Broadcom Adds Governed AI Agents to VMware Private AI Cloud: Will Large Companies Bring Sensitive Workloads Back On-Premises?
See how Broadcom's governed AI agents for VMware Private AI Cloud may influence on-premises adoption, data control, compliance, security and enterprise AI costs

Broadcom's VMware Private AI Cloud strengthens the case for selective AI workload repatriation, not a wholesale retreat from public cloud. For large Sydney and NSW organisations, sensitive inference, retrieval and agent workflows may move closer to enterprise data where privacy, predictable utilisation, latency and auditability justify it.
Public cloud will remain attractive for burst capacity, frontier models and experimentation. The real decision is workload placement, operating capability and governance, not ideology.
Broadcom's latest VMware announcements are important because they address one of the less glamorous questions in enterprise artificial intelligence: where should the workload actually run once an AI experiment becomes operational infrastructure?
At VMware Explore 2026, Broadcom introduced VMware Private AI Cloud as a platform for running inference workloads, agentic applications and traditional enterprise workloads within a private-cloud operating model. VMware AI Factory is positioned as its infrastructure foundation, while VMware Tanzu Platform is being developed as the official agent platform for the environment.
The announcements also extend beyond model hosting. Broadcom is adding hardened agent sandboxes, governed data foundations, agent observability, model gateways and runtime controls intended to regulate which resources autonomous agents can reach and what actions they can perform.
That makes this more consequential than another private-LLM launch.
The emerging enterprise question is whether AI will reverse part of the migration pattern that dominated corporate technology for the previous decade. Instead of moving another application into a hyperscale cloud, could organisations begin moving high-volume, sensitive and operationally important AI inference closer to their own data?
For Sydney enterprises, the answer is increasingly likely to be yes for selected workloads, but not for everything.
Broadcom Is Building A Return Path, Not Arguing That Public Cloud Is Finished
The distinction matters.
"Private AI" is sometimes discussed as though an organisation faces only two choices: send its information to a public AI service or install a model on servers in the basement.
Enterprise infrastructure is considerably more complicated.
A large organisation may operate AI across:
- Its own data centre
- Colocation infrastructure
- A managed private cloud
- A sovereign or dedicated hosting environment
- A virtual private cloud
- Public-cloud GPU infrastructure
- Managed model APIs
- Edge systems located close to operational equipment or users
Broadcom itself reinforces this distinction. AgentMinder, its newly announced agent identity and runtime-governance product, is designed to operate beside models across on-premises infrastructure, virtual private clouds and public-cloud environments.
In other words, even the company making a strong case for private AI is building governance that can span more than one deployment location.
That is a useful signal for CIOs. The likely end state is not another monoculture. It is a controlled portfolio of infrastructure locations selected according to the workload.
The Enterprise Decision Is Becoming A Workload-Placement Exercise
The most useful question for a Sydney bank, insurer, health organisation, legal group, property enterprise or government supplier is therefore not, "Should we move AI on-premises?"
It is: which AI workload belongs where?
- Internal retrieval over confidential corporate documents
- Likely infrastructure preference: Private cloud or tightly governed hosted environment.
- Why: High data sensitivity and persistent retrieval traffic.
- Critical condition: Strong identity, document permissions and retrieval controls.
- Agent acting on finance, HR or operational systems
- Likely infrastructure preference: Private or highly controlled hybrid environment.
- Why: Agent actions may modify consequential enterprise records.
- Critical condition: Runtime authorisation, auditability and least privilege.
- Large, predictable inference workload
- Likely infrastructure preference: Potential private-cloud candidate.
- Why: Consistent utilisation may justify owned capacity.
- Critical condition: Hardware must remain sufficiently utilised.
- Short experimental project
- Likely infrastructure preference: Public cloud or managed API.
- Why: Avoids buying capacity before demand is proven.
- Critical condition: Sensitive information must be appropriately controlled.
- Highly variable or seasonal AI workload
- Likely infrastructure preference: Public or hybrid cloud.
- Why: Elastic infrastructure can absorb demand spikes.
- Critical condition: Usage and egress costs require monitoring.
- Frontier-model experimentation
- Likely infrastructure preference: Managed cloud service.
- Why: Fastest access to new model capability.
- Critical condition: Use case and data classification must permit external processing.
- Latency-sensitive operational inference
- Likely infrastructure preference: Private cloud or edge.
- Why: Processing closer to the application may reduce network dependency.
- Critical condition: Local resilience and capacity planning.
This is why an AI readiness assessment for Sydney organisations should increasingly include infrastructure placement, not just model selection, data quality and process readiness.
Why Sensitive AI May Move Closer To The Data
Broadcom describes its private-AI strategy as bringing the model to the data rather than continually taking enterprise data to a remote model.
There is a practical argument behind that language.
Retrieval-augmented AI and autonomous agents can generate extremely active relationships with enterprise information. A traditional application might read a customer record when an employee opens it. An AI agent may retrieve multiple documents, search policy libraries, query databases, invoke tools, compare records, write new information and repeat those operations across thousands of tasks.
That creates what infrastructure teams often describe as data gravity. The larger, more sensitive and more frequently accessed the information estate becomes, the more expensive and operationally awkward it can be to continually move information between environments.
Private inference can become attractive where the organisation already controls substantial data infrastructure and the AI workload repeatedly operates against it.
Examples might include:
- Analysing years of internal engineering records
- Searching confidential legal matters
- Reviewing customer or employee information
- Operating against proprietary research
- Processing internal software repositories
- Supporting sensitive financial workflows
- Analysing operational technology data
- Running agents across internal enterprise applications
The stronger the connection between AI and proprietary enterprise information, the more infrastructure placement becomes part of data architecture.
But Private AI Does Not Make The Operating Cost Disappear
This is where the discussion needs considerably more discipline.
Elyment has previously examined the economics of running smaller agentic models locally. Large-enterprise private AI introduces a different cost structure.
Public cloud converts much of the infrastructure problem into consumption expenditure. Private AI converts more of it back into capacity planning.
A credible financial model needs to include:
- GPU and CPU acquisition
- Storage
- High-performance networking
- Rack and data-centre capacity
- Electricity and cooling
- Hardware maintenance
- Virtualisation and platform licensing
- Model-management infrastructure
- Cybersecurity tooling
- Backup and disaster recovery
- Platform engineering staff
- 24-hour operational support where required
- Hardware replacement cycles
- Unused capacity
- The cost of expanding when demand exceeds forecasts
Owning GPUs can produce predictable economics when utilisation is high. Owning expensive accelerators that spend much of the day idle can produce the opposite result.
This is why token price alone is becoming a poor measure of enterprise AI cost.
A private model may not generate a supplier invoice for every million tokens, but those tokens still consume electricity, compute capacity, memory, storage, support time and equipment life.
Organisations considering private enterprise AI need to compare cost per completed business workload, not simply API price against server purchase price.
Broadcom's Repatriation Numbers Are Significant, But They Need Context
Broadcom's Private Cloud Outlook 2026 provides evidence that enterprise infrastructure sentiment is changing.
Its survey of 1,800 senior IT decision-makers across eight countries found that 56 per cent of respondents were running or planning production AI inference in private cloud. It also reported that 83 per cent were considering repatriating workloads from public to private cloud and that half had already moved at least some workloads.
Those numbers should be read with an important qualification: the research was conducted in partnership with Broadcom and supports a commercial market in which Broadcom participates.
It is therefore useful evidence of enterprise sentiment, not a neutral forecast that every organisation should migrate.
The more interesting part is the reason respondents gave for reconsidering placement. Security and compliance remained important, while cost predictability and performance were also prominent.
That is consistent with a broader maturation of cloud strategy.
Enterprises are increasingly moving away from treating "cloud first" as a universal architecture rule. The question is shifting towards which operating environment provides the most suitable combination of control, economics, performance and flexibility for each workload.
Governed Agents Make Infrastructure Placement More Consequential
The agent layer changes the calculation again.
A conventional AI assistant may receive a prompt and generate an answer. An enterprise agent may retrieve information, make a decision, invoke a tool and change a live system.
Broadcom's new Tanzu capabilities are aimed at this operating problem. Announced features include hardened sandboxes with isolated credentials, governed data access and lineage, curated model and tool catalogues, human-review controls and an AI gateway capable of monitoring and rate-limiting agent activity.
Some of the newly announced Tanzu capabilities are scheduled for general availability later in 2026, which matters for procurement teams comparing roadmap statements with deployable capability.
AgentMinder, separately announced as generally available, is designed to evaluate agent identity, declared intent, permitted tools and runtime context before an action reaches an enterprise resource.
This points towards a more mature enterprise architecture.
Instead of trusting an agent simply because it runs inside the corporate network, the organisation treats the agent as another identity whose authority must be continuously constrained.
That principle should survive regardless of whether the underlying model runs in a Sydney data centre, a private hosting facility or public cloud.
Physical possession of the infrastructure is not the same as governance of the workload.
For NSW Organisations, Data Location Does Not Replace Privacy Or Assurance
Australian organisations should be particularly careful about treating on-premises AI as an automatic compliance solution.
The Office of the Australian Information Commissioner makes clear that Australian privacy obligations continue to apply when AI systems handle personal information. Organisations still need to consider why the information is being used, who can access it, whether the processing is appropriate and how the resulting information is managed.
Keeping a model in an Australian data centre may reduce some data-transfer risks. It does not remove obligations relating to collection, use, disclosure, security, accuracy or accountability.
NSW Government agencies face another layer. The NSW AI Assessment Framework is mandatory across NSW Government agencies and was updated in 2026 to address newer capabilities including agentic AI. It requires AI risk to be considered through the project lifecycle rather than only at procurement.
The Australian Signals Directorate's Australian Cyber Security Centre has also advised organisations introducing agentic AI to proceed incrementally, maintain strong identity and privilege controls, establish ongoing monitoring and avoid giving agents unrestricted access to sensitive systems.
These principles create an important lesson for private enterprise too.
Moving inference behind the corporate perimeter can change the risk profile. It does not remove the need to govern the agent, its data or the business process it affects.
Repatriating AI Is A Project Programme, Not A Server Migration
The organisations most likely to struggle with private enterprise AI will be those that treat the project as infrastructure procurement first and workflow design second.
A more defensible sequence is:
- Map the workload. Identify what the AI actually does, what information it reads, which systems it reaches and whether it can take action.
- Classify the information. Separate public, internal, confidential, personal, sensitive and regulated data before choosing deployment architecture.
- Measure current consumption. Establish token demand, concurrency, storage movement, latency requirements, egress and existing cloud spend.
- Model several placement options. Compare public cloud, dedicated cloud, colocation, private cloud and hybrid designs rather than forcing a binary choice.
- Design the control plane. Define identity, permissions, model access, retrieval rules, tool authority, monitoring and human approval before agents receive production access.
- Pilot a bounded workload. Validate utilisation, reliability, output quality, support effort and real operating cost before purchasing capacity for the entire organisation.
- Design the run-state before migration. Determine who patches the stack, monitors models, responds to incidents, replaces hardware, manages capacity and executes disaster recovery after consultants leave.
This is where enterprise AI consulting in Sydney should increasingly connect technology strategy with infrastructure, workflow ownership, governance and operating-model design.
The Hidden Constraint May Be The Team, Not The GPU
Private AI infrastructure can solve one dependency while creating another.
A company buying its own AI capacity becomes responsible for operating more of the stack.
That may require capability across:
- Virtualisation
- Kubernetes
- GPU scheduling
- Storage
- Networking
- Identity
- AI gateways
- Model serving
- Retrieval infrastructure
- Security operations
- Observability
- Application engineering
- Business-process governance
Platform vendors are trying to collapse these domains into more manageable operating environments. Broadcom's VMware AI Factory is explicitly designed around automation from physical infrastructure through model deployment and ongoing lifecycle management.
That simplification may be valuable, but organisations should distinguish between reducing operational complexity and eliminating it.
Someone still owns the platform when an upgrade fails at 2am.
The Board-Level Question Is No Longer Simply Build Versus Buy
Large organisations assessing VMware Private AI Cloud or another private-AI architecture should require answers to a wider set of questions before approving capital.
- Which workloads genuinely require private infrastructure?
- What volume of inference makes dedicated capacity economical?
- How much utilisation is required for the business case to work?
- Which workloads must retain public-cloud burst capacity?
- Where will enterprise data physically and logically reside?
- What happens when a preferred model changes?
- Can workloads move between infrastructure providers without major redevelopment?
- How will agents be identified and authorised independently from employees?
- Which agent actions require human approval?
- How will model, retrieval and action logs be preserved?
- Who owns patching, monitoring, capacity and disaster recovery?
- What is the exit plan if the platform no longer meets commercial or technical requirements?
An organisation that cannot answer these questions is probably not yet making an infrastructure decision.
It is making a technology purchase.
Private AI Changes What Enterprise Implementation Partners Need To Deliver
The emergence of private enterprise AI also changes the consulting brief.
It is no longer enough to demonstrate that a model can answer questions over confidential documents.
A production engagement may need to coordinate application architecture, data pipelines, identity, infrastructure placement, retrieval quality, human approvals, operational monitoring, compliance review and support responsibilities.
Elyment's AI systems and software development work approaches production AI as an operational system rather than an isolated model deployment.
For organisations assessing private models specifically, private LLM and custom AI deployment planning can help determine whether confidentiality requirements genuinely justify a private architecture and what integrations will be required around it.
The objective should not be to force workloads into either private or public cloud.
It should be to place them deliberately.
AI INFRASTRUCTURE · GOVERNANCE · OPERATIONAL DELIVERY
Review The Workload Before Choosing Where It Runs
Assess data sensitivity, agent authority, infrastructure economics, integration requirements, governance controls and operational ownership before committing sensitive enterprise AI to a new production environment.
Request an Enterprise AI Project Review
The Bottom Line
Broadcom's VMware Private AI Cloud is another sign that enterprise AI infrastructure is moving beyond the assumption that every important workload will ultimately be consumed through a hyperscale public-cloud service.
Sensitive inference, retrieval-heavy applications and agents operating close to proprietary enterprise data are credible candidates for private infrastructure, particularly where demand becomes predictable and control requirements are high.
That does not mean large companies will simply reverse a decade of cloud migration.
Public cloud still offers advantages for experimentation, elasticity, rapidly changing models and workloads whose demand is difficult to forecast. Private infrastructure introduces its own costs, operational responsibilities and capacity risks.
The more likely outcome is selective repatriation.
High-value workloads will increasingly be classified according to sensitivity, utilisation, latency, data gravity and required authority. Some will remain public. Some will operate across hybrid environments. Some will move into infrastructure the enterprise controls much more directly.
For Sydney and NSW organisations, that makes the next stage of private enterprise AI less about bringing everything "back on-premises" and more about restoring deliberate control over where consequential computing occurs.
The location of the model matters.
The operating model around it matters more.
Sources and References
- Elyment: AI readiness assessment for Sydney organisations
- Elyment: Enterprise AI consulting in Sydney
- Elyment: AI systems and software development
- Elyment: Private LLM and custom AI deployment planning
- Elyment: Contact
Decide What Should Move Before Buying The Infrastructure
Review sensitive workloads, data boundaries, agent permissions, infrastructure economics, integration dependencies and production support requirements before committing enterprise AI to private cloud or on-premises infrastructure.
Review Your AI Project