The TWIML AI Podcast
The TWIML AI Podcast

Why AI Agents Break the GenAI Security Model with Devvret Rishi - #770

In this episode, Sam talks with Dev Rishi, GM of AI at Rubrik, about what happens when agents move beyond answering questions and start taking action across tools, systems, and business processes. We explore why the enterprise playbook of static guardrails plus human approval starts to break down in

Featured Speakers

Dev Rishi Guest

Topics Discussed

Episode Summary

Executive Summary: The episode argues that enterprise AI agents create a new security problem: traditional static guardrails and human-in-the-loop review cannot keep pace with agents’ speed, creativity, and growing tool access. Dev Rishi explains Rubrik’s approach—monitoring, AI-in-the-loop enforcement via SAGE, and recovery/rewind—to secure agents across enterprise workflows without crippling productivity.

Main Topics: Why legacy guardrails fail for agents (Priority: 5/5): Static rules and manual approval break down because agents can improvise, work across systems, and operate faster than humans can review. AI-in-the-loop security and governance (Priority: 5/5): Rubrik argues the right answer is not just human oversight but an AI guardian that inspects prompts, responses, tool calls, and context in real time. Cross-system risk and data exfiltration (Priority: 5/5): Agents can combine permissions across Salesforce, email, cloud tools, and MCP connectors, enabling unintended data leakage or destructive actions. Rubrik Agent Cloud and SAGE (Priority: 5/5): Rubrik’s platform provides observability, runtime enforcement, and recovery/rewind, with SAGE acting as a lightweight semantic governance engine. Recovery, resilience, and rewind (Priority: 4/5): Because prevention will never be perfect, the company emphasizes tying agent observability to backup/recovery so enterprises can undo destructive actions quickly. Protocols, observability, and enterprise adoption (Priority: 4/5): MCP, A2A, and observability tools help structure the problem, but they also expand the attack surface and do not solve policy enforcement by themselves. Future of agent adoption (Priority: 4/5): The discussion predicts agents will move from read-only into write/delete workflows across many knowledge tasks, increasing both productivity and incident rates.

Key Arguments: Agents are fundamentally different from traditional software because they plan, improvise, and find workarounds, making static policies too brittle. Human approval is too slow for agentic systems that can act 10x faster than a person can realistically review. The bigger enterprise risk is not just sending data to an LLM, but giving it access to systems of record like Salesforce and email. Agents behave more like humans than legacy software, so security must account for intent, context, and cross-system behavior, not isolated permissions. AI should be used to secure AI: a specialized guardian model can enforce policies in real time more effectively than deterministic rules alone. SAGE inspects prompts, responses, and tool calls, and can be customized with organizational policies, identity, and data context. A strong security posture needs three layers: visibility, runtime enforcement, and recovery/rewind. Small language models are well-suited for binary allow/deny decisions because the task is constrained, low-latency, and can outperform general-purpose models in this role. Recovery matters because prevention will always have false negatives; enterprises need an undo path when an agent makes a destructive change. MCP and similar protocols improve structure and centralization, but they do not stop an agent from misusing authorized tools or exfiltrating data across boundaries.

Data Points: Years since Rubrik was founded: 11.5–12 years - Describing Rubrik as a startup-turned-public-company with both startup and enterprise DNA. Timing of GA for Rubrik Agent Cloud and SAGE: February this year - The agent security product was launched in general availability a few months before the interview. Speed advantage of agents over humans: 10x faster - Used to argue why human-in-the-loop review cannot scale with agent execution speed. Model comparison: GPT-5.2 - Rishi said Rubrik benchmarked its SLM against GPT-5.2 for allow/deny classification. Performance claim: Order of magnitude faster and cheaper - Rubrik said its SLM was significantly more efficient than the benchmarked large model. Accuracy claim: More accurate - Rubrik said its SLM outperformed the larger model on binary allow/disallow decisions. Token volume processed: Trillions of tokens - SAGE has been operating at scale and processing massive agent traffic. Observed internal agent count: 250 - A large enterprise audit found many more deployed agents than expected, including autonomous background agents. Agent runtime integration time: A few minutes - API-level integration into systems like Copilot Studio or Anthropic compliance APIs was described as quick to set up.

Pivotal Quotes: "it feels like a fast car with no brakes" — Dev Rishi: Describing how enterprise users experience powerful agent tools without sufficient downside protection. "I think we actually need to look... we should use AI and throw AI at the problem. So go from human in the loop systems to AI in the loop systems." — Dev Rishi: Core thesis that AI should police AI rather than relying primarily on manual review. "The terrifying gap that's really the thing slowing down AI adoption of the enterprise today." — Dev Rishi: Referring to the mismatch between agent capability and current security/governance methods.

Implications: Enterprises will likely need layered agent security: real-time AI policy enforcement plus observability and rapid recovery. As agents gain write/delete access, security will shift from review to automated governance and rewind.

🔓 Sign Up for Unlimited Episode Search

About The TWIML AI Podcast

View all episodes from The TWIML AI Podcast