The sheer speed of AI driven attacks combined with the sprawl of non-human identities has rendered traditional security controls obsolete. While we must fight AI with AI, concentrating frontier intelligence within a few closed systems introduces its own risks, as these models often lack the transparency needed for critical forensic work.
Cybersecurity has long benefited from open-source software and the shared exchange of threat intelligence. That is why we are proud to join the Open Secure AI Alliance, alongside NVIDIA and leaders across cloud computing, cybersecurity, enterprise software, open source foundations, and AI research.
Why now? Because frontier AI threats require fundamentally new mental models.
As a participant in Project Glasswing, Rubrik has been at the forefront of investigating zero-day threats and novel AI exploitation techniques. In recent research by Rubrik Zero Labs, we uncovered the first publicly documented Remote Prompt Execution attack that leverages permitted tools and actions within Microsoft Copilot to run compromised code.
The very assumptions underlying enterprise controls are being challenged by the capabilities of frontier AI models:
Frontier AI attacks chain together individually benign actions into sophisticated exploits. Our research into prompt injection is one such example. Every action was permissible, but the sequence produced a destructive outcome.
Enterprise security was designed around human-scale access. The gaps that existed were tolerable because human actors are bounded by role, speed, and the scale of what they can execute. Agents are not.
Access to frontier models is lowering the cost of sophisticated attacks, while the proliferation of agentic systems in the enterprise is an attractive new target for threat actors to manipulate.
We need new security tools capable of observing and remediating complex sequences of actions in context, and of routing the decisions that matter to a human without burying them in noise.
Open models power Rubrik Agent Cloud
Open models are a fundamental part of our own approach to securing AI systems. At the heart of Rubrik Agent Cloud is SAGE, a small language model fine-tuned from open weights to detect when an agent’s actions contradict predefined policies. SAGE detects these violations more accurately than GPT-5.2 at roughly 5x the speed, which is what makes it viable to observe agent interactions and trigger remediation in real time.
Agentic cyber resilience is the future
As attackers gain access to increasingly capable AI, defenders need the freedom to deploy and adapt systems on their own terms. Their ability to investigate, contain, and recover from attacks cannot depend solely on the guardrails of closed frontier models.
The Open Secure AI Alliance is a natural extension of our partnership with NVIDIA and Rubrik’s work across AI security and cyber resilience.
Through the alliance, we are committed to advancing our collective understanding of the observability, identity controls, and recovery capabilities defenders need to stay resilient in the wake of agentic threats.
Read More