Meet the Authors

Key Takeaways What you need to know
  1. Rubrik AI coordinates approved recovery workflows across data, identity, and AI infrastructure while keeping autonomous actions auditable, attributable, and reversible.

  2. Rubrik Annapurna indexes unstructured data in place and stages only the files requested by AI pipelines while preserving lineage and access-control context.

  3. Rubrik Agent Cloud governs Claude Code and Cowork with intent-based policies, Agent Rewind, and off-repository snapshots for code and configuration recovery.

Rubrik has released three products that push its cyber-resilience platform past traditional backup and into the operational layer where AI agents now read data, write code, and change configurations. The launches — Rubrik AI, Annapurna, and Rubrik Agent Cloud for Claude — split enterprise AI resilience into recovery, data readiness, and agent governance.

Rubrik AI: An Agent That Runs the Recovery Playbook

Rubrik AI operates across Rubrik Security Cloud and Rubrik Agent Cloud, coordinating multi-step recovery workflows that the vendor says previously took teams weeks and now execute in minutes once an operator approves each action.

The product handles backup troubleshooting, compliance reporting, and a ransomware pattern Rubrik calls the “Minimum Viable Company,” which sequences the restore of executive users first and completes a petabyte-scale recovery in the background.

Explore related questions

Every autonomous action is described as “auditable, attributable, and reversible,” with human approval gating execution. Rubrik positions the product as “the first agentic AI system built for cyber recovery,” and CEO Bipul Sinha frames it as protection against “both external AI attacks and internal agent deployments.”

Annapurna: Making Unstructured Data Usable for AI

Annapurna targets the data-readiness gap in enterprise AI. Rubrik cites its own framing that “90% of enterprise data is unstructured. Less than 1% reaches AI,” and attributes the bottleneck to the cost of duplicating full data estates through ETL.

Annapurna scans files in place across NFS, SMB, AWS S3, and Azure Blob, then publishes a queryable catalog into Databricks Unity Catalog; when a pipeline requests a subset, only those files stage into the AI workflow. The catalog carries content hashes, ACL records, and signed audit trails, giving downstream models a verifiable lineage from source file to training set.

Corey West, CTO at Piper Sandler & Co., said the product “maps, governs, and indexes our estate for AI without adding another ETL stack or compromising our compliance posture.” Annapurna captures source access controls but leaves enforcement to the Data Intelligence Platform.

Rubrik Agent Cloud: Governing Claude in Production

Rubrik Agent Cloud (RAC) applies resilience mechanics to Anthropic’s Claude Code and Cowork. The Semantic AI Governance Engine, or SAGE, enforces intent-driven policies across deployed agents; Rubrik calls it “the industry’s first AI Governance engine.”

Agent Rewind reverses unintended agent actions, and continuous off-repo snapshots of GitHub and Azure DevOps repositories allow one-click restoration after destructive commits, credential compromise, or ransomware.

RAC also version-tracks system prompts, MCP tool configurations, skills, and CLAUDE.md files, and monitors for drift and prompt injection. Rubrik has joined Anthropic’s Project Glasswing with access to Claude Mythos Preview.

For enterprise practitioners, the portfolio reframes cyber resilience around a broader attack surface: the datasets AI consumes and the agents that act on them.

What This Means for SAPinsiders

  • Recovery design starts before an incident. Rubrik’s portfolio shows how resilience can be embedded in AI workflows. Approval gates, preserved configurations, and reversible actions become design requirements rather than emergency controls.
  • Data lineage becomes a model-risk control. Annapurna’s selective staging model links data economics with governance. When permissions and custody travel with each dataset, teams gain a clearer basis for tracing faulty outputs and assigning accountability.
  • Agent autonomy requires an independent rollback layer. Version control alone cannot capture every prompt, permission, tool, and configuration shaping agent behavior. Enterprises need recovery records outside the systems that agents can modify or corrupt.

 

Events

29Oct
SAPinsider Summit New Orleans 2026New Orleans, Louisiana, United States
View All