IBM Bob Goes Self-Hosted for Air-Gapped AI Development

IBM Bob Goes Self-Hosted for Air-Gapped AI Development

IBM has released a self-hosted version of IBM Bob, its agentic software development platform. Companies can now run AI-assisted development and application modernization on their own infrastructure instead of sending code to an outside service. The option covers on-premises data centers, private clouds, sovereign clouds and fully air-gapped environments. A sovereign cloud keeps data under a specific country's or region's jurisdiction. An air-gapped environment is cut off from external networks entirely.

The target customer is clear. These are organizations whose source code is sensitive, whose data is regulated, or whose systems are too critical to expose to an externally hosted AI tool. IBM is pitching the release to financial services, government, healthcare and critical infrastructure, and to any business worried about protecting its intellectual property.

What Bob does, and what stays the same

Bob is meant to go beyond writing code. IBM describes it as a tool that helps developers understand existing applications, plan changes, carry out the work and check the results. The goal is to cover more of software delivery and modernization, not only code generation.

According to a background post from IBM, the self-hosted edition is generally available now. It keeps Bob's core features:

  • BobShell, its integrated development environment
  • Parallel tool calling
  • Skills and operating modes

Optional premium packages add Java modernization and support for IBM i and IBM Z, the company's midrange and mainframe platforms. These depend on licensing and deployment requirements.

Bring your own model

Customers must supply access to a supported model. For models installed and managed on their own hardware, IBM currently supports two: Nvidia's Nemotron and Poolside's Laguna. Organizations that already pay for eligible models can use them under a bring-your-own-license arrangement.

There is also a hybrid route. Bob can connect to external model services, so teams can decide workload by workload where AI processing happens. IBM says a supported self-hosted setup keeps source code, development context and build artifacts inside the environment the customer manages.

IBM gave a banking example. Developers could use local model processing for core banking software, then switch to an approved external service for less restricted work. The point is that the developer experience stays the same across both setups.

The problem IBM is trying to solve

Neel Sundaresan, IBM's general manager of AI and automation, framed it this way: "Organizations need AI that operates inside environments they have control over, especially when working with sensitive code and regulated data."

IBM backed this up with a June report from its Institute for Business Value. In that survey, 68% of executives said meeting data residency and sovereignty requirements across geographies is challenging. IBM says the new option gives customers more control over data residency, security policies, governance and development workflows.

The market responded quickly. IBM shares rose more than 3% in late trading on the New York Stock Exchange after the announcement.

Our Take

This release fits a pattern we keep seeing. Enterprise buyers want agentic tools, but they want them inside their own security boundary. Recent incidents show why. In one case, AI agents exposed thousands of company screenshots on a public code platform. For a bank or a government agency, sending core source code to a third-party service is a hard sell. Keeping the whole loop in-house removes one major objection.

The limit is the model list. Two supported local models is a narrow choice compared with what hosted services offer. Self-hosted performance will depend on how well Nemotron and Laguna handle complex, multi-step development work. The broader trend toward capable smaller models, such as local coding agents on consumer GPUs, suggests that gap may narrow. Whether it narrows enough for regulated production work is still an open question.

The hybrid design is also worth watching. Routing sensitive work locally and other work externally sounds clean in a slide deck. In practice, it requires clear rules about which code counts as sensitive, and teams have to follow them. It is worth watching whether IBM expands the supported model list. The other thing to watch is whether competitors follow with their own air-gapped options, as vendors have done in other regulated markets such as AI for government agencies.