Broadcom adds AI-ready data foundation to VMware Tanzu to scale enterprise agents
New 'deny-by-default' security sandboxes aim to move autonomous AI agents from pilot to production.
Broadcom has launched a secure, AI-ready data foundation integrated into the VMware Tanzu Platform to help enterprises deploy autonomous AI agents. Announced at VMware Explore, the offering aims to solve the security and data reliability hurdles that currently keep many corporate AI projects in the pilot phase.
The new foundation centers on a "deny-by-default" security model. The platform utilizes containment sandboxes that isolate credentials and block all network and API access unless explicitly permitted. This ensures that an agent cannot connect to any resource unless it is granted specific permission, shifting the security burden from the AI agent to the infrastructure itself.
To streamline development, Broadcom included a "developer harness" featuring buildpacks, persistent memory, human-in-the-loop controls, and pre-approved skills. The underlying infrastructure supports semantic layering and multimodal data ingestion, enabling agents to access both structured and unstructured data within a private cloud environment. For developers, the platform maintains compatibility with several major frameworks, including LangChain, Spring AI, Claude Code, and Goose.
Solving the Trust Gap
Many enterprises currently face "pilot purgatory" when deploying AI agents due to risks involving hallucinations, high token costs, and potential data leakage. Broadcom is addressing this by evolving its Tanzu Data Intelligence offering into a more integrated component of the Tanzu Platform, reducing the need for costly architecture migrations.
This strategy is based on the premise that organizations should not have to trust the agents themselves, but rather the platform governing them. By enforcing strict boundaries to prevent unauthorized lateral movement and data leaks, Broadcom intends to make autonomous agents viable for highly regulated sectors, including legal, insurance, and healthcare, as well as firms protecting proprietary intellectual property.
Federal-Grade Compliance
To meet the requirements of sovereign clouds and government entities, the platform adheres to rigorous security standards. Broadcom confirmed the foundation meets FIPS 140-3 and STIG standards, providing the federal-grade security necessary for public sector adoption.
As enterprises move toward more autonomous operations, the focus will shift toward how these agents interact with private data at scale. The industry will be watching to see if this platform-centric trust model successfully reduces the friction of moving AI from experimental sandboxes into mission-critical production environments.