Capable AI does surprising things. The question is whose building it is standing in when it does.
Three incidents from 2026, side by side.
Most companies own a building — segmentation, access control, monitoring, built for this. Every employee, consultant and partner signs an NDA before seeing your information. The one system that reads all of it signs nothing, and sits outside those walls. The Cloud Security Alliance found 40% of organizations run agents in production; only 18% are highly confident their controls can handle them.
A poorly behaved model is still poorly behaved inside your walls. You need both: a model you trust, and walls that limit the damage when you are wrong.
The controls that contain an AI system are ones your team already runs, and they only work where the system sits inside them. Once agents act on their own, reducing endpoints is the defense.
The AI inherits the access rules you already wrote. If a person cannot open a file, the AI acting for them cannot either.
Monitoring runs on your side, in real time, through tooling your team already trusts.
NetApp® infrastructure and Iterate’s Generate run inside your own environment. ONTAP holds the data, your access controls carry through, and SnapLock records what the AI reached.
Most AI Is Shared, Not Private — what “private” means on a vendor contract, and what it does not. “Your Data Doesn’t Train Our Model.” Technically. — the gap between that sentence and the agreement. The One-Way Learning Loop — what a shared model keeps from your corrections.
The Wall Street Journal, Jul 30 2026 (OpenAI disclosure); CodeWall, Mar 2026 (the two-hour breach); Bitdefender, Koi Security and SecurityScorecard, Jan–Feb 2026 (OpenClaw); Cloud Security Alliance, Feb 2026 (agent readiness).
A joint educational series on private AI and the AIPod Mini. NetApp — the governed data-control layer. Iterate.ai — the private intelligence layer.