Agentic AI forces a reckoning on governance as autonomous actors enter production

As AI agents move from experimental chatbots into production systems, enterprises must rethink agent governance as autonomous actors gain access to sensitive data, tools and business processes that traditional identity and security controls were never designed to handle.

Enterprise cyber resilience company Rubrik Inc., which this week unveiled Rubrik Agent Identity to govern agent access one tool call at a time, argues that agents demand an entirely new control layer. Unlike a service account or a person, an agent pairs a non-deterministic model with federated identity — and that combination breaks conventional assumptions about how software should be secured, according to Dev Rishi (pictured), general manager of AI at Rubrik.

“If you or I were accessing Salesforce [or] accessing email, we have some judgment on how we would use that, that the models don’t,” Rishi said. “So I feel like you need a new class of guardrails that are a lot more intelligent and semantically aware to be able to actually secure and govern what agents are doing.”

Rishi spoke with theCUBE’s Krista Case at Black Hat USA, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how enterprises can deploy autonomous actors with visibility, control and recovery. (* Disclosure below.)