The Short Answer
At VMware Explore on August 31, 2026, Broadcom shipped agent governance as infrastructure: AgentMinder authorizes every tool call against an agent's declared mission, and VMware vDefend discovers agents by monitoring traffic rather than reading an inventory. The thesis is right β governance belongs below the application. The open question is whose infrastructure it runs on. On ibl.ai you own all the code and the data.
This is a significant validation of an argument that until recently was contrarian: the place to govern AI agents is the platform layer, not each application.
It is also a proprietary stack with a platform dependency attached, and both things are true at once.
What did Broadcom actually announce?
Three distinct components, announced August 31, 2026 at VMware Explore in Las Vegas. Most coverage has merged them, and the differences matter:
AgentMinder is the runtime control plane. It independently verifies agent identity and authorizes each action against the agent's declared mission, intent, context, and current risk before the action reaches an enterprise resource.
Its cloud-native AI gateway secures every tool call at runtime β authenticating tokens, routing traffic exclusively to authorized backends, and evaluating context through a dynamic policy engine.
It provides compliance-grade visibility into every agent session: chain of custody, anomaly detection, and operational insight.
VMware vDefend is the discovery layer. It automatically identifies MCP servers, LLMs, datastores and tools by continuously monitoring traffic flows across VMware Cloud Foundation. Zero Day Attack Detection establishes normal agentic traffic baselines to flag and isolate anomalous behavior.
VMware Tanzu Platform, with vDefend, supplies the deny-by-default architecture, a prebuilt harness, and a curated marketplace.
There is also an isolated credential store that shields credentials from agents entirely β the reasoning being that an agent cannot leak or misuse what it never sees.
Why is discovery-by-traffic the most important part?
Because it is the only honest answer to a question most enterprises cannot currently answer.
Two weeks ago the measurable state of enterprise agent governance was this: 96% of organizations run AI agents and only 12% have implemented a centralized platform to manage them, per OutSystems' survey of 1,900 IT leaders.
SAP's LeanIX survey found less than half have visibility into an agent inventory at all.
An inventory built from a form someone fills in captures the agents whose owners knew to fill in the form. That is precisely the population that was never the risk.
An inventory built from observed traffic captures the agent a contractor stood up against an API key in March. Discovery has to be a measurement, not a submission β and that is a genuinely correct architectural instinct.
The tense is worth noting: vDefend will automatically identify these, which reads as announced capability rather than something you can buy and switch on this afternoon.
What is the buyer actually taking on?
A very good control plane, and a dependency on the platform underneath it.
AgentMinder and vDefend govern agents within VMware Cloud Foundation. The governance is only as portable as the infrastructure it is bolted to β and an agent running outside that estate is outside the control plane.
| Control | Governance bolted to a platform | Governance in a stack you own |
|---|---|---|
| Coverage | Agents inside that estate | Every agent you run |
| Audit log | The platform's, in its schema | Your SIEM, your retention |
| Policy engine | Vendor's, configured by you | Yours, running in your perimeter |
| If licensing changes | Your governance layer reprices | Nothing β perpetual license |
| Model choice per agent | What the platform supports | Any LLM, switchable |
That fourth row is not hypothetical for VMware customers. Licensing and packaging changes have been a live procurement topic since the Broadcom acquisition closed in 2023, and a governance layer is a bad place to discover that your renewal terms moved.
Is this bad for the case for owning your stack?
No β it is the strongest third-party validation of it so far, and it would be dishonest to frame it otherwise.
Broadcom is a serious infrastructure company telling its enterprise customers that agent governance belongs below the application, enforced at runtime, with discovery from observed behavior and an audit trail an examiner can read.
That is the architecture argument, made by someone with no interest in helping us make it.
The disagreement is narrower and it is about ownership, not design. Every principle in this launch is one you should want:
- Identity bound to a declared mission, not a static API key
- Per-tool-call authorization evaluated against live context and risk
- Deny-by-default, so a new capability is not automatically an authorized one
- Discovery from observed traffic, not a form
- Chain of custody detailed enough for compliance
None of that requires a particular vendor's hypervisor. It requires a control plane β and where the control plane runs determines who actually holds the controls.
How does ibl.ai approach the same problem?
ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing β so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.
Applied to agent governance: the registry, the policy engine and the audit log are components you run rather than services you subscribe to. Every agent invocation is written to your own SIEM under your retention rules, and policy is enforced by rules your team authored.
Guardrails are programmable rather than inherited β jailbreak and prompt-injection defense, PII redaction, role-based access control, and network isolation, configured to your risk profile.
And because the platform is model-agnostic, which model an agent may use is itself a governance decision that stays with you, rather than a routing choice made upstream.
1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.
ibl.ai is family-owned and operated from New York, NY β a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
The layer is right; the ownership is the question
The interesting thing about this announcement is not that Broadcom built it. It is that the agent-governance problem has become large enough that infrastructure vendors are shipping control planes for it.
Two weeks ago the numbers said almost nobody could inventory their agents. The answer arriving from the infrastructure layer is the correct answer.
Ask only where that layer lives, and who reprices it.
Related: Agent Sprawl Is a Board Issue. Most Cannot Count Theirs. Β· AI Agent Governance: Managing Autonomous AI Systems Responsibly