Executive Summary: VMware Private AI Cloud

VMware Private AI Cloud occupies a structurally unique position in this assessment series: it is neither an infrastructure OEM (Dell, HPE), a hyperscaler (AWS, Google Cloud), nor a data platform vendor (VAST). It is a virtualization and private cloud platform, the abstraction layer that sits between physical infrastructure and workloads. Broadcom’s strategic thesis is that VCF is ‘the permanent abstraction layer between AI software and physical chips,’ and Private AI Cloud extends that thesis into inference and agentic workloads. VMware AI Factory is its software-defined foundation, and Tanzu Platform is its agent platform.

The 4+1 model reveals both the power and the limits of this position. VCF’s strength is Layer 2A — infrastructure orchestration is VMware’s heritage and its deepest IP. VCF Automation, vSphere Supervisor, VKS, vSAN, NSX/vDefend, and VCF Operations collectively provide the most mature unified orchestration surface for mixed workloads (VMs, containers, AI) of any on-prem vendor assessed. No other vendor in this series manages GPU-accelerated AI workloads, Kubernetes clusters, and traditional VMs from a single control plane with equivalent operational maturity. That is a statement about capability on offer, not about how any particular enterprise assembles its stack. VCF is routinely deployed as the substrate under another vendor’s orchestration and runtime, OpenShift on VCF being the common case, and the layers of a real stack are filled by several vendors at once.

At Layer 0, VMware’s multi-accelerator management (AMD, NVIDIA, Intel) requires careful contextualization. GPU vendor choice is not unique to VMware — HPE’s GX5000 supports NVIDIA and AMD blades in the same rack, and hyperscalers fully abstract accelerators at the service layer (a developer calling Vertex AI or Bedrock never sees which silicon powers the response). VMware’s actual differentiator is the level of architectural control: operators manage GPU placement, isolation, and scheduling through familiar vSphere primitives (vGPU profiles, vmclasses, DRS, resource pools). The control plane is borrowed judgment — it is VMware’s opinionated virtualization model applied to acceleration — but that opinion provides stronger knobs that appeal to operators already comfortable with virtualization management. Where hyperscalers abstract the accelerator away from the architect, VMware puts the architect in the driver’s seat through a familiar console.

But the closer the stack gets to AI-specific functions such as model serving, retrieval, agent execution, and governance, the more authority shifts to the runtimes VMware ships (vLLM and Infinity in Private AI Services, with NVIDIA's stack now one option among AMD, NVIDIA, and Intel rather than the core), to open-source components (pgvector, Elasticsearch), or to capabilities that are emerging but not yet at the depth of purpose-built alternatives. Private AI Services (Model Runtime, Agent Builder, Data Indexing/Retrieval, Vector Database, Model Store) are genuine platform capabilities delivered as part of the VCF subscription, but they are foundational AI services, not the deep data lifecycle or agent orchestration that Dell (Dataloop), HPE (Ezmeral/Kamiwaza), or VAST (DataEngine/AgentEngine) provide. Layer 1C, data movement and pipelines, remains a gap: the enterprise brings its own pipeline orchestration and deploys it on VKS.

The installed base is the strategic moat: nine of the top ten Fortune 500 companies have committed to VCF, with 100M+ cores licensed worldwide. For the enormous VMware installed base, Private AI Foundation is the lowest-friction path to on-prem AI — no new infrastructure vendor, no new management plane, no new operational model, and no incremental cost beyond GPU hardware. The 4+1 question is whether lowest-friction adoption translates to sufficient architectural depth when agentic AI workloads demand governance, policy-driven placement, and cross-agent orchestration that VCF does not yet provide.

VMware Private AI Cloud is the enterprise’s most natural on-ramp to private AI, and AgentMinder makes it a real agent-governance platform rather than a collection of signals. The reasoning plane is a different question. Hock Tan’s ‘permanent abstraction layer’ framing is a Layer 2A statement: the abstraction layer manages resources, the reasoning plane governs where they are spent. The design allocates its agent-control effort to identity, enforcement, and audit. AgentMinder ships agent identity, intent binding, runtime authorization, and chain of custody. It does not place inference. It also does not require VCF, deploying on any conformant Kubernetes and integrating through AuthZEN, which means Broadcom built its agent control plane on a substrate independent of VCF, which is notable because VCF is what sees the entire virtualized estate across every OEM’s hardware. The architect buying this stack gets agent governance that travels, and gets no placement capability from the platform that has the broadest view of where workloads actually sit.

Layer-by-layer status: Layer 0 (Hardware-Agnostic Abstraction), Layer 1A (Platform Storage, Not AI-Native), Layer 1B (Foundational RAG Services), Layer 1C (No Pipeline Layer), Layer 2A (VMware Heritage Strength), Layer 2B (Platform-Native, Widening Beyond NVIDIA), Layer 2C (Agent Governance Ships, Placement Does Not), Layer 3 (+1) (ISV Ecosystem on a Private Cloud Platform).

Assessment framework: 4+1 Layer AI Infrastructure Model. Scoring model: Decision Authority Placement Model (DAPM) — Retained, Delegated, or Ceded. Published by The CTO Advisor LLC (DBA The Advisor Bench). Author: Keith Townsend. Date assessed: October 5, 2026. Version: v1.15 - 4+1 v2: NVIDIA One Path of Three.

VMware Private AI Cloud

Mapped to the 4+1 Layer AI Infrastructure Model

v1.15 - 4+1 v2: NVIDIA One Path of ThreeAssessed October 5, 2026Sources & revision history
ACTIVE ASSESSMENT

Summary Finding

VMware Private AI Cloud occupies a structurally unique position in this assessment series: it is neither an infrastructure OEM (Dell, HPE), a hyperscaler (AWS, Google Cloud), nor a data platform vendor (VAST). It is a virtualization and private cloud platform, the abstraction layer that sits between physical infrastructure and workloads. Broadcom’s strategic thesis is that VCF is ‘the permanent abstraction layer between AI software and physical chips,’ and Private AI Cloud extends that thesis into inference and agentic workloads. VMware AI Factory is its software-defined foundation, and Tanzu Platform is its agent platform.

The 4+1 model reveals both the power and the limits of this position. VCF’s strength is Layer 2A — infrastructure orchestration is VMware’s heritage and its deepest IP. VCF Automation, vSphere Supervisor, VKS, vSAN, NSX/vDefend, and VCF Operations collectively provide the most mature unified orchestration surface for mixed workloads (VMs, containers, AI) of any on-prem vendor assessed. No other vendor in this series manages GPU-accelerated AI workloads, Kubernetes clusters, and traditional VMs from a single control plane with equivalent operational maturity. That is a statement about capability on offer, not about how any particular enterprise assembles its stack. VCF is routinely deployed as the substrate under another vendor’s orchestration and runtime, OpenShift on VCF being the common case, and the layers of a real stack are filled by several vendors at once.

At Layer 0, VMware’s multi-accelerator management (AMD, NVIDIA, Intel) requires careful contextualization. GPU vendor choice is not unique to VMware — HPE’s GX5000 supports NVIDIA and AMD blades in the same rack, and hyperscalers fully abstract accelerators at the service layer (a developer calling Vertex AI or Bedrock never sees which silicon powers the response). VMware’s actual differentiator is the level of architectural control: operators manage GPU placement, isolation, and scheduling through familiar vSphere primitives (vGPU profiles, vmclasses, DRS, resource pools). The control plane is borrowed judgment — it is VMware’s opinionated virtualization model applied to acceleration — but that opinion provides stronger knobs that appeal to operators already comfortable with virtualization management. Where hyperscalers abstract the accelerator away from the architect, VMware puts the architect in the driver’s seat through a familiar console.

But the closer the stack gets to AI-specific functions such as model serving, retrieval, agent execution, and governance, the more authority shifts to the runtimes VMware ships (vLLM and Infinity in Private AI Services, with NVIDIA's stack now one option among AMD, NVIDIA, and Intel rather than the core), to open-source components (pgvector, Elasticsearch), or to capabilities that are emerging but not yet at the depth of purpose-built alternatives. Private AI Services (Model Runtime, Agent Builder, Data Indexing/Retrieval, Vector Database, Model Store) are genuine platform capabilities delivered as part of the VCF subscription, but they are foundational AI services, not the deep data lifecycle or agent orchestration that Dell (Dataloop), HPE (Ezmeral/Kamiwaza), or VAST (DataEngine/AgentEngine) provide. Layer 1C, data movement and pipelines, remains a gap: the enterprise brings its own pipeline orchestration and deploys it on VKS.

The installed base is the strategic moat: nine of the top ten Fortune 500 companies have committed to VCF, with 100M+ cores licensed worldwide. For the enormous VMware installed base, Private AI Foundation is the lowest-friction path to on-prem AI — no new infrastructure vendor, no new management plane, no new operational model, and no incremental cost beyond GPU hardware. The 4+1 question is whether lowest-friction adoption translates to sufficient architectural depth when agentic AI workloads demand governance, policy-driven placement, and cross-agent orchestration that VCF does not yet provide.

VMware Private AI Cloud is the enterprise’s most natural on-ramp to private AI, and AgentMinder makes it a real agent-governance platform rather than a collection of signals. The reasoning plane is a different question. Hock Tan’s ‘permanent abstraction layer’ framing is a Layer 2A statement: the abstraction layer manages resources, the reasoning plane governs where they are spent. The design allocates its agent-control effort to identity, enforcement, and audit. AgentMinder ships agent identity, intent binding, runtime authorization, and chain of custody. It does not place inference. It also does not require VCF, deploying on any conformant Kubernetes and integrating through AuthZEN, which means Broadcom built its agent control plane on a substrate independent of VCF, which is notable because VCF is what sees the entire virtualized estate across every OEM’s hardware. The architect buying this stack gets agent governance that travels, and gets no placement capability from the platform that has the broadest view of where workloads actually sit.

Strength
Moderate
Gap
Partner
Layer 0 · ComputeCompute & Network FabricHardware-Agnostic Abstractiondecides: vendor · Delegated▼

Raw compute, networking, and acceleration fabric

Vendor-Provided

VMware vSphere 8/9 (Hypervisor)Ceded

Industry-standard virtualization layer. GPU passthrough and vGPU support via NVIDIA AI Enterprise integration. vSphere Supervisor manages both VMs and Kubernetes workloads from a single control plane. vMotion for live migration of AI workloads. DRS for automated load balancing. The hypervisor is Broadcom’s foundational IP — the abstraction layer between physical infrastructure and all workloads above. vGPU profiles mapped to vSphere Namespaces as vmclasses for multi-tenant GPU isolation are vSphere opinions and stay with vSphere (moved here from the NVIDIA integration chip, October 5, 2026).

Multi-Vendor Hardware SupportRetained

VCF runs on Dell PowerEdge, HPE ProLiant, Lenovo ThinkSystem, Cisco UCS, Supermicro, NEC, Fujitsu, and others. Hardware-agnostic by design — VCF does not manufacture or specify compute. This is the fundamental architectural difference from Dell AI Factory or HPE Private Cloud AI: VMware abstracts hardware, OEMs provide it. The enterprise retains hardware vendor choice.

NVIDIA GPU Integration (vGPU + Passthrough), One Accelerator Path of ThreeDelegated

VCF 9.1 supports NVIDIA Blackwell architecture, NVSwitch on HGX platform, and GPUDirect RDMA over InfiniBand for distributed LLM inference across multiple HGX servers, with enhanced DirectPath I/O for ConnectX-7 NICs and BlueField-3 DPUs. NVIDIA is one accelerator path, not the core: VCF manages AMD and Intel accelerators through the same control plane, and Private AI Services serves models on vLLM and Infinity. Delegated: the enterprise can replace VMware's GPU integration with another hypervisor's without rebuilding its GPU opinions. Pressure-tested October 5, 2026 against the Red Hat standard: the vGPU profiles, MIG layout, scheduler policy, and license server are NVIDIA's definitions and lift intact to any of the five hypervisors NVIDIA supports (vSphere, AHV, RHEL KVM, Ubuntu KVM, Citrix). They don't lift off NVIDIA; that capture is NVIDIA's and sits in the NVIDIA column under the owner's-row ruling.

NSX / vDefend NetworkingCeded

Software-defined networking with micro-segmentation, Zero Trust enforcement via Distributed Firewall (Antrea CNI for Kubernetes), and in-memory malware defense. Avi Load Balancer provides virtualized load balancing for AI inference endpoints and agentic applications — eliminates hardware appliance requirements. Post-quantum cryptography support.

Multi-Accelerator Management (AMD + NVIDIA + Intel)Ceded

VCF 9.1 manages AMD, NVIDIA, and Intel accelerators through the same virtualization control plane — vGPU profiles, vmclasses, DRS policies, resource pools. The architect retains granular control over GPU placement, isolation, and scheduling using familiar vSphere primitives. This is not unique as a multi-vendor GPU capability (HPE GX5000 supports NVIDIA Rubin + AMD MI430X in the same rack; hyperscalers fully abstract accelerators at the service layer). VMware’s differentiator is the level of architectural control: operators already comfortable with virtualization management get GPU scheduling knobs they know how to turn. The control plane is opinionated — it applies VMware’s virtualization model to acceleration — but that opinion is the value for VMware-native shops.

NVIDIA-Provided

NVIDIA AI Enterprise (NVAIE)

Enterprise AI software suite providing vGPU drivers, GPU Operator for Kubernetes, and validated AI frameworks. NVAIE licenses purchased separately from VCF. Deeply integrated but independently licensed — the same NVIDIA dependency Dell and HPE share.

NVIDIA GPU Silicon + Networking

Blackwell, H100/H200, ConnectX-7/8, BlueField-3 DPUs, NVSwitch, InfiniBand. VMware validates and integrates but does not manufacture or specify GPU silicon.

NVIDIA NIM Microservices

Pre-built inference microservices deployable on Private AI Foundation. Nemotron models and community models available through Model Store.

◆ Gap Analysis

VMware’s Layer 0 position is fundamentally different from every other vendor in this assessment: VMware provides the abstraction layer, not the physical infrastructure. Dell, HPE, and VAST own or specify hardware. Google and AWS own data centers. VMware sits above all of them. This creates a unique DAPM profile: the enterprise Retains hardware vendor choice (can switch from Dell to HPE to Lenovo without changing the management plane) and keeps accelerator choice too: VCF manages AMD, NVIDIA, and Intel through one control plane, so NVIDIA is one accelerator path rather than the core of the stack. What the enterprise inherits is whatever GPU integration VMware has validated for the accelerator it picks. The abstraction is VMware’s value proposition and its architectural constraint — VMware can only support GPU features that the hypervisor can virtualize or pass through. Multi-accelerator support requires nuanced comparison across the assessed vendors. GPU vendor choice is NOT unique to VMware: • Hyperscalers (Google, AWS) fully abstract accelerators at the service layer — developers call Vertex AI or Bedrock and never see whether TPUs, Trainium, or NVIDIA GPUs power the response. Accelerator choice is Ceded to the cloud provider. Simplest developer experience, least architectural control. • HPE GX5000 supports NVIDIA Rubin and AMD MI430X GPU blades in the same rack architecture. Multi-vendor at the hardware level. • Dell AI Factory is NVIDIA-only. ‘Dell AI Platform with AMD’ is a separate branding, separate software stack — not a unified runtime. • Broadcom is collaborating with AMD to pair VCF with Instinct MI350 Series GPUs and the ROCm ecosystem under one provisioning path (vSphere and vSAN through Kubernetes and the AMD GPU operator, with the DVX driver attaching GPUs to VKS-consumed VMs). If it ships as described, VMware lands on the HPE side of this line at the software layer rather than the Dell side. It is announced, not GA, so it does not move the cell. • VAST CNode-X is NVIDIA-only. VMware’s actual differentiator is the level of architectural control over acceleration: VCF manages AMD, NVIDIA, and Intel accelerators through familiar virtualization primitives (vGPU profiles mapped to vmclasses, DRS for GPU workload balancing, vMotion for live migration, resource pools for multi-tenant isolation). The enterprise architect retains granular control over GPU placement, scheduling, and isolation using tools they already operate. The control plane is borrowed judgment — it is VMware’s opinionated virtualization model applied to GPU resources — but that opinion provides stronger knobs that appeal specifically to operators already comfortable with vSphere management. Where hyperscalers abstract the accelerator away from the architect, VMware puts the architect in the driver’s seat through a familiar console. The vDefend security story is architecturally significant for AI: micro-segmentation at the packet level between every AI component (model server, vector database, embedding service, API gateway) with Terraform-codified firewall rules. This is infrastructure-layer Zero Trust for AI workloads — a capability that Dell and HPE don’t provide at equivalent depth from the platform layer. VAST’s CrowdStrike integration operates at a different level (application/data-layer security vs. network-layer micro-segmentation).

◆ Borrowed Judgment

Multi-directional: VMware borrows GPU silicon judgment from whichever accelerator vendor the enterprise chooses (AMD, NVIDIA, or Intel) and hardware engineering judgment from OEM partners (Dell, HPE, Lenovo build the servers). But VMware retains the abstraction layer — the hypervisor, the networking, the security model, the orchestration. This is the inverse of Dell’s position: Dell retains hardware judgment and borrows software judgment from NVIDIA. VMware retains software judgment and borrows hardware judgment from OEMs. Critically, the VMware control plane is itself borrowed judgment for the enterprise: the architect gains granular GPU management through vSphere primitives, but those primitives encode VMware’s opinions about how acceleration should be virtualized, scheduled, and isolated. The enterprise borrows VMware’s virtualization worldview in exchange for operational familiarity. This is a different trade-off than the hyperscalers (where the enterprise cedes acceleration decisions entirely) or bare-metal (where the enterprise retains full control but builds everything). VMware occupies the middle: more control than cloud, less effort than bare-metal, but through an opinionated lens. The NVIDIA AI Enterprise dependency applies on the NVIDIA path, where vGPU needs NVAIE licensing; unlike Dell's NVIDIA-only factory, VMware's model runtime (vLLM and Infinity in Private AI Services) and its AMD and Intel paths don't depend on it. VMware’s co-engineering relationship with NVIDIA on VCF integration is comparable to HPE’s Private Cloud AI co-engineering. Decision authority under the override rule (September 4, 2026): DRS places VMs, but a VM-Host rule set to 'Must run on hosts in group' is mandatory, and per-VM manual DRS automation is a documented manual action. Both are pins: vendor decides, visible, overridable, Delegated, the SUSE reading.

◆ Working Notes

The Broadcom acquisition context is impossible to ignore at Layer 0: Gartner projects VMware’s virtualization market share will fall from 70% (2024) to 40% (2029) due to pricing changes. Nutanix CEO has publicly targeted 165,000 of VMware’s approximately 300,000 customers. Broadcom has converted 90%+ of the top 10,000 VMware customers to VCF subscriptions with 200-500% price increases reported. This creates a unique installed-base dynamic: Private AI Foundation’s market opportunity is less about winning new customers than about retaining existing ones by making VCF indispensable for AI workloads. If the enterprise is already paying for VCF, Private AI Services come at no additional cost — a fundamentally different go-to-market than Dell (buy new PowerEdge + NVIDIA), HPE (buy new Private Cloud AI), or VAST (deploy new AI OS). The air-gapped deployment support is significant for regulated industries and government — same capability Dell and HPE emphasize, delivered through the existing VCF automation framework rather than a purpose-built AI appliance. Announced at VMware Explore, August 31, 2026. None of this is GA, and none of it moves this cell: • VMware AI Factory with AMD Instinct MI350 Series and ROCm, with zero-touch provisioning across vSphere, vSAN, VKS, and the AMD GPU operator. Announced as a collaboration; no GA date. • MetalSoft partnership for heterogeneous bare-metal automation, provisioning and repaving multi-vendor physical servers directly from the VCF management console and folding firmware and hardware lifecycle into VCF. Announced as a future integration; no GA date. If it ships, VCF reaches into Layer 0 lifecycle it does not own today. • VCF AI ReadyNodes from Cisco, Lenovo, Supermicro and others alongside certified Dell PowerEdge. Certification breadth, not a capability change.

Layer 1A · StorageData Storage & GovernancePlatform Storage, Not AI-Nativedecides: vendor · Ceded▼

Durable, governed data foundation — the Governance Catalog that Layer 2C queries

Vendor-Provided

vSAN (HCI Storage)Ceded

Hyper-converged storage integrated into VCF. Block and file storage natively. vSAN deduplication and compression for cost reduction. Unified storage policies and multi-tenant self-service access. Proprietary VMware platform: vSAN storage policies cannot be lifted to PowerScale, ONTAP, or VAST without rebuilding.

vSAN for Recovery + Ransomware RecoveryCeded

Sovereign, in-place ransomware recovery using native snapshot capabilities. Deep snapshot chains and integrated replication workflows. On-prem recovery without external dependencies.

Model Store (Private AI Services)Ceded

Curated LLM repository with integrated RBAC access control. MLOps teams and data scientists can securely manage and provide LLMs with governance and security for enterprise data and IP. NVIDIA models, Nemotron, and community models available. Proprietary VMware/Broadcom platform — opinions captive, no open exit.

External Storage IntegrationDelegated

VCF supports Dell PowerScale, Dell ObjectScale, NetApp ONTAP, Pure Storage, HPE Alletra, and other enterprise storage via vSphere APIs. The storage layer is not limited to vSAN — enterprises can bring existing storage investments. This is a heterogeneous storage approach vs. Dell’s vertically integrated storage (PowerScale/ObjectScale/Exascale) or VAST’s collapsed storage (Element Store).

NVIDIA-Provided

No Direct NVIDIA Layer 1A Dependency

NVIDIA does not provide storage or governance components in the VMware Private AI stack. Storage is VMware-owned (vSAN) or enterprise-chosen (external arrays).

◆ Gap Analysis

VMware’s Layer 1A is fundamentally different from every other assessed vendor because VMware is not a storage company. vSAN provides competent hyper-converged block and file storage, but this is general-purpose platform storage — not AI-optimized data infrastructure. Compare to Dell: MetadataIQ indexes billions of files with AI-specific metadata enrichment. Exascale provides 10+ PB/rack unified file+object+fast-file. Trust3 AI provides storage-layer governance for sensitive data discovery. Compare to HPE: Data Fabric v8.1 provides policy-based data placement with Apache Polaris catalog for Iceberg tables. Alletra B10000 provides real-time agentic storage support with semantic understanding. Compare to VAST: Element Store collapses file, object, table, and vector into a single governed data structure with inline metadata enrichment. VMware’s storage story is ‘bring your existing storage’ — which is pragmatic for the installed base but means Layer 1A governance (metadata richness, data lineage, policy-based placement) depends entirely on whichever external storage vendor the enterprise has deployed. VMware itself provides no AI-specific governance catalog, no metadata enrichment, no data lineage tracking. The Model Store capability is a Layer 1A function worth noting: RBAC-governed model repository is a governance primitive that Dell’s AI Factory lacks as a platform-native capability. But Model Store governs models, not data — it does not address the broader question of which data feeds which model under what compliance constraints.

◆ Borrowed Judgment

Low for vSAN (VMware-owned). High for AI-specific storage governance — entirely dependent on whichever external storage vendor the enterprise deploys. If the enterprise runs Dell storage, it inherits Dell’s governance capabilities (MetadataIQ). If it runs NetApp, it inherits NetApp’s. VMware provides no abstraction or unification of storage governance across heterogeneous backends. This is the inverse of VMware’s Layer 0 strength: at Layer 0, VMware abstracts heterogeneous hardware into a unified management plane. At Layer 1A, VMware does NOT abstract heterogeneous storage governance into a unified governance plane. The storage abstraction stops at provisioning and capacity management — it does not extend to metadata, lineage, or policy.

◆ Working Notes

The native S3 Object Storage in VCF 9.1.x (tech preview) is a strategic move: S3 compatibility is the lingua franca of AI data pipelines. Every vendor in this assessment provides S3 access (Dell ObjectScale, HPE Alletra X10000, VAST DataStore, AWS S3, Google Cloud Storage). VMware adding native S3 to vSAN reduces the dependency on external object storage for AI workloads. The Tanzu Marketplace integration provides a curated path to certified middleware and data services — this is VMware’s approach to ecosystem curation at the data layer, comparable in intent (not depth) to HPE’s Unleash AI program or VAST’s Cosmos Community. SQL Server DBaaS as a first-class VCF citizen is a pragmatic enterprise play — most enterprises have SQL Server deployments, and making it a platform service reduces the friction of data access for AI workloads. Announced August 31, 2026, not GA, not scored: • A unified model gallery as a single interface for deploying and managing inference and RAG workflows across VMs, containers, and GPUs, with governed models-as-a-service. This extends the Model Store governance primitive rather than adding data governance. • Tanzu Platform curated marketplace, a centralized catalog where developers and agents discover vetted models, tools, and data products. Generally available in Tanzu Platform in Fall 2026. Neither addresses what this cell actually flags: VMware still provides no AI metadata enrichment, no data lineage over enterprise storage, and no unification of governance across heterogeneous storage backends. Not GA, not scored: vSAN native S3-compatible object storage, which would bring block, file, and object onto one vSAN cluster with multi-tenancy and buckets-as-a-service through VCF Automation. Broadcom documents it as a Technology Preview in an upcoming VCF 9.1 patch, and Explore 2026 did not move it. On GA it splits out as its own component and scores Delegated, matching how the instrument treats S3-interface object storage everywhere: the consumed interface is a genuine multi-vendor standard, so bucket and lifecycle opinions lift. Until then there is no VMware object surface to score, which is why this cell carries no Delegated object component where Nutanix (NUS Objects, GA) does.

Layer 1B · RetrievalContext Management & RetrievalFoundational RAG Servicesdecides: vendor · Delegated▼

Low-latency retrieval for RAG — vector/hybrid search, context windows

Vendor-Provided

Data Indexing & Retrieval (Private AI Services)Ceded

Index and maintain multiple data sources, making them readily available for consumption by AI applications. Integrated with Model Runtime for RAG workflows. Keeps indexed data current as sources change. Proprietary VMware/Broadcom platform — opinions captive, no open exit.

Vector Database (Private AI Services)Delegated

pgvector on PostgreSQL delivered via Data Services Manager with VMware enterprise-level support. Enables domain-specific, up-to-date context for AI models. PostgreSQL 16.8 with pgvector 0.8.0 extension in Private AI Services 2.1. pgvector is OSS and the consumed interface is standard PostgreSQL — embeddings, schema, and index definitions lift via pg_dump to any Postgres platform; DSM operates the database, the open substrate keeps the retrieval opinions portable.

RAG Pipeline IntegrationDelegated

NVIDIA NIM RAG Blueprint v2.5.0 validated on VCF — production-grade, multi-model RAG pipeline. Pre-built catalog items in VCF Automation for deploying complete RAG workflows. Elasticsearch supported as external vector database for advanced retrieval scenarios.

NVIDIA-Provided

NVIDIA NIM + NeMo Retriever

Inference microservices and retrieval-augmented generation components. RAG Blueprints provide pre-built retrieval patterns. Same capabilities available on Dell and HPE platforms.

NVIDIA AI Enterprise RAG Stack

Validated software stack for RAG workflows on VMware Private AI Foundation. GPU-accelerated embedding generation and retrieval.

◆ Gap Analysis

VMware’s Layer 1B provides functional RAG capabilities through Private AI Services — Data Indexing/Retrieval and Vector Database are genuine platform services, not just partner integrations. But the retrieval stack is foundational, not differentiated. pgvector on PostgreSQL is a competent vector database for moderate-scale use cases but lacks the performance characteristics of purpose-built alternatives. Compare to Dell’s Data Search Engine (Elasticsearch 9.4 with GPU-accelerated hybrid search, MetadataIQ integration). Compare to VAST’s InsightEngine (native to the data platform, no data movement for retrieval). Compare to HPE’s Alletra X10000 with KV cache storage support for inference state persistence. The Data Indexing & Retrieval service addresses the core RAG requirement — keeping context current as data sources change — but without the metadata richness or governance integration that Dell (MetadataIQ + Elastic), HPE (Data Fabric + Kamiwaza), or VAST (Catalog + InsightEngine) provide. No retrieval quality observability (recall@k, latency percentiles) is evident — the same gap identified in the Dell assessment. A Layer 2C placement engine would need retrieval quality metrics to make informed routing decisions.

◆ Borrowed Judgment

Moderate. VMware owns the Data Indexing/Retrieval and Vector Database services. RAG pipeline patterns depend on NVIDIA NIM/Blueprints (same dependency as Dell and HPE). Elasticsearch as external vector database option introduces the same Elastic dependency Dell has — search intelligence is Elastic’s, not VMware’s. The pgvector choice is notable: PostgreSQL is the most widely deployed enterprise database. By building on pgvector, VMware reduces adoption friction (most enterprises already have PostgreSQL expertise) at the cost of retrieval performance ceiling. Dell chose Elasticsearch (higher performance, more complex). VAST built its own (highest integration, most proprietary). VMware chose the most pragmatic option.

◆ Working Notes

The OpenWebUI integration with Private AI Services RAG demonstrates VMware’s approach to Layer 1B: provide the retrieval infrastructure, let the enterprise choose the user-facing application layer. This is consistent with VMware’s platform philosophy — VMware provides infrastructure services, not applications. The RAG Blueprint validation on VCF (multi-model, production-grade, 8x NVIDIA H100 80GB GPUs) provides a concrete reference architecture that enterprises can deploy from VCF Automation catalog items. This is operationally simpler than assembling equivalent RAG infrastructure on bare-metal Dell or HPE hardware. Announced August 31, 2026, not GA, not scored: • Tanzu Platform AI-Ready Data Foundations, processing structured and unstructured enterprise data on-site to deliver high-precision context to agents, with lineage tracing every agentic decision back to the data it used. Generally available in Tanzu Platform in Fall 2026. Tracked as a facet here and at 1C, not assigned to one of them: the context-preparation function is 1B’s and the lineage function is 1C’s, and how Broadcom packages the capability does not decide which cell an architect shops it against. Lineage over agent-consumed data is a governance capability this stack has not previously carried. • AI Gateway providing unified model governance between on-premises and cloud through a single consumption interface. Announced as forthcoming; no GA date. On GA these would move 1B toward the depth of purpose-built retrieval stacks. Today the shipping retrieval surface is still pgvector, Elasticsearch, and Data Indexing/Retrieval.

Layer 1C · PipelinesData Movement & PipelinesNo Pipeline Layerdecides: absent · Absent▼

Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering

Vendor-Provided

NVIDIA-Provided

NVIDIA Blueprints

Pre-built AI application patterns deployable through VCF Automation. Pipeline templates, not pipeline infrastructure — same as Dell and HPE.

NVIDIA CMX (Future)

KV cache management for context memory offload. When integrated with VCF, could provide the same KV cache tiering Dell has validated (19x TTFT improvement).

◆ Gap Analysis

Layer 1C is VMware’s most significant gap relative to other assessed vendors. VMware provides no equivalent to: • Dell’s Data Orchestration Engine (Dataloop): No-code/low-code AI data lifecycle management, Dell’s most meaningful software acquisition. • HPE’s Ezmeral Unified Analytics: Enterprise-hardened ML pipeline stack (Airflow, Kubeflow, Ray, Feast, MLflow, Spark). • HPE’s Data Fabric: Policy-based data placement with compliance tagging and data lineage. • VAST’s DataEngine: Serverless data transformation with CLI/SDK, built-in observability, triggers, and automated pipelines. VCF Automation provides deployment pipelines (standing up AI infrastructure) but not data pipelines (moving, transforming, and governing data through ML workflows). The enterprise running VMware Private AI Foundation must bring its own data pipeline orchestration — Airflow, Kubeflow, or a commercial alternative — and deploy it on VKS. This is architecturally consistent with VMware’s platform philosophy: VCF provides infrastructure services, not application-layer data engineering tools. But it leaves a functional gap that competitors have filled. An enterprise choosing VMware for AI inherits a Layer 1C assembly problem that Dell (Dataloop), HPE (Ezmeral), or VAST (DataEngine) partially or fully solve. Decision authority: VMware ships and certifies nothing at this layer, so the reading is Absent; the Airflow or Kubeflow the enterprise deploys is its own, not a reading of VMware (gap-layer narrowing, October 4, 2026).

◆ Borrowed Judgment

High. The enterprise must borrow data pipeline judgment from whatever tools it deploys on VKS — Apache Airflow community, Kubeflow community, or a commercial vendor (Dataloop, Databricks, etc.). VMware provides no opinion on data pipeline architecture, no integration between pipeline metadata and infrastructure governance, and no data lineage capability. Compare to Dell: Dell acquired Dataloop specifically to address Layer 1C. Compare to HPE: HPE assembled Ezmeral through four acquisitions (BlueData, MapR, Ampool, Arrikto). Compare to VAST: VAST built DataEngine as a native platform capability. VMware has made no equivalent investment in data pipeline IP.

◆ Working Notes

The gap is real but may be strategic: VMware has historically succeeded by providing infrastructure primitives that partner ecosystems build on, rather than by building application-layer tooling. The question is whether AI data pipelines are infrastructure (VMware should own them) or applications (VMware should enable them). The Tanzu Marketplace could address this gap through curated data pipeline services — certified Airflow, MLflow, or Kubeflow deployments validated for VCF. This would be a Delegated approach (partner provides the capability, VMware validates the deployment) rather than a Retained approach (VMware builds the capability). Architecturally similar to HPE’s Unleash AI ecosystem model. The KV cache story is notably absent: Dell has validated NVIDIA CMX with 19x TTFT improvement on PowerScale. HPE has native KV cache storage support in Alletra X10000. VAST collocates cache and compute in CNode-X. VMware has not yet announced equivalent KV cache tiering capabilities. (Enhanced NVMe memory tiering in VCF 9.1 addresses memory-bound performance, not data-pipeline orchestration.) Tanzu Platform’s AI-Ready Data Foundations (Fall 2026) is tracked against this cell as well as 1B. Lineage is named in this layer’s own function alongside ETL/ELT and cost-aware movement, and the capability claims lineage tracing every agentic decision back to the data it used and where it came from. That is a 1C function whatever Broadcom calls the product, and it is the first thing VMware has offered against this cell. It does not close the cell, and the reason is function rather than framing. There is still no general pipeline orchestration here: no arbitrary transformation stages, no scheduling and dependency management for ML workflows, no cost-aware movement between tiers. The day-two test decides the grade. When the enterprise’s second data-engineering requirement arrives, the one Broadcom did not design for, another tool still lands beside the platform, so Airflow or Kubeflow on VKS remains the answer and this cell holds at gap. On GA, assess the lineage facet here on its own merits rather than deferring to where the feature sits in Broadcom’s product taxonomy. Partial credit against 1C’s lineage function is the live question; it will not on its own carry the cell past gap without pipeline generality.

Layer 2A · OrchestrationInfrastructure OrchestrationVMware Heritage Strengthdecides: vendor · Delegated▼

GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization

Vendor-Provided

VCF Automation (formerly vRealize/Aria Automation)Ceded

Self-service catalog with pre-built AI workload templates. Quickstart deployment for Private AI Foundation. Infrastructure-as-code with Terraform integration. Multi-tenant resource provisioning with RBAC. Live Application Stack Blueprints for versioned, redeployable application topologies. Day 2 operations for AI Blueprints. Proprietary VMware/Broadcom platform — opinions captive, no open exit.

vSphere Supervisor + VKSDelegated

Unified management of VMs, containers, and AI workloads from a single control plane. VKS (vSphere Kubernetes Service) 3.6 supports up to 500 Kubernetes clusters per Supervisor. Simplified Container-as-a-Service for application teams. VM Fast-Deploy for accelerated provisioning. vSphere Elastic Provisioning for zero-touch fleet expansion. GitOps-based infrastructure management. VKS is conformant Kubernetes — manifests and workloads lift to another conformant cluster without rebuilding, so the K8s opinions are portable (scored as the cloud managed-K8s services are); the proprietary fleet and lifecycle management is captured in the Ceded VCF Automation / Operations / SDDC Manager components.

VCF Operations (formerly vRealize/Aria Operations)Ceded

Private AI Model and GPU Metrics — utilization, memory pressure, and model-level visibility on the same console as the rest of the estate. Real-Time Operational Observability turns telemetry into action. Customizable dashboards for AI model and agent performance. Capacity management and compliance monitoring for AI workloads. Proprietary VMware/Broadcom platform — opinions captive, no open exit.

SDDC ManagerCeded

Full-stack lifecycle management for VCF. Automated deployment, patching, and upgrades across vSphere, vSAN, NSX, and VKS. Single-pane fleet management. Expanded fleet size and upgrade scale in 9.1. This is the operational backbone — the equivalent of HPE’s GreenLake or Dell’s APEX management, but with 20+ years of enterprise maturity. Proprietary VMware/Broadcom platform — opinions captive, no open exit.

Advanced Cyber Compliance (ACC)Ceded

Continuous compliance enforcement with automated drift detection and remediation. Hardened infrastructure images. Integrated with vDefend for security posture management. Disaster recovery via vSAN for Recovery. Proprietary VMware/Broadcom platform — opinions captive, no open exit.

MCP Server Governance (VCF 9.1)Ceded

IT operations can centrally manage and control access to MCP tools and associated servers across their environment. Ensures user groups can only access approved MCP tools. Security guardrails for MCP servers via vDefend and Avi Load Balancer. This is a Layer 2A governance function with 2C implications — controlling which agents can access which tools. Proprietary VMware/Broadcom platform — opinions captive, no open exit.

NVIDIA-Provided

NVIDIA GPU Operator

Kubernetes operator for GPU lifecycle management. Manages GPU drivers, container runtime, device plugins. Standard across all NVIDIA-integrated platforms.

NVIDIA vGPU Manager

GPU virtualization profiles and multi-tenant GPU allocation. Memory partitioning and time-sliced compute scheduling. Managed through vSphere Supervisor.

◆ Gap Analysis

Layer 2A is VMware’s strongest layer — arguably the strongest Layer 2A of any vendor in this assessment series. The reason is operational maturity: VCF has been managing enterprise infrastructure for two decades. No other vendor assessed has equivalent depth in lifecycle management, multi-tenant orchestration, compliance automation, and unified VM/container/AI workload management. Where this design differs from the calibration set: • Unified workload management: Dell manages AI workloads separately from traditional workloads (OpenManage for servers, Run:ai for GPUs, separate tools for each). HPE manages AI through GreenLake Intelligence + OpsRamp + Private Cloud AI (three systems). VMware manages AI, containers, and VMs from ONE control plane (vSphere Supervisor). VAST manages only VAST workloads. • Operational maturity: VCF’s Day 2 operations (patching, upgrades, compliance, capacity planning) for AI workloads inherit the same proven processes used for the enterprise’s existing VM fleet. New operational model required? Zero. Dell and HPE AI stacks require new operational processes. VAST requires an entirely new operational discipline. • MCP Server Governance is a notable 2A/2C bridge: centrally controlling which user groups can access which MCP tools is an infrastructure-level governance function that no other on-prem vendor provides as a platform native capability. Google’s Agent Gateway provides equivalent capability in cloud. Read the capability and the deployment separately. VCF is frequently bought as the virtualization substrate underneath another vendor’s orchestration, and OpenShift on VCF is the common case. In that stack the customer consumes VCF for Layer 0 and infrastructure lifecycle while Red Hat owns the Kubernetes control plane, so vSphere Supervisor and VKS are licensed and unconsumed, and the 2A judgment the enterprise actually inherits is Red Hat’s. The grade here reflects what an architect can deploy on Broadcom’s paper, which is the strongest 2A on the instrument. It does not assert that any given customer runs it. A strong cell is an available option, not an occupied slot. That pattern also makes the Delegated call on vSphere Supervisor and VKS concrete rather than theoretical. The exit is not a thought experiment about conformant Kubernetes; it is a deployment shape enterprises already run. The GPU scheduling gap remains: NVIDIA GPU Operator and vGPU Manager handle GPU allocation, but policy-driven GPU scheduling (which workload gets which GPU based on cost, compliance, and performance constraints) is not a VCF-native function. This is the same gap Dell has with Run:ai — the scheduling intelligence is NVIDIA’s, not the platform vendor’s.

◆ Borrowed Judgment

Low — the lowest of any layer in the VMware assessment. VCF Automation, vSphere, VKS, vSAN, NSX, VCF Operations, and SDDC Manager are all Broadcom/VMware IP. GPU scheduling is the primary borrowed judgment (NVIDIA GPU Operator + vGPU Manager), but this is the same dependency every on-prem vendor shares. Compare to Dell Layer 2A: Dell splits 2A between OpenManage (Dell-owned) and Run:ai (NVIDIA-owned, acquired). VMware retains more 2A authority than Dell. Compare to HPE Layer 2A: HPE’s GreenLake Intelligence is HPE-owned 2A with MCP-based agent communication. VMware’s VCF Operations is VMware-owned 2A with emerging MCP support. Both retain 2A authority; different architectural approaches (HPE: agentic mesh; VMware: traditional orchestration evolving toward agentic). Decision authority under the override rule (September 4, 2026): DRS honors 'must' VM-Host rules, and VKS is conformant Kubernetes, where nodeSelector and required affinity pin pods. Vendor decides, visible, overridable, Delegated, the Red Hat and SUSE reading.

◆ Working Notes

The Intelligent Assist for VCF (tech preview) signals VMware’s evolution toward agentic infrastructure management. An AI-driven support assistant that diagnoses and resolves issues by consulting Broadcom’s knowledge base is functionally similar to HPE’s GreenLake Intelligence domain agents or Dell’s CloudIQ — but at an earlier stage of development. The 100M+ licensed cores installed base gives VMware an operational data advantage no other on-prem vendor can match: patterns learned from managing the world’s largest virtualization fleet can inform AI workload optimization in ways that newer platforms cannot. Nothing in the shipping product surfaces that fleet data as AI-specific intelligence; the operational advantage is latent, not productized. Announced August 31, 2026, not GA, not scored: • VMware AI Factory infrastructure automation, claiming bare metal to first served model in hours rather than weeks through fully automated hardware provisioning, software stack enablement, and end-to-end lifecycle management. • The MetalSoft integration, which would extend VCF’s operational workflows down to physical servers from multiple vendors through the VCF management console. Both are consistent with what already makes this the strongest 2A on the instrument. Neither is GA, and 2A does not need them to hold its grade. MCP Server Governance is scored here and again at 2C as facets of one capability. Infrastructure teams administer it, which is this cell’s function, and it governs which agents reach which tools, which is 2C’s. Controlling which user groups reach which MCP tools is agent-tool access governance, and the instrument scores the comparable capability at 2C elsewhere (Cisco’s AI Defense agent governance; the tool-access restrictions inside Salesforce’s 2C gateway). Against that, it ships as a VCF IT-operations capability administered by the infrastructure team, which is what this cell holds. Neither status turns on it: 2A holds strong either way and 2C holds moderate either way. Which layer owns agent tool access is a cross-row question.

Layer 2B · RuntimeApplication Runtime & ExecutionPlatform-Native, Widening Beyond NVIDIAdecides: model · Delegated▼

Model serving, agent execution, inference APIs, distributed inference

Vendor-Provided

Model Runtime — Inference Endpoints (OpenAI-compatible)Delegated

Run completion and embedding models as a service across the organization. Model endpoints are exposed through OpenAI-compatible APIs and executed on vLLM and Infinity, so applications call the same interface they would call against any other provider. Multi-accelerator support means the same model deployment runs on AMD and NVIDIA GPUs without refactoring. The consumed interface is a genuine multi-vendor standard, and the serving engines underneath are OSS, so the application-side opinions lift to another platform without rebuilding. Delegated on the same basis as Nutanix’s inference runtime.

Customer-Created and Managed Tools (Function Calling / Client-Side)Retained

GA through Private AI Services' OpenAI-compatible inference endpoints (vLLM). The enterprise owns and operates the business logic, APIs, commands and deterministic validators invoked through tool calls: the seam where control passes from instructing the model to executing code outside it. The opinions are the enterprise's and run against a multi-vendor interface, so they lift to another provider with an adapter and re-evaluation, not a rebuild. What the enterprise cedes at this seam is the decision to act: the model chooses whether, when and with which arguments to call, and that judgment is inherited under the serving component above. Added instrument-wide on September 2, 2026 (M4): the seam exists on every runtime that hands control to portable customer code, and a real Retained position is scored, not narrated.

Private AI Services Platform Surface (Model Gallery, endpoint lifecycle, tenancy)Ceded

The VMware surface wrapped around those endpoints: the Model Gallery and Harbor-backed registry, endpoint creation and lifecycle through the VCF Automation UI, and multi-tenant Models-as-a-Service for sharing models across business units. This is the capture that graduates beyond the standard interface. Registry structure, endpoint definitions, and tenancy policy are VMware-specific and do not lift, even though the inference calls in front of them do.

Agent Builder (Private AI Services)Ceded

Build AI agents in a user-friendly playground, leveraging models and knowledge bases created using other Private AI services. Integrated with Model Runtime and Data Indexing/Retrieval for end-to-end agent development. This is a platform-native agent construction surface — not as deep as VAST’s AgentEngine or Google’s Agent Studio/ADK, but integrated into the VCF operational model. Proprietary VMware/Broadcom platform — opinions captive, no open exit.

Deep Learning VMsDelegated

Pre-configured virtual machines with validated AI/ML software stacks: PyTorch, TensorFlow, Miniconda. Software stack validated in advance on NVIDIA GPUs — data scientists start developing immediately without compatibility validation. Provisioned through VCF Automation self-service catalog.

VKS AI ClustersCeded

GPU-capable Kubernetes worker nodes for cloud-native AI/ML workloads. Triton Inference Server deployable from catalog. Distributed LLM inference with GPUDirect RDMA over InfiniBand for models that exceed single-server capacity (DeepSeek-R1, Llama 3.1-405B). This is infrastructure-layer runtime support, not an opinionated agent execution framework.

Tanzu Platform (Application Runtime)Ceded

PaaS-layer application runtime. ‘You provide code, we put it into production.’ Governed agentic coding with Tanzu. Developers can self-publish AI agents and MCP servers, sharing AI applications and tools across the enterprise. MCP server publishing makes Tanzu a distribution surface for enterprise agent tooling.

Spring AI + MCP Java SDK (Tanzu)Delegated

Broadcom owns Spring, and Spring AI is the model-calling, RAG, vector-store, and tool-calling framework for enterprise Java, with MCP Boot Starters integrated into Tanzu Platform. Broadcom shipped Spring AI MCP within weeks of the protocol’s announcement and donated the Java SDK, which Anthropic adopted as the official Java SDK for MCP. Apache 2.0 with a real alternative in LangChain4j, so the application opinions written against it lift to any JVM on any platform. This is the execution facet; the application-estate facet is scored at Layer 3.

NVIDIA-Provided

NVIDIA AI Enterprise Runtime

NIM inference microservices, model optimization, GPU-accelerated frameworks. The core AI runtime dependency — VMware’s Model Runtime wraps NVIDIA inference capabilities in a platform-managed service.

NVIDIA NIM Agent Blueprints

Pre-built agentic workflows (RAG, PDF extraction, digital twins). Same blueprints available on Dell, HPE, Cisco, Lenovo. Non-differentiating for VMware at 2B.

NVIDIA Triton Inference Server

Multi-framework model serving. Deployable as VCF Automation catalog item on GPU-capable VKS clusters.

◆ Gap Analysis

VMware’s Layer 2B is the most architecturally interesting in this assessment because it combines platform-native AI services (Model Runtime, Agent Builder) with NVIDIA runtime dependency — a hybrid Retained/Delegated model. The Model Runtime is a genuine platform capability: model serving as a managed VCF service with API Gateway, multi-tenant isolation, and multi-accelerator support. This is structurally different from Dell’s 2B (entirely NVIDIA-dependent — NemoClaw/OpenShell) and closer to HPE’s 2B (HPE provides the deployment platform, NVIDIA provides the execution runtime, with HPE-owned bracketing governance above and below). The Agent Builder is notable as a platform-native agent construction surface. Compare to alternatives: • Dell: No platform-native agent builder. Relies on NVIDIA NIM/NemoClaw post-deployment. • HPE: CrewAI pre-installed (partner framework). Deloitte Zora AI (partner application). • VAST: AgentEngine — deeply integrated, proprietary agent runtime. • Google: Agent Studio (no-code), ADK (code-first), Agent Designer. • AWS: Bedrock Agents (no-code), Strands SDK (code-first). VMware’s Agent Builder is simpler than the hyperscaler offerings but it’s integrated into the VCF operational model — agents built here inherit VCF’s security (vDefend microsegmentation), governance (MCP server controls), and observability (GPU/model metrics). That operational integration is VMware’s differentiator. The Tanzu Platform MCP server publishing capability is a Layer 2B/2C bridge worth tracking: enabling developers to self-publish MCP servers creates an enterprise-internal agent tool marketplace governed by IT. This is a distributed model for agent capability deployment that differs from Google’s centralized Agent Registry or HPE’s curated Unleash AI ecosystem. The model surface has widened materially. VCF customers can run more than 150 open source and commercial models, with Nemotron 3, Gemma 4, cotomi, Qwen, and GLM 5.2 tested and validated to run on the platform and deliverable as a service to internal users. Most of those arrive from model providers directly rather than through NVIDIA’s packaging, which is what separates this from an NIM catalog. Combined with the AMD Instinct and ROCm collaboration at Layer 0, the runtime story is no longer accurately described as NVIDIA-dependent, even though NVIDIA AI Enterprise remains the deepest integration and the default path. What is not yet decidable from the documentation is whether model validation is certification or a supported runtime commitment. That distinction is the difference between a compatibility list and a capability, and it is the fact that would move this cell to strong.

◆ Borrowed Judgment

Moderate. VMware owns Model Runtime, Agent Builder, and the Tanzu application runtime. But inference execution depends on NVIDIA AI Enterprise (same structural dependency as Dell and HPE). The multi-accelerator support (AMD + NVIDIA) provides a runtime alternative that Dell AI Factory customers don’t have (Dell’s AMD track is a separate stack), though HPE’s GX5000 also supports multi-vendor GPU blades and hyperscalers abstract accelerators entirely. VMware’s value is that the architect controls which accelerator serves which workload through familiar virtualization primitives — the control plane is opinionated (VMware’s virtualization model applied to GPUs) but provides operational knobs that vSphere-native teams already understand. The NVIDIA dependency at 2B is real but partially mitigated by VMware’s abstraction: Model Runtime provides a VMware-managed API surface. If NVIDIA changes its NIM/NemoClaw architecture, VMware absorbs the integration change — the enterprise’s API doesn’t change. This is the same ‘bracketing’ architecture HPE uses (GreenLake governance above and below the NVIDIA runtime), expressed differently (VMware API abstraction wrapping the NVIDIA runtime).

◆ Working Notes

The multi-accelerator Model Runtime is significant but requires context: running the same AI model on AMD and NVIDIA GPUs without refactoring is a runtime-level abstraction that VMware provides through familiar virtualization management tools. HPE’s GX5000 supports multi-vendor GPU blades in the same rack, and hyperscalers abstract accelerators entirely at the service layer (Vertex AI, Bedrock). VMware’s differentiator is not multi-accelerator support per se but the level of architectural control — the operator manages GPU placement and scheduling through vSphere primitives they already know, with stronger knobs than cloud providers offer. Dell’s AMD track (Dell AI Platform with AMD) remains a separate branding with a separate software stack, not a unified runtime. The Tanzu-mediated MCP server publishing is an emerging capability that could become significant for agentic AI: if every enterprise developer can publish MCP servers through Tanzu, and IT governs access through VCF 9.1’s MCP server governance, VMware creates a platform for enterprise agent tooling that is neither centralized (Google) nor delegated to partners (HPE Unleash AI) but distributed-and-governed. Whether this pattern scales depends on enterprise developer adoption of Tanzu. Announced August 31, 2026, not confirmed in product documentation, not scored: • Multi-tenant Model Sharing, secure sharing of models between tenants or lines of business through isolated namespaces, eliminating redundant deployments that waste GPU allocation. Described as shipping (‘Model Runtime now supports’) in the announcement but not yet confirmed in an admin or user guide. This is the one Explore 2026 item most likely to move 2B on doc confirmation. • AI Gateway: intelligent prompt routing, token and usage rate-limiting, and application authorization across on-premises and cloud models. Forthcoming, no date. • Secure AI Sandboxes: virtualized container spaces isolating agent-generated code execution, with a control layer defining how agents are invoked, what tools they access, and how outputs are validated before being acted upon. Forthcoming, no date. Read the validation claim carefully on GA: output validation before action is the deterministic outcome-validator the instrument records as universally absent, and a sandbox that checks legality is not that. • Tanzu Platform hardened agent sandboxes, a deny-by-default containment model isolating credentials against prompt injection and unauthorized network access, plus an out-of-the-box developer harness with pre-approved skills, workflow buildpacks, human-in-the-loop controls, and memory services. Generally available in Tanzu Platform in Fall 2026. • Avi Load Balancer tool and agent misuse prevention, restricting agents from unauthorized MCP tools and inspecting transaction content. Future tense, no date.

Layer 2C · ReasoningAgentic Infrastructure — The Reasoning PlaneAgent Governance Ships, Placement Does Notdecides: code · Retained▼

Policy-driven placement and resource coordination — the Autonomy Layer

Vendor-Provided

AgentMinder — Agent Identity and Intent GovernanceCeded

GA August 31, 2026. Treats autonomous agents as enterprise-grade identities and binds their authority to a declared mission, permitted intents, approved tools, and authorized resources, so an agent must declare what it is trying to do before it can touch an enterprise system. This is the capability that separates AgentMinder from a gateway, and from Nutanix’s Agent Gateway specifically. The authority model is proprietary to Broadcom: the mission and intent declarations the enterprise accumulates have nowhere else to run.

AgentMinder — Runtime Enforcement GatewayCeded

GA. A cloud-native gateway secures every tool call at runtime, authenticating tokens and evaluating context (identity, tool, intent, resource) through a dynamic policy engine before traffic reaches an authorized backend. Deploys on VKS, on Google Cloud, or on any standards-based Kubernetes, alongside models on-premises, in a VPC, or in public cloud, so it is not a VCF-gated capability. AuthZEN integration lets the enterprise keep its existing policy enforcement endpoints rather than routing through a SaaS chokepoint, which preserves policies the enterprise already owns. The enforcement plane itself is proprietary, matching the Ceded call on Salesforce’s Omni and Flex Gateway.

AgentMinder — Agent Observability (OpenTelemetry)Delegated

GA. Compliance-grade visibility into every agent session and action, with chain of custody, anomaly detection, and operational insight, built on OpenTelemetry. OTel is a genuine multi-vendor standard interface, so the instrumentation and traces the enterprise accumulates run against any conformant backend and lift out without rebuilding. Scored Delegated on that basis, which is the distinction from Salesforce’s Agentforce Observability, a proprietary platform surface scored Ceded. Decision tracing, not decision validation: it reconstructs what an agent did, never whether the outcome was right.

MCP Server Governance (VCF 9.1) — Agent Tool Access FacetCeded

Central control over which user groups reach which approved MCP tools and servers across the estate, with security guardrails for MCP servers through vDefend and Avi Load Balancer. Scored at 2A as an infrastructure-administered control and here as agent-tool access governance: one capability serving two layer functions, and how Broadcom organizes the product does not decide which cell an architect shops it against. Proprietary VCF surface, so the access policies configured here do not lift.

NVIDIA-Provided

No NVIDIA Layer 2C on VMware

NVIDIA provides no agent governance, policy-driven placement, or reasoning plane components in the VMware stack. AI-Q is workflow scaffolding, OpenShell is constraint enforcement, Dynamo is performance routing. None is Layer 2C. The shipping 2C capability here is Broadcom’s own, and it comes from the identity portfolio rather than from the accelerator partnership. A near-empty NVIDIA column at 2C is the finding.

◆ Gap Analysis

The buyer gets a shipping agent control plane. AgentMinder, generally available August 31, 2026, treats autonomous agents as enterprise-grade identities and binds their authority to a declared mission, permitted intents, approved tools, and authorized resources. Every agent has to declare what it is trying to do, not just who it is, before it reaches an enterprise system. A cloud-native gateway authenticates tokens and authorizes every tool call at runtime against live context, directing traffic only to authorized backends. An OpenTelemetry layer delivers chain of custody, anomaly detection, and session-level audit. Broadcom runs its own agentic pipeline on it at roughly 36 million customer API calls and 7 million workforce API calls a day, which is production evidence most 2C claims on this instrument cannot produce. That capability set decides the grade by calibration. Cisco scores moderate at 2C on Duo Agentic Identity, AI Defense, and Splunk with Galileo. Salesforce scores moderate on MuleSoft Agent Fabric: registry, broker, and a gateway enforcing auth, rate limits, token caps, tool-access restrictions, and audit. AgentMinder covers the same ground and adds intent binding, which neither of those has. Consistency outranks the story, so this cell reads moderate. It sits above Nutanix’s Agent Gateway, which delivers RBAC, rate-limiting, and MCP audit without an identity and intent model. Now the limit, and it is the whole finding. Separate Intelligence-2C, which agent may act on what under which policy, from Infrastructure-2C, where inference physically runs at request time. AgentMinder is Intelligence-2C and nothing else. It decides whether an action proceeds. It makes no decision about where compute runs relative to data, which model serves which request, or how cost, compliance, and latency are arbitrated per request. Applying the same test to the rest of the surface: MCP Server Governance is access control, GPU and model metrics are observability telemetry, Intelligent Assist is IT operations automation. The governance primitives are now genuinely strong. The placement engine does not exist. The sibling ruling applies too. AgentMinder answers whether an action is legal. It does not validate whether the outcome was right. That deterministic outcome-validator is absent across the entire instrument and is noted here as universal rather than charged to VMware. Two facts about how Broadcom built this matter more than the feature list. AgentMinder came out of the Identity Management Security Division, the CA and Symantec identity lineage, not the VCF division. And it deliberately does not require VCF: it deploys on VKS, on Google Cloud, or on any standards-based Kubernetes, alongside models on-premises, in a VPC, or in public cloud, and it integrates through the AuthZEN standard so enterprises reuse their existing policy enforcement endpoints. What ships is a portable agent authorization plane, architected to run anywhere rather than to exploit VCF’s position. That has a direct consequence for the architect. VCF is the surface that already sees vSAN governance metadata, GPU utilization, vDefend posture, and Model Runtime performance across every OEM’s hardware, and the shipping 2C reads none of it. Agent governance here is portable and estate-blind at the same time.

◆ Borrowed Judgment

Mixed, and the mix is unusually legible. The enterprise inherits Broadcom’s opinion about what an agent is: a mission, a set of permitted intents, approved tools, and authorized resources. That authority model is proprietary, and the declarations and bindings written against it do not lift to another vendor’s agent governance plane without rebuilding. The runtime enforcement plane is likewise Broadcom’s, matching how Salesforce’s gateway is scored. Two deliberate openings cut the other way, and they are real rather than decorative. AuthZEN integration means the policy decision points the enterprise already owns keep making the decisions, instead of traffic being routed through a vendor SaaS chokepoint. OpenTelemetry means the agent telemetry runs against any conformant backend. Broadcom chose standards at exactly the two places where a vendor would normally close the door. The judgment the enterprise still has to supply itself is placement. No vendor on this instrument sells it, so this is not a VMware deficiency so much as the instrument’s standing finding, but the enterprise running agents on VCF decides for itself where inference runs relative to its data, and no product here helps.

◆ Working Notes

The shape of the shipping product is the finding. Effort went to identity, enforcement, and audit; the plane is portable and VCF-independent; it came from the identity division rather than the VCF division. Read together, those tell the architect what this stack governs and what it leaves to them. Live inference placement is not available from this vendor, and is not available from any vendor on the instrument. Announced August 31, 2026, not GA, none scored: • AI Gateway: unified model governance across on-premises and cloud through a single consumption interface, with intelligent prompt routing, token and usage rate-limiting, and application authorization. Forthcoming, no date. This is the closest VMware has come to Infrastructure-2C, since prompt routing across an on-premises and cloud boundary is a which-model-serves-this-request decision. On GA, judge it against the general-versus-fixed-function rule: single-variable routing on prompt characteristics is a slice, not multi-variable policy placement. • vDefend agentic AI component discovery (auto-identifying MCP servers, LLMs, datastores, and tools from traffic flows), Shadow AI monitoring, and AI-generated IDPS signatures. All future tense, no dates. • Avi Load Balancer zero-day detection through agentic traffic baselining, and sensitive data exfiltration prevention. Future tense, no dates. • Tanzu Platform auditable agent governance, integrating an AI gateway to monitor, rate-limit, and log every agent action. Generally available in Tanzu Platform Fall 2026. MCP Server Governance is scored here as a facet and again at 2A. See the 2A note. Instrument note: live inference placement remains absent across all 27 rows. It is recorded here as a universal finding, not a VMware-specific charge. Resolved September 2, 2026: Nutanix reads moderate on its Agent Gateway, in the same band as this cell. Missing legs, named: registry and cross-agent orchestration. Identity and intent binding put AgentMinder at the upper edge of moderate; the complete plane (GCP) is the strong bar.

Layer 3 (+1) · ApplicationsAI Application Layer — The Value PlaneISV Ecosystem on a Private Cloud Platformdecides: vendor · Delegated▼

AI-powered business capabilities — business logic, workflow automation

Vendor-Provided

ISV + OEM EcosystemDelegated

VMware Private AI Foundation validated on Dell, HPE, Lenovo, Cisco, Supermicro, NEC, Fujitsu hardware. ISV ecosystem spans the entire VMware partner network — thousands of validated applications across every industry. AI-specific ISV validation is emerging but not yet at the curation depth of HPE’s Unleash AI (26+ selected ISV partners) or Dell’s AI Ecosystem Program (OpenAI, Palantir, Google, ServiceNow).

OpenWebUI IntegrationDelegated

Open-source AI user interface integrated with VCF Private AI Services RAG. Provides a ChatGPT-like interface for enterprise users to interact with privately-hosted models. Demonstrates the ‘platform enables applications’ model.

NVIDIA-Provided

NVIDIA Model Ecosystem

Nemotron models, community models, NVIDIA NIM containers available through Model Store. NVIDIA provides the model layer; VMware provides the serving and governance layer.

◆ Gap Analysis

VMware’s Layer 3 is structurally different from every other assessed vendor because VMware is explicitly a platform, not an application provider. VMware provides the tools to build and deploy AI applications (Private AI Services) but does not build the applications themselves. Partner, on rule 8: the Layer 3 grade rests on first-party business applications the buyer runs, and platform enablement, marketplaces, and developer tools earn none, whoever owns them. Broadcom owns Spring, the framework a majority of enterprise Java applications are written in, at the moment enterprise Java has become where AI functionality gets built: Azul’s 2026 State of Java survey puts 62 percent of enterprises coding AI functionality in Java. Spring is first-party and it is the strongest asset adjacent to this layer, but it is a framework the enterprise builds in, not an application it runs, and its AI function (Spring AI and the MCP Java SDK) is read at 2B. The peer reading is the Red Hat row, where Quarkus, JBoss EAP, and the Red Hat build of OpenJDK are first-party Java frameworks and runtimes that earn no Layer 3 grade; Red Hat's Layer 3 reads partner, through its certified ecosystem. Private AI Services and the Tanzu runtime are likewise read at 2B; Tanzu’s agent distribution and curated marketplace is an enterprise app store, which rule 8 excludes by name; NVIDIA Blueprints are reference architectures, below the Layer 3 threshold on NVIDIA’s own row. What remains at this layer is the ecosystem, which is the Dell, HPE, and Nutanix shape. The difference from those rows is ecosystem depth: • Dell’s AI ecosystem: OpenAI, Palantir, Google, ServiceNow, SpaceXAI, Hugging Face, 5,000+ deployment customers. Explicitly curated for AI. • HPE’s Unleash AI: 26+ selected ISV partners with validated interoperability. Kamiwaza orchestration. CrewAI pre-installed. Purpose-built for AI. • VAST’s Cosmos Community: TwelveLabs and CrowdStrike with distinct partner tracks. Focused and vertical. • VMware’s AI ecosystem: Inherits the broader VMware partner ecosystem (thousands of ISVs) but without AI-specific curation depth. Private AI Foundation validation is available on major OEM hardware, but AI-specific ISV partnerships are not yet at the maturity of Dell or HPE programs. The Tanzu-mediated MCP server publishing could evolve into VMware’s distinctive Layer 3 model: instead of curating an external ISV ecosystem (HPE’s approach) or partnering with AI application vendors (Dell’s approach), VMware enables the enterprise’s own developers to build and distribute AI agents internally. This is an internally-generated Layer 3 rather than an externally-sourced one. The VCF installed base is the Layer 3 enabler: 100M+ cores means Private AI Services reach more enterprise infrastructure than any competitor’s AI platform. The AI applications built on VMware will be built by the enterprise’s own developers, using VMware’s tools, on VMware’s platform. These are two different product designs, and the difference follows from the problem each product solves. A platform company’s Layer 3 problem is how the enterprise’s own developers build on it, which is why Broadcom owns a framework and a distribution path. A hardware company’s Layer 3 problem is which applications attach to the box, which is why Dell and HPE assemble application partners they do not build. Neither design is a bet awaiting a verdict against the other. The instrument records what each one puts in the architect’s hands: on this row, tools and a framework the enterprise builds with, and on Dell’s and HPE’s rows, a catalog of applications someone else wrote. Both designs leave Layer 3 itself to someone other than the vendor, which is why all three rows read partner; what this row adds is the answer to where the enterprise’s own applications get written, and Spring is that answer.

◆ Borrowed Judgment

Distributed across the enterprise’s own development teams and chosen partners. VMware provides the platform; the enterprise provides the application logic. Applications the enterprise builds itself, in Spring and on open frameworks, are its own and are not VMware’s deliverable at this layer. What VMware’s paper delivers here is the ecosystem: ISV applications and the OpenWebUI interface, procured through VMware and substitutable, Delegated on the rule 8 reading. The trade-off: maximum control and maximum effort, since the enterprise builds everything above the platform services layer, whose captive surfaces are read at 2B. Dell and HPE offer a larger catalog of partner applications as the shortcut.

◆ Working Notes

The Private AI Foundation at no additional cost for VCF subscribers is a strategic masterstroke for customer retention: every VCF customer already has access to Model Runtime, Agent Builder, Vector Database, Data Indexing/Retrieval, and Model Store. The marginal cost of trying Private AI is zero (beyond GPU hardware). This is the lowest-barrier entry to on-prem AI of any vendor assessed. The 9/10 Fortune 500 commitment to VCF means Private AI Foundation has the largest potential enterprise deployment footprint of any on-prem AI platform. Whether that potential converts to actual AI workload deployment depends on whether enterprises find Private AI Services sufficient for production AI or whether they choose purpose-built alternatives (Dell AI Factory, HPE Private Cloud AI, VAST AI OS) for deeper capabilities. The competitive dynamic is unusual: VMware doesn’t compete with Dell or HPE at Layer 0 (VMware runs ON their hardware). VMware competes with them at Layers 1-3 (management, orchestration, AI services). An enterprise could run Dell hardware + VMware VCF + VMware Private AI Services — getting Dell’s Layer 0 with VMware’s Layers 2A/2B. Or Dell hardware + Dell AI Factory — getting Dell’s Layer 0 with Dell/NVIDIA’s Layers 2A/2B. The choice is between VMware’s operational maturity and Dell/HPE’s AI-specific depth. Announced August 31, 2026: • Tanzu Platform is now positioned as the official agent platform for Private AI Cloud, with a developer harness (pre-approved skills, workflow buildpacks, human-in-the-loop controls, integrated memory services) and a curated marketplace of vetted models, tools, and data products. Generally available in Tanzu Platform Fall 2026. This is platform tooling for building applications, which keeps Layer 3 platform-enabled rather than platform-provided. • TrueSource by Broadcom, announced August 31, 2026: commercially supported and verifiably built open source across Spring Enterprise, Java, Python, Node.js, and enterprise data services, pairing AI-assisted vulnerability discovery with engineer-written fixes. Scored as part of the Spring application-estate component rather than logged as out of scope. Read on its own it is supply-chain provenance, but the Spring asset it wraps is the reason this layer is not partner.

Sources & revision history · v1.15 - 4+1 v2: NVIDIA One Path of Three

VMware Explore 2026 (August 31, 2026) product releases: VMware Private AI Cloud, VMware AI Factory, VCF validated models, Tanzu AI-Ready Data Foundations, agentic AI security (vDefend/Avi/AgentMinder), AgentMinder. Prior VCF 9.0/9.1 documentation, Broadcom press releases, VCF Private AI blog series, published 4+1 model. v1.5: row retitled to VMware Private AI Cloud (Broadcom re-branding, and the AMD Instinct collaboration ends the NVIDIA-exclusive framing); 2C gap to moderate on AgentMinder GA, calibrated to Cisco and Salesforce; 2B label widened beyond NVIDIA; Explore 2026 forward capability logged as dated watch-list lines under the GA-gate. Nutanix 2C calibration logged as a /reconcile candidate, not resolved here. Spring AI and the Spring application estate scored for the first time (2B and L3 facets, Delegated); Model Runtime split under the inference-interface rule; vSAN object storage unscored as Technology Preview; MCP Server Governance placement deferred to /reconcile. /reconcile (September 1, 2026): MCP Server Governance resolved as a 2A/2C facet rather than an either/or; no status change on either cell. /reconcile (October 5, 2026): Layer 3 moderate to partner on rule 8. Spring is first-party to Broadcom but a framework the enterprise builds in, not a business application, matching the IBM row, where Red Hat’s Quarkus, JBoss EAP, and OpenJDK earn no Layer 3 grade. Private AI Services, Tanzu agent distribution, NVIDIA Blueprints, and the Spring estate removed as Layer 3 components (read at 2B, excluded as an app store, below threshold, and a developer framework respectively); Spring kept in the prose. /reconcile (October 5, 2026): Layer 3 calibration citation updated for the IBM Layer 3 re-read (strong on its business applications; Red Hat's frameworks still earn no grade). No grade, component, or authority change. /reconcile (October 5, 2026): IBM and Red Hat are now separate rows; citation retargeted to the Red Hat row, no grade moves. /reconcile (October 5, 2026): 1C authority column (rulings of September 15 and October 4, 2026). 1C authority vendor / Delegated to Absent: the enterprise-brought pipeline tooling is the enterprise's, not a reading of VMware. Grade and components unchanged. /reconcile (October 5, 2026): override rule applied to a cell scored before it; layer0, layer1b, layer2a authority Ceded to Delegated on documented pins or per-request overrides. Grades and components unchanged. /reconcile (October 5, 2026): authority re-read against product docs under the judgment test, override rule, and Layer 3 ruling: layer1a visible true (vSAN Disk Balance health check); direction holds Ceded, since rebalance thresholds are bounds. Grades and components unchanged. /reconcile (October 5, 2026): Layer 0 NVIDIA GPU Integration holds Delegated on a corrected reason; vmclass mapping moved to the vSphere chip (vSphere-captive); narrative and summary no longer frame NVIDIA as the core of VMware's private AI stack (Keith, October 5, 2026: VCF manages AMD, NVIDIA, and Intel; Private AI Services runs vLLM and Infinity). Grade unchanged.

4+1 Layer AI Infrastructure Model · Vendor Assessment Series · The CTO Advisor LLC (DBA The Advisor Bench) · thectoadvisor.com