IBM announced self-hosted deployment for its agentic software development platform, Bob, on 1 October. Organisations can now run it on premises, in a private cloud, in a sovereign cloud, or in an air-gapped environment.
The feature is straightforward. The context is not. In agentic coding, “self-hosted” has become a marketing term that covers very different architectures, and IBM is now claiming one of the stricter versions of it.
What IBM actually shipped
The self-hosted build runs the Bob backend on Red Hat OpenShift clusters the organisation operates itself. Developers keep using the same Bob IDE and Bob Shell they already know.
There are two model routes. In a hybrid setup, Bob calls a frontier model through the organisation’s own cloud account: AWS Bedrock, Azure OpenAI, Google Vertex AI, or any OpenAI-compatible service. Identity, audit logs and metering stay on the cluster. In a fully self-hosted setup, for networks with no outbound connection, the model runs on the organisation’s own GPUs.
That second route is the interesting one, because it is genuinely air-gapped. IBM supports an indirect install path where images are downloaded on a connected machine, carried across the gap, and pushed from the isolated side. Installation uses a CLI called bobctl.
The caveat sits in the models. On the fully air-gapped route, IBM lists two supported open-weight models: NVIDIA Nemotron 3 Ultra and Poolside Laguna S 2.1. Those are not the frontier models Bob uses in the cloud. So the strictest sovereignty option is also the one with the least model capability. That is a trade-off buyers will have to weigh, and IBM states it plainly in its documentation.
The market it is selling into
IBM is not inventing a problem. Its own Institute for Business Value found that 68% of surveyed executives say meeting data residency and sovereignty requirements across geographies is challenging.
The broader signals point the same way. Forrester named sovereign AI a strategic priority for 2026. IDC research found it is widely cited as important but poorly defined. One in three respondents could not describe it in their own words.
IDC projects that CIOs at multinationals will raise sovereign-ready investment sharply by 2028. Futurum projects hybrid and edge deployments will take 44% of the AI infrastructure market by 2030.
Regulatory drivers are real, and they are why the term exists. The US CLOUD Act can compel a US-headquartered provider to hand over data regardless of where the servers sit. The EU AI Act, DORA and NIS2 push regulated buyers toward architectures a foreign jurisdiction cannot reach. Residency — where data sits — is not the same as sovereignty — who can lawfully compel access to it. IBM’s air-gapped route is aimed squarely at that distinction.
Why “self-hosted” means different things
This is where the announcement earns its place, because the field is uneven.
GitHub Copilot is cloud-only, routed through an Azure proxy. Business and Enterprise tiers keep your code out of training. But there is no fully local product — self-hosted Actions runners for its cloud agent are the closest option.
Cursor is also cloud-only: every request is assembled on its servers, even if you supply your own API key. Cursor launched “Self-Hosted Machines” in September 2026, but only the execution environment moves. The agent loop, inference and planning stay in Cursor’s cloud.
Amazon Q Developer runs inside the customer’s AWS trust boundary, which is strong isolation but not a true air-gapped product, and it is AWS-centric. Devin, from Cognition, can run in a customer VPC with customer-managed keys. It is pursuing FedRAMP High, but its agent’s reasoning still runs in Cognition’s cloud.
Only a small group offers the real thing. Security reviews consistently name Tabnine and the open-source Cline as the options that can run on-premises, in a VPC, or fully air-gapped with bring-your-own inference. IBM Bob now joins that group — with a fully air-gapped path and the model on the customer’s own GPUs.
That is a meaningful architectural line. Most “self-hosted” agentic coding tools self-host the execution, not the intelligence.
What to scrutinise
Three things deserve a second look before the announcement is taken at face value.
First, the productivity number. IBM cites an average 45% gain across Bob users, but that figure is IBM’s own internal measurement, self-reported, on IBM’s own codebases. It has not been independently verified. IBM’s own coverage acknowledges an open question: whether multi-model orchestration delivers the same results on customer code with different architecture and technical debt.
Second, the air-gapped model constraint. The strictest sovereignty route pairs the platform with open-weight models rather than frontier ones. That is a genuine capability ceiling, and buyers whose workloads need the best available model will be choosing between sovereignty and capability.
Third, the framing. “Self-hosted,” “sovereign” and “data residency” are three different things, and vendors use them loosely. IBM’s own documentation is precise about what runs where, which is to its credit. The reader should hold that precision against the marketing language around it.
The strategy behind it
Self-hosted Bob is not a standalone product move. IBM’s chief executive, Arvind Krishna, has described the company’s AI strategy as built on “hybrid, sovereignty and trust.” IBM positions Bob as a path of adoption toward its agentic governance platform, watsonx Orchestrate.
The timing fits. IBM made Bob generally available as SaaS in April 2026. It said then that on-premises deployment was “targeted in the future” for organisations with residency or regulatory needs. October delivers that promise. It also lands in a market where the buyer — not the vendor — increasingly sets the deployment terms.
What to watch
Three markers will show whether this lands.
First, named deployments. IBM has not published customers for the self-hosted build. A regulated reference — a bank, a government agency, a defence supplier — would carry more weight than the architecture alone.
Second, whether the model gap closes. If open-weight models on customer GPUs get close enough to frontier quality for real workloads, the sovereignty trade-off shrinks. If they do not, the air-gapped route stays a niche.
Third, whether rivals follow. Cursor’s partial self-hosting and Copilot’s cloud-only design are choices, not limits of physics. If regulated demand is as large as the forecasts suggest, the pressure to offer a genuinely air-gapped path will reach every vendor.
The question in agentic coding is shifting from what the model can do to who controls where it runs. IBM has answered that question more directly than most. The caveats are real, but so is the line it just drew.

Editor’s Note
Sources: IBM’s self-hosted Bob release of 1 October 2026, IBM’s newsroom announcement, the IBM Bob blog and product documentation, and IBM’s April 2026 Bob general-availability release. Market context is from IBM’s Institute for Business Value report “The Calculus of AI Sovereignty,” Forrester’s “Top 10 Trends in Sovereign AI, 2026,” Futurum Research, IDC research for Cohere, and an ISG report. Competitive and deployment facts are from vendor documentation and security reviews covering GitHub Copilot, Cursor, Amazon Q Developer, Devin (Cognition), Tabnine (Tricentis) and Cline, plus independent trade coverage from SiliconANGLE and CIO Dive.
The 45% productivity figure is IBM’s own internal, self-reported measurement and is not independently verified; the air-gapped model constraint and the productivity caveat are TechRecast’s own reading of IBM’s documentation.

