Hope there is an off switch
The AI would an easier time if it understands NTFS. If they have taken the easy path then EXT4 will confuse the hell out of it unless support turns up, things get worse with the non-default file systems and fall apart completely with next next versions of them. Perhaps something is possible by watching the whole disk without understanding the file system. That should be fun with a swap partition, multiple partitions with different file systems, file systems distributed across multiple disks and CPU based encryption.
Then comes the application layer. How will it react to true positives let alone false positives?
I am far more terrified of this solution than the problem.