Broadcom opened VMware Explore 2026 in Las Vegas today with the clearest articulation yet of where VMware Cloud Foundation is heading: the Private AI Cloud. After two years of positioning VCF 9 as the modern private cloud platform, the message this year is that private cloud and private AI infrastructure are no longer separate disciplines — they are converging into a single platform. Here's my rundown of everything announced today, and what it means for those of us designing and running these environments.
VMware Private AI Cloud: the new umbrella
The headline announcement is VMware Private AI Cloud, Broadcom's integrated approach to running AI workloads — inference, agentic applications, and traditional enterprise workloads — side by side on infrastructure you own. It brings together VCF 9 as the foundation, the new VMware AI Factory, the VMware Tanzu Platform for agent foundations, vDefend for hypervisor-level microsegmentation, and the brand-new AgentMinder for AI agent governance.
Ram Velaga, president of Broadcom's Infrastructure Software Group, called it "the inflection point where enterprise private cloud and private AI infrastructure stop operating as separate disciplines." The timing is backed by Broadcom's own Private Cloud Outlook 2026 research: 56% of enterprises now plan to run production AI inferencing on their private cloud.
VMware AI Factory: bare metal to inference in hours
For infrastructure architects, VMware AI Factory is the most significant piece. It's a software-defined foundation — included in VCF at no additional cost — that automates the full path from bare metal to a running model. Broadcom claims deployment times drop from weeks to hours. The building blocks:
- Automated AI-ready infrastructure — provisioning and unified lifecycle management that spans hardware and software, with heterogeneous bare metal automation through a MetalSoft integration.
- Model Runtime and a unified Model Gallery — one interface for managing model inference and RAG workflows across VMs, containers, and GPU resources, with new multi-tenant model sharing via isolated namespaces.
- GPU resource pooling — multiple models sharing the same accelerators to improve utilization and control what Broadcom is now calling "AI tokenomics."
- AI Gateway — unified governance across on-prem and cloud endpoints with intelligent prompt routing, token limiting, and rate limiting.
- Secure AI sandboxes — isolated container spaces for executing agent-generated code with proper control layers.
Just as notable is the hardware story. AI Factory pairs VCF not only with NVIDIA but now formally with AMD Instinct GPUs and the ROCm ecosystem, running on certified AI ReadyNodes from Cisco, Dell Technologies, Lenovo, and Supermicro. VMware Chief Product Officer Paul Turner summed it up: customers get "a software-defined foundation that automates infrastructure deployment, unifies lifecycle management, and lets them choose their preferred hardware and vetted models."
Leading AI models, validated on VCF
Broadcom also announced a set of frontier and enterprise models tested and validated to run on VCF:
- NVIDIA Nemotron 3 — multimodal, hybrid Mamba-Transformer architecture, 1M-token context window.
- Google DeepMind Gemma 4 — open-weight multimodal model built for local execution.
- NEC cotomi — Japanese-language model with roughly 40% better token efficiency.
- Alibaba Qwen 3.7-Max — proprietary multimodal model with a one-million-token context window.
- Z.ai GLM 5.2 — open-source model aimed at coding and reasoning agents.
On top of that, VCF supports more than 150 open-source models through the vLLM runtime, with MLPerf Inference v5.1 results showing performance "on par with bare metal" — and mixed compute across AMD, Intel, and NVIDIA hardware. Chris Wolf framed it as "a clear path to data sovereignty and cost-effective AI at scale," which is exactly the conversation I'm having with regulated and government customers every week.
AgentMinder: governance for autonomous agents
AgentMinder — generally available today — is Broadcom's answer to the question every security team is asking: what happens when AI agents start acting on enterprise systems? AgentMinder treats every agent as an enterprise identity with a declared mission, permitted intents, approved tools, and authorized resources. A cloud-native gateway authenticates and authorizes every tool call at runtime against a dynamic policy engine, and OpenTelemetry-based observability delivers compliance-grade audit trails — a "chain of custody" for agent actions.
Broadcom has been running it internally at serious scale: 36 million customer-related and 7 million workforce-related API calls per day, across more than 20 million customer identities. Clayton Donley described it as "a traffic controller" for agents — verifying what they're doing, providing guardrails, and tracking their work.
Tanzu Platform: AI-ready data foundations
The Tanzu team is tackling what Purnima Padmanabhan called the real blocker: "Enterprises do not have an AI ambition problem. They have an agent trust problem." Coming in Fall 2026, the Tanzu Platform adds hardened agent sandboxes with a deny-by-default runtime model (isolating credentials and blocking prompt-injection and unauthorized network access), AI-ready data foundations that process structured and unstructured data on-prem to give agents high-precision context (fewer hallucinations, lower token spend), and governance across three dimensions: access, context, and lineage — so every agentic decision can be traced back to its data sources. A curated marketplace of vetted models and tools plus a Tanzu AI gateway for monitoring, rate limiting, and credential management round it out.
Security hardening: vDefend, Avi, and TrueSource
A few security announcements deserve their own call-out:
- vDefend gains detection of unauthorized shadow AI usage inside the private cloud — a topic close to my heart, as regular readers know.
- Avi Load Balancer adds Agentic Threat Defense, with MCP tool restrictions and real-time threat isolation to prevent agent tool misuse and data exfiltration.
- TrueSource is a new verified open-source portfolio, available today: Trusted Artifacts (secure builds for Java, Python, and Node.js), Data Services (PostgreSQL, RabbitMQ, MySQL, Valkey), alongside the existing Spring Enterprise offering.
Ecosystem momentum
Beyond the product news, colocation provider Flexential announced plans to build AI offerings on VMware AI Factory launching early 2027, combining its infrastructure footprint with hosted Private AI services — an early sign that the AI Factory model will extend beyond enterprise datacenters into the provider ecosystem.
My take
What strikes me most about this year's Explore is coherence. Last year, Private AI Foundation with NVIDIA was an add-on you architected alongside VCF. Today, AI Factory is simply part of the platform — the same VCF domains, the same lifecycle management, the same operational model, now extended from bare metal all the way to model endpoints. For organisations where data sovereignty is non-negotiable, the combination of validated models running at near bare-metal performance, agent governance with a real audit trail, and shadow-AI detection makes the private cloud case stronger than it has ever been.
The multi-vendor accelerator story (NVIDIA and AMD), the model-vendor breadth (from Nemotron to Gemma to Qwen), and the fact that AI Factory ships in VCF at no additional cost all point in the same direction: Broadcom wants the private AI conversation to start — and stay — on VCF. I'll be digging into the AI Factory architecture, Model Runtime, and AgentMinder in detail in upcoming posts and videos as the bits become available.
SOURCES
Broadcom Introduces VMware Private AI Cloud (Aug 31, 2026)
Broadcom Announces VMware AI Factory (Aug 31, 2026)
VMware Cloud Foundation Brings Leading AI Models to the Private AI Cloud (Aug 31, 2026)
Broadcom Unveils AgentMinder (Aug 31, 2026)
Broadcom Unveils AI-Ready Data Foundations in VMware Tanzu Platform (Aug 31, 2026)
VMware Explore 2026 Las Vegas Media Kit — Broadcom
Network World — Private AI cloud, agentic infrastructure dominate VMware Explore


