Annika Gupta, Chief Product Officer at Rubrik, discusses how the company manages risks associated with autonomous AI agents by developing solutions like Agent Rewind and Rubrik Agent Cloud, which monitor, govern, and enforce policies on AI actions in real-time to prevent harmful outcomes. She emphasizes the importance of leadership-driven AI adoption, policy-based risk management, and fostering experimentation to balance innovation with safety in AI integration.
Annika Gupta, Chief Product Officer at Rubrik, shares insights into how her company has navigated the integration of AI agents within their engineering processes while managing the associated risks. Over the past five years at Rubrik, she has played a significant role in the company’s AI transformation, particularly as AI agents began to autonomously take actions in product development. Unlike traditional chatbots, these agents can perform high-impact tasks, which introduced new risks such as unintended deletion or alteration of critical production assets.
Recognizing these risks, Rubrik leveraged its expertise in cyber resilience to develop a solution called Agent Rewind. Launched just eight weeks after identifying the problem, this product helps organizations monitor AI agents’ activities, identify high-risk actions, and provide reversibility for unintended consequences. This innovation evolved into Rubrik Agent Cloud, a comprehensive platform that offers holistic monitoring, governance, and policy enforcement for AI agents, ensuring that actions like sending unauthorized emails or giving financial advice are blocked in real-time.
A key challenge Rubrik faced was the diverse deployment of AI agents across various platforms, such as Microsoft Copilot and Salesforce’s Agent Force. To effectively monitor and control these agents, Rubrik positioned its solution at the model layer, analyzing all interactions between agents and AI models using a fine-tuned small language model. This approach allows for semantic understanding and enforcement of policies, which is more sophisticated than traditional network-based cybersecurity methods.
Gupta emphasizes that managing AI risk requires starting with a set of policies, even though no policy can anticipate every possible agent action. The conversation around AI adoption is shifting beyond IT and security teams to include multiple stakeholders focused on accelerating AI use while balancing risk. Organizations face the dual challenge of rapidly deploying AI to achieve productivity gains and managing the increased risks that come with autonomous AI actions, making risk management a critical part of AI strategy.
Finally, Gupta advocates for leadership-driven AI adoption, where executives actively use and demonstrate AI capabilities to inspire their teams. She highlights the importance of experimentation and continuous learning, encouraging organizations to “let a thousand flowers bloom” to discover valuable AI applications. This iterative approach helps organizations understand the evolving possibilities of AI and effectively integrate it into their operations while managing risks and maximizing return on investment.