Broadcom pushed VMware Cloud Foundation 9.1.1 to general availability on September 3, 2026, and buried inside the release notes is a bet that could reshape where enterprises run their AI workloads. The update makes Multi-Tenant Model Sharing generally available, bolts new security controls onto Kubernetes clusters, and previews an AI gateway meant to broker access to more than 150 open-weight and third-party models. None of that sounds like a headline grabber next to GPT-6 Astra or Gemini’s Windows rollout. But for the thousands of enterprises still running regulated data on-premises, VCF 9.1.1 is Broadcom’s clearest statement yet that private AI infrastructure doesn’t have to mean falling behind the hyperscalers.
The timing matters. Broadcom shipped this update four months after VCF 9.1’s initial general availability in May 2026, and just two days before Amazon expanded its own Aurora Serverless performance gains to five new regions. Both companies are racing to make their infrastructure look AI-native, but they’re taking opposite paths: Amazon is optimizing the public cloud database layer for bursty agentic workloads, while Broadcom is trying to convince enterprises they never need to leave their own data centers at all.
Inside the September 3 Release: What Changed
VMware Cloud Foundation 9.1.1 is a point release, not a major version bump, but Broadcom packed it with capabilities that had been sitting in tech preview since the 9.1 launch in May. According to Broadcom’s official VMware Cloud Foundation blog, the update adds Multi-Tenant Model Sharing to general availability, introduces new AI and Kubernetes private cloud operations tooling, and gives administrators the option to embed an AI conversational chat interface directly into the VCF Operations console, configurable with whatever model the customer chooses to run locally.
That last detail is easy to overlook, but it signals where Broadcom wants VCF to go: fewer separate AI tools bolted onto infrastructure, and more AI baked directly into the operational layer that admins already touch every day. GitOps support and native object storage remain in tech preview in this release, meaning some of the more ambitious platform engineering features enterprises have been asking for still aren’t production-ready. Broadcom has not committed to a date when those will reach general availability.
Multi-Tenant Model Sharing Reaches General Availability
The headline capability in 9.1.1 is Multi-Tenant Model Sharing, and it addresses a real cost problem that private AI deployments have struggled with. Before this release, VMware customers running large language models on VCF often ended up deploying a separate model instance per business unit or project, which meant duplicated GPU capacity, duplicated licensing costs, and duplicated operational overhead. Multi-Tenant Model Sharing lets a single deployed model serve multiple tenants at once, with per-tenant data privacy and isolation enforced through Kubernetes namespaces.
For a platform team supporting five internal product groups that all want access to the same base model, that’s the difference between provisioning one GPU cluster and provisioning five. It’s also the feature most directly aimed at the FinOps concerns that come with running large models on fixed, owned infrastructure rather than a metered public cloud. Enterprises that have already invested in FinOps practices built around tracking AI spend will recognize the logic immediately: shared infrastructure only pays off if utilization stays high, and namespace-level isolation is what makes sharing safe enough to attempt at scale.
The isolation model relies on namespaces the same way Kubernetes normally separates workloads, extended here to cover model access, data governance, and per-tenant usage accounting. That’s a meaningfully different architecture from how most hyperscaler AI services handle multi-tenancy, where isolation typically happens at the account or API-key level rather than inside a shared cluster.
Five New Security Layers Built Around AI Workloads
Security is where Broadcom is spending the most engineering effort, and for good reason. VCF 9.1 introduced five additional layers of security controls covering both AI and conventional workloads, including threat detection and prevention, live patching of VCF hosts without downtime, and data encryption at rest through vSAN. NetworkWorld’s coverage of the release described zero-trust lateral security extending intrusion detection and prevention directly into Kubernetes AI workloads, with live patching now covering an estimated 80% of common upgrade scenarios without requiring a maintenance window.
That live-patching figure is the kind of operational detail that matters more to platform engineers than it does to headline writers, but it addresses a genuine pain point. Kubernetes clusters running AI inference at production scale are expensive to take offline, and every patch cycle that previously demanded a maintenance window now competes directly with GPU utilization targets. Cutting that friction by 80% of use cases changes how often teams are willing to apply security updates at all, which has direct implications for the kind of container hardening practices that used to require scheduled downtime to enforce.
Broadcom also folded in support for the Model Context Protocol, along with a new LLM gallery and performance monitoring tooling for models running inside VCF, according to TechTarget’s reporting on the update. That puts governance and observability for AI models on the same operational footing as governance for virtual machines and containers, rather than treating AI as a separate, less-monitored category of workload.
Kubernetes Performance Jumps 2.6x Under VCF 9.1.1
Broadcom’s most quotable number from this release cycle is a 2.6x increase in Kubernetes cluster scale compared to earlier preview builds, alongside a 75% reduction in deployment time and a 75% shorter upgrade window, according to NetworkWorld’s review of the platform. Those gains come from a combination of the VMware Kubernetes Service improvements built into VCF and new virtualized load balancing through VMware’s Avi Load Balancer paired with vDefend, which together remove the need for dedicated hardware appliances in front of AI inference endpoints.
Removing hardware load balancers from the inference path isn’t just a convenience. It’s a cost and latency argument aimed squarely at teams who assumed on-premises AI infrastructure meant accepting slower iteration cycles than what they’d get running the same workload on EKS, AKS, or GKE. Faster deployment and shorter upgrade windows are the kind of metrics that show up in procurement conversations, where platform teams are increasingly asked to justify why AI infrastructure lives on-premises instead of in a hyperscaler’s data center.
The AI Gateway Preview Opens the Door to 150+ Models
Alongside Multi-Tenant Model Sharing, Broadcom previewed an AI gateway inside the Private AI Factory capability that will support more than 150 third-party open source and open-weight models, with app-level authorization controls governing which applications can call which models. This is still a preview feature rather than a general availability shipment, but it points toward Broadcom’s long-term thesis: enterprises don’t want to pick one model vendor and commit, they want a governed marketplace of models they can swap between depending on cost, latency, or compliance requirements.
That’s a meaningfully different pitch from what Amazon, Microsoft, and Google offer through their own model catalogs. Amazon Bedrock and Google’s Vertex AI already broker access to dozens of third-party models, a point covered in shattered.io’s own reporting on AWS Bedrock’s expanded model catalog. Broadcom’s version of that idea runs entirely inside the customer’s own infrastructure, which changes the compliance calculus for industries like healthcare, banking, and government that face restrictions on sending data to a public cloud API, even one hosted by a trusted hyperscaler.
Why Broadcom Is Racing a VCF 8 Support Deadline
TechTarget’s coverage framed the 9.1.1 release bluntly: Broadcom is racing the clock on support timelines for older VMware infrastructure, and using new AI and Kubernetes capabilities as the incentive to get customers to move. That framing lines up with a broader pattern that’s played out since Broadcom closed its acquisition of VMware.
The 2023 Acquisition That Reshaped VMware
Broadcom completed its roughly $69 billion acquisition of VMware in November 2023, and within months had restructured the company’s entire licensing model around subscriptions rather than perpetual licenses. That shift triggered public frustration from long-time VMware customers, many of whom saw costs rise sharply as they were pushed toward bundled VCF subscriptions instead of the à la carte vSphere licenses they’d used for years.
The Licensing Backlash That Followed
That backlash pushed a visible wave of enterprises to evaluate alternatives, from Nutanix to OpenStack-based private clouds to simply moving workloads to the public cloud outright. Broadcom’s answer has been to make VCF itself indispensable rather than optional, and the AI capabilities in 9.1 and 9.1.1 are the clearest version of that strategy yet: give customers a reason to stay that has nothing to do with switching costs and everything to do with capabilities they can’t easily replicate elsewhere.
Private Cloud vs Hyperscaler AI: The Real Trade-Off
The core tension VCF 9.1.1 is trying to resolve isn’t really about performance. It’s about where sensitive data and proprietary models are allowed to live. Public cloud AI services from AWS, Microsoft, and Google offer elastic scale and managed infrastructure that most enterprises can’t match on their own hardware. What they don’t offer, at least not without extensive contractual and architectural work, is the guarantee that a model and its training data never leave a customer’s own data center.
For regulated industries, that guarantee is often non-negotiable. A bank running fraud-detection models on customer transaction data, or a hospital system fine-tuning a clinical model on patient records, faces different compliance requirements than a startup calling a public API. VCF 9.1.1’s pitch is that those organizations can now get most of the operational convenience of a managed AI platform, including model sharing, governance, and observability, without the API calls ever crossing into a third party’s cloud.
The trade-off is capital cost and operational ownership. Running GPUs on-premises means buying and maintaining that hardware, planning capacity ahead of demand rather than scaling elastically, and staffing a team capable of operating a Kubernetes-native private cloud at the level of sophistication VCF now demands. That’s a real cost, and it’s the reason hyperscaler AI adoption has outpaced private AI adoption industry-wide, even among enterprises that would prefer to keep data in-house.
How VCF 9.1.1 Stacks Up Against AWS, Azure and Google Cloud
Broadcom has not published per-core or per-CPU list pricing for VCF 9.1.1’s AI capabilities, framing Private AI Factory as part of the broader VCF subscription entitlement rather than a separate metered product. That makes direct dollar-for-dollar pricing comparisons against hyperscaler AI services difficult, but the architectural differences are clear enough to compare directly.
| Platform | Deployment Model | Latest AI Milestone | Multi-Tenant Model Sharing | Pricing Structure |
|---|---|---|---|---|
| VMware Cloud Foundation 9.1.1 (Broadcom) | On-premises / private cloud | GA Sept. 3, 2026 | Yes, GA in this release | Bundled subscription entitlement |
| Amazon Bedrock / AWS AI services | Public cloud, managed | Expanded web search and model catalog (2026) | Account and API-key level isolation | Consumption-based, pay-per-use |
| Microsoft Azure AI Foundry | Public cloud, managed | Ongoing model catalog expansion | Tenant-level isolation via Azure AD | Consumption-based, pay-per-use |
| Google Vertex AI | Public cloud, managed | Ongoing model catalog expansion | Project and org-level isolation | Consumption-based, pay-per-use |
The structural difference that stands out is where isolation happens. Hyperscalers isolate tenants at the account or API-key boundary, which works well for organizations comfortable sending data outside their own network. VCF 9.1.1 pushes isolation down to the Kubernetes namespace level inside infrastructure the customer physically controls, which is a fundamentally different trust model, not just a cheaper or more expensive version of the same thing.
From VCF 9.0 to 9.1.1: The Feature Timeline
Broadcom has now shipped three meaningful VCF milestones within about a year, each one adding AI capability on top of the last. The pace shows how central AI has become to Broadcom’s VMware roadmap, in a way that wasn’t true even 18 months ago.
| Version | GA Date | Key AI/Kubernetes Additions | Status of Advanced Features |
|---|---|---|---|
| VCF 9.0 | Late 2025 | Private AI Services folded in: model onboarding, AI-optimized infrastructure management | Foundational, limited multi-tenancy |
| VCF 9.1 | May 5, 2026 | Five new security layers, live patching, vSAN encryption at rest, Private AI Factory preview | Multi-tenant model sharing in preview |
| VCF 9.1.1 | September 3, 2026 | Multi-Tenant Model Sharing GA, AI chat in Operations UI, MCP support, LLM gallery | GitOps and object storage still in tech preview |
That cadence, a major release every four to five months, mirrors the pace hyperscalers set for their own AI platforms, and it’s a departure from VMware’s historically slower, annual-cycle release habits under its previous ownership. Whether Broadcom can sustain that pace while also stabilizing the GitOps and object storage features still stuck in preview is an open question heading into 2027.
AWS Answers the Same Quarter With Aurora Serverless v4
Broadcom isn’t the only infrastructure vendor tuning its stack for AI workloads this quarter. On August 31, 2026, just days before VCF 9.1.1 shipped, Amazon expanded Aurora Serverless platform version 4 to five additional regions, including Asia Pacific (New Zealand), Asia Pacific (Thailand), Africa (Cape Town), Europe (Milan), and Mexico (Central). Platform version 4 delivers up to 30% better database performance and roughly 45% faster capacity scale-up during demand spikes, according to AWS’s own release notes, while still preserving Aurora Serverless’s signature ability to scale down to zero when idle.
Amazon also shipped a related update in early August letting Aurora Serverless reach up to 12 ACUs of capacity within about one second during a scale-up event, continuing to scale as high as 256 ACUs, a change AWS explicitly tied to supporting bursty, agentic AI workloads rather than traditional steady-state applications. Both companies made these improvements available at no additional cost to existing customers, which suggests neither wants pricing friction slowing adoption of AI-tuned infrastructure right now.
The contrast is instructive. Amazon is optimizing a managed database service so public cloud applications can absorb unpredictable AI traffic without over-provisioning. Broadcom is optimizing a private cloud platform so enterprises never have to send that traffic to a public cloud at all. Neither company is wrong about where demand is heading, they’re just betting on different answers to where enterprises want that demand served from.
Early Enterprise Signals: Who’s Actually Adopting VCF 9.1.1
TechTarget’s reporting on the release included direct evidence that the strategy is landing with at least some customers. One bank cited platform security agility as the deciding factor in its decision to move forward with a VCF migration, specifically pointing to the AI and Kubernetes security updates as what tipped the decision. Separately, TechTarget described enterprises re-evaluating their Kubernetes and Tanzu strategy in light of the clarity VCF 9.1.1 brings to how Kubernetes workloads and AI models coexist on the same platform.
Those are early, narrow signals rather than broad market data, and Broadcom hasn’t published customer adoption numbers for VCF 9.1.1 specifically. But the pattern matches what you’d expect from a vendor trying to convert regulatory anxiety about public cloud AI into a reason to renew rather than migrate away. Financial services and healthcare, the two sectors most constrained by data residency rules, are exactly where this kind of pitch should land first if it’s going to land anywhere.
What’s Still Missing: GitOps and Object Storage in Preview
It’s worth being direct about what VCF 9.1.1 doesn’t fix. GitOps workflows, which have become the default way platform teams manage Kubernetes configuration at scale, remain in tech preview rather than general availability. Native object storage, a basic requirement for many AI training and inference pipelines that expect S3-compatible storage, is also still a preview feature. Teams evaluating VCF for a production AI deployment today need to plan around those gaps rather than assume they’ll be solved by the time a migration project actually kicks off.
Here’s a simplified example of the kind of namespace-level resource isolation that underlies Multi-Tenant Model Sharing, illustrating how a platform team might scope GPU and memory limits per tenant on a shared model deployment:
apiVersion: v1
kind: ResourceQuota
metadata:
name: tenant-a-model-quota
namespace: tenant-a-inference
spec:
hard:
requests.nvidia.com/gpu: "2"
limits.memory: "64Gi"
pods: "10"
---
apiVersion: v1
kind: ResourceQuota
metadata:
name: tenant-b-model-quota
namespace: tenant-b-inference
spec:
hard:
requests.nvidia.com/gpu: "1"
limits.memory: "32Gi"
pods: "6"
That’s a generic illustration of the namespace-quota pattern, not an official VMware configuration sample, but it captures the mechanism Broadcom is relying on: shared model, isolated consumption limits, enforced at the Kubernetes layer rather than the application layer.
Five Predictions for Private AI Cloud Through 2027
- Broadcom will move GitOps support and native object storage to general availability within the next one to two VCF point releases, closing the gap that currently forces platform teams to bolt on third-party tooling.
- More regulated-industry enterprises, particularly in banking and healthcare, will publicly cite VCF’s Kubernetes-native AI security features as the deciding factor in staying on VMware rather than migrating to OpenStack or bare-metal alternatives.
- AWS, Microsoft, and Google will each respond with sharper messaging around hybrid and on-premises AI options, since VCF 9.1.1’s pitch directly targets the compliance objections that have slowed hyperscaler AI adoption in regulated sectors.
- The AI gateway’s 150-plus model catalog will expand further, and Broadcom will likely add usage-based billing options for Private AI Factory as customers push back on the current bundled-subscription pricing model.
- Expect a Kubernetes point release from the VCF team roughly every four to five months through 2027, mirroring the release cadence hyperscalers already use, as Broadcom tries to close the perception gap between private cloud and slow-moving cloud.
Frequently Asked Questions
What is VMware Cloud Foundation 9.1.1?
VMware Cloud Foundation 9.1.1 is Broadcom’s point release of its private cloud platform, reaching general availability on September 3, 2026. It adds Multi-Tenant Model Sharing, new AI and Kubernetes operations tooling, and support for the Model Context Protocol on top of the VCF 9.1 foundation shipped in May 2026.
How is VCF 9.1.1 different from Private AI Services in earlier VCF versions?
VCF 9.0 introduced basic Private AI Services, including model onboarding and AI-optimized infrastructure management. VCF 9.1 added five layers of security controls and previewed multi-tenant model sharing. VCF 9.1.1 is the first release where Multi-Tenant Model Sharing reaches general availability rather than tech preview.
Does VCF 9.1.1 compete directly with AWS Bedrock or Azure AI Foundry?
Not in the sense of offering the same public API. VCF 9.1.1 runs entirely inside a customer’s own data center, while Bedrock and Azure AI Foundry are managed public cloud services. They compete for the same budget and the same AI workloads, but on fundamentally different deployment models.
What is Multi-Tenant Model Sharing?
It’s a VCF 9.1.1 capability that lets a single deployed AI model serve multiple internal tenants or business units at once, with data privacy and resource isolation enforced through Kubernetes namespaces, instead of requiring a separate model deployment per tenant.
Are GitOps and object storage available in VCF 9.1.1?
No. Both GitOps workflow support and native object storage remain in tech preview in VCF 9.1.1, meaning they are not yet recommended for production use and Broadcom has not announced a general availability date for either.
Why did Broadcom prioritize security features in this release?
Broadcom is trying to give customers still running older, pre-VCF VMware infrastructure a concrete reason to upgrade before support timelines tighten further. New AI-focused security controls, including live patching and vSAN encryption at rest, are positioned as capabilities that older platforms can’t match.
How much does VCF 9.1.1’s Private AI Factory cost?
Broadcom has not published separate per-core or per-CPU pricing for Private AI Factory. It is currently positioned as part of the broader VCF subscription entitlement rather than a standalone metered product, unlike consumption-based pricing on AWS, Azure, or Google Cloud AI services.
Is Amazon responding to Broadcom’s private AI push?
Not directly. Amazon’s Aurora Serverless platform version 4 update, expanded to new regions on August 31, 2026, targets a different problem: making public cloud databases scale faster for bursty AI workloads. It reflects the same industry-wide push toward AI-tuned infrastructure, but through a public cloud consumption model rather than a private cloud alternative.




