---
title: "Model-Agnostic Is Table Stakes. Source Code Isn't."
slug: "microsoft-foundry-model-agnostic-now-what-you-own"
author: "ibl.ai Engineering"
date: "2026-09-28 15:00:00"
category: "Premium"
topics: "model-agnostic AI, Microsoft Foundry, agent platforms, vendor lock-in, self-hosted AI, air-gapped AI, enterprise AI architecture"
summary: "Microsoft Foundry has documented model-agnostic agents for months, and Microsoft even ships a disconnected on-premises agent path. Both are real, and neither is the thing enterprises should be buying on. The question a managed service still cannot answer is whether you receive the source code."
banner: ""
thumbnail: ""
linkedin: |
  We had a line in an earlier draft of this post that was wrong: "a managed cloud vendor structurally cannot run air-gapped."

  Microsoft can — in preview, on approved hardware, and as a narrower product than its cloud one. Azure Local disconnected operations went GA on 24 February 2026, and Agents and Tools with Foundry Local runs an agentic layer — agents, threads, runs, an MCP server, against a Foundry Agents API — on Azure Arc-enabled Kubernetes with no internet connectivity required at deployment time. Its own documented scenarios are government, defense, regional banks and healthcare.

  So if your pitch against a hyperscaler is "they can't come on-prem", update it. Mine needed updating.

  What is actually true is narrower and more durable:

  Foundry Agent Service — the cloud product — is Azure-hosted, and its documentation has said "swap models without changing your agent code" since at least June. Model choice was settled months ago; it is a floor, not a differentiator, and any vendor still leading with it in 2027 is describing the floor.

  The on-prem path is a different product, currently in preview, and it is agentic RAG rather than the full Agent Service surface — no prompt agents, no hosted-agent containers, no Foundry model catalog. It also requires an eligible agreement and approved hardware.

  And through all of it, you do not receive the source code.

  That is the row that does not move. With ibl.ai you own all the code and the data — the whole platform under a perpetual licence on your infrastructure, model-agnostic across any LLM, on any cloud, in your VPC, on-premise, or fully air-gapped.

  Being able to change your model is not the same as being able to leave.

  #iblai #AgenticAI #EnterpriseAI #ModelAgnostic #SelfHostedAI
---

## The Short Answer

**Model-agnosticism is settled: Microsoft Foundry has documented "swap models without changing your agent code" for months, and Microsoft even ships a preview on-premises agent path that runs disconnected. Neither is the differentiator any more. The question a managed service still answers "no" to is whether you receive the source code — and on ibl.ai you own all the code and the data.**

We made this mistake in an earlier draft of this post: that a managed cloud vendor structurally cannot go air-gapped. It is wrong, it is checkable, and getting it wrong is how a good argument loses to a bad one in a bake-off.

## Has Microsoft Foundry actually committed to model-agnostic agents?

Yes, and not recently. Foundry Agent Service is documented as a managed platform where you build "with any framework, any supported model from the Foundry model catalog," and where you can **"swap models without changing your agent code."**

That sentence about swapping models was already on the page in **June 2026**, together with the same five supported SDKs — Microsoft's own Agent Framework, LangGraph, the OpenAI Agents SDK, the Anthropic Agent SDK and the GitHub Copilot SDK — and the same catalog spanning GPT-4o, Llama and DeepSeek.

So nothing was conceded this month. Model choice on the largest enterprise cloud has been a documented default for a while, which is the real news: a capability shipped by default on Azure is a floor, not an edge.

## Then is model-agnosticism worth paying for?

No. It is worth checking for, and then moving past.

When only a handful of platforms could run any model, picking one of them was a strategic decision. Now every serious platform will claim it within a year and most will be telling the truth.

This is the ordinary lifecycle of a feature — differentiator, then expectation, then assumption — and model-agnosticism is somewhere past the second stage.

A vendor still leading with "we are model-agnostic" as its headline in 2027 will be describing the floor. We include ourselves in that: it is on our list because buyers still ask, not because it separates anyone.

## Can a managed cloud platform run on-premises or air-gapped?

Yes — and this is the part most competitive decks get wrong, including ours until we checked.

**Azure Local disconnected operations** reached general availability on **24 February 2026**, [announced by Microsoft](https://blogs.microsoft.com/blog/2026/02/24/microsoft-sovereign-cloud-adds-governance-productivity-and-support-for-large-ai-models-securely-running-even-when-completely-disconnected/) as part of Sovereign Private Cloud, putting a local control plane inside a network with no public-cloud connection. On top of it, **Agents and Tools with Foundry Local** — the platform whose core is the Azure Arc-enabled Kubernetes extension Microsoft calls Agentic Retrieval in Foundry Local — "extends AI reasoning and grounding capabilities to on-premises, distributed, and disconnected environments that you manage through Azure Arc."

It is not a thin retrieval shim, either. It ships a real agentic layer: agents that reason over instructions and invoke tools, threads, runs, a built-in MCP server, and a chat UI that "communicates with the agents runtime through the **Foundry Agents API**."

Microsoft's own named scenarios are a government customer with sensitive local data, a regional bank under regulatory constraint, a manufacturer, a healthcare provider and an energy company.

If your evaluation of a hyperscaler rests on "they cannot come to our facility," that evaluation is out of date.

## So what are the real limits of that on-prem path?

Four, and they are worth stating precisely rather than dismissively.

<table style="width:100%; border-collapse:collapse; margin:1.5rem 0; font-size:0.95rem;">
  <thead>
    <tr style="background:#f5f5f0; border-bottom:2px solid #2175C5;">
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Question</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Microsoft</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">ibl.ai</th>
    </tr>
  </thead>
  <tbody>
    <tr style="border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;">Can you change models?</td><td style="padding:0.75rem;">Yes — "swap models without changing your agent code"</td><td style="padding:0.75rem;">Yes — model-agnostic across any LLM</td></tr>
    <tr style="border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;">Who manages the compute?</td><td style="padding:0.75rem;">Foundry. Prompt agents: "None, fully managed". Hosted agents: "Container compute, Foundry-managed"</td><td style="padding:0.75rem;">You do</td></tr>
    <tr style="border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;">Can it run disconnected?</td><td style="padding:0.75rem;">Yes — but via a <em>different</em> product (Agentic Retrieval in Foundry Local), in <strong>preview</strong>, on approved Azure Local hardware</td><td style="padding:0.75rem;">Yes — the same platform, generally available</td></tr>
    <tr style="border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;">Is it the full agent product?</td><td style="padding:0.75rem;">No — a reduced surface: agentic RAG, no hosted-agent containers, and models come from Foundry Local or a BYOM endpoint rather than the Foundry catalog</td><td style="padding:0.75rem;">Yes — one platform everywhere</td></tr>
    <tr style="background:#f0f9ff; border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;"><strong>Do you receive the source code?</strong></td><td style="padding:0.75rem;"><strong>No</strong></td><td style="padding:0.75rem;"><strong>Yes — perpetual licence</strong></td></tr>
  </tbody>
</table>

Rows three and four are the kind of gap that closes — preview becomes GA, feature parity arrives, hardware lists lengthen. Anyone betting a procurement decision on "it is only in preview" is betting against a roadmap.

Row two never closes, for the same reason the last row doesn't. Foundry will not hand you compute management, because that is what "managed service" means. Row one is not a gap at all; it is parity, and it was settled months ago.

## Why does the source-code row not move?

Because it is not a feature, it is the business model.

A managed service can bring its control plane to your facility, run with no egress, and hand you every isolation control you ask for — and you still cannot read the orchestration logic, cannot fork it, cannot keep running it if the terms change, and cannot audit what it actually does as opposed to what it is documented to do.

That is not a criticism of Microsoft. It is the definition of a service. The reason to notice it is that once model choice and even disconnected operation stop separating vendors, this is what is left, and it is the question least likely to appear in a feature matrix.

Worth asking in procurement:

- Do we receive the source code, under what licence, and for how long?
- If the vendor is acquired, repriced, or discontinues the product, what do we still have?
- Can we read what the orchestration layer does, or only what it is documented to do?
- Is the disconnected version the *same* product, or a reduced one?

Being able to change your model is not the same as being able to leave.

## Where does ibl.ai actually differ?

The whole platform is the deliverable, not access to it.

On ibl.ai you own all the code and the data. The platform runs under a perpetual licence on your own infrastructure, and it is model-agnostic across any LLM — including an open-weight model running entirely inside your own network with no external inference call.

Pricing is usage-based with no per-seat pricing, and you can deploy anywhere: your cloud, your VPC, on-premise, GovCloud, or fully air-gapped — as the same product, not a reduced edition of it.

More than 1.6M users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.

Microsoft is right that you should not bet your architecture on one model. We would add only this: check what you are left holding if you stop paying.

*Sources: model, framework and compute descriptions from [Microsoft's Foundry Agent Service overview](https://learn.microsoft.com/en-us/azure/foundry/agents/overview); the on-premises agentic layer, its preview status and the customer scenarios from [Agents and Tools with Foundry Local](https://learn.microsoft.com/en-us/azure/azure-arc/agents-tools-foundry-local/overview); the disconnected capability from [Azure Local disconnected operations](https://learn.microsoft.com/en-us/azure/azure-local/manage/disconnected-operations-overview), and its February 2026 GA from [Microsoft's Sovereign Cloud announcement](https://blogs.microsoft.com/blog/2026/02/24/microsoft-sovereign-cloud-adds-governance-productivity-and-support-for-large-ai-models-securely-running-even-when-completely-disconnected/).*

*Related: [Cohere Alternative: Model-Agnostic and Self-Hosted](/blog/cohere-alternative-model-agnostic) — the same two axes applied to the vendor whose positioning is closest to ours.*

## Why does owning the AI stack matter?

**ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing — so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.**

- **You own all the code and the data.** Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform — the stack itself is yours.
- **Model-agnostic.** Run any LLM — Claude, GPT, Gemini, Llama, Command, or your own fine-tune — and switch providers without rewriting the platform.
- **No per-seat pricing.** Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.
- **Deploy anywhere.** Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
