Digital white blood cell agents Cyber-attacks now occur at machine speed, driven by AI agents, making traditional one-off recovery approaches obsolete, according to Rubrik CEO Bipul Sinha and ADP CEO Simon Chappell. Recent incidents include an OpenAI agent breaching Hugging Face and a Cursor agent running Anthropic's Claude Opus 4.6 deleting a startup's database in 9 seconds. The industry must shift to continuous, micro-level defense modeled on the human body's white blood cells, with digital agents patrolling networks and instantly remediating breaches. Digital white blood cell agents Opinion. Talking to ADP https://www.blocksandfiles.com/data-protection/2026/05/14/adp-dram-shortage-is-affecting-ransomware-recovery/5240481 CEO Simon Chappell about Rubrik’s agent cloud, and cyber-attacks happening at machine speed, not human speed, and the Hugging Face breach by rogue OpenAI agent, a series of realizations came into being. Backups were originally needed to replace single events; a lost file, a broken storage array, and then recovery from ransomware. Recovery is the key and it is thought of as recovery from an event, a single event. But that is becoming the wrong approach. Cyber-resilience depends upon lowering risk by preventing breaches, detecting a breach of some kind after it has happened, and then recovering as fast as possible to the last known good state. Then bring in the cyber-forensics people, work out how the breach happened and close the open doors. This is too slow, given recent AI agent attack events. The OpenAI agent, on its own, broke out of an inadequately-defined sandbox environment and then found a way to get into Hugging Face https://www.theregister.com/ai-and-ml/2026/07/23/openai-scored-an-own-goal-with-huggingface-attack-showing-how-open-chinese-models-are-winning/5276699 . PocketOS, had to recover from its own AI agent, Cursor running Anthropic's flagship Claude Opus 4.6, deleting https://www.theregister.com/software/2026/04/27/cursor-opus-agent-snuffs-out-startups-production-database/5224442 its filed data in 9 seconds. As Rubrik CEO and co-founder Bipul Sinha has said, cyber-breaches now happen at machine speed, not human speed. These events are wake-up calls to enterprises and organizations worldwide, and also to cyber-attack organizations; they should use AI agents to devize and mount attacks, helping out their human hackers. Attacks will come in greater numbers and do their work faster. Chappell suggests that cyber-attack groups will need to mount more ransomware attacks simply to pay for the GPU tokens they use as their agents develop new attacks and breaches. We need to stop thinking about attacks as significant, but comparatively rare, one-off events, and assume they will become constant. Current guard-rail-building and post-attack recovery cyber-defence approaches are too slow and inflexible. Billions of systems in the world don’t work like this though. They assume breaches happen constantly and fix them at a micro-level. Think of the human body’s white blood cells. They constantly patrol the human organism, flowing through blood vessels, looking for viruses, bacteria and mal-formed human cells; invaders from outside and cancerous growths inside. When they find them, they destroy them, and dead or dying human cells are replaced, both internally and on the surface, as a result of external breaches; cuts, bruises, broken bones, etc. For our bodies, breaches take place constantly and often and they self-fix. We live and breathe in a world infested with bacteria and viruses, and often damage our bodies through accidents and mishaps as well. At the cellular level, attacks and accidents are common and continuous, and remedied; fixed. We are in a constant state of self-repair. Our IT systems need to become digital organisms with the same approach. They must assume they operate in a malign world full of antagonistic cyber-attacking and mistake-making human and digital agents. They need the equivalent of white blood agents patrolling the network ports and data assets and recording data access events, by humans and AI agents, aka digital employees. When they detect mistaken or malicious access events, they react instantly, closing off a micro access door, removing unwanted access privileges, and restoring corrupted or destroyed data assets. One-off attack responsiveness has to develop into continuous, micro-level, attack breach detection and recovery. Our IT estate defences have to operate at machine speed in order to deal with machine speed malware attackers. They have to have access to the entire IT estate and not just parts of it; production data and not just backup data. They have to be able to detect events in any part of that data estate, correlate and connect them to detect concerted activity signalling an attack, halt it, alert admin staff, and offer recovery options, or even self-fix. This requires something like Rubrik’s agent cloud https://www.blocksandfiles.com/ai-ml/2026/06/10/rubrik-using-ai-for-a-service-interface-anthropic-claude-safety-net-and-cloud-app-stack-recovery/5253408 , Veeam's idea https://www.blocksandfiles.com/ai-ml/2026/06/05/veeam-says-enterprises-need-ai-agents-to-monitor-ai-agents/5251570 of AI agents monitoring AI agents, a layer of agents with awareness of the state of a data estate and maintaining it against a continuous assault of cyber-attacks and accidents. We need, in effect, digital white blood cell agents patrolling our IT estates to maintain their integrity.