An AI now judges every move Rubrik's agents make, its AI chief said at VB Transform 2026 - but no one's measured if the judge is right
Essential brief
Rubrik is experimenting with an AI system called SAGE that autonomously monitors and enforces policy compliance for its AI agents, removing the need for human approval on every action. This approac
Key topics
Key facts
Highlights
Why it matters
As AI agents become more autonomous in enterprise environments, enforcing governance policies without overwhelming human reviewers is a critical challenge. Rubrik's use of an AI system to monitor and judge other AI agents represents a novel approach to scalable policy enforcement. However, without clear accuracy metrics, organizations must carefully evaluate the reliability of such systems before fully trusting them. This development highlights the evolving landscape of AI governance and the need for robust, transp...
At a recent CISO roundtable hosted by Anthropic's chief information security officer, Dev Rishi, Rubrik's GM of AI, highlighted a common issue: while many organizations have documented AI governance and security policies, few have effective enforcement mechanisms. Rubrik is addressing this gap by enabling its AI agents to operate in "YOLO mode," where agents act autonomously without requiring human approval for each action. Instead, a second AI system, called SAGE (Semantic AI Governance Engine), evaluates every agent action in real time against natural language policies.
Rubrik's approach replaces traditional human-in-the-loop approval with AI-in-the-loop oversight. SAGE interprets the intent behind agent actions and enforces policies with organizational context, allowing it to distinguish between permissible and prohibited behaviors more precisely than conventional rule-based systems. This is particularly useful for complex policies, such as restricting edits to specific Salesforce fields, where standard tools struggle due to lack of semantic understanding.
Despite the promise, Rubrik acknowledges that SAGE's accuracy and reliability have not been quantitatively measured. The system provides audit trails and backtesting features that replay historical agent actions against updated policies, enabling human review of decisions. However, no false positive or false negative rates have been reported, leaving the effectiveness of AI-based enforcement an open question.
Security concerns remain significant, especially regarding the "lethal trifecta" scenario where agents with multiple legitimate permissions could inadvertently leak sensitive data. Rubrik's research shows that credential sharing among agents increases the risk of security incidents. The company emphasizes that revoking access is not always feasible, so contextual intent adjudication is critical.
Rubrik Agent Cloud, which incorporates SAGE, became generally available in February 2026. Features like real-time detection, batch analysis of session traces, and policy backtesting are being rolled out to help organizations manage AI agent risks. Industry research indicates that while many enterprises allow autonomous AI agent deployment, only a small fraction fully trust automated evaluations, underscoring the need for improved governance tools.
Rubrik's initiative reflects a broader industry challenge: balancing AI autonomy with security and compliance. As enterprises increasingly deploy AI agents, effective, scalable enforcement mechanisms will be essential. Rubrik's AI-in-the-loop model offers a potential path forward, but its success depends on establishing clear performance metrics and trust in automated judgment systems.
Key topics in this update include ai, judges every move rubrik, and judges every move.