{"id":1003,"date":"2026-09-23T08:10:20","date_gmt":"2026-09-23T08:10:20","guid":{"rendered":"https:\/\/www.schneider.im\/?p=1003"},"modified":"2026-09-23T10:23:24","modified_gmt":"2026-09-23T08:23:24","slug":"broadcom-vmware-vdefend-and-avi-load-balancer-agentic-ai-security-for-the-private-cloud","status":"publish","type":"post","link":"https:\/\/www.schneider.systems\/lu\/broadcom-vmware-vdefend-and-avi-load-balancer-agentic-ai-security-for-the-private-cloud\/","title":{"rendered":"Broadcom VMware vDefend and Avi Load Balancer: Agentic AI security for the private cloud"},"content":{"rendered":"<p>Run <strong>autonomous AI agents<\/strong> without losing control of your network. Effective <strong>August 31, 2026<\/strong>, Broadcom announced new <strong>security<\/strong>, <strong>identity<\/strong>, and <strong>observability<\/strong> capabilities for agentic artificial intelligence (AI) workloads across <strong><a href=\"https:\/\/www.schneider.systems\/lu\/omnissa-the-former-vmware-end-user-computing-business\/\">VMware<\/a> vDefend<\/strong>, <strong>VMware Avi Load Balancer<\/strong>, and the newly unveiled <strong>Broadcom AgentMinder<\/strong>.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.schneider.systems\/media\/2026\/09\/SCHNEIDER-IT-MANAGEMENT-2026-09-14-Update-LinkedIn-Broadcom-VMware-vDefend-and-Avi-Agentic-AI-Security.jpg\" alt=\"Broadcom VMware: Agentic AI Security for the Private Cloud - vDefend and Avi Load Balancer extend Zero Trust to AI agents in the private cloud, announced August 31, 2026\" \/><\/figure>\n<h2>Summary<\/h2>\n<ul>\n<li>Broadcom introduced <strong>multi-layer<\/strong> security, identity, and observability capabilities for agentic AI workloads running on the <strong>Private AI Cloud<\/strong><\/li>\n<li>VMware vDefend contributes <strong>Agentic Zero Trust<\/strong>, while VMware Avi Load Balancer contributes <strong>Agentic Threat Defense<\/strong><\/li>\n<li>Broadcom AgentMinder was unveiled as the <strong>central control plane<\/strong> for autonomous AI agents<\/li>\n<li>The capabilities target blind spots created by <strong>Model Context Protocol (MCP)<\/strong> servers, <strong>large language models (LLMs)<\/strong>, tools, and datastores<\/li>\n<li>vDefend and Avi Load Balancer remain <strong>Advanced Services add-ons<\/strong> to <a href=\"https:\/\/www.schneider.systems\/lu\/vmware-cloud-foundation-vcf-portfolio-offerings-enhancements\/\">VMware Cloud Foundation<\/a> (VCF), <strong>licensed separately<\/strong> from the core per-core subscription<\/li>\n<li>Organizations with agentic AI plans should review their <strong>VCF entitlements<\/strong> before these capabilities become available<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>What is changing?<\/h2>\n<p>Broadcom presented the announcement at <strong>VMware Explore 2026<\/strong> in Las Vegas. The three products address agentic AI risk at <strong>three different layers<\/strong>: the network inside VMware Cloud Foundation, the application delivery layer, and the <strong>agent identity layer<\/strong>. Broadcom describes the combination as <strong>defense-in-depth<\/strong> for the private cloud, so enterprises can operationalize autonomous agents without moving their data to a public cloud.<\/p>\n<p>The announcement builds on the vDefend and Avi Load Balancer release of <strong>August 6, 2026<\/strong>, which added on-premises <strong>malware prevention<\/strong>, full <strong>air-gapped support<\/strong>, and native API protection for virtual machines, <strong>VMware vSphere Kubernetes Service (VKS)<\/strong>, and AI workloads. Broadcom describes the new agentic capabilities as <strong>planned product direction<\/strong>, so the capabilities are announced rather than generally available.<\/p>\n<p>&nbsp;<\/p>\n<h2>What are VMware vDefend and VMware Avi Load Balancer?<\/h2>\n<p>VMware vDefend is the <strong>lateral security<\/strong> layer of VMware Cloud Foundation. It combines a <strong>distributed firewall<\/strong> with advanced threat prevention, so workloads are <strong>segmented<\/strong> inside the data center and not only at the perimeter. VMware Avi Load Balancer is the software-defined <strong>application delivery<\/strong> layer, with a <strong>web application firewall<\/strong> and <strong>API protection<\/strong>, elastic scale-out, and integration with Kubernetes including VKS.<\/p>\n<p>For licensing, both products are <strong>Advanced Services add-ons<\/strong> to VMware Cloud Foundation and are <strong>purchased separately<\/strong> from the core VCF subscription, which is <strong>sold per core<\/strong>. AgentMinder is a newly unveiled Broadcom product and therefore sits <strong>outside<\/strong> the existing vDefend and Avi entitlements. The announcement states <strong>no licensing or pricing terms<\/strong> for AgentMinder, so its commercial model should be confirmed with Broadcom before it enters a budget.<\/p>\n<p>&nbsp;<\/p>\n<h2>Agentic Zero Trust in VMware vDefend<\/h2>\n<ul>\n<li><strong>Discovery<\/strong> of agentic AI components identifies <strong>MCP servers<\/strong>, LLMs, datastores, and tools by continuously monitoring <strong>traffic flows<\/strong> across VMware Cloud Foundation<\/li>\n<li><strong>Shadow AI monitoring<\/strong> detects <strong>unauthorized<\/strong> AI usage and enforces Zero Trust policies against it<\/li>\n<li>AI-generated <strong>Intrusion Detection and Prevention (IDPS)<\/strong> signatures are produced by an agentic AI pipeline at <strong>machine speed<\/strong> and provide distributed <strong>virtual patching<\/strong><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Agentic Threat Defense in VMware Avi Load Balancer<\/h2>\n<ul>\n<li><strong>Tool and agent misuse prevention<\/strong> restricts agents from unauthorized MCP tools and inspects transaction content to block <strong>remote code execution (RCE)<\/strong> and <strong>file injection<\/strong><\/li>\n<li><strong>Zero day attack detection<\/strong> establishes normal traffic <strong>baselines<\/strong> across agents, LLMs, and tools, then flags and isolates <strong>anomalous behavior<\/strong> in real time<\/li>\n<li><strong>Sensitive data protection<\/strong> helps prevent the <strong>exfiltration<\/strong> of credentials, <strong>personally identifiable information (PII)<\/strong>, and sensitive financial data<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Broadcom AgentMinder: identity, intent, and governance<\/h2>\n<ul>\n<li><strong>Identity and intent controls<\/strong> treat autonomous agents as <strong>enterprise-grade identities<\/strong> and bind their authority to a declared <strong>mission<\/strong>, permitted intents, approved tools, and authorized resources<\/li>\n<li><strong>Runtime policy enforcement<\/strong> runs through a <strong>cloud-native gateway<\/strong> that evaluates identity, tool, intent, and resource on every <strong>tool invocation<\/strong> and applies <strong>least-privileged<\/strong> policies<\/li>\n<li><strong>Compliance-grade auditability<\/strong> is built on <strong>OpenTelemetry<\/strong> and delivers <strong>chain of custody<\/strong>, anomaly detection, and operational insight for every agent session<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Why agentic AI security is relevant now<\/h2>\n<p>Agentic AI moves the <strong>attack surface<\/strong> from user traffic to <strong>machine-to-machine<\/strong> traffic. Agents call tools, read datastores, and talk to other agents over MCP and <strong>agent-to-agent (A2A)<\/strong> protocols, and <strong>perimeter controls<\/strong> never see that traffic. Enterprises that keep <strong>inference on-premises<\/strong> gain <strong>data control<\/strong>, but they also inherit the duty to segment, monitor, and <strong>audit<\/strong> those flows themselves. Covering identity, segmentation, and web protection inside one VMware Cloud Foundation stack reduces <strong>tool sprawl<\/strong>, shortens the <strong>audit trail<\/strong>, and keeps the security budget inside an existing <strong>vendor relationship<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h2>What organizations should do now<\/h2>\n<ul>\n<li><strong>Inventory<\/strong> every agentic AI component running on VMware Cloud Foundation, including MCP servers, LLMs, and datastores, and document the count before your <strong>next renewal date<\/strong><\/li>\n<li><strong>Review<\/strong> which vDefend and Avi Load Balancer <strong>entitlements<\/strong> your current VCF subscription covers, and where an <strong>add-on<\/strong> would be required<\/li>\n<li><strong>Validate<\/strong> whether <strong>unsanctioned<\/strong> AI usage already exists in your environment, because <strong>shadow AI<\/strong> changes the scope of any later security purchase<\/li>\n<li><strong>Align<\/strong> an AgentMinder evaluation with your <strong>identity<\/strong> and <strong>compliance<\/strong> owners, as agent governance touches both areas<\/li>\n<li><strong>Monitor<\/strong> Broadcom release notes for <strong>general availability<\/strong> dates, since the agentic capabilities are announced as planned direction<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Ready to review your Broadcom licensing?<\/h2>\n<p>SCHNEIDER IT MANAGEMENT is an <strong>authorized Broadcom partner<\/strong> and <strong>reseller<\/strong> with a dedicated Broadcom licensing division. Our experts review your <strong>VMware Cloud Foundation subscription<\/strong>, clarify which <strong>Advanced Services add-ons<\/strong> your agentic AI plans would require, and keep your Broadcom contracts <strong>cost-optimized<\/strong>, <strong>audit-ready<\/strong>, and aligned with your <strong>renewal cycle<\/strong>. Contact us at <a href=\"https:\/\/www.schneider.systems\/contact\/\">https:\/\/www.schneider.systems\/contact\/<\/a> to review your Broadcom licensing position.<\/p>\n<p>&nbsp;<\/p>\n<h2>Sources<\/h2>\n<p><em>For the announcement of Broadcom VMware vDefend and Avi Load Balancer: Agentic AI Security for the Private Cloud, please visit: <\/em><a href=\"https:\/\/www.broadcom.com\/company\/news\/product-releases\/64641\"><em>https:\/\/www.broadcom.com\/company\/news\/product-releases\/64641<\/em><\/a><em>.<\/em><\/p>\n<p><em>For useful software licensing information on Broadcom products, please visit: <\/em><a href=\"https:\/\/www.schneider.systems\/lu\/broadcom-automic-saas-available\/broadcom\/\"><em>https:\/\/www.schneider.systems\/software\/broadcom\/<\/em><\/a><em>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Run autonomous AI agents without losing control of your network. Effective August 31, 2026, Broadcom announced new security, identity, and observability capabilities for agentic artificial intelligence (AI) workloads across VMware vDefend, VMware Avi Load Balancer, and the newly unveiled Broadcom AgentMinder.<\/p>\n","protected":false},"author":10,"featured_media":37230,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[683,270],"tags":[],"class_list":["post-1003","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-broadcom","category-vmware"],"_links":{"self":[{"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/posts\/1003","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/comments?post=1003"}],"version-history":[{"count":1,"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/posts\/1003\/revisions"}],"predecessor-version":[{"id":61655,"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/posts\/1003\/revisions\/61655"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/media\/37230"}],"wp:attachment":[{"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/media?parent=1003"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/categories?post=1003"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.schneider.systems\/lu\/wp-json\/wp\/v2\/tags?post=1003"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}