October 4, 2026
IBM Puts Its Bob Coding Agent Inside the Firewall: What Self-Hosted, Air-Gapped AI Means for Regulated Enterprises
For the last two years, the default deal for AI coding tools has been simple: your source code travels to someone else’s cloud, and productivity comes back. For banks, government agencies, and other regulated organisations, that deal was often a non-starter. On October 1, 2026, IBM announced that Bob, its agentic software development platform, can now run entirely self-hosted — on a company’s own servers, in a private or sovereign cloud, or fully air-gapped with no outside network connection at all.
This post unpacks what IBM actually announced, why the timing matters, what self-hosting really costs you in operational responsibility, and how engineering leaders should decide whether an “inside the firewall” coding agent belongs in their stack.
What IBM Actually Announced
Bob is IBM’s multi-agent development platform covering the software lifecycle: planning, coding, testing, deployment, and legacy modernisation. The new self-hosted option keeps Bob’s core pieces intact — including its BobShell command-line interface and parallel tool calling — while moving the whole stack inside the customer’s boundary.
Four deployment modes
According to IBM’s release, Bob now supports on-premises data centres, private clouds, sovereign clouds, and fully air-gapped environments, plus hybrid configurations that connect to external model services when a team chooses to. Code and application context stay inside customer infrastructure, and IBM frames the offer around data residency, security policy, and AI governance oversight.
Which models run locally
For models running on a customer’s own hardware, IBM currently supports Nvidia’s Nemotron and Poolside’s Laguna, with hybrid setups for teams that want to mix local and external models. IBM did not disclose pricing in the announcement.
The internal proof point
IBM says Bob has run internally since June 2025, growing from 100 developers to more than 80,000 users, with surveyed users reporting an average 45% productivity gain. Treat that figure with the usual care: it is a vendor-reported, self-surveyed number from IBM’s own workforce, not an independent benchmark.
Why Regulated Industries Have Been Waiting
The pitch is aimed squarely at organisations that have been unwilling to send proprietary source code to a third-party AI cloud. For a bank, a defence contractor, or a public-sector body, the barrier is rarely a lack of enthusiasm. It is data residency rules, audit obligations, and the simple fact that source code often embeds business logic, credentials, and references to regulated data.
IBM’s own release cites research that 68% of executives say meeting data residency requirements across geographies is challenging. The broader policy climate points the same way: Gartner has predicted that 35% of countries will be locked into region-specific AI platforms by 2027. If you want the wider context, our guide to sovereign AI for business explains why this is becoming a board-level topic.
The security argument
Recent incidents have also sharpened the case for keeping agents close to home. Coverage of the launch points to autonomous agent breaches earlier this year as context for IBM’s positioning, arguing that agents running inside controlled infrastructure reduce exposure. We have covered the coding-tool side of that risk before, from leaked screenshots in AI coding agents to a zero-click flaw two vendors would not patch.
Built-In Governance: Audit Trails and Policy Controls
A self-hosted agent is only useful to a regulated buyer if its behaviour can be inspected. IBM says BobShell creates self-documenting audit trails in real time so every agent action is traceable, and that security controls such as prompt normalisation, sensitive-data scanning, real-time policy enforcement, and AI red-teaming are part of the workflow rather than bolted on afterwards.
This matters because the hard part of agent governance is not blocking the obvious. It is reconstructing, after the fact, what an autonomous system did and why. Our earlier piece on putting agents in a box with Nvidia’s Open Agent Safety Platform covers the containment side of the same problem; Bob’s pitch is that containment and auditability should ship together.
The Trade-Off: You Now Run the Thing
Self-hosting is not free sovereignty. Analysts quoted in coverage note that it shifts responsibility to the enterprise: GPU capacity, model updates, audit trails, and governance of agent behaviour all become your team’s job rather than the vendor’s. Patching, scaling, and monitoring move onto your payroll.
IBM itself offers a hybrid option precisely because fully air-gapped operation is not always practical. A locally hosted model also has to be good enough for your codebase. If developers find the in-house option noticeably weaker than public tools, you risk shadow usage of unapproved assistants — the very leak you were trying to prevent.
A quick cost-of-ownership checklist
- Compute: Do you have, or can you procure, the GPU capacity to serve your developer population at acceptable latency?
- Model lifecycle: Who evaluates and upgrades the local models, and how often?
- Operations: Who is on call when the agent platform is down during a release?
- Governance: Who reviews audit logs, and what triggers escalation?
What This Means for the AI Vendor Landscape
IBM is not alone in treating deployment location as a product feature, and the move fits a pattern we have been tracking. IBM’s OpenAI partnership signalled the end of single-vendor AI bets, and Bob’s support for multiple local models extends that multi-model stance into the coding workflow. Meanwhile, vendors such as Tabnine have supported on-premises and air-gapped deployments for security-conscious buyers, so Bob enters a space that already has credible competitors.
For buyers, the lesson is that “where does the model run?” is now a first-class procurement question alongside “how good is it?” and “what does it cost?”.
How to Decide: A Practical Framework
Not every organisation needs an air-gapped coding agent. A sensible evaluation looks like this:
- Classify your code. Separate repositories that contain regulated data or crown-jewel logic from everything else. Many firms discover only a fraction truly needs air-gapping.
- Pilot on a bounded team. Compare self-hosted and cloud assistants on the same real tasks, measuring acceptance rate and rework, not just speed.
- Price the full stack. Include GPUs, platform engineers, and model upgrades, not only licences.
- Demand audit evidence. Ask to see a real action trail from a real session before you sign.
- Plan for hybrid. Route sensitive repositories to local models and low-risk work to external ones, with policy deciding the route.
Conclusion: Key Takeaways
IBM’s self-hosted Bob will not suit everyone, but it marks a real shift: the question for regulated enterprises is moving from “can we use AI coding agents?” to “where, and under whose control?” To act on it:
- Audit which of your repositories genuinely cannot leave your network.
- Treat deployment location, model choice, and audit evidence as procurement criteria.
- Budget for the operational cost of self-hosting before assuming it is the cheaper or safer path.
- Verify vendor productivity claims, including IBM’s 45%, with a pilot on your own code.
Frequently Asked Questions
What is IBM Bob?
IBM Bob is an agentic software development platform that supports planning, coding, testing, deployment, and legacy modernisation. It is built around a command-line interface called BobShell and uses multiple AI models.
What does “self-hosted” mean for Bob?
It means the platform can run on your own servers, in a private or sovereign cloud, or in a fully air-gapped environment with no outside network connection. Code and application context stay inside your infrastructure.
Which models can run locally with Bob?
For models running on a customer’s own hardware, IBM currently supports Nvidia’s Nemotron and Poolside’s Laguna. Hybrid setups can also connect to external model services.
Is the 45% productivity gain reliable?
It is IBM’s own figure, based on surveyed internal users among more than 80,000 employees. It is a useful signal but not an independent benchmark, so test on your own codebase.
What are the downsides of self-hosting an AI coding agent?
Your team takes on GPU capacity, model updates, patching, monitoring, and governance. Local models may also lag the best public ones, which can tempt developers toward unapproved tools.
Sources
- IBM Introduces Self-Hosted Deployment for IBM Bob (PR Newswire) - IBM’s official announcement of deployment options and governance claims
- IBM Brings Bob to Self-Hosted and Air-Gapped Environments (MarkTechPost) - technical coverage including supported local models
- IBM Bob hits 80,000 developers with 45% productivity gains (The New Stack) - internal adoption figures and audit-trail features
- IBM Bets Enterprises Want Their AI Coding Agents Locked Inside Their Own Walls (Startup Fortune) - market context and trade-offs
- IBM Moves Its Bob Coding Agent Inside the Firewall (daily.dev) - analyst view on operational responsibility
- Gartner Predicts 35% of Countries Will Be Locked Into Region-Specific AI Platforms by 2027 - sovereignty policy context
- Tabnine’s Visionary Status (Futurum Group) - on-premises and air-gapped competitor landscape
Have a project like this in mind?
Tell us what you're building — we'll help you scope it and ship it.
Talk to usKeep reading

October 9, 2026
SAP Buys TechWolf: Why the Grounding Layer, Not the Model, Is Enterprise AI's Next Battleground

October 8, 2026
Oracle Fusion Claw: What a Governed Agent Runtime Inside Your ERP Means for Finance and Operations Teams

October 7, 2026