IBM is the enterprise-estate vendor. It owns silicon and systems for running AI next to the data (z17, Power11, Spyre), storage plus a catalog that answers what the data is (watsonx.data intelligence with integrated lineage), streaming and integration (Confluent, DataStage), GPU scheduling (Spectrum LSF, Turbonomic), a model platform (watsonx.ai, Granite), an agent-governance plane complete in every leg but identity (watsonx Orchestrate's control plane), and a first-party application estate (Orchestrate domain agents, Maximo, Cognos, Planning Analytics). It is strong at 1A, 1C, 2A, and Layer 3, and moderate at Layer 0, 1B, 2B, and 2C. Red Hat is its own row: OpenShift is the substrate IBM's on-premises software runs on (on-premises watsonx requires it), so the two rows compose in the common IBM deployment. IBM Cloud is outside this row.
The capture is coupled and visible where the value accumulates. The catalog structure, lineage and governance rules, Confluent's platform surfaces, DataStage flows, Orchestrate agent definitions, and the Maximo and Cognos models are IBM's, and Ceded; Granite's open weights, Milvus, and Ceph are the open seams. It is the inverse of the Red Hat row: portability sits on the Red Hat side, and captured value accumulates on the IBM side. A buyer of both gets a portable substrate under a captive estate, and should price the estate, not the substrate.
The buyer's trade: governed data, AI beside the systems of record, an agent plane with cross-platform reach, and applications that run the business, in exchange for capture in IBM's data and application layers, with the agent-identity leg still in private preview.
Layer-by-layer status: Layer 0 (Owned AI Silicon and Systems Beside the Data (z17, Power11, Spyre) + Owned Storage Arrays; No Fabric), Layer 1A (Owned Storage + Catalog with Classification and Lineage), Layer 1B (Milvus Inside watsonx.data + Unstructured Data Pipelines for RAG), Layer 1C (Confluent + DataStage + Lakehouse Federation), Layer 2A (IBM-Owned GPU Scheduling: Spectrum LSF + Turbonomic), Layer 2B (watsonx.ai Model Platform + Granite, on the Red Hat Engine), Layer 2C (Agentic Control Plane Generally Available; Agent Identity in Preview), Layer 3 (+1) (IBM Portfolio: watsonx Agents, Maximo, Cognos and Planning Analytics; Red Hat the Infrastructure Focus).
Assessment framework: 4+1 Layer AI Infrastructure Model. Scoring model: Decision Authority Placement Model (DAPM) — Retained, Delegated, or Ceded. Published by The CTO Advisor LLC (DBA The Advisor Bench). Author: Keith Townsend. Date assessed: October 5, 2026. Version: v2.3 - 4+1 v2: NetApp Calibration Updated.
IBM is the enterprise-estate vendor. It owns silicon and systems for running AI next to the data (z17, Power11, Spyre), storage plus a catalog that answers what the data is (watsonx.data intelligence with integrated lineage), streaming and integration (Confluent, DataStage), GPU scheduling (Spectrum LSF, Turbonomic), a model platform (watsonx.ai, Granite), an agent-governance plane complete in every leg but identity (watsonx Orchestrate's control plane), and a first-party application estate (Orchestrate domain agents, Maximo, Cognos, Planning Analytics). It is strong at 1A, 1C, 2A, and Layer 3, and moderate at Layer 0, 1B, 2B, and 2C. Red Hat is its own row: OpenShift is the substrate IBM's on-premises software runs on (on-premises watsonx requires it), so the two rows compose in the common IBM deployment. IBM Cloud is outside this row.
The capture is coupled and visible where the value accumulates. The catalog structure, lineage and governance rules, Confluent's platform surfaces, DataStage flows, Orchestrate agent definitions, and the Maximo and Cognos models are IBM's, and Ceded; Granite's open weights, Milvus, and Ceph are the open seams. It is the inverse of the Red Hat row: portability sits on the Red Hat side, and captured value accumulates on the IBM side. A buyer of both gets a portable substrate under a captive estate, and should price the estate, not the substrate.
The buyer's trade: governed data, AI beside the systems of record, an agent plane with cross-platform reach, and applications that run the business, in exchange for capture in IBM's data and application layers, with the agent-identity leg still in private preview.
Raw compute, networking, and acceleration fabric
Mainframe-class systems with on-chip AI inference and Spyre accelerator clusters, running AI beside transactional records. Proprietary integrated system: Ceded.
Enterprise servers with on-chip inference acceleration and Spyre attach for generative and agentic inference. Proprietary integrated system: Ceded.
Owned all-flash arrays with agentic operations and a parallel-file system built for AI and HPC data. Proprietary arrays: Ceded.
Assessment pending
IBM sells owned silicon and systems for running AI next to the data. The z17 mainframe and LinuxONE 5 carry Telum II on-chip AI acceleration and take up to 48 Spyre cards (generally available October 28, 2025); Power11 carries on-chip matrix-math acceleration and takes up to 16 Spyre cards (generally available December 2025). Spyre is IBM's own 5nm, 32-core inference accelerator. Beneath them sits IBM's storage substrate: FlashSystem 5600, 7600, and 9600 with FlashSystem.ai operations agents (generally available March 6, 2026) and Storage Scale System 6000 for AI and HPC data. The buyer gets inference inside the systems that already hold core banking, insurance, and ERP records. The architect's concern: these are proprietary integrated systems with no exit to another vendor's hardware, the accelerators are inference-class rather than training-class, and IBM sells no network fabric and no GPU training systems on premises. Moderate at the top of the band. Calibration: Intel reads moderate on CPUs with a thin accelerator line and no fabric, and IBM is that shape plus owned storage arrays; Dell and HPE read strong on GPU-training-scale systems with fabric; AMD strong on frontier accelerators. Scope: IBM Cloud's rented GPU infrastructure (NVIDIA, AMD MI300X, Intel Gaudi 3) is a separate cloud shape outside this row, and OpenShift on OEM hardware is the Red Hat row's Layer 0.
Low for the silicon, which is IBM's own: Telum II, Spyre, and Power11 carry IBM's judgment, not NVIDIA's. The systems are proprietary integrated platforms whose partitioning, firmware, and array opinions don't lift: Ceded. Partitioning and placement happen inside bounds the enterprise configures, which is configuration under the override rule: vendor decides, visible, not overridable, Ceded, the OEM reading.
The near-empty NVIDIA column is the finding: IBM is the one OEM-shaped row whose AI silicon at this layer is its own. Instrument follow-up: IBM Cloud is a candidate for its own row. Public evidence that moves the cell: training-class accelerators or a GPU fabric on IBM's on-premises paper.
Durable, governed data foundation — the Governance Catalog that Layer 2C queries
Enterprise AI governance: Governance Graph (connected map of AI assets, policies, risks, regulations), model monitoring (bias, drift, fairness), agentic monitoring and security, regulatory library (EU AI Act, HIPAA, GDPR). Cross-platform: governs IBM, OpenAI, AWS, Meta models. IDC named IBM a Leader in AI governance. Proprietary IBM platform — opinions captive, no open exit.
Open data lakehouse with Presto and Spark engines, Iceberg table format. Shared metadata layer across clouds and on-premises. GPU-accelerated Presto (private preview). Context layer for AI-queryable metadata (private preview). watsonx.data intelligence provides data lineage, classification, quality, and Master Data Management. Proprietary IBM platform — opinions captive, no open exit.
IBM's data catalog (formerly IBM Knowledge Catalog) with automated classification, sensitive-data discovery and anonymization, data quality, and Data Lineage (formerly IBM Manta, acquired October 2023) integrated for end-to-end mapping of data flows. The catalog a reasoning plane queries for what the data is. IBM's catalog structure and governance rules don't lift: Ceded.
Ceph: distributed S3-compatible object storage for watsonx.data lakehouse — open-source substrate the enterprise can self-operate; the litmus's own Retained example. Competent but not AI-optimized at competitor level.
Proprietary storage services for OpenShift applications with data caching and acceleration; Storage Fusion HCI hosts watsonx on-premises. Fusion's data-services opinions are IBM-captive — split from the open-source Ceph substrate it sits beside, per the one-chip-one-substrate convention.
GA May 2026. Software platform enforcing data sovereignty across four pillars: operational, data, technology, AI sovereignty. Embeds policy at infrastructure runtime. Built on Red Hat OpenShift. Mistral AI as first certified model partner. Ensures data residency, model execution, and inference all operate within sovereign boundary. Proprietary IBM platform — opinions captive, no open exit.
Private preview. Proof-of-concept with Nestlé showed 83% cost savings. GPU acceleration for analytical queries on the lakehouse.
Strong, on rule 9: IBM pairs owned storage with a catalog that answers what the data is. The storage is IBM's: Storage Ceph for S3 object, Storage Fusion and Fusion Data Foundation for OpenShift workloads, and Storage Scale for parallel file, with the FlashSystem and Scale System arrays as the substrate at Layer 0. The catalog is watsonx.data intelligence: classification, sensitive-data discovery and anonymization, data quality, and Data Lineage (formerly Manta) integrated for end-to-end mapping of data flows. Above it, watsonx.governance maps AI assets through policies, risks, and regulations across IBM and third-party platforms, Sovereign Core enforces data residency, and the watsonx.data lakehouse (Presto and Spark on Iceberg) carries shared metadata across clouds and on premises. The architect's concern: the governance value accumulates in IBM's catalog structure, lineage graph, and governance rules, which don't lift. The open seams are Ceph and the Iceberg tables underneath. Calibration: Dell reads strong on MetadataIQ, VAST on its Catalog, and ServiceNow on Data Catalog (NetApp's Metadata Engine is back in private preview, so NetApp reads moderate as of October 5, 2026); IBM's catalog carries lineage and quality as well, deeper than most of them, and is documented rather than inferred. Composition: Red Hat's paper carries OpenShift Data Foundation Essentials, scored on the Red Hat row; IBM's paper carries the full storage and catalog estate. Confluent's streaming is scored at 1C, where it performs its function.
Low for governance and catalog: watsonx.data intelligence, watsonx.governance, and Sovereign Core are IBM IP, Ceded to IBM. Storage Ceph is open source the enterprise can self-operate: Retained, the litmus's own example. Storage Fusion and the lakehouse's data-services opinions are IBM-captive: Ceded. watsonx.governance is the only assessed governance surface designed to extend beyond its vendor's own platform, monitoring models on OpenAI, AWS, and Meta. Vendor decides, not overridable, Ceded, the Dell and NetApp reading.
The Confluent acquisition is the most strategically significant data-layer move from any vendor in this assessment. Real-time streaming + governed lakehouse + cross-platform governance creates a data foundation story that is architecturally distinct. Where Dell invested in Dataloop (pipeline orchestration) and VAST built DataEngine (serverless compute on data), IBM acquired the streaming substrate itself. The watsonx.data Context layer (private preview) adds contextual metadata directly into the lakehouse — making data AI-queryable without separate ETL. If this matures, it could address the metadata boundary problem identified in the Control Plane Working Notes: metadata that is both governed and real-time, not just batch-indexed. IBM's Governance Graph — mapping AI assets through policies, risks, and regulatory requirements as a connected graph — is the most sophisticated governance data model in this assessment. Whether it can serve as the queryable governance surface that a Layer 2C control plane needs is the open question.
Low-latency retrieval for RAG — vector/hybrid search, context windows
Managed Milvus inside watsonx.data, combining vector similarity with relational-style filtering. Open-source Milvus the enterprise runs on premises: Retained on the possess-and-operate line.
Pipelines that turn documents into RAG-ready chunks and embeddings and populate vector stores; included in the watsonx.data integration, intelligence, and Premium licenses. IBM's flows and operators: Ceded.
Assessment pending
RAG preparation and retrieval inside the governed lakehouse. watsonx.data's Unstructured Data Integration ingests documents, PDFs, and slides, extracts text, removes PII, deduplicates, and runs chunking and embedding operators that populate vector stores; watsonx.data's managed Milvus service (Milvus 2.5) serves hybrid search that combines vector similarity with scalar filters beside the structured data in the lakehouse. The architect's concern: the ingestion pipelines are IBM's flows, the end-to-end retrieval product (OpenRAG on watsonx.data) isn't confirmed generally available, and there is no documented reranking or relevance-tuning stage. Moderate. Calibration: above the Red Hat row's assembled kit, because IBM's pieces are integrated from ingestion to index; below Elastic, Azure AI Search, and Vertex, which ship a generally available relevance stage and a managed retrieval service under rule 6; alongside Cloudera and Redis on a real engine and pipeline short of the frontier deliverable.
Split. Milvus is open source the enterprise runs inside on-premises watsonx.data, and its collections and indexes lift to any Milvus deployment: Retained. The Unstructured Data Integration flows and operators are IBM's and rebuild on exit: Ceded. Milvus ranks inside queries the enterprise composes, with per-request filters: vendor decides, visible, overridable, Delegated, the Elastic reading.
Watch-list, notes only: OpenRAG on watsonx.data (announced; general availability not confirmed), which would deepen the cell. watsonx.data intelligence governs unstructured data and is read at 1A. Red Hat's vector-store integration and Llama Stack RAG are scored on the Red Hat row.
Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering
Real-time streaming as infrastructure: Tableflow's zero-copy integration with watsonx.data Iceberg tables, managed stream processing, and Confluent's enterprise features. These platform surfaces are Confluent's proprietary opinions: Ceded, matching the Confluent row; the open Apache Kafka core and Community License components read Retained there, as they do wherever the enterprise runs them.
IBM-defensible IP. Enterprise data integration engine with decades of maturity. Graphical and code-first pipeline building. Automated data cleansing, tokenization, formatting for LLM consumption. Comprehensive lineage tracking — trace which raw document fed into a specific fine-tuning or RAG dataset. Data sanitization (PII, hate speech, copyrighted content) reduces Layer 2C compliance burden. Proprietary IBM platform — opinions captive, no open exit.
IBM-defensible IP. Zero-copy query federation to external data platforms: Confluent Tableflow, Databricks Unity Catalog, Snowflake Open Catalog, Salesforce Data Cloud. Presto and Spark engines query data where it resides without copying. The federation logic is IBM-specific integration. Proprietary IBM platform — opinions captive, no open exit.
GPU-accelerated Spark on watsonx.data for pipeline processing. Same RAPIDS integration available across vendor platforms.
Strong, on three IBM-owned surfaces. Confluent (acquired for $11 billion) makes real-time streaming infrastructure, with Tableflow exposing live Kafka streams as Iceberg tables in watsonx.data without ETL. DataStage (watsonx Edition) is the enterprise integration engine: graphical and code-first pipelines, automated cleansing and tokenization for LLM consumption, PII and harmful-content sanitization before training, and lineage that traces which raw document fed which fine-tuning or RAG dataset. watsonx.data federation queries Confluent Tableflow, Databricks Unity Catalog, Snowflake Open Catalog, and Salesforce Data Cloud where the data resides. The architect's concern: the defensible value is captive (Confluent's platform surfaces, DataStage flows, the federation logic), and the stack is enterprise-weight; teams used to Python scripts and lightweight RAG tooling can find it heavy. Calibration: the strong 1C cohort (Snowflake Openflow, Databricks Lakeflow, Qlik CDC plus Talend, VAST DataEngine, Confluent) covers batch, streaming, CDC, transformation, and lineage generally, and IBM covers all of it on owned surfaces. Composition: in the common IBM deployment these pipelines run on OpenShift as containerized workloads, so data moves to compute, unlike VAST's DataEngine; the open ML pipeline stack (Kubeflow, Ray, MLflow) and Red Hat's Kafka, Debezium, and Camel are scored on the Red Hat row. Decision authority: both engines that carry the grade execute what the enterprise wrote or configured. Confluent reads code / Retained on its own row, and DataStage runs the flows the enterprise designs (runtime column propagation is opt-in, a setting the enterprise chooses). Code decides, visible, overridable, Retained, the judgment test (October 4, 2026).
Low upstream, and the capture is IBM's. Confluent's platform surfaces, DataStage, and the watsonx.data federation logic are IBM IP: Ceded. The open Kafka core reads Retained, as on the Confluent row. NVIDIA's role is limited to RAPIDS acceleration for Spark. Vendor decides, not overridable, Ceded: the pipelines run on IBM's engines under IBM's execution opinions. Compare VAST, which owns everything at this layer with one authority, and Dell, with four authority boundaries.
The Confluent acquisition creates a unique data velocity advantage. Dell, HPE, and VAST focus on data at rest (storage) and data in batch motion (pipelines). IBM now owns data in continuous motion (streaming). For agentic AI where agents need to reason over current events, current transactions, current sensor data — not yesterday's batch export — this is an architectural differentiator that no other infrastructure vendor possesses. Whether IBM can integrate Confluent deeply enough with watsonx.data to deliver on the 'zero-copy' promise is the execution question. The technology exists; the integration maturity is early. DataStage's data sanitization capabilities (removing PII, hate speech, copyrighted content prior to model training) are a crucial data-plane capability that directly reduces the compliance burden on Layer 2C downstream. This is the pipeline-to-governance connection that the 4+1 model identifies as critical: clean data in the pipeline means fewer governance exceptions at the reasoning plane.
GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization
Workload scheduling for HPC and AI training with GPU-aware placement, fair share weighted by GPU run time, and resource accounting. Proprietary scheduler: Ceded.
Automated GPU resource actions for generative AI inference workloads. Proprietary decision engine and policies: Ceded.
Spectrum LSF and Turbonomic schedule and right-size NVIDIA GPUs (with DCGM integration); the scheduling judgment is IBM's, the silicon NVIDIA's.
IBM sells the 2A purpose line almost word for word. Spectrum LSF (10.1.0.16, July 2026) schedules GPUs on some of the world's largest AI supercomputers, with GPU-runtime fair share and GPU resource accounting; Turbonomic's GPU optimization discovers LLM inference workloads on Kubernetes and OpenShift and scales them to use the available GPUs, as automated actions. The architect's concern: both are proprietary control planes whose queue, fair-share, and optimization policies don't port. In the common deployment the Kubernetes layer underneath is the Red Hat row's (OpenShift, OpenShift AI Kueue, Advanced Cluster Management); IBM's schedulers sit beside it (LSF, for batch training) or above it (Turbonomic), not in place of it. Strong. Calibration: CoreWeave (Kubernetes, Slurm on Kubernetes, Mission Control) and Nebius (Kubernetes plus Slurm) read strong; LSF is a proprietary Slurm-class GPU scheduler at frontier scale, and Turbonomic adds cross-platform automation. HPE reads strong on GreenLake and OpsRamp. IBM Cloud's managed Kubernetes and OpenShift are outside this row.
Low upstream, Ceded to IBM. LSF and Turbonomic are IBM IP whose policies don't lift: Ceded, the Run:ai reading (open-source Slurm, run by the enterprise, would read Retained). LSF honors per-job pins (host selection and resource requirements the engine must satisfy), and Turbonomic's actions can run in recommend or manual mode, a documented gate before the effect: vendor decides, visible, overridable, Delegated under the override rule.
IBM Concert has been generally available since June 2024 (Concert Software 2.x since July 2025); it is application operations and resilience (observability, risk), not orchestration, and isn't scored here. Only the next-generation Concert platform (Think 2026) is in preview. OpenShift, OpenShift AI, and Ansible are the Red Hat row's 2A.
Model serving, agent execution, inference APIs, distributed inference
IBM's model platform for on-premises inference, model deployment, tuning, and prompt tooling. Deployment spaces, prompt templates, and tuned assets are IBM-specific and rebuild on exit: Ceded.
IBM-defensible legal wrapper on open-source models. Granite 4.1 (3B, 8B, 30B dense models, Apache 2.0). ISO 42001 certified. Cryptographic model signing. Uncapped IP indemnity on watsonx.ai. Optimized for agentic workflows: tool calling, instruction following, function calling. Granite Guardian for safety guardrails. Models run anywhere (Hugging Face, Ollama, Dell Enterprise Hub, NVIDIA NIM, Red Hat AI). Open weights the enterprise runs anywhere: Retained; the IP indemnity is IBM's, the model isn't captive.
The business logic, APIs, and deterministic validators the enterprise invokes through tool calls. The enterprise's own code: Retained. Availability of tool calling on the on-premises chat API is flagged in the notes.
Deploying custom foundation models in watsonx.ai software requires A100 or H100 80GB GPUs; Granite on Spyre (Z and Power) is the non-NVIDIA path.
A governed model platform on the enterprise's own hardware. watsonx.ai software (Cloud Pak for Data 5.x) serves IBM-curated and third-party models, deploys the enterprise's own custom foundation models (supported since Cloud Pak for Data 4.8.4), supports tuning and prompt tooling, and carries Granite with IBM's uncapped IP indemnity. The architect's concern: the serving engine underneath belongs to the Red Hat row. watsonx.ai runs on OpenShift and Red Hat AI in the common deployment, so IBM contributes the model platform rather than the inference engine. Custom model deployment is tied to NVIDIA A100 and H100 GPUs, and deployments, prompt templates, and tuned assets live in watsonx.ai's own surface. Moderate. Calibration: the Red Hat row reads strong on the engine itself (vLLM, llm-d, Models-as-a-Service); VMware and Nutanix read moderate on platform-native serving over someone else's engine, and IBM is that shape. The agent runtime in watsonx Orchestrate is read at 2C.
Split. watsonx.ai's deployment spaces, prompt templates, and tuned assets are IBM-specific: Ceded. Granite is open weights the enterprise runs anywhere: Retained. The enterprise's own tool code is Retained. The model decides which tool to call, and the enterprise's own tool code gates the effect: model decides, visible, overridable, Delegated, the NVIDIA reading.
Inference flag: tool calling through watsonx.ai's on-premises chat API (documented on watsonx.ai SaaS); if it isn't available on premises, the customer-tools component moves here. Watch-list, notes only: the watsonx.ai model gateway on premises (SaaS-confirmed). Red Hat AI Inference, llm-d, MLflow, and InstructLab are the Red Hat row's 2B. IBM Cloud is outside this row.
Policy-driven placement and resource coordination — the Autonomy Layer
Generally available on AWS and IBM Cloud (June 2026). A centralized layer to observe, govern, and orchestrate AI agents regardless of where they were built or run: the AI Gateway applies policies at the gateway level to every connected agent; agent discovery and registration from Amazon Bedrock (generally available August 31, 2026) feeds a shared agent catalog; multi-agent orchestration spans frameworks; the AgentOps Agent (generally available August 31, 2026) answers observability questions in plain language. Agent Identity and discovery from Microsoft Foundry and Gemini Enterprise are preview, in the notes. Governance policies and catalog opinions authored in the control plane are IBM-captive: Ceded.
Generally available. A developer assistant whose multi-model routing sends each task to Claude, Mistral, or Granite on accuracy, latency, and cost; 80,000 internal IBM users. Its routing acts at runtime and contributes a routing leg to the plane; under routing-is-not-reasoning it doesn't carry the cell alone. IBM IP: Ceded.
GA May 2026. Four sovereignty pillars: operational, data, technology, AI. AI sovereignty enforced at runtime — governing where inference happens, who controls models, how decisions are logged/traced/reviewed. Built on OpenShift + Red Hat AI. Mistral AI first certified model partner. Proprietary IBM platform — opinions captive, no open exit.
Governance Graph mapping AI assets through policies, risks, and regulatory requirements. Agentic monitoring and security capabilities. Cross-platform: governs IBM, OpenAI, AWS, Meta. Continuous compliance monitoring, not periodic audits. The governance query surface that a 2C control plane needs. Proprietary IBM platform — opinions captive, no open exit.
Governs agent execution, tool access, inference routing. 2B constraint enforcement with 2C policy potential. Same OpenShell available across NVIDIA partners.
IBM ships a nearly complete Intelligence-2C plane. watsonx Orchestrate's Agentic Control Plane (generally available June 2026) brings the request-time gateway, the agent registry fed by cross-platform discovery, multi-agent orchestration, and observability through the AgentOps Agent; watsonx.governance maps AI assets through policies, risks, and regulations across platforms; Sovereign Core enforces where inference runs; and Bob's multi-model routing contributes a routing leg. The missing leg is first-class agent identity, which is in private preview. Every component here is IBM's own: there is no open-source equivalent for cross-framework agent governance at this depth, and nothing at this layer depends on Red Hat, NVIDIA, or a partner. Sovereign Core runs on OpenShift and Red Hat AI, which is a co-deployment fact with the Red Hat row rather than a dependency in the plane. The plane's reach is its distinction. Orchestrate governs agents from other platforms (Bedrock generally available; Foundry and Gemini Enterprise in preview), and watsonx.governance monitors models IBM doesn't run. IBM names its agent orchestration layer a control plane, and as of June 2026 it ships as one, not as an announced direction. Applying the Intelligence 2C vs. Infrastructure 2C split established in the AWS assessment: Intelligence 2C (productized and portable): watsonx.governance provides continuous model monitoring, bias detection, drift tracking, regulatory compliance enforcement, and the Governance Graph mapping AI assets through policies, risks, and regulatory requirements. watsonx Orchestrate provides cross-framework agent governance — managing agents from IBM native, LangFlow, LangGraph, and A2A protocol with centralized policy enforcement, identity/credential management, and audit logging. IBM Bob demonstrates practical multi-model routing: tasks dynamically routed to Claude, Mistral, or Granite based on accuracy, latency, and cost — a multi-variable placement decision, not single-variable optimization like NVIDIA Dynamo's KV-aware routing. Sovereign Core enforces sovereignty as a runtime requirement, governing where inference happens, who controls models, and how decisions are logged within sovereign boundaries. IBM's Intelligence 2C is the strongest in this assessment for on-premises deployments. Four capabilities that no other on-prem vendor matches: (1) Cross-framework agent governance (watsonx Orchestrate) — manages agents regardless of which framework built them. Dell has no equivalent. HPE delegates to Kamiwaza. VAST's AgentEngine governs VAST-native agents only. (2) Cross-platform AI assurance (watsonx.governance) — governs models running on IBM, OpenAI, AWS, or Meta. No other governance solution spans vendor boundaries. (3) Multi-variable model routing (IBM Bob) — 80,000 internal users, demonstrated accuracy/latency/cost optimization. Production evidence at scale. (4) Runtime sovereignty (Sovereign Core) — sovereignty enforced at infrastructure runtime, not as a policy checkbox. No equivalent from any assessed vendor. Infrastructure 2C (absent/manual): watsonx Orchestrate governs agent behavior but does not autonomously calculate: 'Based on real-time token cost, data residency tags in watsonx.data, and current GPU cluster queue times, route this inference to on-prem PowerEdge versus burst to Azure.' That infrastructure placement coordination remains a manual configuration task for the platform architect. No productized engine queries Layer 1A governance metadata to make multi-variable infrastructure placement decisions in real time. This is the same split AWS exhibits: Intelligence 2C is productized (AgentCore Policy, Guardrails), Infrastructure 2C is implicit inside managed services. IBM's Intelligence 2C is more portable than AWS's (runs on-prem, multi-cloud). IBM's Infrastructure 2C is equally absent. Read across the instrument by shape rather than by roster. Three positions exist at 2C. One cohort ships nothing and the enterprise owns the function by default. A second and now larger cohort ships productized Intelligence-2C — agent identity, gateways, registries, runtime policy enforcement, audit — and reads moderate or strong on it, with authority Ceded to whoever built the control plane. Nobody ships Infrastructure-2C as a configurable product. Naming which vendor sits where is what the heat map is for; repeating it inside a cell only guarantees the cell goes stale the next time a peer moves. IBM's position within that second cohort is the portability claim: watsonx.governance and Orchestrate run on-premises and across clouds, which is a genuine difference from a control plane that only governs its own vendor's estate. Infrastructure-2C is a gap here and is handled manually, the same as everywhere else on the instrument. The maturity gap is the identity leg. Agent Identity in watsonx Orchestrate (private preview, September 2026) would give each agent its own verifiable identity, separate from its creator and end user, with on-behalf-of tokens evaluated at tool invocation and audit records linking user, agent, and action; it supports IBM Verify and Microsoft Entra. At general availability it completes the plane and moves this cell toward strong, beside GCP. Until then the cell reads moderate on four generally available legs, the same discipline applied to ServiceNow.
Low — the lowest borrowed judgment of any IBM layer, because every component is IBM proprietary IP. watsonx Orchestrate, watsonx.governance, Sovereign Core, and Bob are all IBM-owned. No open-source dependency, no NVIDIA dependency, no partner dependency at this layer. The framework-agnostic approach means IBM borrows less agent-level judgment from any single framework vendor — but it also means IBM's orchestration authority depends on integration quality with frameworks it doesn't control (LangFlow, LangGraph, A2A). If LangGraph changes its execution model, IBM must update the integration. This is a different kind of dependency than NVIDIA runtime dependency — it's integration maintenance, not architectural dependency. The DAPM classification requires the Retained/Ceded distinction established in the series: • watsonx Orchestrate: Ceded to IBM. The enterprise consumes IBM's control plane — configures policies within it, but cannot replace it without re-architecture. Portable across clouds but not substitutable. • watsonx.governance: Retained by the enterprise. The enterprise defines its own governance policies, ethical thresholds, and compliance constraints. IBM provides the framework; the enterprise provides the judgment. The closest to genuinely Retained authority in IBM's stack. • Sovereign Core: Retained by the enterprise. The enterprise defines sovereignty boundaries; IBM enforces them at runtime. • Bob: Ceded to IBM. Multi-model routing logic is IBM's — the enterprise configures preferences but IBM's software makes the placement decisions. Compare to Google: Agent Platform provides 2C as a deeply integrated platform capability. More production-proven but less framework-agnostic. Entirely Ceded to Google — no on-prem option. Compare to HPE/Kamiwaza: Kamiwaza provides similar agent coordination but as a partner (Delegated). IBM provides it as owned IP. Compare to VAST: PolicyEngine provides data-layer governance with 2C ambitions. VAST builds 2C from data up; IBM builds 2C from platform out. Different architectural vectors toward the same Layer 2C function.
Not scored, dated preview: Agent Identity in watsonx Orchestrate (private preview, September 15 to 21, 2026; IBM Verify and Microsoft Entra only; no published general-availability date); agent discovery from Microsoft Foundry and Gemini Enterprise (preview, September 15, 2026). The documentation-tier check is the IBM Docs topic "Managing agent identity": a general-availability label there would override the announcements and move the cell. Infrastructure-2C (per-request placement across cost, residency, and capacity) is absent here as everywhere on the instrument; the deterministic outcome-validator is likewise universal and noted, not charged.
AI-powered business capabilities — business logic, workflow automation
Generally available prebuilt agents in the watsonx Orchestrate agent catalog, documented by IBM Developer, connecting to SAP SuccessFactors, Workday, Salesforce, Microsoft 365, and other systems of record. IBM's agent definitions, customized in IBM's builders: Ceded.
Enterprise asset management with predictive maintenance; version 9.1, generally available June 24, 2025, adds Maximo Assistant, a native generative-AI chat over asset data. Asset models, maintenance strategies, and predictive configurations are captive to Maximo: Ceded.
Business intelligence with an AI assistant, and financial planning with AI-assisted forecasting, natural-language analysis, and anomaly and driver insight (Planning Analytics Workspace 3.1.10). Reports, models, and cubes are IBM-specific: Ceded.
~160,000 consultants with an AI practice. Vertical industry solutions across banking, healthcare, government, and manufacturing. Delegated, not Retained: the Delegated definition covers a genuinely substitutable delivery partner, and a different systems integrator could deliver the same outcome. The enterprise keeps the right to change providers without rebuilding the layer, which is Delegated by definition; Retained is reserved for a commodity substrate the enterprise operates or a layer no vendor has claimed. The enterprise can select Deloitte, Accenture, Wipro, or a boutique for platform implementation without architectural impact. The SAP BASIS pattern: platform IP is the moat, implementation services are not.
NVIDIA NIM microservices and Agent Blueprints deployable on Red Hat AI Factory with NVIDIA. Same blueprints available across NVIDIA partners.
The boundary first. Layers 0 through 2C read IBM's AI infrastructure (its silicon and systems, storage and catalog, data movement, schedulers, model platform, and agent plane); Red Hat is its own row, and IBM Cloud sits outside this one. Layer 3 reads IBM's paper: the first-party business applications IBM sells under the same commercial relationship count, whichever product line hosts them (the methodology's company-paper rule, the OCI and Fusion precedent). Strong. IBM's application estate is broad, first-party, and generally available with AI inside it. The watsonx Orchestrate prebuilt domain agents cover HR, procurement, sales, customer care, finance, and supply chain, connecting to SAP SuccessFactors, Workday, Salesforce, and Microsoft 365. Maximo Application Suite runs enterprise asset management with predictive maintenance and, since 9.1 (generally available June 24, 2025), a native generative-AI assistant over asset data. Cognos Analytics carries an AI assistant, and Planning Analytics ships AI forecasting, natural-language analysis, and anomaly and driver insight. Envizi's ESG planning rides Planning Analytics; Sterling and Guardium are named here without scored AI evidence. That breadth across asset management, financial planning, analytics, and agentic business processes stands with the Salesforce, ServiceNow, SAP, and Oracle value planes under rule 6. What separates IBM from them is the system of record: IBM's agents and applications often work over other vendors' records (SAP, Workday) rather than its own, which is a capture fact the DAPM column carries, not a grade gap. IBM Consulting (~160,000 consultants) is a competitive advantage in a substitutable services market, not a structural platform dependency. Enterprises switch AI platform implementation partners the same way they switch SAP BASIS support: IBM to Accenture, Accenture to Deloitte, Deloitte to Wipro. The platform doesn't notice. The open-source components (OpenShift, vLLM, KServe, Kubeflow) run identically regardless of which SI assembled them. IBM Consulting's advantage is scale and experience, not lock-in. This is structurally different from every other vendor's services model: • Dell's Accelerator Services are additive — the NVIDIA runtime works without Dell's humans. • HPE's Kamiwaza partnership is structural — remove Kamiwaza and HPE loses Layer 2C orchestration. • VAST requires minimal consulting because the platform makes architectural decisions for you. • IBM's consulting is the primary go-to-market motion for a platform built from open-source components. The components are free. The assembly expertise is what IBM sells. But any competent SI can provide the assembly expertise. IBM Consulting competes for the engagement; it doesn't own the engagement by virtue of platform architecture. Granite is read at 2B, where the model family is scored; a model isn't a business application. IBM Z/Power transactional AI (Telum on-chip inference beside the ledger for banking, insurance, and government) and watsonx Code Assistant for Z (Bob Premium for Z) are real and IBM-only, but neither is a business application: Telum is IBM silicon running inference, a Layer 0 and 2B fact, and the code assistant is a developer tool rule 8 excludes. Neither carries the Layer 3 grade. The ISV ecosystem comparison: • Dell's ecosystem is broad and horizontal: 5,000+ customers, OpenAI, Palantir, Google, ServiceNow, SpaceXAI. • HPE's ecosystem is curated and vertical: 26+ ISVs through Unleash AI. • IBM's ecosystem is consulting-driven: IBM Consulting partnerships with SAP, Salesforce, Adobe, and ServiceNow. The OpenShift ISV ecosystem is scored on the Red Hat row.
IBM's applications carry IBM's judgment: the domain agents, Maximo, Cognos, and Planning Analytics decide inside IBM's application logic, and customization is configuration. Vendor decides, visible, not overridable, Ceded, the Salesforce, ServiceNow, and OCI reading for first-party applications. The ecosystem and services around them are substitutable. The consulting question is critical for DAPM: IBM Consulting is NOT a borrowed-judgment dependency. The enterprise retains full authority to select any SI for platform implementation, customization, and ongoing support. Switching SIs does not change the platform architecture, does not require re-engineering, and does not break running workloads. This is the SAP BASIS pattern: the platform IP (watsonx.governance, Orchestrate) is the structural dependency; the implementation services are a competitive market. The structural comparison: • Dell's ecosystem is load-bearing: ISV partners provide infrastructure-level functions. Remove Cohere North and Dell loses agent orchestration. • HPE's ecosystem is curated: partners provide domain applications. Remove Deloitte Zora AI and HPE loses a finance use case, not a platform function. • IBM's consulting is competitive: remove IBM Consulting and the enterprise hires Accenture. The platform remains intact. The adoption motion may slow but the architecture doesn't change. • VAST's ecosystem is additive: platform is self-sufficient. Partners add vertical use cases.
IBM's Layer 3 strategy is tightly focused on high-value, unglamorous enterprise utility — code modernization, automated compliance, legacy IT orchestration, mainframe fraud detection — rather than broad consumer-facing generative applications. Dell's Layer 3 partners are flashy (OpenAI, Palantir, SpaceXAI). HPE's Unleash AI partners target emerging AI use cases (video AI, geospatial, vision). IBM's Layer 3 targets the work enterprises actually need done: converting COBOL to Java, generating Ansible playbooks, detecting fraud in real-time transaction streams, modernizing mainframe applications. Nobody puts COBOL modernization on a keynote slide, but it's where regulated enterprise budgets concentrate. The watsonx application surfaces reinforce this enterprise utility focus: watsonx Assistant (conversational AI for customer service, HR, operations), watsonx Code Assistant / IBM Bob (AI-assisted development across the software lifecycle), watsonx Orchestrate applications (workflow automation binding agents to enterprise processes). These are not general-purpose AI platforms — they are purpose-built for specific enterprise operational domains. The 80,000 internal IBM Bob users represent the largest internal AI deployment from any vendor in this assessment. IBM is eating its own cooking at scale — and the 45% productivity gain claim, if sustained across production workloads, validates the agentic AI thesis more concretely than any vendor keynote. The EY tax technology partnership (Bob in private beta, described as 'closer to a collaborative agent than a simple coding tool') signals enterprise validation from a major professional services firm. Granite's Apache 2.0 licensing + uncapped IP indemnity is a distinctive governance posture. No other model family provides both open-source freedom AND vendor-backed legal protection. This addresses a specific enterprise concern: 'I want to run this model anywhere, and I don't want to worry about IP claims.' Neither OpenAI (closed-source, no indemnity) nor Meta (open-source, no indemnity) nor Google (Gemma open-weight but limited indemnity) matches this combination. The Kubernetes-baseline test at Layer 3: applications are inherently above the platform baseline, but IBM's distribution model matters. Granite models are Apache 2.0 — run on any platform. IBM Consulting is substitutable. The OpenShift ISV ecosystem targets any Kubernetes. IBM's defensible Layer 3 assets are narrow: Z/Power transactional AI (hardware adjacency), Granite IP indemnity (legal wrapper), watsonx Code Assistant for Z (mainframe-specific), and the watsonx application surfaces that integrate with Layer 2C governance (watsonx.governance integration creates application-level governance that doesn't port to Tanzu). The governance integration is the subtle lock-in: applications built to leverage watsonx.governance's Governance Graph inherit a dependency on IBM's governance architecture.
IBM Think 2026, Red Hat Summit 2026, Red Hat AI 3.4 GA, watsonx Orchestrate next-gen preview, IBM Sovereign Core GA, IBM Concert public preview, IBM Confluent acquisition, Granite 4.1 release, analyst coverage (SiliconANGLE, NAND Research, Futurum Group, ECI Research) v1.5 (July 12, 2026, /reconcile): OpenShell descored from 2B to a dated watch-list line — alpha on four peer rows; GA-gate applies uniformly. 1A Ceph+Fusion chip split: open-source Ceph Retained, proprietary Fusion Ceded (one chip, one substrate). v1.6 (July 12, 2026, /ga-check): watsonx Orchestrate Agentic Control Plane promoted from the watch-list on doc-confirmed GA ('available today on AWS and IBM Cloud,' IBM announcement + release notes) — scored as a Ceded 2C component; status holds moderate (Intelligence-2C governance, not placement). /reconcile (September 1, 2026): human-delivered services moved Retained to Delegated; a substitutable delivery partner is the Delegated definition. /reconcile (September 1, 2026): retired status vocabulary replaced with gap. /reconcile (September 1, 2026): shared 2C findings stated explicitly (live-placement universality, outcome-validation finding). /reconcile (September 1, 2026): the hard-coded cross-vendor 2C roster replaced with a shape-based reading. The roster had drifted out of agreement with the rows it described (HPE 2C scored three Ceded, not Retained plus Delegated) and went stale on every peer promotion. /reconcile (September 4, 2026, Elastic row): Layer 0 authority Ceded to Absent. The Ceded-invisible reading is for a vendor that absorbs the layer beneath its own service; OpenShift on OEM hardware absorbs nothing, so the layer reads Absent, matching Kamiwaza, Articul8, and Elastic. No status changed. /reconcile (October 5, 2026): Layer 3 partner to strong under the company-paper rule (ratified on this row): watsonx Orchestrate prebuilt domain agents, Maximo Application Suite, and Cognos plus Planning Analytics added as Ceded components, with the Red Hat focus and portfolio boundary stated in the cell. Granite removed from Layer 3 (already scored at 2B), multi-model support removed (platform enablement, rule 8), and the Z/Power chip removed (Telum is silicon, the code assistant a developer tool); the Layer 0 reading of Telum is logged for reconcile. Authority re-read to vendor / visible / not overridable / Ceded. v2.0 (/reconcile, October 5, 2026): the IBM / Red Hat OpenShift AI row split along the vendor support boundary; Red Hat now has its own row (redhat). This row rescoped to IBM's AI infrastructure and re-graded: Layer 0 gap to moderate (z17, Power11, Spyre, FlashSystem, Storage Scale System; IBM Cloud excluded as a separate cloud shape); 1A moderate to strong on rule 9 (owned storage plus watsonx.data intelligence with integrated lineage); 1B held moderate on watsonx.data Milvus and Unstructured Data Integration; 1C held strong, the open ML pipeline stack moved to the Red Hat row and the Confluent chip aligned with the Confluent row; 2A held strong, re-grounded from OpenShift onto Spectrum LSF and Turbonomic, with the stale Concert entry corrected; 2B held moderate on watsonx.ai and Granite, the serving engine on the Red Hat row; 2C held moderate with the stale preview prose replaced by the generally available control plane and Agent Identity noted as private preview; Layer 3 boundary text updated and the Red Hat partner ecosystem chip moved to the Red Hat row. /reconcile (October 5, 2026): 1C authority column (rulings of September 15 and October 4, 2026). 1C authority vendor / Ceded to code / Retained: Confluent reads code / Retained on its own row, and DataStage runs the flows the enterprise designs. Grade unchanged. /reconcile (October 5, 2026): authority visible set from the cell's own text where it settles it: layer1a true. Direction, grades, and components unchanged. /reconcile (October 5, 2026): calibration text citing NetApp's AI Data Engine updated after its documentation was withdrawn and NetApp's 1A moved to moderate. Text only; grades and readings unchanged.