{"slug": "broadcom-says-that-enterprise-ai-agents-need-two-things-data-they-can-trust-and", "title": "Broadcom says that enterprise AI agents need two things: Data they can trust and boundaries they can’t cross", "summary": "Broadcom introduced a secure, AI-ready data foundation in the VMware Tanzu Platform at VMware Explore, designed to help enterprises deploy production-ready AI agents with strict security controls and trusted data access. The platform, integrated into VMware Cloud Foundation, offers agent sandboxes with deny-by-default containment, credential isolation, and a curated marketplace for vetted models and data products, according to Purnima Padmanabhan, GM of Broadcom's Tanzu Division.", "body_md": "For enterprises deploying AI agents, security and trust are top-of-mind issues. When given the authority to act autonomously, they can inadvertently leak or expose data, rack up huge token costs, or produce inaccurate or patently false outputs. These risks, says VMware, require a new type of platform that imposes strict controls over what agents can do, while giving them access to the contextually-relevant data they need.\n\nWith this in mind, Broadcom has introduced a new secure, AI-ready data foundation in the VMware Tanzu Platform that it says addresses these needs. Announced today at [VMware Explore](https://www.networkworld.com/article/4215847/private-ai-cloud-agentic-infrastructure-dominate-vmware-explore.html), the offering is intended to help enterprises move beyond pilot purgatory to production-ready agents.\n\nIt isn’t a new data platform, or a new feature that customers must deploy, noted [Adam Reeves](https://my.idc.com/getdoc.jsp?containerId=PRF005917), a research director at IDC. Instead, the VMware team “built the missing plumbing between the data enterprises already have and the agents that need it.”\n\nIntegrated directly into VMware Cloud Foundation (VCF), the updated Tanzu Platform features an “[AI-ready](https://www.infoworld.com/article/4214584/why-enterprise-ai-projects-keep-failing.html)” data infrastructure, [Purnima Padmanabhan](https://www.broadcom.com/company/about-us/executives/purnima-padmanabhan), GM of Broadcom’s Tanzu Division, explained during a briefing. Structured and unstructured data can be processed within a customer’s private cloud, and remain in that environment, and multimodal data ingestion, parsing, and semantic layering give agents context.\n\nBuilders also get an out-of-the-box developer harness featuring pre-approved skills, step-by-step buildpacks, persistent memory capabilities, and customizable human-in-the-loop controls. Enterprises can provision an agent either with a single click or via a command line interface (CLI), Padmanabhan said.\n\nA curated marketplace serves as a centralized catalog where developers can access vetted AI models, data products, and Model Context Protocol (MCP) servers, she said. The platform supports VCF models, public cloud, and other specialized models, as well as Python and Java frameworks.\n\nTo address the security question, the Tanzu Platform offers agent sandboxes that allow for deny-by-default containment that isolates credentials. “[An agent] cannot connect to anything unless it’s explicitly given the permission,” Padmanabhan explained. “Explicit routes and bindings prevent lateral movement.”\n\nAgents aren’t given API keys or blind access; they can only touch a “curated data product that is consistently kept in sync,” she said, adding, “We have deepened our sandbox capabilities, separated out our credential management capabilities, and we are adding this built-in harness.”\n\nUsers can also see lineage and follow agent prompts, tool calls, and accessed resources; they also get insight into [failures or other issues](https://www.infoworld.com/article/4211198/when-an-ai-agent-goes-off-the-rails-file-a-bug-to-fix-the-documentation-then-test-the-fix.html). Along with this, the platform features an integrated gateway so users can monitor individual agents and attribute actions taken and token usage.\n\nAs AI agents become integrated into day-to-day workflows, enterprises should be focused on time to value, Padmanabhan noted: “How quickly can you go from idea to execution?”\n\nWith pre-built agent harnesses built into the Tanzu Platform, users don’t have to learn how to orchestrate or build agent loops, she said; they define their intent via a simple MD file and push to production. Capabilities like memory loops and built-in caching help improve performance, and agents can be designed to talk to and call each other in the right sequence, with the right credentials.\n\n“How the agent gets deployed, where it gets deployed, how it scales out, and how, in a secure way, it connects to tools, skills, services, and other agents, is all controlled by the bind capability within the platform,” Padmanabhan noted.\n\nShe explained: “The idea would be, if I’m building an agent and I’ve got three sources, I shouldn’t have to go and build a whole data lakehouse for that.” Rather, she said, builders can point to required sources, and, in the background, the platform deploys the right-sized environments. “The agent building process becomes much, much faster.”\n\nShe added that with AI-ready data foundations, customers don’t need to worry about how data is configured or organized; Tanzu automatically organizes it based on type. “We put the data wherever it needs to be for the most efficient access,” Padmanabhan noted. “You simply point to your data sources, start ingesting them.”\n\nShe pointed to VMware’s strong data expertise, and said the platform is based on technology built into [Tanzu Data Intelligence](https://www.infoworld.com/article/4046114/broadcom-launches-vmware-tanzu-data-intelligence-and-tanzu-platform-10-3-to-drive-agentic-ai.html): “The warehouse, the bringing together of structured and unstructured data, the cleansing, the vectorization, then providing an MCP gateway: we know how to run these sandbox services at scale and use them for business applications in production,” she said.\n\nThe new capabilities will be generally available in the Tanzu Platform in the next few months.\n\nThe VMware Tanzu Platform is an evolution of sorts of the company’s existing Tanzu Data Intelligence offering, IDC’s Reeves explained. The latter was a standalone data lakehouse that worked well, “but forcing a complete architecture migration just to start building AI agents was a potential obstacle.”\n\nThe AI-ready data foundation built directly into the Tanzu Platform overcomes this, he said: It doesn’t move data; it parses it where it already lives, adds a semantic layer, and applies policy and lineage controls all in one product. Agents can then easily plug in using an embedded MCP server.\n\nArchitectural choices are what set the platform apart, Reeves noted. The agent runtime locks everything down by default; all network and API access is blocked until explicitly allowed, and the platform has an isolated credential store.\n\n“Tanzu’s bet is you shouldn’t have to trust the agents,” he said. “Deny-by-default and isolated credentials are the same instincts that made its app platform predictable and dependable.”\n\nAdditionally, the offering doesn’t lock builders into a single framework. Spring AI, LangChain, Goose, Claude Code, and Broadcom’s own harness all run safely inside the same governed sandbox. This is in contrast to standard agent frameworks that default to open access, Reeves pointed out.\n\nThus, the Tanzu platform is a good fit for enterprises processing sensitive documents where data residency and decision auditability are non-negotiable, he said. For instance, in sectors like insurance, healthcare, and legal, where strict regulations dictate these rules. But non-regulated industries have nearly identical needs for different reasons; for instance, manufacturers must guard trade secrets and retailers have to protect customer data.\n\nThey “care just as much about lineage and security, even if their main driver is IP protection or customer trust rather than a regulatory fine,” Reeves said.\n\n“This also taps right into the sovereign cloud conversation,” he added. Broadcom built the storage layer for localized data processing and backed it with federal-grade security standards like [FIPS 140-3](https://csrc.nist.gov/pubs/fips/140-3/final) and [STIG](https://csrc.nist.gov/glossary/term/security_technical_implementation_guide).\n\n“That means your agents can work with enterprise data entirely behind your own firewall,” Reeves said. This is particularly important for companies seeking what he called “the power of AI without handing data residency over to public hyperscalers.”", "url": "https://wpnews.pro/news/broadcom-says-that-enterprise-ai-agents-need-two-things-data-they-can-trust-and", "canonical_source": "https://www.infoworld.com/article/4216658/broadcom-says-that-enterprise-ai-agents-need-two-things-data-they-can-trust-and-boundaries-they-cant-cross.html", "published_at": "2026-09-01 00:33:42+00:00", "updated_at": "2026-09-01 00:51:27.461563+00:00", "lang": "en", "topics": ["ai-agents", "ai-products", "ai-infrastructure", "ai-safety"], "entities": ["Broadcom", "VMware Tanzu Platform", "VMware Cloud Foundation", "Purnima Padmanabhan", "VMware Explore", "IDC", "Adam Reeves", "Model Context Protocol (MCP)"], "alternates": {"html": "https://wpnews.pro/news/broadcom-says-that-enterprise-ai-agents-need-two-things-data-they-can-trust-and", "markdown": "https://wpnews.pro/news/broadcom-says-that-enterprise-ai-agents-need-two-things-data-they-can-trust-and.md", "text": "https://wpnews.pro/news/broadcom-says-that-enterprise-ai-agents-need-two-things-data-they-can-trust-and.txt", "jsonld": "https://wpnews.pro/news/broadcom-says-that-enterprise-ai-agents-need-two-things-data-they-can-trust-and.jsonld"}}