Autonomous AI agents are moving from experimental sandboxes into the core of enterprise operations, yet most organizations are unprepared to manage them. While Gartner projects that 40% of enterprise applications will embed task-specific AI agents by the end of 2026, the security infrastructure to govern these digital workers remains largely absent. Data from a CSA/Oasis Security survey reveals that 78% of organizations lack any documented policy for creating or removing AI agent identities, while Okta’s AI Agents at Work 2026 report finds only 34% apply the same security controls to agents as they do to human employees. This creates a significant operational blind spot as agents begin to execute tasks autonomously.
Broadcom is attempting to solve this by embedding governance directly into the compute and networking fabric. At VMware Explore 2026, the company unveiled AgentMinder, a tool bundled into the VMware Private AI Cloud. Rather than treating governance as an optional security layer, Broadcom is positioning it as a fundamental piece of infrastructure. AgentMinder acts as a central control plane and traffic controller, binding an agent’s authority to a specific mission, a set of approved tools, and a defined list of authorized resources. When an agent attempts a task, the system functions as a cloud-native AI gateway, authenticating tokens and ensuring traffic is routed only to authorized backends.
The urgency for these controls is reflected in the Salesforce Agentic Enterprise Index, which tracks a 15% compound monthly growth rate in the action-to-output ratio for agents, alongside a 32% escalation rate. As agents become more active, the potential for unintended consequences grows. Without guardrails, organizations are essentially operating without a map.
Broadcom is testing this model internally, processing approximately 43 million API calls daily across 20 million customer identities and 72,000 workforce identities. According to Broadcom CIO Alan Davidson, this architecture has enabled the company to maintain global scale with zero downtime, even during routine maintenance. By using its own tools, Broadcom provides a practical baseline for how these systems perform under heavy, real-world pressure. The system also leverages OpenTelemetry for observability, providing compliance-grade visibility, chain of custody, and anomaly detection. By integrating with existing authorization stacks via the AuthZEN standard, it avoids the common pitfall of routing all traffic through a single, fragile SaaS chokepoint.
The market is currently splitting into two distinct approaches to this problem. On one side, there is an identity-layer strategy, exemplified by the recent launch of Okta Agent SSO. This approach treats agents as first-class identities within the existing authentication stack, allowing IT teams to manage them alongside human users. On the other side, Broadcom is pursuing an infrastructure-layer strategy. By bundling AgentMinder into the VMware Private AI Cloud—alongside VCF 9, the AI Factory, Tanzu services, vDefend, and the Avi Load Balancer—Broadcom is baking governance into the underlying compute and networking environment.
Clayton Donley, VP and GM of Identity Management Security at Broadcom, describes the role of AgentMinder as a traffic controller that verifies exactly what AI agents are doing, providing the necessary guardrails to track their work. This shift suggests that the industry is moving toward a point where private cloud and private AI infrastructure are no longer treated as separate disciplines. Ram Velaga, President of the Infrastructure Software Group at Broadcom, views this integration as a necessary step toward stability and auditability in an increasingly automated enterprise.
However, there is a practical caveat to this infrastructure-first model. Because AgentMinder is bundled into the VMware Private AI Cloud rather than sold as a standalone product, it requires a commitment to the broader VMware stack. Organizations that have already standardized their AI development on other cloud platforms or disparate toolsets may find it difficult to adopt this specific governance model without significant architectural changes. While the integration offers a unified path for those already within the VMware ecosystem, it creates a clear divide between those who prefer a platform-agnostic identity solution and those who want their governance deeply embedded into their private cloud infrastructure.
As organizations navigate these choices, the focus remains on balancing the speed of AI deployment with the need for control. Whether through an identity-centric approach or an infrastructure-embedded model, the goal is to ensure that as agents take on more responsibility, they remain within their intended scope, preventing the operational risks that come with unmanaged autonomous systems.