Recruiting a New Army of Agents
- By Lachlan Colquhoun
- March 02, 2026

While the human population is plateauing and forecast to decline later this century, one population set to increase exponentially is that of AI agents.
A recent report from Databricks, based on data gathered from more than 20,000 global organisations, found that the use of multi-agent systems soared by 327% over only four months in 2025, as organizations moved from single chatbots to multi-agent systems built on domain intelligence and capable of acting across business workflows.
In dollar terms, BCC Research estimates that the market for AI agents is set to grow from US$8 billion in 2025 to USD48.3 billion by the end of 2030, a compound annual growth rate of 43.4%.
Black hoodies are so 2024
One thing that is certain is that, alongside the increasing use of AI agents in legitimate businesses for routine operations, there will be an explosion in their use for more nefarious purposes.
The cyberworld will be populated not just by hackers in black hoodies stooped over computer screens, but also by a whole army of AI agents tasked with penetrating the networks and operations of identified targets. Non-human identities are creating new threat vectors and continually multiplying.
“We can assume that the number of attacks will continue to go up and the number of agents and non-human entities will continue to grow,” says Pranay Ahlawat, the chief technology and AI officer at cybersecurity vendor Commvault.
“The bad guys are actually moving faster than the good guys, and the challenge is that the innovation cycles are shrinking, and for anything you do, the chances are it will be discovered by agents almost instantaneously, and they will make highly sophisticated and engineered attacks… That’s the world we live in, and you might decide not to use AI agents internal to your organisation, but the reality is that cyber risk is increasing all the time.”
Ghost in the machine vs. ghost in the machine
Ahlawat talks about “agentic resilience” as key to the organization's response to threats. This involves using AI agents within the security posture and automating their operations under strictly defined governance to respond to threats and incursions they detect.
Most organizations deploy their data in hybrid configurations across more than one cloud, so these agents need to operate on-premises, within cloud-native hyperscalers, and within SaaS operations to make cyber resilience a unified effort that sits best on one platform.
“The user is the one who gets to decide if they want the agent to be automated and to take action.” – Pranay Ahlawat, the chief technology and AI officer at cybersecurity vendor Commvault
“If you are serious about having a strong cyber resilience posture in an AI, cloud-first world, you have to think about these capabilities together, and they have to play off each other,” said Ahlawat.
“You need a platform that doesn’t just bring you back from a cyber incident but can actually be automated and take action and bring it all together end-to-end in terms of data security, access governance, identity, and auditing.”
Keeping a leash on the digital guard dog
AI agents are there to identify threats and incidents, detect anomalies and automate recovery and remediation.
“A typical organization might have thousands of VMs and multiple databases,” said Ahlawat.
“That is a big challenge to back up a cloud VM. Do you take a snapshot every hour? Do you do a full back air gap?
“A lot of these are decisions that humans have had to make, but with agentic, we can automate all that so that it is at the front end of the funnel,” he continued.
Commvault has rolled out its Arlie, AI powered assistant integrated into its cloud platform, which acts as a “co-pilot” for administrators.
With appropriate governance in place, Arlie can also act automatically, enabling an instantaneous response to incidents. But it is the human who originally gives the agent their job description, and sets the limit of what they can do and how they behave.
“The user is the one who gets to decide if they want the agent to be automated and to take action,” said Ahlawat.
“There are some actions that are safe and some that are unsafe, and if there is an unsafe action, you need to have that human loop to approve or disapprove of what an agent can do.”
“So you need to constrain and bind the agent in well-designed workflows, and also have full observability with audit logs so you can see everything that is happening in the system,” he added.
Don't just pray and spray
Ultimately, Ahlawat’s advice to clients is always to invest in foundational technology and governance, because these agents — like soldiers on a battlefield — need to operate within a strategic framework that includes other technologies and supporting policy.
“I think the big mistake customers make is to pray and let a thousand flowers bloom with AI, and that is an approach which hasn’t worked,” he said.
“If you look at companies that have made a serious impact, they have this cyber resilience, and that comes from having data strategies, observability and governance.”
“But the world of agents is upon us, and it’s clear that inaction is not the answer,” he added.
Image credit: iStockphoto/nespix
Lachlan Colquhoun
Lachlan Colquhoun is the Australia and New Zealand correspondent for CDOTrends and the NextGenConnectivity editor. He remains fascinated with how businesses reinvent themselves through digital technology to solve existing issues and change their business models.