Broadcom adds AI-ready data foundations to VMware Tanzu Platform
- Broadcom announces AI-ready data foundations for VMware Tanzu Platform at VMware Explore 2026
- New features include hardened agent sandboxes, governed data access, and a curated marketplace
- Update complements earlier launch of VMware Private AI Cloud and AgentMinder for agentic governance
- Tanzu Platform capabilities will be generally available in Fall 2026

*this image is generated using AI for illustrative purposes only.
Broadcom Inc. (NASDAQ: AVGO) announced new AI-ready data foundations for the VMware Tanzu Platform at VMware Explore 2026 in Las Vegas on August 31, 2026. The update positions Tanzu as the official agent platform for VMware Private AI Cloud.
The release aims to solve the "agent trust problem" by securing both the agent and the underlying data. It enables enterprises to transition from initial AI pilots to production-ready agents within their private clouds.
Tanzu Platform Capabilities
The latest release introduces five key capabilities to govern agentic AI operations:
- Hardened Agent Sandboxes: Enforces a deny-by-default security model that isolates credentials to prevent prompt injection and unauthorized network access.
- AI-Ready Data Foundations: Processes structured and unstructured enterprise data on-site to improve accuracy, reduce hallucinations, and lower token costs.
- Out-of-the-Box Developer Harness: Accelerates build times with pre-approved skills, workflow buildpacks, human-in-the-loop controls, and memory services.
- Curated Marketplace: Provides a centralized catalog for developers and agents to discover vetted AI models, tools, and data products.
- Auditable Agent Governance: Integrates an AI gateway to monitor, rate-limit, and log every agent action for compliance.
Data Governance and Security
The platform addresses risks such as data leakage, unexpected cloud egress fees, and inaccurate outputs. Agents run in hardened sandboxes with isolated credentials and explicit connections to services.
Data governance focuses on three pillars:
- Access: Ensures agents reach only the right data.
- Context: Prepares data efficiently before consumption to improve accuracy and reduce token costs.
- Lineage: Traces every agentic decision to its specific data source for auditability.
Existing Infrastructure and AgentMinder
This announcement complements Broadcom’s earlier launch of VMware Private AI Cloud and AgentMinder at the same event. That suite unifies private cloud infrastructure with secure, governed AI agent operations.
Cost and Infrastructure Efficiency
VMware Cloud Foundation (VCF) 9 reduces hardware costs through NVMe memory tiering and cluster-wide storage deduplication. It supports heterogeneous clusters using GPUs, CPUs, and accelerators from various vendors.
Key infrastructure innovations include:
- VMware AI Factory: Automates deployment of AI-ready infrastructure and Day 2 operations to accelerate time to first model deployment.
- Model as a Service: Enables VCF customers to run more than 150 open source and commercial models, including Nemotron 3, Gemma 4, cotomi, Qwen 3.7-Max, and GLM 5.2.
Security and Compliance
Designed with a defense-in-depth approach aligned to NIST CSF 2.0, the platform minimizes attack surfaces and enables continuous compliance. Automated updates keep systems current without disruption.
Security features include:
- TrueSource by Broadcom: Provides verifiably built open source artifacts for Java, Python, Node.js, PostgreSQL, RabbitMQ, MySQL, and Valkey.
- vDefend Enhancements: Extends Zero Trust lateral security for agentic AI by monitoring traffic flows and detecting unauthorized shadow AI usage.
- Avi Load Balancer: Protects agentic workloads by restricting access to unauthorized tools and preventing data exfiltration.
Agentic AI Governance with AgentMinder
Broadcom unveiled AgentMinder, a solution that acts as a traffic controller for autonomous AI agents. It independently verifies agent identity and authorizes each action against declared mission, intent, context, and current risk before the action reaches an enterprise resource.
AgentMinder closes the operational trust gap in agentic AI through:
- Identity and intent: Treats agents as enterprise-grade identities, binding authority to declared missions, permitted intents, approved tools, and authorized resources.
- Runtime enforcement: Secures every tool call at runtime via a cloud-native AI gateway, authenticating tokens and directing traffic exclusively to authorized backends based on dynamic policy evaluation.
- Observability and audit: Built on OpenTelemetry, it provides compliance-grade visibility into every agent session, delivering chain of custody, anomaly detection, and operational insight.
AgentMinder integrates with existing authorization stacks via the AuthZEN standard, allowing organizations to reuse current policy enforcement endpoints without routing traffic through a single SaaS chokepoint. It is deployed alongside large language models (LLMs) on-premises, in virtual private clouds (VPCs), or across public cloud environments.
Scale and Internal Adoption
Broadcom uses AgentMinder internally to power its own AI agentic pipeline. The multi-region, active-active architecture supports continuous uptime and handles peak loads of nearly 36 million customer-related and seven million workforce-related API calls daily.
Alan Davidson, CIO at Broadcom, stated that AgentMinder enabled company-wide deployment of their AI agentic pipeline by providing chain of custody capabilities between developers and multiple agents or skills. The system delivers high-availability, low-latency connections for over 20 million customer identities and 72,000 workforce identities.
What the Numbers Show
The platform supports more than 150 distinct AI models, indicating a broad compatibility strategy rather than reliance on a single proprietary model ecosystem. This diversity allows enterprises to choose between open source and commercial options like Nemotron 3 and Qwen 3.7-Max while maintaining data sovereignty.
Internally, Broadcom’s use of AgentMinder demonstrates significant scale, processing nearly 36 million customer-related API calls daily. This volume underscores the operational necessity of runtime enforcement and observability when deploying autonomous agents across millions of identities.
Availability and Customer Validation
Capabilities announced here will be generally available in Tanzu Platform in Fall 2026.
Business Development Bank of Canada (BDC) used VMware Tanzu Platform to support internal business applications since 2019. Marie-Claude Potvin, Assistant Vice President at BDC, noted the platform helped standardize deployment and management across teams, reducing manual processes and operational overhead.
Rachel Stephens, Research Director at RedMonk, stated that platforms making data access governed, curated, and auditable by default turn the fear of unintended consequences into something manageable. Purnima Padmanabhan, Vice President and General Manager of Tanzu Division at Broadcom, emphasized that enterprises have an agent trust problem, not an AI ambition problem.
How will Broadcom's 'deny-by-default' security model impact the development velocity and operational costs for enterprises transitioning from AI pilots to production?
What competitive advantages does VMware's support for over 150 heterogeneous models provide against cloud providers that are pushing proprietary, closed-ecosystem AI solutions?
Given the high volume of API calls processed internally by Broadcom, what are the projected latency implications of AgentMinder's runtime enforcement for real-time agentic workflows in customer environments?
































