Agentic AI

VAST Data Builds Governance and Self-Learning Into Its AI OS

At VAST Forward on Feb 25, 2026, VAST Data announced PolicyEngine and TuningEngine: inline zero-trust governance for agent actions and automated LoRA/SFT/RL feedback loops, on NVIDIA CNode-X hardware.

VAST Data Builds Governance and Self-Learning Into Its AI OS — article cover
On this page6 SECTIONS
  1. PolicyEngine: Pre-Execution Governance for Agent Behavior
  2. TuningEngine: Turning Feedback Into Model Updates
  3. CNode-X: The NVIDIA-Bound Compute Layer
  4. CrowdStrike, Polaris, and the Cosmos Ecosystem
  5. What It Means for Platform Teams
  6. Sources

On February 25, 2026, at the VAST Forward 2026 user conference in Salt Lake City, VAST Data took another step away from its storage-vendor origins. It announced two new compute components for its AI Operating System — PolicyEngine and TuningEngine — aimed at making agents that run fast inside enterprises, but also governable and self-improving. CEO Renen Hallak’s framing: the system the company set out to build when it was founded “has now come to life.”

Both engines are slated to ship with the VAST AI OS by the end of 2026. They fill the two gaps agent systems most conspicuously lack today: governance before an action executes, and learning after it does.

PolicyEngine: Pre-Execution Governance for Agent Behavior

PolicyEngine is an inline policy enforcer embedded at the data layer. It governs every access an agent makes — to shared memory, external tools, knowledge bases, even other agents — combining fine-grained explicit permissions with AI-derived contextual conditions, and making the allow-or-block decision before the action runs rather than in a post-hoc log review.

The supporting design is zero-trust throughout: agent actions leave tamper-proof traces and logs, making the system “observable, explainable, auditable.” For enterprises moving agents into production, this effectively lifts IAM-grade governance to the agent-behavior layer — permissions live in the data plane, not in a prompt.

TuningEngine: Turning Feedback Into Model Updates

TuningEngine closes the other half of the loop. It continuously captures outcomes from agentic pipelines alongside curated human feedback, automatically feeds that data into LoRA, SFT, and RL fine-tuning pipelines, produces candidate models, then evaluates and benchmarks them inside the AI OS itself, with either manual approval or automatic deployment at the end.

Add the existing AgentEngine — a serverless agent runtime coordinating multi-agent workflows, model invocation, and tool use — and VAST’s ambition is a “thinking machine,” in co-founder Jeff Denworth’s words: observe, reason, act, evaluate, improve, repeat.

CNode-X: The NVIDIA-Bound Compute Layer

The same event brought CNode-X, designed with NVIDIA: the AI OS software runs directly on NVIDIA GPU servers as certified configurations, with Cisco and Supermicro among the certified builders. The Sirius query engine is open-sourced on top of NVIDIA cuDF — VAST claims up to 44 percent lower query time and 80 percent lower query cost — with cuVS vector-search acceleration and NIM microservices built in.

For long-context multi-agent inference, the bigger item is support for NVIDIA Context Memory (CMX): paired with BlueField-4 DPUs and Spectrum-X Ethernet, shared KV cache access is accelerated, directly cutting time-to-first-token in long-context workloads. This software-hardware binding rides the same demand engine behind NVIDIA’s record $68.1 billion quarter reported the same day (see NVIDIA’s FY2026 Q4 earnings). VAST also open-sourced three DataEngine blueprints: video intelligence, enterprise document RAG, and genomics.

CrowdStrike, Polaris, and the Cosmos Ecosystem

Security integration is the other throughline. CrowdStrike is being embedded into the AI OS and PolicyEngine — monitoring data access, admin activity, and workload behavior, correlating with endpoint, identity, and threat intelligence, and able to trigger quarantine, access restriction, workload isolation, and preservation of forensic records. Notably, CrowdStrike already runs parts of its own infrastructure on VAST.

Management goes to the new Polaris control plane: a Kubernetes-based multi-tenant design with a lightweight agent per node, managing fleets spread across on-premises, neoclouds, and public clouds — included with the AI OS at no charge. The Cosmos partner program launched alongside, with Mirantis’s k0rdent as the inaugural partner, South Korea’s Lablup joining with Backend.AI for sovereign AI, and Firmus Technologies appearing as a neocloud customer.

What It Means for Platform Teams

Three observations. First, governance is sinking down the stack: enforcing agent permissions at the data layer is harder to bypass than app-layer or prompt-level controls — a real architectural pull for compliance-heavy buyers. Second, the closed-loop economics: TuningEngine moves “feedback to fine-tune to evaluate to deploy” into the infrastructure, turning agent improvement from a project cadence into an operational one. Third, lock-in risk: CNode-X, cuDF, CMX, and NIM all stack on NVIDIA, so adopting this means choosing the chip and the software stack in one move. Before the end-of-2026 release, it is worth benchmarking against open-source query routes and alternative agent-governance approaches.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

SHAREXEMAIL