Broadcom Addresses Enterprise AI Security Risks With Sandboxed Runtimes for Autonomous Agents
As companies move agentic workflows into production, Broadcom’s Tanzu division is introducing deny-by-default execution environments to constrain autonomous software.

As enterprise artificial intelligence transitions from early experimental phases to full production environments, organizations are encountering structural security challenges regarding autonomous AI agents. Software agents built to automate business processes, process claims, and write software code require broad connectivity to enterprise data and internal APIs, creating friction for technology leaders hesitant to let autonomous code roam corporate networks without oversight.
This shift is placing internal platform engineering teams back at the core of enterprise technology architecture, as first reported by SiliconANGLE. Companies are adapting traditional cloud-native operational paradigms—including orchestration, telemetry, detailed observability, and granular permission controls—to manage large deployments of intelligent software agents. Because agentic tools function similarly to microservices architecture, centralized platform infrastructure serves as a natural enforcement point for security boundaries.
Speaking during an interview at VMware Explore 2026 with John Furrier of theCUBE, Broadcom Inc. Vice President and Tanzu Division General Manager Purnima Padmanabhan highlighted the inherent risks of autonomous software. “Agents have, by definition, agency, which means you just give the intent and resources and then the agent interprets that intent and decides to do something,” Padmanabhan stated. She emphasized that enterprise organizations must figure out how to build and execute agents rapidly while ensuring they operate inside isolated sandbox environments.
To address these governance demands, Broadcom is positioning dedicated execution runtimes rather than basic software development kits as the standard framework for enterprise agent security. The company has embedded Tanzu Platform Agent Foundations into VMware Private AI Cloud, creating an isolated environment where every underlying model, auxiliary tool, and corporate dataset must be explicitly assigned to an agent before execution can take place.
Alongside isolated execution environments, the platform incorporates structured data management pipelines that perform text chunking, vector embedding generation, and granular access enforcement. This architecture enables AI models to interact with vetted, processed data products without requiring direct authorization to access sensitive original databases. Padmanabhan noted that locking down an agent completely renders it useless, stating, “The right way to secure an agent is to put it in a black box and give it nothing, but then you won’t get any intelligence.” She explained that security must be managed through structured identity, credential management, and role-based access controls connected to curated data sources.
Beyond execution controls, ensuring the security of underlying open-source libraries and code repositories has become a critical focal point for enterprise vendors. Broadcom uses automated scanning tool Mythos across both its proprietary software repositories and external open-source packages. The company is currently expanding its historical Java and Spring framework vulnerability scanning to include Python and Node.js ecosystems, following a major security release in June that marked the largest patch update in its 23-year management of Spring.
Padmanabhan underscored the severity of potential software flaws discovered within open-source components used by autonomous applications. “We are finding issues. We are finding vulnerabilities,” she noted, pointing out that these security flaws are not minor issues but systemic vulnerabilities capable of taking down an entire enterprise infrastructure.
For corporate technology executives, adopting secure private AI systems is quickly shifting from an experimental IT goal to a core strategy for maintaining market share. As coding assistants and process automation tools demonstrate measurable efficiency gains, enterprise decision-makers face increasing pressure to establish operational frameworks quickly or risk losing ground to faster-moving competitors.
Padmanabhan advised corporate technology leadership to treat the current shift toward autonomous enterprise AI as a direct commercial opportunity. “I think the message to the CIO is this is the chance to shine, right? Because this is a revenue opportunity for business,” she said. She added that deploying private AI effectively provides a clear competitive edge, cautioning that failing to adopt these tools creates an immediate business disadvantage as rival firms move forward.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.

