VCF 9.1.1 reaches general availability
Broadcom made VMware Cloud Foundation 9.1.1 generally available on September 3, 2026. The release centers on Multi-Tenant Model Sharing, a capability that lets different tenants, lines of business, or teams access shared AI models from within the same VMware private AI infrastructure. The value proposition is straightforward: instead of deploying separate model runtimes and GPU pools for each business silo, an enterprise can offer a common set of models while keeping each tenant’s data isolated in its own namespace. Broadcom says the design cuts redundant model copies and minimizes idle GPU allocation, but it has not provided independently verified cost or utilization metrics to back those claims.
This GA milestone comes at a time when many IT organizations are shifting from experimental AI pilots to production-grade workloads. The private AI stack in VMware Cloud Foundation is meant to help companies that cannot or do not want to run sensitive data in public clouds but still want modern model serving and management capabilities.
Key facts from the release
- VMware Cloud Foundation 9.1.1 is generally available as of September 3, 2026.
- Multi-Tenant Model Sharing is included in the GA release.
- AI Assistant for VCF Operations can connect to Private AI Services or a private Google Gemini instance.
- The centralized GitOps Service and native vSAN Object Storage remain Tech Preview features.
- AI Gateway, Secure Agent Framework, and Model Autoscaling are future capabilities.
Multi-Tenant Model Sharing explained
Multi-Tenant Model Sharing addresses a common challenge in enterprise AI: organizations often have numerous teams that want to use the same foundation model or fine-tuned model. Without a shared architecture, each team might provision its own serving endpoint and its own model copy, leading to inefficient GPU usage and inconsistent model versions. Broadcom designed this VCF feature to put models into a shared service layer while preserving namespace isolation. Tenants can use the models without seeing or accessing one another’s underlying data. This separation is essential in compliance-heavy industries where data sovereignty, access control, and auditability are mandatory.
Even with that isolation, the rollout is not necessarily finished. Broadcom’s documentation notes that the Multi-Tenant Model Sharing capability depends on the Private AI Services environment. Enterprises should verify the required component versions and licensing terms before treating it as a production-ready foundation. A separate VMware AI Factory post says Model Runtime “will be enhanced” for multi-tenant sharing, creating a documentation mismatch with the VCF 9.1.1 GA announcement, which lists model sharing as available. That contradiction does not mean the capability is absent; it means infrastructure teams should validate the intended configuration with Broadcom.
AI Assistant for VCF Operations
The new release also introduces an AI Assistant for VCF Operations. This assistant is intended for administrators who want to interact with their operational data using natural language. It can be configured to use models running through Private AI Services or through a private Google Gemini instance, giving organizations a way to avoid sending operational telemetry to an external SaaS service.
With the AI assistant, an administrator might ask a normal-language question about a health alert or a configuration issue. The assistant is designed to correlate alerts, configurations, logs, and other telemetry to help pinpoint the likely cause of a problem. It can also help build management packs without requiring the user to master APIs or automation interfaces. For IT teams that are already under pressure to run AI systems at scale, an operations assistant can lower the barrier to monitoring private-cloud health.
AI infrastructure pressure is rising
The operational background to VCF 9.1.1 is a visible need for refreshed infrastructure. In a Google Cloud survey of 1,402 IT leaders, 83% said their infrastructure required upgrades to support production-grade agentic AI. Another 79% identified security, governance, and MLOps as their leading challenge. These numbers reflect the gap between running a few experiments and running AI systems that must be secure, governed, observed, and continuously updated.
Other research has documented an enterprise AI governance gap as organizations move systems into production. The market is looking for a layer that manages models, permissions, usage, and audit trails in a consistent way. VMware Cloud Foundation is one attempt to supply that layer through private AI services, isolated namespaces, and model sharing. Many of the surrounding controls, however, are not yet fully released. That creates a situation where core model infrastructure is broadly available while governance features are still lagging.
GitOps and object storage remain in preview
Two supporting technologies in VCF 9.1.1 are still at the Tech Preview stage. The first is the VCF GitOps Service, which integrates Argo CD into VCF Automation for organization users. GitOps is a popular operating model in which infrastructure and application state is declared in Git repositories, and continuous delivery tools automatically sync the platform to that desired state. Broadcom says the existing Argo CD supervisor service that was introduced with VCF 9.0.1 remains supported for production use, so enterprises are not left without a supported option while the newer GitOps Service matures.
The second Tech Preview is native S3-compatible vSAN Object Storage. Broadcom first detailed this capability in May as a way to offer object storage alongside block and file services on the same vSAN cluster. Object storage is increasingly important for AI because datasets, checkpoints, documents, and model artifacts are often stored in object buckets. The ability to run that storage on vSAN could simplify private-cloud deployments, but the Tech Preview label signals that it should not yet be considered the default production choice for large-scale AI workloads.
AI Gateway, Secure Agent Framework, and Model Autoscaling are still ahead
Broadcom also outlined several planned capabilities that have not arrived in VCF 9.1.1. The AI Gateway is expected to provide prompt routing and usage controls, which are important for organizations that want to manage access to models in a more centralized way. The Secure Agent Framework is intended to give administrators control over agent sandboxing and tool permissions. Agentic AI applications often let software agents take actions on behalf of users; without fine-grained controls, those agents could access tools or data beyond their intended scope.
Model Autoscaling is also listed as a future release capability. Autoscaling would allow the platform to add or remove model replicas based on demand, helping enterprises manage GPU cost more carefully. The need for such controls is not unique to VMware. The broader industry conversation around advanced AI agents has emphasized monitoring, access restrictions, and mechanisms for blocking risky actions. These themes are reflected in Google DeepMind’s published roadmap for controlling advanced AI agents and in the wider push for agent security frameworks.
What the release means for enterprises
VCF 9.1.1 offers a meaningful step forward for enterprises that want to share private models across multiple teams. Multi-Tenant Model Sharing and the AI Assistant are both designed to make private AI infrastructure more usable in day-to-day operations. At the same time, important pieces of Broadcom’s broader AI control plan are not yet complete. Centralized GitOps and native object storage are still Tech Preview capabilities, while the AI Gateway, Secure Agent Framework, and Model Autoscaling are reserved for future releases.
Enterprises evaluating VCF 9.1.1 should consider their own maturity and requirements. If the immediate goal is shared model inference on private infrastructure with isolated data namespaces, the GA release provides a path. If the plan depends on centralized GitOps, native object storage, agent governance, or autoscaling from day one, those dependencies need to be tracked as upcoming capabilities rather than assumed components of the current release.
Broadcom’s documentation inconsistency around multi-tenant model sharing is a reminder to validate the actual software versions and licensing terms before committing. Even with the GA announcement, a production deployment may require certain versions of Private AI Services and careful review of the support matrix. The broader point is that VCF 9.1.1 is part of a longer road map. Shared private-model infrastructure and AI-assisted operations are available now, but the full private-AI control layer will continue arriving over future releases.
Source: eWeek News