Key Takeaways
- Most AI projects now stall at the data, not the compute, and expensive accelerators sit idle waiting on data that’s hard to find, trust, or clear for use.
- NetApp’s answer is a single platform that makes data AI-ready where it already lives, so AI inherits the governance and security already in place instead of copying data into a separate stack.
- The unified storage and resilience layer is well established, and the newer AI data capabilities carry the upside, with their value riding on how well they reach across messy, multi-vendor data estates at scale.
The hardest problem in enterprise AI used to be getting compute. Now it’s getting a company’s own data ready for models and agents to use. At its recent industry analyst summit, NetApp put that problem at the center of its strategy and made its bid to be the trusted data foundation beneath enterprise AI, with a platform built to make a company’s data discoverable, governed, current, and safe without moving it somewhere new. The approach reflects where AI projects actually stall today, and it resets what a buyer should expect from the data layer beneath an AI program.
Why GPUs So Often Sit Idle
For years, enterprise AI has been a conversation about compute — who has the GPUs, who can get more, how fast they can be stood up. That conversation is now shifting. The organizations furthest along are finding that their hardest problem sits a layer below the hardware, in whether their data is ready to be used at all. The chips are bought, powered, and cooled at real cost, yet they spend much of their lives waiting on data that is hard to find, hard to trust, or not cleared for use. Compute is the easy half of the problem to fix: a company can write a bigger check for more GPUs, or rent them by the hour. Getting its own data ready for AI is slow work that no purchase order solves on its own — and that is why so many well-funded AI programs stall well short of what the hardware could do.
Enterprises are hitting the same wall in production, where the center of gravity in AI implementation is moving from raw performance to data quality and context. The work is also moving past frontier models toward inferencing and smaller, purpose-built models that run against a company’s own information, which is exactly where data readiness bites hardest. A model is only as good as the data it can find, trust, and act on, and for most enterprises that has become the gating factor.
AI-Ready Data Must Meet Four Requirements
Getting data ready for AI is harder than most buyers expect. Enterprise data is routinely scattered across various on-premises systems and multiple public clouds. Teams struggle to find the right data inside that sprawl, and once they find it, they have to gain confidence that it is current, correct, and appropriate to use. Sensitive information that should never reach a model has a way of slipping into pipelines when governance is an afterthought.
Said plainly, AI-ready data has to meet four requirements: It must be discoverable, governed, current, and safe to use. Discoverable means having a single view of what exists across the whole estate. Governed requires well-enforced rules about who can see what, and these rules must travel with the data wherever it goes. Current means that a change at the source shows up downstream without reprocessing everything from scratch. Safe means a model gets all of the relevant data and none of the material it should never see.
Reaching that point takes work that goes beyond knowing a file exists. It means looking inside unstructured content, enriching it with metadata, and understanding where a file lives, why it is there, and what it holds. That is how a platform tells sensitive data apart from ordinary data and handles each correctly. Strip away the labels and steps, and this is all data quality work — and it is proving to be the real blocker in enterprise AI.
The Evolution of Data: From Content to Context
For decades, data storage was judged on capacity and performance — how much it could hold, the cost per terabyte, how fast you could reach it, and how well it held up over time. Those aspects remain table stakes, but they are largely solved problems. Agentic AI changes the question being asked of data. A system used to be asked to return a specific file. Now it is asked to find what is relevant to a particular question, for a particular user, at a particular moment. Answering that requires understanding what the data means, beyond where it sits.
Consider a single question put to an AI agent. Answering it can pull in several types of information — from several places — all at once: a contract stored as a file, a supplier record in a database, a set of embeddings, and the relationships connecting all of it. The embeddings are what allow a model to search by meaning rather than by keyword. Traditionally that spans several systems, each with its own access method and its own governance model — and the old approach of checking permissions once when a file is opened cannot hold when an agent is assembling an answer from many sources at once. Permissions now have to be enforced on every retrieval.
This is why NetApp frames context, rather than raw content, as the scarce resource of the agentic era, and it is a fair description of where the difficulty has moved. It also changes what a data platform is for. Holding the most data at the lowest cost gives way to delivering the right slice of governed, current context for a given request.
NetApp’s Three-Layer Stack
At its summit event, NetApp backed all of this with real architecture. It described its platform as three layers, with data resilience running across all of them as a property of the platform rather than a separate product.
- Unified storage. No single system is right for every job, so NetApp matches the storage to where data sits in its lifecycle, using: high-throughput E-Series arrays with a parallel file system to feed AI training and high-performance computing; ONTAP for the broad run of enterprise production workloads; and StorageGRID object storage for scale and long-term retention. All of it is delivered the same way on-premises, in the major clouds, and in hosted environments. What makes the portfolio behave as one environment is not a single storage OS but the layer above it. A consistent set of data services, run from a single control plane, spans the whole portfolio so data is not trapped in a silo defined by the system or the place it sits.
- AI data layer. NetApp calls this the AI Data Plane, and it has two capabilities that build on each other. The AI Data Catalog comes first, building a single live view of data wherever it sits, including legacy systems and storage from other vendors, so an organization can find, understand, and govern what it has. That view stays current as the source data changes, updated incrementally so the overhead for keeping it accurate stays low. NetApp is comfortable in either role, whether sitting on top to manage across the whole estate, or feeding its own data and governance upward into a broader strategy run on another platform. The customer chooses, and that flexibility is what makes the catalog easier to adopt in the mixed data estates where NetApp has to earn its place.
- Unified control plane. NetApp Console is the single place to run and monitor the whole environment, from the storage portfolio across on-premises and the clouds to the AI data pipelines feeding models. Rather than needing a separate tool for each system and each location, an operator gets one view of what is running, how it is performing, and whether the data moving to AI is healthy. In the mixed estates this platform is built for, that consolidation is the difference between having one operational picture and needing to fuss with a different console for every box and every cloud.
The control plane is also where NetApp points AI at the infrastructure itself, and this is further along than a roadmap promise. Through Active IQ, the company already ships predictive fault detection that flags and remediates problems on its own, AI advisors that implement recommendations automatically rather than just listing them, and root-cause analysis that pinpoints what went wrong, or nearly did. The fuller vision — a system that detects, corrects, and rightsizes capacity and performance largely on its own with a human in the loop — is still being built on that base, but the building blocks are in customers’ hands today.
Together these map onto the four requirements with real machinery: the catalog handles discovery, governance is enforced down where the data sits, change detection keeps it current, and classification keeps sensitive material out of the pipelines. It is a coherent response to a problem most enterprises are still solving by hand.
FlexCache and the Case Against Copying Data
There is another key element of NetApp’s technical approach worth emphasizing. Most AI projects start in the cloud, often with an assistant or a frontier model, while a great deal of the data they need still lives on-premises. That gap is where things get messy. The instinct is to copy data to wherever the AI runs, and copying carries real costs. Lineage breaks, permissions drift, spend multiplies, and every copy becomes one more thing to secure. It is not unusual to end up with several copies of the same file scattered around, with the same name, same date, and no clear record of which one to trust.
NetApp’s answer is to avoid copying wherever possible. With a unified view of data across on-premises systems and the clouds, applications can see the whole namespace — a single view of every file across locations — while only the data actually needed gets pulled to where the work happens, then released when the job is done. Its caching technology, FlexCache, makes that work across the major clouds, on-premises stacks, and sovereign environments, so a workload can run in one cloud against data that lives somewhere else without relocating the entire dataset. NetApp also offers its storage as a native, first-party service sold directly by the major cloud providers, which keeps the same data management and controls in place no matter where a workload lands.
Bringing the AI capability to the data rather than the data to the AI lets it inherit the governance and controls already in place. For an enterprise already running ONTAP, much of this is less a new product to buy than a capability to switch on to address data that the platform already holds and protects. And open, standardized interfaces — including Model Context Protocol — let AI agents reach governed data through a single common doorway rather than a custom integration built for every project.
The Trust That NetApp Has Already Earned
For all the attention on new AI capabilities, enterprises still make storage decisions based on trust. The data feeding AI is likely to include some of the company’s most sensitive data, and putting it to work raises the stakes for protecting it. A wave of newer vendors has arrived with storage that is purpose-built for AI speed, and the raw performance is real. But handling enterprise data safely over many years is a different discipline. Encryption and key management, protection against data being quietly exfiltrated, privacy controls, and dependable recovery when something goes wrong are the parts that take a long time to get right.
This is where NetApp leans on its history. The company markets its storage as the most secure on the planet, which is its claim to make rather than an independent verdict. Slogans aside, the underlying design choice is sound. Security and recovery cannot be bolted on after the data is already feeding models, so they have to belong to the layer the data lives in. NetApp likewise builds ransomware detection and recovery directly into storage and backs it with a published recovery guarantee. That protection matters more as AI raises the value of the data being protected. For a buyer, the speed of feeding a model matters, but whether the platform can be trusted with the data in the first place is usually what settles the decision.
AI Outcomes, Sold as Solutions
Speaking of buyers, NetApp is also changing how it sells. It traditionally focused on putting storage in front of the infrastructure teams that run it. But its new platform makes a different motion possible, organized around the outcomes a customer wants rather than the products underneath. Whether an organization is most concerned with AI and data lakes, cyber resilience, data protection, virtualization, or reducing the power and cost of the datacenter, NetApp solutions can be bought and consumed as a straightforward purchase, as a subscription, as a first-party service inside any of the major clouds, or through a marketplace, without re-architecting. That flexibility is genuinely hard for others to match, and it follows directly from having one platform that runs consistently across on-premises and every major cloud.
This shift also comes with a change in audience. Selling an outcome means talking to the security leaders, data leaders, and executives now accountable for AI — a broader set of buyers than the infrastructure teams NetApp historically reached. That naturally implies somewhat different conversations about desired outcomes (often aided by NetApp channel partners). But it should also give buyers fewer moving parts to integrate and help them get more out of what they already own, with no rip-and-replace of the storage a business already depends on.
The honest caveat is about maturity and reach. NetApp’s unified storage and resilience foundations are well established and widely deployed. The capabilities that make data AI-ready are newer, and the catalog is only as good as the data it can reach. In a messy, multi-vendor estate, that reach is the open question, and it has not been proven at scale yet. Even so, the catalog is the lower-commitment way in, since a customer can start there for discovery and governance before taking on the engine.
NetApp’s Bet on the Data Foundation
As foundation models become more interchangeable, NetApp is making the case that the data foundation already sitting under a company’s information has the shortest path to achieving lasting advantage in enterprise AI. The company sometimes reaches further and calls itself a data platform, but its strongest ground is the foundation itself, the governed layer that the analytics and query engines must still trust. The summit showed a company organizing its strategy around that bet. NetApp’s customers already trust it with their storage, and that kind of trust goes a long way. The likely outcome is that they follow the company up the stack, letting the vendor they already rely on govern and serve the data their AI runs on.

