As AI adoption continues to accelerate across APAC, organisations are increasingly looking for ways to manage the security, governance, and operational risks introduced by autonomous AI systems.
Across APAC, organisations are moving from experimentation with agentic AI to real-world implementation. They are asking themselves: how do we stay in control when AI agents can act at machine speed across critical systems?
Rubrik’s latest announcements, including Rubrik AI as the first AI system built for recovery and the launch of Rubrik Agent Cloud for Anthropic’s Claude Code, aim to help organisations securely deploy, govern, and recover AI-powered operations at scale.
We find out more from Ananth Nag, General Manager and Vice President, Asia Pacific, Rubrik.

How do you see organisations across APAC approaching agentic AI adoption?
Ananth: The first wave of agentic AI adoption is typically happening in areas where risk can be more tightly managed, such as customer experience and software development. These are natural starting points because they help organisations scale output, manage operational spikes and reduce manual work.
However, as agents begin to interact with more sensitive enterprise data, applications, identities and workflows, the risk profile changes significantly. The security infrastructure many organisations rely on today was built for a world where technology was deterministic and human-driven actions occurred at human-scale speeds, making them structurally ill-equipped for the machine-speed, autonomous nature of the AI era.
Organisations need real-time guardrails around agent actions. Every action should be auditable, attributable and reversible.
Security and resilience need to be built into AI adoption from day one. Otherwise, the same speed that makes agentic AI powerful can also become the speed at which risk spreads across the organisation.
What may be lacking in these approaches, and what are some key emerging governance and security challenges associated with AI agents?
Ananth: What is often lacking today is an agentic resilience strategy. Prevention and detection remain critical, but they are not enough on their own. In the agentic AI era, it’s not if an attack will happen, but when, making resilience a business imperative when thinking about the inevitable.
Organisations are moving from human-speed risk to machine-speed risk. AI agents can trigger workflows, access systems and make decisions in seconds. If those actions are unintended or unauthorized, the impact can cascade quickly across the business.
Organisations need to adopt an “assume breach” mindset. The question is no longer how to prevent every incident, but how quickly the organisation can understand what happened, contain the impact and restore operations.
Many organisations maintain operational Recovery Time Objectives (RTOs) for standard business continuity, yet these are fundamentally different from Cyber Recovery Time Objectives (Cyber RTOs). While operational RTOs focus on restoring services after hardware failure or site outages, Cyber RTOs must account for the complexities of an active, malicious attack.
A critical gap for many organizations is the failure to clearly define and test Cyber RTOs across key applications, data, identity systems, and business workflows. Relying on standard operational RTOs during a cyber incident is a major risk. An attack is not the time to discover unknown dependencies, attempt to identify clean recovery points, or guess the duration required to restore compromised services to a trusted state.
The key governance and security challenge with AI agents is therefore not just visibility or access control. It is ensuring that agentic actions can be monitored, governed, audited and, when necessary, reversed so the business can recover quickly from disruption.
Why is agentic cyber resilience important for enterprises? How should it be embedded in an enterprise AI strategy?
Ananth: Traditional cyber resilience was designed around human speed. Teams would detect an issue, investigate what happened, remediate the problem and recover the environment. The model becomes much harder to sustain when attacks, misconfigurations or unintended agentic actions can happen in seconds.
Resilience has to be built during peacetime, not when an incident hits. Organisations need to test their recovery plans, understand where their clean recovery points are, define RTOs for critical systems and ensure they can orchestrate recovery across AI-driven workflows.
To embed agentic cyber resilience into enterprise AI strategy, organizations need a plan and platform that can govern every autonomous action. They should understand what agents can access, enforce policies in real time, log actions for auditability and ensure there is a way to trace and reverse unintended or destructive actions.
Agentic AI can only scale safely when organisations are confident that they can govern what agents do and recover quickly if those actions create disruption. For organizations, this will determine whether agentic AI remains a controlled source of productivity or becomes a new source of business risk.
