Veeam Unleash – Enable AI and Advance Use Cases
Michael Cade and Emilee Tellez introduce the Unleash pillar, which focuses on empowering administrators to leverage backup data for AI-driven insights and advanced operational use cases. Veeam addresses the common challenge of garbage in, garbage out by providing a framework to ensure data hygiene before it is used to train models or fuel AI agents. The centerpiece of this initiative is Veeam Intelligence, an evolved natural language chatbot that moves beyond simple documentation scraping to interact directly with a customer’s specific backup environment. This allows users to generate complex reports, such as identifying failed jobs or malicious activity, through simple conversational queries, effectively transforming backup data from a dormant insurance policy into an active business asset.
The presentation features a live demonstration of the Model Context Protocol (MCP), a standard that Veeam is utilizing to bridge the gap between disparate IT management tools. By integrating Veeam Intelligence with other MCP-compatible servers, such as ServiceNow, administrators can automate entire workflows, from detecting an anomaly and generating an HTML executive report to opening a prioritized incident ticket, all within a single AI interface like Claude Desktop. While these capabilities are currently in technical preview, Veeam emphasizes that they are built with strict role-based access controls (RBAC) and data privacy guardrails, ensuring that only metadata leaves the customer’s site and that immutable backups remain protected from unauthorized modifications by AI agents.
Looking toward the future of enterprise AI, Veeam is positioning itself to manage “agentic” risks by providing visibility into the “social network” of AI agents across the infrastructure. This includes dynamically discovering agents in platforms like AWS Bedrock and Microsoft Copilot to map their access to sensitive data and implementing LLM firewalls to prevent data leakage. In response to delegate concerns about agents making misinformed decisions, the speakers explain that Veeam is developing specialized internal agents, such as a Backup Admin Agent, to provide contextual guardrails and enforce secondary human approval for critical changes. By allowing customers to “bring their own model” (BYOM) or use integrated options, Veeam aims to provide a flexible, secure foundation for the next era of data-driven innovation.
Presented by Michael Cade, Field CTO. Recorded live at Tech Field Day Extra at RSAC 2026 in San Francisco on March 23, 2026. Watch the entire presentation at https://techfieldday.com/appearance/veeam-presents-at-tech-field-day-extra-at-rsac-2026/ or visit https://techfieldday.com/event/rsac2026/ or https://Veeam.com for more information.
Transcript
Cool. Hey, everyone. Yeah, so this is the final segment of our session, and it goes around that wheel of understand, secure, resilience, and now unleash.
I'm Michael Cade from Veeam. I'm a Field CTO. I've actually been here 11 years today.
Yeah, I just worked that out. Unleashing data. So from a leveraging data point of view, we've been doing it, enabling our customers to spin up from backups for a number of years.
Where we're going in the world of AI and understanding that data and contextualizing that data to be able to use it, either from a production point of view, so you've been more hygienic with that data, you know what it is, to being able to protect it. But then what about using backup data to leverage that against agents or being able to get insight out of that data, which has always been our premise, right? Being able to leverage data that you've taken from a backup point of view.
It sits there for a retention or for a bad thing to happen, and then it's used for a recovery. Actually, we should be able to use that data. It sits on pretty good storage.
We don't have that much bad storage out there today. So performance-wise, we should be able to use it. We should be able to spin it up and use that data.
So there's three areas that I touched on. One was that leveraging of data. The second is how are we using AI to help enhance our users, our administrators' world from a backup point of view?
How can we make their life easier? How can we make the backup is boring job a little bit more exciting or easier so they can spend time building out these sandbox environments with data? And then the third one is around, well, okay, now that you've got the ability to understand that, how can we learn about AI systems that are being used across the business, across the environment, and make sure that we're putting some governance across that?
So we all know these numbers. I think we've touched on them. In terms of data growth, garage to garage, you'll only get that analogy if you're in the other session, so you'll have to go back and watch those.
But the growth of data is expanding. We know that AI has a massive impact, and we need to have good, clean, understood data or hygienic data. You've heard the term garbage in, garbage out.
But equally, we've got a lot of our peers within businesses are just uploading files to any model. ChatGPT, they're dropping Excel spreadsheets, et cetera, sensitive information, and really there's no governance. There's no regulation around that.
There's no one really stopping that. I'm sure we're going to see a lot at RSAC suggesting that they're doing something similar. So the first point is how are we as Veeam enabling our users to take advantage of AI?
And that started with a chatbot. I think every software company in the world started with a chatbot, right? You interact with your help center or your documentation.
Tell me how to do this, and it gives you that back. It scrapes the... It goes and gets the information from the help center and then gives you a natural language response to say, "This is what you should be doing," or, "Perfect," or whatever the response is.
The evolution of that over the last nine months for us around Veeam Intelligence, we call it Veeam Intelligence, so it still is a natural language chatbot system, and it has access to that documentation, but equally it has access to your Veeam environment. So now you can query that and instead of going and building out custom reports based on the backups that you have and the recovery and the access and all of this stuff, you can actually create your report inside of this Veeam Intelligence chatbot and get some immediate insight into that environment. Tell me all the backup jobs that went wrong last night.
Tell me if there were any malicious activity across my backups to everything that Emily was saying about those security integrations, versus having to visualize it or go into an observability tool such as VeeamOne or any of the other SIEM or SOAR tools that Emily touched on, being able to actually just you log in in the morning, just ask it some questions. How did everything work last night? Rather than having to go and create and see and visualize all of that stuff.
Equally, and I'm going to touch on a little bit around MCP as well. So there's many different MCP servers that we've built within Veeam. The one that I'm going to demonstrate is the ability to interact the Veeam Intelligence MCP, which is exactly what I was just talking about, being able to query in natural language the status of your Veeam environment.
But couple that with other MCP servers. Maybe it's a ServiceNow MCP, and now you put them together, and now you start to get a ticketing pipeline to that as well. So exactly that.
So using Claude Desktop as an interface, and maybe MCP, and we'll see a lot more this week around MCP. As a protocol, it's definitely blown up in the last 12 to 18 months. But I feel like from an MCP perspective is that could this be how we interact with software over the next course...
MCP is one protocol. There's also A2E, which is from Google. But is this a better way to encompass all of the ways in which we visualize and manage our environment?
So like I say, a very simple demo. We're using the MCPProtocol to hook into our Veeam Intelligence, and we're also using the MCP to hook into our ServiceNow. And we're going to couple those together in the next demo to show how we're blending that together.
But you could bring heaps of MCP servers into this workflow. It could be bring a security MCP, and then suddenly this Claude desktop and other MCP clients are available. But you can start to potentially see how this becomes the interaction, this becomes the UI of how we day-to-day manage our environments.
Does this play? Okay, so we've got a prompt here. Good morning.
What does my Veeam environment look like today? What do the backup jobs look like, their state, run duration, any warnings? Are there any given alarms?
Give me a nice HTML report. So this is me just interacting with the Veeam MCP. You see it's going along, it's got all of the information, and suddenly over on the right-hand side, not like everyone's seen an AI-generated report, but you can see that we've got an exec summary, a very nice coffee dashboard report just telling me, well, what happened.
I don't have to click ups through all of the Veeam stuff. You can see that I've got a good understanding, color-coded for those that can understand the traffic light system, recommendations about, okay, how can we go and fix, what are the first jobs that I need to do today? But then based on that, I've got a ServiceNow MCP also implemented here.
So I can take the issues that we found and start creating incident numbers and incident cases and tasks within ServiceNow. So none of this is... Veeam has an integration into ServiceNow, but this is based on just bringing those two MCPs into one client.
So imagine we have that integration with ServiceNow, but I think this opens up the door to many of those other integrations that we might see, whether it's from a Veeam point of view with a security vendor that is doing something, but being able to interact this way with natural language and then leveraging APIs underneath to get an outcome. So you see, and then he does a PowerPoint presentation to extract that out and go to the board later on that morning, which basically summarizes everything that we found for our coffee dashboard now into a presentation. We didn't even have to open PowerPoint for it.
And then what do we need to do? What should my team be doing today? Because based on this, we've already opened a ticket within ServiceNow.
We've got the information that we need to do and go and fix. This is what I'm going to be focused on. Equally, this enables us to start speaking in a different language to it and being able to provide that accessibility more than anything into our world.
So it's going to come back and provide that. And you see all it is based on three MCP add-ons that we use in the ServiceNow and the Veeam Intelligence of VBR. And I think this next bit, so there's leveraging data.
Sorry. Before you jump into the next bit, as you open up the Veeam environment to MCPs, what should people be concerned about? Great question, right.
I think MCP security is going to be another hot topic when we walk over the road later on this week. But everything that we're doing is from a role-based access control perspective. You have to sign in, you have to provide credentials to get into that.
So you're bringing that authentication authorization into that platform to be able to query what you've got access to within your Veeam environment. If you're a viewer only, then you're only going to be able to view what you have access to. I don't know if that gives you the level.
MCP security, me and you could probably talk for a while on the whole MCP security landscape, and I think that's probably where you were going, but. Yes, but I also, I'm concerned about what happens when you expose your backup environment to AI agents. What can an AI agent, what knowledge is it going to be able to extract out of there?
And do you think that presents any sort of risk? So just to level set what data is actually being sent where as well, is that only metadata leaves the customer site. Nothing sensitive will leave the site.
That would be pretty bad of us when we've just spent an hour and a half talking about sensitive data and the likes. Equally, there is no ability to impact the backups, like in terms of you can't tell it to delete backups. They're in an immutable state.
If they've been designed and configured correctly, there's no way in which you can manipulate that. " You can give it commands that way. So just conscious of time.
The other area, so we talked about leveraging data. How can we help customers use their data today? Forget about AI.
Everyone wants AI, or the board wants AI. But actually, people are still just trying to do their day jobs and trying to get on. Leveraging that backup data for some insight and some use could be still useful for that.
It could be the clean room. Then how are we helping our administrators manage Veeam more proactively, more using natural language, and being able to hook that into the other tools that they're having to use on a daily basis? Now, a further out vision is, okay, now if we think about AI, if we think about enterprise AI as just another application.
There's some sort of AI model. There's some sort of LLM in the situation. Where are they sitting?
What are the applications that it has access to, whether it's agents, assistants, chatbots, et cetera, but it's a new category of apps. But it becomes the same as a database in regards to if I can understand where it is, what it's doing, who has access to it, then I can start to protect and have a good understanding of what that data is. So within the understand side of things, we're dynamically discovering those AWS Bedrock, the copilot agents that are across that estate.
When you add those data systems in, it's picking up that context and being able to provide you the graph of that, the social network of that copilot agent, who's the user, what data does it have access to, building out a map of that. Then equally, to the point that we touched on around Agent Commander, but this is a broader vision, is the ability to, if an agent does make a mistake or changes something, I agree with Tom. So Tom's question in the last session was if an AI agent just goes and runs wild, probably fix the agent.
Great, want to recover the data 100%, and that might be a Veeam job to recover that data, but then you're not just going to let the agent go again and delete the database again. You're going to go and fix the agent and make sure that role-based access control is in place, and you're going to fix that. But what this end-to-end does is gives you visibility of what it has access to, making sure that it doesn't have access to sensitive data, the ability to roll back if something bad happens, but that's the same as if we think about the three resilience trees that Rick and Emily touched on.
The fire, flood, blood, or accidental deletion, that's the same scenario as an agent deleting something. It's an accident, so being able to recover that. So what we're saying here is this can give us the ability to roll back and recover when those agents do make a mistake, because it might be that you can fix the agent, but the likelihood is, is that agents are going to just continue to keep making mistakes.
Not the same mistake, but the ability to change. Let me-- And I think this is important, not only the understanding of the actual data, but what does it look like in terms of your AI agents? What access of data do they have?
What are the controls in place? How are we ensuring that they're not sharing sensitive information, and how do we block that? And we have the concept of these LLM firewalls that are in there.
What is the data that is being used? What LLM? Is it a public LLM?
Is it ChatGPT? Is it Copilot? Who else can understand that data?
There's lots of different LLM companies out there. Equally, being able to leverage that data to create a company's own SLM, so a small language model, from that good data. I can see Tom coming up.
So firstly, is there any questions? But that was me whistle-stop tour of the unleash data. So Skye Fugate, one quick question.
I know when we get into giving AI the ability to go and interact via MCP, AD, whatever, with something, let's say backup schedules, what's it to stop from making a misinformed decision on-- Maybe it doesn't understand what your RTO is, so instead you're like, "I want to save money," and it changes it to seven days instead of 24 hours. What's to make sure that it has the right context before it makes those modifications? The oversight.
Yeah, there's a few different ways. So for internally here at Veeam, from a product development standpoint, we're actually building additional AI agents to provide that context, like a backup admin agent, a security agent, et cetera, that can do deep analysis and be able to provide that information back. So that way, before you actually go and you try to take some action on it, essentially it's going to red flag that and say, "Well, no, you have this one set from an SLA perspective," so this would kind of provide some guardrails.
So that is something that we are building internally in-house. We're still a little bit away from allowing customers to lever something like MCP to take an action on it, but as we go to move to that direction, that is something 100% that we're trying to put those guardrails in place to actually surface, "This is the information. This is the SLA that you set.
" And if so, we actually have some secondary rules that have been created, so that way if they do try to change a policy, if they do try to delete the data, a secondary admin actually has to approve it. So it can't just be done on behalf of an agent itself. There's a secondary overhead that can approve that action.
So the MCP is not GA yet. That's still in beta? It's a technical preview right now.
Yeah, there's several MCPs that are happening across Veeam, but yeah, the best way to put that is that they're all in a technical beta type situation. And then my second question, for the agents, are those going to be house-kept where I have to interact with your AI, or can I take those and bring your own AI? Good question.
So out of the box, they will use Microsoft OpenAI LLM, but you can bring your own model as well. So it's a configuration change to put it to your Ollama or whatever local model that you're using. All right.
Thank you. All right. That wraps our Unleash session for Tech Field Day 2026.