passed physical, network, endpoint and application security, data is all that is left. Companies should therefore assume a breach and rehearse recovery, much as Californians rehearse for earthquakes.
The most notable part of the session concerned Anthropic’s Project Glasswing. Poonen said Cohesity, pushed by its own management and by customers in government and banking, became the first company in its segment to gain access to the restricted Mythos model. Cohesity let the model search its source code for vulnerabilities, while a few customers ran it against the compiled binaries. Like a second medical opinion, the exercise was repeated with OpenAI’s and Google’s cyber models, and open-weights models are being evaluated with investor Nvidia. Poonen’s initial finding is that Mythos outperforms OpenAI’s GPT-5.6 Cyber, though he stressed that the race remains open. Products built on these models are due in the coming weeks and months; he gave no details.
The second focus is AI agents. Poonen compares an agent to a Mini Cooper: small, but it needs brakes. Cohesity now backs up the components of agents, including prompts, vector databases, memory and MCP connections, and has launched protection for agents on Amazon Bedrock. According to Poonen, a customer survey ranked agent resilience first among the areas the company is investing in. A Cohesity product executive added that agent state can be saved roughly every five minutes. In one example, an email-triage agent was manipulated by hidden text and began forwarding messages to a third party; restoring its memory would reverse the damage. Discovery remains a hurdle, since there are about 25 agent platforms to connect to.
The same executive described a model of three components: flexible but unpredictable agents, deterministic systems such as backups, and humans who bear responsibility. In a demo, Claude, connected to Cohesity’s MCP server, found a missing air-gapped copy and proposed a fix, which took effect only after human approval. Questions about privacy were answered candidly: prompts go to Anthropic’s cloud, and customers cannot yet verify that they are not used for training. “It’s a trust,” the executive said. Some customers therefore prefer isolated open-weights models, and Cohesity points to on-premises deployments on Nvidia hardware in the Netherlands.
Recovery is also where Cohesity sees its place in the security stack. Poonen referred to the NIST framework: vendors such as CrowdStrike and Palo Alto Networks work on the detect-and-prevent side, while Cohesity concentrates on recovery. Its answer to disconnected storage is a third backup copy in an isolated cyber vault, marketed as Fort Knox, which stays offline while the first two copies remain inside the network. Poonen noted that even governments and armed forces cannot operate fully cut off from the internet. He also commented on calls to slow AI development: halting innovation, in his view, is no option; companies should keep their foot on the accelerator but install seat belts and airbags.
Identity is another open question. Today, agents largely inherit the access rights of the user who starts them. The product executive expects each agent to receive its own, narrower identity in future. Some large customers already prohibit agents from performing privileged operations, such as deleting backups, and reserve them for separate human administrator accounts.
On the business side, Cohesity now ships on-premises releases four times a year, with security and AI updates every two weeks. Product quality, Poonen said, comes before schedule, and schedule before features. The company also names managed service providers, sovereign deployments and alternatives to VMware as priorities this year. Poonen described the company as profitable and growing and expects to reach two billion dollars in annual recurring revenue soon. An IPO remains a possibility, he said, without naming a timeframe. He also made clear that AI will reshape staffing: when employees leave, the company weighs replacing them with people or with tokens.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de