TechBeetle | An AI now judges every move Rubrik's agents make, its AI chief said at VB Transform 2026 - but no one's ...
Tech Beetle briefing US AI

An AI now judges every move Rubrik's agents make, its AI chief said at VB Transform 2026 - but no one's measured if the judge is right

Essential brief

Rubrik is experimenting with an AI system called SAGE that autonomously monitors and enforces policy compliance for its AI agents, removing the need for human approval on every action. This approac

Key topics

ai judges every move rubrik judges every move move rubrik agents ai chief said transform measured

Key facts

Rubrik enables AI agents to act autonomously with oversight from a second AI system called SAGE.
SAGE interprets semantic intent behind agent actions to enforce natural language policies in real time.
The system replaces human approval with AI-in-the-loop governance but lacks established accuracy metrics.
Security risks arise from agents holding multiple permissions, necessitating contextual intent adjudication.

Highlights

Rubrik's AI agents operate in "YOLO mode," acting without human approval on each action.
SAGE is a small language model that judges agent actions against policies written in natural language.
About 80% of organizations find human monitoring of AI agents time-consuming and ineffective.
Credential sharing among AI agents correlates with higher security incident rates.
Rubrik Agent Cloud reached general availability in February 2026, with ongoing feature rollouts for enforcement and auditing.

Why it matters

As AI agents become more autonomous in enterprise environments, enforcing governance policies without overwhelming human reviewers is a critical challenge. Rubrik's use of an AI system to monitor and judge other AI agents represents a novel approach to scalable policy enforcement. However, without clear accuracy metrics, organizations must carefully evaluate the reliability of such systems before fully trusting them. This development highlights the evolving landscape of AI governance and the need for robust, transp...

At a recent CISO roundtable hosted by Anthropic's chief information security officer, Dev Rishi, Rubrik's GM of AI, highlighted a common issue: while many organizations have documented AI governance and security policies, few have effective enforcement mechanisms. Rubrik is addressing this gap by enabling its AI agents to operate in "YOLO mode," where agents act autonomously without requiring human approval for each action. Instead, a second AI system, called SAGE (Semantic AI Governance Engine), evaluates every agent action in real time against natural language policies.

Rubrik's approach replaces traditional human-in-the-loop approval with AI-in-the-loop oversight. SAGE interprets the intent behind agent actions and enforces policies with organizational context, allowing it to distinguish between permissible and prohibited behaviors more precisely than conventional rule-based systems. This is particularly useful for complex policies, such as restricting edits to specific Salesforce fields, where standard tools struggle due to lack of semantic understanding.

Despite the promise, Rubrik acknowledges that SAGE's accuracy and reliability have not been quantitatively measured. The system provides audit trails and backtesting features that replay historical agent actions against updated policies, enabling human review of decisions. However, no false positive or false negative rates have been reported, leaving the effectiveness of AI-based enforcement an open question.

Security concerns remain significant, especially regarding the "lethal trifecta" scenario where agents with multiple legitimate permissions could inadvertently leak sensitive data. Rubrik's research shows that credential sharing among agents increases the risk of security incidents. The company emphasizes that revoking access is not always feasible, so contextual intent adjudication is critical.

Rubrik Agent Cloud, which incorporates SAGE, became generally available in February 2026. Features like real-time detection, batch analysis of session traces, and policy backtesting are being rolled out to help organizations manage AI agent risks. Industry research indicates that while many enterprises allow autonomous AI agent deployment, only a small fraction fully trust automated evaluations, underscoring the need for improved governance tools.

Rubrik's initiative reflects a broader industry challenge: balancing AI autonomy with security and compliance. As enterprises increasingly deploy AI agents, effective, scalable enforcement mechanisms will be essential. Rubrik's AI-in-the-loop model offers a potential path forward, but its success depends on establishing clear performance metrics and trust in automated judgment systems.

Key topics in this update include ai, judges every move rubrik, and judges every move.