
Agentic AI is expanding the enterprise attack surface rapidly. Broadcom is pushing security enforcement into the hypervisor to inspect traffic without added latency.
Mahajan says perimeter firewalls can be bypassed, so lateral security must be deployed now.
Security decisions are moving to the infrastructure layer as a result.
What happened
Broadcom's Umesh Mahajan says agentic AI's constantly shifting cloud infrastructure is expanding the enterprise attack surface, pushing security enforcement down to the virtualization layer. The company is delivering this through its vDefend and Avi Load Balancer product lines, with firewalling at 75 terabits per vCenter cluster and IDS IPS at 17 terabits.
Why it matters
Mahajan argues perimeter firewalls alone can be bypassed and that enterprises delaying lateral security risk falling behind automated attacks. He warns that bolting protection onto infrastructure already carrying production AI traffic is the failure mode to avoid, saying security must be at the infrastructure level and at scale before compromise happens.
What to watch
Broadcom is doing security processing in the hypervisor to avoid latency from separate appliances, which matters for AI workloads. Mahajan says agents and Model Context Protocol services are transient, so admins need a real-time picture of what is authorized versus shadow IT, with work now landing alongside private cloud modernization programs.
Ask the AI about this article →
The conversation at VMware Explore 2026 frames agentic AI not just as a workload change but as a structural challenge for enterprise security. Mahajan describes how customers have bought multiple security products that do not integrate, leaving seams that attackers exploit. Broadcom's answer is an integrated software stack sharing context across vDefend and Avi Load Balancer, pushing enforcement into the hypervisor where traffic inspection can occur without the delay of separate appliances. That design choice is grounded in the scale of AI workloads, which generate heavy east-west traffic and punish any added latency.
The emphasis on visibility reflects the transient nature of agents and Model Context Protocol services. Administrators need a real-time picture of what is authorized and what is shadow IT before they can quarantine anything, and that work is now being folded into private cloud modernization programs. Mahajan's warning is pointed: waiting two years to deploy lateral security means risking compromise, especially as automated attacks evolve. He frames the choice as deploying security at the infrastructure level and at scale now, rather than bolting it onto infrastructure already carrying production AI traffic.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Chinese large-model developer Z.ai says it can now support large-scale inference using roughly 100,000 domesti…

AI system scaling has pushed interconnect requirements inside data centers from chips and boards up to racks…

Analyst Ming-Chi Kuo says Nvidia has revived the Rubin CPX AI accelerator with a substantially redesigned arch…

Palantir Technologies stock has posted multi-year gains, including an 11x return over 3 years

Apple has escalated its legal battle against OpenAI, claiming in a new court filing that OpenAI is actively de…

Samsung Electronics has locked up as much as 70% of its memory production capacity under long-term supply agre…
