According to a presentation by Rubrik, enterprise cybersecurity faces a fundamental speed problem: frontier AI models can enable autonomous attacks that progress from initial access to full system compromise in as little as 27 seconds. That timeframe outpaces any human-operated security workflow for detection, escalation, and response.
As a consequence, security operations can no longer assume there will be time for humans to intervene between breach and damage. Rubrik argues that the security posture required in the AI era should center on cyber resilience: continuously identifying clean recovery states, mapping critical data and identity dependencies, and automating restoration so organizations recover in hours rather than days.
"Everything that relied on process or human-in-the-loop intervention is no longer going to be able to execute at the speed of the attacks," says Dev Rishi, GM of AI at Rubrik. "If the attacks are happening in 27 seconds, it means I need my recovery to happen just as quickly."
Why traditional detection and prevention are struggling
Decades of enterprise security have relied on rules-based logic—static access controls, signature-based detection, and deterministic behavioral policies—designed for deterministic software. AI agents behave differently: they are non-deterministic, able to pursue the same objective via multiple paths, and increasingly capable of bypassing static guardrails by finding alternative routes.
Conventional security checks identity, permissions, and whether an individual access is allowed, but it cannot determine if a sequence of permitted actions across multiple applications constitutes a data leak, destructive operation, or attack. "You need a system that can understand context," Rishi says. "You need to use AI to look at what an agent is doing and say, ‘it looks like what you're doing might be a risk of leaking sensitive data externally.’"
Internal versus external threats: the distinction is blurring
Historically, enterprise security drew a meaningful line between external and internal threats: internal threat speed and scope were limited by human capability. AI agents undermine that distinction. They can access multiple systems at once and operate at speeds no human employee can match. Errors such as hallucinations, misread instructions, or unintended data transfers can produce damage indistinguishable operationally from a malicious insider. If an external attacker compromises an internal agent, they inherit its full access across connected applications.
Rishi argues organizations need runtime guardrails that enforce policies consistently across agents. The practical solution is an AI-native guardian layer that monitors agent behavior semantically, understands intent across actions, can block or terminate a misbehaving agent at machine speed, and immediately triggers recovery.
Preparing for inevitable compromise
Frontier AI models, including those capable of autonomously discovering and operationalizing zero-day vulnerabilities, change the economics of attacks. Consequently, interest in preparedness for systems like Mythos is growing. Enterprises increasingly assume attacks are inevitable rather than exceptional, and that investment in resilience and rapid recovery must be treated as strategically important as prevention.
This reframes recovery from a reactive, post-incident task into a capability that is deliberately designed, tested, and continuously validated. "The idea that you can recover quickly from an attack is going to become one of the most important facets of security," Rishi says. "It's the insurance policy that organizations now have to treat as a first-class citizen."
Why small models matter for AI-powered cyber resilience
True cyber resilience requires both real-time intelligent enforcement to intercept threats in motion and automated recovery to restore operations immediately. Backups are a baseline, but organizations need workflows that continuously monitor systems at machine speed and instantly identify the most recent clean state under attack conditions.
Applying AI to real-time enforcement poses technical and economic challenges. Relying on large frontier models to monitor every agent action introduces latency overhead and prohibitive compute costs. A guardian AI that slows systems or doubles costs is not viable for broad adoption.
"It has to be a fast, small, and cheap AI model," Rishi says. "No one wants to sign up for a secure solution that doubles their cost or latency." Rubrik's approach—anchored in part by its acquisition of Predibase—is to build the frontline defense on small language models (SLMs) optimized for speed and efficiency. Unlike heavyweight frontier models, SLMs can semantically evaluate agent behavior at machine speed and at a fraction of the cost, serving as a real-time checkpoint.
That hyper-efficient enforcement layer enables a tight, seamless connection to recovery: when the system detects a destructive action (deleting a database, corrupting a critical file, or exfiltrating sensitive data), the small model detects it immediately, halts the damage, identifies the most recent clean snapshot, and initiates recovery in a single automated workflow.
From incident response to architectural resilience
More broadly, Mythos and similar frontier AI systems shift how organizations must approach security. As AI compresses the gap between attack and impact, resilience and recovery become architectural requirements rather than operational afterthoughts.
Rubrik contends that security systems can no longer stop at detection. As AI agents gain autonomy, observability, identity context, and recovery must operate as a coordinated resilience layer. The objective is not just to identify failures but to shorten the interval between detection and restoration.
"The same thing that's introducing the threats, the frontier capabilities of models like Mythos, can also be used to help us combat the threat," Rishi says. "Positioning yourself for the AI era means closing the gap between detecting that something has gone wrong and restoring the systems that were affected, before the cost of that gap compounds."
This article is sponsored content (Presented by Rubrik). Sponsored articles are produced by a company that pays for the post or has a business relationship with VentureBeat. For more information: sales@venturebeat.com.



