NetApp
/
What’s in Private AI Certified — Expert
/
AI Risks That Differ from IT Risks
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
Deep Dive · AI Governance

AI Risks That Differ
from IT Risks

Understanding the six MADCAF governance risks and how the AIPod Mini with Iterate.ai addresses them.

A joint educational white paper by NetApp® and Iterate.ai.

What you’ll learn
  • Why AI failures differ fundamentally from IT failures
  • The six MADCAF risks — model drift, agent errors, data poisoning, compliance gaps, accountability loss, and fakes — and why they’re far more exposed with public AI than private
  • Real enterprise breaches and how the AIPod Mini helps govern each risk
  • How to think about endpoints — every prompt, response, and tool call — as the foundation of AI governance
NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 01 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
A True Story

The McKinsey Breach That Wasn’t

In early 2026, an autonomous AI agent broke into McKinsey’s internal AI platform — Lilli — in two hours. Not a human hacker. An AI agent. It accessed 46.5 million private conversations about strategy, mergers, and client deals. It extracted 728,000 internal files. It compromised 57,000 employee accounts — data sellable on the dark web. And it gained write access to 95 secret instructions that govern how McKinsey’s AI thinks — all of them changeable.

It didn’t exploit a software vulnerability. It didn’t crack a password. It reasoned its way through the system’s logic, found gaps in the access controls, and walked right in.

This is the new threat landscape.

AI systems reason, remember, and act. When they fail, they fail in ways traditional IT security can’t catch.

Traditional human threat

Hours to days

Sequential. One person, one target, slow reconnaissance.

Agentic AI threat

Computer speed, 24/7

Parallel swarms. Hundreds of parallel tries, 24/7, at computer speed.

Why IT Risk Frameworks Don’t Cover AI

Big organizations have IT controls: firewalls, access management, disaster recovery, compliance audits. All necessary. Unfortunately, none of that is sufficient for AI.

Traditional IT executes

When a database fails, it stops. IT risks are deterministic — you can test whether a query returns the right result.

AI reasons

When an AI system fails, it keeps running — generating plausible but wrong answers. AI risks are probabilistic. You can’t always predict what an agent will do at an edge it’s never seen.

The same controls that secure a database don’t catch an AI that has quietly gotten the wrong answer — or taken the wrong action — a thousand times before anyone noticed.

The old playbook falls short for a deeper reason. IT security assumes two things: the system stays what you built it to be, and the threat comes from outside. AI breaks both. A model changes as it learns, so last year’s audit no longer describes today’s system. And the danger often starts on the inside — the AI reasoning its way to a wrong action, with no attacker involved. You’re no longer guarding a perimeter; you’re governing something that thinks. That shift makes AI a board-level risk — one that belongs on the board’s agenda, not buried in IT’s.

NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 02 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
The Framework

Endpoints: The Door to MADCAF

Every prompt, response, and tool call is an endpoint. With public AI, your company’s institutional memory is exposed across dozens of points you don’t control. Each is a door for MADCAF risks. Private infrastructure means one boundary: yours. Public AI means dozens.

The new six risks exposed

MADCAF: What Exploits Those Endpoints

We call them MADCAF risks — a riff on Mad Cow Disease, because AI without proper governance behaves in a reckless, unpredictable way. Here are six unique, new failure modes that traditional IT security was never built to catch.

M

Model Drift

Your AI gets dumber over time — silently.

A

Agent Errors at Scale

When AI takes the wrong action — at machine speed.

D

Data Poisoning

Corrupting the model from the inside.

C

Compliance Gaps

Regulations written for humans, not AI.

A

Accountability Loss

“The agent did it” — so who’s responsible?

F

Fakes

Confident, well-formatted, and completely wrong.

NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 03 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
The Reverse Information Paradox

What This Means: Endpoints and Exposure

Here’s the insight: every prompt, response, and tool call creates an endpoint where your business touches an outside system. As Satya Nadella warned on July 12, 2026, you pay for AI twice: once with money, and again with proprietary knowledge you must reveal to make it useful.

Models learn from ‘exhaust’ — the prompts people write, the tools agents use, and especially the corrections people make when the model is wrong. Every correction is distilled into institutional know-how. It’s the kind of knowledge a competitor could never buy, and the kind that leaks almost imperceptibly: trace by trace, correction by correction, eval by eval.

Satya Nadella, CEO, Microsoft. Read: “The Reverse Information Paradox” — snscratchpad.com (Jul 12, 2026)

Payment 1: Money
$

Tokens · API calls · service fees

You pay for tokens, API calls, and service fees. The meter is visible — it arrives as an invoice.

Payment 2: Knowledge
YOUR KNOWLEDGE RIVALS UPSTARTS THE AI ITSELF

Flows to rivals · upstarts · the AI itself

The meter you can’t see. Your know-how flows to rivals, to upstarts — and to the AI itself, which can turn around and compete with you.

The threat isn’t data theft. It’s institutional knowledge transfer. Modern language models are sophisticated — they don’t need your files to learn from you. They can infer your practices from how you correct them, and even simulate your data from the patterns in your prompts. Your unique workflows and decision-making patterns become training signal for models that serve your competitors.

The solution: a hard trust boundary. One where your data, prompts, corrections, evals, and learned patterns stay inside your organization. You own the means of production. Your learning loop is yours alone.

The AIPod Mini approach brings the AI to your Data

It is architected so nothing needs to leave your building. The language model lives in your environment, behind your firewall — the AIPod Mini brings the AI to your data, not your data to the AI. You can still reach outside MCPs, APIs, and services when you want to, but that is your choice, not a requirement. Your institutional knowledge compounds in your own learning loops, not inside a model owned by a third party.

NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 04 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
The fix for Payment #2

How the AIPod Mini Keeps Payment #2 Inside Your Walls

Payment #2 was the meter you can’t see: on public AI, your prompts, corrections, and patterns leak out — to rivals, to upstarts, and to the model itself. The AIPod Mini closes that second payment. Your data, your model, and the hardware they run on all sit inside your own walls.

YOUR WALLSDATAMODELHARDWARE
With the AIPod Mini, you gain ownership, control and governance

You control all three layers — data, model, and hardware — so the learning loop compounds for you, not your competitors. Nothing crosses the wall. There is no second payment.

NetApp AIPod Mini
Public AI · Payment #2

Your know-how flows out with every prompt and correction — and can come back as a competitor’s answer.

AIPod Mini · No Payment #2

Your know-how stays behind your walls and accrues to you. What you teach the model, you keep.

True AI sovereignty means owning all three — data, models, and hardware. Anything less is just access.

NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 05 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
Deep Dive · 1 of 3

The Six AI Risks — Beyond Unpredictable Token Costs and IP Loss — in More Detail

Each one below: how it manifests, why it differs from traditional IT, and what real enterprises face.

M

Model Drift

Your AI gets dumber over time

Model drift is the silent degradation of AI performance as production data diverges from training data. Outputs still look reasonable — no errors, no alerts — but the AI that was 95% accurate six months ago is now 78%, and no one noticed.

Why it’s different from IT

Traditional software doesn’t degrade on its own — a payroll system works the same year to year. AI models decay as the world changes around them.

Enterprise impact
  • Healthcare: claims AI misses new 2026 billing codes
  • Finance: fraud model blind to new patterns
  • Retail: recommender pushes last year’s trends
Private AI advantage · AIPod Mini

Your company controls when models retrain — monitoring drift against your own data and validating accuracy before deploying updates. Public vendors update on their timeline; you find out when performance drops.

A

Agent Errors at Scale

When AI takes the wrong action

Modern agents don’t just answer — they send emails, update databases, approve requests, and change infrastructure autonomously. When an agent makes a mistake, it doesn’t give a wrong answer; it executes the wrong action across your entire infrastructure, at machine speed.

Why it’s different from IT

RBAC governs what users can do. Agents aren’t users — they reason through multi-step workflows, and it’s the combination of permissions that makes their errors catastrophic.

Real enterprise risks
  • 10,000 emails sent with the wrong pricing
  • A schema migration corrupts production data
  • Purchases approved outside policy limits
Private AI advantage · AIPod Mini + Iterate AgentWatch

Governance-grade observability: every agent action is logged, every decision auditable, every workflow traceable. Set boundaries on what agents do independently and what needs human approval. Public agents are black boxes — you find out after the damage is done.

NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 06 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
Deep Dive · 2 of 3
D

Data Poisoning

Corrupting the model from the inside

An adversarial attack where malicious actors manipulate the data used to train, fine-tune, or update a model — to degrade performance, introduce bias, or embed hidden backdoors. Once poisoned, the model is compromised at its core, and there’s no patch — today the fix is retraining. That is changing: models are starting to learn on the fly, updating during inference, not only in training (Iterate’s From Static to Dynamic). A model that keeps learning in production can be poisoned continuously — all the more reason to own and govern what it learns.

Why it’s different from IT

Traditional attacks target code or infrastructure. Poisoning targets the AI’s understanding of reality — and can stay dormant until triggered. Firewalls and antivirus don’t validate whether training data is trustworthy.

How it happens
  • Mislabeled data injected during training
  • Malicious data during fine-tuning
  • Corrupted documents in RAG knowledge bases
Private AI advantage · AIPod Mini

Your company controls the entire data pipeline. Training data comes from your own verified sources — not public datasets of unknown provenance — and you can audit what the AI learned, when, and from where.

C

Compliance Gaps

Regulations written for humans, not AI

HIPAA, GDPR, SOC 2, ISO 27001 — all written before AI became operational infrastructure. They assume humans make decisions, humans access data, and humans can explain why something happened. AI breaks those assumptions.

Why it’s different from IT

IT compliance is about controls — who accessed what, when. AI compliance is about reasoning — why the AI decided, what data influenced it, and whether you can prove it was fair and policy-compliant.

The 2026 landscape
  • EU AI Act — enforcement begins Dec 2027
  • GDPR — right to explanation of decisions
  • HIPAA — most public vendors don’t guarantee it
Private AI advantage · AIPod Mini

Data never leaves your infrastructure. You can show regulators PHI and PII stayed on-premises, produce audit trails for every decision, and prove human oversight. Public vendors can’t — the data and logs live in the vendor’s cloud.

NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 07 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
Deep Dive · 3 of 3
A

Accountability Loss

“The agent did it”

When an AI agent makes a bad call, who is responsible? As systems gain autonomy, the line between human decision and machine decision blurs — and organizations struggle to attribute accountability when something goes wrong.

Why it’s different from IT

Traditional software has a clear chain — developer, QA, ops. With AI it’s murkier: did the model hallucinate, was the data flawed, did the agent misinterpret, was oversight insufficient? IT governance tracks who deployed what, not why the AI decided.

Enterprise impact
  • Healthcare: AI denies a claim — who decided?
  • Finance: AI rejects a loan — who’s liable for bias?
  • HR: AI screens out a candidate — who’s accountable?
Private AI advantage · AIPod Mini + Iterate AgentWatch

Every decision is traceable. Your company can show regulators exactly what data the AI used, what reasoning it followed, and what oversight was in place — and you own the audit trail. With public AI, that trail lives with the vendor.

F

Fakes

Confident, well-formatted, and completely wrong

Fakes — often called hallucinations — occur when models generate information that looks credible but is factually wrong or entirely fabricated. When traditional software fails, it throws an error. When AI fakes an answer, it delivers it confident, well-formatted, and completely wrong — and keeps running.

The scale problem

At enterprise scale, even a 1–2% fake rate can create a real problem. Handle 100,000 interactions a month and that’s 1,000–2,000 wrong answers — each a potential compliance violation, complaint, or safety incident.

Real enterprise failures
  • Retail CX pulled AI after wrong return policies
  • Legal AI fabricated case citations
  • Healthcare AI generated wrong dosages
Private AI advantage · RAG on the AIPod Mini

Retrieval-Augmented Generation grounds responses in your own verified data and cites sources — instead of “remembering” from training. The fake rate drops dramatically when the AI has the information it needs.

NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 08 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
Putting the framework to work

What Public AI Asks You to Trust

If your company is using public AI today, it’s trusting a model it can’t inspect, trained on data it can’t audit; hoping the model doesn’t drift, fake an answer, or act wrongly; assuming compliance your company can’t prove; and liable for every decision it doesn’t control.

Ask your CISO

“Your IT security is strong — but it was built to protect traditional systems, not the six MADCAF risks AI introduces. When your AI fails — and it will — can you detect it? Can you explain it? Can you prove to regulators you had the right controls in place?”

NetApp, Iterate.ai, and the AIPod Mini are here to help you answer those questions — in a positive light.

Fun fact

The agentic AI market is exploding. Precedence Research estimates the global agentic AI market will grow from $8B in 2025 to $199B by 2034 — roughly 25x in nine years.

GLOBAL AGENTIC AI MARKET (PRECEDENCE RESEARCH) $8B 2025 $199B 2034 ~25x in nine years

And that’s the market alone: PwC forecasts agentic AI’s economic contribution could reach $4.4T annually by 2030.

Source: Harvard Business School Working Knowledge

The AIPod Mini value proposition

Regulated industries

  • Data sovereignty — PHI and PII never leave.
  • Audit trails for every decision.
  • You decide when models retrain.
  • Built for HIPAA, GDPR, SOC 2, FedRAMP.

Deploying AI agents

  • Iterate AgentWatch governance in real time.
  • See what agents access and do.
  • Human-in-the-loop approval controls.
  • Rollback — trace, understand, fix.

Worried about reliability

  • RAG grounds answers in your own data.
  • Drift monitoring — retrain when it drops.
  • Private training — control what it learns.
  • Audit what the model learned.
NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 09 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
The cost you can’t predict

The Meter You Didn’t See

On June 1, 2026, GitHub Copilot switched from a flat subscription to token-based billing. The base plan didn’t change — $10 to $39 a month. What changed is that heavy use now runs a meter. One reported developer bill jumped from $29 to $750 a month — same tool, same habits. Light users barely noticed; the jump hit multi-step agentic loops that burn tokens fast.

ONE DEVELOPER’S MONTHLY GITHUB COPILOT BILL (REPORTED) $29 Flat subscription before June 1, 2026 $750 Token-based billing heavy agentic use ~25× jump same tool, same habits
What runs the meter
Multi-step agentic loops

A single task can fire 20+ metered model calls.

Oversized context windows

Every token loaded into context is billed.

Frontier-model calls

The priciest models, called on every request.

The number isn’t the point — the unpredictability is.

With usage-based billing you can’t know next month’s bill. Private inference on your own hardware is a fixed, known cost. That predictability is the control this paper is about.

Source: GitHub’s own usage-based billing announcement, effective Jun 1, 2026. The $29→$750 example is a widely reported developer case — directionally accurate, but not an actual bill.

NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 10 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
The fix for the meter

Why the AIPod Mini Has No Meter

The meter exists because someone else owns the model, owns the hardware, and counts your tokens. The AIPod Mini removes it at the architectural level: the model, the hardware, and the data all live behind your walls. You bought the box — you run it as hard as you like. The running cost is small and predictable, not a per-token meter.

YOUR WALLS · ONE FIXED COSTMODELHARDWAREDATA
Public AI · metered

You pay per token. Agentic loops, big contexts, and frontier calls all spin the meter — and the bill is different every month.

AIPod Mini · fixed

One appliance, bought once, running behind your walls. No per-token meter to run — your only variable is the electricity it draws, and a small model on a small footprint draws little of it. Nothing like a token bill.

The architectural fix

When the model, the hardware, and the data all sit inside one owned system, there is nothing left to meter. Predictable cost is not a discount — it is a consequence of ownership.

No meter. No surprise invoice. Just the appliance you own, running as hard as you need behind your walls.

NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 11 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
The cost side of control

How Smaller Models Cut the Bill

The same private setup that lets you govern AI also lets you run it cheaper. You don’t always need a giant model. For many jobs, a right-sized model on one or two GPUs — the AIPod Mini, now shipping on six OEM platforms — returns the same answer at a fraction of the scale.

INPUT · PROMPT Summarize this vendor contract in one sentence. LLM Large Language Model Hundreds of GPUs HIGH cost · power · scale SLM Small Language Model 1–2 GPUs · the AIPod Mini® LOW cost · power · scale SHIPS ON 6 OEM PLATFORMS Dell · Cisco · HPE · Lenovo · Supermicro · ASUS SAME OUTPUT Either side can cancel with 30 days’ notice; unused fees are refunded.
What Iterate delivers with Lifeboat

Examples of what Iterate has accomplished using small language models and efficient processing on small GPU clusters, optimized by our Lifeboat runtime. Right-sized models, run efficiently — the same quality of answer at a fraction of the cost and hardware.

National retailer ·
site search
~95%

lower processing cost · ~75% less compute · 20× less memory

Outdoor equipment brand · image gen
~6×

faster per image · 12×+ lower cost per image

Iterate inference stack · throughput
2–6×

higher throughput than leading open-source engines (vLLM, SGLang)

Throughput comparison per Iterate Lifeboat benchmarks.

NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 12 / 13
NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
Two paths, two outcomes

IT Risk Protects Systems. AI Risk Governs Intelligence.

Your company knows how to secure databases, patch software, and audit access logs. But AI is different — it reasons, remembers, and acts. It drifts, fakes answers, and makes decisions. When it fails, it fails in ways traditional IT controls can’t catch.

Treat AI like IT.
Compliance violations, outages, damage.
Govern AI as its own risk class.
Compliant, governed AI becomes your advantage.

Private AI isn’t just about cost savings. It’s about control — over what the AI learns, what it does, and what you can prove to regulators. The AIPod Mini is designed to manage all six MADCAF risks, giving your organization the governance infrastructure to deploy AI safely, compliantly, and confidently.

More in this series
  • What Makes AI Different from IT? — The foundational paper on memory, reasoning, and learning.
  • The Oohs, Awes, and Dangers of AI Memory — What AI memory holds, and the five layers attackers can reach.
  • What Private AI Actually Means — The keystone Field Brief: the three-circle test for sovereignty and control.

Full series — iterate.ai/partners/netapp/papers.

About this series

A joint educational series on private AI and the AIPod Mini. NetApp — the governed data-control layer. Iterate.ai — the private intelligence layer.

NetApp AIPod Mini
NetApp
Iterate.ai
Authored by Jon Nordmark (Iterate.ai CEO) with support from Brian Sathianathan (Iterate.ai President, CAIO) and the NetApp AI Solutions Team
v1.22 · Aug 11, 2026
NetApp | Iterate.ai
AI Risks That Differ from IT Risks · 13 / 13