

Plenty of enterprises want AI coding agents. Fewer are willing to send their source code to someone else’s cloud to get them.
That tension has slowed adoption at banks, insurers, government agencies and other organizations that build software under strict rules about where code and data can live. IBM is betting a self-hosted option will help close the gap. This week, the company announced that IBM Bob, its agentic software development platform, can now run on-premises, in private clouds, in sovereign clouds and in fully air-gapped environments.
IBM made Bob generally available as a SaaS offering in April. At the time, it said on-premises deployment would come in a future release. That release is now here.
Bob is meant to do more than complete code. IBM pitches it as a partner across the software development lifecycle, from planning and design through coding, testing, deployment, and modernization. It coordinates specialized agents for code, tests, documentation, and pipelines. It routes tasks across multiple models, including Anthropic’s Claude, Mistral open-source models, and IBM Granite, based on accuracy, performance, and cost. It also includes approval checkpoints that keep developers in the loop, plus security controls such as sensitive data scanning and real-time policy enforcement.
IBM has been its own biggest test case. The company says more than 80,000 employees now use Bob, up from 100 developers when internal use began in June 2025. Surveyed users report an average productivity gain of 45%.
Those numbers mean little to a regulated enterprise that can’t use the tool. That’s the point of the new deployment options.
With self-hosting, organizations can run supported licensed models on-premises, including in air-gapped environments with no outside network connection. Teams that want more flexibility can use a hybrid setup that keeps Bob inside their own infrastructure while connecting to supported external model services. IBM describes the goal as letting enterprises “bring AI to the data instead of moving their data for the AI.”
“Organizations need AI that operates inside environments they have control over, especially when working with sensitive code and regulated data,” said Neel Sundaresan, general manager of AI and automation at IBM. “Bob’s self-hosted deployment provides a way for enterprises to bring agentic AI directly to those environments so they can benefit from the technology while maintaining security, compliance, and operational control.”
IBM also expanded its Bob Premium Package for Z with the same self-hosted option, along with deeper analysis capabilities that give developers more IBM Z-specific context when they work on mainframe applications. That matters. Much of the code enterprises most want to modernize runs on mainframes, and it’s also the code they’re least willing to expose.
The market data supports IBM’s read. An IBM Institute for Business Value report published in June, “The Calculus of AI Sovereignty,” found that 68% of surveyed executives say meeting data residency and sovereignty requirements across geographies is challenging. IBM also cites Futurum Research projections that hybrid and edge deployments will capture 44% of the AI infrastructure market by 2030, while public cloud’s share falls to 46%.
Sovereignty concerns aren’t new. What’s changed is the kind of AI teams want to run. A code-completion tool that suggests one line at a time is one thing. An agent that reads an entire repository, plans changes across services, writes tests, and touches deployment pipelines is something else. It needs broad access to some of the most sensitive assets a company owns. For many security and compliance teams, granting that access to a service running outside their control is a nonstarter.
“Bob is IBM’s bid for a beachhead with enterprise developers, and self-hosting puts it where cloud-first coding agents struggle to reach. Modernizing mainframe code behind the firewall at banks, insurers, and government agencies is the work that gets IBM in the door,” said Mitch Ashley, vice president and practice lead for CIO & Technology Buyers, and Software Lifecycle Engineering at The Futurum Group.
“An agent trusted within those core systems is positioned to become the platform on which the same teams build their own agents. That makes choosing Bob a multi-year commitment. Watch whether customers use Bob for modernization, new agent development, or both.”
Self-hosting doesn’t make the hard parts go away. It moves them. Teams that run Bob on their own infrastructure take on operating it. That means provisioning GPU capacity for local models, managing model updates, monitoring agent behavior, and keeping audit trails that satisfy regulators. Air-gapped deployments also narrow the set of available models. Platform teams must decide whether locally hosted models deliver enough quality for the work they want agents to do.
Then there’s governance inside the firewall. Running an agent on premises keeps code from leaving the building. It doesn’t control what the agent does once it’s there. Approval checkpoints, policy enforcement, and traceability still have to be configured, and they have to fit into existing change management and CI/CD controls.
Still, the announcement reflects a broader shift. The first wave of AI coding tools was built for developers who could use whatever cloud service they liked. The next wave has to work for organizations that answer to auditors, regulators, and national data laws. Vendors that can run their agents where the code already lives will have an easier path into those accounts.
For DevOps and platform teams in regulated industries, the practical first step is to map where AI coding agents would need to run and what they would need to touch. Then compare that map against data residency rules, network segmentation, and existing pipeline controls. Self-hosted options like Bob’s make that conversation possible. They don’t settle it. That work still falls to the teams that build and run the systems.
from DevOps.com https://ift.tt/elCKIym
Comments
Post a Comment