Tuesday, September 1, 2026
HomeTechWho Gives AI a CIBIL Score? Two 20-Year-Old Indians Are Building the...

Who Gives AI a CIBIL Score? Two 20-Year-Old Indians Are Building the Answer

Still in the second year of their engineering programmes, BITS Pilani student Gautam R. Patil and IIT Madras student Dheeraj S are building through XAGI Labs the control, evidence and rating infrastructure autonomous AI may need before companies and insurers can trust it.

Before a bank lends money, it checks a borrower’s credit history. Before a car reaches families, independent laboratories test what happens when it fails. Artificial intelligence is approaching a similar moment.

AI agents can now browse websites, write code, operate software and update company records. Once a machine can act, a mistake can become a security breach, a faulty payment, a compliance failure or an insurance claim. Yet basic questions remain: What was the AI allowed to do? What did it actually do? Can anyone prove it?

Those questions sit at the centre of XAGI Labs, a frontier-AI research company being built in India by Gautam R. Patil and Dheeraj S, both 20, and associated with SST in Bengaluru. Their thesis is simple: the next major bottleneck in artificial intelligence may not be capability alone, but accountability.

What makes the timeline particularly striking is that the company, its research, its open-source projects and its early technical systems have all taken shape while the founders are still near the beginning of their engineering education.

XAGI frames its answer as a limit, a record and a rating. The limit defines what an agent may do, the record shows what it did, and the rating indicates how far it can be trusted. Its operating layer is MELRA; its independent evidence and rating arm is TRUSCOR.

TRUSCOR is being designed as a crash-test laboratory and credit bureau for AI systems. Its proposed rating examines how easily an AI can be manipulated, what it can reach and what a failure could cost. That evidence could help a company approve a vendor, a bank assess an AI provider or an insurer understand the exposure it is being asked to cover.

What sets TRUSCOR apart is what it refuses to do. It does not intend to build the AI being examined or sell the repair after finding a weakness. A referee who coaches one team and profits from the result is no longer credible. By separating measurement from remediation, XAGI wants TRUSCOR’s conclusions to matter to buyers, auditors, banks and insurers, and not only to the vendor.

That is why the founders speak about making AI insurable. Insurance becomes possible only after risk can be observed and priced. Cars needed crash tests, aviation needed flight recorders and credit markets needed bureaus. Autonomous AI may similarly need an independent record of what systems can do, how they fail and what those failures may cost.

Gautam leads XAGI’s SOVA, evidence and AI-security research. The company has developed the SOVA Engine, an authorised adversarial-testing system that maps an agent’s capabilities, creates relevant attacks, runs them with permission and turns the observed behaviour into structured evidence.

He also authored the paper “.sova: Portable, Evidence-Bounded Reproduction of AI-Agent Security Findings.” It proposes .sova and .sova-trace, formats that carry a security finding with the conditions and evidence needed to inspect it. Think of .sova as a recipe card inside an evidence bag, and .sova-trace as the flight recorder. The idea is that an AI failure should travel with proof, not survive as a screenshot and somebody’s explanation.

XAGI has released SOVA-OSS, an open-source repository through which researchers and developers can test their own agent systems. Its second public repository, MELRA OSS, supports the operating side of the same vision.

MELRA can be understood as Windows or iOS for AI agents inside a company. The model supplies the intelligence; MELRA provides a controlled path to files, browsers, terminals and business software. It can apply permissions, request human approval, verify whether the intended result occurred and preserve a receipt. The model may change while the company keeps its rules, credentials, history and evidence.

Dheeraj leads MELRA, platform engineering and product delivery. The journey began when a repetitive task involving roughly 30 to 40 Figma screens led him to build a browser-automation tool. That experiment expanded into memory, computer use, terminal control and model-tool coordination. XAGI says the broader journey has produced more than 200,000 lines of work.

Gautam, a BITS Pilani computer-science student, received the Government of India’s INSPIRE Award in Class 8. Dheeraj, an IIT Madras student, also began building in school through a privacy-focused messaging application and the venture Coding Desk, which he scaled to almost 100 clients. Both founders are pursuing their second-year studies at BITS Pilani and IIT Madras, respectively. Their work has also been shaped by their association with the Scaler School of Technology ecosystem in Bengaluru. Bhavana Sanal leads client relations, while Mainak Patra supports research and strategy after research experience at the Okinawa Institute of Science and Technology and work on a NASA JPL project.

The technical work has produced measurable results. In published component tests, MELRA reported more than 90 per cent performance on both long-horizon memory and supporting-evidence coverage. It also reported 20 to 40 times faster click grounding, memory ingest at 18 items per second, and correct final-state browser reads in all 30 delayed-render trials. The SOVA mechanism matched the expected outcomes across its frozen semantic, evidence and contract tests. The young team has attempted technical work normally associated with much larger frontier-AI laboratories operating with vastly greater capital, infrastructure and specialised personnel.

XAGI reports backing, support and programme access through Scaler Innovation Lab, Build3, YNOS at IIT Madras Research Park, Razorpay Rize, Google for Startups at T-Hub, AWS Activate and Microsoft for Startups. It has also drawn early advice from investor Amit Singhal of Fluid Ventures. The company says these programmes have helped it secure more than $1 million in cloud, AI and infrastructure benefits.

For India, the larger opportunity is to create standards the world may eventually depend on. Training the largest AI model may require billions of dollars in compute. Making autonomous systems measurable, governable and insurable may instead reward rigorous engineering, public evidence and the willingness to start early.

Gautam and Dheeraj are making a simple but ambitious bet: as AI gains authority, trust itself will become infrastructure. That they have begun building this venture while only in their second year of engineering makes the ambition even more unusual. XAGI Labs wants to build that infrastructure from India.

RELATED ARTICLES

Most Popular