As Black Hat USA 2026 descends on Las Vegas, one theme is impossible to ignore: AI agents have moved from experimental tools to autonomous actors executing real business workflows — and the security models built for human employees simply weren’t designed for them. To unpack how enterprises should be thinking about this shift, VMblog sat down with Dev Rishi, General Manager of AI at Rubrik, whose team has been racing to close the gap between how fast AI agents can act and how slowly traditional security tooling can respond.
In this exclusive Q&A, Rishi discusses Rubrik’s newly launched Agent Identity offering, an extension of Rubrik Agent Cloud that eliminates standing permissions in favor of scoped, short-lived tokens issued per tool call. He also previews fresh threat research from Rubrik Zero Labs detailing a vulnerability chain uncovered in Microsoft 365 Copilot and Azure infrastructure, shares sobering statistics on the visibility gap security leaders face with AI agents operating in their environments, and lays out why he believes the industry must pivot from prevention-first strategies to what he calls “Agentic Cyber Resilience.”
++
VMblog: Agentic AI is reshaping both offense and defense. How is Rubrik building security for — and with — autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?
Dev Rishi: Frontier AI models now chain vulnerabilities at machine speed, collapsing the time between intrusion and breach to zero seconds and rendering traditional human-speed defenses obsolete. Most organizations underestimate this shift by relying on passive detection and logging, which leaves them defenseless the moment an autonomous agent takes a destructive action. Organizations require moving from simple detection to complete agentic resilience.
At Rubrik, we secure and accelerate the world’s AI transformation by making security an enabler of AI adoption rather than a bottleneck.
That’s why we built Rubrik Agent Cloud (RAC). Powered by our Semantic AI Governance Engine (SAGE), RAC enforces real-time guardrails across Microsoft, AWS, Google Cloud, OpenAI, and Anthropic based on policy intent, not rigid text filters. Because static permissions fail the moment an agent is hijacked or misaligned, we also launched Agent Identity to deliver dynamic runtime authorization, checking an agent’s true intent before high-stakes operations execute. When an agent inevitably hallucinates or takes an unintended action, RAC provides Agent Rewind, the industry’s first undo button for AI which allows enterprises to roll back destructive agentic actions and restore clean system states.
Agentic capabilities are built directly into our own platform. Instead of requiring human operators to manually navigate dashboards and perform multi-step investigation workflows during an attack, our platform performs the heavy lifting autonomously. Humans remain in the loop strictly for judgment and high-stakes decisions.
VMblog: Are you unveiling any major product announcements, partnerships, or research findings at Black Hat 2026? Can you tease it or give us a preview?
Rishi: RAC Agent Identity is a new product expansion to solve enterprise AI’s biggest identity bottleneck. Additionally, we unveiled threat research from Rubrik Zero Labs exposing hidden vulnerability chains in cloud AI infrastructure.
- Rubrik Agent Identity: AI agents are no longer just summarizing text. They are taking actions on behalf of employees across SaaS applications, databases, and APIs. But static credentials and traditional access models were never designed for autonomous machine actors, creating an unmonitored shadow workforce in the enterprise. At Black Hat, we are launching Rubrik Agent Identity, an extension of Rubrik Agent Cloud, which eliminates standing permissions entirely. Instead, it uses fine-tuned AI to evaluate policy intent and issue scoped, short-lived tokens per tool call at the MCP gateway before sensitive actions execute. Integrating natively with Okta and Microsoft Entra ID, it allows organizations to scale agentic workflows with confidence.
- Rubrik Zero Labs Research: On the research side, Rubrik Zero Labs is presenting a session on August 6, at 11:05 a.m., on a novel, high-stakes attack vector discovered manually by our threat research team. Our researchers uncovered a complex vulnerability chain in Microsoft 365 Copilot and underlying Azure cloud infrastructure. By simply getting a victim to upload a single malicious Word document, an attacker could silently escape the AI code-execution sandbox. This granted the attacker an interactive “prompt shell” inside the victim’s Copilot session, allowing them to query sensitive emails, files, calendars, and financials on the victim’s behalf.
VMblog: Identity has become the new perimeter — and attackers know it. How has your approach to identity security, authentication, or access management evolved, and what are organizations still getting dangerously wrong?
Rishi: Rubrik Zero Labs research reveals that 86% of IT and security leaders expect AI agents to outpace their security guardrails within the next year, yet only 23% report having full visibility into the agents operating in their environment. The perimeter has shifted from human identities to autonomous machine actors. In today’s organizations, non-human AI agent identities drastically outnumber human users, creating a massive, unmonitored digital workforce capable of executing complex workflows across software-as-a-service (SaaS) apps, databases, and application programming interfaces (APIs) at machine speed.
If you treat an autonomous agent like a human employee with permanent API keys, you hand an attacker master access. With Rubrik Agent Identity, we are redefining how autonomous actors are authenticated and authorized.
- Zero Standing Permissions: Static credentials were never designed for non-deterministic AI. Instead of giving agents persistent broad access, we eliminate standing permissions entirely by minting scoped, short-lived tokens per tool call.
- Intent-Aware Runtime Checkpoints: Before any tool call executes at the gateway layer, SAGE performs behavioral analysis to evaluate the agent’s request, context, and potential operational impact against policy intent.
- Federated Identity Infrastructure: Rather than building a separate identity directory, Agent Identity extends existing enterprise IAM investments like Okta and Microsoft Entra ID using On-Behalf-Of federation.
- Resilience Meets Identity: If an agent is compromised or hallucinates, identity blocking is paired with Rubrik Agent Rewind—allowing security teams to immediately undo destructive agentic actions and restore a clean system state.
VMblog: Security teams are being asked to do more with tighter budgets and leaner headcounts. How does your solution help security leaders justify ROI and actually reduce operational burden rather than add to it?
Rishi: Real AI ROI isn’t about immediate headcount cuts. It’s a force multiplier that accelerates business outcomes without expanding operational teams. Requiring security staff to manually review and approve every routine AI action creates an unsustainable bottleneck that destroys the efficiency AI promises. By leveraging RAC, security leaders can shift from a slow block and review model to an automated inform and audit posture. This governance allows non-engineering teams, like legal, to safely build self-service AI agents.
Instead of focusing on misleading stats like “amount of code AI generated,” this strategy drives actual business results, delivering new products months faster and fixing customer problems much quicker. It also eliminates hidden AI waste by giving leaders full visibility into tool usage, stopping long chat sessions that quietly run up massive bills, and automatically matching simple tasks to cheaper AI models.
By pairing built-in safety guardrails with smart spending controls, security leaders can protect corporate budgets and lighten their team’s daily workload as AI adoption grows.
VMblog: What should be sitting at the very top of every security leader’s priority list in the second half of 2026?
Rishi: The top priority for every security leader right now must be accepting that traditional prevention and detection strategies are no longer sufficient on their own, and pivoting entirely to Agentic Cyber Resilience. This is why Rubrik has just announced its founding partnership of CSAI Foundation’s AI Resilience Center of Excellence, a commitment to equip risk leaders with the resilience needed to confidently adopt and govern AI.
Other key priorities include:
- Transition from Prevention to Continuous Resilience: As frontier AI models chain vulnerabilities and reduce breach times to zero, security leaders must prioritize business continuity and rapid recovery over traditional prevention.
- Treat Cyber Risk as an Operational Management Process: Security must be embedded directly into daily business operations as an ongoing risk management function rather than treated as a separate technical problem.
- Govern Autonomous AI Agents with Dynamic Controls: Organizations need dynamic runtime authorization to verify an agent’s intent and prevent compromised digital workers from executing destructive actions at machine speed.
- Adopt Agentic Security Tools to Match Machine Speed: Security teams must deploy autonomous, agentic platforms to execute response workflows at machine speed, keeping humans in the loop strictly for high-stakes, irreversible decisions.
##






