Who Gives AI a CIBIL Score? Gautam Patil Wants to Build the Answer
Who Gives AI a CIBIL Score? Gautam Patil’s Vision for AI Risk & Trust
At 20, BITS Pilani student Gautam R. Patil is working on a question that sounds futuristic until one considers what AI agents can already do: browse websites, operate software, write code, access company systems and take actions with real-world consequences.
If an autonomous AI causes a financial loss, exposes sensitive data or makes a damaging decision, who measures the risk? Who proves what happened? And how does an insurer decide whether that system is safe enough to cover?
Those questions are at the centre of XAGI Labs, the frontier-AI research company Gautam is building with co-founder Dheeraj S, an IIT Madras student. Both are 20 and still early in their engineering education.
For Gautam, the bigger ambition is TRUSCOR, XAGI Labs’ independent AI-risk evidence and rating business. Think of it as a crash-test laboratory and CIBIL-like bureau for artificial intelligence.
A car manufacturer can say its vehicle is safe, but society still relies on independent crash testing. A borrower can say he is financially responsible, but a bank still checks a credit history. Gautam believes autonomous AI will eventually need an equivalent layer of independent trust.
TRUSCOR is being designed to examine how easily an AI system can be manipulated, what it can reach, and what the consequences of failure could cost. The evidence could help a company decide whether to deploy an AI product, a bank assess an AI vendor, or an insurer understand a new kind of technology risk.
The unusual part is what TRUSCOR intends not to do. It is not being built to discover a weakness and then sell the repair. Gautam sees that separation as essential. A referee who coaches one team and profits from the result is no longer much of a referee. TRUSCOR’s value, in his view, comes from being trusted by the party that did not build the AI.
That leads directly to Gautam’s long-term dream: taking TRUSCOR into the insurance market and helping build the risk-data infrastructure for autonomous AI.
Insurance works only when risk can be measured, compared and priced. Cars developed crash-test data, aviation developed flight recorders and financial markets developed credit bureaus. Gautam believes AI will require its own evidence base: a record of how systems behave, how they fail, what they can reach and what those failures cost.
If that record becomes credible, insurers and brokers could use it to decide what to cover and how to price the exposure. TRUSCOR would then be less like a conventional cybersecurity company and more like infrastructure between AI companies, enterprises and insurers.
The technical foundation for that idea is SOVA. Gautam leads XAGI Labs’ SOVA, evidence and AI-security research, and the team has built the SOVA Engine, an authorised adversarial-testing system for AI agents. In simple terms, it maps what an AI can reach, creates relevant tests, runs them with permission and turns the result into structured evidence.
Gautam also authored the research paper “.sova: Portable, Evidence-Bounded Reproduction of AI-Agent Security Findings.” The paper proposes .sova and .sova-trace, formats intended to carry an AI-agent security finding together with the context and observable evidence needed to inspect it.
Think of .sova as a recipe card inside an evidence bag, while .sova-trace is the flight recorder. Instead of an AI failure surviving only as a screenshot, log or somebody’s explanation, the aim is for the finding to travel with enough evidence for another party to examine it.
Part of this work has been released through SOVA-OSS, XAGI Labs’ open-source AI-agent security project. Its second public repository is MELRA OSS.
MELRA represents the other side of the XAGI thesis and is led primarily by Dheeraj. It can be explained as a Windows- or iOS-like operating layer for AI agents inside a company. The model supplies the intelligence, while MELRA is intended to control how the agent reaches files, browsers, terminals and business software, when human approval is required, and how actions are verified.
Dheeraj began building in school, creating a privacy-focused messaging platform that crossed 50,000 users and later Coding Desk, a software venture that served more than 100 clients. At XAGI Labs, he leads MELRA, platform engineering and product delivery.
The broader XAGI story began with a repetitive browser task involving roughly 30 to 40 Figma screens. What started as an automation experiment expanded into browser use, computer control, terminal access, memory and model-tool coordination. XAGI says the broader work has grown beyond 200,000 lines across its systems and experiments.
Gautam’s interest in building also predates XAGI. In Class 8, he built a text-to-Braille hardware system that received recognition through the Government of India’s INSPIRE Award programme. His later work moved toward AI security, adversarial evaluation, multi-agent systems and agent forensics.
The wider team includes Bhavana Sangal in client relations and Mainak Patra in research and strategy. The founders also maintain an association with the Scaler School of Technology ecosystem in Bengaluru.
XAGI Labs reports support or programme access through Scaler Innovation Lab, Build3, YNOS at IIT Madras Research Park, Razorpay Rize, Google for Startups at T-Hub, AWS Activate and Microsoft for Startups. It has also drawn early advice from investor Amit Singhal of Fluid Ventures, and reports access to more than $1 million in cloud, AI and infrastructure benefit ceilings through startup programmes.
He wants TRUSCOR to become part of the infrastructure through which AI earns trust in the real economy.
His bet is that as artificial intelligence gains authority, trust itself will become a market. Someone will have to measure it, preserve the evidence and help insurers put a price on it.
Gautam wants XAGI Labs to build that layer from India.