SECURITY
SECURITY
SECURITY
As AI agents move from experimental chatbots into production systems, enterprises must rethink agent governance as autonomous actors gain access to sensitive data, tools and business processes that traditional identity and security controls were never designed to handle.
Enterprise cyber resilience company Rubrik Inc., which this week unveiled Rubrik Agent Identity to govern agent access one tool call at a time, argues that agents demand an entirely new control layer. Unlike a service account or a person, an agent pairs a non-deterministic model with federated identity — and that combination breaks conventional assumptions about how software should be secured, according to Dev Rishi (pictured), general manager of AI at Rubrik.
“If you or I were accessing Salesforce [or] accessing email, we have some judgment on how we would use that, that the models don’t,” Rishi said. “So I feel like you need a new class of guardrails that are a lot more intelligent and semantically aware to be able to actually secure and govern what agents are doing.”
Rishi spoke with theCUBE’s Krista Case at Black Hat USA, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how enterprises can deploy autonomous actors with visibility, control and recovery. (* Disclosure below.)
Traditional identity stacks fall short because agents inherit legitimate permissions but lack the judgment to use them wisely, Rishi noted. An agent can pull data from Salesforce, then paste sensitive fields into an outbound email — each action authorized, the combination toxic. To avoid flooding humans with endless approvals, Rubrik built SAGE, a small language model trained to act as a cybersecurity professional that vets actions at machine speed.
“The entire [business] case on agents is that they’re doing 10 times as much work as a human in the same amount of time,” Rishi said. “If I’m sitting there and I’m hitting approve, approve, approve, we feel like it’s more security theater than anything else.”
Observability is the foundation of AI agent governance, but raw telemetry at scale creates its own challenge, Rishi noted. Rubrik’s internal deployment emits trillions of tokens, so raw telemetry needs an intelligence layer to surface risk and runaway spend. In one case, the company found that a small fraction of activity drove a disproportionate share of cost.
“One percent of sessions were driving 40% of the cost, and there was a lot more that we could drive once we had the observability in place,” he said.
Stay tuned for the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Black Hat USA.
(* Disclosure: Rubrik sponsored this segment of theCUBE. Neither Rubrik nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.