Saturday, 25 Jul 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • White
  • ScienceAlert
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > An AI now judges every move Rubrik's agents make, its AI chief said at VB Transform 2026 — but no one's measured if the judge is right
Tech and Science

An AI now judges every move Rubrik's agents make, its AI chief said at VB Transform 2026 — but no one's measured if the judge is right

Last updated: July 25, 2026 12:35 am
Share
An AI now judges every move Rubrik's agents make, its AI chief said at VB Transform 2026 — but no one's measured if the judge is right
SHARE

Contents
Security approval, not cost, blocks AI ROIOne AI reading what the rulebook can’tThe lethal trifectaThe attacks no single turn reveals

During a CISO roundtable organized by Anthropic’s chief information security officer, Dev Rishi posed a straightforward question: had everyone documented their AI governance and security policies? All hands were raised—around 14 people, by his count. However, when he inquired about the enforcement of these policies, the response was different. “And everybody chuckled,” Rishi, the GM of AI at Rubrik, recounted at the VB Transform 2026 fireside chat in Menlo Park. “It was like the dirty secret in the room that everyone has these policies, but no way to actually make them real.”

“Our founder and CTO has actually been really pushing to enable our agents in YOLO mode,” Rishi shared with the audience. This statement comes from a publicly traded data security firm that backs up what he described as the most important data in the world.

YOLO mode removes the permission prompt from agent workflows, allowing the agent to act independently. In Rubrik’s approach, a second AI evaluates every action in real time against policy, replacing the need for human approval. Rubrik is testing this experiment internally first. Rishi sees autonomy as a settled capability but an open judgment question. “If you ask the agent to act autonomously, it will,” he explained. “It’s a question that you have internally. Should it?”

Rubrik came to this question through experience. When Claude Code and Cowork pilots were launched, every command had to run in ask mode, making the employee issuing it liable. Developer feedback filled a single Slack thread with 120 messages.

“The developers basically are pushing back, and they’re like, this is like the iTunes service agreement. I’m just hitting check, check, check, check, check, check, check,” Rishi said. “There’s no way that I can actually read through this. And it becomes security theater.” Approximately 80% of respondents are in the same situation, Rishi said, referencing Rubrik Zero Labs research that found monitoring and approving agent actions takes more time than agents save. The State of the Agent, the April report behind that figure, surveyed more than 1,600 IT and security leaders.

SAGE is why Rubrik believes in this approach. The Semantic AI Governance Engine, SAGE, is the arbitration layer within Rubrik Agent Cloud that monitors every agent action, interpreting the semantic intent behind it, and deciding whether the action aligns with policies written in natural language. “We took what people said was human in the loop, a good idea, and we replaced it with AI in the loop,” Rishi explained, describing this to security chiefs wary of non-deterministic systems.

See also  New Data Released from NASA’s Juno Mission, and New Satellites Launched for Internet and Trees

Security approval, not cost, blocks AI ROI

Rishi’s journey to Rubrik involved Predibase, the generative AI infrastructure startup he co-founded and led as CEO until Rubrik decided to acquire it in June 2025. Before that, he led ML product at Google on the team that evolved into Vertex AI, served as Kaggle’s first product manager during its growth from one million to ten million users, and earned bachelor’s and master’s degrees in computer science from Harvard.

In his first three and a half months at Rubrik, Rishi conducted 200 customer discussions with IT and security leaders from a customer base similar to the Global 2000, discussing open-ended questions about cost, latency, performance, and orchestration. “Pretty consistently, what I heard through all of those conversations was that all of those are pretty secondary,” he noted. “The main challenge is actually, how do I get this approved from a security and risk standpoint? I’m concerned about all the different things that could go wrong. Actually, I felt like that was one of the biggest things constraining ROI.”

VentureBeat Pulse research presented on the Transform stage earlier in the day corroborates the gap Rishi kept hearing about. Two-thirds of enterprises, 66%, already allow or are actively working toward production deployment with zero human review, yet only 5% fully trust the automated evaluations necessary to make that decision.

One AI reading what the rulebook can’t

Rubrik’s internal policies highlighted why written rules often fail in enforcement. One rule specifies that agents should adhere to Rubrik’s customer data use policy, which seems enforceable until someone tries to apply it. “Rubrik’s customer data use policy is like a three-page document of legal text,” Rishi said. “I have no idea how to write that in there as a rule.” When asked on stage how a team of AI infrastructure people tackled a problem belonging to security engineers, Rishi replied, “with a lot of naivety and innocence, honestly.” His team believed models adept at understanding language could oversee other models, and SAGE became the solution.

The argument for having a model act as a judge centers on precision. A rule like “agents should not be able to edit revenue fields in Salesforce” fails with conventional tools because Salesforce doesn’t specify which fields qualify as revenue, Rishi explained. As a result, administrators resort to manually approving every Salesforce action. SAGE interprets intent instead and acts as a judge, providing organizational context that can distinguish a benign lookup from a prohibited edit.

Keeping the judge small ensures economic viability. SAGE operates on a small language model that Rishi said functions at a cost and latency significantly lower than a frontier LLM. “If I told you, don’t worry, you’re gonna be secure and governed, but I’m gonna double your cost and latency, you would tell me to get out of the room,” Rishi pointed out.

See also  Who will judge the chief judge who says courts are too tough on crime?

When Rishi questioned the audience about concerns over token consumption during the past year, half the hands were raised. “And I guess the other half is probably just too lazy to raise their hand,” he added.

SAGE is a collection of judges based on parameter-efficient fine-tuning that Rubrik employs to address task-specific variants of a base model with shared organizational context. One judge monitors tool-use hallucinations while another prevents PII from being exposed, each functioning as an enforceable policy. Security and GRC teams have begun incorporating financial rules into this same layer, including a policy prohibiting AI spending on personal projects.

The lethal trifecta

Asked about the attacks that concern him most, Rishi pointed to the lethal trifecta, a term coined by security researcher Simon Willison in June 2025 for an agent holding private data while ingesting unvetted content, with a channel to transmit findings externally. The risk, according to Rishi, arises when individually legitimate permissions combine. An agent with Salesforce access and email access under an employee’s credentials hasn’t done anything wrong yet, with yet being the operative word. “A very simple example is that an agent can start pulling data from Salesforce and then decide to accidentally leak and exfiltrate that out via an email,” he explained. A financial services company he met earlier that day illustrated this point, telling Rishi that none of the individual permissions are problematic on their own, and the agent requires each of them to function. “It should have permission to each of those systems, but it’s the combination that ends up becoming really destructive,” Rishi said.

Traditional identity and access management didn’t account for this combination because it relied on the judgment of the credential holder, Rishi argued, which agents lack. “I can tell you the number of times Claude Code has tried to leak some of our sensitive source code to a public GitHub repository is incredibly high,” he said. Completely restricting agents from public resources would undermine their purpose, shifting the issue back to evaluating intent within context rather than revoking access.

A separate VentureBeat June Pulse survey of 107 qualified enterprise respondents maps the impact of this exact pattern. On the Transform stage that morning, VentureBeat research reported that 69% of companies use credential sharing within their agent fleet. Companies with any shared credentials experienced security incidents or near-misses at a 63.5% rate (47 of 74), compared to 40.9% (9 of 22) where each agent has its own scoped identity.

See also  Bryan Kohberger Defense Theory On Who The 'Real' Killers Are Shot Down By Judge

The attacks no single turn reveals

Rubrik Agent Cloud became generally available in February, though not all features Rishi described are included yet. Backtesting is just being introduced. This feature replays an organization’s historical agent actions and tool calls against a new policy, showing where the policy would have intervened and where actions would have gone unnoticed, with real-time policy edits. Rishi described this archive as one of the most valuable data resources an enterprise possesses.

Real-time detection and blocking serve as the starting point rather than the complete solution. Some attacks don’t trigger a single-action rule. “No individual turn of the conversation was problematic, but if you took the session as a full trace, that ended up being problematic,” Rishi observed. Agent Cloud conducts batch analysis across entire session traces hourly or daily, surfacing what Rubrik calls insights—the issues no single guardrail identified. The same Zero Labs report found that 88% of respondents lack the ability to reverse agent actions without disrupting systems, a recovery gap at the core of Rubrik’s original business.

A skeptical CISO might raise the question left unanswered at the fireside. SAGE is a non-deterministic model overseeing other non-deterministic models, and Rishi provided no false positive or false negative rate for the judge itself. The architecture’s closest answer is auditability, as backtesting and batch insights leave a human-reviewable trail of every call SAGE made and anything it missed. For now, “who watches the watcher” is a trail of receipts rather than a benchmark. Until such a benchmark exists, AI in the loop remains an operational gamble rather than a quantified control.

Three questions arise from the session for security teams. How many of the guardrails currently in use depend on human approval, and what happens to that workload as the number of agents increases? Does the stack enforce semantic intent, or is it limited to allow and deny lists? Can the team backtest agent behavior against a new policy and unwind a multi-turn session without disrupting systems?

Rishi’s timing aligns with market trends. In the same VentureBeat research, 82% of enterprises still rely on their primary AI provider’s built-in guardrails and cloud controls as their main agent security layer, and 59% plan to adopt, add, or replace agent security tools within the next 12 months. Only 12% are considering an agent-identity product, even though credential sharing remains prevalent. Every CISO at that Anthropic roundtable possessed a policy document but lacked an enforcement mechanism, and Rubrik developed a product to fill this gap. YOLO mode is the gamble that an AI supervising other AIs can finally enforce policies effectively.

TAGGED:agentschiefJudgeJudgesMeasuredMoveone039sRubrik039stransform
Share This Article
Twitter Email Copy Link Print
Previous Article FDA advisory panel rejects compounding of one peptide, backs another FDA advisory panel rejects compounding of one peptide, backs another
Next Article 7 Stylish Celebrity Looks to Recreate This Week 7 Stylish Celebrity Looks to Recreate This Week

Popular Posts

How Trump Could Weaken the Affordable Care Act

President-elect Donald Trump’s return to the White House has rekindled the debate over the Affordable…

November 24, 2024

Tottenham vs. Qarabag FK odds, picks, how to watch, stream, time: Sept. 26, 2024 UEFA Europa League prediction

Tottenham Hotspur is gearing up to face Qarabag FK in a highly anticipated UEFA Europa…

September 26, 2024

Quadria Capital closes Fund III fundraising round to advance healthcare at $1.07bn

Quadria Capital, a Singapore-based private equity company, has successfully closed its Fund III fundraising round,…

May 27, 2025

Reading Hits Differently to Listening For Your Brain, Science Says : ScienceAlert

Why Reading Still Matters: A Neuroscientific Perspective Let's embark on a thought experiment: Imagine the…

August 1, 2025

Landry wants to be kingmaker in Louisiana. He’s annoying other Republicans.

Louisiana Governor Jeff Landry is striving to become a significant political influencer by supporting Rep.…

May 14, 2026

You Might Also Like

A Common Gym Supplement May Give Cancer-Fighting Cells an Energy Boost : ScienceAlert
Tech and Science

A Common Gym Supplement May Give Cancer-Fighting Cells an Energy Boost : ScienceAlert

July 24, 2026
Don’t Trust Those Oppo Find W Rumours – Tech Advisor
Tech and Science

Don’t Trust Those Oppo Find W Rumours – Tech Advisor

July 24, 2026
Fungus-made fashion—researchers turn living organisms into textiles
Tech and Science

Fungus-made fashion—researchers turn living organisms into textiles

July 24, 2026
On Facebook, Cook County judge says ‘F@ck ICE’ and calls Trump a ‘modern day Hitler’
Crime

On Facebook, Cook County judge says ‘F@ck ICE’ and calls Trump a ‘modern day Hitler’

July 24, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?