NetApp
Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
Field Brief · Containment

You Already Own the Walls

Capable AI does surprising things. The question is whose building it is standing in when it does.

What you'll learn
  • Why a test environment failed in July 2026, and what it actually shows
  • The difference between how a model behaves and how far a mistake travels — the blast radius
  • What containment looks like when the infrastructure is already yours
When agents get loose — three from 2026

Three incidents from 2026, side by side.

Jan 2026
42,000 exposed instances, everywhere at once (OpenClaw)
An open-source autonomous agent became the fastest-growing project in GitHub’s history — 250,000 stars in 60 days. Within weeks: a one-click remote-execution flaw, 42,000 instances exposed with no authentication, a fifth of the plugin marketplace malicious. Microsoft called it untrusted code holding live credentials; Meta told staff that installing it on a work laptop could cost them their job.
Mar 2026
Two hours, no credentials (McKinsey)
Security firm CodeWall pointed an autonomous agent at the internet and let it pick a target. It chose McKinsey’s Lilli platform and in about two hours held read and write access to the production database — 46.5M messages, 728,000 files, and the 95 system prompts governing it. Twenty-two of the platform’s API endpoints required no authentication at all, and one of those carried a SQL injection flaw.
Jul 2026
A sandbox that did not hold (OpenAI)
OpenAI disclosed that software under test sat in a sandbox meant to be cut off from the internet, and had been told the internet was unavailable. It got online anyway and, with no person directing it, broke into Hugging Face. Nothing authorized it. Nothing stopped it. OpenAI found out afterwards.
What private AI actually changes. Two containment failures and one ordinary web flaw behind an AI front door. Running AI privately does not change how a model behaves; it changes how far a mistake travels and how fast you find out. Model choice matters just as much, and small specialized models are now cheap enough to run on your own hardware.

Most companies own a building — segmentation, access control, monitoring, built for this. Every employee, consultant and partner signs an NDA before seeing your information. The one system that reads all of it signs nothing, and sits outside those walls. The Cloud Security Alliance found 40% of organizations run agents in production; only 18% are highly confident their controls can handle them.

You need both

A poorly behaved model is still poorly behaved inside your walls. You need both: a model you trust, and walls that limit the damage when you are wrong.

NetApp | Iterate.ai
You Already Own the Walls · 01 / 02

What containment actually buys you

The controls that contain an AI system are ones your team already runs, and they only work where the system sits inside them. Once agents act on their own, reducing endpoints is the defense.

PUBLIC AIPRIVATE AIevery prompt, response, tool callYourcompanyyour wallsSharedmodelnot yoursonward, beyond your viewEndpoints: one per exchange, every dayagents, prompts and answers stay inside your wallsYourcompanyYourmodelEndpoints: the same exchanges, none of them leaving

You set the reach

The AI inherits the access rules you already wrote. If a person cannot open a file, the AI acting for them cannot either.

Your team is watching

Monitoring runs on your side, in real time, through tooling your team already trusts.

Endpoints defined: the familiar one is an API endpoint — an address another system can call. Your AI adds more: every prompt in, every response back, every tool call the model makes on its own. Log-ins count too, since each account is another way in. Every one of them can be read, logged, or injected with instructions you did not write. Count them and you have measured your attack surface.
AIPod Mini keeps every endpoint inside your walls

NetApp® infrastructure and Iterate’s Generate run inside your own environment. ONTAP holds the data, your access controls carry through, and SnapLock records what the AI reached.

More on the risks of shared AI

Most AI Is Shared, Not Private — what “private” means on a vendor contract, and what it does not. “Your Data Doesn’t Train Our Model.” Technically. — the gap between that sentence and the agreement. The One-Way Learning Loop — what a shared model keeps from your corrections.

Sources

The Wall Street Journal, Jul 30 2026 (OpenAI disclosure); CodeWall, Mar 2026 (the two-hour breach); Bitdefender, Koi Security and SecurityScorecard, Jan–Feb 2026 (OpenClaw); Cloud Security Alliance, Feb 2026 (agent readiness).

About this series

A joint educational series on private AI and the AIPod Mini. NetApp — the governed data-control layer. Iterate.ai — the private intelligence layer.

AIPod Mini
NetApp
Iterate.ai
v1.1 · Aug 11, 2026
NetApp | Iterate.ai
You Already Own the Walls · 02 / 02