Broadcom has unveiled VMware AI Factory, a software-defined private AI platform designed to help enterprises move from bare-metal infrastructure to production-ready AI services while improving security, governance, and automation.
Announced at VMware Explore 2026, VMware AI Factory will serve as a core component of VMware Private AI Cloud.
The platform combines VMware Cloud Foundation (VCF), validated server configurations, GPU infrastructure, model services, lifecycle management, and operational tooling into a unified environment for organizations deploying AI workloads involving sensitive enterprise data.
Broadcom Launches VMware AI Factory
Broadcom said the platform can reduce the time needed to provision infrastructure and serve an initial AI model from weeks to hours.
The goal is to remove bottlenecks in scaling GPU-intensive workloads, including server provisioning, software stack deployment, model enablement, and ongoing Day 2 lifecycle operations.
A central cybersecurity capability is the introduction of secure AI sandboxes and an agent-governance layer. The platform uses virtualized container spaces to isolate code dynamically generated or executed by AI agents.
The governance layer is intended to control agent invocation, restrict the tools an agent may access, and validate outputs before those outputs trigger downstream actions. This establishes a control boundary for organizations that use autonomous or semi-autonomous AI systems in production.
The feature is particularly relevant to retrieval-augmented generation (RAG), coding agents, workflow automation, and AI applications connected to internal data repositories, APIs, or infrastructure-management systems.
Such integrations can expose businesses to prompt-driven unsafe behavior, excessive permissions, unauthorized tool usage, and malicious code execution if agents are not properly constrained.
| Feature | Technical capability | Security and operational impact |
|---|---|---|
| Secure AI sandboxes | Virtualized containers isolate agent-generated code | Helps contain untrusted and dynamically produced workloads |
| Agent governance | Controls invocation, tool permissions, and output validation | Reduces unsafe actions and excessive agent privileges |
| Multi-tenant model sharing | Isolated namespaces support model sharing | Preserves privacy between business units or tenants |
| AI Gateway | Common interface for local and cloud models | Supports authorization, rate controls, and prompt routing |
| Unified model gallery | Manages inference and RAG workflows across VMs, containers, and GPUs | Centralizes governance and model operations |
| Observability | Measures throughput, latency, compute, and memory use | Supports cost controls, planning, and performance monitoring |
| Bare-metal automation | MetalSoft provisions or repaves heterogeneous hardware through VCF | Accelerates infrastructure lifecycle operations |
VMware AI Factory also addresses “AI tokenomics,” referring to the cost of generating and consuming AI tokens. Organizations can pool GPU resources so that multiple models share the underlying infrastructure, rather than requiring dedicated hardware for each workload.
The platform provides telemetry for token throughput, latency, compute consumption, and memory utilization. This visibility can help IT, security, and data-science teams identify inefficient workloads, manage capacity, enforce policies, and avoid uncontrolled AI spending.
Its AI Gateway is expected to deliver centralized consumption controls for both on-premises and cloud-hosted models. Planned capabilities include intelligent prompt routing, application authorization, and token- and usage-based rate limiting.
VMware AI Factory is compatible with certified Dell PowerEdge systems and VCF AI ReadyNodes from Cisco, Lenovo, Supermicro, and other hardware vendors.
Broadcom is also working with AMD to integrate VCF with AMD Instinct MI350-series GPUs and the ROCm software ecosystem.
Customers will be able to deploy more than 150 commercial and open-source models, including Nemotron 3, Gemma 4, Cotomi, Qwen, and GLM 5.2.
The platform positions VMware Private AI Cloud as a controlled alternative for enterprises seeking data sovereignty, infrastructure flexibility, and stronger governance over increasingly autonomous AI workloads.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN