Jul 23, 2026
AI

Rubrik SAGE AI governance puts a model in charge of agent approvals

Rubrik says SAGE judges agent actions against policy in real time, but it has not disclosed error rates for the AI arbiter.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 4 min read

Rubrik SAGE AI governance is becoming the control layer for a risky enterprise bet: letting AI agents act without a human approving each step. Dev Rishi, Rubrik's GM of AI, said at VB Transform 2026 that the data security company is testing the approach internally, using another AI system to judge agent actions against corporate policy in real time.

The company has not disclosed pricing for Rubrik Agent Cloud in this context, nor did Rishi provide false positive or false negative rates for SAGE. That omission matters because Rubrik is asking security teams to trust a non-deterministic system to police other non-deterministic systems.

Rishi described the pressure behind the shift during a fireside chat in Menlo Park. In a CISO roundtable organized by Anthropic's CISO, he said about 14 attendees indicated they had written AI governance and security policies. When asked how those policies were enforced, he said the room treated the gap as a shared problem.

What is Rubrik SAGE AI governance?

SAGE stands for Semantic AI Governance Engine. According to Rishi, it sits inside Rubrik Agent Cloud and evaluates the meaning and intent of an agent's action against policies written in natural language, rather than relying only on static allow lists or manual approvals.

Rubrik's internal push toward what Rishi called “YOLO mode” removes the approval prompt from agent workflows. A second AI model then decides whether the action should proceed. Rishi said the capability question is no longer whether agents can act autonomously, but whether an enterprise should allow them to do so.

That shift followed friction with early Claude Code and Claude Cowork pilots at Rubrik. Rishi said the company initially required commands to run in ask mode, leaving the employee to approve each action. Developers pushed back in a Slack thread that grew to 120 messages, saying the repeated prompts became something they clicked through rather than reviewed.

Rishi tied that problem to Rubrik Zero Labs research. The April “State of the Agent” report, based on a survey of more than 1,600 IT and security leaders, found that roughly 80% of respondents said monitoring and approving agent actions takes more time than agents save.

Why Rubrik says manual approval is breaking

Rishi joined Rubrik after the company agreed in June 2025 to acquire Predibase, the generative AI infrastructure startup he co-founded and led as CEO. He said that in about his first three and a half months at Rubrik, he held 200 customer conversations with IT and security leaders. Across those discussions, he said security and risk approval came up as a bigger constraint on AI return than cost, latency, performance, or orchestration.

VentureBeat Pulse research presented at the same event put numbers behind that concern. According to that research, 66% of enterprises already allow or are building toward production deployment with no human review, while only 5% fully trust automated evaluations.

Rishi said SAGE uses smaller language models rather than frontier models, which he said keeps cost and latency about an order of magnitude lower. He described SAGE as a collection of task-specific judges, including one that watches for tool-use hallucinations and another that suppresses personally identifiable information before it leaves an environment.

The security risk Rubrik is targeting is not only a bad permission in isolation. Rishi pointed to the “lethal trifecta,” a term coined by security researcher Simon Willison for agents that combine private data access, untrusted input, and an external communication channel. Rishi said an agent with Salesforce and email access may need both to do useful work, but that combination can also enable data leakage.

Rubrik Agent Cloud became generally available in February, though Rishi said not every capability he described is fully shipped. Backtesting, which replays past agent actions against new policies, is beginning to roll out. Rubrik also runs batch analysis across full session traces to find problems that no single action would reveal.

The unresolved issue is measurement. Rishi pointed to audit trails, backtesting, and human-reviewable records as checks on SAGE's decisions, but he did not cite benchmark results showing how often the judge is right. For CISOs, that leaves AI-in-the-loop enforcement as a promising control with an unquantified failure rate.

This story draws on original reporting from VentureBeat.

More from AI

All AI →