← All insights

News analysisLens: United States4 min read

IBM Bob goes self-hosted. Where an AI agent runs is now part of the product decision

IBM made its agentic development platform available on premises, in private and sovereign clouds and air-gapped. What deployment topology changes for regulated engineering teams.

Listen to this article · 6 min

AI-generated narration of the full article.

A weathered stone tower under a clear sky, in La Madre duotone, beside the words Where AI runs
Photo: rawpixel (CC0)

For most AI coding tools, the deployment question has a single answer: the vendor’s cloud. That works until the code itself is the regulated asset. In banks, insurers, defense programs and public agencies, source code, build logs and the systems an agent touches often cannot leave a controlled network.

IBM is addressing that directly. It announced general availability of a self-hosted deployment option for IBM Bob, its agentic software development and modernization platform, for on-premises, private-cloud, sovereign-cloud and air-gapped environments.

The more useful point is not about IBM. It is that where an agent runs is becoming a product feature, evaluated alongside what the agent can do.

What IBM announced

According to IBM, the self-hosted option runs the core of Bob inside customer-managed environments: the IDE experience, BobShell, parallel tool calling, the agent harness, skills and modes.

Model choice depends on the topology:

  • Fully self-hosted, including air-gapped, with supported models the customer has licensed. IBM lists NVIDIA Nemotron and Poolside Laguna.
  • Hybrid, where Bob stays inside the customer environment and connects to an approved external model service. IBM’s list there includes models from Anthropic, Google and OpenAI.

Optional premium packages cover Java modernization, IBM i and IBM Z. IBM frames the release around sovereignty and cites its own Institute for Business Value research, in which 68% of surveyed executives said meeting data residency and sovereignty requirements across geographies is challenging.

The announcement does not detail audit, logging or policy features specific to the self-hosted option, and it does not publish pricing.

Not an isolated move

Two weeks earlier, Cohere and OpenText announced a partnership aimed at governments and regulated industries that combines Cohere’s North platform and models with OpenText’s enterprise data and Aviator agents. The pitch was the same: the combined solution can run on premises or in private, public or sovereign cloud environments, depending on requirements.

Different vendors, different use cases, one shared message. For regulated buyers, deployment control is now part of what is being sold.

Deployment topologies for an AI coding agentMODEL CALLS LEAVE YOUR NETWORKNOTHING LEAVES01Vendor-hosted SaaS02Agent in yourenvironment, externalmodel service03Agent and models inyour environment04Air-gappedOptions IBM now lists for Bob
  1. Vendor-hosted SaaS
  2. Agent in your environment, external model service
  3. Agent and models in your environment
  4. Air-gapped
  • Model calls leave your network: Vendor-hosted SaaS · Agent in your environment, external model service
  • Nothing leaves: Agent and models in your environment · Air-gapped

Options IBM now lists for Bob

Each step to the right adds control and moves operating work onto your team.

What topology actually decides

Choosing a deployment model looks like an infrastructure decision. In practice it settles several product questions at once.

Which models you can use. In IBM’s own lists, the fully self-hosted option supports a shorter set of models than the hybrid option. Air-gapped means accepting the models you can run locally, and testing whether they are good enough for your codebase, before anyone promises frontier quality.

Who operates the agent. Self-hosting moves patching, upgrades, capacity and incident response onto your team. An agent harness with shell access is not a static install. Someone has to own its versions and its failure modes, just as with any other production platform.

What the agent can reach. An agent that runs commands inside your network sits closer to your systems than a SaaS tool. Network segmentation, credentials for the agent, and which repositories and environments it may touch need the same design as any privileged service account.

What evidence you keep. Sovereignty is only half the requirement. The other half is being able to show what the agent did. Because the announcement does not describe audit features, ask how prompts, tool calls and code changes are logged, and whether those logs land in your own SIEM.

What it costs to run models yourself. On-premises inference needs GPU capacity, and that capacity has to be sized, bought and kept busy. That is a real line item in the business case, not a footnote.

We described a similar custody split for model safety monitoring in our analysis of Enterprise Frontier Safeguards: control moves to the customer, and so does the work.

For US regulated teams

Air-gapped and on-premises networks are already the norm in defense programs, parts of the public sector and some financial services environments. For those teams, a self-hosted option can be the difference between “not allowed” and “worth a pilot.”

A sensible evaluation:

  1. Start with the boundary. Write down what may leave the network (nothing, model calls only, or telemetry too) before comparing tools.
  2. Test the self-hosted models on your own code. Use real modernization tasks from your backlog, not vendor demos.
  3. Treat the agent as a privileged workload. Give it its own identity, limit its repositories and environments, and review its permissions like a service account’s.
  4. Ask for the logging model in writing. Which events are captured, where they are stored and how long they are kept.
  5. Budget the operations. Include GPU capacity, upgrades and on-call ownership in the total cost.

The bottom line

Self-hosted Bob shows where enterprise AI buying is heading in regulated sectors: the first question is not which model is smartest, but where the system runs and who controls it. That brings agents within reach of teams that could not use SaaS tools. It also hands those teams the job of operating them. Our 2026 enterprise AI stack guide lists the controls that come with that job.

Have an AI use case stuck between prototype and production?

Tell us what you’re trying to ship. We’ll reply with honest next steps.

Discuss a use case