Skip to content

Product1 publisher2 min readPublished

NetApp wants its storage to flag AI agents that read more data than their task needs

NetApp has added a behavior-based policy engine to its AI Data Engine that flags unusual data use by AI agents, with six months free. For storage admins running agents, its value depends on what happens once a flag fires.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying NetApp wants its storage to flag AI agents that read more data than their task needs
Generated illustration

What happened

  • Russell Fishman, a NetApp senior director, said the company is moving storage access controls from yes-or-no permissions to policies based on behavior.
  • AI Data Engine, NetApp's software for preparing and governing enterprise data for AI, can be deployed against any existing NetApp system, Fishman said.
  • A new integration sends NetApp's ransomware signals into Commvault recovery workflows, alongside existing links to Microsoft Sentinel and Cisco Splunk.
  • Fishman made his case on theCUBE, a paid media partner of NetApp INSIGHT 2026, in an interview with Christophe Bertrand and Rebecca Knight.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision ONTAP admins with agents in production can use the free six months to count flags per agent, and how many needed a person, before committing any budget.
  • exposure Storage admins become the first people to see an agent overreach, so they will need a named owner on the agent's side to call when a flag fires.
  • precedent Teams building agents can expect storage owners to ask for each agent's intended data scope before granting access, since behavior rules need a baseline to compare against.

An agent is sent to look at one customer's account and opens every customer's account instead. Russell Fishman, NetApp's senior director of global AI solutions and field activation, used that case to explain the behavior-based policy engine in NetApp's AI Data Engine [5]. "I would expect you to look at maybe one customer's account, not all of the customers' accounts," he said. "That seems a bit weird to me." [6]

A yes-or-no permission lets every one of those reads through, as long as the agent was granted access to the accounts at all. In Fishman's telling, agents chase the task they were given. Most organizations he talks with worry less about bad actors than about agents causing unintended consequences along the way [1]. "We're starting to get away from thinking about everything through a human lens," he said. "This is an agent. Agents don't think the same way. They're not acting the same way." [4]

Fishman's case is that organizations cannot always keep a human in the loop at the speed agents work, so more of the response has to be automated [2]. The agent policy engine, as he described it, flags unusual patterns of data use [5]. NetApp's ransomware service, by his account, detects and blocks attacks [9]. His advice to customers is stronger than a flag. "I want to lock this down now," he said [13]. The interview does not say whether the agent engine can stop a read or only raises an alert, or what AI Data Engine costs after the free six months [8].

The buyer is the ONTAP admin who already runs NetApp storage and has agents reading from it. In that seat, Fishman said, "that's the first thing I'd be doing." [12]

Whether the engine helps that admin depends first on whether anyone has written down what data the agent's task should touch. Fishman's example works only because someone knew the answer was one account. It also depends on whether a flag changes anything without a person stepping in.

- Scope written, automatic response: the case Fishman describes. The engine has a baseline, and a flag changes what the agent can do. - Scope written, human response: workable while flags arrive more slowly than on-call can clear them. - No written scope, automatic response: the engine decides for itself what unusual means. Expect it to stop some legitimate work along with the overreach. - No written scope, human response: an alert queue with no baseline, read by people at human speed.

What to watch

  • NetApp documentation showing whether the AI Data Engine policy engine can block or throttle an agent's reads on its own.
  • The price NetApp sets for AI Data Engine once the free six-month offer ends.
  • Reports from ONTAP admins in the free period on how many flags the engine raises per agent and how many turned out to be real overreach.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories