989: Security for Mythos-Era Agentic Risks, with Rubrik’s Anneka Gupta and Cal Al-Dhubaib

5 May 2026 · 1 h 4 min · 27 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The episode argues that “Mythos-era” agentic AI will rapidly expand cyber risk by enabling faster vulnerability discovery/exploitation and by increasing the attack surface through autonomous actions and “non-human identities.” Guests say organizations must shift from prevention/detection to cyber resilience and recovery planning, including runtime governance and the ability to “rewind” harmful agent actions.

Guests

Annika Gupta (Chief Product Officer at Rubrik; Stanford BS in math/computational sciences; 11 years at LiveRamp with ~17 roles; now leads Rubrik’s AI/cyber resilience direction). Cal Al-Dhubaib (Principal Technologist at Rubrik; previously ran AI at Further; advocated “making AI boring” for production; now emphasizes the growing blast radius of autonomous systems).

Key claims

Open-weight models with Mythos-like exploit capability may proliferate in 6–18 months. Most orgs lack visibility into what agents do. Zero trust = assume breach; enterprise needs trust infrastructure for AI. Rubrik’s approach centers on preemptive recovery, governance, and agent rewind.

Notable examples

Anthropic’s Claude Mythos preview not released publicly; an Anthropic misconfigured boolean flag reportedly exposed cloud code. Example incidents include Amazon losing 99% of orders from agent-generated code and a small business database wipe tied to agentic tooling. Rubrik examples: credential compromise (e.g., MGM casino-style support-driven reset), then exfiltration/encryption/deletion; Rubrik scans to assess blast radius and recover quickly. SAGE governance uses a fine-tuned small language model for fast policy enforcement; Agent Rewind restores changes like dropped DB tables or broken Salesforce relationships.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Introduction to AI Security Risks

0:00 to 0:18

Learn about the capabilities and risks associated with mythos-era AI models.

“Anthropic claim mythos is so capable at finding and exploiting cyber vulnerabilities that they can't release it to the public.”

Background on Rubrik and Cyber Resilience

1:00 to 2:20

Understand Rubrik's journey in improving data resilience and its focus on AI.

“This episode of Super Data Science is made possible by Anthropic, Excel Data, and Cisco.”

AI's Impact on Cybersecurity

2:20 to 4:50

Explore the evolving landscape of AI in cybersecurity and the challenges posed.

“very timely matters, I want our audience to have a little bit of background on both of you.”

Cal's Transition to Rubrik and AI Insights

4:50 to 8:00

Discussion on Cal's move to Rubrik and his insights on the AI landscape.

“Now, Cal, Cal, last March, you were on this podcast in episode number 865, so people can listen to get a whole bunch more context on you if they want to.”

The State of AI and Cyber Incidents

8:00 to 9:00

Cal shares alarming statistics about recent AI-related cybersecurity incidents.

“company with thousands of employees, they still very much operate like a startup.”

The Risks of AI Tools like Mythos

9:00 to 11:40

Discuss the risks associated with AI tools that can exploit vulnerabilities.

“You know, there's only people testing it privately.”

Trust Infrastructure and AI Mistakes

11:40 to 14:01

Examine the need for trust infrastructure to mitigate AI mistakes in cybersecurity.

“attacker gets into your system and destroys your data, your identities, or your infrastructure.”

Understanding AI Agent Risks and Cybersecurity

14:01 to 16:56

Learn how AI agents can inadvertently create cybersecurity risks and the implications of their autonomous actions.

“And what that means is that inevitably, AI agents are going to make mistakes.”

The Growing Threat of AI Vulnerabilities

16:56 to 19:35

Discover the increasing concern among executives regarding AI vulnerabilities as a vector for cyber risks.

“Vijoy Pandey, the head of Outshift by Cisco, walks through how horizontal scaling of intelligence works and why it matters.”

Navigating Cyber Attacks and Recovery Strategies

19:35 to 24:11

Understand the typical flow of a cyber attack and how to effectively recover using the Rubrik platform.

“How do we help our businesses stay resilient in the face of a risk that is growing exponentially day by day?”
Show all 27 chapters

Identity Management in the Agentic Era

24:11 to 27:25

Explore the challenges of managing non-human identities and the implications for cybersecurity in AI.

“And in doing so, we've built a deep understanding of data and of identity.”

Zero Trust Architecture Explained

27:25 to 28:00

Learn about the concept of zero trust in cybersecurity and its importance in modern security architecture.

“There's a term that we haven't said yet that I hear a lot in the cybersecurity space, which is a zero trust world.”

Understanding Zero Trust in Cybersecurity

28:00 to 28:50

Learn about the concept of zero trust and its implications for cybersecurity.

“And in an ideal world, that access is somewhat ephemeral so that there's no permanent access to things that are incredibly important.”

Introduction to the Trust Engineering Framework

28:50 to 30:00

Explore the Trust Engineering Framework and its relevance to AI governance.

“Cal, I've got a question for you that is specific to some talks you've been giving a LinkedIn learning course that you have coming out soon.”

The Importance of Human-Centered Design

30:00 to 33:10

Understand how human-centered design integrates with AI systems for risk management.

“And for listeners who didn't catch the last episode, I spent 10 years designing machine learning and AI systems and leading teams that do that in heavily regulated environments.”

The Intersection of AI and Cybersecurity

33:10 to 35:00

Discuss the merging fields of AI risk management and cybersecurity.

“And it's only in thinking about all of these three holistically together that we can actually truly solve a problem.”

Proactive Cybersecurity Measures

35:00 to 36:30

Learn about the necessity of proactive cybersecurity in the age of AI.

“You have to think about it holistically because any sort of risk management you put in place could also potentially come at the expense of productivity.”

Introducing SAGE: The Semantic AI Governance Engine

36:30 to 37:50

Discover the capabilities of SAGE in managing AI governance effectively.

“You've been speaking a lot in the past few minutes, both of you, about this intersection between AI and cybersecurity.”

How the Rubrik Agent Cloud Operates

37:50 to 42:01

Learn about Rubrik Agent Cloud and its role in AI operations and security.

“Why did you go with a custom trained SLM rather than maybe fine tuning or distilling a frontier model?”

Understanding Rubric Agent Cloud Policies

42:01 to 43:30

Learn about defining and enforcing policies for AI agents within Rubric's platform.

“where you can define a policy in natural language saying like, hey, I don't want my agents giving financial advice or I don't want them sending emails out to my customers.”

The Evolving Landscape of AI Agents

43:31 to 45:12

Explore how quickly the AI agent landscape is changing and its implications for the future.

“Opening AI didn't even come up, which is just two years ago.”

Agent Rewind Functionality Explained

45:13 to 47:18

Discover the concept of Agent Rewind and its importance in AI actions recovery.

“So yeah, now rewinding to Agent Rewind, much like the rubric Agent Cloud that really caught my attention.”

Evaluating AI Security in Today's Models

47:19 to 52:22

Understand how to evaluate AI models in terms of security and resilience in enterprise settings.

“looking at what is actually, the agent's actually doing it and stopping there.”

Questions for a Zero-Trust AI World

52:23 to 56:00

Identify key questions that should be asked regarding AI governance in a zero-trust environment.

“And yeah, some great ideas there around looking beyond benchmarks, including in the security space, when we're thinking about what kinds of AI models we should be using.”

AI Attorney's Role in Risk Management

56:00 to 56:50

Learn how AI attorneys are crucial in managing enterprise risk exposure.

“I was so thrilled to learn at Rubrik that we actually have a dedicated AI attorney.”

Book Recommendations and Discussion

56:50 to 58:51

Discover insightful book recommendations related to AI risks and lighthearted fiction.

“Um, so this has been a fantastic episode.”

Staying Connected with Guests

58:51 to 59:38

Find out how to connect with guests Annika and Cal on LinkedIn post-episode.

“And then the very last thing is how should people follow you after the episode?”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Jon Krohn:Anthropic claim mythos is so capable at finding and exploiting cyber vulnerabilities that they can't release it to the public. Regardless, the clock is ticking. Within 6-18 months, open-weight models will have the same security exploiting capabilities. So, what are we going to do? Welcome to another episode of the Super Data Science Podcast. I'm your host, Jon Krohn. my sensational guests today are Anika Gupta and Cal Aldubabe, who serve as Chief Product Officer and Principal Technologist, respectively, at Rubrik, a massive Bay Area security and AI company that is listed on the New York Stock Exchange.

0:37Jon Krohn:In the Claude Code and Mythos era, we have wildly powerful code generation tools at our disposal, but this is rapidly accelerating security risks, both through inadvertent oversights and purposeful misuse. Luckily, Rubrik have equally powerful solutions to meet the challenge. In today's episode, Annika and Cal will tell you all about it. Enjoy. This episode of Super Data Science is made possible by Anthropic, Excel Data, and Cisco. Wow, I have two guests on the show today. Cal, Annika, how you doing? Maybe let's start with Annika, since it's your first time on the show. Well, I'm very excited to be here.

1:18I'm in sunny Florida right now. So what a place to be recording and spending time with you today.

1:24Jon Krohn:Nice, enjoying it. And Cal, welcome back to the podcast. You were such a treat last time. It's great to be back. And I'm so excited to be dialing in from ODSC, one of our favorite conference venues. The Open Data Science Conference. We've run lots of sponsor messages for that show on this podcast, but we genuinely love it. I've seen you there, Cal, so many times and so many guests that we've had on the show. It's really the Open Data Science Conference. If listeners haven't had a chance to go, I realize that they do sponsor this show. So this sounds like it might be biased, but there's no conference that's better for a listener of this podcast.

1:57Jon Krohn:And there's no place that you can go and meet more Super Data Science Podcast listeners. Nice. So great to have you both here calling in despite your travels. And we had to make this episode happen because there are very timely things happening in AI that couldn't go another week without us covering. But before we get into those very timely matters, I want our audience to have a little bit of background on both of you. So let's start with you, Annika. You did a Stanford bachelor's degree in math and computational sciences, and then you did 11 years at LiveRamp in the Bay Area, I believe that whole time.

2:35Jon Krohn:And you held something like 17 different roles before becoming the chief product officer, where you are now at Rubric, publicly listed company, but I'm no expert at Rubric. You are, you seem to be loving it there. So tell us about the platform and let us know, are you going to break your 11 year record that you had at LiveRamp now at Rubric? Well, I'm five years in, so we'll see. And it still feels like it's day one. Super excited to be here. Rubric is a cyber resilience platform, and we've been around for about 12 years now. We have been innovating and evolving throughout those 12 years at the same speed that we were, I think, on day one of the company.

3:14We started by recognizing that there was a huge challenge around resilience of data and making sure that your data could always be available to you, regardless of where that data lives, which it's now living in many more places across cloud, across on-prem, across SaaS applications. And that was the beginning of our journey. And what we found is over the first few years of the company that we got pulled into cyber because really what was happening was that people weren't losing data anymore because of accidental deletions or because of natural disasters. They were still losing data for that. But the more frequent reason why they needed to bring back their data was because of cyber attacks.

3:57And now, as we think about the future and the past few years and going forward, we're now really focused around AI and AI agents and recognizing that the next vector is not just increase of cyber attacks, but also looking at AI and the way that AI is being used. Inevitably, AI is going to make mistakes. Those mistakes might be benign mistakes or they might be malicious mistakes, but it's going to make mistakes and you need to build resilience for your organization in order to make sure that no matter what happens, whether it's a natural disaster, cyber attack, AI agent making a mistake, your business is never coming down and that your customers are not materially impacted.

4:36Jon Krohn:Right. So it sounds like the starting point for Rubrik as a business before it grew into this big publicly traded, NYSE listed business is that. Oh, and by the way, I also recently noticed that your share price has been doing very well since listing. So that's a nice sign to have. And it sounds like you got started as a cybersecurity business, but then with all of these fast shifts in AI and all of the vectors for security issues that have emerged, especially now in the agentic AI era, Rubrik has had to come up with solutions for all these issues. Absolutely. And that's been a big focus for us.

5:15Jon Krohn:All right. Now, Cal, Cal, last March, you were on this podcast in episode number 865, so people can listen to get a whole bunch more context on you if they want to. At that time, you were running AI at Further, which is an AI consulting firm. You were 80-plus AI projects deep. And at that time, in that episode, you were advocating for making AI boring as the path to success, especially with production AI. But now, Cal, a year later, you've left that role at Further and you've joined Rubrik as principal technologist. And now you're publicly arguing the opposite of making AI boring. You're saying that we're in a watershed cyber AI moment that's anything but.

5:57Jon Krohn:What changed your read of the landscape between last year's episode and this one now? I think the step function and the blast radius of autonomous systems that can iterate over multiple steps and chain together a series of tools that are now increasingly resulting in material impacts to business. I mean, the news cycle, even in the last two months, has been more intense than any other period. I've been tracking AI incidents. I'm a big fan of the AI Incident Database Project, and that's been on a hockey stick. But within the last couple of months, Amazon, for example, lost 99 % of their orders on a single day as a result of code that was generated by an agentic tool.

6:46There is this Reddit thread that blew up this past weekend, and it was about a small business that had a bookings and reservation system, and it completely wiped every instance in their database. And so their customers were trying to retrace through restraints and stripes. And so the material impact is here and the blast radius is growing. I still maintain that we need AI to become boring. I think it's gotten a little too exciting and we need to dial the heat down. And I know we're going to talk a little bit more about what that means with trust infrastructure and trust engineering. But when this opportunity came up with Rubrik, I was so excited.

7:26I was already seeing the trend unfolding that the only way to make AI work in the enterprise is if we could, one, secure the data and information assets that it's connecting to, and two, safeguard AI from malicious attackers that are now increasingly very productive with their own use of AI. And oh, by the way, they don't have AI usage policies. So I'm really excited to be a part of the story here. And I can say three weeks in, even though Rubrik has gone public and they're a massive company with thousands of employees, they still very much operate like a startup. And it's been so fun getting to immerse in this culture.

8:12Jon Krohn:Really cool. Well, congrats on the move. And it makes so much sense to me in addition to or perhaps correlating. with all of these cybersecurity incidents that you've been describing is, you talked about it being this big influx in the past two months. And it's interesting that that coincides with, it's been two months at the time of recording since the release of Claude Opus 4.6 and Claude Code really taking off as something that people can be leveraging as a serious power tool for doing development work and probably identifying vulnerabilities. Absolutely. And then now, more recently, just a couple of weeks ago at the time of recording, on April 7th, Anthropic announced Claude Mythos preview.

8:58Jon Krohn:And so this is a model that famously they haven't released to the public. You know, there's only people testing it privately. Anthropic's own estimate, however, is that Mythos class capabilities will proliferate to other labs within 6 to 18 months with open-weight versions to follow. So, yeah, the reason supposedly why they didn't release it to the public is because of its prolific ability to identify cybersecurity issues and exploit them if it's not being used by a friendly person. Now, I also do think it's brilliant marketing to say that. It is very fortunate. to the public. But yeah, from inside rubric, is mythos the inflection or just the most visible point on a curve you'd already been planning against?

9:47You know, I think when you look at mythos, it's definitely the most visible point on the curve that we've already been planning for. Because even if you look at models like Opus, for instance, they also are able to find vulnerabilities. They just require a few more hand, a little bit more handholding to get there. Whereas Mythos, you can point it at an open source repository and tell it to find me all the vulnerabilities and it will find you the vulnerabilities. And this is just the nature of where AI is going. The challenge is that the cybersecurity industry as a whole has been super focused on attack prevention and attack detection, because it used to be the case that attackers would enter into your system, they would sit there for weeks, if not months, sifting through your data, finding the opportune time to actually exploit this vulnerability and really perpetrate the attack, and then actually do that in a visible way, such that the company then has to react to it.

10:49But with the reality that now with AI agents, you can find and exploit these vulnerabilities much, much faster and at machine speed that requires machine speed response. And no longer can you hope that if you detect an attacker, detect a breach, okay, maybe you can cut that off before the attacker has done damage. Instead, you have to assume that you've already been breached and you need a plan for how are you actually going to recover and ensure that in that recovery, you're minimizing any impact to your overall business. And that's the business that Rubric has been in. So I feel like there's never been a more important time for what we've been doing because what we're ensuring is that you can actually restore your applications, your data, your identity, your infrastructure back up and running extremely quickly in the case that an attacker gets into your system and destroys your data, your identities, or your infrastructure.

11:55What I find really interesting is it's like this twofold problem, and we're kind of feeding into it from the enterprise perspective. There's still massive FOMO. Everyone has to use AI. Everyone has to be more productive, and it's coming from leadership down. And so we're very quickly opening up actually the surface area, that models that are like mythos can actually chain together vulnerabilities. So it's one, you've got this problem of adoption as increasing surface area. And then two, these models themselves, and I know we're going to nerd out a little bit more about it, but I get so passionate about this.

12:27We don't yet have the right trust infrastructure in place in most cases to prevent models from causing harm on their own. So you don't even need the bad guys.

12:37Jon Krohn:Right. Yeah, it's pretty wild. I mean, it was Anthropic themselves that actually had, there was some flag, like a Boolean flag that they got wrong in some, like somehow it was possible for them. You guys might be able to explain this better than me because you actually are cybersecurity experts. Cal's been one for three weeks. And, but there was like a flag that was set the wrong way in some code that was pushed to GitHub. And so that allowed people to see the entirety of the cloud code base. How does something how does something like that happen? Well, I think that's an interesting case. There's a lot of different scenarios where things have been exposed publicly that they weren't that weren't wasn't supposed to be.

13:18There are cases where code has been exposed externally because the AI agents posted it into the wrong repository. That's not what happened in the Anthropic case. In an anthropic case, there was, again, a Boolean flag that was misconfigured and sent out. But the reality is, is that the challenge that we have today is that AI agents, they're very outcome focused. They're going and trying to say, how do I get this job done in the least steps possible, the fastest way possible? And they're not taking into account the same rules that us as humans, as employees working in an organization know to follow.

13:55You know, they haven't gone through all the security training that we've gone through. They haven't gone through the developer best practices training. Now, obviously, they have that information in their models broadly, but they're not optimizing for the same thing that we're optimizing for. And what that means is that inevitably, AI agents are going to make mistakes. Inevitably, they're going to do things that you didn't want them to do in their pursuit of this outcome of a task that you've given them. I find it really interesting that these models, because we've been investing in the capabilities for them to iterate autonomously, think of it as an exhaustive search that's now happening across all of the data assets and tools and configurations of that tool.

14:40Humans in the past, we actually had a lot of security through obscurity. We might have had permissions. I've been studying my cyber stuff. You have. I've impressed. We had security through obscurity. And like, you know, we had access to files and permissions, but we didn't broadly use these permissions to take large scale actions. And now we have these very hyperproductive agentic systems that can do an exhaustive search of everything that's available to it to accomplish the task. And so a lot of cyber controls really were never designed with this reality in mind. And it's not just about the mistakes that AI can make or what it can publicly expose.

15:19there are other kinds of data exposure risks that you have even internally, right? You could say, hey, like, you know, salaries of an employee could be accidentally shared with another employee because you've hooked up your AI agents to your employee and compensation systems. And that is really scary too. So there's a lot of implications both internally and externally to exactly what Cal is talking about. And as the models themselves are able to take just more and more and more and more steps independently, it's really hard to diagnose like where in that 20 step process did this happen and what caused it.

16:01And you're certainly not going to be able to fix that after the fact. You have to figure out how you're actually going to fix this during like while this agent is actually running.

16:11Jon Krohn:Quick reality check for anyone building with With AI agents, your agents can discover each other, they can pass messages, they can coordinate on tasks. But here's what they can't do. They can't think together. When your agent figures out how to handle a complex workflow, that knowledge stays isolated. The industry has focused on scaling AI vertically, bigger models, more compute. Those breakthroughs matter. But intelligence also scales horizontally. Agents sharing knowledge across a network, coordinating on common intent, reasoning together. The infrastructure for that second horizontal axis doesn't exist yet.

16:45Jon Krohn:Outshift by Cisco is formalizing it. They call it the Internet of Cognition. They're publishing the architecture and building reference implementations. Read Scaling Out Superintelligence. We've got a link to that in the show notes. Then check out episode number 961. In it, Dr. Vijoy Pandey, the head of Outshift by Cisco, walks through how horizontal scaling of intelligence works and why it matters. Right, yeah. Yeah, so on the one hand, having these kinds of tools like Cloud Code to be able to generate so much code so quickly that creates opportunities for mistakes inadvertently entered because, like both of you have said, the agent is trying to get to the outcome as quickly as possible and therefore some security things can get through.

17:30Jon Krohn:And then there's so much code that it could be really hard for humans, impossible for humans to have oversight over all that code. I've been reading that in a lot of organizations now, the engineering team is struggling to know what to do with this vast amount of code that's being generated. There's so much potential, but also so much risk. Now, on the other side of things, something that we haven't talked about very much, which was actually kind of my starting point with this question, I was thinking, oh, the release of Claude Opus 4.6 in February, this correlates with this boom in cybersecurity incidents.

18:03Jon Krohn:In my mind, I was thinking this is because bad actors are using it to find and exploit vulnerabilities. And so far, we've mostly been talking about, you know, kind of people inadvertently creating, exposing vulnerabilities through using cogent tools. But the cogent tools can also be used maliciously, right? Yeah, absolutely. And it's already starting to happen. There are cases where this has publicly already happened. I think what we see, though, is that it's more about what people are planning for is really about the future and where these tools are starting to be used at scale. So for instance, over 87 % of executives at companies are now worried about AI vulnerabilities and that being their fastest growing vector of cyber risk.

18:56So that was from the World Economic Forum published that. Most organizations, again, over 80 % of organizations don't feel like they have the kind of visibility that they need into AI agents. And so when you start saying like, hey, attackers are gonna be exploding traditional vulnerabilities as well as AI vulnerabilities, it's just starting now. And there's already examples now that people are talking about. But fast forward six, 12 months, and this problem is going to be untenable. And that's what is getting everyone right now in our space really worked up about, OK, how do we come together as a community?

19:35How do we help solve this? How do we help our businesses stay resilient in the face of a risk that is growing exponentially day by day? Well, I can't stress this enough. The phrase resilience resonates with me. And part of why I was so enticed to join Rubric is it's not if, it's when, and then what do you do next? And when I've consulted clients in the past on their AI governance strategy and their approach, the most often missing element, it's like, okay, we can do evals, we can do testing, we can get some observability in place, and that's kind of mid. But the thing that rarely was ever done is, all right, when it fails, whose job is it to recover?

20:18And what does that plan look like? And oh, by the way, have you tested that? All right.

20:24Jon Krohn:So this sounds like a perfect time to ask. You're kind of alluding to it now, but let's get into some brass tacks around the Rubik platform itself. It's been around for a long time. It's a publicly listed company. So there's probably a lot of facets, but is there some kind of like exemplary or maybe a few exemplary user stories that you can walk us through so that we can visualize what it's like to use the Rubrik platform to have better cybersecurity in this agentic AI era? Yeah, absolutely. So, you know, what I'll do is I will take you through an example of what does a cyber attack really look like?

21:02And then where does rubrics platform fit into that. So typically what happens is that a cyber attacker will go in, the most common vector now is that they'll go in and compromise credentials of some user within your organization. That's why if you're working in a company, you have all this like anti-phishing training and all these videos and tutorials you need to go through because this is very, very common. This is the most common way. It's very like not sophisticated in some senses, Like they're sending you emails with links to click on. They're calling into your support. It's a very common one that in the, I think the MGM casino breach, they're called into support and they basically pretended to be the employee and they reset their password as well as their multi-factor authentication.

21:50And therefore they were able to compromise the credentials. So that's like, that is a very common attack vector as well. So again, not super sophisticated, but that's how they get in. And then what they do is they look at what system access does that user have. They look for ways to give themselves more access, compromise other identities once they've compromised your identity, and get closer and closer to the crown jewels, to your production systems, to your customer data before taking action. And that action might be, hey, they're going to exfiltrate that data. So, you know, export that data out, threaten to put it on the dark web, encrypt or delete a bunch of data and hold that for ransom and say they are not going to give you the decryption keys or give you all that data back if you don't pay them.

22:40And that's typically what happens during a cyber attack. Now, the challenge is that within this scenario, before you actually go and say, I need to recover, I've been attacked, okay, all these files were deleted, I need to recover. The first question that most organizations are going to ask or leaders are going to ask their teams in this scenario is, what was the impact? What actually happened? And actually answering that question is really challenging. understanding what was the blast radius of the attack? Was any sensitive data impacted? When did this attack first start? Where was the first point of infection?

23:24And before I recover, how do I make sure I don't recover back all these vulnerabilities again and just open myself up again for the attack? So all of these questions you have to answer. And what Rubric really focused on is like we built our software in such a way that we have built in something called the preemptive recovery engine, which actually goes and scans all of this data, scans all the data, understands how that data is changing over time to basically help you answer these questions and answer them extremely quickly so that you can also quickly hit the recover button and bring back your systems up and running as fast as possible.

24:06And that's kind of the secret sauce of what Rubrik has built. And in doing so, we've built a deep understanding of data and of identity. And these are the areas that you need to have a deep understanding of in order to build resilience, security, and AI operations for AI agents. And so that's really what has gave us this opening into this new world of AI is just having this deep, deep understanding of data and identity that practically no other company on the planet has.

24:38Jon Krohn:You're so good at this. That was such a good explanation. My understanding of cybersecurity attacks and how a solution like Rubrik helps is, yeah, I feel like I went from zero to a hundred. That was a masterclass. Thank you. Cal, anything to add? I mean, I know we're going to talk a little bit more about this from the AI side of things, but I can't stress enough that we have an identity crisis in the AI world. And so increasingly we have what we call non-human identities. So this is increasing the number of surface or port points that then malicious actors can exploit. And it's not just now your user, but it's your user and every agent that's acting on their behalf that now has access to keys and tokens and APIs and all the systems that they can then cascade to, X, the actions and permissions that they can take in those systems.

25:35And so this non-human identity explosion in the enterprise is the problem to solve.

Read the full transcript

25:41Jon Krohn:Yeah, and those agents are famously friendly and helpful as much as they can be. Yes, let me reset that 2FA for you. Well, it's also interesting because if you think about, I'm sure a lot of listeners are Cloud Code users. If you think about using Cloud Code today, especially in enterprise context, I have it set up on my laptop. I go and fetch all of my API keys from all of the SaaS apps that I have access to. I try to give it the longest time period before they're going to revoke and circle my tokens because I don't want to have to go set them up again. I'm giving them the exact same permissions that I as a person have and setting up my tokens that way.

26:27And then I'm sticking those tokens on my laptop and they're sitting in a file on my laptop. So when you look at this whole system and how identity is architected in the agentic world, it's obviously still nascent because all of the tool sets are changing quite a bit. But the security protocols and the way that you should actually be architecting identity, authorization, and all of the other pieces are very, very rudimentary. And a lot of the things that we're all doing today are not things that you would allow when you're building enterprise applications. And so but there's this trade off between like, are you going to cut off people's productivity by saying, hey, they can't do these things?

27:09Or are you going to allow it and have the right monitoring and visibility in place in order to manage it? And of course, organizations want to do the latter. But the tooling hasn't been there in order for them to be able to do that.

27:24Jon Krohn:Really nicely said. There's a term that we haven't said yet that I hear a lot in the cybersecurity space, which is a zero trust world. What does that mean to be in a zero trust world? And what is operating in that zero trust world look like? So zero trust, I would say, is just a fancy word to say, assume breach. Assume that every device, every identity, every account has already been breached. What then? How do you architect a system such that basically for your crown jewels of data, for your crown jewels of infrastructure, the very least number of people have the ability to access and change that?

28:06And in an ideal world, that access is somewhat ephemeral so that there's no permanent access to things that are incredibly important. And that's like what zero trust means. It's been a big term used in cybersecurity more broadly as we thought about cyber attacks. And again, I walked through that anatomy of a cyber attack. It's like if someone compromises my credentials, I should have access to almost nothing. Now, the reality of an enterprise is that you can't have employees that have access to nothing. So you're doing this balanced trade-off of saying, okay, I know I have to give them access, but in that world, how am I gonna respond assuming that that credential or that user has already been breached?

28:48Jon Krohn:Nice, crystal clear. As with all of your explanations today, Annika, thank you. Cal, I've got a question for you that is specific to some talks you've been giving a LinkedIn learning course that you have coming out soon. So you've been developing something called the Trust Engineering Framework. you keynoted on it at something in March that sounds to me like, um, I grew up in Canada and somehow the name of this conference, I'd never heard of it before. It sounds like the name of like the, are the indigenous people that live in the North. It sounds like a town that they would have Irmak. Um, so you're speaking at Irmak in March and, uh, you've got a LinkedIn learning course coming up on this framework.

29:27Jon Krohn:You're keynoting at data summit, 2026 in Boston next Next week after, so the same week that this episode is coming out, right after ODS East in Boston, you're still there. And all of this is centered around this trust engineering framework you've been developing. So help us understand what trust engineering is all about. Yeah, so we have terms like AI governance, responsible AI, AI safety, ML ops. How does trust engineering relate to those? And is there a role called trust engineer? I think that there should be a role called trust engineer. But I'll take a step back and I'll say trust engineering is something that I've been playing around with over the last decade of my career.

30:08And for listeners who didn't catch the last episode, I spent 10 years designing machine learning and AI systems and leading teams that do that in heavily regulated environments. Healthcare, financial services, education, energy, places where there's a high cost of making mistakes and you're already building these models on top of sensitive data assets. and there's a whole set of nuances that you have to deal with. And the big aha for me really isn't that surprising, but it's consistent with the zero trust mindset. It's assume your models are going to mess up. You cannot control them to 100%. And so how then do you operate in the enterprise adopting and designing these AI tools and workflows in a way where you can actually manage the risk?

30:55And so trust engineering is a combination of two different fields. It is the combination of understanding human-centered design as it relates to AI systems. How can you manage user expectations and balance workflows between humans and machines according to level of risk or cost of making mistakes? And then you're pairing that human-centered design approach with the ability to configure the appropriate trust infrastructure and trust assurance. And think of that as your governance and human-led architecture of the trust infrastructure you have in place. And trust engineering is a framework of how do you unify all this?

31:35Because you can't just bolt on AI risk management after the fact. It has to start at the front. And I'll give you a very simple example. if anyone's been to San Francisco recently you've probably come across a Waymo and it can feel like a game of chicken when you're trying to go across the crosswalk does it see me is it gonna mow me down is it safe and I'm a runner every time in San Francisco I take a run along the Embarcadero and there's Waymo's galore they have this new feature that I actually really love as you're crossing the street a little cross man appears on that little circular cone on top of the Waymo And it's a clear signal saying, hi, human, I see you.

32:14It's now safe to walk. And I love that because that's such a great example of human-centered design and expectation management around an AI system that could otherwise cause meaningful harm. So trust engineering is unifying that with the trust infrastructure. Happy to nerd out a little bit more about that. But having the building blocks in place that allow you to determine what potential risks exist up front, to monitor the system and detect when it's misbehaving or behaving not according to your expectations. And then three, when a mistake does happen, what's your failback? What's your fall safe?

32:48And so it really is trust engineering is building off of what Anika so eloquently described as the zero trust mindset, but applied to AI systems. What I love about the trust engineering framework is that it's really bringing together people, process and technology, which is the framework that we always think about as business leaders as we're driving change throughout the organization. And it's only in thinking about all of these three holistically together that we can actually truly solve a problem. Because if you only solve for one piece, you're only solving for one leg of the stool. And you're not going to be able to actually build these products and processes in a way that are truly achieving the end means that you're trying to achieve.

33:32Jon Krohn:I mean, I've complimented you a bunch of times, Anika, on your speaking ability, but I think Cal did a pretty good job there, too. I think I've been too hard on him by joking that he's only been so busy for three weeks because I forget that the whole time running Pandita and then it further, he's doing AI consulting in industries like healthcare, like finance, where security is paramount. That's why we brought him onto the team. Well, I mean, you know, we were nerding a little bit out of a little bit about this before the call, but there's almost like this crossover moment happening where AI risk management is kind of reaching over into cybersecurity and I'm seeing the birth of a new discipline.

34:12And so I'm not a cybersecurity expert yet. I'm working on that, but I can already see where you can't really have one of these now without the other. So we're seeing the birth of a new breed here. It's so true. Even when we're going and having conversations around AI and security and operations of AI with large enterprises, it's really interesting to see that the people we're talking to, sometimes it's the CIO and their organization. Sometimes it's the CTO. Sometimes it's the CISO. Sometimes it's all three of them. Sometimes it's some chief data officer or chief AI officer. And the reality is, is that the lines are blurring because the problem space crosses all of these different disciplines.

34:56And it's not like you can just solve again for one discipline or the other. You have to think about it holistically because any sort of risk management you put in place could also potentially come at the expense of productivity. So how do you manage both of those together in tandem? them.

35:11Jon Krohn:Well, yeah, this does have me thinking I should be more concerned about security than I have been before this episode. There's probably a lot of listeners out there thinking about, you know, because you kind of, you know, I've gotten this far without any major issues personally or professionally. And so you kind of think, ah, it's going to be fine. But then when I'm using cloud code and I don't even know, you know, I'm not even really a software developer and I'm using cloud code to create production code, I should definitely be really on the ball with cybersecurity concerns. I mean, that's exactly why we're doing this.

35:46It's kind of like we're not trying to be like the naysayers, but this is like ringing the alarm bells. We really need to start thinking about AI adoption differently. And resilience has to be a part of the conversation. And it has to be a part of the conversation up front. If you look at another revolution that happen in technology is the cloud revolution, public cloud, people moving to the public cloud. And a lot of, you know, when we've talked to organizations about cyber resilience, they've thought about bolting on cyber resilience after they've already made the move instead of up front. And that means that that level of effort to do so is so much higher.

36:21With AI, we can't afford to bolt it on after the fact. We have to do it up front. Otherwise, things are going to happen that are very bad. And that is that's super important for people to recognize.

36:33Jon Krohn:Right. Yeah. You've been speaking a lot in the past few minutes, both of you, about this intersection between AI and cybersecurity. I also, in my last question to Cal, I asked him, you know, I built on some things that he'd been doing at conferences. And so you, Annika, in the same way that Cal has come from AI risk into cybersecurity, you come from this long cybersecurity background, increasingly into AI, to wit, at RSAC, which is the biggest security conference. It was held in March, I think in the Bay Area. And at that conference, at RSAC, you announced something called SAGE, the Semantic AI Governance Engine, which built on a custom small language model, or SLM for short.

37:18Jon Krohn:We don't need any sharding on this podcast.

37:23And I don't think that's a word we even have to bleep out.

37:28Jon Krohn:It's just a fun one. But yes, a small language model at SLM called Sage, Semantic AI Governance Engine. And so you published a head-to-head between GPT 5.2, where your SLM processed messages five times faster, which shouldn't be surprising given that it's such a small model relative to GPT 5.2, but it was also higher accuracy on policy violation detection. So tell us more about this. Why did you go with a custom trained SLM rather than maybe fine tuning or distilling a frontier model? Yeah. So let's take a step back and talk about how we're approaching AI governance. When we think about the challenges that organizations are having with as they deploy AI and as they deploy, try to deploy AI safely, there are really three pillars of what we're trying to solve for.

38:21The first one is lack of visibility. I shared this stat before, like over 80 % of organizations feel like they lack visibility into what agents are running in their environment, what are those agents doing, what actions are they taking, et cetera. So that's the first pillar is you have to have that visibility. The second pillar is governance and control. So agents are going to be taking actions all the time. You need to be able to block the actions that you don't want it to take. You need to be able to monitor for high risk actions. Now, the challenge with agents is different than other traditional enterprise systems is that agents and models are inherently non-deterministic.

39:01You don't know what they're going to do. And therefore, you can't use a simple rule engine to actually monitor these agents. You have to use AI agents to govern the agents. And so that's where Sage comes in. And what we did is we fine-tuned an SLM because when we're talking about this policy enforcement layer, looking at all of the activity and all of the calls that are happening to the model and the responses back and being able to block it, there are three factors that we have to solve for. The first one is performance. Obviously, accuracy is super, super important. If we're not able to do this accurately, we can't build that trust with our customers that we're actually solving their problems for them.

39:47The second is cost. When we're talking about running this, there is a real cost associated with it. By running a fine-tuned SLM, we can manage the cost. And the third is latency, and that the response time has to be super fast. if we're going to block an action, we can't wait five seconds in order to decide whether to do that, especially when an agent may be chaining together so many multiple actions. And that would increase the response time, which would be untenable for the user. So when we take cost, performance, and latency together, we recognize the best way to solve this problem was by fine-tuning a small language model.

40:27And about a year ago, we acquired a company called Predibase that specialized in this area. At the time, we actually didn't know that it was going to evolve into this area or into what it is today as part of Rubric Agent Cloud and Sage. But we acquired them knowing that, hey, we have a lot of contacts into data and into identity, but we don't understand the models well enough. We don't understand fine tuning. And we recognize that bringing all these three together could be a magic combination. So now that's providing the foundation for SAGE, which is our governance pillar. And then the last piece is remediation, which is what happens when your policy doesn't catch everything?

41:09What happens when an agent inevitably makes a mistake? How do you actually rewind those actions? And that's agent rewind, where we're able to actually undo the malicious agent actions and restore your systems back to normal.

41:23Jon Krohn:Wow. There was a term in there that you kind of glossed over that sounded really exciting to me and I need to hear more about, which is I think you described it as the rubric agent cloud. Mm hmm. What is that? So Rubric Agent Cloud is the platform that we are selling for AI operations and security. So it has these three pillars of being able to give you complete visibility into your agents, whether those agents are Microsoft Copilot agents, AWS Bedrock agents, Cloud Code agents, whatever agents you have, it's giving you that holistic visibility. is giving you the governance and control with Sage where you can define a policy in natural language saying like, hey, I don't want my agents giving financial advice or I don't want them sending emails out to my customers.

42:11However, you wanna express those policies and then Sage will help do the enforcement of those policies at runtime. And then there's the agent rewind piece which allows you to rewind any agent actions that were unintentional in your system to get your system back up and running. So that whole platform is what we call Rubric Agent Cloud. It's been really fun learning about this. And just to kind of like why I'm so excited about it. This is like, you know, new halo effect. But it's like the e-discovery of information assets but applied to AI agents. And so it's not just like, hey, manually add everything in here.

42:46But it's like, hey, discover every single agent that your users and human identities have spun off acting on their behalf. and then across all of them, it proactively checks permissions and policy violations that could exist. And so you kind of get a posture up front and nothing pops eyeballs more than showing a dashboard of like, hey, did you actually know that you have like X hundred number of agents and oh, by the way, these 50 of them have read write access to these four databases. Are you cool with that? Do you want that to happen?

43:17Jon Krohn:Yeah. Another great example and another great reason why I can see why you're so excited to be at Rubrical. There was rewinding a moment back to what Annika was talking about. I'm going to get into something called Agent Rewind. But before we get into Agent Rewind, there's something that I want to highlight really quickly, which is that, Annika, when you were reeling off kind of mainstream agents that people might be using, I think it's so interesting and telling that you listed a Microsoft one, You listed AWS, Anthropic. Opening AI didn't even come up, which is just two years ago. Who would have thought?

43:54Jon Krohn:And obviously, they are still big players in this space. But you can reel off three of the top agentic platforms or tools that people might be using and not mention them without somebody batting an eyelid. Yeah. Interesting. I think it just goes to show how fast the landscape is changing. And a year from now, who knows who we'll be talking about, right? It's always easy to say, extrapolate, oh, the people that are winning today are the ones that are going to win a year from now. I think with AI, that's less certain than ever before in the history of technology, which is both exciting and incredibly scary at the same time.

44:34Well, it's been interesting to watch and see who is winning the race on enterprise adoption. And so these companies are also clearly aligning themselves around whether this is for workplace tools or it's more consumer focused. And so I think in the next couple of years to come, we'll start to see even more of that differentiation and specialization. And I'd be willing to bet just based off of some of the product news these companies are making, we'll see ones that start to align around very specific industries.

45:01Jon Krohn:It makes so much sense. Yeah, right now the big players that we think of are diversified across all kinds of enterprises. is, but it's such a fast-growing space that it can't stay like that forever. So yeah, now rewinding to Agent Rewind, much like the rubric Agent Cloud that really caught my attention. This Agent Rewind functionality sounds really interesting to me, and it's one of the more conceptually interesting things. I think you're shipping, you know, of all the interesting things you're doing, that idea of being able to undo what AI agents have done, it sounds, you know, almost counter intuitive that this is possible because agents do things that touch the world.

45:42Jon Krohn:They send emails, execute API calls against third-party software platforms. They write to databases that you don't own. They could even place trades in some cases. So what kinds of things can, like, are there things that can't be rewound, rewinded? I'm not exactly sure what the past one is. Yes. It's a great question. So when we think about Agent Rewind, it really harkens back to our legacy and our strength in cyber recovery and being able to recover different kinds of systems. So where does Agent Rewind work great and where can we rewind actions? Okay, you dropped a production database table.

46:20We can bring back that production database table. You changed something in Salesforce that broke the relationship between your opportunities and accounts in Salesforce. far as, okay, we can fix that for you. You made some change to your identity systems that gave people a bunch of access that they shouldn't have. We can fix that. So those are the kinds of actions that we're able to rewind. Now, if you've sent an email to a customer and it's already arrived at the customer, there's not really too much that we can do. We can do about those kinds of situations and those will require, and that's where we think the layer of defense with Sage is really the right approach of saying, hey, define upfront some of those high risk activities.

47:05Like I don't want it to be making, I don't want agents to be making trades for me. I don't want it to be sending emails to my customers. Define those things, those kinds of behaviors upfront because the best way to prevent those is to actually be at runtime, looking at what is actually, the agent's actually doing it and stopping there. But now if you talk about, hey, a agent is making a change to a system, which is actually really hard to put at runtime because a lot of changes are legitimate and only some changes are illegitimate. And you need a lot more context to understand what was legitimate and not legitimate.

47:41And that's hard to do at runtime. So that's where Agent Rewind is going to be important. And when I think about like Rubric agent cloud and overall like enterprise strategies overall, we need to think about the multiple layers of defense. And it is four or five layers of defense that are really going to protect your organization. You can kind of think of it as like, you're going to layer like different Swiss cheese layers together. And hopefully, the combination of all of your Swiss cheese slices means that you actually have a block that isn't, there aren't any holes in. That's the approach that one has to take in this AI world.

48:22Jon Krohn:I love that. We're going to have to turn that into an animated short. Look out for that on YouTube because that is such a fun analogy with the Swiss cheese. I love it. Fantastic. Yeah. So I think I understand Agent Rewind. It makes perfect sense to me. I'd like some kind of guarantee that if an agent sends an email that it wasn't supposed to send and my client has read it, that Rubric will personally guarantee that Will Smith and Tommy Lee Jones will show up at their home and erase their memory. I'll put that on the roadmap. Yeah, exactly. Perfect. Perfect. I haven't seen Tommy Lee Jones in much lately.

48:59Jon Krohn:He's probably looking for something to do. But all joking aside, it seems like this Agent Rewind ends up being able to be effective in far more use cases than we might imagine because of the way that rubric has its preemptive recovery engine. Is that right? Yes. We're able to, I mean, the basic thing is that you have to be able to trace what are the activities that the, that happened, what were the changes that actually happened to the data. So the same preemptive recovery engine that we're using to trace what happens during a cyber attack, we're using as well with agent Rewind. Fantastic. All right.

49:37Jon Krohn:So now getting into my final technical question for both of you, for all of our data scientists and ML engineers and software developers listening, many of whom will be asked in the future to either evaluate AI-assisted security tooling or harden their own AI systems. Someone's going to knock on their door or slack them and say, you know, it's great that you're using cloud code or these other kinds of tools to generate so much code, but what are we doing about security? So how do our listeners evaluate AI models today when we know that benchmarks have so many inherent issues? This is such a great question.

50:19There's a paper that came out earlier this year that was looking at whether or not, and it's a very interesting design, whether or not you could actually train a large language model to pass a benchmark test while still failing every single real world test case. And so they actually effectively proved that you can train a model in such a way that it's so good at gamifying the exam that actually hides how terrible it really is. And so that signaled to me from the market is we've reached the point where benchmarks, while useful, are not sufficient and they're only one frame of reference. And so there's some great websites you can dig into, model evaluation, like artificial analysis that look at this by combining multiple different benchmarks, but they're very hard to read or hard to trust given some of these limitations with benchmarks.

51:14What I find missing is there's actually not a lot of benchmarks out there that focus on the cyber resilience or safety scoring of these models as applied to test cases. And I can track down the name of this one resource, but there's this one benchmark hub that I've liked, and it's Trust Hub or Trust LM Hub. And what they do is they actually run jailbreaking attempts on each of the models. And so in addition to saying, you know, this is how it's doing on MMLU, for example, it'll show you this has a 99 % success rate at blocking jailbreaking attempts. And so my call to action here is we really need to think about more standards of how we evaluate the safety of these models when operating with enterprise environments measured against actions like over-permissioning, exhaustively searching for information and data assets that are out of scope, And so we need new tools and resources out there to think about models in this context.

52:19And so I have less of a solution here and more of a call to action.

52:22Jon Krohn:Oh, makes sense. And yeah, some great ideas there around looking beyond benchmarks, including in the security space, when we're thinking about what kinds of AI models we should be using. The jailbreaking point that you made there, we could do a whole episode on for sure. Absolutely. Final question for both of you. I tend to be long-winded with my questions, but this one is going to be quite terse, which is simply, what questions should we be asking in a zero-trust world? I don't know. Whoever wants to go first. Yeah, sure. I mean, I think one is like, how do I get visibility into my AI agents and what are they doing within my organization?

53:04How do I have the right governance in place to be able to control what these agents can't and can't do? And how am I going to respond and recover when AI agents inevitably make mistakes? Listen, I know there's a lot of ML engineers and data scientists and engineers on the call or watching this. I know there's a lot of engineers watching this. I am sure many of you are having this struggle with your AI governance teams where they're saying, hey, I have this risk that I'm concerned about. What happens if this person uses your application in this way and is able to get access to this information or do this thing?

53:46That's like in the nature of security professionals. And I think as an engineer, what you can do is you can go ask the question back, well, what do you need to see to feel more confident that you have the visibility that you need to monitor what is happening in our system? What do you need to do? Like, what are the kinds of policies that you need to enforce in order to, again, feel comfortable that the highest risk areas are being managed appropriately and blocked appropriately. And then what kinds of resilience strategies you need in place to ensure that there's business uptime. And I think by asking those questions back, you can have a better discussion versus being in this mode where you're like, well, OK, I don't know how to answer that question.

54:31You tell me. You have to be able to progress that conversation forward. And that's where I see a lot of organizations getting stuck today is in this deadlock of security has all these risks. Engineers are like, I need to build this thing. And they aren't able to come together and solve. I am so 1 ,000 % aligned. And the only thing that I would even add to that is just further articulating this enablement and literacy as a part of what enterprises need to do. And nobody loves sitting through their annual privacy training. And I actually just finished my annual cyber training in my last month at Further before doing my new annual cyber training when joining the rubric.

55:10So I am especially burnt out by the excessive privacy and data security training when that's what I teach to many people. But we sit through it and it really gives you this sense of obligation. This is what can go wrong when you take these actions. This is why your duty matters. Taking these actions could have an impact on our customers, our reputation, your job. And so we do a great job at that from a data security and information protection perspective at the enterprise level. I don't yet see widespread AI literacy training that brings that same level of awareness and understanding of what your obligation is as a worker who now has access to these tools and truly the impact of your larger blast radius.

55:54And the second thing I would add to that is really acknowledging that we need cross-functional professionals. I was so thrilled to learn at Rubrik that we actually have a dedicated AI attorney. And this is an individual who really started off in that position of like asking a lot of questions like, hey, what's our risk exposure? How are we dealing with this? Then he started attending conferences that really focused on upskilling and meeting other lawyers that are actually dealing with the same issue. And I think the same is going to be true. You're going to have attorneys that need to make that crossover.

56:27You need our listeners here who are primarily data scientists and engineers that need to start getting better versed in risk management language. And I think the evolution of knowledge work in the enterprise that's AI enabled is by default cross-functional.

56:42Jon Krohn:I like how it sounded like you were going to add something really short onto the end there, but we got a really comprehensive answer anyway, but it was valuable. I'm not, I, I don't regret that you went into that detailed response. Um, so this has been a fantastic episode. I really enjoyed having you back on the show, Cal, obviously, and Anika, my goodness, so good. Uh, loved having you on for your first appearance and hopefully not your last. um i don't know cal may have prepared you for this i was actually supposed to prepare you for this before we started recording so i'm gonna i'm gonna pick on cal something that i always ask my guests is for a book recommendation and so cal should have been prepared i'm ready i'm ready so cal you go first and that gives out a little some time in case you needed it i am i i this just got launched and so there's a big plug to reed blackman um but his new book the ethical AI nightmare challenge.

57:41And it is waiting for me at home as soon as I get back. But it's this premise of our measures to manage AI risk are outdated. And it's like we had house cats with old models of AI and we have house cat manuals. And now we have tigers in our house and we're trying to use this house cat manual and update it. And that's just not working. So it's a totally different way about thinking about managing the emergent risk of AI systems.

58:05Jon Krohn:Great analogy. The second best in this episode after the Swiss cheese. I'm going to give like a sci-fi fantasy recommendation because that's mostly what I read these days. Love it. I am going to recommend Dungeon Crawler Carl, which is a seven book series. Eighth book is coming out in May. And there's a fun rogue AI in there. So that's the connection back to AI. But highly recommend it. It's very entertaining if you need something that's lighthearted and is it going to cause you stress? That sounds so great. I think my book might cause some stress. And it's nonfiction is the worst part of yours, Gal.

58:43Jon Krohn:It's stressful and nonfiction. So it's like real world stress. You can't escape it when you put it down. Nice. Thank you for that, Annika. I really do need something like that. And it's so hard to find. Nice. All right. And then the very last thing is how should people follow you after the episode? Gal, you can go first. I am very active on LinkedIn. And if you are excited by trust engineering, you will get no shortage of content. But if any of this was interesting, please reach out. I love to chat. Nice. And Annika? Same. You can find me on LinkedIn. I'm there all the time. Feel free to DM me if you have questions or if you want to chat.

59:22And thanks for listening.

59:24Jon Krohn:Fantastic. Yes. Thank you both so much for taking the time out of your very busy schedules while traveling to get this breaking news out at this very important time. Thank you so much. and hopefully we'll have you on again sometime soon. Thank you. Thanks for having us. Wow, I sure loved that episode. I trust you did too. In it, Anika Gupta and Cal Aldubabe covered how Anthropic's mythos model can be pointed at an open source code repo and autonomously surface every vulnerability inside it and how Anthropic themselves estimate mythos class capabilities will reach other labs within six to 18 months with open-weight versions likely to follow.

1:00:00Jon Krohn:We talked about how Rubrik's Agent Cloud delivers three pillars of resilience in this new agentic AI era, visibility into every agent in your environment, governance and runtime control through the SAGE small language model, and remediation through Agent Rewind. We also talked about why the next wave of knowledge work is inherently cross-functional with AI attorneys, security pros, and data scientists all needing shared literacy in AI risk. As always, you can get all those show notes, including the transcript for this episode, the video recording, any materials we mentioned on the show, the URLs for Annika and Cal's social media profiles, as well as my own at superdatascience.com slash 989.

1:00:43Jon Krohn:Thanks, of course, to everyone on the Super Data Science podcast team. Our podcast manager, Sonja Breivich, media editor, Mario Pombo, partnerships manager, Natalie Zajski, researcher, Serge Bassis, writer, Dr. Zahra Karche, and our founder, Kirill Aramanco. Thanks to all of them for producing another stellar episode for us today for enabling that super team to create this free podcast for you. We are deeply grateful to our sponsors. You can support the show by checking out our sponsors links, which are in the show notes. And if you'd ever like to sponsor the show, you can get the details on how by making your way to johnkrone.com slash podcast.

1:01:18Jon Krohn:Otherwise, please help us out by sharing this podcast with folks that would like to listen to it and learn all about cybersecurity and AI. Review the podcast on your favorite podcasting app or on YouTube. Subscribe, obviously, if you're not already a subscriber. But most importantly, I hope you'll just keep on tuning in. I'm so grateful to have you listening, and I hope I can continue to make episodes you love for years and years to come. Until next time, keep on rocking it out there. And I'm looking forward to enjoying another round of the Super Data Science Podcast with you very soon.

From the publisher

Rubrik’s Anneka Gupta and Cal Al-Dhubaib speak to Jon Krohn about cybersecurity measures, the risks AI in business might pose for malicious attacks, and why AI should be kept “boring.” Find out how Rubrik safeguards client data, what zero trust is in the context of cybersecurity, and why cyber-resilience needs to be a top priority for companies looking to adopt AI.

Additional materials: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠www.superdatascience.com/989⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠

Interested in sponsoring a SuperDataScience Podcast episode? Email natalie@superdatascience.com for sponsorship information.

In this episode you will learn:

(02:25) All about Rubrik                                  

(08:51) The announcement of Claude Mythos             

(26:26) Utilizing zero trust                  

(40:36) About the Rubrik agent cloud  

More from Super Data Science: ML & AI Podcast with Jon Krohn

All 130 episodes
989: Security for Mythos-Era Agentic Risks, with Rubrik’s Anneka Gupta and Cal Al-DhubaibSuper Data Science: ML & AI Podcast with Jon Krohn · 1 h 4 min
Listen in VO