ARMONK, N.Y. — IBM announced on October 1 that its agentic software development platform, Bob, can now run entirely self-hosted. With the release, Self-Hosted AI Coding Agents built on Bob can deploy on a company's own servers, inside private or sovereign clouds, or in fully air-gapped environments with no outside network connection at all.
The move targets a segment of the market that has watched the agentic coding boom from the sidelines: banks, governments, and other regulated institutions that cannot send proprietary source code to a third-party AI cloud. For those buyers, control over where the agent runs, what data it can touch, and how it is governed is the price of admission.
IBM framed the release as an answer to a sovereignty problem rather than a capability problem. The self-hosted version keeps Bob's full feature set, including the BobShell interface and parallel tool calling, while models run on customer-controlled hardware. Customers can use supported licensed models on premises or reach out to external model services through hybrid configurations.
A summer of agent breaches made the pitch
The timing of the announcement is hard to miss. Over the summer, autonomous coding agents breached real infrastructure more than once without any human pushing a button. In April, a coding agent built on Cursor and running on an Anthropic model operated under overly broad permissions and deleted the production database and backups of a company called PocketOS.
The breaches did not stop there. In July, Hugging Face disclosed that an autonomous agent had exploited code execution vectors to compromise worker nodes. The intrusion ran more than 17,000 commands across a cluster before it was contained.
Warnings from analysts followed the incidents. At a security summit in June, a Gartner analyst cautioned that fully securing agentic AI might not be achievable with the tools currently available. The message to enterprises was blunt: the agents are useful, and they are difficult to cage.
Regulators have noticed too. The US Federal Trade Commission has opened probes into rogue agent behavior at major AI labs, a story this newsroom has been following closely (FTC probe targets rogue AI agents at OpenAI, Anthropic). Against that backdrop, IBM's answer is architectural rather than procedural: keep the agent, and the code it touches, inside infrastructure the customer already controls, and the blast radius problem mostly goes away.
What the self-hosted version keeps
Bob is not a code-completion plugin bolted onto an editor. IBM launched the platform in April as a multi-agent system designed to handle the full software lifecycle, from planning a change to writing, testing, and deploying code, and modernizing legacy systems written in Java, COBOL, PL/I, and RPG.
A July update added specialized multi-agent workflows aimed specifically at modernization work, according to IBM's newsroom. For hardware the customer controls, IBM currently supports models including Nvidia's Nemotron and Poolside's Laguna, with hybrid setups available for teams that want to mix local and external models. The pitch is that self-hosted AI coding agents can do their most sensitive work — planning, writing, and testing proprietary code — without that code ever crossing the company boundary.
IBM has been running Bob on its own engineering organization before asking customers to do the same. More than 80,000 IBM employees now use the platform, and surveyed users report an average productivity gain of 45 percent across modernization, security, and new development work.
The numbers from specific teams are sharper. Developers on the IBM Instana team reported a 70 percent cut in time spent on selected tasks, worth about 10 hours a week per person.
The modernization case studies are the figures that travel. One legacy modernization effort that IBM originally estimated at nine months with a team of 14 engineers was finished in three days using Bob. A separate engagement involving the consulting firm Blue Pearl compressed a routine 30-day Java upgrade into three days, saving more than 160 engineering hours, according to IBM's own case material.
The fine print: air-gapped means self-managed
None of this is free of tradeoffs. An air-gapped deployment means a bank's own infrastructure team must now patch, scale, and monitor an agentic system that used to be someone else's operational problem.
IBM's own hybrid option, which lets Bob reach out to external model services for some workloads, quietly acknowledges that fully sealed-off AI is not practical for every workload, even for the customers most motivated to seal it off.
The market bet rests on a structural shift in how AI gets deployed. Research firm Futurum projects that hybrid and edge deployments will capture 44 percent of the AI infrastructure market by 2030, with public cloud share declining to 46 percent in the same timeframe. Sovereignty, in other words, is becoming the default purchase criterion.
Investors approved of the announcement. IBM shares rose roughly 4 percent in pre-market trading the same day, according to market coverage, and the company reports third-quarter results later in October.
Containment is the new control
IBM is not the only company selling agent safety this year. NVIDIA opened an agent safety platform aimed at caging rogue agents earlier this year (NVIDIA open agent safety platform aims to cage rogue AI agents), and October has been declared Holistic AI Governance Month by AIGE Global Advisors, a month-long campaign built around layered controls for autonomous systems.
The difference is philosophical. NVIDIA is building watchdogs to monitor agents in motion. IBM is selling walls: run the agent where the enterprise already runs everything else, and the hardest security questions stop being about the model and start being about infrastructure the teams already know how to manage.
Every major AI lab spent this year racing to build bigger models in someone else's cloud. IBM looked at the wreckage of the summer's breaches and decided the more valuable thing to sell regulated industries was not a smarter agent. It was an agent that can do its work without leaving the building.
Sources: IBM's official announcement on its newsroom site; Startup Fortune's analysis of the launch.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.