NetApp Emphasizes AI Data Governance for Cyber Resilience
Enterprises deploying AI agents in production are discovering that cyber resilience now hinges as much on managing how autonomous software interacts with data as it does on defending against external threats. The primary risk often stems not from malicious actors but from AI agents acting unpredictably at high speeds. This shift is prompting storage providers like NetApp Inc. to develop smarter data infrastructure capable of evaluating data usage patterns.
Russell Fishman, senior director of global AI solutions and field activation at NetApp, highlighted the company’s move towards behavior-based access controls, moving beyond traditional yes-or-no permissions. “We’re starting to get away from thinking about everything through a human lens,” Fishman said. “This is an agent. Agents don’t think the same way. They’re not acting the same way.” Fishman discussed these developments during an interview at NetApp INSIGHT, alongside other announcements such as Novus, a new storage architecture for AI factories and neoclouds.
NetApp’s existing protection tools, including its autonomous ransomware protection service, remain critical as threats evolve. The company has integrated these capabilities with Commvault Systems Inc., Microsoft Corp.’s Sentinel, and Cisco Systems Inc.’s Splunk, enabling real-time threat detection and response. However, AI agents introduce a new challenge: organizations are more concerned about unintended consequences from agents executing tasks than they are about external attacks. NetApp’s AI Data Engine now includes a behavior-based policy engine that identifies unusual data usage patterns, helping mitigate these risks.
Fishman emphasized the need for automation to keep pace with AI-driven operations, noting that human oversight is often insufficient. NetApp is offering a free six-month deployment of AI Data Engine on existing systems to enhance cyber resilience. “If I was an ONTAP admin, if I was a NetApp customer, that’s the first thing I’d be doing,” Fishman said. “The risk of not doing so, not just from a lack of innovation, but the risk of misuse of data, the lack of control, it’s too great.”