Safety professionals reside in a time of recent AI realities. Risk discovery, as soon as the principle focus of safety evaluation, is now quick and ample. Breaches that used to evolve over weeks now occur in seconds. Vulnerability chains, lengthy invisible to one of the best safety groups and builders, are immediately surfaced by highly effective new frontier fashions. Throughout a big codebase, the mannequin has the potential to seek out massive volumes of potential safety points.
In June, Rubrik joined Venture Glasswing, which gave our engineers entry to Anthropic’s Mythos Preview. After a month of working with the mannequin that targeted the trade on new challenges, I’m assured that we will discover efficient methods to fulfill the brand new challenges of the AI period – and to enhance cyber resilience.
Particularly, we introduced collectively a multifunctional “tiger group” from engineering and infosec, prioritizing high-fidelity risk discovery and elimination inside our personal techniques, and automating processes wherever potential. The main focus was to construct an efficient harness (the software program layer wrapping the AI mannequin) that manages instrument calls and checkpoints, provides enterprise context, safety context, and belief boundaries.
If assaults now occur at AI velocity, options may even must be produced at that velocity. In observe, which means the work doesn’t finish with discovery. At these volumes, each stage downstream turns into a constraint — and the toughest engineering issues turned out to not be those we began with.
A Excessive-Constancy Method
From Rubrik’s work utilizing Mythos as a part of Venture Glasswing, our first intuition was to deal with new discoveries as a capability drawback: larger queue, extra reviewers. However we realized that including capability was not the repair; we needed to rethink what the pipeline was doing.
What really labored was treating this as an structure drawback. As an alternative of asking “How will we evaluation our findings?” we thought-about “How will we construct a system the place solely the precise findings attain an engineer?”
That shift modified how we thought concerning the harness. Enterprise context, safety context, the precise risk mannequin of an organization the place many purchasers depend on us as a final line of resilient restoration: none of this might reside in a immediate. Prompts drift. Harness structure doesn’t. When context is structural, it applies constantly throughout each scan and each move, with out relying on anybody getting the wording proper every time.
Complete-repository scans got here first, no assumptions, each file. We progressively focused passes, seeded by what early rounds revealed about the place the true patterns have been. The outcome was a big discount from findings to validated, precedence points. Excessive constancy is what makes the downstream remediation viable.
Automation and People within the Loop
What has shocked my group most about constructing a remediation pipeline wasn’t the automation. It was how a lot of the engineering work we’ve performed goes into deciding what to not automate.
The underlying drawback is structural. Human-driven remediation won’t maintain tempo with AI-speed discovery — that’s not a resourcing drawback you may rent your approach out of. The one reply is constructing automation that may match the speed at which potential vulnerabilities are surfaced, however doing it in a approach you may really belief.
The automated path covers a deliberate subset of potential vulnerability lessons — those the place machine remediation is dependable and well-scoped. All the things exterior that set will get structured plans and richer context, however human judgment owns the repair. In safety, reliable automation and most automation pull in numerous instructions. We selected the previous.
In constructing a harness for Mythos Preview, it turned clear that AI raises the demand for engineering rigor within the techniques surrounding it, not lowers it. The taxonomy, the verification structure, the selections about the place people keep within the loop: these weren’t incidental to the work. They have been the work.
The Vigilance of Many
This work was solely potential due to the trouble of many individuals. Different firms in Venture Glasswing have been beneficiant in sharing their early classes. Anthropic itself has been an ideal accomplice, eager to be taught and adapt. My group at Rubrik, arrange forward of time to be comparatively small and targeted, prioritizes nicely, and is executing brilliantly.
Earlier this 12 months the discharge of Mythos was a wakeup name to the trade. We have now began to reply it. In the long run I consider we are going to create higher software program and higher safety procedures on account of this effort—that’s the reward of persistent vigilance.

