Autonomous AI Agents Demand New Governance Paradigm
As autonomous AI agents move from experimental chatbots to production systems, enterprises must rethink agent governance to secure sensitive data and tools. Rubrik Inc., a cyber resilience company, argues that traditional identity and security controls are insufficient for autonomous actors.
Rubrik's general manager of AI, Dev Rishi, notes that agents lack the judgment to use authorized permissions wisely. An example is an agent pulling data from Salesforce and pasting sensitive fields into an email, each action authorized but toxic in combination.
According to Rishi, a new class of AI agent governance is needed to secure and govern autonomous actors. Rubrik built SAGE, a small language model trained as a cybersecurity professional that vets actions at machine speed.
The company's internal deployment emits trillions of tokens, requiring an intelligence layer to surface risk and runaway spend. In one case, a small fraction of activity drove 40% of the cost, highlighting the importance of observability in AI agent governance.