**Lance** (0:12)
Welcome to another episode of the Inside the ICE House podcast. Today's guest is Cal Al-Dhubaib. He is the principal technologist at Rubrik. Cal, thanks so much for joining us inside the ICE House. Happy to have you here.
**Cal Al-Dhubaib** (0:23)
Thanks, Lance. Great to be here.
**Lance** (0:25)
So Cal, Rubrik recently launched Rubrik Agent Cloud for Anthropics, Cloud Code and Cloud Cowork. So as AI agents increasingly write and deploy code on their own, what challenge did Rubrik see in the markets that made something like this just so important?
**Cal Al-Dhubaib** (0:41)
So the controls that we've relied on, just even for the last few years, let alone the last few decades of security, were never built for probabilistic software. These AI systems, they behave in really different ways, and that doesn't mean that they're bad, but you can't just control them with static rules.
I'll give you one of the fundamental challenges here. These AI systems are only really useful when you start to give them permissions. So you need to give them read and write access to your data and your systems and your files. But that means then you have to have an ability to then inspect its actions and say, okay, does this read actually make sense for the action it's trying to do, or might this lead to some other intended or intended consequence? And so that was the problem that we set out to solve with Rubrik Agent Cloud. How do we evolve traditional controls to be able to account for the ways in which these systems can be?
**Lance** (1:39)
And I think a major theme of the launch is giving organizations more visibility, more control over these AI agents. As companies deploy more autonomous agents across their business for various different reasons, how can they maintain confidence in what those agents are accessing and what those agents are doing?
**Cal Al-Dhubaib** (1:58)
So I think of this as the hierarchy of needs. And frankly, most organizations have been so focused on their rollout of AI systems and their pursuit of productivity or effectiveness, that this tension is really starting to bubble to the surface this year, last year.
And problem number one, where is AI in the enterprise? There's this great conversation we had with a client about eight, nine months ago, when we were starting to do our customer discovery for Rubrik Agent Cloud. We said, hey, this is the concept, this is the problem we're trying to solve. And he said to us, oh, we've only got, you know, 10 agents in the enterprise, we've got it under control. Six months later, we had a conversation. It turns out there's actually 200 And the number of times that I've had conversations like that recently with CISOs, where there's hundreds or even thousands of these identities and accounts cascading across platforms, tools, data sources, systems of record. So problem number one is, where is AI in the enterprise? Problem number two, what can these tools actually affect in the enterprise? Can they delete data? Can they produce code? Can they access or manipulate data and systems of record? And then problem number three, and this is really when you start to get into one of the harder problems here, is how do you know when these systems are misbehaving, are behaving in an unintended way, when they're taking those actions?
And then lastly, four, how do you remediate? And that can be with a block, an escalation to a human, and you need the trust infrastructure in place with tools like Rubrik Agent Cloud in order to be able to address that hierarchy of needs. But frankly, most organizations are still there, number one, where is AI in my enterprise today?
**Lance** (3:44)
And I think among that hierarchy, right, you brought up, I think it was point number four, right? Like how do you then solve the issue if one of these agents misbehaves or doesn't do what it is intended to do? And I think that brings in then this agent rewind that is obviously a part of Rubrik Agent Cloud.
Why do you think the ability to reverse an AI agent's actions is just becoming increasingly important? Because it's something that makes a lot of sense, right? Like if this AI does something wrong, obviously it makes a ton of sense to just, hey, let's sort of rewind backspace, whatever you want to call it, bring it back to where it was previous. But why is it becoming increasingly important? What have you noticed from what your clients have told you? And just what have you noticed as someone who absorbs and evaluates the technology that's coming?
**Cal Al-Dhubaib** (4:33)
So, it's funny, why are we unleashing the software anyways to begin with, if it has a chance to take these actions and make mistakes? The reality is the cost of the alternative not using these AI tools is actually worse. In many instances where I've worked with clients in healthcare, for example, physicians are overwhelmed, ambulatory nursing is a challenge that can only be addressed with some amount of automation and insight where you're leveraging these AI tools. So, one, why are we doing this? It's because we actually don't have a very good alternative.
20 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID