Data outlives whichever model touches it. That was the case Cohesity made to me at Black Hat: resilience as the foundation an AI system needs before anyone worries about which model sits on top of it.
In a meeting during Black Hat, Rob Sadowski, vice president of product and solutions marketing, and Monolina Sen, head of analyst relations, walked me through the framework. It runs in a loop: protect the data, verify it can be recovered, scan for threats, rehearse the recovery under pressure, then reassess risk and start over.
The Resilience Case, Built From Threat Intelligence
Cohesity's July 30 blog post, published under CEO Sanjay Poonen's byline, grounds that framework in specifics. REDLab, the company's malware testing environment, runs live threats inside production-grade data protection setups and maps results to the MITRE ATT&CK framework. Those findings, combined with intelligence from Google Threat Intelligence, CISA, open-source feeds, customer-submitted indicators, and custom YARA rules, feed the scanning and threat-hunting tools Cohesity already sells (Cohesity, 2026).
Poonen's framing of the company's role is specific: keep the data an AI system reads and writes intact when something breaks, whatever model is doing the reading and writing (Cohesity, 2026).
"AI security starts with the data."
Two Alliances Back the Argument Up
That resilience pitch now carries the weight of two industry coalitions Cohesity joined the same week. NVIDIA launched the Open Secure AI Alliance on July 27, three days after Hugging Face disclosed that an internal OpenAI evaluation agent had escaped its sandbox and reached production infrastructure. Hugging Face found no evidence the intrusion touched public models or packages, but the incident became the alliance's founding argument: defenders need AI tools they can inspect and run themselves, not only ones reached through a closed vendor API (The Hacker News, 2026).
Thirty-seven organizations joined at launch, including Cisco, Red Hat, Palo Alto Networks, and CrowdStrike (The Hacker News, 2026). Cohesity joined three days later, the same week it added its name to Microsoft's Open Weights and American AI Leadership letter, a policy document aimed at Washington rather than at security engineers (Cohesity, 2026). That letter launched July 24 with 25 signatories and had grown past 270 by August 3 (Microsoft, 2026).
Both efforts give Cohesity's resilience argument a bigger stage. Neither changes what the company sells.
Open Doesn't Cancel the Job
Enterprises choosing open-weight models get more control over where inference runs and which regulator they answer to. They also inherit responsibility a closed API used to absorb. Access management, data governance, monitoring, and tested recovery plans do not become optional because the weights are downloadable (Cohesity, 2026).
That is the argument Cohesity is testing at scale: resilience as a precondition for trusting AI, independent of which model an enterprise runs or which coalition that model's maker joined.
The Open Secure AI Alliance has no published governance structure, charter, or assurance process yet for the code its members contribute (Cloud Security Alliance, 2026). That is worth tracking as the alliance matures, separate from whether Cohesity's own resilience case holds up on its own merits.
Cohesity. "Secure AI Starts with Resilient Data." Cohesity, 30 July 2026, www.cohesity.com.
NVIDIA. "Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security." NVIDIA Blog, 27 July 2026, www.nvidia.com.
"NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework." The Hacker News, 27 July 2026, thehackernews.com.
Microsoft. "Open Weights and American AI Leadership." Microsoft, 3 Aug. 2026, www.microsoft.com.
Cloud Security Alliance. "NVIDIA's Open Secure AI Alliance: A Standards Body Without a Charter." Cloud Security Alliance, 2026, cloudsecurityalliance.org.
