V

VMware Tanzu Platform

by Broadcom

Enterprise PlatformAI Agents & OrchestrationInfrastructure & CloudGovernance & Security

Production AI agents inside your own private cloud, with a deny-by-default runtime

Subscription · Contact for pricing·Added Sep 4, 2026·Updated Sep 4, 2026
Share:
THE DAILY BRIEF
VMware Tanzu Platform

by Broadcom

Enterprise PlatformAI Agents & OrchestrationInfrastructure & CloudGovernance & Security

Production AI agents inside your own private cloud, with a deny-by-default runtime

Subscription · Contact for pricing

VMware Tanzu Platform is Broadcom's application platform for VMware Cloud Foundation, and as of VMware Explore 2026 it is the designated agent platform for VMware Private AI Cloud. It targets regulated enterprises that want to run AI agents against sensitive data entirely inside their own private or air-gapped infrastructure, with agent identity, audit trails and a deny-by-default sandbox rather than public-cloud model APIs.

At a Glance

Category
Enterprise Platform
Pricing
Subscription, Contact for pricing
Target Market
CIOs, CTOs, Platform Engineering Teams, Enterprise Architects, Security and Compliance Leaders
Deployment
Self-hosted, Hybrid, Multi-cloud, Edge-first
Headquarters
Palo Alto, California, United States
Team Size
500+

Key Features

  • Deny-by-default agent runtime
  • Agent identity and attribution
  • Agent Buildpack with harness and memory
  • Curated marketplace for models, tools and MCP servers
  • AI Gateway audit in Tanzu Hub
  • Configurable human-in-the-loop controls
  • Sovereign AI-ready data foundations
  • Regex-based tool filtering

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Regulated-industry agent deployment
  • Air-gapped and sovereign AI
  • Governed agent enablement at scale
  • Agent cost and behaviour control
  • Legacy application modernisation with agents

Ideal For

Best For

  • Running AI agents against regulated or sovereign data that is not permitted to leave a private or air-gapped estate
  • Enterprises already standardised on VMware Cloud Foundation who want an agent runtime that reuses existing platform operations
  • Security teams that need per-agent identity and an auditable record of every tool call, prompt and resource use
  • Centralising which models, tools and MCP servers developers are allowed to bind to, via a curated internal marketplace
  • Modernising existing Cloud Foundry and Kubernetes application estates without adopting a separate agent stack

Not Ideal For

  • Startups and small teams — PeerSpot reviewers repeatedly flag the price as very high against open-source Kubernetes, citing minimum licensing around $350 per core, and explicitly say it is unsuitable for startups
  • Organisations not already committed to VMware — Broadcom's commercial motion bundles Tanzu into VMware Cloud Foundation, so the platform dependency and switching cost are substantial, and theCUBE's analyst openly questions whether its openness translates into real portability
  • Teams that need the AI-ready data foundations today, since those are only slated for general availability in Fall 2026 and the Agent Buildpack shipped as a technical preview
  • Small platform teams without Linux and networking depth — reviewers report setup taking weeks and describe Tanzu Service Mesh installation as very complex

Market Analysis

Enterprise-gradePrivate cloudSovereign AIRegulated industries
User Rating4/ 5

Pros

  • Genuinely addresses the private-AI gap: data sovereignty, compliance and inference economics that public-cloud AI services do not solve for regulated estates
  • Strong VMware integration and single-pane management across Kubernetes clusters, with automation and self-healing rated highly by PeerSpot reviewers
  • Deny-by-default containment plus agent identity and AI Gateway audit is a materially stronger security posture than most agent runtimes ship with
  • RedMonk's Rachel Stephens credits the approach with turning enterprise agent risk into something manageable by making data access governed, curated and auditable by default
  • Reuses an existing, mature application platform and the operations teams already running it, rather than requiring a parallel AI stack

Cons

  • Cost is the dominant complaint. PeerSpot reviewers call the price very high against open-source Kubernetes and cite minimum licensing around $350 per core; licensing advisors report 1.5-3x increases for narrow users and 20-40% renewal quote increases on core-repriced estates
  • Bundling removes choice: Kubernetes runtime, application platform, observability and data services are consolidated, so customers who use one capability pay for all of them
  • Deployment complexity is real — reviewers report setup taking weeks and requiring Linux and networking expertise, with Tanzu Service Mesh installation described as very complex and disaster recovery and networking configuration difficult
  • theCUBE's analyst notes that VCF integration increases platform dependency and openly questions whether openness translates into meaningful portability once operational processes are built around it
  • Several announced capabilities are roadmap rather than shipping: the AI-ready data foundations are only generally available in Fall 2026 and the Agent Buildpack arrived as a technical preview
  • Broadcom's cited customer metrics (such as a 99% deployment reduction) come from vendor-selected examples and the same analyst warns they should not be read as universal benchmarks
  • Ecosystem risk from the acquisition itself — Broadcom has cut roughly 19,000 VMware roles since closing the deal, which buyers weigh against long-term support expectations

Pricing

VMware Cloud Foundation (Tanzu Platform included)

Contact for pricing

  • Tanzu Platform for Cloud Foundry
  • Tanzu Platform for Kubernetes
  • Tanzu Hub
  • Agent Buildpack
  • Core-based subscription licensing

No list price is published. Broadcom moved Tanzu to core-based subscription only and retired perpetual licences, bundling Kubernetes runtime, application platform, observability and data services together so narrow users pay for the whole platform whether or not they deploy it. Licensing specialists report 1.5x to 3x the prior cost for single-capability users (2.3x median) and 20-40% quote increases at renewal for estates repriced onto cores, with roughly 22% average reductions achievable when buyers arrive with a deployment audit and costed open-source alternatives. PeerSpot reviewers cite minimum licensing around $350 per core.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

VMware Tanzu Platform is Broadcom's application platform for VMware Cloud Foundation, and as of VMware Explore 2026 it is the designated agent platform for VMware Private AI Cloud. It targets regulated enterprises that want to run AI agents against sensitive data entirely inside their own private or air-gapped infrastructure, with agent identity, audit trails and a deny-by-default sandbox rather than public-cloud model APIs.

VMware Tanzu Platform is Broadcom's application runtime layer for VMware Cloud Foundation, combining Tanzu Platform for Cloud Foundry, Tanzu Platform for Kubernetes, Tanzu Hub for observability and governance, and Tanzu Data Services (Postgres, GemFire, RabbitMQ, Valkey, Greenplum). At VMware Explore 2026 on 31 August 2026, Broadcom positioned it as the official agent platform for VMware Private AI Cloud and announced AI-ready data foundations built on five pillars. First, a secure-by-default agent runtime: agents run deny-by-default with zero access to APIs, networks, MCP servers or the internet unless explicitly granted, with credentials stored separately to blunt sandbox breakout and prompt injection. Second, governed patterns through a curated marketplace that centralises vetted models, tools and MCP servers so developers bind to approved services with a single command. Third, streamlined delivery via an enhanced Agent Buildpack carrying an out-of-the-box harness, persistent memory exposed over REST and MCP, configurable human-in-the-loop autonomy levels (always deny, always allow, request before action) and progressive skills disclosure that loads capabilities incrementally to preserve context. Fourth, auditability: an integrated AI Gateway records per-agent tool calls, prompts and resource usage into Tanzu Hub, with regex-based tool filtering constraining which MCP tools an agent may call, and agent identity attributing every action back to an accountable owner. Fifth, sovereign data foundations that ingest, parse and semantically layer multimodal enterprise data on-site into isolated data products agents can query without the data leaving the estate. The agent data foundations are slated to be generally available in Tanzu Platform in Fall 2026; the Agent Buildpack shipped as a technical preview in Tanzu Platform 10.4.

Ideal Buyer

A platform or infrastructure leader at a regulated enterprise already running VMware Cloud Foundation, who has been blocked from putting agents into production because the data cannot leave the private estate.

Key Benefit

Agents run against sensitive enterprise data inside your own private or air-gapped cloud, with a deny-by-default sandbox, per-agent identity and a full audit trail in Tanzu Hub.

At a Glance

Category
Enterprise Platform
Pricing
Subscription, Contact for pricing
Target Market
CIOs, CTOs, Platform Engineering Teams, Enterprise Architects, Security and Compliance Leaders
Deployment
Self-hosted, Hybrid, Multi-cloud, Edge-first
Headquarters
Palo Alto, California, United States
Team Size
500+

Key Features

  • Deny-by-default agent runtime

    Agents start with zero access to APIs, networks, MCP servers or the internet unless explicitly granted, with credentials held separately to limit sandbox breakout and prompt injection.

  • Agent identity and attribution

    Every agent action traces back to an accountable origin, which is what makes root-cause analysis and mean-time-to-repair possible once agents act on production systems.

  • Agent Buildpack with harness and memory

    Packages agents for deployment with an out-of-the-box harness, persistent memory over REST and MCP, and progressive skills disclosure to keep context windows efficient.

  • Curated marketplace for models, tools and MCP servers

    Centralises pre-approved services so developers bind with a single command instead of routing around governance with unvetted dependencies.

  • AI Gateway audit in Tanzu Hub

    Records per-agent tool calls, prompts and resource usage with rate limiting, giving platform teams the metrics needed to control agent cost and behaviour.

  • Configurable human-in-the-loop controls

    Autonomy is set per action as always deny, always allow, or request before action, so risk tolerance is a platform policy rather than a per-agent code decision.

  • Sovereign AI-ready data foundations

    Ingests, parses and semantically layers multimodal enterprise data on-site into isolated data products, improving grounding without moving data off the estate.

  • Regex-based tool filtering

    Rules enable or disable specific MCP server tools, constraining an agent to a defined path rather than trusting it with a whole server's capability surface.

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Regulated-industry agent deployment

    A bank runs customer-data agents entirely inside its private cloud, satisfying data residency and audit obligations that public-cloud model APIs cannot meet.

  • Air-gapped and sovereign AI

    Government and defence estates deploy agents in disconnected environments where the curated marketplace substitutes for internet access to models and MCP servers.

  • Governed agent enablement at scale

    A platform team publishes approved models and MCP servers to the marketplace so hundreds of developers ship agents without each one negotiating security review.

  • Agent cost and behaviour control

    Operations use AI Gateway metrics in Tanzu Hub to attribute token spend and tool calls per agent, then rate-limit the ones consuming disproportionate resources.

  • Legacy application modernisation with agents

    Existing Cloud Foundry and Kubernetes workloads gain agent capabilities through the Agent Buildpack rather than being rebuilt on a separate AI platform.

Ideal For

Best For

  • Running AI agents against regulated or sovereign data that is not permitted to leave a private or air-gapped estate
  • Enterprises already standardised on VMware Cloud Foundation who want an agent runtime that reuses existing platform operations
  • Security teams that need per-agent identity and an auditable record of every tool call, prompt and resource use
  • Centralising which models, tools and MCP servers developers are allowed to bind to, via a curated internal marketplace
  • Modernising existing Cloud Foundry and Kubernetes application estates without adopting a separate agent stack

Not Ideal For

  • Startups and small teams — PeerSpot reviewers repeatedly flag the price as very high against open-source Kubernetes, citing minimum licensing around $350 per core, and explicitly say it is unsuitable for startups
  • Organisations not already committed to VMware — Broadcom's commercial motion bundles Tanzu into VMware Cloud Foundation, so the platform dependency and switching cost are substantial, and theCUBE's analyst openly questions whether its openness translates into real portability
  • Teams that need the AI-ready data foundations today, since those are only slated for general availability in Fall 2026 and the Agent Buildpack shipped as a technical preview
  • Small platform teams without Linux and networking depth — reviewers report setup taking weeks and describe Tanzu Service Mesh installation as very complex

Integrations

SDK Available
SDK:JavaGoNode.jsPython.NET

Deployment

On-Premise

Market Analysis

Enterprise-gradePrivate cloudSovereign AIRegulated industries
User Rating4/ 5

Pros

  • Genuinely addresses the private-AI gap: data sovereignty, compliance and inference economics that public-cloud AI services do not solve for regulated estates
  • Strong VMware integration and single-pane management across Kubernetes clusters, with automation and self-healing rated highly by PeerSpot reviewers
  • Deny-by-default containment plus agent identity and AI Gateway audit is a materially stronger security posture than most agent runtimes ship with
  • RedMonk's Rachel Stephens credits the approach with turning enterprise agent risk into something manageable by making data access governed, curated and auditable by default
  • Reuses an existing, mature application platform and the operations teams already running it, rather than requiring a parallel AI stack

Cons

  • Cost is the dominant complaint. PeerSpot reviewers call the price very high against open-source Kubernetes and cite minimum licensing around $350 per core; licensing advisors report 1.5-3x increases for narrow users and 20-40% renewal quote increases on core-repriced estates
  • Bundling removes choice: Kubernetes runtime, application platform, observability and data services are consolidated, so customers who use one capability pay for all of them
  • Deployment complexity is real — reviewers report setup taking weeks and requiring Linux and networking expertise, with Tanzu Service Mesh installation described as very complex and disaster recovery and networking configuration difficult
  • theCUBE's analyst notes that VCF integration increases platform dependency and openly questions whether openness translates into meaningful portability once operational processes are built around it
  • Several announced capabilities are roadmap rather than shipping: the AI-ready data foundations are only generally available in Fall 2026 and the Agent Buildpack arrived as a technical preview
  • Broadcom's cited customer metrics (such as a 99% deployment reduction) come from vendor-selected examples and the same analyst warns they should not be read as universal benchmarks
  • Ecosystem risk from the acquisition itself — Broadcom has cut roughly 19,000 VMware roles since closing the deal, which buyers weigh against long-term support expectations

Pricing

VMware Cloud Foundation (Tanzu Platform included)

Contact for pricing

  • Tanzu Platform for Cloud Foundry
  • Tanzu Platform for Kubernetes
  • Tanzu Hub
  • Agent Buildpack
  • Core-based subscription licensing

No list price is published. Broadcom moved Tanzu to core-based subscription only and retired perpetual licences, bundling Kubernetes runtime, application platform, observability and data services together so narrow users pay for the whole platform whether or not they deploy it. Licensing specialists report 1.5x to 3x the prior cost for single-capability users (2.3x median) and 20-40% quote increases at renewal for estates repriced onto cores, with roughly 22% average reductions achievable when buyers arrive with a deployment audit and costed open-source alternatives. PeerSpot reviewers cite minimum licensing around $350 per core.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

Connect

Sources

This page was written from 6 sources, 6 on domains other than vmware.com.

  1. 1.blogs.vmware.comscaling the agentic enterprise production ready ai agents wi
  2. 2.globenewswire.combroadcom unveils ai ready data foundations in vmware tanzu p
  3. 3.blogs.vmware.comdont miss these vmware tanzu sessions at vmware explore 2026
  4. 4.peerspot.comvmware tanzu platform reviews
  5. 5.thecuberesearch.comvmware explore 2026 wrap up private cloud becomes the operat
  6. 6.redresscompliance.comvmware tanzu licensing broadcom era
Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe