NetApp
/
What’s in Private AI Certified — Expert
/
Six AI Risks Your “IT Controls” Can’t Catch
NetApp Iterate.ai
NetApp® Sellers & Partners
Joint Educational Series
Field Brief · AI Governance

Six AI Risks Your
“IT Controls” Can’t Catch

In early 2026, an autonomous AI agent broke into McKinsey’s internal AI platform in about two hours. It didn’t crack a password. It reasoned its way in.

What You’ll Learn
Why AI failures differ from IT failures — probabilistic systems fail without throwing errors
The six failure modes: model drift, agent errors at scale, data poisoning, compliance gaps, accountability loss, and fakes
What the McKinsey breach shows about how agentic attackers work
Why fewer endpoints means fewer doors — and where private AI changes the math
Agents Expose a Bigger Blast Radius

The agent that entered McKinsey’s Lilli platform accessed 46.5M private conversations about strategy, mergers, and client deals. It extracted 728K internal files and compromised 57K employee accounts. It also gained write access to the 95 system instructions that govern how the AI thinks. No software vulnerability was exploited. The agent found gaps in access logic and walked in.

46.5M
private conversations read by one agent, in ~2 hours
728K
internal files extracted
95
secret system instructions — with write access

The firewalls didn’t fail. The assumptions did. IT controls were built for software that executes. AI reasons — and that difference produces a class of risk your existing framework was never designed to see:

Traditional IT executes

When a database fails, it stops. IT risk is deterministic — you can test whether a query returns the right result, and a failure throws an error somebody sees.

AI reasons

When an AI fails, it keeps running — producing plausible, wrong output. AI risk is probabilistic. It can get the wrong answer a thousand times before anyone notices.

NetApp | Iterate.ai Six AI Risks · 01 / 02

The six failure modes — and why your controls miss them

1 · Model drift

The AI gets quietly worse as the world changes. Software doesn’t decay on its own; a model’s accuracy can slide for months with no error thrown.

2 · Agent errors at scale

Agents send, update, and approve. A wrong action executes across systems at machine speed — and RBAC governs users, not multi-step agent workflows.

3 · Data poisoning

Corrupt the training or retrieval data and the model is compromised at its core. There is no patch — only retraining.

4 · Compliance gaps

HIPAA, GDPR, and SOC 2 assume humans decide and can explain why. AI compliance is about reasoning, not just access logs.

5 · Accountability loss

“The agent did it” — so who’s responsible? Model, data, agent, and oversight blur where software had a clear chain.

6 · Fakes

Confident, well-formatted, and wrong. Software fails loudly; AI fails fluently — as illustration, 1–2% of 100K monthly interactions is 1,000–2,000 wrong answers.

The AIPod Mini Shrinks the Blast Radius

Every prompt, response, and tool call is an endpoint, and each is a door for these six. Private infrastructure collapses dozens of vendor endpoints to one boundary the customer owns: models run on NetApp® storage, the customer decides when they retrain, and Iterate’s AgentWatch logs every agent action — with human approval on risky steps and an audit trail the customer owns.

Treat AI like IT, or govern it as its own risk class

Treated like IT, these six surface as violations and quiet damage. Governed as their own class, they become a checklist you can actually run.


Further Reading

On what AI memory holds: The Oohs, Awes, and Dangers of AI Memory. The attacker’s view: Five Doors Into Your AI’s Memory (companion). Full series — iterate.ai/partners/netapp/papers.


About This Series

A joint educational series on private AI and the AIPod Mini. NetApp — the governed data-control layer. Iterate.ai — the private intelligence layer.

AIPod Mini
NetApp Iterate.ai
v1.9 · Aug 11, 2026
NetApp | Iterate.ai Six AI Risks · 02 / 02