NetApp
/
What’s in Private AI Certified — Expert
/
Protecting Institutional Knowledge in the AI Era (Deep Dive)
NetApp Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
Field Brief  ·  What Your Company Knows

Protecting
Institutional Knowledge
in the AI Era

Every employee carries a piece of what your company knows. AI tools make it easier than ever to copy that knowledge somewhere you can’t see — a little at a time, or all at once on the way out the door.

A joint educational white paper by NetApp® and Iterate.ai.

What You’ll Learn
Why institutional knowledge now leaves the company two ways — a slow, constant leak through everyday AI use, and a sudden burst when someone resigns.
Why 70% of insider IP theft happens within 30 days of a resignation announcement — and why none of it requires hacking anything.
What’s actually showing up in AI prompts: customer billing data, employee records, legal and financial documents.
Why breaches involving shadow AI cost $670,000 more on average, and why 97% of those breaches happened at companies with no access controls in place.
What changes, role by role, when the AI a team uses is private and governed instead of public and shared.
Version 1.1
Aug 11, 2026  ·  01 / 07
A Real Case

A Human Spy

In March 2025, the payroll platform Rippling filed suit alleging that an employee at competitor Deel — hired into a global payroll compliance role with ordinary access to Slack, Salesforce, and Google Drive — used that access to pull customer lists, pricing details, and competitive intelligence out of the company. No password was cracked. No firewall was breached. The access was already there, granted on day one, and the activity blended into a normal workday for four months before anyone noticed.

70%
of insider intellectual-property theft happens within the 30 days surrounding a resignation announcement — Carnegie Mellon University’s CERT Insider Threat Center, analyzing more than 700 cases.

Call this the burst pipe: a short, predictable window where a career’s worth of institutional knowledge can leave through channels no security tool is watching, because the person leaving already had permission to be there. It’s the dramatic half of this problem. The other half never makes the news.

Also: “Developing Controls to Prevent Theft of Intellectual Property” — Carnegie Mellon University Software Engineering Institute Blog (Apr 23, 2012).
The Other Leak

The Slow Technological Drip: Prompts

Most institutional knowledge doesn’t leave in a burst. It leaves in a drip — one prompt at a time, from employees who have no intention of taking anything anywhere. According to LayerX Security’s Enterprise AI and SaaS Data Security Report 2025, 45% of enterprise employees now use generative AI tools at work, and most of them are pasting company information directly into the chat window.

77% of AI users
have copied and pasted company data directly into a chatbot query.
22% of those pastes
include personal or payment information — PII or PCI data.
82% of pastes
came from personal, unmanaged accounts invisible to security teams.

The burst pipe gets attention because it looks like theft. The slow leak rarely does — it looks like someone doing their job a little faster.

NetApp | Iterate.aiProtecting Institutional Knowledge  ·  02 / 07
What's Actually in the Prompt

It’s Not Just Passwords

When Harmonic Security analyzed a sample of enterprise AI prompts flagged as risky in late 2024, the contents weren’t exotic. They were the ordinary paperwork of running a business.

1
Customer data, including billing information
45.8% of risky prompts — account numbers, invoices, and payment details typed in to draft a reply or reformat a report.
2
Employee data, including payroll and PII
26.8% of risky prompts — compensation figures, performance notes, and personal records pasted for a quick rewrite.
3
Legal and financial documents
14.9% of risky prompts — sales-pipeline detail, M&A material, and contract language sent in for a summary.

Separately, a CybSafe/National Cybersecurity Alliance survey found that 38% of employees admit to sharing sensitive work information with an AI tool without their employer’s permission — not to leak anything, but because the AI tool was the fastest way to get an answer.

Read: “1 in 10 AI Prompts Could Expose Sensitive Data” — THE Journal, citing Harmonic Security (Jan 22, 2025).
What It Costs When It Surfaces

The Bill Nobody Sees Until the Breach

IBM’s 20th annual Cost of a Data Breach Report, produced with the Ponemon Institute, put a number on both leaks at once. Breaches involving a high level of shadow AI — unsanctioned tools employees adopt without security sign-off — cost organizations measurably more, and happen more often than most security teams assume.

+$670K
Added to the average breach cost when shadow AI is involved
20%
Of breached organizations were compromised through shadow AI

The gap is a governance gap, not a technology gap: 97% of organizations with an AI-related breach lacked proper access controls. And shadow-AI breaches don’t expose a random slice of the business — customer PII shows up in 65% of them, versus 53% industry-wide, and stolen intellectual property carries the highest cost per record of anything in the report.

NetApp | Iterate.aiProtecting Institutional Knowledge  ·  03 / 07
The Practical Question

What Not to Paste, Role by Role

Day-to-day risk looks different depending on what a person’s job actually touches. The same chatbot window that’s harmless for one role is a live wire for another.

CFO / Finance
Don’t paste: unreleased earnings figures, board financial models, or M&A terms before they’re public.
R&D / Engineering
Don’t paste: proprietary source code, unfiled invention disclosures, or formulation and design specs.
Product Manager
Don’t paste: unreleased roadmap dates, competitive positioning docs, or pricing strategy ahead of launch.
Sales / Account Exec
Don’t paste: customer contract terms, win-loss notes, or named-account pricing concessions.
HR / People Ops
Don’t paste: compensation bands, performance review content, or reorg and layoff plans before they’re announced.
Legal / Compliance
Don’t paste: privileged litigation strategy, draft regulatory filings, or settlement negotiation positions.
Operations / Supply Chain
Don’t paste: supplier contract terms, capacity and allocation plans, or unreleased cost structures.
Marketing / Brand
Don’t paste: pre-launch campaign creative, embargoed announcements, or competitive intelligence briefs.
Software Developer / DevOps
Don’t paste: API keys and credentials, infrastructure architecture diagrams, or incident postmortems.

None of this is a reason to ban AI tools — every one of these roles has legitimate, valuable uses for them. It’s a reason to control where the prompt goes, so the answer to “can I use AI for this?” can stay yes. Just use AI that resides behind your firewalls. It’s why NetApp and Iterate provide AI chat, agents, and projects — privately — via the AIPod Mini.

AIPod Mini
The AIPod Mini — private AI chat, agents, and projects, on infrastructure you own.
NetApp | Iterate.aiProtecting Institutional Knowledge  ·  04 / 07
The NetApp-Specific Advantage

The Pipe You Own vs. The Drain You Don’t

A Ponemon Institute study for Symantec found that 59% of departing employees take confidential information with them on the way out. Cyberhaven’s more recent analysis of exfiltration incidents found that generative AI tools now account for 13.1% of the channels used to move that data — behind only personal cloud storage and removable media, and the fastest-growing of the group.

Dimension
Public / Shared AI
AIPod Mini
Visibility into prompts
Security teams see nothing once a prompt leaves a personal account.
Every prompt, response, and tool call runs on infrastructure your team can see and log.
Access at resignation
Access to the AI tool itself often outlives access to company systems.
Access is revoked the same moment every other system is — one governance model, not two.
Where the data goes
Into a third-party model the vendor’s contract controls, not yours.
Stays on infrastructure your company owns and NetApp secures.
Proof of what happened
Rarely exists. Most pastes leave no enterprise-visible trail at all.
ONTAP Snapshots and audit logs establish what left and when.
Read: “Data Loss Risks During Downsizing: As Employees Exit, so Does Corporate Data” — Ponemon Institute, sponsored by Symantec (Feb 23, 2009).
Also: “The Cubicle Culprits: In-Office Employee Data Exfiltration” — Cyberhaven, Q1 2024 Insider Risk Report (Mar 19, 2024).
The Fine Print

The Agreement Nobody Reads Before Pasting

Once something is pasted into a public AI tool, a company’s own data-handling policy is no longer the only document that matters — the vendor’s terms of service are. An analysis of AI vendor contracts by TermScout, conducted with Stanford Law School’s CodeX center, found that 92% of AI contracts claim data usage rights beyond what’s necessary to deliver the service, compared with 63% for software contracts generally.

SaaS Contracts, Generally
63%
AI Vendor Contracts
92%

Many of those contracts allow the vendor to use customer prompts and data for retraining models or other purposes well beyond answering the question that was asked. Once a prompt is sent, the company that typed it no longer decides what happens to it next. Private, governed infrastructure changes that equation at the source: the data never leaves an environment a company’s own contract governs in the first place.

That NDA your company signed? An employee may breach it with a single prompt—by pasting a partner’s confidential information into a public AI model.

NetApp | Iterate.aiProtecting Institutional Knowledge  ·  05 / 07
Two risks, no attacker required

The Leak and the Burst Are the Same Pipe

Every company already has both problems: a slow, constant leak from everyday AI use, and a burst risk sitting in every resignation on the calendar. Neither requires an attacker. Both just require a pipe nobody is watching. The fix isn’t banning AI — every role in this paper has a legitimate reason to use it. The fix is making sure the pipe belongs to the company, not to whichever chatbot happened to be open.

The AIPod Mini keeps institutional knowledge on infrastructure you own.
Role-based access that ends the moment someone leaves, a full audit trail of every prompt, and a contract that doesn’t reserve rights to your data — because the data never had to leave in the first place.
More in This Series
The Oohs, Awes, and Dangers of AI Memory. The companion piece to this paper — how AI memory architecture itself creates governance risk, independent of who’s using it.
The Rest of the Invoice. Why idle GPUs and stalled pilots are also costs nobody budgets for.
From Empty Infrastructure to Working AI in 20 Minutes. Why data readiness, not model choice, is the real deployment bottleneck.

About This Series

A joint educational series on private AI and the AIPod Mini. NetApp — the governed data-control layer. Iterate.ai — the private intelligence layer.

AIPod Mini
NetAppIterate.ai
v1.1 · Aug 11, 2026
NetApp | Iterate.aiProtecting Institutional Knowledge  ·  06 / 07
Appendix

A Quick Glossary of Institutional Knowledge Risk

Plain-language definitions for the governance and security terms in this paper.

Shadow AI
Generative AI tools employees adopt for work without security or IT sign-off, invisible to the company’s own monitoring.
E.g. an employee using the free version of a chatbot at work, unknown to IT or security.
Institutional Knowledge
The accumulated, often undocumented expertise a company holds through its people — pricing logic, client relationships, product history, and process know-how.
Pre-Termination Window
The period immediately before and after a resignation announcement, when departing employees still hold legitimate system access.
E.g. the 30 days around a resignation announcement, when 70% of insider IP theft occurs.
Exfiltration
Moving data out of a company’s control, whether through a deliberate act or an ordinary, well-intentioned prompt.
Data Usage Rights (Contract)
Contract language granting an AI vendor the right to use customer inputs for purposes beyond delivering the requested service, such as model retraining.
E.g. a clause letting a vendor retrain its model on prompts a customer typed in.
Access Control
A technical restriction on who can reach a given system or dataset, and the first line of defense IBM’s 2025 report found missing in 97% of AI-related breaches.
Audit Trail
A recorded, reviewable history of who accessed or prompted a system and when — the evidence a “pipe you own” can produce that a public tool usually can’t.
Governed AI / Private AI
An AI system where every prompt, response, and tool call runs on infrastructure the company itself owns, secures, and can log.
E.g. an AI system where every prompt runs on infrastructure the company itself controls and logs.
NetApp | Iterate.aiProtecting Institutional Knowledge  ·  07 / 07