At VMware Explore 2026, Broadcom introduced AgentMinder: a central control plane designed to turn autonomous AI agents into "governed digital employees." The product is significant not because it adds another monitoring tool to the security shelf, but because it treats agents as first-class identity principals rather than software scripts with elevated access.

For enterprise buyers, this matters enormously. The past twelve months have seen a flood of agent deployments inside large companies, but most security models were built for human users, not for autonomous systems that make decisions and take actions independently. Broadcom's announcement signals that the infrastructure layer is starting to catch up with the application layer. The question for procurement and architecture teams is no longer whether to deploy agents, but whether the governance stack can keep pace with the agent stack.

What AgentMinder does

Broadcom describes AgentMinder as a traffic controller for AI agents. It independently verifies agent identity, authorises each action against declared mission and intent, and enforces policy before the agent ever reaches an enterprise resource. This is not retrospective logging. It is runtime intervention.

The product rests on three capabilities. First, identity and intent: every agent must declare what it is trying to do, not just who it is, before it can touch enterprise systems. Its authority is bound to a declared mission, permitted intents, approved tools and authorised resources. Second, runtime enforcement: a cloud-native AI gateway secures every tool call at runtime, authenticating tokens and directing traffic exclusively to authorised backends, driven by a dynamic policy engine that evaluates context from user identity through to intent. Third, observability and audit: an OpenTelemetry-based observability layer delivers chain of custody, anomaly detection and operational visibility at machine speed, giving security and risk teams full visibility into every agent session and action.

Broadcom is already running this at scale internally. Its CIO, Alan Davidson, reports that AgentMinder supports over 20 million customer identities and 72,000 workforce identities, handling peak loads of nearly 36 million customer-related and 7 million workforce-related API calls every single day, across multi-region, active-active deployments with zero downtime during maintenance and upgrades. The company is also running a swarm of more than twenty internal agents building Tanzu itself, from requirements through tickets to code and tests.

Why the timing is right

The announcement lands in the same week that IDC published the second part of its "Securing the Agentic Enterprise" perspective, stating that the shift to agents "demands unified governance, continuous authorisation, and real-time telemetry to ensure every agent action is observable, attributable, and reversible." AgentMinder is a direct, vendor-specific response to that demand.

It also arrives as enterprises hit a governance wall. Research published at the start of July found that 88% of organisations experienced at least one AI agent-related security incident in the past year, and 86% delayed agentic AI deployments by an average of nearly six months citing data security and governance as the primary cause. The gap between deployment speed and security readiness has become the defining constraint on enterprise AI adoption.

Broadcom's Clayton Donley, VP and GM of identity management security, put the case plainly: "Existing security models were designed for human users, not for autonomous digital employees that can make decisions and take actions on their own." The implication is that retrofitting human-first identity and access management onto agent workflows is not working, and the market is ready for purpose-built runtime control.

What it means for enterprise buyers

AgentMinder carries three direct implications for organisations evaluating agentic platforms.

Governance is now a runtime question, not a policy question. Most enterprises have an AI governance policy. Few have a system that intercepts agent actions in real time and blocks those that exceed authorised scope. The difference is the same as the difference between having a speed limit and having a speed camera. Buyers should ask any agent vendor whether their product can enforce intent-based access controls at the point of action, not just log what happened afterwards. If the answer is no, the deployment is inherently higher risk.

Agent identity must be as robust as human identity. Broadcom's approach gives every agent a verified identity and binds its permissions to its declared mission. This mirrors the emerging industry consensus that agents should be treated as privileged users with just-in-time access and session-bound credentials. Buyers should evaluate whether their current identity provider can support agent principals natively, or whether the vendor can integrate with existing policy enforcement endpoints via standards such as AuthZEN, as AgentMinder does.

Private infrastructure remains a competitive battlefield. AgentMinder ships as part of the broader VMware Private AI Cloud, which runs on VMware Cloud Foundation and supports both on-premises and cloud-native Kubernetes environments. The bundling signals Broadcom's strategy: governance, model serving and traditional enterprise workloads in the same private perimeter where data already resides. For regulated sectors, government contractors and any organisation handling sensitive intellectual property, this hybrid positioning is a procurement filter. Buyers that need data residency will find private-cloud agent governance attractive. Buyers that are fully cloud-native will need to evaluate whether Broadcom's tight integration with VCF is an advantage or a lock-in risk.

What it means for suppliers

For companies building agentic products, services or tooling, AgentMinder creates both competitive pressure and opportunity.

Horizontal platforms without runtime governance are exposed. An agent that cannot prove what it did, why it did it, and who authorised it is becoming unsellable in regulated markets. Suppliers should treat audit trails, explainable decision-making and human-in-the-loop controls as release blockers, not roadmap items. The next generation of procurement RFPs will ask for chain of custody by default.

The governance tooling market is fragmenting into layers. AgentMinder occupies the runtime identity and authorisation layer. Other vendors are building model routing, cost monitoring, AI-ready data foundations and open-source supply-chain verification. Suppliers should pick their layer and build depth, because buyers are assembling multi-vendor stacks rather than buying monolithic suites. The vendor that tries to do everything may find itself outcompeted by specialists at every layer.

Standards integration becomes a gating factor. AgentMinder integrates with existing authorisation stacks via the AuthZEN standard, allowing organisations to reuse current policy enforcement endpoints without routing traffic through a single SaaS chokepoint. Suppliers that adopt open standards for identity, authorisation, observability and model interoperability will find faster enterprise sales cycles. Those that build proprietary silos will face integration friction.

The broader context

Broadcom's move is part of a broader pattern. In the past eight weeks, multiple enterprise infrastructure vendors have launched or enhanced agent governance capabilities: Google Cloud expanded its Gemini Enterprise Agent Platform with semantic governance and content protection; SnapLogic launched MCP Builder to turn integration pipelines into agent-ready tools; and AvePoint, Deloitte and the UN Scientific Panel have all published data showing that agent deployment is outpacing security readiness.

The common thread is that the industry is moving from "can agents work?" to "can we trust them?" This is the natural maturation of any enterprise technology. First comes capability. Then comes scale. Then comes control. We are now firmly in the control phase.

Broadcom's scale claim is also worth attention. Handling 43 million API calls daily across multi-region active-active deployments is not a proof of concept. It is production evidence that agent governance can operate at the same scale as the agents themselves. For buyers who have been told that governance adds unacceptable latency, Broadcom's numbers are a useful counterpoint.

The Agentic Expo angle

Agentic Expo exists because the gap between agent capability and enterprise trust is where the real commercial value lives. Broadcom's AgentMinder is proof that the largest infrastructure vendors now agree. They are not selling models. They are selling the control plane that makes models safe to run inside regulated enterprises.

By March 2027, when Agentic Expo opens at Olympia London, runtime governance will be a standard procurement criterion, not an advanced feature. The exhibitors and speakers on our floor will be the people who have built, sold and deployed agentic systems with verifiable identity, real-time policy enforcement and production-grade observability. The conversation will not be about whether agents are technically possible. It will be about whether they are organisationally safe. Broadcom has just shown us where the infrastructure market is heading. Our job is to bring the people who will get there into the same room.

Get Tickets Exhibit at Agentic Expo

Sources: Broadcom, Broadcom Unveils AgentMinder, An Enterprise Solution for AI Agent Governance and Runtime Control, 31 August 2026; StorageNewsletter, VMware Explore 2026: Broadcom Unveils AgentMinder, 2 September 2026; The Fast Mode, Broadcom Expands VMware Private AI Cloud with AI Factory, 7 September 2026; Cube Research, VMware Explore 2026 Wrap-Up, 4 September 2026; StorageReview, VMware Explore 2026: Broadcom Doubles Down on Private Cloud Economics and Agentic AI, 5 September 2026.