In short
AI “agents” (models with tool/API access) create new security risk because data can move between agents and outside human visibility. Rubrik’s Predibase acquisition powers Rubrik Agent Cloud to inventory, monitor, govern, and “rewind” destructive agent actions across local, cloud, and custom-built agent environments.
Guest backgrounds
Devvret Rishi, deaf co-founder/CEO of Predibase (acquired by Rubrik in summer prior to episode). Previously at Google (5 years) working on early agent-like assistant work and cloud AI platform foundations; earlier masters in computer science/stats focused on privacy-preserving resilient ML.
Key claims
ROI is slowed by lack of risk frameworks for agent runtime behavior; orchestration alone misses policy context. Agents are “promiscuous,” and one wrong fast action can cause major damage.
Notable examples
agents opening drive.google.com to upload despite disabled connector; agents deleting production databases; AWS reported 4 Sev1 outages in ~90 days after recording agents; Meta incident involving inbox access/deletion; Rubrik caught public GitHub gist sharing via Cloud Code governance. Product: dashboard inventory; SAGE (Symantec AI Governance Engine) uses fine-tuned small language models to enforce natural-language policies; rewind via Rubrik backups/snapshots.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOUnderstanding AI Agents
0:00 to 0:34
Learn about the concept of AI agents and their potential risks within organizations.
“We define agents as just really like models with access.”
Devvret Rishi's Journey
0:45 to 2:36
Discover Devvret's experience, from co-founding Predabase to joining Rubrik.
“Tell us a little of your background so far as it's relevant, particularly education and what you were doing before Rubrik.”
Rubrik's Core Offerings
2:36 to 3:54
Explore Rubrik's focus on data and cyber resilience along with its evolution.
“The AI tools and models are actually getting quite good very quickly as well.”
The Impact of AI on Security
3:54 to 4:50
Examine how AI and agents represent new threat vectors for businesses.
“But increasingly over time, that became more geared towards ransomware attacks and cyber.”
Introduction to Rubrik Agent Cloud
4:50 to 6:35
Learn about the Rubrik Agent Cloud and its role in managing AI agents.
“We define agents as just really like models with access.”
Agent Control and Visibility
6:35 to 8:25
Understand the importance of agent visibility and control in organizational security.
“who had built these frameworks at Uber to make it easier to be able to use machine learning and internally and build these applications.”
Challenges and Risks of AI Agents
8:25 to 10:30
Discuss the risks associated with AI agents and real-world incidents.
“There are these agentic build platforms where you can build and deploy agents.”
Real Threats from Agentic Systems
10:30 to 14:00
Devvret shares alarming examples of rogue agents and their consequences.
“any of the things that those agents are doing.”
Agent Autonomy and Scary Outcomes
14:00 to 14:24
Learn about the potential dangers of AI agents autonomously accessing systems.
“I had an example where I was asking the agent to create a document.”
Real-World Examples of Security Incidents
14:24 to 15:18
Explore real incidents where AI agents caused serious issues for organizations.
“Did anything bad happen in that instance?”
Show all 26 chapters
Monitoring AI Agent Actions
15:18 to 16:32
Understand the importance of monitoring AI agent actions to prevent disasters.
“Like this company has processes, but these agents are going through them very quickly.”
Deploying Rubrik Agent Cloud Solutions
16:32 to 18:58
Discover how to deploy Rubrik Agent Cloud and its integration capabilities.
“Unless you have that, it's sort of like, you know, deploy it and maybe have some grit teeth and hope nothing goes wrong.”
SAGE: AI Governance Engine
18:58 to 23:08
Learn how the SAGE system governs AI actions to ensure compliance.
“and really can hook into the three different kind of surface areas where we see agents get built and deployed.”
Rewinding Destructive Actions
23:08 to 24:29
Understand how to rewind actions taken by AI agents using Rubrik's backup.
“You guys had an ad with Ludacris playing rewind or wind it back.”
AI in Enterprise vs. Individual Use
24:29 to 26:50
Explore the differences between enterprise and individual use of AI agents.
“Do you offer a consumer subscription or something that's geared more toward an individual user or small company?”
The Future of Agent Communications
26:50 to 28:00
Discuss the future of agent-to-agent communication and its implications.
“I mean, beyond agents having access to tools and to databases, agents are talking to each other, And as that fabric expands, you know, humans aren't going to know what's happening between the agents in that layer.”
Understanding Agent Interaction Security
28:00 to 30:10
Learn how to secure interactions between AI agents to prevent data leaks.
“Iosha is getting maybe a first-line support, and then you have your next step of an agent that's looking to be able to do a resolution or investigation.”
Stakeholders in AI Security
30:10 to 32:08
Discover the key stakeholders involved in AI security and governance.
“Yeah, but oftentimes misses the context on what, like at an organizational level, should be happening from like a policy standpoint.”
Competitive Landscape for AI Security
32:08 to 34:13
Explore the competition and positioning of Rubrik in the AI security space.
“I imagine that this is all going to converge into one thing.”
Targeting the Global 2000 Enterprises
34:13 to 36:17
Understand the market focus of Rubrik on Global 2000 enterprises and the challenges they face with AI adoption.
“And so I think one of the unique differentiations that combination has actually brought in is a lot of security companies, I think, approach the challenge here in a conventional security way.”
Current Challenges in AI Adoption
36:17 to 38:27
Identify the barriers and pressures organizations face in adopting AI workflows.
“as like the global 2000 enterprise, like a large country.”
Future of Rubrik Agent Cloud
38:27 to 40:48
Learn about the future developments and strategic goals for Rubrik Agent Cloud.
“around like AI risk and not even myself.”
Evolving Perception of AI Agents
40:48 to 42:00
Explore changing attitudes toward adopting AI agents in enterprises for better ROI.
“I mean, when you go out and talk to companies, are you kind of an agent evangelist saying, look, you're afraid of deploying agents in your enterprise because of the risk and security concerns?”
Understanding the Demand for Secure AI Agents
42:00 to 43:32
Learn about the market's interest in securing AI agents and the approach to addressing their needs.
“Or are enterprises that either have a pilot or are integrating an agentic system into their enterprise realize, hey, we need a security solution.”
Exploring Rubrik's Agent Cloud Functionality
43:32 to 46:30
Discover how Rubrik's Agent Cloud operates, including its setup and security features.
“data and identity context is important that you need to be able to do this at runtime protection.”
Managing Risks in AI Transformation
46:30 to 47:32
Understand the key challenges in securely managing AI agents and the potential for ROI improvement.
“So Rubrik Agent Cloud itself is an agentic system, is that right?”
Transcript
Automatic transcript. May contain errors.0:00We define agents as just really like models with access. So like access to tools or APIs that can start to do work inside an organization. Once these become agents unseen and visible to the humans talking to each other, transferring data to each other, you're really vulnerable because you don't know where the data is going beyond agents having access to tools and to databases. Agents are talking to each other. Where do you see this agent economy going? Yeah, there's a question about like, will AI agents and AI cause job displacement? AI may not, but someone who knows AI. We're going to talk about Rubrik.
0:39We're going to talk about Rubrik Agent Cloud. Can you start by introducing yourself to listeners? Tell us a little of your background so far as it's relevant, particularly education and what you were doing before Rubrik. rubric. Yeah, I can start at the beginning, maybe. And I'll say that I'm deaf. So I was one of the co-founders and CEO for Predibase, which was a generative AI infrastructure company. We started right before the beginning of the Gen AI wave in 2021. And really, we're helping organizations build and then deploy the precursor to large language models, which were really pre-trained deep learning models.
1:22It came out of our experience at Uber and Google, which is where my co-founders worked. Prior to starting the company, I was at Google for about five years. Before that, I was always in the AI space doing my masters and others in core computer science and stats. So that's really my background. My company was acquired by Rubrik last summer. We actually joined forces with our core machine learning and LLM infrastructure platform. So we were the model backbone that drove deployments of AI in Fortune 500 organizations, faster tech forward moving companies as well. So we really had a really broad gamut.
2:00And when we joined forces with Rubrik, the core idea was we wanted to take the platform we had built and mix in what Rubrik did really well. Rubrik is a data and cyber resilience company. It started off its core offerings around making sure that businesses were resilient to downtown data, layered on security offerings for cyber. And with the acquisition of my company, Predabase, we're building kind of a combination of like our AI platform plus data and identity security into a net new offering we call the Rubric Agent Cloud. The core goal and the observation that we had is that AI is coming very quickly.
2:36The AI tools and models are actually getting quite good very quickly as well. And so people are starting to adopt these tools en masse. But the thing that's actually slowing down their ability to deliver ROI is that I think that there isn't a great framework to manage the risk of what these agents can do inside of an organization. So that's the challenge we set out to solve with the Rubrik Agent Cloud. Before, cyber resilience and that sort of thing, Rubrik was focused on what? On making sure that all the ports to the data were closed and all the various things that people screw up that leaks data.
3:16I can tell you a little bit about the early days of both Predabase and Rubrik. I mean, a rubric I know from being here, but I think rubric really started its early days with a mentality of assumed breach, which was to say that there was lots of solutions that were trying to say, well, let's make sure that the, you know, door is locked. But the real thing you needed to be able to do is make sure that as a tax actually happens for the ones that would get through the defenses and were successful, did you have a way to be resilient towards your business? It used to be the case that most of the things that drove business downtime were like natural disaster, fire, flood.
3:53These were the things that you kind of conventionally bought that insurance policy for. But increasingly over time, that became more geared towards ransomware attacks and cyber. So security became really the primary threat vector that acquired business resilience. So Rubrik really thought about regardless of the types of instances in which your business might be put at risk, whether that's something like the natural disaster of old or the cyber attack of new, like how do we provide a way that your business can basically be resilient or bounce back regardless from both of those situations? That was really its core genesis.
4:25And then it started adding more capabilities around prevention and detection over time. So you got kind of a layered approach towards the defense. You knew that things could only get so bad if anything did come through, but it started to layer on based on the data understanding, the identity understanding it had. Yeah. Mom, I think Rubrik recognized that the next threat vector, if you thought about like natural disaster, fire, flood, and then cyber attacks, we think that the next threat vector is going to come from AI and specifically agents that are deployed in an organization. We define agents as just really like models with access.
4:57So like access to tools or APIs that can start to do work inside of an organization. And that's why I think it motivated Rubrik to do the acquisition of Predabase, my company, because what we actually had really started off on is building the core infrastructure platform on which people were building models and starting to deploy agents as well. So we wanted to bring all of that in-house to be able to say, we've secured you in natural disaster, fire, flood, in cyber and security, and now also for the upcoming wave of agents. Well, your background, what were you doing at Google? Were you in a GenTech or security?
5:33Yeah, it's funny. So prior to Google, I was both doing my undergrad master's concurrently in computer science and stats, focused on resilient machine learning algorithms, specifically for privacy-preserving use cases. Then I went over to Google, and I worked on it across a number of different teams, including Google Research, where I was working on, if you remember, the early days of agents actually looked like the Google Assistant as well, which was like this embedded assistant and all these different devices, we were working on more deep learning focused use cases within the assistant. So that was my first exposure to agents more than a decade ago at this point.
6:10And then the second area that I worked was actually on Google Cloud's AI platform. So I remember we hadn't even named it Vertex AI when I was there, which is the name of it now. But we were really forming kind of the initial basis for the fact that more people were starting to do machine learning and AI workloads on the cloud. How do we build a platform that people could actually use across all that? So that's what I was working on until the end of 2020, the pandemic, when I met my co-founders, who had built these frameworks at Uber to make it easier to be able to use machine learning and internally and build these applications.
6:43These frameworks got popular, so they open sourced them. As things happen in the open source, they got popular externally. And so we all decided to team together and start a company around it, which was credit-based in early 2021. When you say Rubrik agentic cloud, why cloud? Is it a bunch of different components? Is it an ecosystem? Or are you literally saying it's in the cloud and we apply it to whatever system? The honest reason for why Rubrik agentic cloud is because Rubrik today, I think, before the agent cloud had one primary product, which is called the Rubrik security cloud. and the core intuition behind the rubric security cloud was as organizations were thinking both about their on-prem but also shift from on-prem to cloud migrations how do you secure that you know transformation that's happening in the organization uh and then when we rolled out like the agent cloud we realized like ai was a whole new system where your conventional security principles didn't really hold up and so we thought we needed a new approach we wanted to name it the the Rubric Agent Cloud is kind of a mirror towards the Rubric Security Cloud.
7:45And I think the core thing about the Rubric Agent Cloud is that it really speaks to the fact that agents exist everywhere in an ecosystem. And when I say everywhere, I mean they can exist on your laptop as something you're running. We think about instances like OpenClaw or Cloud Code and others. They can run it in a cloud environment that you manage. It can run in a number from different places. But what you want is a single kind of control plane across all of those that gives you the visibility and what are these agents doing and some level of control over those agents as well. And so that's what we think our agent cloud basically does, is it hooks into these different environments and allows you to be able to get that visibility and governance.
8:22I've spoken to a lot of agent orchestration companies that are building. There's the LLM Foundation. There are these agentic build platforms where you can build and deploy agents. there's, there are now companies that are building just the orchestration layer so that you can keep track of what these agents are doing. Are you guys orchestration or are you a layer above that? We're a layer above it. My point of view is that there's lots of good orchestration tools that exist out there. There's lots of good platforms to build agents today. You know, each of the hyperscalers has their own agent platforms, including orchestration.
9:03So Vertex AI has, their own agent ADK. You have Bedrock inside of AWS with AgentCore. You have a suite of tools inside of Azure. Salesforce has AgentForce. ServiceNow is an agent platform. Plenty of good ways now to be able to build agents. What we've noticed is actually hard is how do you place some level of controls around making sure that the agents, regardless of where they're built, actually have some level of consistent runtime guardrails on what they can and can't do. And this actually, I think, is a very tricky problem because agents look less like conventional software and inside of an IT organization, a little bit more like what you or I might be able to do.
9:42And so like my agent, as an example, which my agent, the one I use most heavily is just out of personal use, is like Cloud Code and Cloud Code Work. My agent has access to Salesforce and my agent has access to email because I use it to write emails and I use it to summarize opportunities in Salesforce. But what I don't want it to do is take something that's sensitive from Salesforce and put it out and send it out in an email autonomously, right? And so that's just one thing that happens with cloud code and co-work that I need to secure. But if you're using a different agent harness, if you're using OpenAI's codex, it'd be the same concern.
10:13And so my view is that there's lots of different good systems. They're building excellent ways to integrate into the different areas, good harnesses, good orchestration frameworks, ways to be able to run in the cloud, like Anthropical launched managed agents yesterday. But how do you have a consistent way to be able to monitor, observe, and actually run time guardrail? any of the things that those agents are doing. That's where we come in. So if you think about the core layer, it's like your models and your MCP tools or your other API tools. The layer above is going to be your agent platform builders plus orchestrators.
10:43And then what we think about is having the security umbrella across this with the agent cloud. Does that apply if an enterprise is using a combination of agent builders, a combination of orchestration? Can you apply this across? That's one of the settings where I think it's the most compelling. And frankly, I think that this would be true for most enterprises, sort of similar to how you saw in the cloud era, like you had organizations adopting multi-cloud. I think you're seeing even more of that in the AI era because these things are coming out so quickly. I think where Rubrik Agent Cloud actually really shines is you have multiple different agent platforms that you're using.
11:20At Rubrik, we ourselves have multiple different agent platforms. We, in fact, have a couple different coding agents that we have, including Cloud Code. but we also build agents on top of Vertex AI. We have agents that are built and also other third-party tools that I'm not even mentioning. And so the question is, how do you secure across all of this? This is where I think our agent cloud provides a tremendous amount of value, really at day zero, because oftentimes what people want to know, even at the beginning, is what are the agents that are even deployed in all these different ecosystems? So we can plug in, provide the automatically discovered and scanned inventory, and then allow you to start to get the system of control across all of this.
11:55Yeah. One thing I've wondered about, you know, there's a lot of talk about the security risks of agentic systems and something like Rubrik Agent Cloud. is it sort of belt and suspenders that you just don't want to worry about security? Or are there examples, very real examples of agents going rogue? I know you have a program or a campaign right now with this Chungar, this little... Have you seen Chungar? I haven't, but we were talking about it earlier. is how real are the risks? And I use OpenClaw on my primary computer and everyone's like, oh my God, you're crazy. I don't know, what is the risk?
12:51Nine months ago when we started to talk about it, there were probably like one or two of these incidences that I think were important to flag as like what the risks could be. Now, my feeling is that like it's almost you're really stuck between a rock and a hard place where I see organizations take two things they either a take a posture that like this stuff is too risky so we're just going to block access and then you have a question about why is our aoi not good you know delivering roi it's like the code because we said we have you know the agent but it can't access any tool internally of course it can't deliver roi the second is where you say we're going to um you for lack of a better phrase, basically grit our teeth and just say, go and hope nothing goes wrong.
13:38And you give agents access to the different tools. And as a user of these tools myself, I think you mentioned you use OpenClawed. I use also other local coding harnesses. The agent does ask me permission for things. My gosh, it's asking me permissions every 20 seconds, every 30 seconds. Totally transparently, I'm hitting accept, accept, accept at a certain point. And it's not that these things are necessarily all dangerous, but it's asking for root permissions to certain folders. I had an example where I was asking the agent to create a document. And the agent noticed that my Google Drive connector was disabled.
14:17My agent wasn't supposed to go through Google Drive. So what did it do? It spun up a browser window, typed in drive.google.com, clicked upload, and then opened up my file navigation. Now, was that scary? Yeah, that was scary. Did anything bad happen in that instance? Nothing bad happened in the sense that I didn't have any local credentials on it. But actually, I think since we started talking about it in the last nine months, we've seen incident after incident where this has gone wrong. Small example would be like the coding agent that like deletes production databases. I think there's at least two different examples now of public areas that are publicly posted where an agent got access to a production database because, you know, you're hitting yes, yes, yes or something along those lines.
14:53And poof, like, you know, your database is dropped altogether. That's a nightmare for any organization to go through. I think AWS had its post where it said after recording agents got rolled out, they had four Sev1 outages in about 90 days, which for AWS, like, and it might have been shorter than 90 days, but for AWS, like the hallmark of like stability, cloud resilience, that is what you buy them for. SLA is what you buy them for. That's incredible, right? Like this company has processes, but these agents are going through them very quickly. Yeah. Meta, I think, like had its own like incident as well, where I think it was an instance of OpenClaw that actually got access to, you know, someone's email inbox and deleted.
15:33I read about that point, yeah. And so I think, and look, we shared a blog post too, where we did a limited release of Cloud Code. And just even in our individual organization, we saw three different instances of things that we knew like should not be happening. we were able to catch, but we were only able to catch because we had Asian Cloud clicked in, and Asian Cloud uses AI to actually secure and govern all these things. Like we saw an instance where, you know, people were writing and connected into GitHub, writing these gists, and the gist was accidentally shared to a public domain, not the private GitHub.
16:06Sounds like entropic. It's not, and of course, there have been a number of leaks that I think we could be talking about in the last week or two in the market as well. But I guess like my quick point of view is, I think nine months ago, it felt maybe a little bit more felt and suspenders. Like, you know, let's make sure that the things are placed correctly in order. But where I think things are now is you really are stuck between two types of choices. Either block access altogether. And my guess is somewhere, some boardroom or some CEO is going to be like, why aren't we getting ROI with AI? Or enable access.
16:39and kind of in some ways live with the fact, unless you have a solution that's actually monitoring everything that the agents are doing and can enforce these policies, which is like what we've built for us since internally are now packaging. Unless you have that, it's sort of like, you know, deploy it and maybe have some grit teeth and hope nothing goes wrong. But these agents are quite promiscuous, I think, in what they can access. I've read about some of these cases. I haven't read a good analysis of what went wrong. I mean, the email, the woman that's like frantically typing, stop deleting my inbox.
17:14And it just keeps on deleting. I think what often goes wrong is actually quite simple. It's like the agent was doing the right thing 90 % of the time and then just decided to take one wrong action. But the wrong action can happen like that because the agents are operating so fast. What do I love about the agent? It does what took me a week. Like, you know, it does it in an hour. Also somewhat bad when that thing that might have taken me a week would be something that's dropped there. Agent Cloud, Rubrik Agent Cloud, how do you deploy it? If you've got, for example, Cloud Cowork running Cloud Code, OpenClaw, maybe someone's doing something with OpenClaw.
17:51Maybe you're using Copilot as well as Microsoft as part of your Azure subscription. I mean, I think typically I see three different places that people are building agents, and then I can cover how Rubrik Agent Cloud deploys. The first is like you're building using agents on your client. like on the desktop. So that's like Cloud Code, OpenClaw, Cloud Codework. They're all local. The second is that you're building agents that are in the cloud. And this is like maybe you're using things like Copilot Studio from Microsoft or any of the managed services from the hyperscalers. And then the third is you're truly building something homegrown.
18:25Like you just got your OpenAI API key or your Anthropic OpenAI key and you're like, you know, wiring it up through one of these orchestration frameworks. The Rework Agent Cloud has actually hooks into each of these different types of ecosystems. So direct API integrations that can integrate with your mobile device management system, as example, to get a sense of like what the local is happening, has an AI gateway as well. So it provides a way to hook into each of these systems and then immediately start to get like the logs and monitoring and servability inside of our platform and then also start to push down its level of control that it has.
18:54And so our offering can deploy either as a fully managed SaaS offering, which deploys in the cloud managed by rubric or inside of our customers, VPC, inside of their virtual private cloud. and really can hook into the three different kind of surface areas where we see agents get built and deployed. And when you say hook in, is it like an API? Someone's enabling? Yeah. We have multiple different ways that we can hook in. And so the simplest way people often get started is if you're building an agent like in Copilot or Copilot Studio, you can provide your Azure API credentials and Agent Cloud is automatically plugged in, has access to the right set of things on its backend.
19:34If you're running on the endpoint, then we can integrate with an existing mobile device management tool, like an MDM that you have. And then otherwise, if you're just, again, using your own APIs, we can give you the API from the Rubric Agent Cod to use as well. So a little flexible in how we can kind of get there. API integration, give you an API you can use or integrate with your MDM. All different ways that RAC, as we call it, Rubric Agent Cod. I just want to talk about OpenClaw. How much do you know about how OpenClaw works and those security vulnerabilities? partly because I'm using it. I think enough to be dangerous would probably be my answer.
20:10I think OpenClaw really has a lot of the same types of security concerns that I think we would have with some of the conventional desktop agents with like an enhanced level of concern in the sense that it's like not necessarily managed or federated historically. I think when the open source project was getting distributed by, you know, a central party like Cloud Codes or Coworks might be, which has some inbuilt guardrails. So, yeah, enough to be dangerous. I think, you know, organizations oftentimes take a few different types of postures. Like one of them is like we ban OpenClaw outright. In that case, you have a problem of like, how do I know if OpenClaw is even running in the organization?
20:45So that's one of the problems that we solve right out of the box. Like how do we monitor and detect? And then there's, you know, what can OpenClaw do, which is another area where we help. And what does the product look like? Is there a dashboard that a human monitors or is it all agentic? and you just kept an alert if something was going wrong. Yeah, there is a dashboard that like a human can access and monitor. And the product really has, I think, like three key, let's say, journeys that you can think about. The first is the dashboard will show you like the inventory. The inventory will tell you what are all the agents that are running?
21:21What are the different tools that this agent can call? And again, this is across the different places your agents might be built. What are the identities associated with those agents? What models are they calling? So it's like all that visibility like in one place just so you add it. The nice thing is all of this is like automatically discovered and scanned. You don't like go in there and automatically register and manually register. That's like the first user journey is the dashboard and visibility. The second thing, which I think is like one of the more powerful things in the product, is we have a technology we've called SAGE, which stands for Symantec AI Governance Engine.
21:52Really came from our observation that a lot of the customers I worked with would have a policy that they wanted to make sure their agents were consistently adhering to. something like I wouldn't so I spoke with a customer in healthcare yesterday and they said like hey you know agents are not supposed to give clinical diagnoses no idea how to look at us and write a static rule like a string match and be like hey is what the agent said a clinical diagnosis or not so our view is like what you need to do is instead of having like human judgment try and look at everything that an agent was going to put out because that's way too slow we're actually going to have these small language models that can be fine-tuned and deployed to run on every single agent input and output to see if it violates any custom policy that you define.
22:32So we call that system Sage. And really what you can do is you can go into the platform and you just type out a natural language. You could literally type out agents should not give clinical diagnoses. And then we expand on that. We like fill it in with some examples. We show you what examples we'd flag on what we wouldn't flag on as borderline cases. And you can deploy that as a guardrail that'll actually run automatically and everything and then trigger an alert when something goes wrong. So that's the second experience. The third and final experience is inside of our platform, you can also double click into an agent and get a sense of like what's all of its map of actions.
23:02So you can see kind of the trail of like what did it do, when did it do it, and then you know if you need to, you can rewind an action as well to the previous snapshot we have from our Rubrics backup. You guys had an ad with Ludacris playing rewind or wind it back. is on that. How do you rewind an action? It's a complicated thing, but I think that the core of it is that Rubrik actually is lucky to protect a lot of the data for many of our large customers today. And so as we protect the data, we actually maintain like iterative snapshot of like the underlying data source that we might protect. So if you consider this like an Azure SQL database or Salesforce instance, And so if an agent takes a destructive action, you know, let's say on Salesforce or on Azure SQL database, like the first thing we get is like we get the observability that the agent took that action because that's the first journey that I mentioned.
24:00So if we notice a destructive action and a user wants to then say this was incorrect, rewind it back to the previous snapshot, we can then use the power of rubric in the backup in order to be able to restore it from there. Yeah. This is a SaaS offering you were saying. is it priced how is it priced is it by seat or enterprise subscription yeah we do kind of like right sizing towards the individual company and like the use case the product is new so we went GA recently earlier this year and so we've actually been iterating with our early customers on the preferred pricing way but we've been baking in kind of a license fee that gives them certain tiers of usage Yeah.
24:45With the explosion of agents being used by individuals, not enterprises, and as important as the enterprise use is, I think the individual use of agents is going to be as large a market in time as people become comfortable. Do you offer a consumer subscription or something that's geared more toward an individual user or small company? It's a good question. We don't do a subscription for individual or consumer use today. I would say if you're a small to medium business, like it's certainly still like we're open to reaching out. We can look to set up. We have some starter plans. but we really think about the opportunity there's certainly personal and consumer risk that exists but the thing that i think motivates us is that most of the businesses and the enterprises i think are actually either like not adopting ai or adopting out of a very risk for posture because of a lack of way to be able to do this for the enterprise solution and that's the market that i think we're most about if they stay on right now so we think about like global 2000 enterprise really as like some of the key folks, the early and large AI dodgers.
Read the full transcript
26:08And there's a lot of personal users in that market. Like Cloud Cowork is something that people will use as like using their business subscription for the mix of both business and sometimes slightly personal tasks. But like we think about anything running inside of the business context, using your business administration, act the CRIT infrastructure, that's what we want to be able to protect. Yeah, there's been a lot of talk of the agentic enterprise. I mean, enter these agentic native startups that are challenging legacy businesses. So I would imagine this would be something they would want. Is that right?
26:48If they're building an entire business, I mean, beyond agents having access to tools and to databases, agents are talking to each other, And as that fabric expands, you know, humans aren't going to know what's happening between the agents in that layer. Is that something that you're looking at? I mean, where do you see this agent economy going? Well, I think one part of your question was predicated on like these more agentic native organizations. And then I think another part is like how we think about the agent to agent communication. They're kind of enabling. On the first, I would kind of summarize by saying probably anyone who feels like they have something to lose when it comes towards the business value that they have and are trying to accelerate AI, find value here.
27:37And so if you're even a smaller organization, but you've built some level of IP that you want to make sure that you have some protection around, your database is sensitive, certainly this gets more and more relevant as we become a larger organization. You have stake, you're a public company, you're regulated. but really i think about it is anyone who has something to lose and are going to go and unleash agents on that you'll probably want like a level of protection against sin and i just want to like underscore there's a very good reason you unleash agents on the sensitive things that you have something to lose which is like that's how they actually ultimately drive productivity in roi but to your um second question which is around like the agent fabric how does that evolve i think that um we see this first party inside of rubric today which is a lot of what agents do is they go call another agent.
28:25You have your triage agent. Iosha is getting maybe a first-line support, and then you have your next step of an agent that's looking to be able to do a resolution or investigation. I think that the same primitives of how you want to secure and govern, agent-to-agent interaction, apply from when you're a single agent to a multi-agent workflow, which is that you want to be able to make sure that what's going into each agent and coming out of each agent is something that you have an opportunity to do a check on. so if an agent is receiving an input and then receiving a route clip to another agent you want to be able to fly your bar rows on that input and also that output and so then you kind of make sure every node in the graph or every edge connecting those nodes in the graph is secure and that's the way we've been approaching as and so we can see things like is the agent you know classic example for where this could go wrong is like agent A doesn't have access to sensitive data but agent V has access to sensitive data and you want to make sure that agent A doesn't actually get in recurrence that's their data via agent B.
29:25So as long as you're running the guardrail on like, what is agent A getting in this inbook? What is agent A getting as output? You've had Paul's agent B, and you're kind of like intercepting that at the point at which we recognize something and sense of it. That scenario is one that I've talked to people about for a couple of years now since the whole agentic movement started. Once these become agents unseen, and visible to the humans, you know, talking to each other, transferring data to each other. Yeah, you're really vulnerable because you don't know where the data is going. There's a loss of control.
30:03Yeah, yeah, exactly. And the orchestration layer is supposed to take care of that. Yeah, I think the orchestration layer takes care of making sure that the calls are kind of chained, let's say, correctly. Yeah, but oftentimes misses the context on what, like at an organizational level, should be happening from like a policy standpoint. So the orchestration layer does a great job of saying something like, Agent A needs this information to fulfill its request, so let's go to Agent B and kind of go into it. But I think like that introspection of like, well, should the request be filled or is the context that's coming in to be able to fill this request actually appropriate for Agent A?
30:40That's where I think you need the layer on top. Correct. Who is the end user in the organization? Is this the IT department that's applying this? Is it the C-suite? Is it the individual user who has access to an agentic platform? AI has moved so quickly through the enterprise that we certainly see that there's a few different areas that have interest in it. But there's two that I think say that is kind of the strongest. The first is within IT, there's usually an AI platform team. That AI platform team may have titles like AI Enterprise Architects or otherwise. And they're thinking about how do they build trust and governance out of the platforms that they're actually enabling organizations and, you know, their employees to be able to use.
31:28And so that's like one area. And then the second area is within security. Oftentimes, I think within security, there's a few different stakeholders, but maybe within like sec ops, like they're concerned around what are the APHIS, you know, the turn of yesterday was like might have been like did an employee accidentally exfiltrate sensitive data. And now it's gotten exacerbated by the agentic future. And so that's the second stakeholder that we see in those strongholds. There's certainly others that we see, like governance, risk and compliance tends to be an organization that has like a heavy amount of oversight here as well.
31:57and then we even see like in the CTO or BP engineering organizations there's a demand for guardrails. But it's like enterprise IT and AI architects as well as like inside of security and security architects are the two places where we see this as the user. How's the uptake? I mean, this is all new. Yes. And do you think that the security layers of the rubric agent cloud will eventually merge with the orchestration layer, be folded into the orchestration, either because rubric builds on an orchestration layer or somebody acquires rubric. I imagine that this is all going to converge into one thing.
32:43Yeah. You know, I think that my point of view actually might feel a little bit different, which is I think that there will be many good solutions for where people build and deploy agents. And the way that I think Bipple, our CEO, is kind of framed it is you will want a Switzerland-like collider to actually secure and govern the different agents that are actually being built. You probably won't want the model company to also be policing the models that it's necessarily opening out. It might do a decent job to a large extent, but I think you'll want a system of controls above and beyond that have your enterprise and IT context as well.
33:16And so the way I think about it is like, I think Rubrik Asian Cloud is going to remain orchestration, kind of platform neutral or agnostic to the extent that we can. I don't want to have a strong point of view on which model you use or which platform you use as you're building Agri-Agent. We want to just try and make sure we deliver a consistent governance and security experience regardless. The competitive landscape that you're facing, I would imagine that there are a lot of companies who are already in the security space that are moving in this direction. It's obvious Asians are the future. How do you position yourselves to stay competitive?
34:02I think Rubrik did something very unique, which was it was a data security company. So security can be kind of by DNA that acquired a model infrastructure company like my startup, Predabase. And so I think one of the unique differentiations that combination has actually brought in is a lot of security companies, I think, approach the challenge here in a conventional security way. But what we've decided to do is like we're saying the only way you can secure and govern AI is to use AI and SOC. So that's where Sage and our small language model differentiation built and deployed on top of the Predabase platform, I think is in some ways a large part of the competitive advantage we have against other organizations that might see the same trouble.
34:43you know what we often say is like if you are going with us you probably want to buy the thesis that i need to use ai to help me secure and govern these agents and we can uniquely do that and it has to be small language models because there's no way you could deal with the latency or cost footprint if it wasn't um and so you know we think about that as a core part of our differentiator mixed in with the data and identity signals that rubric has internally as a normalization so i think there's certainly gonna be there's certainly competition in the airwaves i would say I think the reality is a lot of product is either new or still being announced.
35:16You know, we went to earlier this month, sorry, earlier this year, but I think a lot of the external products are maybe coming soon is what I hear. And I think that there will be good offerings that oftentimes will be complementary to what we have as well. And then maybe good competitive offerings too. The differentiation we'll continue to lean on is number one, our ability to use like AI to secure and govern agents, predicated on credit basis technology around small language models. and a number two data and identity context root or guess. You said you're really targeting the Fortune 2000. Was that under?
35:47I think that Global 2000 Enterprise tends to be like some of the most, I think they're like organizations that have a combination of like a risk profile where they want to be able to make sure that things are done in a secure way, but also the pressure to adopt AI. We really think about anyone who is deploying AI at some level of scale and looking to be able to give it access. Like the type of user who's looking to graduate from read to write, you know, simple read agents to write agents, that's kind of the person that we're looking to target. And Rubik's customer base, I oftentimes think about as like the global 2000 enterprise, like a large country.
36:21You know, there's famously over the last year been a lot of pilot programs, very few. I mean, the production, putting into production is ramping up. But as you said, a lot of companies just don't want to take any risks. They're kind of watching the market. How is the penetration in the global 2000 for agentic workflows? Do you have a sense of that? My view is that there is, and speaking with a lot of the conversations, especially at the exact level, is that there's tremendous pressure to adopt AI. I spoke with a CISO recently who was part of a panel. And I think he said, like, I think all of our CDOs went to the same retreat for a week where the boards were like, you must adopt AI faster.
37:12But then they kind of hit this difficult reality, which is that, OK, we need to adopt AI. But in order for AI to do anything useful, we need to have access. And I can't, you know, the existing architecture that I have wasn't built for agents to have this access securely. It's pretty much conventionally the story I hear, I think, repeatedly. And so in terms of penetration into Global 2000, I'd say I see tremendous pressure. So I see a lot of projects that have been spun up. But I also see a lot of pain maybe in the very early phases of those projects, which is just kind of like slow down there.
37:47Like, let's go and figure out how are we supposed to do this? Let's have a meeting. Let's do a design job. Let's go through a committee approval process. And the committee itself is still crankily trying to figure out what are the level of controls. we had the same problem you know in terms of like what would be process look like um the internally at rubric um and i think what we realized is like we need to go away from like people and paper and process to something that's actually the software product platform solution and that's why we built what we built but in terms of like i think what's the level of penetration i see lots of interest lots of like and and also lots of like funded pilots yep um and i think a big question around a big open question that's holding back the progress from being as fast as I might like it to be around like AI risk and not even myself.
38:30Yeah. So you guys must be growing very fast. It's been a lot of fun, I think, post-acquisition as well to be inside of Rubrik and actually see the growth. Yeah. But I mean, in terms of the addressable market, so your addressable market are people who are implementing agentic workflows. and that's only beginning really. I mean, we're still at the kind of the early slope. We're in the early adopters in A's. Yeah, it might be for where a lot of the organizations are. But I think the pace at which it's graduating from like early adopter towards the healthy middle, I think it's the fastest in any technology trend that I've seen in terms of how much this is being pushed.
39:13It's being pushed top down, it's being pushed bottom up. It's like a lot of pressure that needs building this system. So what's next for Rubrik Agent Cloud? I mean, where do you go from here besides expanding your customer base? I really think about the core of our mission is to help secure and accelerate the world's AI transformation. We think that limiting risk is a huge part of that. So our approach at Agent Cloud is to be able to use AI in heavier ways to do that. So where we're going to go is right now, like a user can define their guardrails as they want directly natural language. We're going to be building more agentic workflows to help out on this.
39:53And so you can think about this as like today, it's very human dilubent, like how do you govern? But can we actually even ease the burden on that side? It's like one natural area that we want to be able to go. And the second is like there's plenty of service area out there still for us to cover in terms of place to do out of line agents or new testing use cases. That's what we might be running into. And so I think we've got our work cut out for us. but really the thing that's most motivating is like yeah we see a definitive need for this in the market and like I feel the pain that I think a lot of the folks in the other side of the table feel because it's sort of like what do you mean you want me to give access you know my agent access to my system of record for my customer data but also how can I get my agent to meaningful work if it cannot just my customers and so like I think I see that pain we have an odd opportunity to be able to pull into it we're continuing to invest in ways that we can use AI as like a high leverage way to be able to solve a problem.
40:43And I think we're going to continue kind of focusing on the mission of securing and accelerating the edge. I mean, when you go out and talk to companies, are you kind of an agent evangelist saying, look, you're afraid of deploying agents in your enterprise because of the risk and security concerns? It's funny. I don't think of myself as an agent evangelist. I will say I think everyone should be adopting this technology at a much heavier rate because of the incredible upside potential that it has. And I ultimately think that those, there's a question about like, well, AI agents and AI like cause job displacement.
41:23And I think like the view that I've conventionally heard that tracks is like, AI may not, but someone who nails AI. And I think that's going to exist at the organizational level too. It's like, who's using AI to best? I believe going to dictate a lot of what happens over the next five years. so I don't feel like I if someone's not let's say a believer that AI is the right solution towards them I think that's totally an appropriate conclusion and want them to be able to go forward with it the place that I think I feel the most kindred spirit or ability to help is when someone recognizes that this is the right solution they might be stuck on how to get started because they have this stuck between a rock and a hard post problem is most of your the adoption that you see of rubric open rubric agent cloud, I'm sorry, coming because you're out talking to companies about how to make agents secure so that they can get the ROI, They can start on that journey.
42:22Or are enterprises that either have a pilot or are integrating an agentic system into their enterprise realize, hey, we need a security solution. And they're out looking and find you. I mean, oh, yeah. You know, because I've been like doing this kind of part of the pipeline building for at least like five or six years now. on. I will say something feels different in this market, which is we try not to pitch very heavily in terms of like what it is that like we do or not. We describe the pain in a conversation. Sometimes we describe this in a webinar or a marketing event. Sometimes we describe it in direct customer conversation.
43:00I think we're very transparent in saying like the solution might not be for where you are right now, but if it is like we'd love to go and have the conversation. We've been lucky enough that I think there's so much interest in the market that we've been able to not have to pitch so hard. So we kind of just described like here's basically the narrative is like here's the pains. We know these pains because we ran into that out rubric. Here's the way that we thought about approaching them as a problem in terms of like the solution architecture. Here's what that looks like as a product to prove a gauge.
43:28If that sounds like it's the right that if you believe into our thesis that you need AI to help you secure and govern agents and that data and identity context is important that you need to be able to do this at runtime protection. We're going to have agents in a number of different places. We kind of believe a few of these things, then it's, and like, this is a timely issue for you, we should definitely have that next conversation. And if not, like, you know, we're happy to revisit in six, six to nine months. So I'd say it's like a healthy mix of both outbound and inbound. But regardless for both, we're at the phase where we're not really like trying to push this at all on anyone.
43:57But we've been getting a lot of pull, because people recognize that's kind of an issue that they're facing today. Yeah. Can you talk a little bit about what's happening under the hood? I mean, what is happening? And the interface for setting it up, you say, you know, the Rubrik agent cloud goes in and scans a system and sort of a lot of the setup is automatic, but it does. Yeah. How does that work? And is there a conversational interface I was going to ask? Yeah. So Rubrik does have a conversational interface called Ruby, which is essentially a conversational interface towards the Rubrik platform.
44:40In terms of the setup for what it looks like and what's going on under the hood, you can really think about what's going on under the hood and maybe three key phases. The first is like we're connecting in. What is connecting in means? It means that we're getting exposure to the Asian runtime such that it can help expose its logs, like the literal prompts, the responses, the tool calls, everything that's coming out of a system directly into our visibility stage. So like the very first thing we're doing is like we're getting those hooks in to the runtimes in those three different service areas we are where we're starting to see prompts, responses, and tool calls flow through our system.
45:16We then use that in the Earthflow to go and populate. This is an agent. Here's its graph. We're kind of showing you the literal map of what it could be. The second thing that's kind of going on over the hood is you're defining policies. Now, we have a number of policies that you could just enable in one click. So you could say things like prevent prompt injection or make sure your agents are read-only by default just in one click. But what we also allow you to do is define your custom policy in English. So what's happening under the hood is you enter essentially a prompt, like your own individual text.
45:48And we will go and expand that definition with a number of best practices we know. We'll give it reference definitions, examples. We'll allow you to confirm. And then in the back end, what we'll do under the hood is we'll actually still listen to a small model that can be deployed on very efficient infrastructure sure and start to put it in line with the prompts and responses that we were seeing in that first uh you know bucket that we looked up to uh and then the third thing we're doing is we are giving you some level of like alerting and control under the hood so anytime like this smart agent sage is basically picking up on something that was mistaken sage is like popping up on alert that's saying here's something that went wrong or it's just blocking it all together you can figure it that way.
46:31So Rubrik Agent Cloud itself is an agentic system, is that right? I think that Rubrik Agent Cloud is a platform that has some agentic workflows running within it, yeah, and will continue to have more and more agentic workflows running in it every time. Say whatever you want to say the cloud about. I think maybe just the cloud, the biggest thing I would say is, you know, since when I started in the company Predabase, so like where I am today, I think like the models have gotten so much smarter, the sophistication around the harnesses and the orchestration frameworks have gotten so much better that I think that now the bottleneck is really like, how do we securely manage the risk these agents are going?
47:13I think that's like the big open opportunity. I think the lack of it is why you see the ROI question a lot of organizations. And like, that is, I think the biggest thing that I'm firstly, it's just an impassioned about solving is how do we look securely and accelerate the world's AI transformation by giving you, the ability to really trust what your agents are doing. Yeah. Okay.
From the publisher
What is an AI agent, really? Strip away the hype, and it's a model with access - to tools, APIs, databases, email, anything that lets it take real action instead of just generating text. That access is exactly where the risk lives, and Devvret Rishi, GM of AI at Rubrik, and former co-founder & CEO of Predibase, joins Craig Smith with a string of real-world incidents that make the case concrete: AWS reporting four major outages in 90 days after deploying coding agents, a Meta-related agent that deleted someone's emails while they were actively asking it to stop, and Rubrik's own internal pilot catching incidents that, without governance in place, would have gone unnoticed.
The conversation lays out the impossible choice most enterprises are facing right now - block AI agents and forfeit the ROI boards are demanding, or grant access and hope nothing breaks - and walks through how Rubrik's approach uses small, fine-tuned AI models to enforce plain-English security policies on every single agent action in real time. It closes on one of the most underexamined risks ahead: as agents increasingly talk to other agents to get work done, a layer of activity is forming that no human is watching, and the question of who's accountable when something goes wrong in that layer is only getting more urgent.
Subscribe to Eye on A.I. for weekly conversations with the people building and deploying the future of AI.




