VMware VCF Head On AI Model Vision, ‘Monthly’ Software Patches And Besting Public Clouds In AI Era
VMware’s Krish Prasad explains to CRN his company’s new AI innovation, software patching strategy in the AI era and why he sees VMware Cloud Foundation private cloud besting public cloud solutions.
VMware is bullish about VMware Cloud Foundation (VCF) being the best cloud platform in the AI era as it takes a unique approach to frontier AI model security, doubles down on providing software patches and adds models from companies including Google and Nvidia to VCF.
“On the AI model security side, we have put a lot of focus on hardening our own infrastructure—meaning all the software products from Broadcom, including VCF—are going to be hardened using the frontier security models,” said Krish Prasad, general manager of Broadcom’s VCF division, told CRN.
“Now we have built those models into our software development process on an ongoing basis so that our software that we develop is continuously hardened before it reaches the customer,” he said.
[Related: VMware Adds Google, Nvidia AI Models To VCF; Boosts Tanzu Security To Drive AI Adoption]
VMware Explore 2026
With the launch of VMware AI Factory and other innovations at VMware Explore 2026 this week in Las Vegas, Prasad said VMware is providing the best solution in the market today for AI workloads, infrastructure and AI deployments.
“Because today the problem is to get a model running, they have to put a lot of these pieces together on their own—which is error-prone, expensive, and it takes a long time for them to get it done. What we want to do is make it essentially a push-button to stand up the stack with [our AI Factory], so they can go from metal to model as a service, and to first token, in the shortest time possible,” Prasad said.
“We are giving customers choice of models, choice of accelerators, and choice of servers and OEMs,” he said.
In an interview with CRN, Prasad explains VMware’s AI model strategy for VCF, why organizations are choosing VCF over public clouds, and how his company is committed to launching software patches in the AI era.
“We are delivering patches to customers on a monthly basis. As customers are deploying these patches, we have also focused a lot on innovating around making it easier for customers to consume these patches,” he said.
Here is what every channel partner and customer needs to know about VMware’s future.
What is VMware’s AI model strategy as you add models from Google and Nvidia on VCF?
When it comes to running models for the customer workloads, we do see a lot of focus from customers on moving their AI workloads to on-prem because of the data and IP concerns.
What we are doing is we are announcing a VMware AI Factory.
So think of that as a software stack that runs on top of VCF that is a curated and pre-integrated set of software with all the right drivers and all the other open-source components that you need to run these models—all pre-integrated and validated—that customers can essentially deploy with ease.
Because today the problem is to get a model running, they have to put a lot of these pieces together on their own—which is error-prone, expensive, and it takes a long time for them to get it done.
What we want to do is make it essentially a push-button to stand up the stack so they can go from metal to model as a service, and to first token, in the shortest time possible.
What’s unique about AI Factory and VMware’s AI model workload vision?
What is unique about the way we do this is we are going to be supporting large arrays of about 150 models that we support on top of VCF on-premises.
A large majority of them are open weight models, like Nemotron from Nvidia, Gemma from Google, we have a lot of international models—almost every country is coming up with some variant of open-source models that is focused more regionally on their applications.
So we are going to be supporting all of that for our customers, and they’ll be able to run it on our private AI Factory stack on-premises.
What is VMware’s AI model security vision as there are now over 150 models on VCF?
Frontier models are very powerful in exposing vulnerabilities and the concerns related to that in the security space for customers.
On the AI model security side, we have put a lot of focus on hardening our own infrastructure—meaning all the software products from Broadcom, including VCF—are going to be hardened using the frontier security models.
We were one of the few select vendors who were part of Anthropic’s Glasswing project launched before the release of Mythos. [Anthropic] gave access to a select set of software companies, like Broadcom, early versions of the model. So we got a head start in running those models against our own software. Finding the vulnerabilities early, and that gave us a head start on fixing the vulnerabilities.
So here is a commitment that we have made to customers: We today have gone past the initial stage of trying out those models. Now we have built those models into our software development process on an ongoing basis so that our software that we develop is continuously hardened before it reaches the customer.
Is VMware giving customers choice in terms of AI accelerators or hardware?
So in addition to the models, we are providing customers with the choice of accelerators.
We have a long relationship with Nvidia and enabling the Nvidia GPUs as part of VCF.
This AI Factory stack obviously takes advantage of the work that we have been doing with Nvidia, but in addition to that we are going to give customers the choice of accelerators.
So, if they prefer to use AMD, we have the AI Factory stack also supporting the AMD GPUs.
Another thing we provide is you can run this AI Factory stack on a variety of certified hardware from OEMs ranging from Dell to Cisco to Supermicro and so on.
So we are giving customers choice of models, choice of accelerators, and choice of servers and OEMs.
What are the VMware partner opportunities for this new AI Factory?
A lot of customers are working with their partners to deploy AI workloads. The partners are very active in that space. They see the opportunity.
They see the AI workloads being repatriated on-prem, and so partners are very active in the space.
All these we created are now tools in their hands to go and make their customers successful.
Talk about VMware’s commitment to software patches for customers, which is a big concern in the AI era.
As we find vulnerabilities in our software, we have made a commitment to customers to release patches for the vulnerabilities right away and on an ongoing and regular basis.
What we are doing is we are delivering patches to customers on a monthly basis.
As customers are deploying these patches, we have also focused a lot on innovating around making it easier for customers to consume these patches.
Because it’s one thing to deliver patches to customers, it’s another thing for customers to apply the patches while their infrastructure is still running critical apps and all of that. So things like Live Patching, which is a critical functionality that we deliver to customers, helps the customer consume these patches without disrupting their operations.
So we are focused on not only detecting the vulnerabilities, providing quick fixes to our customers, but also helping them consume these patches.
Why are customers choosing VMware VCF versus the public cloud in the AI era?
The first and foremost, VCF is a platform that allows you to deploy a private cloud that brings all the benefits that you had in the public cloud, from a user experience standpoint, that people like.
Let’s face it, the experience that people get by going and interacting with the public cloud is pretty good, and customers love the experience.
They don’t like the cost of it, but they like the experience.
So they are able to deploy something on-prem with VCF and provide a private cloud with the same experience that people would get interfacing with the public cloud—but at the same time you get better security, better cost controls and better resiliency because you are managing the infrastructure yourself as a private cloud within your premise.
So that’s the fundamental benefit that all customers like.
Where is VMware seeing momentum versus public cloud providers?
We see momentum in customers moving their modern workloads back onto this private cloud.
The reason for that is today, some of the modern workloads are either running in the public cloud or they run in silos within the private infrastructure.
With the hardware costs skyrocketing, they are looking to streamline everything.
So we provide a single platform that can run all different types of applications—whether it’s traditional applications, whether it is containers running on Kubernetes, whether it’s AI workloads— everything running on a single platform with the same operational model, same security [controls], all of that as part of the single VCF-based private cloud.
So that’s where we see the moment: people bringing in these traditional workloads, AI and also the modern workloads back on-premises from either the cloud or within silos in their environment.