Thanks for your post.
Sometimes AV software doing scans, Search crawlers (Google desktop or similar), Sharepoint crawlers, ect may be doing read on all files to search / scan / index them.
The GXHSMService log will show the process doing the recall if its local:
1692 7f8 06/12 14:50:15 ### RecallFile(1304): -Debug-: Process Name :notepad.exe; pid=3344;uid=0;sid=1;<-UserID->=ADVANCED\ted;File=C:\DataToArchive\Archived_Data\PrePostInstall.
If the request comes in to the server over a UNC path, this will always show SYSTEM as the process since the local server service is what does the recall. In this case the customer will need to monitor the network traffic to see what remote machine/software is reading the files on the share. There is no workaround for this since we cannot filter out the SYSTEM process as this would break all recalls.