top of page
Search

2026 Tech Ascension Awards Winner Spotlight: Rubrik’s Dev Rishi on Securing the Agentic Enterprise

1 day ago
4 min read

We sat down with Dev Rishi, General Manager of AI at Rubrik, to discuss the company’s recognition as the Best AI / ML Powered Solution in the 2026 Tech Ascension Awards and how Rubrik is helping enterprises securely adopt autonomous AI systems. In this interview, Dev explores why traditional, human-speed defenses are no longer enough, how agent identity and real-time governance can contain risky actions, and why instant recovery must become a core component of enterprise AI security.

Agentic AI is reshaping both offense and defense. How is Rubrik building security for — and with — autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?


Frontier AI models now chain vulnerabilities rapidly, collapsing the time between intrusion and breach and rendering traditional human-speed defenses obsolete. Passive detection and logging can't stop an autonomous agent once it turns destructive. Organizations need agentic cyber resilience.


At Rubrik, we secure and accelerate the world’s AI transformation by making security an enabler of agentic AI adoption rather than a bottleneck. 


That’s why we built Rubrik Agent Cloud (RAC). Powered by our Semantic AI Governance Engine (SAGE), RAC empowers organizations with all four pillars of agentic cyber resilience:

  • Agent Observability: monitor every agent and MCP at runtime.

  • Agent Identity: control access per tool call at speed and scale using fine-tuned AI.

  • Agent Runtime Security: SAGE intent-driven governance to enforce policies, and detect agent errors in real time.

  • Agent Rewind: the industry’s first undo button for AI which allows enterprises to roll back destructive agentic actions and restore clean system states


RAC enforces real-time guardrails across Microsoft, AWS, Google Cloud, OpenAI, Anthropic, and more based on policy intent, not rigid text filters.  


Agentic capabilities are built directly into our own platform through Rubrik AI, which adapts to each organization’s context and security threats and autonomously acts across Rubrik’s product portfolio. Rubrik AI performs the heavy lifting autonomously, keeping humans in the loop strictly for final judgment calls, rather than time-consuming multi-step investigation workflows. 


You recently announced a new product feature, can you give more details about it?


RAC Agent Identity is a new product expansion to solve enterprise AI's biggest identity bottleneck. AI agents are no longer just summarizing text, but taking actions on behalf of employees across SaaS applications, databases, and APIs. But static credentials and traditional access models were never designed for autonomous machine actors, creating an unmonitored shadow workforce in the organization. 


Rubrik Agent Identity stops giving AI models permanent keys to company systems. Instead, a smart security layer double-checks what the AI is trying to do in real time and hands out a temporary, single-use pass right before any risky action takes place. 


Identity has become the new perimeter — and attackers know it. How has your approach to identity security, authentication, or access management evolved, and what are organizations still getting dangerously wrong?


Rubrik Zero Labs research reveals that 86% of IT and security leaders expect AI agents to outpace their security guardrails within the next year, yet only 23% report having full visibility into the agents operating in their environment. The perimeter has shifted from human identities to autonomous machine actors. In today's organizations, non-human agent identities drastically outnumber human users, creating a massive, unmonitored digital workforce capable of executing complex workflows across SaaS apps, databases, and APIs at an unblinking pace. 


If you treat an autonomous agent like a human employee with permanent API keys, you hand an attacker master access. With Rubrik Agent Identity, we are redefining how autonomous actors are authenticated and authorized. 


  • Zero Standing Permissions: Ditches permanent access keys for single-use, temporary passes generated only when a tool is called.

  • Intent-Aware Checkpoints: Analyzes an agent's true motives before high-risk commands are allowed to run.

  • Seamless IAM Integration: Hooks directly into existing setups like Okta and Microsoft Entra ID without rebuilding your identity stack.

  • Instant Rewind: Pairs live access blocking with Agent Rewind, the industry’s first undo button to immediately reverse rogue actions or AI hallucinations.


Security teams are being asked to do more with tighter budgets and leaner headcounts. How does your solution help security leaders justify ROI and actually reduce operational burden rather than add to it?


Real AI ROI isn't about immediate headcount cuts. It’s a force multiplier that accelerates business outcomes without expanding operational teams. Requiring security staff to manually review and approve every routine AI action creates an unsustainable bottleneck that destroys the efficiency AI promises. By leveraging RAC, security leaders can shift from a slow block and review model to an automated inform and audit posture.


Non-engineering teams, such as Legal, can safely build self-service AI agents with the governance model RAC provides. 


Instead of focusing on misleading stats like "amount of code AI generated," RAC’s strategy drives actual business results, delivering new products months faster and fixing customer problems much quicker. It also eliminates hidden AI waste by giving leaders full visibility into tool usage, stopping long chat sessions that quietly run up massive bills, and automatically matching simple tasks to cheaper AI models. 


By pairing built-in safety guardrails with smart spending controls, security leaders can protect corporate budgets and lighten their team's daily workload as AI adoption grows.


What should be sitting at the very top of every security leader's priority list in the second half of 2026?


The top priority for every security leader right now must be a strategic pivot to agentic cyber resilience. Organizations must accept that traditional prevention and detection strategies are no longer sufficient on their own. Rubrik recently announced its founding partnership of CSAI Foundation’s AI Resilience Center of Excellence, a commitment to equip risk leaders with the resilience needed to confidently adopt and govern AI.


Other key priorities include:

  • Shift from Prevention to Instant Recovery: When breaches happen in milliseconds, stopping every attack is impossible. Rebounding instantly is what matters.

  • Embed Security into Daily Ops: Treat cyber risk as a core business muscle, not an isolated IT issue.

  • Intercept Rogue AI in Real Time: Use dynamic controls to check an agent’s motives before it executes a destructive move.

  • Fight AI with AI: Let autonomous defenses handle split-second threats so humans only step in for high-stakes calls.

 
 
bottom of page